thx got spysweeper and it found 27 items heres the log:
********
07:53: | Start of Session, 17 February 2006 |
07:53: Spy Sweeper started
07:53: Sweep initiated using definitions version 616
07:54: Starting Memory Sweep
07:54: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:54: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:54: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:54: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:54: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:54: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:54: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:54: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:55: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:55: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:55: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:55: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:55: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:55: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:55: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:55: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:56: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:56: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:56: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:56: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:57: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:57: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:57: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:57: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:57: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:57: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:57: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:57: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:58: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:58: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:58: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:58: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:58: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:58: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:58: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:58: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:59: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:59: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:59: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:59: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:59: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:59: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
07:59: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
07:59: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:01: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:01: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:01: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:01: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:01: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:01: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:01: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:01: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:02: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:02: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:02: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:02: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:02: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:02: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:02: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:02: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:03: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:03: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:03: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:03: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:03: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:03: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:03: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:03: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:04: Memory Sweep Complete, Elapsed Time: 00:10:48
08:05: Starting Registry Sweep
08:05: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:05: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:05: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:05: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:05: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:05: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:05: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:05: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:05: Found Adware: findthewebsiteyouneed hijack
08:05: HKLM\software\microsoft\internet explorer\main\ || search page (ID = 125241)
08:05: HKLM\software\microsoft\internet explorer\search\ || searchassistant (ID = 125242)
08:05: Found Adware: effective-i toolbar
08:05: HKLM\software\effective-i\ (ID = 125658)
08:05: Found Adware: internetoptimizer
08:05: HKLM\software\microsoft\windows\currentversion\policies\ameopt\ (ID = 128912)
08:05: HKLM\software\policies\avenue media\ (ID = 128929)
08:06: Found Adware: ist yoursitebar
08:06: HKCR\interface\{03b800f9-2536-4441-8cda-2a3e6d15b4f8}\ (8 subtraces) (ID = 147832)
08:06: HKCR\interface\{dfbcc1eb-b149-487e-80c1-cc1562021542}\ (8 subtraces) (ID = 147835)
08:06: HKLM\software\classes\interface\{03b800f9-2536-4441-8cda-2a3e6d15b4f8}\ (8 subtraces) (ID = 147838)
08:06: HKLM\software\classes\interface\{dfbcc1eb-b149-487e-80c1-cc1562021542}\ (8 subtraces) (ID = 147841)
08:06: HKLM\software\classes\typelib\{4ee12b71-aa5e-45ec-8666-2db3ad3fdf44}\ (9 subtraces) (ID = 147842)
08:06: HKLM\software\microsoft\internet explorer\toolbar\ || {86227d9c-0efe-4f8a-aa55-30386a3f5686} (ID = 147852)
08:06: HKCR\typelib\{4ee12b71-aa5e-45ec-8666-2db3ad3fdf44}\ (9 subtraces) (ID = 147861)
08:06: Found Adware: visfx
08:06: HKLM\software\microsoft\windows\currentversion\uninstall\ovmon\ (2 subtraces) (ID = 712951)
08:06: HKLM\system\currentcontrolset\services\windows overlay components\ (12 subtraces) (ID = 712954)
08:06: Found Trojan Horse: trojan-downloader-zlob
08:06: HKCR\nvideocodek.chl\ (2 subtraces) (ID = 820294)
08:06: HKLM\software\classes\nvideocodek.chl\ (2 subtraces) (ID = 820324)
08:06: Found Adware: enbrowser
08:06: HKLM\software\system\sysold\ (ID = 926808)
08:06: HKLM\software\microsoft\windows\currentversion\run\ || themonitor (ID = 1028873)
08:06: Found Adware: quicklink search toolbar
08:06: HKCR\typelib\{2f6e85dc-8d2d-4896-8a4f-7df8a7b1749d}\ (9 subtraces) (ID = 1134093)
08:06: Found Adware: dollarrevenue
08:06: HKLM\software\microsoft\drsmartload2\ (1 subtraces) (ID = 1134137)
08:06: HKLM\software\classes\typelib\{2f6e85dc-8d2d-4896-8a4f-7df8a7b1749d}\ (9 subtraces) (ID = 1134251)
08:06: HKU\S-1-5-21-1275210071-113007714-1060284298-1003\software\microsoft\internet explorer\main\ || search bar (ID = 125237)
08:06: HKU\S-1-5-21-1275210071-113007714-1060284298-1003\software\microsoft\internet explorer\main\ || search page (ID = 125238)
08:06: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:06: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:06: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:06: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:06: HKU\S-1-5-21-1275210071-113007714-1060284298-1003\software\effective-i\ (6 subtraces) (ID = 125657)
08:06: HKU\S-1-5-21-1275210071-113007714-1060284298-1003\software\policies\avenue media\ (ID = 128928)
08:06: HKU\S-1-5-21-1275210071-113007714-1060284298-1003\software\microsoft\internet explorer\search\searchassistant explorer\main\ || default_search_url (ID = 555437)
08:06: HKU\S-1-5-21-1275210071-113007714-1060284298-1003\software\microsoft\windows\currentversion\policies\ameopt\ (ID = 654042)
08:06: HKU\S-1-5-21-1275210071-113007714-1060284298-1003\software\system\sysuid\ (1 subtraces) (ID = 731748)
08:06: HKU\S-1-5-21-1275210071-113007714-1060284298-1003\software\microsoft\internet explorer\main\ || search bar (ID = 790268)
08:06: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:06: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:06: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:06: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:06: Registry Sweep Complete, Elapsed Time:00:01:50
08:06: Starting Cookie Sweep
08:06: Found Spy Cookie: 2o7.net cookie
08:06: everybody@2o7[2].txt (ID = 1957)
08:06: Found Spy Cookie: pointroll cookie
08:06: everybody@ads.pointroll[1].txt (ID = 3148)
08:06: Found Spy Cookie: apmebf cookie
08:06: everybody@apmebf[2].txt (ID = 2229)
08:06: Found Spy Cookie: falkag cookie
08:06: everybody@as-us.falkag[2].txt (ID = 2650)
08:06: Found Spy Cookie: atlas dmt cookie
08:06: everybody@atdmt[2].txt (ID = 2253)
08:06: Found Spy Cookie: enhance cookie
08:06: everybody@c.enhance[2].txt (ID = 2614)
08:06: Found Spy Cookie: fastclick cookie
08:06: everybody@fastclick[2].txt (ID = 2651)
08:06: Found Spy Cookie: hotlog cookie
08:06: everybody@hotlog[1].txt (ID = 2801)
08:06: Found Spy Cookie: mediaplex cookie
08:06: everybody@mediaplex[1].txt (ID = 6442)
08:06: Found Spy Cookie: qksrv cookie
08:06: everybody@qksrv[2].txt (ID = 3213)
08:06: Found Spy Cookie: realmedia cookie
08:06: everybody@realmedia[1].txt (ID = 3235)
08:06: everybody@sel.as-us.falkag[2].txt (ID = 2650)
08:06: Found Spy Cookie: spylog cookie
08:06: everybody@spylog[1].txt (ID = 3415)
08:06: Found Spy Cookie: statcounter cookie
08:06: everybody@statcounter[2].txt (ID = 3447)
08:06: Cookie Sweep Complete, Elapsed Time: 00:00:03
08:07: Starting File Sweep
08:07: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:07: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:07: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:07: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:07: Found Adware: command
08:07: c:\program files\network monitor (1 subtraces) (ID = -2147459771)
08:08: c:\program files\jalmp (3 subtraces) (ID = -2147459072)
08:08: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:08: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:08: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:08: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:08: __sysc00.exe (ID = 244277)
08:08: uni_eh.exe (ID = 245110)
08:09: netmon.exe (ID = 231443)
08:09: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:09: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:09: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:09: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:09: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:09: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:09: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:09: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:09: titno.exe (ID = 238242)
08:10: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:10: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:10: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:10: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:10: Found Adware: targetsaver
08:10: class-barrel (ID = 78229)
08:10: Found Adware: look2me
08:10: h62olgf3162.dll (ID = 159)
08:10: Found Adware: findthewebsiteyouneed hijacker
08:10: __winsysupd8.exe (ID = 245943)
08:10: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:10: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:10: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:10: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:11: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:11: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:11: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:11: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:12: vocabulary (ID = 78283)
08:12: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:12: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:12: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:12: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:12: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:12: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:12: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:12: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:12: jalmp.dll (ID = 238167)
08:13: Found Adware: surfsidekick
08:13: vcupdate.exe.config (ID = 212361)
08:13: hr8u05l9e.dll (ID = 163672)
08:13: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:13: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:13: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:13: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:13: icxrtmgr.dll (ID = 159)
08:13: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:13: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:13: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:13: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:14: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:14: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:14: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:14: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:14: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:14: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:14: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:14: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:15: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:15: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:15: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:15: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:16: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:16: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:16: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:16: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:16: __winsysban8.exe (ID = 245942)
08:17: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:17: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:17: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:17: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:17: __ms04530303-191.exe (ID = 244278)
08:17: uninstall.exe (ID = 237448)
08:17: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:17: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:17: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:17: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:18: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:18: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:18: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:18: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:18: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:18: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:18: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:18: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:19: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:19: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:19: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:19: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:20: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:20: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:20: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:20: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:20: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:20: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:20: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:20: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:21: cgmcat.dll (ID = 159)
08:21: tsupdate2[1].ini (ID = 193498)
08:21: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:21: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:21: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:21: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:21: uninstall_nmon.vbs (ID = 231442)
08:21: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:21: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:21: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:21: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:22: pf78.exe (ID = 244430)
08:22: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:22: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:22: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:22: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:23: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:23: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:23: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:23: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:23: arpf.cfg (ID = 208796)
08:23: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:23: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:23: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:23: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:24: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:24: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:24: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:24: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:25: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:25: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:25: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:25: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:25: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:25: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:25: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:25: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:26: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:26: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:26: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:26: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:26: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:26: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:26: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:26: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:27: vcclient.exe.config (ID = 212358)
08:27: File Sweep Complete, Elapsed Time: 00:20:15
08:27: Full Sweep has completed. Elapsed time 00:33:25
08:27: Traces Found: 164
08:27: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:27: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:27: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:27: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:27: Removal process initiated
08:27: Quarantining All Traces: look2me
08:28: Warning: QF[866]: CmprsF(): Sector size must be 512 bytes, not 50173
08:28: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:28: look2me is in use. It will be removed on reboot.
08:28: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:28: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:28: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:28: h62olgf3162.dll is in use. It will be removed on reboot.
08:28: hr8u05l9e.dll is in use. It will be removed on reboot.
08:28: cgmcat.dll is in use. It will be removed on reboot.
08:28: Quarantining All Traces: trojan-downloader-zlob
08:28: Quarantining All Traces: visfx
08:28: Quarantining All Traces: dollarrevenue
08:28: Quarantining All Traces: enbrowser
08:28: Quarantining All Traces: internetoptimizer
08:28: Quarantining All Traces: quicklink search toolbar
08:28: Quarantining All Traces: surfsidekick
08:28: Quarantining All Traces: command
08:28: Quarantining All Traces: effective-i toolbar
08:28: Quarantining All Traces: findthewebsiteyouneed hijacker
08:28: Quarantining All Traces: findthewebsiteyouneed hijack
08:28: Quarantining All Traces: ist yoursitebar
08:28: Quarantining All Traces: targetsaver
08:28: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:28: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
08:28: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:28: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
08:28: Quarantining All Traces: 2o7.net cookie
08:28: Quarantining All Traces: apmebf cookie
08:28: Quarantining All Traces: atlas dmt cookie
08:28: Quarantining All Traces: enhance cookie
08:28: Quarantining All Traces: falkag cookie
08:28: Quarantining All Traces: fastclick cookie
08:28: Quarantining All Traces: hotlog cookie
08:28: Quarantining All Traces: mediaplex cookie
08:28: Quarantining All Traces: pointroll cookie
08:28: Quarantining All Traces: qksrv cookie
08:28: Quarantining All Traces: realmedia cookie
08:28: Quarantining All Traces: spylog cookie
08:28: Quarantining All Traces: statcounter cookie
08:29: Preparing to restart your computer. Please wait...
08:29: Removal process completed. Elapsed time 00:01:34
********
07:51: | Start of Session, 17 February 2006 |
07:51: Spy Sweeper started
07:53: Your spyware definitions have been updated.
07:53: | End of Session, 17 February 2006 |
I then ran CWshredder and it didn't find any coolwebsearch
+ i removed new.new.hijacker
and heres my new hijack this log:
Logfile of HijackThis v1.99.1
Scan saved at 08:44:54, on 17/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\Explorer.EXE
C:\Inetpub\wwwroot\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\tftaiseA.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Everybody\My Documents\Alastair\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....er=6&ar=msnhome
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....er=6&ar=msnhome
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [tftaiseA] C:\WINDOWS\tftaiseA.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...kr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zon...er.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\hr8u05l9e.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVSync Manager (AvSynMgr) - Network Associates, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: MySQL - Unknown owner - C:\Inetpub\wwwroot\MySQL.exe (file missing)
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
stil don't know what C:\WINDOWS\tftaiseA.exe is, any ideas?