Hi Ken545,
I had both spybot and ad-awre already. I coudlnt find the following anywhere in spybot:
* Then to Tools/ Hosts Files click on Add Spybot S&D Hosts Files.
The program is the correct version and is up to date, so i dont know what thats all about!
Also, after rebooting once i had run ad-aware and spybot scans, i did a one button check with norton works, it found 55 windows registry errors and 4 program integrity errors. I didnt choose to fix them incase it reversed some of the work done by the to spyware progs. Should i do this later???
OK, so here are my new logs:
Spysweeper:
********
21:48: | Start of Session, 24 February 2006 |
21:48: Spy Sweeper started
21:48: Sweep initiated using definitions version 621
21:48: Starting Memory Sweep
21:53: Memory Sweep Complete, Elapsed Time: 00:05:16
21:53: Starting Registry Sweep
21:53: Found Adware: hotbar
21:53: HKCR\interface\{20d21e02-8c1c-41fe-9826-dab4c223436c}\ (8 subtraces) (ID = 127333)
21:53: HKCR\interface\{66291bef-c867-43c0-a7b4-d13393814bcd}\ (8 subtraces) (ID = 127342)
21:53: HKLM\software\classes\clsid\{460ac4db-b0de-4626-a0f0-175dd84dcb9b}\ (2 subtraces) (ID = 127416)
21:53: HKLM\software\classes\interface\{20d21e02-8c1c-41fe-9826-dab4c223436c}\ (8 subtraces) (ID = 127498)
21:53: HKLM\software\classes\interface\{66291bef-c867-43c0-a7b4-d13393814bcd}\ (8 subtraces) (ID = 127506)
21:53: HKLM\software\classes\spamblockerconfig.application\ (3 subtraces) (ID = 127536)
21:53: HKLM\software\classes\typelib\{5ba32d9e-f1bd-476c-ad42-97c9379a57a4}\ (9 subtraces) (ID = 127538)
21:53: HKLM\software\spam blocker\ (7 subtraces) (ID = 127633)
21:53: HKCR\spamblockerconfig.application\ (3 subtraces) (ID = 127634)
21:53: HKCR\typelib\{5ba32d9e-f1bd-476c-ad42-97c9379a57a4}\ (9 subtraces) (ID = 127636)
21:53: Found Adware: accoona toolbar
21:53: HKCR\typelib\{ea3956d2-ec38-41ab-b601-47aa281e4952}\ (9 subtraces) (ID = 520538)
21:53: HKCR\clsid\{f80c1d93-0d22-436e-963e-9d3156997a4e}\ (4 subtraces) (ID = 954998)
21:53: HKLM\software\classes\clsid\{f80c1d93-0d22-436e-963e-9d3156997a4e}\ (4 subtraces) (ID = 955055)
21:53: HKLM\software\classes\typelib\{ea3956d2-ec38-41ab-b601-47aa281e4952}\ (9 subtraces) (ID = 955503)
21:53: HKCR\sbcoresrv.coreservices\ (5 subtraces) (ID = 968212)
21:53: HKCR\sbcoresrv.coreservices.1\ (3 subtraces) (ID = 968218)
21:53: HKCR\sbcoresrv.lfgax\ (5 subtraces) (ID = 968222)
21:53: HKCR\sbcoresrv.lfgax.1\ (3 subtraces) (ID = 968228)
21:53: HKCR\sbhostie.bho\ (5 subtraces) (ID = 968232)
21:53: HKCR\sbhostie.bho.1\ (3 subtraces) (ID = 968238)
21:53: HKCR\sbhostol.mailanim\ (5 subtraces) (ID = 968242)
21:53: HKCR\sbhostol.mailanim.1\ (3 subtraces) (ID = 968248)
21:53: HKCR\sbhostol.webmailsend\ (5 subtraces) (ID = 968252)
21:53: HKCR\sbhostol.webmailsend.1\ (3 subtraces) (ID = 968258)
21:53: HKCR\sbinstie.sbinstobj\ (5 subtraces) (ID = 968262)
21:53: HKCR\sbinstie.sbinstobj.1\ (3 subtraces) (ID = 968268)
21:53: HKCR\sbsrv.coreservices\ (5 subtraces) (ID = 968272)
21:53: HKCR\sbsrv.coreservices.1\ (3 subtraces) (ID = 968278)
21:53: HKCR\sbtoolbar.htmlmenuui\ (5 subtraces) (ID = 968282)
21:53: HKCR\sbtoolbar.htmlmenuui.1\ (3 subtraces) (ID = 968288)
21:53: HKCR\sbtoolbar.toolbarctl\ (5 subtraces) (ID = 968292)
21:53: HKCR\sbtoolbar.toolbarctl.1\ (3 subtraces) (ID = 968298)
21:53: HKCR\sbwallpaper.wallpapermanager\ (5 subtraces) (ID = 968302)
21:53: HKCR\sbwallpaper.wallpapermanager.1\ (3 subtraces) (ID = 968308)
21:53: HKCR\spamblockerconfig.application.1\ (3 subtraces) (ID = 968312)
21:53: HKCR\spamblockerutility.commband\ (5 subtraces) (ID = 968316)
21:53: HKCR\spamblockerutility.sbmain\ (5 subtraces) (ID = 968326)
21:53: HKCR\spamblockerutility.sbmain.1\ (3 subtraces) (ID = 968332)
21:53: HKCR\spamblockerutility.travelcomparebar\ (5 subtraces) (ID = 968336)
21:53: HKCR\spamblockerutility.travelcomparebar.1\ (3 subtraces) (ID = 968342)
21:53: HKLM\software\classes\sbcoresrv.coreservices\ (5 subtraces) (ID = 968767)
21:53: HKLM\software\classes\sbcoresrv.coreservices.1\ (3 subtraces) (ID = 968773)
21:53: HKLM\software\classes\sbcoresrv.lfgax\ (5 subtraces) (ID = 968777)
21:53: HKLM\software\classes\sbcoresrv.lfgax.1\ (3 subtraces) (ID = 968783)
21:53: HKLM\software\classes\sbhostie.bho\ (5 subtraces) (ID = 968787)
21:53: HKLM\software\classes\sbhostie.bho.1\ (3 subtraces) (ID = 968793)
21:53: HKLM\software\classes\sbhostol.mailanim\ (5 subtraces) (ID = 968797)
21:53: HKLM\software\classes\sbhostol.mailanim.1\ (3 subtraces) (ID = 968803)
21:53: HKLM\software\classes\sbhostol.webmailsend\ (5 subtraces) (ID = 968807)
21:53: HKLM\software\classes\sbhostol.webmailsend.1\ (3 subtraces) (ID = 968813)
21:53: HKLM\software\classes\sbinstie.sbinstobj\ (5 subtraces) (ID = 968817)
21:53: HKLM\software\classes\sbinstie.sbinstobj.1\ (3 subtraces) (ID = 968823)
21:53: HKLM\software\classes\sbsrv.coreservices\ (5 subtraces) (ID = 968827)
21:53: HKLM\software\classes\sbsrv.coreservices.1\ (3 subtraces) (ID = 968833)
21:53: HKLM\software\classes\sbtoolbar.htmlmenuui\ (5 subtraces) (ID = 968837)
21:53: HKLM\software\classes\sbtoolbar.htmlmenuui.1\ (3 subtraces) (ID = 968843)
21:53: HKLM\software\classes\sbtoolbar.toolbarctl\ (5 subtraces) (ID = 968847)
21:53: HKLM\software\classes\sbtoolbar.toolbarctl.1\ (3 subtraces) (ID = 968853)
21:53: HKLM\software\classes\sbwallpaper.wallpapermanager\ (5 subtraces) (ID = 968857)
21:53: HKLM\software\classes\spamblockerconfig.application.1\ (3 subtraces) (ID = 968867)
21:53: HKLM\software\classes\spamblockerutility.commband\ (5 subtraces) (ID = 968871)
21:53: HKLM\software\classes\spamblockerutility.commband.1\ (3 subtraces) (ID = 968877)
21:53: HKLM\software\classes\spamblockerutility.sbmain\ (5 subtraces) (ID = 968881)
21:53: HKLM\software\classes\spamblockerutility.sbmain.1\ (3 subtraces) (ID = 968887)
21:53: HKLM\software\classes\spamblockerutility.travelcomparebar\ (5 subtraces) (ID = 968891)
21:53: HKLM\software\classes\spamblockerutility.travelcomparebar.1\ (3 subtraces) (ID = 968897)
21:53: HKLM\software\microsoft\office\outlook\addins\sbhostol.mailanim\ (4 subtraces) (ID = 975743)
21:53: HKLM\software\spamblockerutility\ (61 subtraces) (ID = 978182)
21:53: HKLM\software\microsoft\windows\currentversion\internet settings\5.0\user agent\post platform\ || spamblockerutility 4.7.1 (ID = 993504)
21:53: HKCR\clsid\{460ac4db-b0de-4626-a0f0-175dd84dcb9b}\ (2 subtraces) (ID = 1084062)
21:53: HKU\S-1-5-21-790525478-920026266-1343024091-1004\software\microsoft\internet explorer\extensions\cmdmapping\ || {946b3e9e-e21a-49c8-9f63-900533fafe14} (ID = 127575)
21:53: HKU\S-1-5-21-790525478-920026266-1343024091-1004\software\microsoft\internet explorer\extensions\cmdmapping\ || {e77eda01-3c56-4a96-8d08-02b42891c169} (ID = 127576)
21:54: HKU\S-1-5-21-790525478-920026266-1343024091-1004\software\microsoft\installer\features\10b0642b36134f8f914ea8e11ee5b503\ (1 subtraces) (ID = 788006)
21:54: HKU\S-1-5-21-790525478-920026266-1343024091-1004\software\microsoft\installer\products\d493500bd4a54ea6bc805fc9cda952c5\ (2 subtraces) (ID = 788008)
21:54: HKU\S-1-5-21-790525478-920026266-1343024091-1004\software\spamblockerutility\ (160 subtraces) (ID = 968537)
21:54: Registry Sweep Complete, Elapsed Time:00:00:28
21:54: Starting Cookie Sweep
21:54: Found Spy Cookie: yieldmanager cookie
21:54: bob@ad.yieldmanager[1].txt (ID = 3751)
21:54: Found Spy Cookie: a cookie
21:54: bob@a[1].txt (ID = 2027)
21:54: Found Spy Cookie: belnk cookie
21:54: bob@belnk[1].txt (ID = 2292)
21:54: bob@dist.belnk[2].txt (ID = 2293)
21:54: Found Spy Cookie: nextag cookie
21:54: bob@nextag[2].txt (ID = 5014)
21:54: Found Spy Cookie: rn11 cookie
21:54: bob@rn11[2].txt (ID = 3261)
21:54: Cookie Sweep Complete, Elapsed Time: 00:00:00
21:54: Starting File Sweep
22:19: Found Adware: apropos
22:19: wingenerics.dll (ID = 50187)
22:21: Found Adware: shopathomeselect
22:21: intlib.bin (ID = 131688)
22:32: Found System Monitor: potentially rootkit-masked files
22:32: 00072143. (ID = 0)
22:32: 00072122. (ID = 0)
22:32: vbapsets.exe (ID = 0)
22:32: 00072246. (ID = 0)
22:32: ftdiint5.sys (ID = 0)
22:32: 00005336. (ID = 0)
22:32: sndvi80n.exe (ID = 0)
22:32: 00072320. (ID = 0)
22:32: ace.dll (ID = 0)
22:32: data.bin (ID = 0)
22:32: 00072205. (ID = 0)
22:32: ltfotvid.exe (ID = 0)
22:32: ai_22-02-2006.log (ID = 0)
22:32: ai_21-02-2006.log (ID = 0)
22:32: ai_23-02-2006.log (ID = 0)
22:32: ai_19-02-2006.log (ID = 0)
22:32: ai_24-02-2006.log (ID = 0)
22:32: ai_18-02-2006.log (ID = 0)
22:32: ai_20-02-2006.log (ID = 0)
22:34: File Sweep Complete, Elapsed Time: 00:39:53
22:34: Full Sweep has completed. Elapsed time 00:45:58
22:34: Traces Found: 631
22:35: Removal process initiated
22:35: Quarantining All Traces: potentially rootkit-masked files
22:36: potentially rootkit-masked files is in use. It will be removed on reboot.
22:36: 00072143. is in use. It will be removed on reboot.
22:36: 00072122. is in use. It will be removed on reboot.
22:36: vbapsets.exe is in use. It will be removed on reboot.
22:36: 00072246. is in use. It will be removed on reboot.
22:36: ftdiint5.sys is in use. It will be removed on reboot.
22:36: 00005336. is in use. It will be removed on reboot.
22:36: sndvi80n.exe is in use. It will be removed on reboot.
22:36: 00072320. is in use. It will be removed on reboot.
22:36: ace.dll is in use. It will be removed on reboot.
22:36: data.bin is in use. It will be removed on reboot.
22:36: 00072205. is in use. It will be removed on reboot.
22:36: ltfotvid.exe is in use. It will be removed on reboot.
22:36: ai_22-02-2006.log is in use. It will be removed on reboot.
22:36: ai_21-02-2006.log is in use. It will be removed on reboot.
22:36: ai_23-02-2006.log is in use. It will be removed on reboot.
22:36: ai_19-02-2006.log is in use. It will be removed on reboot.
22:36: ai_24-02-2006.log is in use. It will be removed on reboot.
22:36: ai_18-02-2006.log is in use. It will be removed on reboot.
22:36: ai_20-02-2006.log is in use. It will be removed on reboot.
22:36: Quarantining All Traces: apropos
22:36: apropos is in use. It will be removed on reboot.
22:36: wingenerics.dll is in use. It will be removed on reboot.
22:36: Quarantining All Traces: hotbar
22:36: Quarantining All Traces: accoona toolbar
22:36: Quarantining All Traces: shopathomeselect
22:36: Quarantining All Traces: a cookie
22:36: Quarantining All Traces: belnk cookie
22:36: Quarantining All Traces: nextag cookie
22:36: Quarantining All Traces: rn11 cookie
22:36: Quarantining All Traces: yieldmanager cookie
22:37: Removal process completed. Elapsed time 00:02:12
********
21:34: | Start of Session, 24 February 2006 |
21:34: Spy Sweeper started
21:36: Your spyware definitions have been updated.
21:48: | End of Session, 24 February 2006 |
New HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 22:58:12, on 24/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\Program Files\ZyXEL\ADSL USB Modem\CnxDslTb.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\ONSPEED\onspeedcore.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\ONSPEED\onspeedgui.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\FRU\Remind32.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5405
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\ONSPEED\PBHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program
Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: ONSPEED - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - C:\Program Files\ONSPEED\Toolband.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [pdfFactory Dispatcher v2] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZyXEL\ADSL USB Modem\CnxDslTb.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LE.EXE /P24 "EPSON
Stylus Photo R1800" /O6 "USB001" /M "Stylus Photo R1800"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SlipStream] "C:\Program Files\ONSPEED\onspeedcore.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - Startup: Hewlett-Packard Recorder.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 900 series\FRU\Remind32.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: ONSPEED.lnk = C:\Program Files\ONSPEED\onspeedgui.exe
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Show All Original Images - res://C:\Program Files\ONSPEED\gui_resource.dll/327
O8 - Extra context menu item: Show Original Image - res://C:\Program Files\ONSPEED\gui_resource.dll/328
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth
Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program
Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1131071378661
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cab
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) -
http://das.microsoft...tail/DASAct.cab
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://D:\SuperCD\IntraLaunch.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cab
O16 - DPF: {C1BAC744-8F0B-11D0-89E7-00C0A8295197} (Cameractl Class) -
http://www.nwales-tr...ivex/camera.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
http://h30043.www3.h.../qdiagh.cab?321
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) -
http://by103fd.bay10...ex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE05D28B-3E6B-4585-9B8A-D67B0557F12B}: NameServer = 195.184.228.6
195.184.228.7
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: BackupClientSvc - Unknown owner - C:\PROGRA~1\MYDATA~1\BackupClientSvc.Exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth
Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec
Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common
Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Personal
Firewall\ccPxySvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common
Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton
SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton
Personal Firewall\NISUM.EXE
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton
SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common
Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy
Sweeper\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security
Center\SymWSC.exe
END OF LOG
Also Ken545, i dont know why my HJT log was all funny last time, the only thing i may have done differently to your request was that i may have right clicked and copied instead of EDIT/COPY as you suggested.....wouldnt have thought it would make a difference.
Ok, thanks again mate.........computer does seem a fair bit quicker.....(i think...
)
Stu