Cont'....
2:07 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:07 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:07 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:07 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:07 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:07 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:11 PM: Warning: File not found
2:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:11 PM: Warning: Unhandled Archive Type
2:11 PM: Warning: Invalid Stream
2:11 PM: Warning: Invalid file - not a PKZip file
2:11 PM: Warning: Invalid file - not a PKZip file
2:11 PM: Warning: Invalid file - not a PKZip file
2:11 PM: Warning: Invalid file - not a PKZip file
2:11 PM: Warning: Invalid file - not a PKZip file
2:11 PM: Warning: Invalid file - not a PKZip file
2:11 PM: Warning: Invalid file - not a PKZip file
2:11 PM: Warning: Invalid file - not a PKZip file
2:11 PM: Warning: Invalid file - not a PKZip file
2:11 PM: Warning: Invalid Stream
2:11 PM: Warning: Invalid Stream
2:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:11 PM: File Sweep Complete, Elapsed Time: 00:46:27
2:11 PM: Full Sweep has completed. Elapsed time 00:56:18
2:11 PM: Traces Found: 5
2:11 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:11 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: Removal process initiated
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: Quarantining All Traces: look2me
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: look2me is in use. It will be removed on reboot.
2:12 PM: f0l00a3med.dll is in use. It will be removed on reboot.
2:12 PM: dzsrslvr.dll is in use. It will be removed on reboot.
2:12 PM: Quarantining All Traces: command
2:12 PM: Quarantining All Traces: ist yoursitebar
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:12 PM: Quarantining All Traces: whenu
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:13 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:13 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:13 PM: Removal process completed. Elapsed time 00:01:26
********
1:11 PM: | Start of Session, Friday, March 10, 2006 |
1:11 PM: Spy Sweeper started
1:12 PM: Messenger service has been disabled.
1:13 PM: Your spyware definitions have been updated.
1:13 PM: Your definitions are up to date.
1:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
1:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
1:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
1:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
1:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
1:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
1:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
1:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
1:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
1:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
1:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
1:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
1:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
1:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
1:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
1:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
1:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
1:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
1:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
1:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
1:15 PM: | End of Session, Friday, March 10, 2006 |
The first time i ranspy sweeper it asked me to reboot but i wanted to save the log first and declined the reboot. Saved the log but unable to reboot so ran spysweeper again.
Then i ran a new HJT log ....BUT system wont allow me to reboot,or ctrl-alt-del and i wanted to wait for advice from you before I hit the power switch
Heres the hjt log (without reboot)
Logfile of HijackThis v1.99.1
Scan saved at 3:16:02 PM, on 3/10/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\ViRobot NT\vrmonsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\Nics\Rcsdeamon.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\WINNT\nics\SafeULoader.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINNT\nics\Safecom.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Documents and Settings\Jason Waldie\Desktop\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://drudgereport.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwproxy.student.unimelb.edu.au:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = login.wireless.unimelb.edu.au;localhost
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [SafePC Starter] C:\WINNT\safepcstartnt.exe
O4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [OptusNet DSL Setup] D:\OptusNet.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINNT\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Vrmon] C:\Program Files\ViRobot NT\vrmonnt.exe Main
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://dsl.optusnet.com.au/
O20 - Winlogon Notify: ModuleUsage - C:\WINNT\system32\f0l00a3med.dll
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: ViRobot Professional Monitoring (vrmonsvc) - HAURI - C:\Program Files\ViRobot NT\vrmonsvc.exe
Thanks tons!
Jason