This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT Log Assistance Request

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was hoping you could assist me in evaluating my HJT log. I appreciate the service!!!
My problem relates to being redirected to "errorplace.com" primarily when attempting to go to a site to download software.
Here's the log:

Logfile of HijackThis v1.99.1
Scan saved at 7:55:06 PM, on 3/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NavNT\vptray.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\NavNT\defwatch.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\WINDOWS\system32\MsgSys.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://charter.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/w/search.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: jimmyhelp.CBrowserHelper - {EA8E2DCA-A30A-4F28-BB2D-51B76440C5D0} - C:\WINDOWS\htduolq.dll
O2 - BHO: jimmyhelp.CBrowserHelper - {FD1A0C37-701E-45EE-AAF0-AE1B8EB66BC0} - C:\WINDOWS\axqjnl.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [dxcps] C:\WINDOWS\fuet.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\BRIANC~1\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Hpas] C:\Documents and Settings\Brian Caimi\Application Data\tabu.exe
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\RunOnce: [DelayShred] "C:\Program Files\McAfee\McAfee Shared Components\Shredder 5\SHRED32.EXE" /q C:\DOCUME~1\BRIANC~1\LOCALS~1\TEMPOR~1\Content.SH!
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Enjoy It - {47055D63-DFCD-11d3-8406-00500445A7D1} - C:\WINDOWS\system32\windialup\3037[1]\windialup.exe (file missing)
O9 - Extra 'Tools' menuitem: Enjoy It - {47055D63-DFCD-11d3-8406-00500445A7D1} - C:\WINDOWS\system32\windialup\3037[1]\windialup.exe (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.stevengould.org
O15 - Trusted Zone: *.stevengould.org
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,7…pdatePortal.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - http://cabs.roings.com/cabs/budicon.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

Thank you
BrianSTL
Hello Brian STL, Welcome to the forum.

This is what I suggest you do.


Please do not delete anything unless instructed to.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Even if you've already run these, make SURE they're up-to-date and run per instructions.

Make sure you have the up-to-date versions of Spybot V 1.4 and Ad-aware SE Build 1.06 . All are free and available below.

Download Spybot, install and update. Then download Ad-aware, install, and update.

Spybot:

Install the program and launch it.

Go to Start > Programs >Spybot > Search & Destroy and choose Spybot S&D

Close ALL windows except Spybot S&D
Click the button to "Search for Updates" and download and install the Updates.
Next click the button "Check for Problems"
When Spybot is complete, it will be showing "RED" (RED) entries "BLACK" entries and "GREEN" (GREEN) entries in the window
Put a check mark beside the RED (RED) entries ONLY.
Choose "Fix Selected Problems" and allow Spybot to fix the RED (RED) entries.

Ad-Aware FULL SCAN:

Install the program and launch it.

1. Launch Ad-Aware SE and run the WebUpdate feature. (Click on the Globe icon > Click connect > Click OK > Click Finish.)
2. Set up the Configurations as follows:
– Click the Gear wheel at the top of the Ad-Aware window
– Click General > Safety & Settings: Check (Green) all three.
– Click Tweak > Cleaning Engine > UNcheck "Always try to unload modules before deletion".
3. Click "Proceed"
4. Click "Scan Now"
5. Deselect "Search for negligible risk entries" as negligible risk entries (MRU's) are not considered to be a threat.
6. Select "Search for low-risk threats"
7. Run the scanner using the Full Scan (Perform full system scan) mode.
8. When the scan has completed, select Next.
9. In the Scanning Results window, select the "Scan Summary" tab.
10. Check the box next to each "target family" you wish to remove.
11. Click next > Click OK.

Next:

Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

Exit Spy Sweeper.

Empty Recycle Bin

Reboot and "copy/paste" a new HJT log as well as the Resullts from Spy Sweeper file into this thread.
Also please describe how your computer behaves at the moment.
Thank you for the suggestions - I really appreciate your help. It took a while to download the updates to Spybot & Ad-Aware since the primary issue I have is whenever I try to download a program I am redirected to errorplace.com. I also couldn't find a way to download the trail Spy Sweeper, so I went ahead and purchased a year subscription and ran it. Took a long time to get the link to all of these download sites to "take."

My browser is working much the same as before. I can navigate without a lot of issue until I try to download a program, at which time I'm redirected to errorplace.com. So while I seem to find and isolate spyware when I ran all three programs, the issue remained. I guess they are identified but not removed.

I look forward to your assistance.

Here are the logs you requested

HijackThis Log

Logfile of HijackThis v1.99.1
Scan saved at 8:19:48 AM, on 3/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\NavNT\defwatch.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://charter.msn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: jimmyhelp.CBrowserHelper - {EA8E2DCA-A30A-4F28-BB2D-51B76440C5D0} - C:\WINDOWS\htduolq.dll
O2 - BHO: jimmyhelp.CBrowserHelper - {FD1A0C37-701E-45EE-AAF0-AE1B8EB66BC0} - C:\WINDOWS\axqjnl.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [dxcps] C:\WINDOWS\fuet.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\BRIANC~1\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Hpas] C:\Documents and Settings\Brian Caimi\Application Data\tabu.exe
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\RunOnce: [DelayShred] "C:\Program Files\McAfee\McAfee Shared Components\Shredder 5\SHRED32.EXE" /q C:\DOCUME~1\BRIANC~1\LOCALS~1\TEMPOR~1\Content.SH!
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Enjoy It - {47055D63-DFCD-11d3-8406-00500445A7D1} - C:\WINDOWS\system32\windialup\3037[1]\windialup.exe (file missing)
O9 - Extra 'Tools' menuitem: Enjoy It - {47055D63-DFCD-11d3-8406-00500445A7D1} - C:\WINDOWS\system32\windialup\3037[1]\windialup.exe (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.stevengould.org
O15 - Trusted Zone: *.stevengould.org
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,7…pdatePortal.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe


SPY SWEEPER LOG

1:22 AM: | Start of Session, Saturday, March 25, 2006 |
1:22 AM: Spy Sweeper started
1:22 AM: Sweep initiated using definitions version 641
1:22 AM: Starting Memory Sweep
1:41 AM: Memory Sweep Complete, Elapsed Time: 00:19:07
1:41 AM: Starting Registry Sweep
1:41 AM: Found Adware: exact cashback/bargain buddy
1:41 AM: HKLM\software\microsoft\windows\currentversion\app management\arpcache\bargain buddy\ (2 subtraces) (ID = 104023)
1:42 AM: Found Adware: purityscan
1:42 AM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediaticketsinstaller.ocx\ (2 subtraces) (ID = 137986)
1:42 AM: Found Adware: elitemediagroup-mediamotor
1:42 AM: HKLM\software\microsoft\windows\currentversion\uninstall\mediamotor\ (2 subtraces) (ID = 140209)
1:42 AM: HKLM\software\roimoi\ (3 subtraces) (ID = 140213)
1:42 AM: HKLM\software\ssprint\ (1 subtraces) (ID = 140214)
1:42 AM: Found Adware: syncroad
1:42 AM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/syncroadx.dll\ (2 subtraces) (ID = 143513)
1:42 AM: Found Adware: wildmedia
1:42 AM: HKCR\interface\{851f86c9-d3cc-4574-93f5-40e2d65159e4}\ (8 subtraces) (ID = 146695)
1:42 AM: HKLM\software\classes\interface\{851f86c9-d3cc-4574-93f5-40e2d65159e4}\ (8 subtraces) (ID = 146709)
1:42 AM: Found Adware: searchv hijack
1:42 AM: HKLM\software\microsoft\internet explorer\search\ || default_search_url (ID = 1177482)
1:42 AM: Found Adware: drsnsrch.com hijack
1:42 AM: HKU\S-1-5-21-1547161642-1383384898-854245398-1003\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
1:42 AM: Registry Sweep Complete, Elapsed Time:00:01:34
1:42 AM: Starting Cookie Sweep
1:42 AM: Found Spy Cookie: shopnav cookie
1:42 AM: brian caimi@shopnav[1].txt (ID = 3369)
1:42 AM: Found Spy Cookie: go.com cookie
1:42 AM: brian [removed][1].txt (ID = 2729)
1:42 AM: brian caimi@go[1].txt (ID = 2728)
1:42 AM: Found Spy Cookie: atwola cookie
1:42 AM: brian caimi@atwola[1].txt (ID = 2255)
1:42 AM: Found Spy Cookie: a cookie
1:42 AM: brian caimi@a[2].txt (ID = 2027)
1:42 AM: brian caimi@atwola[3].txt (ID = 2255)
1:42 AM: brian [removed][1].txt (ID = 2729)
1:42 AM: brian [removed][2].txt (ID = 2729)
1:42 AM: brian caimi@atwola[2].txt (ID = 2255)
1:42 AM: Found Spy Cookie: rightmedia cookie
1:42 AM: brian caimi@rightmedia[1].txt (ID = 3259)
1:42 AM: Found Spy Cookie: specificclick.com cookie
1:42 AM: brian [removed][1].txt (ID = 3400)
1:42 AM: Found Spy Cookie: offeroptimizer cookie
1:42 AM: brian caimi@offeroptimizer[1].txt (ID = 3087)
1:42 AM: Found Spy Cookie: adknowledge cookie
1:42 AM: brian caimi@adknowledge[1].txt (ID = 2072)
1:42 AM: brian caimi@atwola[4].txt (ID = 2255)
1:42 AM: brian [removed][1].txt (ID = 2256)
1:42 AM: Found Spy Cookie: yieldmanager cookie
1:42 AM: brian [removed][2].txt (ID = 3751)
1:42 AM: Found Spy Cookie: tacoda cookie
1:42 AM: brian caimi@tacoda[2].txt (ID = 6444)
1:42 AM: Found Spy Cookie: burstnet cookie
1:42 AM: brian caimi@burstnet[2].txt (ID = 2336)
1:42 AM: Cookie Sweep Complete, Elapsed Time: 00:00:03
1:43 AM: Starting File Sweep
1:43 AM: Warning: Failed to open file "c:\pagefile.sys". Access is denied
1:43 AM: Warning: Failed to open file "c:\hiberfil.sys". Access is denied
1:48 AM: c:\program files\windows syncroad (ID = -2147480177)
2:01 AM: Warning: Failed to open file "c:\inetpub\catalog.wci\cisp0000.000". The process cannot access the file because it is being used by another process
2:01 AM: Warning: Failed to open file "c:\inetpub\catalog.wci\index.000". The process cannot access the file because it is being used by another process
2:01 AM: Warning: Failed to open file "c:\inetpub\catalog.wci\cicl0001.000". The process cannot access the file because it is being used by another process
2:01 AM: Warning: Failed to open file "c:\inetpub\catalog.wci\cisl0001.000". The process cannot access the file because it is being used by another process
2:01 AM: Warning: Failed to open file "c:\inetpub\catalog.wci\cip10000.000". The process cannot access the file because it is being used by another process
2:01 AM: Warning: Failed to open file "c:\inetpub\catalog.wci\cip20000.000". The process cannot access the file because it is being used by another process
2:01 AM: Warning: Failed to open file "c:\inetpub\catalog.wci\cipt0000.000". The process cannot access the file because it is being used by another process
2:01 AM: Warning: Failed to open file "c:\inetpub\catalog.wci\cist0000.000". The process cannot access the file because it is being used by another process
2:01 AM: Warning: Failed to open file "c:\inetpub\catalog.wci\civp0000.000". The process cannot access the file because it is being used by another process
2:10 AM: Warning: Failed to open file "c:\windows\system32\config\system.log". The process cannot access the file because it is being used by another process
2:10 AM: Warning: Failed to open file "c:\windows\system32\config\software.log". The process cannot access the file because it is being used by another process
2:10 AM: Warning: Failed to open file "c:\windows\system32\config\default.log". The process cannot access the file because it is being used by another process
2:10 AM: Warning: Failed to open file "c:\windows\system32\config\security". The process cannot access the file because it is being used by another process
2:10 AM: Warning: Failed to open file "c:\windows\system32\config\sam". The process cannot access the file because it is being used by another process
2:10 AM: Warning: Failed to open file "c:\windows\system32\config\sam.log". The process cannot access the file because it is being used by another process
2:10 AM: Warning: Failed to open file "c:\windows\system32\config\security.log". The process cannot access the file because it is being used by another process
2:10 AM: Warning: Failed to open file "c:\windows\system32\config\system". The process cannot access the file because it is being used by another process
2:10 AM: Warning: Failed to open file "c:\windows\system32\config\software". The process cannot access the file because it is being used by another process
2:10 AM: Warning: Failed to open file "c:\windows\system32\config\default". The process cannot access the file because it is being used by another process
2:24 AM: Found Adware: ipinsight
2:24 AM: conscorr.inf (ID = 64277)
2:26 AM: Found Adware: wild media - minigolf
2:26 AM: wildapp.inf (ID = 69911)
2:26 AM: roing18.inf (ID = 74136)
2:28 AM: Found Adware: internetoptimizer
2:28 AM: c:\windows\stwsi (ID = -2147480829)
2:39 AM: Warning: Failed to open file "c:\windows\softwaredistribution\eventcache\{4088c2b7-9b09-4a64-bb46-ffc736fd9c3e}.bin". The process cannot access the file because it is being used by another process
2:40 AM: Warning: Failed to open file "c:\documents and settings\all users\application data\mcafee\spamkiller\logs\filtering.log". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs534751d2-fd3b-4ca1-ac34-67318e818e5f.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa8a5e944-1bd8-4d24-b047-05c143e6a207.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs82abaf3e-187a-4113-91cf-597f678aca61.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs33e8afe7-7b32-4969-9a24-1c01244fc5f4.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs9e0d849a-04cc-4d05-8076-5788d55fdf84.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsca64da49-b8a9-4457-8a31-696c4f1641e9.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse09eb042-97b8-4ffa-b6c6-0d91258b5458.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs16588e5d-8dc9-4491-8caf-19416929bc3f.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8f68967c-4a81-4386-b538-66162a5b107b.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8d5dad04-d1ff-4345-80e0-1e974c82043b.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1aa028e0-e76d-4f19-81f7-c0e8c9793b20.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs799fc8f6-392c-4b05-9611-6d70d0be79b7.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs9b5d9427-6850-479c-86e4-ce897abe817e.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs43801307-6555-499f-bb9e-cf5c323cac79.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse668ebee-a9f2-4f73-9c59-d2d5d692f167.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs10a9f260-8e52-4519-9717-429408dbb450.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd1b46c7f-52d2-42f4-8212-03e959738768.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5ec71987-6bd0-4cc9-ab9a-81f8b7712394.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd3319774-a386-49c5-a18e-6f769da7d8e3.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7f6601ee-5dfc-4517-860e-2b262d7fda3b.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs700c79d5-b12b-47a8-9782-f0c0ebbd1386.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4ec59759-017e-4f5a-ae91-c71f55ba2b1c.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs432c971b-25d3-49b1-b07a-b71095b8ce89.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8eda1269-5768-4e10-bffd-1a50fa5a7f4f.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1648fd89-e881-4bc2-8940-a8acc1e33be7.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1904359a-128c-4a00-a76f-cf5b24ad7f6a.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb3395669-e560-413b-81c6-b44f2c672e77.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs958b62d3-6777-4177-b41d-e4869505cb0f.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5c1ed045-63c3-4ab9-8b96-4409eebd9056.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs260ab473-ccd6-4b81-9ef1-783c67bdbcf0.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc88d6a72-f259-4cf1-b37a-646f3cfe2447.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb627f9e4-640e-449d-a761-d859124080ab.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs07774570-fd30-402b-aeb6-b05c10ae69f9.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbf87be65-72ee-4a98-8a72-0aa16121662b.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1be9676a-d441-4ddb-ba32-06a406750c28.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf5aafc12-bf0d-481e-b67c-65fcb548108b.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs243dd9e6-722d-4ddd-ba71-0ff276816878.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs34801ac9-9cd2-49bd-91db-966b680fea26.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8340ec61-7408-4cd0-bff3-f6c4bc8b9bc8.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbef880dc-370f-4b3e-ab7e-478cb559e7da.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs240ab380-eb3f-4b9e-b05f-3bf74a841487.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse9368850-c1af-46b8-bc05-b828f0621f3c.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7a4535e4-0a35-436e-9269-fa0c938c2f56.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7d11e985-dcaa-4c74-8fd7-12929dd5111c.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8863ebd0-bd31-45d2-80a1-fb78b9427c3c.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs434fa011-b5de-46c8-a349-24791d01281e.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsfbae3c85-6a94-4a0a-acd6-778618d57489.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs57b0252c-f4b3-4f56-86f5-c3cd999830d8.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc2a0bf2f-440e-474c-9aef-f855984278d4.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4bcdf712-3bb1-40a0-a383-60a44f9ee5d6.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsec8f3d08-ba5c-443d-923b-ec4acaf43bce.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs52df38c4-c889-4c83-979e-8ac7a02d672c.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse53b4778-562a-4560-9e1c-ce4d10ed7abe.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb5262742-c3e2-4615-ad19-f24b2747353b.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc7b83d8f-8a62-45ba-9afe-424ce6cc84ed.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc94cb454-9172-4a8d-89d3-a20953e8970c.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs9c4861ab-6e1c-44ac-9cd0-c818fa65a059.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa02412c7-48ae-4130-a8f9-4ead48f61b8a.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscba0829e-e756-4b82-b37d-31bb05983713.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0edce252-ce38-436e-8eb8-2569bcecc795.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs58ffa706-a6b3-4821-a412-6db17b661802.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs714329e1-d917-4cd7-afc4-affa8c9e3758.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsdda83574-6457-4272-a3d3-56397121868c.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf216ccfd-f5f2-4375-9152-701881dbcf2f.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8d62cc66-df76-4911-adc6-6ae2143a3fbd.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3e4dc44b-8e36-4ae7-891f-ead750a0b9d9.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6669a775-f98c-4b2f-ac73-5dd80ca57ef8.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd8709bec-e3c6-4069-b825-11ac55a1bd1d.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb80c3b65-6632-4e22-b5f5-3a59760b381f.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs45e7e55b-c746-479e-86b2-09536fc926e0.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs758ab560-e5c5-48e2-bd06-2f207f0fc9c5.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsee049f3e-242e-441a-a1f1-691d3945c21d.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs739c4525-e3f2-48cc-8fd6-6efc1125b184.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsca6080c9-a13d-4d7e-9e3b-8b3310b48102.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse522a7ec-538c-4ec5-b5c1-fa0acce4be4b.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs22ae1860-ff0a-48e0-a7cb-cd960d2c6a9a.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4945b4f2-9f3c-40d9-8de5-318169428b92.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5011d1f3-e2f2-494f-8aae-e6493376aa3e.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd4492828-eaf1-4a65-a41b-104c659819ea.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs05de59b1-c7af-4c4f-a343-24f696619486.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd0b72bda-32fc-40ef-8347-d2b83c566ce5.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs693fe220-bd22-464a-8798-58a88b4e865b.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs37494dfa-2bc0-406e-a153-f83140b0e9e7.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs52c2a4ce-081d-4b09-b60d-e2631527a7e2.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsab192e2c-3169-4a8b-af9a-be94e1dba475.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsefaa92e0-6b56-4b0c-94c5-f2ada3597454.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs9619d234-d6ac-41a5-be0e-575b94c1ca32.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7d0f19e0-13ee-4949-8e6b-8e5c72d86b55.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2e6452fc-828e-48a2-a6db-997e19d09cfd.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa49be7c5-7679-4488-b173-2f30b2477d46.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs9256bdab-58b9-4519-88c2-58f539e98491.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsca4ca35a-b5ab-4d4e-b59e-691524a04c03.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbb2db138-727c-4123-b0d1-890b03de5ec6.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf47121e8-58fe-451a-8882-0c9f49481f3b.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6c2c1006-3459-4d3a-ac19-90ed09d75931.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8cca6532-83de-4181-affb-f1998fe1b0c3.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3e381d1d-65e8-4b79-b322-7040c95bfd17.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2d9c3a8f-d56a-4fd5-b6b4-c1641d843fd9.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf301ad84-44a2-4d40-ba7c-134b89dfd2bd.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsfa14e5f2-3958-497d-8e46-99aa6ad3dfa7.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscseed2f20b-2c11-49aa-bf05-ac7f25ded951.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb7d7c288-acb4-498c-94e0-f514569427fd.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa9cd61aa-23fe-43ea-bcab-d3d397b1cf84.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0f817d21-64ab-4f43-9faf-f990698587d8.tmp". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\brian caimi\ntuser.dat". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\brian caimi\ntuser.dat.log". The process cannot access the file because it is being used by another process
2:44 AM: Warning: Failed to open file "c:\documents and settings\brian caimi\local settings\temp\perflib_perfdata_7b0.dat". The process cannot access the file because it is being used by another process
2:47 AM: Warning: Failed to open file "c:\documents and settings\brian caimi\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
2:47 AM: Warning: Failed to open file "c:\documents and settings\brian caimi\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
2:48 AM: Found Adware: coolwebsearch (cws)
2:48 AM: c:\documents and settings\brian caimi\application data\winshow (2 subtraces) (ID = -2147481200)
2:48 AM: winshow.cfg (ID = 54621)
2:53 AM: File Sweep Complete, Elapsed Time: 01:10:35
2:53 AM: Full Sweep has completed. Elapsed time 01:31:30
2:53 AM: Traces Found: 65
7:43 AM: Removal process initiated
7:43 AM: Quarantining All Traces: purityscan
7:43 AM: Quarantining All Traces: wildmedia
7:44 AM: Quarantining All Traces: coolwebsearch (cws)
7:44 AM: Quarantining All Traces: elitemediagroup-mediamotor
7:44 AM: Quarantining All Traces: internetoptimizer
7:44 AM: Quarantining All Traces: drsnsrch.com hijack
7:44 AM: Quarantining All Traces: exact cashback/bargain buddy
7:44 AM: Quarantining All Traces: ipinsight
7:44 AM: Quarantining All Traces: searchv hijack
7:44 AM: Quarantining All Traces: syncroad
7:44 AM: Quarantining All Traces: wild media - minigolf
7:44 AM: Quarantining All Traces: a cookie
7:44 AM: Quarantining All Traces: adknowledge cookie
7:44 AM: Quarantining All Traces: atwola cookie
7:44 AM: Quarantining All Traces: burstnet cookie
7:44 AM: Quarantining All Traces: go.com cookie
7:44 AM: Quarantining All Traces: offeroptimizer cookie
7:44 AM: Quarantining All Traces: rightmedia cookie
7:44 AM: Quarantining All Traces: shopnav cookie
7:44 AM: Quarantining All Traces: specificclick.com cookie
7:44 AM: Quarantining All Traces: tacoda cookie
7:44 AM: Quarantining All Traces: yieldmanager cookie
7:46 AM: Removal process completed. Elapsed time 00:02:26
Are you running Norton's and McAfee anti-virus at the same time?
That can cause lockup's and conflicts.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
Viewpoint Manager



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O2 - BHO: jimmyhelp.CBrowserHelper - {EA8E2DCA-A30A-4F28-BB2D-51B76440C5D0} - C:\WINDOWS\htduolq.dll

O2 - BHO: jimmyhelp.CBrowserHelper - {FD1A0C37-701E-45EE-AAF0-AE1B8EB66BC0} - C:\WINDOWS\axqjnl.dll (file missing)

O4 - HKLM\..\Run: [dxcps] C:\WINDOWS\fuet.exe

O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O9 - Extra button: Enjoy It - {47055D63-DFCD-11d3-8406-00500445A7D1} - C:\WINDOWS\system32\windialup\3037[1]\windialup.exe (file missing)

O9 - Extra 'Tools' menuitem: Enjoy It - {47055D63-DFCD-11d3-8406-00500445A7D1} - C:\WINDOWS\system32\windialup\3037[1]\windialup.exe (file missing)


Close ALL windows and browsers except HijackThis and click "Fix checked"


Delete this Folder if listed:
C:\WINDOWS\system32\windialup


Delete this File if listed:
C:\WINDOWS\fuet.exe




Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Thank you. This appears to have worked. I have been able to download files without being redirected to errorplace.com.
How do I check if I have both Norton and McAfee running at the same time? Sorry if this is obvious, but I can't seem to be able to determine if I am.

You have been awesome!!!! I can't tell you how much I appreciate your help.

Here is thie HJT log. Please let me know if there are any additional files to delete. Thanks again. BrianSTL

Logfile of HijackThis v1.99.1
Scan saved at 12:55:58 PM, on 3/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NavNT\vptray.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\NavNT\defwatch.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MICROS~3\Office\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://charter.msn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\BRIANC~1\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Hpas] C:\Documents and Settings\Brian Caimi\Application Data\tabu.exe
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\RunOnce: [DelayShred] "C:\Program Files\McAfee\McAfee Shared Components\Shredder 5\SHRED32.EXE" /q C:\DOCUME~1\BRIANC~1\LOCALS~1\TEMPOR~1\Content.SH!
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.stevengould.org
O15 - Trusted Zone: *.stevengould.org
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,7…pdatePortal.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Look in Add/Remove Programs and I'd remove Norton's / Symantec anti-virus if listed.

Good Job :thumbup:

Log looks good :D

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.





If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI