This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT log

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:o

Ok…thought I had a different problem and started out in another area. BUT they told me I must still be infected and to come here and post a HJT log.

So here it is:

Logfile of HijackThis v1.97.7
Scan saved at 12:17:55 PM, on 3/24/06
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\CONSUMER INPUT\CONSUMERINPUT.EXE
C:\PROGRAM FILES\CONSUMER INPUT\CONSUMERINPUTUA.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\PROMPTCAST\PROMPTCAST.EXE
C:\PROGRAM FILES\WALGREENS\WALGREENS PHOTOSHOW\DATA\XTRAS\MSSYSMGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hp.msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F0 - system.ini: Shell=explorer.exe ibm00001.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe C:\PROGRA~1\WILDTA~1\APPS\CDA\CDAENG~1.DLL,cdaEngineMain
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Consumer Input] C:\Program Files\Consumer Input\ConsumerInput.exe
O4 - HKLM\..\Run: [Consumer Input Update] C:\Program Files\Consumer Input\ConsumerInputUa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [remoteuploadsoapsafe] C:\WINDOWS\Application Data\Bold name remote upload\Elsethat.exe
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [mmxp2passion.exe] C:\WINDOWS\SYSTEM\mmxp2passion.exe
O4 - HKLM\..\Run: [mcspy.exe] C:\WINDOWS\SYSTEM\mcspy.exe
O4 - HKLM\..\Run: [loadadv64] C:\WINDOWS\SYSTEM\loadadv64
O4 - HKLM\..\Run: [drsmartload482a.exe] C:\WINDOWS\SYSTEM\drsmartload482a.exe
O4 - HKLM\..\Run: [loader.exe] C:\WINDOWS\SYSTEM\loader.exe
O4 - HKLM\..\Run: [{10-04-40-06-ZN}] C:\WINDOWS\SYSTEM\DWDSREGT.EXE CORN001
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [keyboard] C:\\KEYBOARD1.exe
O4 - HKLM\..\Run: [mousepad] C:\\MOUSEPAD1.exe
O4 - HKLM\..\Run: [gimmysmileys] C:\\GIMMYSMILEYS1.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NPFMonitor] C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ALU Scheduler Service] C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O4 - HKCU\..\Run: [PromptCast] C:\Program Files\PromptCast\PromptCast.exe
O4 - HKCU\..\Run: [mix camp] C:\WINDOWS\APPLIC~1\DENTUS~1\barbrectway.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\DATA\XTRAS\MSSYSMGR.EXE
O4 - Startup: Z_Start.lnk = C:\WINDOWS\SYSTEM\qjdsregq.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\SYSTEM\nwinkrag.exe
O9 - Extra button: AIM (HKLM)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Dell Home (HKCU)
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedCon…n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon…bin/AvSniff.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://netscape.musicnotes.com/download/mnviewer.cab
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (WebProgramManager Class) - http://isupport4.hp.com/awebui/jsp/answerw…SWebManager.CAB
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…7872.4213310185
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc3.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: Pop Fu by pogo - http://popfu.pogo.com/applet-6.0.4.37/popf…u-ob-assets.cab
O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.4.0.41/supe…o-ob-assets.cab
O16 - DPF: {93EFDAB8-8800-4896-B428-76F943140E1B} - http://www.consumerinput.com/panel/quince/dcainst.cab
O16 - DPF: Squelchies by pogo - http://squelchies.pogo.com/applet-6.0.4.37…s-ob-assets.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/UnSkin/gf.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.com/applet-6.2.1.34/popp…2-ob-assets.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.4.3.28/mahj…g-ob-assets.cab
O16 - DPF: {77DD44BF-551D-4E3C-82CD-D637D5018D3C} - http://www.surveys.com/promptcast/Installs…AST%20SETUP.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.com/applet-6.4.0.34/peng…s-ob-assets.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.4.2.30/popp…a-ob-assets.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/luxr/default/mjolauncher.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = covad.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = covad.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 64.105.113.138,64.105.97.90


Thanks!!
Welcome to the forum.

Nice collection of malware you have - this is going to take several steps so please be patient!

You are using an old version of HJT, could you please delete it and rescan the system with the new version and post that log next time.
When you do, please download HJT into its own folder so backups can be made.

example: C:\MyHJT\HJT.exe, C:\Program Files\MYHJT\HJT.exe or C:\MyDocuments\MyHJT\HJT.exe

http://tools.radiosplace.com/HijackThis.exe <–new version HJT!!!!!!!!

——————————-

Go to your control panels add/remove programs and uninstall NewDot.net - the link below will help - use their uninstaller if necessary (it's safe)

http://www.newdotnet.com./removal.html

——————

Download and unzip the KillBox to a folder - we'll use it later.

————————

Download Free Trial of Spysweeper
http://www.webroot.com/consumer/downloads/
Install it, update definitons. Please don't run it yet.

——————-

Close ALL programs down, leaving ONLY HijackThis running - Click Scan and…..
Place a check against the following items:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F0 - system.ini: Shell=explorer.exe ibm00001.exe
O4 - HKLM\..\Run: [mmxp2passion.exe] C:\WINDOWS\SYSTEM\mmxp2passion.exe
O4 - HKLM\..\Run: [loader.exe] C:\WINDOWS\SYSTEM\loader.exe
O4 - HKLM\..\Run: [{10-04-40-06-ZN}] C:\WINDOWS\SYSTEM\DWDSREGT.EXE CORN001
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [mousepad] C:\\MOUSEPAD1.exe
O4 - HKLM\..\Run: [gimmysmileys] C:\\GIMMYSMILEYS1.exe
O4 - HKLM\..\Run: [remoteuploadsoapsafe] C:\WINDOWS\Application Data\Bold name remote upload\Elsethat.exe
O4 - HKLM\..\Run: [mcspy.exe] C:\WINDOWS\SYSTEM\mcspy.exe
O4 - HKLM\..\Run: [loadadv64] C:\WINDOWS\SYSTEM\loadadv64
O4 - HKLM\..\Run: [drsmartload482a.exe] C:\WINDOWS\SYSTEM\drsmartload482a.exe
O4 - HKLM\..\Run: [keyboard] C:\\KEYBOARD1.exe
O4 - HKCU\..\Run: [mix camp] C:\WINDOWS\APPLIC~1\DENTUS~1\barbrectway.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\SYSTEM\qjdsregq.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\SYSTEM\nwinkrag.exe

Click on Fix Checked and exit HijackThis.

Now open up the KillBox and copy and paste each one of these in and hit delete, if the file exists, it will appear in blue under the window, if not move on to the next file.

c:\secure32.html
C:\WINDOWS\SYSTEM\mmxp2passion.exe
C:\WINDOWS\SYSTEM\loader.exe
C:\WINDOWS\SYSTEM\DWDSREGT.EXE
C:\\MOUSEPAD1.exe
C:\\GIMMYSMILEYS1.exe
C:\WINDOWS\Application Data\Bold name remote upload\Elsethat.exe
C:\WINDOWS\SYSTEM\mcspy.exe
C:\WINDOWS\SYSTEM\loadadv64
C:\WINDOWS\SYSTEM\drsmartload482a.exe
C:\\KEYBOARD1.exe
C:\WINDOWS\APPLIC~1\DENTUS~1\barbrectway.exe
C:\WINDOWS\SYSTEM\qjdsregq.exe
C:\WINDOWS\SYSTEM\nwinkrag.exe

——————–

Run Spysweeper:
Click on "Options > Sweep Options" and check "Sweep all Folders on Selected drives". Check "Local Disc C".
Under What to Sweep: check all of the boxes except Sweep Contents of Compressed Files and do not Sweep Systemrestore Folder.

Click on Sweep and allow it to fully scan your system.

When the sweep has finished, click "Remove". Click "Select All" and then "Next".

Spy Sweeper initially quarantines the spyware it finds on your computer. DO NOT remove items from Quarantine, until after you verify your system still functions properly once spyware has been quarantined. After reboot ensure important programs still work before you remove any items from Quarantine.
From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

Exit Spy Sweeper.

——————————-

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

Reboot and post a fresh HijackThis log (make sure you use the new version please), the SpySweeper log and we'll take another look. MrC
:P

Thank you so much for your time!

First off, I did everything you instructed me to BUT the free trial of the spysweeper will run the scan but not quarantine any of it. Once you hit "Remove", everything was already selected but it would do no more from that point without my $30 payment and I do not have those funds available. I did however, make a list on a word document hoping it may aide in the removal of these boogers. Hopefully it will give a hint towards what to look for.

I also noticed that before I performed your steps I would get error messages when I tried to shut down my computer through start and several while it was coming back up. Every time I would go to shut down or restart my computer before I would get an error message stating Lucallbackproxy had performed an illegal operation and would shut down. I did not notice this come up after performing your steps. Also, before your steps I had error messages saying IPHLPAPI.DLL cannot start, ibm00001.exe cannot find, and at the bottom of the screen a box would come up stating it was searching for qjdsregq.exe and also for nwinkrag.exe.

NOW after performing your steps, the only message that continues to come up is the imb00001.exe cannot find. So, whatever you had me do must have fixed the other problems as well..Thanks! I've been looking at those boxes for some time now!

Thank you again for all your help!

This is copied from my word document stating what the spysweeper found:

Izio
Spysheriff fakealert
Trojan downloader matcash
Win-spy monitor
Crackserver
Dollarrevenue
Elitemediagroup-mediamotor
Enbrowser
Surfsidekick
Bingofun games
Bullguard popup ad
Effective-I toolbar
Findthewebsiteyouneed hijack
Seekmo search assistant
Zenosearchassistant
27.net cookie
addynamix cookie
adecn cookie
adprofile cookie
adrevolver cookie
adserver cookie
advertising cookie
ask cookie
atlas dmt cookie
atwola cookie
azjmp cookie
bizrate cookie
bluestreak cookie
burstbeacon cookie
casalemedia cookie
clickbank cookie
dealtime cookie
directtrack cookie
falkag cookie
fastclick cookie
hypertracker.com cookie
mediaplex cookie
nextag cookie
on-time-offer cookie
pch cookie
questionmarket cookie
realmedia cookie
ru4 cookie
specificclick.com cookie
stamps.com cookie
tacoda cookie
trafficmp cookie
tribalfusion cookie
valuead cookie
web-stat cookie
webtrendslive cookie
yieldmanager cookie
zedo cookie



Here is my new HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 12:11:19 PM, on 4/7/06
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\CONSUMER INPUT\CONSUMERINPUT.EXE
C:\PROGRAM FILES\CONSUMER INPUT\CONSUMERINPUTUA.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\PROMPTCAST\PROMPTCAST.EXE
C:\PROGRAM FILES\WALGREENS\WALGREENS PHOTOSHOW\DATA\XTRAS\MSSYSMGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\WRSSSDK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\OPSCAN.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\LUCOMSERVER_3_0.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\LUCALLBACKPROXY.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\LUCALLBACKPROXY.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\LUCALLBACKPROXY.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\MY HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://msn.com/
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe C:\PROGRA~1\WILDTA~1\APPS\CDA\CDAENG~1.DLL,cdaEngineMain
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Consumer Input] C:\Program Files\Consumer Input\ConsumerInput.exe
O4 - HKLM\..\Run: [Consumer Input Update] C:\Program Files\Consumer Input\ConsumerInputUa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NPFMonitor] C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ALU Scheduler Service] C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O4 - HKCU\..\Run: [PromptCast] C:\Program Files\PromptCast\PromptCast.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\DATA\XTRAS\MSSYSMGR.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\INSTANT MESSENGER\AIM.EXE
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
O9 - Extra button: Dell Home - {B5439B40-2A98-11D5-B1BE-000103E071E2} - http://www.my.delleworks.com (file missing) (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedCon…n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon…bin/AvSniff.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://netscape.musicnotes.com/download/mnviewer.cab
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (WebProgramManager Class) - http://isupport4.hp.com/awebui/jsp/answerw…SWebManager.CAB
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: Pop Fu by pogo - http://popfu.pogo.com/applet-6.0.4.37/popf…u-ob-assets.cab
O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.4.0.41/supe…o-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://squelchies.pogo.com/applet-6.0.4.37…s-ob-assets.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/UnSkin/gf.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.com/applet-6.2.1.34/popp…2-ob-assets.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.4.3.28/mahj…g-ob-assets.cab
O16 - DPF: {77DD44BF-551D-4E3C-82CD-D637D5018D3C} - http://www.surveys.com/promptcast/Installs…AST%20SETUP.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.com/applet-6.4.0.34/peng…s-ob-assets.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.4.2.30/popp…a-ob-assets.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/luxr/default/mjolauncher.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = covad.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = covad.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 64.105.113.138,64.105.97.90



Thanks once again for all your help!
SpySweeper shouldn't have done that.
Take a look at This Recent Post and you'll see how it works.

Lets do this for now (these are all free)……..

Even if you have these programs on your system, pleaese UPDATE and run them.
Let me know of anything that can't be cleaned.

To start the clean-up process:

Download and run CW-Shredder - Hit the FIX button and let it run and fix what it finds.

<==><==><==><==><==><==><==><==><==><==><==><==><==><==><==><==>
Next…..

Download and run SpyBot

Install the program and launch it.

Go to Start > Programs >Spybot > Search & Destroy and choose Spybot S&D

Close ALL windows except Spybot S&D
Click the button to "Search for Updates" and download and install the Updates.
Next click the button "Check for Problems"
When Spybot is complete, it will be showing "RED" entries "BLACK" entries and "GREEN" (GREEN) entries in the window
Put a check mark beside the RED entries ONLY.
Choose "Fix Selected Problems" and allow Spybot to fix the RED entries.
Reboot……….

<==><==><==><==><==><==><==><==><==><==><==><==><==><==><==><==>


Next…

Download and run AD-Aware

Install the program and launch it.

1. Launch Ad-Aware SE and run the WebUpdate feature. (Click on the Globe icon > Click connect > Click OK > Click Finish.)
2. Set up the Configurations as follows:
– Click the Gear wheel at the top of the Ad-Aware window
– Click General > Safety & Settings: Check (Green) all three.
– Click Tweak > Cleaning Engine > UNcheck "Always try to unload modules before deletion".
3. Click "Proceed"
4. Click "Scan Now"
5. Deselect "Search for negligible risk entries" as negligible risk entries (MRU's) are not considered to be a threat.
6. Select "Search for low-risk threats"
7. Run the scanner using the Full Scan (Perform full system scan) mode.
8. When the scan has completed, select Next.
9. In the Scanning Results window, select the "Scan Summary" tab.
10. Check the box next to each "target family" you wish to remove.
11. Click next > Click OK.

Reboot….

<==><==><==><==><==><==><==><==><==><==><==><==><==><==><==><==>

See if you can run SpySweeper again - if not…..

Please do an online scan with Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.

The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make that the following are selected:

Scan using the following Anti-Virus database:
  • Extended (If available otherwise Standard)
Scan Options:
  • Scan Archives
  • Scan Mail Bases
Click OK

Now under select a target to scan select My Computer

The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.
Copy and paste that information in your next post.

Reboot and post a fresh HijackThis log and we'll take another look. MrC
:blink:

Alllllriiiiighty then…..

I uninstalled the version of Spy Sweeper and looked for a trial version download and that seemed to be my problem there.

CWShredder did not find anything.

Spybot S&D; did not find anything.

Ad-Aware was completed and items were quarantined.

I re-ran Spy Sweeper (the new download). During the step where I was to remove all, something went wrong and the S.S. asked I send them an error report, which I did so they would have any details. Here is my S. S. log:

********
10:20 AM: | Start of Session, Tuesday, April 11, 2006 |
10:20 AM: Spy Sweeper started
10:20 AM: Sweep initiated using definitions version 654
10:20 AM: Starting Memory Sweep
10:25 AM: Memory Sweep Complete, Elapsed Time: 00:05:07
10:25 AM: Starting Registry Sweep
10:25 AM: Found Adware: bingofun games
10:25 AM: HKCR\clsid\{aaa8135f-d41a-4e85-a40f-58e6be393e6f}\ (2 subtraces) (ID = 104416)
10:25 AM: HKLM\software\classes\clsid\{aaa8135f-d41a-4e85-a40f-58e6be393e6f}\ (2 subtraces) (ID = 104417)
10:26 AM: Found Adware: surfsidekick
10:26 AM: HKLM\software\surfsidekick3\ (2 subtraces) (ID = 143413)
10:26 AM: Found Adware: dollarrevenue
10:26 AM: HKLM\software\policies\ || {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} (ID = 916803)
10:26 AM: HKLM\software\policies\ || {6bf52a52-394a-11d3-b153-00c04f79faa6} (ID = 967836)
10:26 AM: HKLM\software\policies\ || {645ff040-5081-101b-9f08-00aa002f954e} (ID = 1036890)
10:26 AM: Found Adware: seekmo search assistant
10:26 AM: HKU\.DEFAULT\software\microsoft\cryptography\userkeys\one8tsolutionscont@in3rn@me\ (4 subtraces) (ID = 782153)
10:26 AM: Registry Sweep Complete, Elapsed Time:00:01:23
10:26 AM: Starting Cookie Sweep
10:26 AM: Found Spy Cookie: 2o7.net cookie
10:26 AM: default@microsofteup.112.2o7[1].txt (ID = 1958)
10:26 AM: default@msnportal.112.2o7[1].txt (ID = 1958)
10:26 AM: Found Spy Cookie: atwola cookie
10:26 AM: default@atwola[1].txt (ID = 2255)
10:26 AM: default@bookspan.122.2o7[1].txt (ID = 1958)
10:26 AM: Found Spy Cookie: pch cookie
10:26 AM: [removed][1].txt (ID = 3124)
10:26 AM: Found Spy Cookie: ask cookie
10:26 AM: default@ask[1].txt (ID = 2245)
10:26 AM: Found Spy Cookie: yieldmanager cookie
10:26 AM: [removed][1].txt (ID = 3751)
10:26 AM: Found Spy Cookie: directtrack cookie
10:26 AM: [removed][2].txt (ID = 2528)
10:26 AM: default@stubhub.122.2o7[1].txt (ID = 1958)
10:26 AM: Found Spy Cookie: stamps.com cookie
10:26 AM: [removed][1].txt (ID = 3438)
10:26 AM: Found Spy Cookie: burstbeacon cookie
10:26 AM: [removed][1].txt (ID = 2335)
10:26 AM: [removed][2].txt (ID = 2528)
10:26 AM: Found Spy Cookie: dealtime cookie
10:26 AM: [removed][2].txt (ID = 2506)
10:26 AM: Found Spy Cookie: specificclick.com cookie
10:26 AM: [removed][2].txt (ID = 3400)
10:26 AM: Found Spy Cookie: columbiahouse cookie
10:26 AM: default@columbiahouse[2].txt (ID = 2443)
10:26 AM: default@ford.112.2o7[1].txt (ID = 1958)
10:26 AM: [removed][3].txt (ID = 3751)
10:26 AM: default@redcats.122.2o7[1].txt (ID = 1958)
10:26 AM: default@columbiahouse[1].txt (ID = 2443)
10:26 AM: [removed][3].txt (ID = 2528)
10:26 AM: Found Spy Cookie: gostats cookie
10:26 AM: [removed][2].txt (ID = 2748)
10:26 AM: [removed][1].txt (ID = 3400)
10:26 AM: Found Spy Cookie: tacoda cookie
10:26 AM: default@tacoda[1].txt (ID = 6444)
10:26 AM: Found Spy Cookie: adknowledge cookie
10:26 AM: default@adknowledge[2].txt (ID = 2072)
10:26 AM: [removed][2].txt (ID = 2335)
10:26 AM: default@dealtime[1].txt (ID = 2505)
10:26 AM: Found Spy Cookie: adecn cookie
10:26 AM: default@adecn[2].txt (ID = 2063)
10:26 AM: Found Spy Cookie: overture cookie
10:26 AM: [removed][1].txt (ID = 3106)
10:26 AM: Found Spy Cookie: about cookie
10:26 AM: [removed][2].txt (ID = 2038)
10:26 AM: Found Spy Cookie: adlegend cookie
10:26 AM: default@adlegend[1].txt (ID = 2074)
10:26 AM: default@about[1].txt (ID = 2037)
10:26 AM: [removed][1].txt (ID = 2506)
10:26 AM: [removed][1].txt (ID = 2506)
10:26 AM: [removed][2].txt (ID = 3751)
10:26 AM: Cookie Sweep Complete, Elapsed Time: 00:00:05
10:26 AM: Starting File Sweep
10:26 AM: Found Trojan Horse: lzio
10:26 AM: real.exe (ID = 254866)
10:26 AM: Found Trojan Horse: trojan downloader matcash
10:26 AM: new_pop.exe (ID = 252852)
10:27 AM: Warning: Failed to open file "c:\windows\win386.swp". The process cannot access the file because
it is being used by another process
10:27 AM: Found Adware: enbrowser
10:27 AM: checks02.exe (ID = 251279)
10:34 AM: Found Adware: zenosearchassistant
10:34 AM: msnav32.ax (ID = 220229)
10:34 AM: pre2.exe (ID = 250773)
10:34 AM: setup95.exe (ID = 251313)
10:39 AM: Found Adware: effective-i toolbar
10:39 AM: glb71b4.tmp (ID = 253666)
10:39 AM: explorer.exe (ID = 247512)
10:39 AM: Found Adware: elitemediagroup-mediamotor
10:39 AM: mcspy.exe (ID = 251295)
10:39 AM: glb8100.tmp (ID = 253666)
10:39 AM: Found Adware: bullguard popup ad
10:39 AM: c:\windows\temp\bullguard (1 subtraces) (ID = -2147476409)
10:39 AM: bulldownload.exe (ID = 52017)
10:41 AM: Found System Monitor: win-spy monitor
10:41 AM: c:\windows\dll (1 subtraces) (ID = -2147480025)
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs0cecde79-3612-44f1-b14b-71daed4320aa.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscscfc5dfc9-43f2-49b7-9939-1ed9975e0491.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs838b16fb-479c-41ee-9f6a-390d242181cb.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsd4e865b5-d00d-4646-82c4-cc5b520dbfbe.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs7d1f3afb-aefb-47fa-ac14-f4a890509d1b.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs0297b563-3fb5-4c9d-a22e-9c542a42e534.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsc07a8b77-6005-4144-adab-bba5374d6d4a.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscscb27eafa-9cd0-4ca4-92f6-de40b47eb331.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs768cbcab-af93-4c04-aafd-509500ead6b1.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsa2c5b059-3115-49d5-8440-9aee5acdeb0d.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscscc987c51-cf3b-4a9f-96e1-443070b04fc4.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs97159dea-5c05-44e0-9706-2cc45d8d6857.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsd7c28354-97d0-4d93-bf1b-994cfb7f9db9.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs4a953a58-d536-4787-8bbc-891fdd55f590.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsdc753eb1-4cd9-4f8f-833f-e7431ae84eb4.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsb179aaa4-209b-452d-9816-ded91dce391e.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscse3d3f108-ad84-4d42-b7e5-9795c1a8a497.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsf0f11049-2130-433d-8cf0-36bc799581f6.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs7a0b7d71-72a0-40b6-9d70-687ce6ed57a0.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsf4194589-4d58-4866-9aa9-594b408918d5.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs7c9d8bbb-3258-4fae-850e-a001d13886fe.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsea94f3f5-043d-47b3-92be-d6783acec7cf.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs998260a7-749b-4f10-a2d9-f7e0c513a5fb.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs1c8678d5-9663-4655-a0c5-80ca52ae0621.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsfe27b179-6345-4ec8-bfb4-220914ef90e2.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsa8e20721-ea45-4d1e-8ee5-be1befe67fb8.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsa3c3d32b-0029-40e2-bc8d-5c6b96dac054.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsa7f55d62-2755-4242-bdba-a0b59879c128.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs3fdf7702-e80a-4cf0-a068-ecefed492a0a.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs8d97bf40-c66c-431f-baab-31f6f3b99e5d.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs1695eb8b-9d1c-4bb1-b53f-22ecff3a0004.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsb601016d-1d5d-4e33-a18a-413898533e5e.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs708ccd5c-138e-404f-84d8-be2c6d01a91b.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs7bcf6681-d1e0-4a3e-a3bb-ca39239440d1.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs3c0f14b3-6d4d-4d32-b88b-cc66209129bd.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs76e17a96-3071-42e6-9fb7-80e244581627.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs5289fd33-2c3c-4faf-bde2-93205188fdc0.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs20baa46f-60c3-42a2-90a3-0346dedfb912.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsc7aa2d35-ccd0-49a9-91a6-e589e5bb55d9.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs212dea77-c7ed-4fb4-a000-13be20802306.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs7ccabc8b-9761-44e8-91ff-32e991384597.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs9f63a66f-cbaf-4424-86c2-bf4ac153493e.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs636cc465-4dd0-48b2-ba39-8ba29c2e0c11.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs57f320ce-8f43-4396-9773-6fa7ef578521.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsa93bbd28-434b-47cd-986a-df6ba9e4e9cd.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsba89781b-efad-452b-8add-85e407e5273c.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsa93020f8-0a13-4ab2-8481-83b07d1e0791.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscse8cf3587-b9ad-4dae-a427-d1b8827a571a.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs54c89d73-3daf-4eb9-99a6-cf5e0dc49dc9.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsdd4c5082-938b-4a1f-b9c1-7d98c5653345.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs9faa156a-a36e-4935-9132-76f43f71bc40.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs109b7864-ac0c-413f-abdc-73a557cadc08.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsb227480d-7d95-4aab-bba6-2cce233db956.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs11dac356-45fd-40f4-8129-c0293f3b53b4.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsf8c5603b-11f2-453e-b6b4-6991dda6370d.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscseaa6c083-5a60-4de9-9dc9-7893f838a6ad.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsbd16693f-fa28-4877-b8fa-e5a0203f95ab.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs1d61e64a-8559-44a1-ae61-7a87a64e71a1.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs8e8c4f39-f471-41c5-9ed4-3de174b6470f.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsafcc1a82-ea8f-4594-9cfd-863eb537fdb2.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs13411ad6-30df-4c9f-a8fc-4b20abc8dffc.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs62aab689-d1ea-43d2-90fb-585355d93362.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs54df6c24-e88b-4575-bbaf-b00f462f2cb3.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs9ba58ca5-56ab-465e-a120-1dcd22277ebf.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs1fd4ae68-8493-4796-a072-ce849161b411.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs228ade19-3b1f-496f-b383-521826c04007.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs99330af3-a6d2-41b7-b521-0dae72839d19.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsf4397985-c4c2-436e-a76e-21068eb30d18.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsddfab516-4273-4ebf-bccd-6ff9eca2ff87.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscscbd6e8af-0b3c-4647-b616-1ca689f2192a.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsf73e5e7e-c32f-49a5-8bfc-e0dfe15c532b.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs09a6326b-b609-48a7-99e5-3f2268c43062.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs4ca72363-af89-46db-a7f0-d36449e9a517.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs54d0ba35-5013-49dd-b49d-bd9ebdc422ea.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs8fb7691c-d73c-4da1-ab46-d438a1fdab44.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs748706c1-a43c-4058-a3de-df0ada907b2e.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs1352a518-50ac-4928-ab1c-b81b3a21e585.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscscb8a0a09-cf29-4b78-a4e1-73113739a064.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsa4311b8a-ab12-4ddc-964b-d27c789dfa85.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscscd44144b-695f-4746-82fd-650924a048d7.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsa5a3e260-4e01-4ad9-a913-d881f79e4c16.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs67d033da-df38-4297-9648-89bda262958f.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsbaf56673-f33b-480d-b32c-fda7718ee4e0.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs55358dc3-bb0e-4576-b6e9-3c51dd48a2f6.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscse8ee0178-9ce9-4d58-a1e2-76fe783efd88.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsd210c1ce-5946-453a-828f-a7bef6b85437.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs19beb71b-7165-4b96-9e03-fd0a6355445b.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs7bf2bd20-a56b-4baa-bf08-f1043fbb0a51.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs5743c6f8-5864-43a0-bf10-789ccce04a88.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsf688c1e8-c818-4066-b65a-effb67bd1bd0.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs8ccc206c-3f4c-4705-af2b-bd7958c14517.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs08feefc4-ccb4-4ed3-95fe-d4344c4dc90b.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsba8c36d3-d84e-4157-bc9c-3992d3ff7209.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscscdb74ba0-6160-4f0f-ac12-5c016ed6dcb2.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs6d0c21c2-3d7e-44bf-ad40-b224506fb4ac.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69183b46-65c5-4718-9e1c-65704111e450.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs4b7b3aa0-8613-4abc-b714-010ef4621329.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs49a3d7a2-7485-4d61-aebf-e1fad633f554.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs8857ece6-ceb5-45d4-ad47-9e09b5231afb.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs46e4c73b-2d17-49e4-a342-31ac80287803.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs42603c22-2820-47fd-b4b2-14728be96b7d.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsd58e8d0b-5568-42ff-86b6-4887b1dae4b0.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs08a3ea2d-cf90-4b30-b097-9c48253fe5b2.tmp". The process cannot access the file because
it is being used by another process
10:42 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs37bd5029-0f6e-4925-9744-775c7a57ecf7.tmp". The process cannot access the file because
it is being used by another process
10:43 AM: Warning: Failed to open file "c:\windows\temporary internet files\content.ie5\s5n2vq5e\product_jump[___-". The system cannot find the file specified
10:47 AM: Warning: Failed to open file "c:\windows\temporary internet files\content.ie5\sta7ktub\default[3].ht________". The system cannot find the file specified
10:51 AM: Warning: Failed to open file "c:\windows\temporary internet files\content.ie5\eb4bjwpg\0000050851_000000000000000________-___". The system cannot find the file specified
11:10 AM: Warning: Failed to open file "c:\program files\common files\symantec shared\virusdefs\lulock.dat". The process cannot access the file because
it is being used by another process
11:10 AM: Warning: Failed to open file "c:\program files\common files\symantec shared\ccpd-lc\symlcrst.dll". The process cannot access the file because
it is being used by another process
11:11 AM: Warning: Failed to open file "c:\program files\common files\symantec shared\symcdata\ids-diskless\lulock.dat". The process cannot access the file because
it is being used by another process
11:11 AM: c:\program files\common files\vcclient (6 subtraces) (ID = -2147461290)
11:11 AM: biuninst.exe (ID = 51257)
11:11 AM: clientupdater.bat (ID = 212353)
11:11 AM: vcclient.exe.config (ID = 212358)
11:11 AM: vcupdate.exe.config (ID = 212361)
11:20 AM: Found Adware: crackserver
11:20 AM: c:\program files\crackserver (ID = -2147467140)
11:21 AM: bigameres.dll (ID = 51182)
11:21 AM: bisysinfo.dll (ID = 51193)
11:21 AM: biuninst.exe (ID = 51257)
11:21 AM: bibingoclient.x32 (ID = 51180)
11:21 AM: c:\program files\thesearchaccelerator (ID = -2147481059)
11:23 AM: Found Adware: spysheriff fakealert
11:23 AM: secure32.html (ID = 184319)
11:23 AM: Warning: Invalid Stream
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:23 AM: Warning: Unhandled Archive Type
11:24 AM: Warning: Invalid Stream
11:24 AM: Warning: Invalid Stream
11:24 AM: uninstall.lnk (ID = 51257)
11:24 AM: File Sweep Complete, Elapsed Time: 00:57:49
11:24 AM: Full Sweep has completed. Elapsed time 01:04:38
11:24 AM: Traces Found: 85
11:25 AM: Removal process initiated
11:25 AM: Quarantining All Traces: lzio
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine lzio
11:25 AM: Failed to quarantine real.exe
11:25 AM: Quarantining All Traces: spysheriff fakealert
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine spysheriff fakealert
11:25 AM: Failed to quarantine secure32.html
11:25 AM: Quarantining All Traces: trojan downloader matcash
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine trojan downloader matcash
11:25 AM: Failed to quarantine new_pop.exe
11:25 AM: Failed to quarantine explorer.exe
11:25 AM: Quarantining All Traces: win-spy monitor
11:25 AM: Error: Out of memory.
11:25 AM: Quarantining All Traces: crackserver
11:25 AM: Error: Out of memory.
11:25 AM: Quarantining All Traces: dollarrevenue
11:25 AM: Quarantining All Traces: elitemediagroup-mediamotor
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine elitemediagroup-mediamotor
11:25 AM: Failed to quarantine mcspy.exe
11:25 AM: Quarantining All Traces: enbrowser
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine enbrowser
11:25 AM: Failed to quarantine checks02.exe
11:25 AM: Failed to quarantine pre2.exe
11:25 AM: Failed to quarantine setup95.exe
11:25 AM: Quarantining All Traces: surfsidekick
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Error: Out of memory.
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine surfsidekick
11:25 AM: Failed to quarantine clientupdater.bat
11:25 AM: Failed to quarantine vcclient.exe.config
11:25 AM: Failed to quarantine vcupdate.exe.config
11:25 AM: Failed to quarantine HKLM: software\surfsidekick3\
11:25 AM: Quarantining All Traces: bingofun games
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine bingofun games
11:25 AM: Failed to quarantine biuninst.exe
11:25 AM: Failed to quarantine bigameres.dll
11:25 AM: Failed to quarantine bisysinfo.dll
11:25 AM: Failed to quarantine biuninst.exe
11:25 AM: Failed to quarantine bibingoclient.x32
11:25 AM: Failed to quarantine uninstall.lnk
11:25 AM: Failed to quarantine clsid\{aaa8135f-d41a-4e85-a40f-58e6be393e6f}\
11:25 AM: Failed to quarantine HKLM: software\classes\clsid\{aaa8135f-d41a-4e85-a40f-58e6be393e6f}\
11:25 AM: Quarantining All Traces: bullguard popup ad
11:25 AM: Warning: Out of memory
11:25 AM: Error: Out of memory.
11:25 AM: Failed to quarantine bullguard popup ad
11:25 AM: Failed to quarantine bulldownload.exe
11:25 AM: Quarantining All Traces: effective-i toolbar
11:25 AM: Error: Out of memory.
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine effective-i toolbar
11:25 AM: Failed to quarantine glb71b4.tmp
11:25 AM: Failed to quarantine glb8100.tmp
11:25 AM: Quarantining All Traces: seekmo search assistant
11:25 AM: Quarantining All Traces: zenosearchassistant
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine zenosearchassistant
11:25 AM: Failed to quarantine msnav32.ax
11:25 AM: Quarantining All Traces: 2o7.net cookie
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine 2o7.net cookie
11:25 AM: Failed to quarantine default@microsofteup.112.2o7[1].txt
11:25 AM: Failed to quarantine default@msnportal.112.2o7[1].txt
11:25 AM: Failed to quarantine default@bookspan.122.2o7[1].txt
11:25 AM: Failed to quarantine default@stubhub.122.2o7[1].txt
11:25 AM: Failed to quarantine default@ford.112.2o7[1].txt
11:25 AM: Failed to quarantine default@redcats.122.2o7[1].txt
11:25 AM: Quarantining All Traces: about cookie
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine about cookie
11:25 AM: Failed to quarantine [removed][2].txt
11:25 AM: Failed to quarantine default@about[1].txt
11:25 AM: Quarantining All Traces: adecn cookie
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine adecn cookie
11:25 AM: Failed to quarantine default@adecn[2].txt
11:25 AM: Quarantining All Traces: adknowledge cookie
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine adknowledge cookie
11:25 AM: Failed to quarantine default@adknowledge[2].txt
11:25 AM: Quarantining All Traces: adlegend cookie
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine adlegend cookie
11:25 AM: Failed to quarantine default@adlegend[1].txt
11:25 AM: Quarantining All Traces: ask cookie
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine ask cookie
11:25 AM: Failed to quarantine default@ask[1].txt
11:25 AM: Quarantining All Traces: atwola cookie
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine atwola cookie
11:25 AM: Failed to quarantine default@atwola[1].txt
11:25 AM: Quarantining All Traces: burstbeacon cookie
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine burstbeacon cookie
11:25 AM: Failed to quarantine [removed][1].txt
11:25 AM: Failed to quarantine [removed][2].txt
11:25 AM: Quarantining All Traces: columbiahouse cookie
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine columbiahouse cookie
11:25 AM: Failed to quarantine default@columbiahouse[2].txt
11:25 AM: Failed to quarantine default@columbiahouse[1].txt
11:25 AM: Quarantining All Traces: dealtime cookie
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine dealtime cookie
11:25 AM: Failed to quarantine [removed][2].txt
11:25 AM: Failed to quarantine default@dealtime[1].txt
11:25 AM: Failed to quarantine [removed][1].txt
11:25 AM: Failed to quarantine [removed][1].txt
11:25 AM: Quarantining All Traces: directtrack cookie
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine directtrack cookie
11:25 AM: Failed to quarantine [removed][2].txt
11:25 AM: Failed to quarantine [removed][2].txt
11:25 AM: Failed to quarantine [removed][3].txt
11:25 AM: Quarantining All Traces: gostats cookie
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine gostats cookie
11:25 AM: Failed to quarantine [removed][2].txt
11:25 AM: Quarantining All Traces: overture cookie
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine overture cookie
11:25 AM: Failed to quarantine [removed][1].txt
11:25 AM: Quarantining All Traces: pch cookie
11:25 AM: Warning: Out of memory
11:25 AM: Failed to quarantine pch cookie
11:25 AM: Failed to quarantine [removed][1].txt
11:25 AM: Quarantining All Traces: specificclick.com cookie
11:25 AM: Warning: Out of memory
11:25 AM: Warning: lzma: LZMA_Init failed
11:25 AM: Failed to quarantine specificclick.com cookie
11:25 AM: Failed to quarantine [removed][2].txt
11:25 AM: Failed to quarantine [removed][1].txt
11:25 AM: Quarantining All Traces: stamps.com cookie
11:25 AM: Warning: lzma: LZMA_Init failed
11:25 AM: Failed to quarantine stamps.com cookie
11:25 AM: Failed to quarantine [removed][1].txt
11:25 AM: Quarantining All Traces: tacoda cookie
11:25 AM: Warning: lzma: LZMA_Init failed
11:25 AM: Failed to quarantine tacoda cookie
11:25 AM: Failed to quarantine default@tacoda[1].txt
11:25 AM: Quarantining All Traces: yieldmanager cookie
11:25 AM: Warning: lzma: LZMA_Init failed
11:25 AM: Warning: lzma: LZMA_Init failed
11:25 AM: Warning: lzma: LZMA_Init failed
11:25 AM: Failed to quarantine yieldmanager cookie
11:25 AM: Failed to quarantine [removed][1].txt
11:25 AM: Failed to quarantine [removed][3].txt
11:25 AM: Failed to quarantine [removed][2].txt
11:25 AM: Warning: lzma: LZMA_Init failed
11:25 AM: Removal process completed. Elapsed time 00:00:32
11:26 AM: Sent error log: C:\WINDOWS\Application Data\Webroot\Spy Sweeper\Logs\bugreport.txt
********
10:01 AM: | Start of Session, Tuesday, April 11, 2006 |
10:01 AM: Spy Sweeper started
10:04 AM: Your spyware definitions have been updated.
10:18 AM: Updating spyware definitions
10:18 AM: Your definitions are up to date.
10:19 AM: Updating spyware definitions
10:19 AM: Your definitions are up to date.
10:20 AM: | End of Session, Tuesday, April 11, 2006 |





And here is my new HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 11:37:48 AM, on 4/11/06
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\CONSUMER INPUT\CONSUMERINPUT.EXE
C:\PROGRAM FILES\CONSUMER INPUT\CONSUMERINPUTUA.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\PROMPTCAST\PROMPTCAST.EXE
C:\PROGRAM FILES\WALGREENS\WALGREENS PHOTOSHOW\DATA\XTRAS\MSSYSMGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\WRSSSDK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://msn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://msn.com/
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe C:\PROGRA~1\WILDTA~1\APPS\CDA\CDAENG~1.DLL,cdaEngineMain
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Consumer Input] C:\Program Files\Consumer Input\ConsumerInput.exe
O4 - HKLM\..\Run: [Consumer Input Update] C:\Program Files\Consumer Input\ConsumerInputUa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NPFMonitor] C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ALU Scheduler Service] C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O4 - HKCU\..\Run: [PromptCast] C:\Program Files\PromptCast\PromptCast.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\DATA\XTRAS\MSSYSMGR.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\INSTANT MESSENGER\AIM.EXE
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
O9 - Extra button: Dell Home - {B5439B40-2A98-11D5-B1BE-000103E071E2} - http://www.my.delleworks.com (file missing) (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedCon…n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon…bin/AvSniff.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://netscape.musicnotes.com/download/mnviewer.cab
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (WebProgramManager Class) - http://isupport4.hp.com/awebui/jsp/answerw…SWebManager.CAB
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: Pop Fu by pogo - http://popfu.pogo.com/applet-6.0.4.37/popf…u-ob-assets.cab
O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.4.0.41/supe…o-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://squelchies.pogo.com/applet-6.0.4.37…s-ob-assets.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/UnSkin/gf.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.com/applet-6.2.1.34/popp…2-ob-assets.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.4.3.28/mahj…g-ob-assets.cab
O16 - DPF: {77DD44BF-551D-4E3C-82CD-D637D5018D3C} - http://www.surveys.com/promptcast/Installs…AST%20SETUP.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.com/applet-6.4.0.34/peng…s-ob-assets.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.4.2.30/popp…a-ob-assets.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/luxr/default/mjolauncher.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = covad.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = covad.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 64.105.113.138,64.105.97.90




System seems to be running a tad bit quicker BUT the error messages appeared again during rebooting. System won't let me use the Start-Restart steps. Error message says Lucallbackproxy and I have to hard boot the system.

And upon rebooting, I get IPHLPAPI.DLL cannot start and ibm00001.exe cannot find.

Do I still need to run that alternative scan? I know you mentioned it if the Spy Sweeper did not work again. And since it had that error I was not sure if you still needed me to run the alternative.

Thanks again for all your help!
The log looks OK.

Here's a fresh copy of IPHLPAPI.DLL, please download and place it in C:\WINDOWS\SYSTEM. Let it replace the one that's in there now.

———————-

Now for the error message….

First: Enable Hidden Files

Open My Computer.
Select the View menu and click Folder Options.
Select the View Tab.
In the Hidden files section select Show all files.
Click OK.

Now….
Open up the KillBox and copy and paste each one of these in, if the file exists it will appear in blue under the window - if found hit delete.
C:\Windows\System\ibm00001.exe
C:\Windows\ibm00001.exe


If you can't find it, please do a search for ibm00001.exe and see if you can delete it, you may have to reboot into safe mode to do it.

—————————

If you could please try the Kaspersky scan, it doesn't fix anything but will give us a report of any malware on the system. I'm not going to pay attention to the SpySweeper scan because of the problems you had.

Good Luck and let me know, MrC
:blink: Wow! I guess I've got myself one big doozy of a mess here!! I tried to download the IPHLPADI file you sent and at the time of download it came up with a messages that said Cannot copy, There has been a sharing violation. The source or destination file may be in use. HOWEVER, when I rebooted I did not get the can't find message that I was getting before SO maybe it downloaded anyways. I still cannot reboot using the restart command. I must hard boot. Still getting the Lucallbackproxy error message. And upon restarting I still get the ibm00001.exe message. I performed the removal steps you gave me. I also tried removing it in safe mode. It told me it could not find that file each time. But the error message still pops up upon reboot. Ok…that't it for the behaviour report. Here is my Kaspersky Log: KASPERSKY ON-LINE SCANNER REPORT Friday, April 14, 2006 08:27:29 Operating System: Microsoft Windows 98 SE Kaspersky On-line Scanner version: 5.0.67.0 Kaspersky Anti-Virus database last update: 13/04/2006 Kaspersky Anti-Virus database records: 188036 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: a:\ c:\ d:\ Scan Statistics: Total number of scanned objects: 152301 Number of viruses found: 72 Number of infected objects: 207 Number of suspicious objects: 0 Duration of the scan process: 7063 sec Infected Object Name - Virus Name c:\WINDOWS\TEMP\ConsumerInputInstall.exe/data0003 Infected: not-a-virus:RiskTool.Win32.PsKill.n c:\WINDOWS\TEMP\ConsumerInputInstall.exe Infected: not-a-virus:RiskTool.Win32.PsKill.n c:\WINDOWS\TEMP\ConsumerInputUpdate.exe/data0003 Infected: not-a-virus:RiskTool.Win32.PsKill.n c:\WINDOWS\TEMP\ConsumerInputUpdate.exe Infected: not-a-virus:RiskTool.Win32.PsKill.n c:\WINDOWS\TEMP\warez_p2p_setup.exe/data0042 Infected: not-a-virus:AdWare.Win32.NewDotNet c:\WINDOWS\TEMP\warez_p2p_setup.exe/data0043 Infected: not-a-virus:AdWare.Win32.Lop.ai c:\WINDOWS\TEMP\warez_p2p_setup.exe Infected: not-a-virus:AdWare.Win32.Lop.ai c:\WINDOWS\Desktop\Tresa\Big.Kahuna.Reef.v1.4.5.UNLOCKER.WinAll-PH.zip/crack-inf.exe/data0002 Infected: not-a-virus:RiskTool.Win32.PsKill.n c:\WINDOWS\Desktop\Tresa\Big.Kahuna.Reef.v1.4.5.UNLOCKER.WinAll-PH.zip/crack-inf.exe/data0004 Infected: Trojan-Clicker.Win32.VB.jy c:\WINDOWS\Desktop\Tresa\Big.Kahuna.Reef.v1.4.5.UNLOCKER.WinAll-PH.zip/crack-inf.exe Infected: Trojan-Clicker.Win32.VB.jy c:\WINDOWS\Desktop\Tresa\Big.Kahuna.Reef.v1.4.5.UNLOCKER.WinAll-PH.zip Infected: Trojan-Clicker.Win32.VB.jy c:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv470.jar-5c362d1c-334537d0.zip/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c c:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv470.jar-5c362d1c-334537d0.zip Infected: Trojan-Downloader.Java.OpenStream.c c:\WINDOWS\Temporary Internet Files\Content.IE5\CPEVCXE3\ucmoreiex[1].exe/unknown2.bin Infected: not-a-virus:AdWare.Win32.Ucmore.e c:\WINDOWS\Temporary Internet Files\Content.IE5\CPEVCXE3\ucmoreiex[1].exe Infected: not-a-virus:AdWare.Win32.Ucmore.e c:\WINDOWS\Temporary Internet Files\Content.IE5\8HMZSLQZ\id8[1].exe Infected: Trojan-Dropper.Win32.Agent.hl c:\WINDOWS\Temporary Internet Files\Content.IE5\SBSNU3KR\rs[1].php Infected: Trojan-Clicker.JS.Linker.b c:\WINDOWS\Temporary Internet Files\Content.IE5\UXZK9K3M\wbkE0A3.TMP Infected: Trojan-Spy.HTML.Bayfraud.hn c:\WINDOWS\Temporary Internet Files\Content.IE5\S90FOJ4F\XoftSpy416_123b[1].exe/data0013 Infected: not-a-virus:RiskTool.Win32.PsKill.n c:\WINDOWS\Temporary Internet Files\Content.IE5\S90FOJ4F\XoftSpy416_123b[1].exe Infected: not-a-virus:RiskTool.Win32.PsKill.n c:\WINDOWS\.housecall\Quarantine\COMMAND.EX$.bac_a31997 Infected: not-a-virus:AdWare.Win32.CommAd.a c:\WINDOWS\.housecall\Quarantine\command.exe.bac_a31997 Infected: not-a-virus:AdWare.Win32.CommAd.a c:\WINDOWS\.housecall\Quarantine\DR21206.exe.bac_a31997/data0002 Infected: Trojan-Clicker.Win32.Small.jf c:\WINDOWS\.housecall\Quarantine\DR21206.exe.bac_a31997 Infected: Trojan-Clicker.Win32.Small.jf c:\WINDOWS\.housecall\Quarantine\loaderadv470.jar-5c362d1c-334537d0.zip.bac_a31997/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c c:\WINDOWS\.housecall\Quarantine\loaderadv470.jar-5c362d1c-334537d0.zip.bac_a31997 Infected: Trojan-Downloader.Java.OpenStream.c c:\WINDOWS\.housecall\Quarantine\paytime.exe.bac_a31997 Infected: Trojan.Win32.StartPage.adi c:\WINDOWS\.housecall\Quarantine\gimmygames11.exe.bac_a31997 Infected: Trojan-Downloader.Win32.Adload.u c:\WINDOWS\.housecall\Quarantine\winsysban11.exe.bac_a31997 Infected: Trojan-Clicker.Win32.VB.li c:\WINDOWS\.housecall\Quarantine\winsysupd11.exe.bac_a31997 Infected: Trojan.Win32.VB.ajo c:\WINDOWS\.housecall\Quarantine\pms111x.exe.bac_a31997 Infected: Trojan-Downloader.Win32.VB.tw c:\WINDOWS\.housecall\Quarantine\MTE3NDI6ODoxNg.exe.bac_a31997 Infected: Trojan-Downloader.Win32.Small.buy c:\WINDOWS\.housecall\Quarantine\MTE3NDI6ODoxNg[1].exe.bac_a31997 Infected: Trojan-Downloader.Win32.Small.buy c:\WINDOWS\.housecall\Quarantine\IUCmore.dll.bac_a31997 Infected: not-a-virus:AdWare.Win32.Ucmore c:\WINDOWS\.housecall\Quarantine\SYSC00.exe.bac_a31997 Infected: Trojan.Win32.VB.tg c:\WINDOWS\.housecall\Quarantine\UCMTSAIE.dll.bac_a31997 Infected: not-a-virus:AdWare.Win32.Ucmore.a c:\WINDOWS\.housecall\Quarantine\ucmoreiex[1].exe.bac_a31997/unknown2.bin Infected: not-a-virus:AdWare.Win32.Ucmore.e c:\WINDOWS\.housecall\Quarantine\ucmoreiex[1].exe.bac_a31997/UCMTSAIE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore.a c:\WINDOWS\.housecall\Quarantine\ucmoreiex[1].exe.bac_a31997/IUCMORE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore c:\WINDOWS\.housecall\Quarantine\ucmoreiex[1].exe.bac_a31997 Infected: not-a-virus:AdWare.Win32.Ucmore c:\WINDOWS\.housecall\Quarantine\ucmoreiex.exe.bac_a31997/unknown2.bin Infected: not-a-virus:AdWare.Win32.Ucmore.e c:\WINDOWS\.housecall\Quarantine\ucmoreiex.exe.bac_a31997/UCMTSAIE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore.a c:\WINDOWS\.housecall\Quarantine\ucmoreiex.exe.bac_a31997/IUCMORE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore c:\WINDOWS\.housecall\Quarantine\ucmoreiex.exe.bac_a31997 Infected: not-a-virus:AdWare.Win32.Ucmore c:\WINDOWS\.housecall\Quarantine\Installer.exe.bac_a31997 Infected: not-a-virus:AdWare.Win32.Look2Me.ab c:\WINDOWS\.housecall\Quarantine\Installer[1].exe.bac_a31997 Infected: not-a-virus:AdWare.Win32.Look2Me.ab c:\WINDOWS\.housecall\Quarantine\stub_113_4_0_4_0[1].exe.bac_a31997 Infected: Trojan-Downloader.Win32.TSUpdate.o c:\WINDOWS\.housecall\Quarantine\stub_113_4_0_4_0.exe.bac_a31997 Infected: Trojan-Downloader.Win32.TSUpdate.o c:\WINDOWS\.housecall\Quarantine\DXSTYLE.DLL.bac_a31997 Infected: not-a-virus:AdWare.Win32.Look2Me.ap c:\WINDOWS\.housecall\Quarantine\ibm00001.dll.bac_a31997 Infected: Trojan-Spy.Win32.Small.dg c:\WINDOWS\.housecall\Quarantine\ibm00002.dll.bac_a31997 Infected: Trojan-Spy.Win32.Small.dg c:\WINDOWS\.housecall\Quarantine\kl1.exe.bac_a31997 Infected: Trojan-Dropper.Win32.Small.amd c:\WINDOWS\.housecall\Quarantine\SS1001.exe.bac_a31997/data0010 Infected: Trojan-Dropper.Win32.Small.qn c:\WINDOWS\.housecall\Quarantine\SS1001.exe.bac_a31997 Infected: Trojan-Dropper.Win32.Small.qn c:\WINDOWS\.housecall\Quarantine\SS1001[1].exe.bac_a31997/data0010 Infected: Trojan-Dropper.Win32.Small.qn c:\WINDOWS\.housecall\Quarantine\SS1001[1].exe.bac_a31997 Infected: Trojan-Dropper.Win32.Small.qn c:\WINDOWS\.housecall\Quarantine\i5011.TMP.bac_a31997 Infected: not-a-virus:AdWare.Win32.SurfSide.j c:\WINDOWS\.housecall\Quarantine\ibm00001.dll.bac_a63333 Infected: Trojan-Spy.Win32.Small.dg c:\WINDOWS\.housecall\Quarantine\ibm00002.dll.bac_a63333 Infected: Trojan-Spy.Win32.Small.dg c:\WINDOWS\.housecall\Quarantine\OWBCCP32.DLL.bac_a67977 Infected: not-a-virus:AdWare.Win32.Look2Me.ap c:\WINDOWS\.housecall\Quarantine\ibm00001.dll.bac_a67977 Infected: Trojan-Spy.Win32.Small.dg c:\WINDOWS\.housecall\Quarantine\ibm00002.dll.bac_a67977 Infected: Trojan-Spy.Win32.Small.dg c:\WINDOWS\.housecall\Quarantine\ucmoreiex.exe.bac_a67977/unknown2.bin Infected: not-a-virus:AdWare.Win32.Ucmore.e c:\WINDOWS\.housecall\Quarantine\ucmoreiex.exe.bac_a67977/UCMTSAIE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore.a c:\WINDOWS\.housecall\Quarantine\ucmoreiex.exe.bac_a67977/IUCMORE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore c:\WINDOWS\.housecall\Quarantine\ucmoreiex.exe.bac_a67977 Infected: not-a-virus:AdWare.Win32.Ucmore c:\WINDOWS\NDNuninstall7_22.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e c:\Program Files\Norton AntiVirus\Quarantine\incoming\AP0.exe Infected: Email-Worm.Win32.Magistr.b c:\Program Files\Norton AntiVirus\Quarantine\incoming\AP0 Infected: Email-Worm.Win32.Magistr.b c:\Program Files\Norton AntiVirus\Quarantine\incoming\AP1 Infected: Email-Worm.Win32.Magistr.b c:\Program Files\Norton AntiVirus\Quarantine\incoming\AP2 Infected: Email-Worm.Win32.Magistr.b c:\Program Files\Norton AntiVirus\Quarantine\incoming\AP3 Infected: Email-Worm.Win32.Magistr.b c:\Program Files\Norton AntiVirus\Quarantine\incoming\AP4 Infected: Email-Worm.Win32.Magistr.b c:\Program Files\Norton AntiVirus\Quarantine\incoming\AP5 Infected: Email-Worm.Win32.Magistr.b c:\Program Files\Norton AntiVirus\Quarantine\incoming\AP1.exe Infected: Trojan-Downloader.Win32.Small.bws c:\Program Files\Norton AntiVirus\Quarantine\incoming\AP3.exe Infected: Trojan-Downloader.Win32.Small.bws c:\Program Files\Norton AntiVirus\Quarantine\incoming\AP4.exe Infected: Trojan-Downloader.Win32.Small.bws c:\Program Files\Norton AntiVirus\Quarantine\incoming\AP5.exe Infected: Trojan-Downloader.Win32.Small.bws c:\Program Files\Norton AntiVirus\Quarantine\incoming\AP6.exe Infected: Trojan-Downloader.Win32.PassAlert.d c:\Program Files\Norton AntiVirus\Quarantine\incoming\AP7.exe Infected: Trojan-Downloader.Win32.PassAlert.d c:\Program Files\Norton AntiVirus\Quarantine\2CF1055F.TMP Infected: Email-Worm.Win32.Magistr.b c:\Program Files\Norton AntiVirus\Quarantine\44744980.TMP Infected: Trojan-Downloader.Win32.Small.bws c:\Program Files\Norton AntiVirus\Quarantine\585A239A.DL$ Infected: not-a-virus:AdWare.Win32.Sud.a c:\Program Files\Norton AntiVirus\Quarantine\585D4D97.OC$ Infected: not-a-virus:AdWare.Win32.AzSearch.b c:\Program Files\Norton AntiVirus\Quarantine\585D4D97.exe Infected: not-a-virus:AdWare.Win32.Lop.ag c:\Program Files\Norton AntiVirus\Quarantine\58617793.exe Infected: not-a-virus:AdWare.Win32.MDH.e c:\Program Files\Norton AntiVirus\Quarantine\5864218F.exe Infected: Trojan-Downloader.Win32.Adload.l c:\Program Files\Norton AntiVirus\Quarantine\43D76711.exe Infected: not-a-virus:AdWare.Win32.Lop.ag c:\Program Files\Norton AntiVirus\Quarantine\5864218F.DL$ Infected: not-a-virus:AdWare.Win32.AzSearch.b c:\Program Files\Norton AntiVirus\Quarantine\58674B8C.exe Infected: not-a-virus:AdWare.Win32.Suggestor.o c:\Program Files\Norton AntiVirus\Quarantine\09A04510.exe Infected: not-a-virus:AdWare.Win32.Lop.ag c:\Program Files\Norton AntiVirus\Quarantine\3D2A7348.exe Infected: Trojan-Downloader.Win32.Small.buy c:\Program Files\Norton AntiVirus\Quarantine\586E1F85.exe Infected: Trojan-Downloader.Win32.TSUpdate.o c:\Program Files\Norton AntiVirus\Quarantine\5874737D.ex$ Infected: Trojan.Win32.StartPage.aw c:\Program Files\Norton AntiVirus\Quarantine\5874737D.exe Infected: not-a-virus:AdWare.Win32.Lop.ag c:\Program Files\Norton AntiVirus\Quarantine\20C03D0D.exe/WISE0009.BIN Infected: Trojan-Downloader.Win32.TSUpdate.n c:\Program Files\Norton AntiVirus\Quarantine\20C03D0D.exe/WISE0010.BIN Infected: Trojan-Downloader.Win32.TSUpdate.p c:\Program Files\Norton AntiVirus\Quarantine\20C03D0D.exe/WISE0011.BIN Infected: Trojan-Downloader.Win32.TSUpdate.l c:\Program Files\Norton AntiVirus\Quarantine\20C03D0D.exe/WISE0012.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f c:\Program Files\Norton AntiVirus\Quarantine\20C03D0D.exe Infected: Trojan-Downloader.Win32.TSUpdate.f c:\Program Files\Norton AntiVirus\Quarantine\58781D7A.exe Infected: Trojan-Downloader.Win32.TSUpdate.l c:\Program Files\Norton AntiVirus\Quarantine\587B4776.exe Infected: Trojan-Downloader.Win32.TSUpdate.p c:\Program Files\Norton AntiVirus\Quarantine\58811B6F.EX$ Infected: Trojan-Downloader.Win32.TSUpdate.n c:\Program Files\Norton AntiVirus\Quarantine\58886F68.exe Infected: Trojan-Downloader.Win32.TSUpdate.f c:\Program Files\Norton AntiVirus\Quarantine\32C708F2.exe Infected: Trojan-Clicker.Win32.VB.kc c:\Program Files\Norton AntiVirus\Quarantine\7D050F3F.exe Infected: Trojan.Win32.Runner.h c:\Program Files\Norton AntiVirus\Quarantine\0B8F7313.exe Infected: not-a-virus:AdWare.Win32.MDH.e c:\Program Files\Norton AntiVirus\Quarantine\2A7B6FA5.exe Infected: Trojan-Downloader.Win32.Adload.j c:\Program Files\Norton AntiVirus\Quarantine\6D174967.dll Infected: not-a-virus:AdWare.Win32.Sud.a c:\Program Files\Norton AntiVirus\Quarantine\6D247159.exe Infected: Trojan-Downloader.Win32.Qoologic.at c:\Program Files\Norton AntiVirus\Quarantine\47177799.exe Infected: Trojan-Clicker.Win32.VB.jx c:\Program Files\Norton AntiVirus\Quarantine\47381B75.cla Infected: Exploit.Java.ByteVerify c:\Program Files\Norton AntiVirus\Quarantine\00747A02.cla Infected: Trojan.Java.ClassLoader.Dummy.d c:\Program Files\Norton AntiVirus\Quarantine\47381B75.wmf Infected: Trojan-Downloader.Win32.Agent.acd c:\Program Files\Norton AntiVirus\Quarantine\473B4572.cla Infected: Exploit.Java.ByteVerify c:\Program Files\Norton AntiVirus\Quarantine\473E6F6E.cla Infected: Exploit.Java.ByteVerify c:\Program Files\Norton AntiVirus\Quarantine\473E6F6E.wmf Infected: Trojan-Downloader.Win32.Agent.acd c:\Program Files\Norton AntiVirus\Quarantine\4B9D57C3.dll Infected: Trojan-Clicker.Win32.Small.jf c:\Program Files\Norton AntiVirus\Quarantine\550D3560.exe Infected: Trojan-Clicker.Win32.VB.ij c:\Program Files\Norton AntiVirus\Quarantine\11FF0333.exe Infected: Trojan-Downloader.Win32.VB.nw c:\Program Files\Norton AntiVirus\Quarantine\2EB42B9E.txt Infected: Trojan-Downloader.Win32.Agent.aea c:\Program Files\Norton AntiVirus\Quarantine\2EB42B9E.exe Infected: Trojan-Downloader.Win32.Agent.aea c:\Program Files\Norton AntiVirus\Quarantine\3FEC604C.txt Infected: Trojan-Downloader.Win32.Agent.aea c:\Program Files\Norton AntiVirus\Quarantine\3FEC604C.exe Infected: Trojan-Downloader.Win32.Agent.aea c:\Program Files\Norton AntiVirus\Quarantine\578E5AA0.txt Infected: Trojan-Downloader.Win32.Agent.aea c:\Program Files\Norton AntiVirus\Quarantine\57A1568A.exe Infected: Trojan-Downloader.Win32.Agent.aea c:\Program Files\Norton AntiVirus\Quarantine\57A1568A.txt Infected: Trojan-Downloader.Win32.Agent.aea c:\Program Files\Norton AntiVirus\Quarantine\719149A9.exe Infected: Trojan-Downloader.Win32.Agent.aea c:\Program Files\Norton AntiVirus\Quarantine\719149A9.txt Infected: Trojan-Downloader.Win32.Agent.aea c:\Program Files\Norton AntiVirus\Quarantine\348D0E4C.exe Infected: Trojan-Downloader.Win32.Agent.aea c:\Program Files\Norton AntiVirus\Quarantine\257B46DE.TMP Infected: Trojan-Downloader.Java.OpenConnection.aj c:\Program Files\Norton AntiVirus\Quarantine\089F2B4C.TMP Infected: Trojan-Downloader.Java.OpenConnection.aj c:\Program Files\Norton AntiVirus\Quarantine\257E70DB.TMP Infected: Trojan.Java.ClassLoader.h c:\Program Files\Norton AntiVirus\Quarantine\25821AD7.TMP Infected: Trojan.Java.ClassLoader.d c:\Program Files\Norton AntiVirus\Quarantine\1F6F5614.ocx Infected: not-a-virus:AdWare.Win32.AzSearch.b c:\Program Files\Norton AntiVirus\Quarantine\1F6F5614.exe Infected: not-a-virus:AdWare.Win32.MDH.e c:\Program Files\Norton AntiVirus\Quarantine\1F720010.exe Infected: Trojan-Downloader.Win32.Adload.u c:\Program Files\Norton AntiVirus\Quarantine\28632816.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.m c:\Program Files\Norton AntiVirus\Quarantine\1F762A0C.exe Infected: Trojan-Downloader.Win32.Small.abd c:\Program Files\Norton AntiVirus\Quarantine\1F762A0C.TMP Infected: not-a-virus:AdWare.Win32.SurfSide.j c:\Program Files\Norton AntiVirus\Quarantine\1F795409.dll Infected: not-a-virus:AdWare.Win32.AzSearch.b c:\Program Files\Norton AntiVirus\Quarantine\1F795409.exe Infected: not-a-virus:AdWare.Win32.Look2Me.ab c:\Program Files\Norton AntiVirus\Quarantine\33F36414.exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.p c:\Program Files\Norton AntiVirus\Quarantine\33F36414.exe Infected: Trojan-Downloader.NSIS.Agent.p c:\Program Files\Norton AntiVirus\Quarantine\4A004384.exe Infected: Trojan-Downloader.Win32.Small.buy c:\Program Files\Norton AntiVirus\Quarantine\1F7F2802.exe Infected: Trojan-Dropper.Win32.Agent.hl c:\Program Files\Norton AntiVirus\Quarantine\1F8351FE.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.m c:\Program Files\Norton AntiVirus\Quarantine\054C7E12.exe Infected: Trojan-Dropper.Win32.Small.qn c:\Program Files\Norton AntiVirus\Quarantine\42DF7188.exe/data0010 Infected: Trojan-Dropper.Win32.Small.qn c:\Program Files\Norton AntiVirus\Quarantine\42DF7188.exe Infected: Trojan-Dropper.Win32.Small.qn c:\Program Files\Norton AntiVirus\Quarantine\0F0D17F1.exe Infected: Trojan-Downloader.Win32.TSUpdate.o c:\Program Files\Norton AntiVirus\Quarantine\1F8925F7.exe Infected: Trojan-Downloader.Win32.Adload.q c:\Program Files\Norton AntiVirus\Quarantine\1F8C4FF3.TMP Infected: not-a-virus:AdWare.Win32.SurfSide.aa c:\Program Files\Norton AntiVirus\Quarantine\1F8C4FF3.exe Infected: Trojan-Downloader.Win32.Small.abd c:\Program Files\Norton AntiVirus\Quarantine\56A41810.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.m c:\Program Files\Norton AntiVirus\Quarantine\33AB6216.dll Infected: Trojan-Clicker.Win32.Small.jf c:\Program Files\Norton AntiVirus\Quarantine\33B80A07.TMP Infected: Email-Worm.Win32.Magistr.b c:\Program Files\Norton AntiVirus\Quarantine\1F847766.exe Infected: Trojan-Clicker.Win32.VB.lj c:\Program Files\Norton AntiVirus\Quarantine\345F1E73.tmp Infected: Trojan-Dropper.Win32.Agent.abu c:\Program Files\Norton AntiVirus\Quarantine\39F5744D.exe/data0002 Infected: Trojan-Clicker.Win32.Small.jf c:\Program Files\Norton AntiVirus\Quarantine\39F5744D.exe Infected: Trojan-Clicker.Win32.Small.jf c:\Program Files\Norton AntiVirus\Quarantine\7B592858.exe Infected: Trojan-Downloader.Win32.Small.ckj c:\Program Files\Norton AntiVirus\Quarantine\7B762237.exe Infected: SpamTool.Win32.Mailbot.aq c:\Program Files\Norton AntiVirus\Quarantine\4034032A.exe Infected: Trojan-Downloader.Win32.Tiny.bi c:\Program Files\Norton AntiVirus\Quarantine\1D264725.exe/data0002 Infected: Trojan-Clicker.Win32.Small.jf c:\Program Files\Norton AntiVirus\Quarantine\1D264725.exe Infected: Trojan-Clicker.Win32.Small.jf c:\Program Files\Norton AntiVirus\Quarantine\213818AA.exe Infected: Trojan.Win32.VB.tg c:\Program Files\Norton AntiVirus\Quarantine\1AB05B3B.exe Infected: Trojan.Win32.VB.tg c:\Program Files\Norton AntiVirus\Quarantine\06B83A17.exe Infected: Trojan-Dropper.Win32.Agent.aie c:\Program Files\Norton AntiVirus\Quarantine\21593C86.exe Infected: not-a-virus:AdWare.Win32.MDH.e c:\Program Files\Norton AntiVirus\Quarantine\215F107F.exe Infected: Trojan-Downloader.Win32.Adload.aj c:\Program Files\Norton AntiVirus\Quarantine\60124332.exe Infected: Trojan-Downloader.Win32.Adload.v c:\Program Files\Norton AntiVirus\Quarantine\21633A7C.TMP Infected: not-a-virus:AdWare.Win32.SurfSide.j c:\Program Files\Norton AntiVirus\Quarantine\21666478.exe Infected: not-a-virus:AdWare.Win32.Look2Me.ab c:\Program Files\Norton AntiVirus\Quarantine\6BA27F31.exe Infected: not-a-virus:AdWare.Win32.Look2Me.ab c:\Program Files\Norton AntiVirus\Quarantine\21690E74.exe Infected: not-a-virus:AdWare.Win32.MDH.e c:\Program Files\Norton AntiVirus\Quarantine\216C3871.exe Infected: Trojan-Downloader.Win32.Small.buy c:\Program Files\Norton AntiVirus\Quarantine\21796062.exe Infected: Trojan-Downloader.Win32.Small.buy c:\Program Files\Norton AntiVirus\Quarantine\21870854.exe Infected: Trojan-Downloader.Win32.VB.tw c:\Program Files\Norton AntiVirus\Quarantine\218A3250.exe Infected: Trojan-Dropper.Win32.Small.qn c:\Program Files\Norton AntiVirus\Quarantine\218D5C4D.exe/data0010 Infected: Trojan-Dropper.Win32.Small.qn c:\Program Files\Norton AntiVirus\Quarantine\218D5C4D.exe Infected: Trojan-Dropper.Win32.Small.qn c:\Program Files\Norton AntiVirus\Quarantine\31046729.exe/data0010 Infected: Trojan-Dropper.Win32.Small.qn c:\Program Files\Norton AntiVirus\Quarantine\31046729.exe Infected: Trojan-Dropper.Win32.Small.qn c:\Program Files\Norton AntiVirus\Quarantine\21900649.exe Infected: Trojan-Downloader.Win32.TSUpdate.o c:\Program Files\Norton AntiVirus\Quarantine\219A043F.exe Infected: Trojan-Downloader.Win32.TSUpdate.o c:\Program Files\Norton AntiVirus\Quarantine\21A40234.exe/data0002 Infected: Trojan-Downloader.Win32.VB.tw c:\Program Files\Norton AntiVirus\Quarantine\21A40234.exe/data0003 Infected: Trojan.Win32.VB.tg c:\Program Files\Norton AntiVirus\Quarantine\21A40234.exe/data0006 Infected: Trojan.Win32.VB.tg c:\Program Files\Norton AntiVirus\Quarantine\21A40234.exe/data0007 Infected: Trojan.Win32.VB.tg c:\Program Files\Norton AntiVirus\Quarantine\21A40234.exe Infected: Trojan.Win32.VB.tg c:\Program Files\Norton AntiVirus\Quarantine\21A72C30.exe Infected: Trojan-Clicker.Win32.VB.li c:\Program Files\Norton AntiVirus\Quarantine\5F465723.exe Infected: Trojan.Win32.StartPage.aib c:\Program Files\Norton AntiVirus\Quarantine\21AA562D.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.m c:\Program Files\Norton AntiVirus\Quarantine\250E3523.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.m c:\Program Files\Norton AntiVirus\Quarantine\5D9D4E6D.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.m c:\Program Files\Norton AntiVirus\Quarantine\5DAD205B.exe Infected: Trojan-Downloader.Win32.VB.ys c:\Program Files\Norton AntiVirus\Quarantine\339D0AE4.exe Infected: Trojan-Downloader.Win32.VB.ys c:\Program Files\Norton AntiVirus\Quarantine\291C1CBF.exe Infected: Trojan-Clicker.Win32.VB.li c:\Program Files\Norton AntiVirus\Quarantine\5DB04A58.exe Infected: Trojan-Clicker.Win32.VB.li c:\Program Files\Norton AntiVirus\Quarantine\796568E3.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.n c:\Program Files\Norton AntiVirus\Quarantine\5DB47454.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.m c:\Program Files\Norton AntiVirus\Quarantine\5DB71E50.exe Infected: Trojan-Clicker.Win32.VB.li c:\Program Files\Consumer Input\uninstall.exe/data0003 Infected: not-a-virus:RiskTool.Win32.PsKill.n c:\Program Files\Consumer Input\uninstall.exe Infected: not-a-virus:RiskTool.Win32.PsKill.n c:\NNSCAA638.EXE Infected: not-a-virus:AdWare.Win32.NewDotNet c:\id8.exe Infected: Trojan-Dropper.Win32.Agent.hl Scan process completed. I did notice that alot of this scan contained Quarantined items. Is there a way to delete those items? Could they still affect my computer even though they are quarantined? Thanks again for your help! You are a GOD LOL!!
OK, open the KillBox and copy and paste each of these in and hit delete:

c:\WINDOWS\NDNuninstall7_22.exe
c:\NNSCAA638.EXE
c:\id8.exe

While you still have the KillBox open - click tools > delete temp files > check all boxes except cookies > then hit delete.

——————–

I'm not really familiar with Housecall or Norton but you should be able to delete the contents of these folders:

c:\WINDOWS\.housecall\Quarantine

c:\Program Files\Norton AntiVirus\Quarantine

————————

Go to your control panel and see if there's a Java icon, open it up and click on delete files or cache.

———————–

Do you have any idea what these are:

c:\WINDOWS\Desktop\Tresa\Big.Kahuna.Reef.v1.4.5.UNLOCKER.WinAll-PH.zip/crack-inf.exe/data0002 Infected: not-a-virus:RiskTool.Win32.PsKill.n
c:\WINDOWS\Desktop\Tresa\Big.Kahuna.Reef.v1.4.5.UNLOCKER.WinAll-PH.zip/crack-inf.exe/data0004 Infected: Trojan-Clicker.Win32.VB.jy
c:\WINDOWS\Desktop\Tresa\Big.Kahuna.Reef.v1.4.5.UNLOCKER.WinAll-PH.zip/crack-inf.exe Infected: Trojan-Clicker.Win32.VB.jy
c:\WINDOWS\Desktop\Tresa\Big.Kahuna.Reef.v1.4.5.UNLOCKER.WinAll-PH.zip Infected: Trojan-Clicker.Win32.VB.jy

———————————-

Go to start > programs > startup > see what's listed > delete anything you don't recognize > if not sure please ask first.

———————————

Run the registry cleaner:
http://forums.tomcoyote.org/index.php?showtopic=42862

——————–

Let me know, MrC
:P Ok…Killbox. I deleted the specified files. During deleting the temp files, it would give me a time overrun error message while trying to delete C\Windows\Temporary Internet Files. So I deleted them another way. I deleted all items located in the housecall and Norton Quarantine files. I deleted the files in Java. The Big Kahuna Reef was an unlocker for a game. I deleted all in that file. The Start/Programs/start up was empty. I performed the Reg cleanup also. System will still not allow me to restart using command. Must still hard boot system. Error message Lucallbackproxy still repeatedly pops up when I try to do it using the restart command. Upon rebooting, I am still getting the error message that it cannot find ibm00001.exe. Although I can't find it either, I can't figure out how to make it stop telling me so LOL!! Do I need to rerun scans now? I am at work and therefor can let them run until I get back in the office Monday. Thanks!
For the ibm00001.exe error message:

Go to your Windows folder and find System.ini, make a copy of it (right click on it and choose copy) and paste it somewhere safe like My Documents, etc.

Now right click on the System.ini file that's in the Windows folder, choose properties and make sure the "read-only" box is unchecked.
Now double click on it to open it, it should open up with notepad.
In the first couple of lines look for shell=explorer.exe ibm00001.exe
See if it's there, if so CAREFULLY only delete only ibm00001.exe
leaving shell=explorer.exe
Now close System.ini by using the X in the upper right hand corner as you normally would.
Reboot and see if the errors gone.

If anything goes wrong you can always replace System.ini with the backup copy!

——————————-

Here's what I found about the Lucallbackproxy error, see if it applies:

This is a problem with the Live Update portion of your Norton Antivirus. If
you have recently uninstalled it, you didn't get all of it and need cleaning
instructions pertinent to your version of NAV (or Norton Internet Security)
to clean it all. If you haven't uninstalled it, you probably need to
uninstall and reinstall it.

Take A Look Here

Let me know the exact error message. MrC
:rofl: Yes, I'm so sorry. Unfortunatly it is my work computer that is so messed up. I have been trying to get my work done while completing the necessary steps as well to fix it. Norton says it is so user friendly but …. NOT! I have been working the past couple of days to complete the unintall/reinstall steps they have on thier websight. I think I may have finally finished. I restarted a couple of times and I THINK the Lucallbackproxy thing is gone. It surprises me once in awhile though when I think I've just about got it taken care of. The ibm00001 message is gone. Now I am getting an error message upon rebooting saying the cstray.exe can not be found. I am hoping this is the last of the brain twisters here. Any idea on the cstray.exe? Thanks for being so helpful and patient! Woogs

cstray.exe is related to Cometcursor or CompuServe, do either sound familiar to you?
Look in your add/remove programs for Cometcursor. MrC
:rofl: Ok. I went into msconfig and found the systray that was no longer appearing upon bootup and checked that. I also found the cstray which was compuserve (this computer apparently had a comuserve account a long time ago I guess) and unchecked that box. I am not getting anymore error messages upon bootup anymore BUT I am having some freezing problems in my Outlook Express now and the system seems to be moving extremely slow. The Lucallbackproxy was definetly connected to the Norton Anitvirus as when I turn off the Auto-Protect function that error message does not appear. I have a request for help sent to them and am waiting for thier reply on that matter. Also, my system keeps wanting to run a Scan disk now so I guess I will execute that and let it run but I was hoping to do that this evening when I leave for the day as it takes hours and I have work I have to do in the meantime. Any other suggestions? I am having problems with my Outlook Express this morning for some reason. I don't know if it is connected with all these other problems I have been having. Thanks again, Woogs

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI