maximus1284
so before I read your latest messages, I ran a couple other scans (such as ewido, defender, etc.) and they have seemed to help in combination with your solutions. my computer is running better, and it appears the main spyware problem has been taken care of, although spysweeper curiously found a couple things that I hadn't seen in previous scans of other programs so that was interesting. switching to FireFox seems to be going well, but am I still at risk of spyware with it?
btw, does combofix trigger diskcleanup to initiate? diskcleanup has curiously launched a few times, and most recently right after combofix finished but before the log popped up
here are my logs:
Start Time= Thu 07/06/2006 17:17:24.29
Running from: C:\
QuickScan did not find any signs of infected files
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-07-06 15:37:30 ( .D… ) "C:\Program Files\Webroot"
2006-07-06 15:37:30 ( .D… ) "C:\Documents and Settings\Paul Farnum\Application Data\Webroot"
2006-07-06 06:38:16 ( .D… ) "C:\Documents and Settings\Paul Farnum\Application Data\Mozilla"
2006-07-06 06:37:44 ( .D… ) "C:\Program Files\Mozilla Firefox"
2006-07-06 06:33:16 ( .D… ) "C:\Program Files\Google"
2006-07-05 22:49:32 0 ( A…. ) "C:\Documents and Settings\Paul Farnum\Application Data\internaldb41.dat"
2006-07-04 14:20:46 331174 ( A…. ) "C:\combofix.exe"
2006-07-04 14:19:54 818752 ( A…. ) "C:\blbeta.exe"
2006-07-03 12:26:16 ( .D… ) "C:\Documents and Settings\Paul Farnum\Application Data\PC Tools"
2006-07-03 10:24:44 ( .D… ) "C:\Program Files\ewido anti-spyware 4.0"
2006-07-03 10:13:44 ( .D… ) "C:\Program Files\Spyware Doctor"
2006-07-03 00:12:52 ( .D… ) "C:\Program Files\Windows Defender"
2006-07-03 00:08:22 308 ( A…. ) "C:\WINDOWS\poiyb.dll"
2006-07-02 22:48:28 32976 ( A…. ) "C:\WINDOWS\system32\uninstIcn.exe"
2006-07-02 22:45:26 0 ( A…. ) "C:\WINDOWS\system32\cloudsim.exe"
2006-07-02 22:45:20 359634 ( A…. ) "C:\WINDOWS\media_motor_bundle.exe"
2006-07-02 22:45:20 178726 ( A…. ) "C:\WINDOWS\YazzleBundle-1119.exe"
2006-07-02 22:45:00 ( .D… ) "C:\Program Files\htwu"
2006-07-02 22:44:56 ( .D… ) "C:\Program Files\Cowabanga"
2006-07-02 21:09:10 ( .D… ) "C:\Program Files\WinPcap"
2006-07-02 21:09:06 ( .D… ) "C:\Program Files\Nmap"
2006-06-21 17:38:40 235228 ( A…. ) "C:\WINDOWS\system32\icon_mediamotor.exe"
2006-06-21 17:38:16 115239 ( A…. ) "C:\WINDOWS\system32\ts_mediamotor.exe"
2006-05-26 22:17:28 25992 ( A…. ) "C:\WINDOWS\system32\pgdfgsvc.exe"
2006-04-22 02:19:14 233472 ( A…. ) "C:\WINDOWS\system32\wpcap.dll"
2006-04-22 02:19:14 81920 ( A…. ) "C:\WINDOWS\system32\Packet.dll"
2006-04-22 02:19:14 61440 ( A…. ) "C:\WINDOWS\system32\WanPacket.dll"
2006-04-22 02:19:14 53299 ( A…. ) "C:\WINDOWS\system32\pthreadVC.dll"
((((((((((((((((((((((((((((((((((((((((( Files Created - Last 30days ))))))))))))))))))))))))))))))))))))))))))))))
2006-07-06 15:37 8,192 C:\WINDOWS\system32\ssiefr.EXE
2006-07-06 15:37 684,032 C:\WINDOWS\libeay32.dll
2006-07-06 15:37 492,544 C:\WINDOWS\system32\WRLogonNtf.dll
2006-07-06 15:37 478,720 C:\WINDOWS\WRUninstall.dll
2006-07-06 15:37 17,920 C:\WINDOWS\system32\wrlzma.dll
2006-07-06 15:37 155,648 C:\WINDOWS\ssleay32.dll
2006-07-06 15:37 102,912 C:\WINDOWS\system32\islzma.dll
2006-07-05 23:11 21,312 C:\WINDOWS\choice.exe
2006-07-04 14:20 331,174 C:\combofix.exe
2006-07-04 14:19 818,752 C:\blbeta.exe
2006-07-02 22:45 0 C:\WINDOWS\system32\cloudsim.exe
2006-07-02 22:44 359,634 C:\WINDOWS\media_motor_bundle.exe
2006-07-02 22:44 32,976 C:\WINDOWS\system32\uninstIcn.exe
2006-07-02 22:44 308 C:\WINDOWS\poiyb.dll
2006-07-02 22:44 178,726 C:\WINDOWS\YazzleBundle-1119.exe
2006-06-21 17:38 235,228 C:\WINDOWS\system32\icon_mediamotor.exe
2006-06-21 17:38 115,239 C:\WINDOWS\system32\ts_mediamotor.exe
2006-05-27 02:03 62,672 C:\WINDOWS\system32\xinput1_1.dll
2006-05-27 02:03 229,584 C:\WINDOWS\system32\xactengine2_1.dll
2006-05-27 02:02 61,136 C:\WINDOWS\system32\xinput9_1_0.dll
2006-05-27 02:02 230,096 C:\WINDOWS\system32\xactengine2_0.dll
2006-05-27 02:02 2,388,176 C:\WINDOWS\system32\d3dx9_30.dll
2006-05-27 02:02 2,332,368 C:\WINDOWS\system32\d3dx9_29.dll
2006-05-27 02:02 2,323,664 C:\WINDOWS\system32\d3dx9_28.dll
2006-05-27 02:02 2,222,800 C:\WINDOWS\system32\d3dx9_24.dll
2006-05-27 02:02 14,032 C:\WINDOWS\system32\x3daudio1_0.dll
((((((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"00THotkey"="C:\\WINDOWS\\System32\\00THotkey.exe"
"000StTHK"="000StTHK.exe"
"cPadAlarm"="C:\\Program Files\\Synaptics\\SynTP\\cPad\\AlarmWatcher.exe"
"TFNF5"="TFNF5.exe"
"Tpwrtray"="TPWRTRAY.EXE"
"TosHKCW.exe"="C:\\Program Files\\TOSHIBA\\Wireless Hotkey\\TosHKCW.exe"
"TFncKy"="C:\\Program Files\\Toshiba\\TOSHIBA Controls\\TFncKy.exe /Type 05"
"TDispVol"="TDispVol.exe"
"SxgTkBar"="SxgTkBar.exe"
"Logitech Utility"="Logi_MwX.Exe"
"LXSUPMON"="C:\\WINDOWS\\System32\\LXSUPMON.EXE RUN"
"vptray"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"Zone Labs Client"="\"C:\\Program Files\\ZoneAlarm\\zlclient.exe\""
"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeper.exe\" /startintray"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"msxdra"="C:\\WINDOWS\\system32\\msxdra.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,40,01,00,00,00,00,00,00,00,05,00,00,92,04,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:40000004
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Acrobat Speed Launcher.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\WINDOWS\\Installer\\{AC76BA86-1033-0000-7760-000000000002}\\SC_Acrobat.exe "
"item"="Adobe Acrobat Speed Launcher"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l"
"item"="Microsoft Office"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Paul Farnum^Start Menu^Programs^Startup^Notmad Manager.lnk]
"backup"="C:\\WINDOWS\\pss\\Notmad Manager.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\NOTMAD~1\\notmgr.exe "
"item"="Notmad Manager"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Acrotray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDElbyCDFL]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ElbyCheck"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvMcTray"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Registry Cleaner Scheduler]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Registry Cleaner Scheduler"
"hkey"="HKCU"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="vptray"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Messenger"=dword:00000002
"Fax"=dword:00000002
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"nwiz"="nwiz.exe /install"
HKEY_LOCAL_MACHINE\system\controlset001\control\safeboot\minimal\vds
HKEY_LOCAL_MACHINE\system\controlset001\control\safeboot\minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}
HKEY_LOCAL_MACHINE\system\controlset002\control\safeboot\minimal\svcWRSSSDK
HKEY_LOCAL_MACHINE\system\controlset002\control\safeboot\minimal\vds
HKEY_LOCAL_MACHINE\system\controlset002\control\safeboot\minimal\WinDefend
HKEY_LOCAL_MACHINE\system\controlset002\control\safeboot\minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}
HKEY_LOCAL_MACHINE\system\controlset003\control\safeboot\minimal\vds
HKEY_LOCAL_MACHINE\system\controlset003\control\safeboot\minimal\WinDefend
HKEY_LOCAL_MACHINE\system\controlset003\control\safeboot\minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
Completion time: Thu 07/06/2006 17:17:50.91
ComboFix ver 06.07.04 - This logfile is located at C:\ComboFix.txt
ComboFix.2006-07-05.233651.txt
ComboFix.2006-07-06.171724.txt
********
3:44 PM: | Start of Session, Thursday, July 06, 2006 |
3:44 PM: Spy Sweeper started
3:44 PM: Sweep initiated using definitions version 713
3:44 PM: Starting Memory Sweep
3:50 PM: Memory Sweep Complete, Elapsed Time: 00:05:58
3:50 PM: Starting Registry Sweep
3:50 PM: Found Adware: elitemediagroup-mediamotor
3:50 PM: HKLM\software\mm\ (1 subtraces) (ID = 140211)
3:50 PM: Found Adware: trafficsolution
3:50 PM: HKCR\bannerrotator.rotator\ (5 subtraces) (ID = 1337087)
3:50 PM: HKCR\bannerrotator.rotator.1\ (3 subtraces) (ID = 1337093)
3:50 PM: HKCR\typelib\{defdeada-c390-4eb9-97fa-59d56b21e5d5}\ (9 subtraces) (ID = 1337109)
3:50 PM: HKLM\software\classes\bannerrotator.rotator.1\ (3 subtraces) (ID = 1337124)
3:50 PM: HKLM\software\classes\typelib\{defdeada-c390-4eb9-97fa-59d56b21e5d5}\ (9 subtraces) (ID = 1337140)
3:50 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/amm06.ocx\ (2 subtraces) (ID = 1346073)
3:50 PM: Found Adware: oddbot
3:50 PM: HKCR\oddbot.adclicker.1\ (3 subtraces) (ID = 1525943)
3:50 PM: HKCR\typelib\{c845ac9a-70a6-491c-9106-d34a360e1f58}\ (9 subtraces) (ID = 1525947)
3:50 PM: HKLM\software\classes\oddbot.adclicker\ (5 subtraces) (ID = 1525973)
3:50 PM: HKLM\software\classes\oddbot.adclicker.1\ (3 subtraces) (ID = 1525979)
3:50 PM: HKLM\software\classes\typelib\{c845ac9a-70a6-491c-9106-d34a360e1f58}\ (9 subtraces) (ID = 1525983)
3:50 PM: HKCR\oddbot.adclicker\ (5 subtraces) (ID = 1527745)
3:51 PM: Registry Sweep Complete, Elapsed Time:00:00:28
3:51 PM: Starting Cookie Sweep
3:51 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
3:51 PM: Starting File Sweep
3:51 PM: Warning: Failed to open file "c:\pagefile.sys". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs01d79e58-e51d-4874-b7c7-e6200c80021f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs041e62fd-6ca4-45a0-a87a-7f33180b13f3.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0447cfc5-81d4-4b6b-a560-e30943f01a8a.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0610039d-0e9e-48e9-8db3-88bbc62b1fd5.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0799af5f-9de1-47a3-a307-6520c8b923d1.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0a4d2db9-377f-4398-a687-8b5aa33efbc1.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0a934fa6-3220-4b40-8e5d-b2af1b90a0d8.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0db6c2bb-0a02-4062-9f20-30cd12f8575f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0ee97b2c-9958-4fb9-8038-673995926f69.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs11ad8a8d-831f-4775-81f5-b9aa32472971.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs128c81d7-8d79-440d-8830-abf3b51556f9.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs163901fb-40bc-4c8c-a39f-c40e5ab582e0.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1a01f7bf-77d6-47fd-b70f-a64f7a37cc17.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1b4f8996-4062-4053-8bf7-993ca36a2dd4.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1c426766-f103-45dc-b380-5ee78c8bc0a9.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs21998d8b-e2f7-4a20-91de-e2c8805bf78c.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs21c802e7-0e9d-4cf0-b339-8c0d69d3c139.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs229e8f83-6443-47c7-bda1-e9aeb18df09d.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2950e7f3-9c3c-4a70-bef4-359b6fb003ef.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2978ef6c-20d1-4efe-99d3-d7f0c7790186.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2d07e3af-c7c0-414a-afb6-aef348d12e0d.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs32752b85-0e76-4d50-935b-5ce570df8a1b.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs35f1aad9-965a-4289-b7e1-84daebb2d011.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs366ca556-22e1-414f-b48c-32c3b285d019.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs37e23923-86e6-4991-83ff-cab886ca08e8.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs395a220c-fd8b-44ad-8a07-26fd4ee2bd7e.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3df278c4-2b55-443b-8006-dca5e1364ee1.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs41039ac1-5a05-49b9-8f06-0140df868f02.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4f668cd6-e4d6-4841-8c39-3a68e801a651.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs523f9726-2bcd-498c-93de-ad7e20d723c5.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5605c752-b93f-44d9-a9ca-bbc0caad8ff1.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs56652016-ffa5-426a-9e46-6e2cba91f8d3.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs586fd19d-d05e-4163-8102-e630587527d4.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5a142cd0-60a7-4185-b4a0-ad0d5caf88cb.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5f078734-578a-4b86-9070-c6cf6ee87fda.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs616bda64-e733-41a9-889e-582a03b5f507.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs63104588-1d4c-4ee5-9959-f9833f6f904f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs642eeb4d-7d37-4620-9613-e85f03c73704.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs66849f82-4141-447a-9fc8-4498987e9e50.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs668a9458-047b-4696-849c-7e03af97535a.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6857d578-9d37-42bf-b135-cb1bc6465488.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs69d78532-bf54-4013-bf70-cd5b72ca7cfa.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6b5b37ae-2383-4dc5-8dfd-f92d8dcb6033.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6ba64817-3330-4331-990b-349f02275598.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6cefca5e-6fb4-4d50-8518-3dd013876350.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6d1099e4-4dcc-4234-9b4c-f6839e766b75.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6dd2996a-3f77-4861-b583-4e776b4162b6.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6f6f1a3d-553e-4425-990b-de7bc682018d.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs731b9be1-f656-43f6-b6ff-738ff16ba95d.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs749d7804-8302-48b9-ae70-b9ad7c7bdc9b.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs75a802ed-703d-4431-ad4c-896619b14c2f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7725aef1-eb9a-4516-b777-85876e2c078e.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs789ebc81-35f3-4275-9543-e446566d76e8.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7fd80943-5d53-4e44-93c7-9d1975d3fcbf.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8111f2d4-a25d-4d67-b2d9-4d3146e3a660.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs82dc2ed8-4efc-4f16-973f-2bc947066689.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8344261b-f675-472d-b8ef-2bda3191d7b0.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs83676380-b830-4aa4-a523-7406a6be78ba.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs86ab2290-959a-42fa-835f-c7dda9336a87.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8a281f4e-89fa-4394-b734-3c967a567e24.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8b7dac8b-4118-46f8-88f7-5c0d076f2a0c.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8cf10092-50d1-44f2-9cd9-f1308e22d94c.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs90338ff6-68bc-4f91-824c-d7e1c8d23345.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs912ca8bc-f354-44a5-9d3b-5c6dda75a77f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs92847e4b-01c6-4e17-8507-ed5b31fa8619.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs958768fb-58e9-43c3-822b-8df4c380f3a0.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs962fa74d-5053-4994-899b-538bafb6572e.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs96ed5f96-d131-49f5-a75d-7cd4b8b08c9f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa283ca2b-309c-4e30-9576-385b810a7578.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa7bb2cf5-caba-4438-b7ca-c11b45c53fc1.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsad807bca-3581-42fe-ad2c-122c1a263ce9.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsaefbccbe-bf85-4a34-aa03-1aa3a64b40ee.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsaf725b56-f03b-4925-a04f-53fa2d6917f3.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb08d5e6d-5a75-4dc7-a6ae-3bbb1b0804ac.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb29a9475-8387-4624-814a-01d32789d9ee.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbe264f20-2091-4cb8-b64a-fff74eb44acc.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc190814a-e894-4d2a-909a-671b250b16da.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc3f6afba-b492-4113-b930-b61506d4c34c.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc5473585-08d9-441e-9901-00e6490a15f7.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc55483c0-cd20-46f8-8495-88c10917aa39.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc6a94a86-6815-48d5-bc8c-6e498d1f4992.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsca2eb44f-7b67-436e-b817-86496c21d711.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscacc3b5e-913c-42d7-ba98-ef647b1e09fd.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscb4fd253-6a48-40f6-ada3-de20b2327761.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscba2e959-54e8-401d-b42e-e8b06099aa4c.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscce4be90-01fc-4909-bae8-13403f44c1b6.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscf20cb85-3aa3-4577-a3c2-9f0b71ce1e1c.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd48558cb-394f-45fd-b209-804a5c618d8c.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsdcdf2c30-24b5-45b4-af71-5877a384f94f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse1f278ee-4ef0-4bd4-bde1-d5725b177a98.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse25ae5f8-38d6-4705-a85e-6d468e2355e0.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse44f20e5-6a7c-4ae5-8be9-bafa3e249eb4.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse4a35052-0713-421d-a8ea-4a4d277a138b.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse4b354af-5a3d-4d7d-8043-5f9ef8b147a7.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse9a43a75-109c-470f-a822-c13fb5d8ec93.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsed36202b-846d-42b8-b770-1a4d73542f53.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsee3b91bd-f7d5-4bca-a6d9-8084dc1bb117.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscseed0f4ad-c628-479a-b368-9f2ac750655e.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf22bc028-68a4-4c00-8654-2a043732332d.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf2fbd938-93de-4488-bd04-effc218ab579.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf4ed1a47-7c30-40af-824b-cb61d41565b4.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf906a1d0-9cd9-4e3b-8244-665235f9fb32.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsfec273c8-fa53-4b10-9061-53fdcb97623f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsfeed6780-cfef-4661-9ed4-31091f333046.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\paul farnum\ntuser.dat". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\paul farnum\ntuser.dat.log". The process cannot access the file because it is being used by another process
3:53 PM: Warning: Failed to open file "c:\documents and settings\paul farnum\application data\mozilla\firefox\profiles\oio8c3pk.default\parent.lock". The process cannot access the file because it is being used by another process
3:53 PM: Warning: Failed to open file "c:\documents and settings\paul farnum\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
3:53 PM: Warning: Failed to open file "c:\documents and settings\paul farnum\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
3:53 PM: Warning: Failed to open file "c:\documents and settings\paul farnum\local settings\application data\microsoft\windows defender\filetracker\{ede50b76-dd0f-4e39-91e5-4cf4f06e0906}". The process cannot access the file because it is being used by another process
4:17 PM: Warning: Failed to open file "c:\recycler\nprotect\00144311.". The system cannot find the file specified
4:17 PM: Warning: Failed to open file "c:\recycler\nprotect\00144312.". The system cannot find the file specified
4:18 PM: Found Trojan Horse: trojan-dropper-chad
4:18 PM: chad_bundle.exe (ID = 320230)
4:26 PM: amm06.inf (ID = 297265)
4:37 PM: icon_chad.exe (ID = 319900)
4:41 PM: safe.tlb (ID = 318895)
4:41 PM: Found Adware: ezula ilookup
4:41 PM: ts_chad.exe (ID = 320007)
4:42 PM: Warning: Failed to open file "c:\windows\system32\catroot2\edb.log". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\catroot2\tmp.edb". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\default". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\default.log". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\sam". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\sam.log". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\security". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\security.log". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\software". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\software.log". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\system". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\system.log". The process cannot access the file because it is being used by another process
4:43 PM: Warning: Failed to open file "c:\windows\system32\drivers\atapi.sys". The process cannot access the file because it is being used by another process
4:43 PM: Warning: Failed to open file "c:\windows\system32\drivers\dtscsi.sys". The process cannot access the file because it is being used by another process
4:43 PM: Warning: Failed to open file "c:\windows\system32\drivers\sptd.sys". The process cannot access the file because it is being used by another process
4:43 PM: Warning: Failed to open file "c:\windows\system32\drivers\sptd9661.sys". The process cannot access the file because it is being used by another process
4:46 PM: Warning: Failed to open file "c:\windows\temp\zlt05887.tmp". The process cannot access the file because it is being used by another process
4:58 PM: Warning: Unhandled Archive Type
5:11 PM: File Sweep Complete, Elapsed Time: 01:20:02
5:11 PM: Full Sweep has completed. Elapsed time 01:26:33
5:11 PM: Traces Found: 84
5:15 PM: Removal process initiated
5:15 PM: Quarantining All Traces: elitemediagroup-mediamotor
5:15 PM: Quarantining All Traces: trafficsolution
5:15 PM: Quarantining All Traces: trojan-dropper-chad
5:15 PM: Quarantining All Traces: ezula ilookup
5:15 PM: Quarantining All Traces: oddbot
5:15 PM: Removal process completed. Elapsed time 00:00:05
********
3:37 PM: | Start of Session, Thursday, July 06, 2006 |
3:37 PM: Spy Sweeper started
3:38 PM: Your spyware definitions have been updated.
3:44 PM: | End of Session, Thursday, July 06, 2006 |
Logfile of HijackThis v1.99.1
Scan saved at 5:19:23 PM, on 7/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\00THotkey.exe
C:\Program Files\Synaptics\SynTP\cPad\AlarmWatcher.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TDispVol.exe
C:\WINDOWS\system32\SxgTkBar.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\ZoneAlarm\zlclient.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.stedwards.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=localhost:8080;gopher=localhost:8080;http=localhost:8080;https=localhost:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2
btw, does combofix trigger diskcleanup to initiate? diskcleanup has curiously launched a few times, and most recently right after combofix finished but before the log popped up
here are my logs:
Start Time= Thu 07/06/2006 17:17:24.29
Running from: C:\
QuickScan did not find any signs of infected files
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-07-06 15:37:30 ( .D… ) "C:\Program Files\Webroot"
2006-07-06 15:37:30 ( .D… ) "C:\Documents and Settings\Paul Farnum\Application Data\Webroot"
2006-07-06 06:38:16 ( .D… ) "C:\Documents and Settings\Paul Farnum\Application Data\Mozilla"
2006-07-06 06:37:44 ( .D… ) "C:\Program Files\Mozilla Firefox"
2006-07-06 06:33:16 ( .D… ) "C:\Program Files\Google"
2006-07-05 22:49:32 0 ( A…. ) "C:\Documents and Settings\Paul Farnum\Application Data\internaldb41.dat"
2006-07-04 14:20:46 331174 ( A…. ) "C:\combofix.exe"
2006-07-04 14:19:54 818752 ( A…. ) "C:\blbeta.exe"
2006-07-03 12:26:16 ( .D… ) "C:\Documents and Settings\Paul Farnum\Application Data\PC Tools"
2006-07-03 10:24:44 ( .D… ) "C:\Program Files\ewido anti-spyware 4.0"
2006-07-03 10:13:44 ( .D… ) "C:\Program Files\Spyware Doctor"
2006-07-03 00:12:52 ( .D… ) "C:\Program Files\Windows Defender"
2006-07-03 00:08:22 308 ( A…. ) "C:\WINDOWS\poiyb.dll"
2006-07-02 22:48:28 32976 ( A…. ) "C:\WINDOWS\system32\uninstIcn.exe"
2006-07-02 22:45:26 0 ( A…. ) "C:\WINDOWS\system32\cloudsim.exe"
2006-07-02 22:45:20 359634 ( A…. ) "C:\WINDOWS\media_motor_bundle.exe"
2006-07-02 22:45:20 178726 ( A…. ) "C:\WINDOWS\YazzleBundle-1119.exe"
2006-07-02 22:45:00 ( .D… ) "C:\Program Files\htwu"
2006-07-02 22:44:56 ( .D… ) "C:\Program Files\Cowabanga"
2006-07-02 21:09:10 ( .D… ) "C:\Program Files\WinPcap"
2006-07-02 21:09:06 ( .D… ) "C:\Program Files\Nmap"
2006-06-21 17:38:40 235228 ( A…. ) "C:\WINDOWS\system32\icon_mediamotor.exe"
2006-06-21 17:38:16 115239 ( A…. ) "C:\WINDOWS\system32\ts_mediamotor.exe"
2006-05-26 22:17:28 25992 ( A…. ) "C:\WINDOWS\system32\pgdfgsvc.exe"
2006-04-22 02:19:14 233472 ( A…. ) "C:\WINDOWS\system32\wpcap.dll"
2006-04-22 02:19:14 81920 ( A…. ) "C:\WINDOWS\system32\Packet.dll"
2006-04-22 02:19:14 61440 ( A…. ) "C:\WINDOWS\system32\WanPacket.dll"
2006-04-22 02:19:14 53299 ( A…. ) "C:\WINDOWS\system32\pthreadVC.dll"
((((((((((((((((((((((((((((((((((((((((( Files Created - Last 30days ))))))))))))))))))))))))))))))))))))))))))))))
2006-07-06 15:37 8,192 C:\WINDOWS\system32\ssiefr.EXE
2006-07-06 15:37 684,032 C:\WINDOWS\libeay32.dll
2006-07-06 15:37 492,544 C:\WINDOWS\system32\WRLogonNtf.dll
2006-07-06 15:37 478,720 C:\WINDOWS\WRUninstall.dll
2006-07-06 15:37 17,920 C:\WINDOWS\system32\wrlzma.dll
2006-07-06 15:37 155,648 C:\WINDOWS\ssleay32.dll
2006-07-06 15:37 102,912 C:\WINDOWS\system32\islzma.dll
2006-07-05 23:11 21,312 C:\WINDOWS\choice.exe
2006-07-04 14:20 331,174 C:\combofix.exe
2006-07-04 14:19 818,752 C:\blbeta.exe
2006-07-02 22:45 0 C:\WINDOWS\system32\cloudsim.exe
2006-07-02 22:44 359,634 C:\WINDOWS\media_motor_bundle.exe
2006-07-02 22:44 32,976 C:\WINDOWS\system32\uninstIcn.exe
2006-07-02 22:44 308 C:\WINDOWS\poiyb.dll
2006-07-02 22:44 178,726 C:\WINDOWS\YazzleBundle-1119.exe
2006-06-21 17:38 235,228 C:\WINDOWS\system32\icon_mediamotor.exe
2006-06-21 17:38 115,239 C:\WINDOWS\system32\ts_mediamotor.exe
2006-05-27 02:03 62,672 C:\WINDOWS\system32\xinput1_1.dll
2006-05-27 02:03 229,584 C:\WINDOWS\system32\xactengine2_1.dll
2006-05-27 02:02 61,136 C:\WINDOWS\system32\xinput9_1_0.dll
2006-05-27 02:02 230,096 C:\WINDOWS\system32\xactengine2_0.dll
2006-05-27 02:02 2,388,176 C:\WINDOWS\system32\d3dx9_30.dll
2006-05-27 02:02 2,332,368 C:\WINDOWS\system32\d3dx9_29.dll
2006-05-27 02:02 2,323,664 C:\WINDOWS\system32\d3dx9_28.dll
2006-05-27 02:02 2,222,800 C:\WINDOWS\system32\d3dx9_24.dll
2006-05-27 02:02 14,032 C:\WINDOWS\system32\x3daudio1_0.dll
((((((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"00THotkey"="C:\\WINDOWS\\System32\\00THotkey.exe"
"000StTHK"="000StTHK.exe"
"cPadAlarm"="C:\\Program Files\\Synaptics\\SynTP\\cPad\\AlarmWatcher.exe"
"TFNF5"="TFNF5.exe"
"Tpwrtray"="TPWRTRAY.EXE"
"TosHKCW.exe"="C:\\Program Files\\TOSHIBA\\Wireless Hotkey\\TosHKCW.exe"
"TFncKy"="C:\\Program Files\\Toshiba\\TOSHIBA Controls\\TFncKy.exe /Type 05"
"TDispVol"="TDispVol.exe"
"SxgTkBar"="SxgTkBar.exe"
"Logitech Utility"="Logi_MwX.Exe"
"LXSUPMON"="C:\\WINDOWS\\System32\\LXSUPMON.EXE RUN"
"vptray"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"Zone Labs Client"="\"C:\\Program Files\\ZoneAlarm\\zlclient.exe\""
"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeper.exe\" /startintray"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"msxdra"="C:\\WINDOWS\\system32\\msxdra.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,40,01,00,00,00,00,00,00,00,05,00,00,92,04,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:40000004
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Acrobat Speed Launcher.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\WINDOWS\\Installer\\{AC76BA86-1033-0000-7760-000000000002}\\SC_Acrobat.exe "
"item"="Adobe Acrobat Speed Launcher"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l"
"item"="Microsoft Office"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Paul Farnum^Start Menu^Programs^Startup^Notmad Manager.lnk]
"backup"="C:\\WINDOWS\\pss\\Notmad Manager.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\NOTMAD~1\\notmgr.exe "
"item"="Notmad Manager"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Acrotray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDElbyCDFL]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ElbyCheck"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvMcTray"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Registry Cleaner Scheduler]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Registry Cleaner Scheduler"
"hkey"="HKCU"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="vptray"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Messenger"=dword:00000002
"Fax"=dword:00000002
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"nwiz"="nwiz.exe /install"
HKEY_LOCAL_MACHINE\system\controlset001\control\safeboot\minimal\vds
HKEY_LOCAL_MACHINE\system\controlset001\control\safeboot\minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}
HKEY_LOCAL_MACHINE\system\controlset002\control\safeboot\minimal\svcWRSSSDK
HKEY_LOCAL_MACHINE\system\controlset002\control\safeboot\minimal\vds
HKEY_LOCAL_MACHINE\system\controlset002\control\safeboot\minimal\WinDefend
HKEY_LOCAL_MACHINE\system\controlset002\control\safeboot\minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}
HKEY_LOCAL_MACHINE\system\controlset003\control\safeboot\minimal\vds
HKEY_LOCAL_MACHINE\system\controlset003\control\safeboot\minimal\WinDefend
HKEY_LOCAL_MACHINE\system\controlset003\control\safeboot\minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
Completion time: Thu 07/06/2006 17:17:50.91
ComboFix ver 06.07.04 - This logfile is located at C:\ComboFix.txt
ComboFix.2006-07-05.233651.txt
ComboFix.2006-07-06.171724.txt
********
3:44 PM: | Start of Session, Thursday, July 06, 2006 |
3:44 PM: Spy Sweeper started
3:44 PM: Sweep initiated using definitions version 713
3:44 PM: Starting Memory Sweep
3:50 PM: Memory Sweep Complete, Elapsed Time: 00:05:58
3:50 PM: Starting Registry Sweep
3:50 PM: Found Adware: elitemediagroup-mediamotor
3:50 PM: HKLM\software\mm\ (1 subtraces) (ID = 140211)
3:50 PM: Found Adware: trafficsolution
3:50 PM: HKCR\bannerrotator.rotator\ (5 subtraces) (ID = 1337087)
3:50 PM: HKCR\bannerrotator.rotator.1\ (3 subtraces) (ID = 1337093)
3:50 PM: HKCR\typelib\{defdeada-c390-4eb9-97fa-59d56b21e5d5}\ (9 subtraces) (ID = 1337109)
3:50 PM: HKLM\software\classes\bannerrotator.rotator.1\ (3 subtraces) (ID = 1337124)
3:50 PM: HKLM\software\classes\typelib\{defdeada-c390-4eb9-97fa-59d56b21e5d5}\ (9 subtraces) (ID = 1337140)
3:50 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/amm06.ocx\ (2 subtraces) (ID = 1346073)
3:50 PM: Found Adware: oddbot
3:50 PM: HKCR\oddbot.adclicker.1\ (3 subtraces) (ID = 1525943)
3:50 PM: HKCR\typelib\{c845ac9a-70a6-491c-9106-d34a360e1f58}\ (9 subtraces) (ID = 1525947)
3:50 PM: HKLM\software\classes\oddbot.adclicker\ (5 subtraces) (ID = 1525973)
3:50 PM: HKLM\software\classes\oddbot.adclicker.1\ (3 subtraces) (ID = 1525979)
3:50 PM: HKLM\software\classes\typelib\{c845ac9a-70a6-491c-9106-d34a360e1f58}\ (9 subtraces) (ID = 1525983)
3:50 PM: HKCR\oddbot.adclicker\ (5 subtraces) (ID = 1527745)
3:51 PM: Registry Sweep Complete, Elapsed Time:00:00:28
3:51 PM: Starting Cookie Sweep
3:51 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
3:51 PM: Starting File Sweep
3:51 PM: Warning: Failed to open file "c:\pagefile.sys". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs01d79e58-e51d-4874-b7c7-e6200c80021f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs041e62fd-6ca4-45a0-a87a-7f33180b13f3.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0447cfc5-81d4-4b6b-a560-e30943f01a8a.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0610039d-0e9e-48e9-8db3-88bbc62b1fd5.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0799af5f-9de1-47a3-a307-6520c8b923d1.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0a4d2db9-377f-4398-a687-8b5aa33efbc1.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0a934fa6-3220-4b40-8e5d-b2af1b90a0d8.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0db6c2bb-0a02-4062-9f20-30cd12f8575f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0ee97b2c-9958-4fb9-8038-673995926f69.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs11ad8a8d-831f-4775-81f5-b9aa32472971.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs128c81d7-8d79-440d-8830-abf3b51556f9.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs163901fb-40bc-4c8c-a39f-c40e5ab582e0.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1a01f7bf-77d6-47fd-b70f-a64f7a37cc17.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1b4f8996-4062-4053-8bf7-993ca36a2dd4.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1c426766-f103-45dc-b380-5ee78c8bc0a9.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs21998d8b-e2f7-4a20-91de-e2c8805bf78c.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs21c802e7-0e9d-4cf0-b339-8c0d69d3c139.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs229e8f83-6443-47c7-bda1-e9aeb18df09d.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2950e7f3-9c3c-4a70-bef4-359b6fb003ef.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2978ef6c-20d1-4efe-99d3-d7f0c7790186.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2d07e3af-c7c0-414a-afb6-aef348d12e0d.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs32752b85-0e76-4d50-935b-5ce570df8a1b.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs35f1aad9-965a-4289-b7e1-84daebb2d011.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs366ca556-22e1-414f-b48c-32c3b285d019.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs37e23923-86e6-4991-83ff-cab886ca08e8.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs395a220c-fd8b-44ad-8a07-26fd4ee2bd7e.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3df278c4-2b55-443b-8006-dca5e1364ee1.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs41039ac1-5a05-49b9-8f06-0140df868f02.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4f668cd6-e4d6-4841-8c39-3a68e801a651.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs523f9726-2bcd-498c-93de-ad7e20d723c5.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5605c752-b93f-44d9-a9ca-bbc0caad8ff1.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs56652016-ffa5-426a-9e46-6e2cba91f8d3.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs586fd19d-d05e-4163-8102-e630587527d4.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5a142cd0-60a7-4185-b4a0-ad0d5caf88cb.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5f078734-578a-4b86-9070-c6cf6ee87fda.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs616bda64-e733-41a9-889e-582a03b5f507.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs63104588-1d4c-4ee5-9959-f9833f6f904f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs642eeb4d-7d37-4620-9613-e85f03c73704.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs66849f82-4141-447a-9fc8-4498987e9e50.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs668a9458-047b-4696-849c-7e03af97535a.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6857d578-9d37-42bf-b135-cb1bc6465488.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs69d78532-bf54-4013-bf70-cd5b72ca7cfa.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6b5b37ae-2383-4dc5-8dfd-f92d8dcb6033.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6ba64817-3330-4331-990b-349f02275598.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6cefca5e-6fb4-4d50-8518-3dd013876350.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6d1099e4-4dcc-4234-9b4c-f6839e766b75.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6dd2996a-3f77-4861-b583-4e776b4162b6.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6f6f1a3d-553e-4425-990b-de7bc682018d.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs731b9be1-f656-43f6-b6ff-738ff16ba95d.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs749d7804-8302-48b9-ae70-b9ad7c7bdc9b.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs75a802ed-703d-4431-ad4c-896619b14c2f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7725aef1-eb9a-4516-b777-85876e2c078e.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs789ebc81-35f3-4275-9543-e446566d76e8.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7fd80943-5d53-4e44-93c7-9d1975d3fcbf.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8111f2d4-a25d-4d67-b2d9-4d3146e3a660.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs82dc2ed8-4efc-4f16-973f-2bc947066689.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8344261b-f675-472d-b8ef-2bda3191d7b0.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs83676380-b830-4aa4-a523-7406a6be78ba.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs86ab2290-959a-42fa-835f-c7dda9336a87.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8a281f4e-89fa-4394-b734-3c967a567e24.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8b7dac8b-4118-46f8-88f7-5c0d076f2a0c.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8cf10092-50d1-44f2-9cd9-f1308e22d94c.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs90338ff6-68bc-4f91-824c-d7e1c8d23345.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs912ca8bc-f354-44a5-9d3b-5c6dda75a77f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs92847e4b-01c6-4e17-8507-ed5b31fa8619.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs958768fb-58e9-43c3-822b-8df4c380f3a0.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs962fa74d-5053-4994-899b-538bafb6572e.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs96ed5f96-d131-49f5-a75d-7cd4b8b08c9f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa283ca2b-309c-4e30-9576-385b810a7578.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa7bb2cf5-caba-4438-b7ca-c11b45c53fc1.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsad807bca-3581-42fe-ad2c-122c1a263ce9.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsaefbccbe-bf85-4a34-aa03-1aa3a64b40ee.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsaf725b56-f03b-4925-a04f-53fa2d6917f3.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb08d5e6d-5a75-4dc7-a6ae-3bbb1b0804ac.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb29a9475-8387-4624-814a-01d32789d9ee.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbe264f20-2091-4cb8-b64a-fff74eb44acc.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc190814a-e894-4d2a-909a-671b250b16da.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc3f6afba-b492-4113-b930-b61506d4c34c.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc5473585-08d9-441e-9901-00e6490a15f7.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc55483c0-cd20-46f8-8495-88c10917aa39.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc6a94a86-6815-48d5-bc8c-6e498d1f4992.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsca2eb44f-7b67-436e-b817-86496c21d711.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscacc3b5e-913c-42d7-ba98-ef647b1e09fd.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscb4fd253-6a48-40f6-ada3-de20b2327761.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscba2e959-54e8-401d-b42e-e8b06099aa4c.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscce4be90-01fc-4909-bae8-13403f44c1b6.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscf20cb85-3aa3-4577-a3c2-9f0b71ce1e1c.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd48558cb-394f-45fd-b209-804a5c618d8c.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsdcdf2c30-24b5-45b4-af71-5877a384f94f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse1f278ee-4ef0-4bd4-bde1-d5725b177a98.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse25ae5f8-38d6-4705-a85e-6d468e2355e0.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse44f20e5-6a7c-4ae5-8be9-bafa3e249eb4.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse4a35052-0713-421d-a8ea-4a4d277a138b.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse4b354af-5a3d-4d7d-8043-5f9ef8b147a7.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse9a43a75-109c-470f-a822-c13fb5d8ec93.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsed36202b-846d-42b8-b770-1a4d73542f53.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsee3b91bd-f7d5-4bca-a6d9-8084dc1bb117.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscseed0f4ad-c628-479a-b368-9f2ac750655e.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf22bc028-68a4-4c00-8654-2a043732332d.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf2fbd938-93de-4488-bd04-effc218ab579.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf4ed1a47-7c30-40af-824b-cb61d41565b4.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf906a1d0-9cd9-4e3b-8244-665235f9fb32.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsfec273c8-fa53-4b10-9061-53fdcb97623f.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsfeed6780-cfef-4661-9ed4-31091f333046.tmp". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\paul farnum\ntuser.dat". The process cannot access the file because it is being used by another process
3:52 PM: Warning: Failed to open file "c:\documents and settings\paul farnum\ntuser.dat.log". The process cannot access the file because it is being used by another process
3:53 PM: Warning: Failed to open file "c:\documents and settings\paul farnum\application data\mozilla\firefox\profiles\oio8c3pk.default\parent.lock". The process cannot access the file because it is being used by another process
3:53 PM: Warning: Failed to open file "c:\documents and settings\paul farnum\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
3:53 PM: Warning: Failed to open file "c:\documents and settings\paul farnum\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
3:53 PM: Warning: Failed to open file "c:\documents and settings\paul farnum\local settings\application data\microsoft\windows defender\filetracker\{ede50b76-dd0f-4e39-91e5-4cf4f06e0906}". The process cannot access the file because it is being used by another process
4:17 PM: Warning: Failed to open file "c:\recycler\nprotect\00144311.". The system cannot find the file specified
4:17 PM: Warning: Failed to open file "c:\recycler\nprotect\00144312.". The system cannot find the file specified
4:18 PM: Found Trojan Horse: trojan-dropper-chad
4:18 PM: chad_bundle.exe (ID = 320230)
4:26 PM: amm06.inf (ID = 297265)
4:37 PM: icon_chad.exe (ID = 319900)
4:41 PM: safe.tlb (ID = 318895)
4:41 PM: Found Adware: ezula ilookup
4:41 PM: ts_chad.exe (ID = 320007)
4:42 PM: Warning: Failed to open file "c:\windows\system32\catroot2\edb.log". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\catroot2\tmp.edb". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\default". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\default.log". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\sam". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\sam.log". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\security". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\security.log". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\software". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\software.log". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\system". The process cannot access the file because it is being used by another process
4:42 PM: Warning: Failed to open file "c:\windows\system32\config\system.log". The process cannot access the file because it is being used by another process
4:43 PM: Warning: Failed to open file "c:\windows\system32\drivers\atapi.sys". The process cannot access the file because it is being used by another process
4:43 PM: Warning: Failed to open file "c:\windows\system32\drivers\dtscsi.sys". The process cannot access the file because it is being used by another process
4:43 PM: Warning: Failed to open file "c:\windows\system32\drivers\sptd.sys". The process cannot access the file because it is being used by another process
4:43 PM: Warning: Failed to open file "c:\windows\system32\drivers\sptd9661.sys". The process cannot access the file because it is being used by another process
4:46 PM: Warning: Failed to open file "c:\windows\temp\zlt05887.tmp". The process cannot access the file because it is being used by another process
4:58 PM: Warning: Unhandled Archive Type
5:11 PM: File Sweep Complete, Elapsed Time: 01:20:02
5:11 PM: Full Sweep has completed. Elapsed time 01:26:33
5:11 PM: Traces Found: 84
5:15 PM: Removal process initiated
5:15 PM: Quarantining All Traces: elitemediagroup-mediamotor
5:15 PM: Quarantining All Traces: trafficsolution
5:15 PM: Quarantining All Traces: trojan-dropper-chad
5:15 PM: Quarantining All Traces: ezula ilookup
5:15 PM: Quarantining All Traces: oddbot
5:15 PM: Removal process completed. Elapsed time 00:00:05
********
3:37 PM: | Start of Session, Thursday, July 06, 2006 |
3:37 PM: Spy Sweeper started
3:38 PM: Your spyware definitions have been updated.
3:44 PM: | End of Session, Thursday, July 06, 2006 |
Logfile of HijackThis v1.99.1
Scan saved at 5:19:23 PM, on 7/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\00THotkey.exe
C:\Program Files\Synaptics\SynTP\cPad\AlarmWatcher.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TDispVol.exe
C:\WINDOWS\system32\SxgTkBar.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\ZoneAlarm\zlclient.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.stedwards.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=localhost:8080;gopher=localhost:8080;http=localhost:8080;https=localhost:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2