This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

about:blank; unable to remove

52 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was prompted on the task bar to download new Mcafee stuff. Afterwards, my computer began operating slower and slower. about:blank pops into the URLs. From reading some info, I have to get the re-enabler (do not know the technical description) removed: essentially it re-installs the bad stuff after you remove the scripting in the registry. Can someone help me get about:blank entirely remove? Also, I am practically illiterate when comes to fixing computer issues, so please explain thoroughly with concern for how to make the changes. thanks a lot. Hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 4:20:21 PM, on 8/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\eFax Messenger 4.0\J2GDllCmd.exe
C:\Program Files\eFax Messenger 4.0\J2GTray.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\MPS\mps.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Documents and Settings\Owner\My Documents\Clint's stuff Folder\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: eFax DllCmd 4.0.lnk = C:\Program Files\eFax Messenger 4.0\J2GDllCmd.exe
O4 - Global Startup: eFax Tray Menu 4.0.lnk = C:\Program Files\eFax Messenger 4.0\J2GTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mctskshd.exe
O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\Program Files\McAfee\MPS\mps.exe
Hello Clint and Welcome to TomCoyote,

Please do the following:

STEP 1.
======
SpySweeper
Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

If you are taken to the internet page, just close the page.

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.


STEP 2.
======
The Ewido program’s detection rate is excellent. After the Trial has expired, the auto updates and real time protection stop but you can still update it manually and run scans anytime you want.

First download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the
    results of the ewido report scan.
Empty Recycle Bin
Reboot

Please post the results from SpySweeper, ewido and a new hijackthis log.
Susan, thanks for helping me. I am posting the logs you requested. Also, just as some information I have found concerning about:blank, a person at castlecops helping someone else with this same problem wrote that the main problem is a .dll file that is hidden even from viewing in the registry. Somehow we have to get rid of that file, and apparently it continues to change its name. There was not a detailed explanation of how they fixed the problem before though.

Hijack This New log:

Logfile of HijackThis v1.99.1
Scan saved at 5:04:20 PM, on 8/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\eFax Messenger 4.0\J2GDllCmd.exe
C:\Program Files\eFax Messenger 4.0\J2GTray.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\McAfee\MPS\mps.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Documents and Settings\Owner\My Documents\Clint's stuff Folder\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: eFax DllCmd 4.0.lnk = C:\Program Files\eFax Messenger 4.0\J2GDllCmd.exe
O4 - Global Startup: eFax Tray Menu 4.0.lnk = C:\Program Files\eFax Messenger 4.0\J2GTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mctskshd.exe
O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\Program Files\McAfee\MPS\mps.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

SpySweeper Log
3:25 PM: Removal process completed. Elapsed time 00:00:10
3:25 PM: Quarantining All Traces: mediaplex cookie
3:25 PM: Quarantining All Traces: atlas dmt cookie
3:25 PM: Quarantining All Traces: advertising cookie
3:25 PM: Removal process initiated
3:14 PM: Traces Found: 3
3:14 PM: Full Sweep has completed. Elapsed time 00:21:08
3:14 PM: File Sweep Complete, Elapsed Time: 00:16:00
3:11 PM: Warning: Failed to open file "c:\windows\temp\sqlite_8iurwd7pyghwhyi". The operation completed successfully
3:11 PM: Warning: Failed to open file "c:\windows\temp\sqlite_jidt8eoruzfatxa". The operation completed successfully
2:58 PM: Starting File Sweep
2:58 PM: Cookie Sweep Complete, Elapsed Time: 00:00:02
2:58 PM: c:\documents and settings\owner\cookies\owner@mediaplex[2].txt (ID = 6442)
2:58 PM: Found Spy Cookie: mediaplex cookie
2:58 PM: c:\documents and settings\owner\cookies\owner@atdmt[2].txt (ID = 2253)
2:58 PM: Found Spy Cookie: atlas dmt cookie
2:58 PM: c:\documents and settings\owner\cookies\owner@advertising[2].txt (ID = 2175)
2:58 PM: Found Spy Cookie: advertising cookie
2:58 PM: Starting Cookie Sweep
2:58 PM: Registry Sweep Complete, Elapsed Time:00:00:49
2:57 PM: Starting Registry Sweep
2:57 PM: Memory Sweep Complete, Elapsed Time: 00:04:03
2:53 PM: Starting Memory Sweep
2:53 PM: Sweep initiated using definitions version 691
2:53 PM: Spy Sweeper 5.0.5.1286 started
2:53 PM: | Start of Session, Saturday, August 12, 2006 |
********
2:53 PM: | End of Session, Saturday, August 12, 2006 |
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
2:48 PM: Shield States
2:48 PM: Spyware Definitions: 691
2:46 PM: Spy Sweeper 5.0.5.1286 started
2:46 PM: Spy Sweeper 5.0.5.1286 started
2:46 PM: | Start of Session, Saturday, August 12, 2006 |
********

Ewido Log

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 4:50:48 PM 8/12/2006

+ Scan result:



C:\Program Files\WebEx\ieatgpc.dll -> Adware.WebEx : Cleaned with backup (quarantined).
C:\Program Files\WebEx\ieatgpc.tmp/ieatgpc.dll -> Adware.WebEx : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Cookies\owner@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).


::Report end

Let me know what we need to do next. Thanks again
Hello Clint,

Your log does not show the typical CWS infection, however, let's do the following:

STEP 1.
======
Please download ATF Cleaner by Atribune.

This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

STEP 2.
======
AboutBuster
  • Download AboutBuster.
    http://www.malwarebytes.org/AboutBuster.zip
  • Unzip AboutBuster in an own folder such as C:\AboutBuster.
  • Start AboutBuster.exe. Click OK, Update, Check For Update and download the updates if present.
  • Start Aboutbuster and let it scan. When the scan is done and you choose exit, it will automatically create a log in the same folder where aboutbuster is in.
  • Please post the results in your next reply.
STEP 3.
======
Dllcompare

Dllcompare is a scanner to help detect hidden or non-accessible files in Windows, like the CWS super-hidden dll.

Please download and run Dllcompare
  • Click the Compare button to start the sorting process.
    Files in the upper portion have been verified to "exist" as where Files in the bottom section have some form of problem being accessed.
    There will be only minimal, if any files listed there… once that Compare scan is complete, and you find you have a few files listed in the lower box.
  • Click on any of the listed entries to select it.. Right click the mouse and use the Option Rescan
    This will run the file through the standard Windows Find and if it does exist, will be removed from the list (to further filter the found objects) After that if you are left with files that are still not found,
  • click the Make a Log of what was found button,
Please post with the log in your next reply.

STEP 4.
======
Open Internet Explorer and on the menu click Tools, click Internet Options, and then click Use Current. at Restart your computer, and then restart Internet Explorer.

Please be sure you replied with the results from AboutBuster, DllCompare, and let me know if you were able to change your homepage.
Susan, I have completed your tasks and these are the logs. Does not look like much information. I can tell you my computer is working harder and harder, definitely slowing down even more. The homepage was changed and remained after restart. Some more info: On the open browser pages, when I move from one site to the next(leaving one site for the next site), about:blank appears at the bottom left on the bar next to Internet Explorer icon. the about: blank flashes for a second and is gone. Do not know how that info might help, but thought you should know. About Buster Log AboutBuster 6.05 Scan started on [8/13/2006] at [10:47:13 AM] ————————————————————- Internet Explorer Instances Terminated! HomeSearch Service stopped if present ————————————————————- No Ads Found! ————————————————————- No Files Found! ————————————————————- Scan was COMPLETED SUCCESSFULLY at 10:49:39 AM DllCompare Log * DLLCompare Log version(1.0.0.127) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ O^E says: "There were no files found :)" ________________________________________________ 1,230 items found: 1,230 files (1 H/S), 0 directories. Total of file sizes: 265,286,265 bytes 252.99 M Administrator Account = True ——————–End log——————— The only file Dll found turned out to be okay and removed from list. What do we do next? Thanks
Some more info Susan. McAfee recorded this log for me, of a malware attack. Even though this does not show the .dll info, it definitely is from the registry and is .dll. At the end are a few of changes that keep popping into history of Internet Explorer. McAfee has detected a potentially unauthorized change to your computer. Details SystemGuard Name: Internet Explorer Bars Change: Registry Created More Info SystemGuard Description: Monitors changes made to your list of Internet Explorer Bar programs. An explorer bar is a pane like the Search, Favorites, or History panes that you see in Internet Explorer (IE) or Windows Explorer. Process: C:\Program Files\Internet Explorer\iexplore.exe Process Name: Internet Explorer Process Publisher: Microsoft Corporation Affected Items: C:\WINDOWS\system32\shdocvw.dll, HKEY_USERS\S-1-5-21-1343024091-113007714-839522115-1003\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}\, HKEY_CLASSES_ROOT\CLSID\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}\InProcServer32\ If you did not expect this change, McAfee recommends that you block it. If you expected this change, allow it. End Notes. Another Change is in the history for Internet Explorer. misp://c:\PROGRA~1\mcafee\mpf\mc\mpfmisp.dll::mpfptraffic.htm misp://C:\PROGRA~1\McAfee\MQC\QcMISP.dll::McpMain.htm misp://C:\PROGRA~1\McAfee\MQC\QcMISP.dll::QcCleanResult.htm misp://C:\PROGRA~1\McAfee\MQC\QcMISP.dll::QcMsgBox.htm misp://c:\PROGRA~1\mcafee\mshr\ShrMISP.dll::SHREDDER.HTM
Thank you for the information. Let's try the System File Checker

start > Run > copy and paste in the bold: (there is a space between the sfc and the /)
sfc /scannow
Click 'OK'
You will need your XP/2000/ME disk. If you don't have it and instead only have a recovery CD, there is a work around. View the following link for a tutorial:

http://www.updatexp.com/scannow-sfc.html

sfc - system file checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.

If you want to see what was replaced, right click My Computer > manage, expand event viewer > system.
Susan, Completed the System File Check. Had to redirect SourcePatch, but got it finally. System seems to be moving a bit faster, but still quite slow. I noticed that the "about:blank" is still appearing in the bottom lefthand bar near the Internet Explorer icon of the browser window. This happens when I change sites. When I exit Internet Explorer altogether, about:blank shows as url for about 2 seconds; then Internet Explorer closes. So it appears about:blank is still there, preparing more pain for me. How do we get rid of this thing? More help, please?
Susan, I really need your help. I can hardly get any of my work done, and most of it has to be done through this computer. Literally, it is taking 3 hours to do work that normally is 15 minutes. Any more suggestions? I am not trying to be a jerk, just frantic.
Susan, I did it. about:blank still going strong. When I close browser windows, an about:blank page replaces the browser window, then it closes. It also still appears in the bottom lefthand corner next to the icon. What do we do?
Let's runa couple of scans, please.

Now for Ad-Aware : available from here.

1. Download and Install Ad-Aware SE, keeping the default options. However, some of the settings will need to be changed before your first scan
2.Close ALL windows except Ad-Aware SE

3. Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.

4. Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window

1) In the ‘General’ window make sure the following are selected in green:
*Automatically save log-file
*Automatically quarantine objects prior to removal
*Safe Mode (always request confirmation)

Under Definitions:
*Prompt to udate outdated definitions - set the number of days

2) Click on the ‘Scanning’ button on the left and select in green :

Under Driver, Folders & Files:
*Scan Within Archives

Under Select drives & folders to scan -
*choose all hard drives

Under Memory & Registry: all green
*Scan Active Processes
*Scan Registry
*Deep Scan Registry
*Scan my IE favorites for banned URL’s
*Scan my Hosts file

3) Click on the ‘Advanced’ button on the left and select in green:

Under Shell Integration:
*Move deleted files to recycle bin

Under Logfile Detail Level: (all green)
*include addtional object information
*DESELECT - include negligible objects information
*include environment information

Under Alternate Data Streams:
*Don't log streams smaller than 0 bytes
*Don't log ADS with the following names: CA_INOCULATEIT

4) Click the ‘Tweak’ button and select in green:

Under the ‘Scanning Engine’:
*Unload recognized processes during scanning
*Scan registry for all users instead of current user only

Under the ‘Cleaning Engine’:
*Let Windows remove files in use at next reboot

Under the Log Files:
*Include basic Ad-aware SE settings in logfile
*Include additional Ad-aware SE settings in logfile
*Please do not check and make Green: Include Module list in logfile


5. Click on ‘Proceed’ to save the settings.

6. Click ‘Start’

*Choose:'Perform Full System Scan'
*DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.

7. Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.

8. If Ad-Aware SE finds bad entries in the registry or bad files, you will receive a list of what it found in the window

9. Save the log file when it asks and then click ‘finish’

10. REBOOT to complete the removal of what Ad-Aware SE found

Please let me know if anything can not be cleaned by these utilities.

Now run this online scan using Internet Explorer:
Kaspersky Online Scanner from http://www.kaspersky.com/virusscanner

Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
Copy and paste that information from Kapersky in your reply.
Susan, Ad-Aware SE cannot finish its scan; it locks everytime I try it (4 times). I did try restarting my computer but that did not help it. Kapersky log below. I had to work from another office today, and will tomorrow also. If you have a chance to send me something else to do tonight, I will try to get it done before I have to relocate. Tuesday, August 15, 2006 8:25:04 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 16/08/2006 Kaspersky Anti-Virus database records: 202722 Scan Settings Scan using the following antivirus database standard Scan Archives true Scan Mail Bases true Scan Target My Computer A:\ C:\ D:\ E:\ Scan Statistics Total number of scanned objects 49084 Number of viruses found 0 Number of infected objects 0 / 0 Number of suspicious objects 0 Duration of the scan process 01:20:27 Infected Object Name Virus Name Last Action C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{5A5A2E3F-14FA-46FE-A527-0D71A7673389}.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR2.tmp Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS00D9BFA8-8876-41D9-B10A-C45938A94060.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS014EA97B-2193-4735-97EC-A263183691C9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS02F381BA-0A6E-4F7B-9F6B-F9413AEB2005.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS058A0CBE-34E0-4494-82DE-74B8F46DAB36.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS083D5C73-061D-4D33-B9ED-C4BBA1AB9229.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0B2C43C2-F3AE-4051-A4EE-6B84D9533A6E.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0B53724C-AA20-4AD5-92AC-2AE9E9743EB8.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0C0DABF8-6B74-46EA-BFA9-7AE265ADA363.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0F69AC43-F522-4695-9E26-86C89F447E0B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0FA38207-5754-44EC-9B63-D767273B62B1.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1354B109-A872-496A-BDE8-ABD40D65FD4D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS14A5F0D0-DDC7-4ADD-B21D-CF7AC7B780FC.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS17017237-39E2-494D-AFDD-A0C1A9BBD2C9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS17E13EF9-03DA-4BC6-AFC1-89CEE91127BF.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1BACEA5C-A548-4905-ADC3-AE6608BBD6FE.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1CA0E30B-05FE-4CBD-92F9-EB9643989A9D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS203D8EE5-263D-4557-B5D8-8496CAF943B9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS20791FE8-7D31-4F51-8ED2-D31729CF5810.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS22E3235E-0D5A-4F96-822C-CDC2A7DF0FA7.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS24B2ED96-6D4C-41D4-9540-A779B72EDFF8.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS25EBA361-42C5-4DFB-9F9D-82DF448DEDA3.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2A2FCD84-0484-4CDA-B25D-AD861B9035C6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2B8A4336-F767-4211-B9AF-777398D174DC.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2F530CAC-6168-49A4-AF50-A51F55B7F529.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS333894DE-8F03-4513-B3FA-36E9681476E4.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS344AB6F5-35F7-4E85-A254-CBFCDB616D5A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS39C9558A-949B-4F86-9798-EB4D06424608.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3A4B324B-227F-48E7-A956-1CF003749915.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3C86E8E7-D79E-4C5E-8C93-AF887E011384.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS412F23A7-4B9B-44F1-8F85-9F4EBA7CE682.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS46056E99-A322-4490-A318-80BB5CA8247D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS465B24F3-F915-4E04-8A9A-6682B42975E5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4667865C-B216-4CE5-9349-E90A8D7638BA.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS474EA757-21D0-4687-AEE6-0E1DC788D78C.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS48560C98-DED4-46D2-B4F5-181D5247FA24.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS48CC79B5-F81A-4B23-B250-C6B4060FE5D3.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS492FF046-4EAA-4E45-87CA-8EE8289749C7.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4E810B6F-8420-4C5D-8B5D-11516888A774.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4EB959D7-AFD1-4EE1-B318-8C0C56D2FCF9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5073C214-0944-4B21-A0B8-F9F401D27941.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS52A3FC79-CF97-4E56-BAB7-634D532880CF.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5649AEDB-EFCC-4522-B6B5-D11F3AA937CB.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5B1F5408-C1A0-4719-A2D9-1F16FD8B672B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5F64FA62-6C99-4E8F-9F51-D83E4F175BD1.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS60A7752C-6CAA-45F3-AA85-90FAC3665ED3.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6264A3F1-6CC1-40EA-86B8-5BDA328CAE14.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS64545F12-0228-4CC8-9F3E-7F9F5AEEFC8B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6670E404-845A-4573-A6C8-420DE3BFD64D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS66D89323-F408-4E4A-A8D4-311908AD4EE9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6819822F-E7E0-496E-B836-A70BFB8E21E3.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6B219F25-337E-468D-87FC-F43C4DD1A049.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS70082AAB-F66B-4C3B-9C93-E1601496BEB1.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7634AA3A-5D1D-4776-905E-3217F1DFB130.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7AF6FC20-72CE-49CA-A4D5-029D7FEFEF8B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7B66BD54-18A0-46D5-AE82-9BCBF5267E4F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7C921722-E453-4CF8-8F14-F8A6B9C79FC9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7CAC259C-5D95-472D-8EF3-D5C74650E42F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7E6A51D5-60A4-4A2C-A600-762365E1DEC8.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8169AF1D-801F-4198-A418-D802B8A3AFAA.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS83D4C262-F784-4679-97EE-52EE915C9CCE.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8798A34A-3E2A-44CE-BE8D-77B4AA3AA57B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8A1FCAC3-1609-4565-8EF5-FC6C8F451143.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8D33809D-F76F-4BE6-B89D-F825AABEBBD2.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9005FF09-8C0E-465E-A7B0-14884EF7E8FE.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9021DB51-D06A-48F1-B3A5-4016C3C9A467.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS93539BE2-7E88-4B38-861D-4671ECDB1F35.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS94F3A0FE-0336-41DD-9667-7414C4552B68.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9606F251-C3FC-496F-BA98-124B95A91BB7.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS97066484-D8CF-4173-AFD0-506F31F0C498.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9851CB09-06AA-492F-9E00-67BF3ABB4648.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS995BECBD-3C10-4B06-84FE-5BCA21FD8E97.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9BA7D76C-E004-4C7F-AAF5-7020BBC3E937.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9E484FE4-BC53-4479-91B2-871DFBA68ECB.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9F1A0C6A-AA3C-4136-B02E-172F4A6079DD.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9FD44CFC-5E37-497E-9E20-CB0DD9FBC37D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA08CF9EE-FE19-4EC3-B417-E183F6CF2346.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA1498790-51D6-405A-AE18-EE6A67AC8D78.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA1DDD89C-BD46-4396-8E00-68CF9C568FC5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA90352C2-811C-4CDE-A76B-63447687C4C5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA9E385F5-5AE8-4662-90EA-48BEF2AE7C64.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAF83825B-7262-4012-A5AF-508041E22204.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB5A51C86-8E4E-40E0-8335-B52A5E0D1667.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB7DF592E-BE35-46EC-9F7E-36999A6BF178.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB8EBFBA6-D773-455D-8461-0B3EA9E3C897.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBA34509A-F247-485D-8837-20E52B6690BD.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBAC1EDA2-F62C-4CE5-AA1D-37C53707AE15.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBECED128-C8E7-4879-8A04-D15DA3582AB3.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC18DA091-ACCC-4CB9-B62B-DDE25890B16D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC5A3EE9C-52F6-4133-A112-9A4DC4675D6E.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC9752524-4269-4999-87F5-79C28A75C43E.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCC08BAEA-79EA-41FF-8422-5C3F8B9564BC.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD21326D9-4203-4C61-ACA4-995534EF4D2D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD2E6E47D-BA38-495F-93BA-8356F7DF349D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD36B67BD-3450-4A2B-9606-41C3758F2910.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD454DC12-78D2-4681-B852-4722A392BB9D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD5ACB47E-831F-4769-BE54-5BE48FEB21B6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD7FDCE9D-F0A5-4236-BBC9-BDC0476E21B2.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDA173868-8D94-4081-9E63-55840DAE41B6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDD5CC4CF-3E52-4D09-AEF6-9B1EB9E5EB6A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDF1C8914-F786-44BB-BAAB-98C43FE70565.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDFC777BB-ADFC-4AF4-BF5C-4ADBEAE41BC0.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE4BAC1DC-6756-434B-91CD-39729C6CAE6A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE63F9874-58DA-4CE8-9E75-70ADEFC5CF20.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEF2FC1DC-BA16-4011-B990-6B89FCA1ED44.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF0A9ADA1-2CDE-4DA7-87C2-525BC151ECDE.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF2FB8B36-E3DE-4EC3-9AAA-3A328E9AEB82.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF3FF5B34-5680-4C91-AF15-D6078B89AD31.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFC73E6F9-2824-42C7-A0BF-F85C659F765A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFE52792A-79E4-4542-9113-0BF8DD6016C1.tmp Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\Application Data\Adobe\Acrobat\7.0\Updater\udlog.txt Object is locked skipped C:\Documents and Settings\Owner\Application Data\Webroot\Spy Sweeper\Logs\060812144632.ses Object is locked skipped C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{91FC926D-40ED-4C18-85B0-4C932E9D0C60}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\sqlite_7BCeTY6YHBMTxZx Object is locked skipped C:\WINDOWS\Temp\sqlite_pbqbyVU99gVj5ME Object is locked skipped C:\WINDOWS\Temp\sqlite_QPeVqJi4f0fHsU8 Object is locked skipped C:\WINDOWS\Temp\sqlite_TYlfqMqONEh1Hpv Object is locked skipped C:\WINDOWS\Temp\sqlite_xvw9fF6tBUzc0Gd Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
Susan, I was finally able to get Ad-Aware SE to scan. Log below. It was able to quarantine all the files. But About:blank is still there. When I close out browser windows it pops up. Computer is running slower than ever. What do we do next? Ad-Aware SE Build 1.06r1 Logfile Created on:Wednesday, August 16, 2006 10:35:20 AM Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R119 15.08.2006 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» IEHIjacker.SearchExe(TAC index:6):3 total references Tracking Cookie(TAC index:3):7 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Definition File: ========================= Definitions File Loaded: Reference Number : SE1R119 15.08.2006 Internal build : 143 File location : C:\Program Files\Spy and Ad ware Software\Ad-Aware SE Personal \defs.ref File size : 733938 Bytes Total size : 2379781 Bytes Signature data size : 2331552 Bytes Reference data size : 47717 Bytes Signatures total : 64975 CSI Fingerprints total : 3384 CSI data size : 127666 Bytes Target categories : 15 Target families : 946 Memory + processor status: ========================== Number of processors : 1 Processor architecture : Intel Pentium IV Memory available:7 % Total physical memory:260096 kb Available physical memory:15284 kb Total page file size:640004 kb Available on page file:246304 kb Total virtual memory:2097024 kb Available virtual memory:2043168 kb OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600) Ad-Aware SE Settings =========================== Set : Search for low-risk threats Set : Safe mode (always request confirmation) Set : Don't log streams smaller than 0 Bytes Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan within archives Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects 8/16/2006 10:35:22 AM - Scan started. (Full System Scan) Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] FilePath : \SystemRoot\System32\ ProcessID : 372 ThreadCreationTime : 8/16/2006 4:29:10 PM BasePriority : Normal #:2 [csrss.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 536 ThreadCreationTime : 8/16/2006 4:29:12 PM BasePriority : Normal #:3 [winlogon.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 560 ThreadCreationTime : 8/16/2006 4:29:13 PM BasePriority : High #:4 [services.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 672 ThreadCreationTime : 8/16/2006 4:29:13 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : services.exe #:5 [lsass.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 684 ThreadCreationTime : 8/16/2006 4:29:13 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:6 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 836 ThreadCreationTime : 8/16/2006 4:29:14 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:7 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 900 ThreadCreationTime : 8/16/2006 4:29:15 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 992 ThreadCreationTime : 8/16/2006 4:29:15 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:9 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1052 ThreadCreationTime : 8/16/2006 4:29:15 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:10 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1148 ThreadCreationTime : 8/16/2006 4:29:16 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:11 [lexbces.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1436 ThreadCreationTime : 8/16/2006 4:29:18 PM BasePriority : Normal FileVersion : 7.4 ProductVersion : 7.4 ProductName : MarkVision for Windows (32 bit) CompanyName : Lexmark International, Inc. FileDescription : LexBce Service InternalName : LexBce Service LegalCopyright : © 1993 - 2002 Lexmark International, Inc. OriginalFilename : LexBceS.exe #:12 [spoolsv.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1568 ThreadCreationTime : 8/16/2006 4:29:18 PM BasePriority : Normal FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) ProductVersion : 5.1.2600.2696 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : spoolsv.exe #:13 [lexpps.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1576 ThreadCreationTime : 8/16/2006 4:29:18 PM BasePriority : Normal FileVersion : 7.4 ProductVersion : 7.4 ProductName : MarkVision for Windows (32 bit) CompanyName : Lexmark International, Inc. FileDescription : LEXPPS.EXE InternalName : LEXPPS LegalCopyright : © 1993 - 2002 Lexmark International, Inc. OriginalFilename : LEXPPS.EXE Comments : MarkVision for Windows '95 New P2P Server (32-bit) #:14 [explorer.exe] FilePath : C:\WINDOWS\ ProcessID : 1600 ThreadCreationTime : 8/16/2006 4:29:18 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE #:15 [hkcmd.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1864 ThreadCreationTime : 8/16/2006 4:29:20 PM BasePriority : Normal FileVersion : 3.0.0.4342 ProductVersion : 7.0.0.4342 ProductName : Intel® Common User Interface CompanyName : Intel Corporation FileDescription : hkcmd Module InternalName : HKCMD LegalCopyright : Copyright 1999-2004, Intel Corporation OriginalFilename : HKCMD.EXE #:16 [bcmsmmsg.exe] FilePath : C:\WINDOWS\ ProcessID : 1872 ThreadCreationTime : 8/16/2006 4:29:20 PM BasePriority : Normal FileVersion : 3.5.25 08/27/2003 20:04:35 ProductVersion : 3.5.25 08/27/2003 20:04:35 ProductName : BCM Modem Messaging Applet CompanyName : Broadcom Corporation FileDescription : Modem Messaging Applet InternalName : smdmstat.exe LegalCopyright : Copyright © Broadcom Corporation 1998-2000 OriginalFilename : smdmstat.exe #:17 [lxbbbmgr.exe] FilePath : C:\Program Files\Lexmark X74-X75\ ProcessID : 1880 ThreadCreationTime : 8/16/2006 4:29:20 PM BasePriority : Normal FileVersion : 1.0.5.0 ProductVersion : 1.0.5.0 ProductName : Button Manager Executable CompanyName : Lexmark International, Inc. FileDescription : Lexmark X74-X75 Button Manager InternalName : lxbbbmgr.exe LegalCopyright : © 2002 Lexmark International, Inc. OriginalFilename : lxbbbmgr.exe #:18 [qttask.exe] FilePath : C:\Program Files\QuickTime\ ProcessID : 1888 ThreadCreationTime : 8/16/2006 4:29:21 PM BasePriority : Normal FileVersion : 6.5.1 ProductVersion : QuickTime 6.5.1 ProductName : QuickTime CompanyName : Apple Computer, Inc. InternalName : QuickTime Task LegalCopyright : © Apple Computer, Inc. 2001-2004 OriginalFilename : QTTask.exe #:19 [realsched.exe] FilePath : C:\Program Files\Common Files\Real\Update_OB\ ProcessID : 1912 ThreadCreationTime : 8/16/2006 4:29:21 PM BasePriority : Normal FileVersion : 0.1.0.3275 ProductVersion : 0.1.0.3275 ProductName : RealPlayer (32-bit) CompanyName : RealNetworks, Inc. FileDescription : RealNetworks Scheduler InternalName : schedapp LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004 LegalTrademarks : RealAudio™ is a trademark of RealNetworks, Inc. OriginalFilename : realsched.exe #:20 [ituneshelper.exe] FilePath : C:\Program Files\iTunes\ ProcessID : 1928 ThreadCreationTime : 8/16/2006 4:29:21 PM BasePriority : Normal FileVersion : 4.8.0.31 ProductVersion : 4.8.0.31 ProductName : iTunes CompanyName : Apple Computer, Inc. FileDescription : iTunesHelper Module InternalName : iTunesHelper LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved. OriginalFilename : iTunesHelper.exe #:21 [lxbbbmon.exe] FilePath : C:\Program Files\Lexmark X74-X75\ ProcessID : 1936 ThreadCreationTime : 8/16/2006 4:29:21 PM BasePriority : Normal FileVersion : 1.0.5.0 ProductVersion : 1.0.5.0 ProductName : Button Monitor Executable CompanyName : Lexmark International, Inc. FileDescription : Lexmark X74-X75 Button Monitor InternalName : lxbbbmon.exe LegalCopyright : © 2002 Lexmark International, Inc. OriginalFilename : lxbbbmon.exe #:22 [winpatrol.exe] FilePath : C:\PROGRA~1\BILLPS~1\WINPAT~1\ ProcessID : 1944 ThreadCreationTime : 8/16/2006 4:29:21 PM BasePriority : Normal FileVersion : 9, 7, 4, 0 ProductVersion : 9.7.4.0 ProductName : WinPatrol Monitor CompanyName : BillP Studios FileDescription : WinPatrol System Monitor InternalName : WinPatrol Monitor LegalCopyright : Copyright © 1997- 2005 BillP Studios OriginalFilename : Scotty Comments : Let Scotty the Windows Watchdog patrol your system. #:23 [spysweeperui.exe] FilePath : C:\Program Files\Webroot\Spy Sweeper\ ProcessID : 1960 ThreadCreationTime : 8/16/2006 4:29:21 PM BasePriority : Normal FileVersion : 5,0,5,1286 ProductVersion : 5, 0 ProductName : Spy Sweeper CompanyName : Webroot Software, Inc. FileDescription : Spy Sweeper Client Executable LegalCopyright : Copyright © 2002 - 2006, All Rights Reserved. OriginalFilename : SpySweeper.exe #:24 [j2gdllcmd.exe] FilePath : C:\Program Files\eFax Messenger 4.0\ ProcessID : 2004 ThreadCreationTime : 8/16/2006 4:29:21 PM BasePriority : Normal FileVersion : 4.0.134.0 ProductVersion : 4.0.134.0 ProductName : eFax Messenger ™ CompanyName : j2 Global Communications, Inc. FileDescription : eFax Messenger - DLL Command Utility InternalName : DllCmd32 LegalCopyright : Copyright © 2005 j2 Global Communications, Inc. LegalTrademarks : eFax® eFax.com ™ eFax Messenger ™ eFax Messenger Plus ™ JetSuite® PaperMaster Pro ™ OriginalFilename : DllCmd32.exe #:25 [j2gtray.exe] FilePath : C:\Program Files\eFax Messenger 4.0\ ProcessID : 2012 ThreadCreationTime : 8/16/2006 4:29:22 PM BasePriority : Normal FileVersion : 4.0.134.0 ProductVersion : 4.0.134.0 ProductName : eFax Messenger ™ CompanyName : j2 Global Communications, Inc. FileDescription : eFax Messenger - Tray InternalName : HotTray LegalCopyright : Copyright © 2005 j2 Global Communications, Inc. LegalTrademarks : eFax® eFax.com ™ eFax Messenger ™ eFax Messenger Plus ™ JetSuite® PaperMaster Pro ™ OriginalFilename : HotTray.exe #:26 [guard.exe] FilePath : C:\Program Files\ewido anti-spyware 4.0\ ProcessID : 268 ThreadCreationTime : 8/16/2006 4:29:26 PM BasePriority : Normal FileVersion : 4, 0, 0, 172 ProductVersion : 4, 0, 0, 172 ProductName : ewido anti-spyware CompanyName : Anti-Malware Development a.s. FileDescription : ewido anti-spyware guard InternalName : ewido anti-spywareguard LegalCopyright : Copyright © 2005 Anti-Malware Development a.s. OriginalFilename : guard.exe #:27 [hwapi.exe] FilePath : C:\Program Files\Common Files\McAfee\HackerWatch\ ProcessID : 304 ThreadCreationTime : 8/16/2006 4:29:26 PM BasePriority : Normal FileVersion : 8.0.162.0 ProductVersion : 8.0.162.0 ProductName : McAfee HackerWatch Service CompanyName : McAfee, Inc. FileDescription : McAfee HackerWatch Service LegalCopyright : © McAfee, Inc. All rights reserved. OriginalFilename : HWAPI.exe #:28 [mclogsrv.exe] FilePath : C:\PROGRA~1\McAfee\MSC\ ProcessID : 468 ThreadCreationTime : 8/16/2006 4:29:29 PM BasePriority : Normal FileVersion : 7,0,317,0 ProductVersion : 7,0,0,0 ProductName : McAfee SecurityCenter CompanyName : McAfee, Inc. FileDescription : MSC Log Manager InternalName : mclogsrv LegalCopyright : Copyright © 2006 McAfee, Inc. OriginalFilename : mclogsrv.exe #:29 [mcupdmgr.exe] FilePath : C:\PROGRA~1\McAfee\MSC\ ProcessID : 484 ThreadCreationTime : 8/16/2006 4:29:29 PM BasePriority : Normal FileVersion : 7,0,317,0 ProductVersion : 7,0,0,0 ProductName : McAfee SecurityCenter CompanyName : McAfee, Inc. FileDescription : McAfee Update Manager Service InternalName : mcupdmgr LegalCopyright : Copyright © 2006 McAfee, Inc. OriginalFilename : mcupdmgr.exe #:30 [mcnasvc.exe] FilePath : c:\program files\common files\mcafee\mna\ ProcessID : 508 ThreadCreationTime : 8/16/2006 4:29:30 PM BasePriority : Normal FileVersion : 1,0,176,0 ProductVersion : 1,0,0,0 ProductName : McAfee Integrated Security Platform CompanyName : McAfee, Inc. FileDescription : McAfee Network Agent InternalName : McNASvc LegalCopyright : Copyright © 2006 McAfee, Inc. OriginalFilename : McNASvc.exe #:31 [mcods.exe] FilePath : C:\PROGRA~1\McAfee\VIRUSS~1\ ProcessID : 568 ThreadCreationTime : 8/16/2006 4:29:31 PM BasePriority : Normal FileVersion : 11,0,201,0 ProductVersion : 11,0,0,0 ProductName : McAfee VirusScan CompanyName : McAfee, Inc. FileDescription : McAfee VirusScan - On Demand Scan InternalName : mcods.exe LegalCopyright : Copyright © 2006 McAfee, Inc. OriginalFilename : mcods.exe #:32 [mcpromgr.exe] FilePath : C:\PROGRA~1\McAfee\MSC\ ProcessID : 604 ThreadCreationTime : 8/16/2006 4:29:31 PM BasePriority : Normal FileVersion : 7,0,317,0 ProductVersion : 7,0,0,0 ProductName : McAfee SecurityCenter CompanyName : McAfee, Inc. FileDescription : McAfee Integrated Security Platform InternalName : McProMgr LegalCopyright : Copyright © 2006 McAfee, Inc. OriginalFilename : McProMgr.exe #:33 [mcproxy.exe] FilePath : c:\PROGRA~1\COMMON~1\mcafee\mcproxy\ ProcessID : 752 ThreadCreationTime : 8/16/2006 4:29:32 PM BasePriority : Normal FileVersion : 1,0,222,0 ProductVersion : 1,0,0,0 ProductName : McAfee Proxy CompanyName : McAfee, Inc. FileDescription : McAfee Proxy Service Module InternalName : McProxy LegalCopyright : Copyright © 2006 McAfee, Inc. OriginalFilename : McProxy.exe Comments : McAfee Proxy Service #:34 [redirsvc.exe] FilePath : c:\PROGRA~1\COMMON~1\mcafee\redirsvc\ ProcessID : 804 ThreadCreationTime : 8/16/2006 4:29:32 PM BasePriority : Normal FileVersion : 1,0,198,0 ProductVersion : 1,0,0,0 ProductName : McAfee Redirector CompanyName : McAfee, Inc. FileDescription : McAfee Redirector Service Module InternalName : McRedirector LegalCopyright : Copyright © 2006 McAfee, Inc. OriginalFilename : RedirSvc.exe Comments : McAfee Redirector Service #:35 [mcshield.exe] FilePath : C:\PROGRA~1\McAfee\VIRUSS~1\ ProcessID : 864 ThreadCreationTime : 8/16/2006 4:29:32 PM BasePriority : High #:36 [mcsysmon.exe] FilePath : C:\PROGRA~1\McAfee\VIRUSS~1\ ProcessID : 1108 ThreadCreationTime : 8/16/2006 4:29:34 PM BasePriority : Normal FileVersion : 11,0,281,0 ProductVersion : 11,0,0,0 ProductName : McAfee VirusScan API CompanyName : McAfee, Inc. FileDescription : McAfee SystemGuards Service InternalName : sysmon LegalCopyright : Copyright © 2006 McAfee, Inc. OriginalFilename : sysmon.exe #:37 [mctskshd.exe] FilePath : C:\PROGRA~1\McAfee\MSC\ ProcessID : 1196 ThreadCreationTime : 8/16/2006 4:29:36 PM BasePriority : Normal FileVersion : 7,0,317,0 ProductVersion : 7,0,0,0 ProductName : McAfee SecurityCenter CompanyName : McAfee, Inc. FileDescription : McAfee Tqsk Scheduler InternalName : McTskShd LegalCopyright : Copyright © 2006 McAfee, Inc. OriginalFilename : mctskshd.exe #:38 [mcusrmgr.exe] FilePath : C:\PROGRA~1\McAfee\MSC\ ProcessID : 1284 ThreadCreationTime : 8/16/2006 4:29:36 PM BasePriority : Normal FileVersion : 7,0,317,0 ProductVersion : 7,0,0,0 ProductName : McAfee SecurityCenter CompanyName : McAfee, Inc. FileDescription : MISP User Manager InternalName : McUsrMgr LegalCopyright : Copyright © 2006 McAfee, Inc. OriginalFilename : McUsrMgr.exe #:39 [mpfsrv.exe] FilePath : C:\Program Files\McAfee\MPF\ ProcessID : 1396 ThreadCreationTime : 8/16/2006 4:29:37 PM BasePriority : Normal FileVersion : 8.0.198.0 ProductVersion : 8.0.198.0 ProductName : McAfee Personal Firewall CompanyName : McAfee, Inc. FileDescription : McAfee Personal Firewall Service InternalName : MPFService LegalCopyright : Copyright © 2005 McAfee, Inc. All Rights Reserved. OriginalFilename : MpfService.exe Comments : McAfee Personal Firewall Service #:40 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1504 ThreadCreationTime : 8/16/2006 4:29:39 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:41 [wdfmgr.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 2132 ThreadCreationTime : 8/16/2006 4:29:44 PM BasePriority : Normal FileVersion : 5.2.3790.1230 built by: dnsrv(bld4act) ProductVersion : 5.2.3790.1230 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows User Mode Driver Manager InternalName : WdfMgr LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : WdfMgr.exe #:42 [mcagent.exe] FilePath : C:\PROGRA~1\mcafee.com\agent\ ProcessID : 2144 ThreadCreationTime : 8/16/2006 4:29:44 PM BasePriority : Normal FileVersion : 7,0,317,0 ProductVersion : 7,0,0,0 ProductName : McAfee SecurityCenter CompanyName : McAfee, Inc. FileDescription : McAfee Integrated Security Platform InternalName : McAgent LegalCopyright : Copyright © 2006 McAfee, Inc. OriginalFilename : McAgent.exe #:43 [mps.exe] FilePath : C:\Program Files\McAfee\MPS\ ProcessID : 3096 ThreadCreationTime : 8/16/2006 4:30:29 PM BasePriority : Normal FileVersion : 9.0.370.0 ProductVersion : 9.0.370.0 ProductName : McAfee Privacy Service CompanyName : McAfee, Inc. FileDescription : McAfee Privacy Service 9.0 InternalName : mps9 LegalCopyright : Copyright © 2006 McAfee, Inc. OriginalFilename : mps.exe #:44 [mpsevh.exe] FilePath : C:\Program Files\McAfee\MPS\ ProcessID : 3212 ThreadCreationTime : 8/16/2006 4:30:38 PM BasePriority : Normal FileVersion : 9.0.370.0 ProductVersion : 9.0.370.0 ProductName : McAfee Privacy Service CompanyName : McAfee, Inc. FileDescription : McAfee Privacy Service 9.0 Event Handler InternalName : MpsEventHandler LegalCopyright : Copyright © 2006 McAfee, Inc. OriginalFilename : mpsevh.exe #:45 [ipodservice.exe] FilePath : C:\Program Files\iPod\bin\ ProcessID : 3292 ThreadCreationTime : 8/16/2006 4:30:48 PM BasePriority : Normal FileVersion : 4.8.0.31 ProductVersion : 4.8.0.31 ProductName : iTunes CompanyName : Apple Computer, Inc. FileDescription : iPodService Module InternalName : iPodService LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved. OriginalFilename : iPodService.exe #:46 [spysweeper.exe] FilePath : C:\Program Files\Webroot\Spy Sweeper\ ProcessID : 3544 ThreadCreationTime : 8/16/2006 4:30:53 PM BasePriority : Normal FileVersion : 3,0,5,1286 ProductVersion : 3, 0 ProductName : Spy Sweeper SDK CompanyName : Webroot Software, Inc. FileDescription : Spy Sweeper Engine LegalCopyright : Copyright © 2002 - 2006, All Rights Reserved. LegalTrademarks : Spy Sweeper is a trademark of Webroot Software, Inc. OriginalFilename : SpySweeper.exe #:47 [alg.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 3760 ThreadCreationTime : 8/16/2006 4:31:16 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Application Layer Gateway Service InternalName : ALG.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ALG.exe #:48 [wuauclt.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1164 ThreadCreationTime : 8/16/2006 4:31:56 PM BasePriority : Normal FileVersion : 5.8.0.2469 built by: lab01_n(wmbla) ProductVersion : 5.8.0.2469 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Automatic Updates InternalName : wuauclt.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : wuauclt.exe #:49 [acrord32.exe] FilePath : C:\Program Files\Adobe\Acrobat 7.0\Reader\ ProcessID : 1764 ThreadCreationTime : 8/16/2006 4:42:06 PM BasePriority : Normal FileVersion : 7.0.8.2006051600 ProductVersion : 7.0.8.2006051600 ProductName : Adobe Reader CompanyName : Adobe Systems Incorporated FileDescription : Adobe Reader 7.0 LegalCopyright : Copyright 1984-2006 Adobe Systems Incorporated and its licensors. All rights reserved. OriginalFilename : AcroRd32.exe #:50 [ad-aware.exe] FilePath : C:\Program Files\Spy and Ad ware Software\Ad-Aware SE Personal\ ProcessID : 2612 ThreadCreationTime : 8/16/2006 5:28:14 PM BasePriority : Normal FileVersion : 6.2.0.236 ProductVersion : SE 106 ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft AB Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» IEHIjacker.SearchExe Object Recognized! Type : Regkey Data : TAC Rating : 6 Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : interface\{b1e68d42-02c4-465b-8368-5ed9b732e22d} Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 1 Objects found so far: 1 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 1 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie Object Recognized! Type : IECache Entry Data : owner@advertising[1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:41 Value : Cookie:[removed]/ Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][2].txt TAC Rating : 3 Category : Data Miner Comment : Hits:10 Value : Cookie:[removed]/ Tracking Cookie Object Recognized! Type : IECache Entry Data : owner@atdmt[2].txt TAC Rating : 3 Category : Data Miner Comment : Hits:8 Value : Cookie:[removed]/ Tracking Cookie Object Recognized! Type : IECache Entry Data : owner@mediaplex[2].txt TAC Rating : 3 Category : Data Miner Comment : Hits:6 Value : Cookie:[removed]/ Tracking Cookie Object Recognized! Type : IECache Entry Data : owner@doubleclick[1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:6 Value : Cookie:[removed]/ Tracking Cookie Object Recognized! Type : IECache Entry Data : owner@live365[1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 7 Objects found so far: 8 Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 8 Scanning Hosts file…… Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 1 entries scanned. New critical objects:0 Objects found so far: 8 Performing conditional scans… »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» IEHIjacker.SearchExe Object Recognized! Type : RegValue Data : TAC Rating : 6 Category : Malware Comment : Rootkey : HKEY_CURRENT_USER Object : software\microsoft\internet explorer\main Value : Search Page IEHIjacker.SearchExe Object Recognized! Type : RegValue Data : TAC Rating : 6 Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\internet explorer\search Value : SearchAssistant Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 2 Objects found so far: 10 10:53:59 AM Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:18:36.968 Objects scanned:138139 Objects identified:10 Objects ignored:0 New critical objects:10
Help!!!!!!!!!!!!!!!!!!!!! I am about to rip my head off and beat my computer with it (the computer moves so slow I really doubt I need a brain to operate it anymore).

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI