This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cws-aboutblank

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 9:16:35 PM, on 4/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TrojanHunter 4.6\THGuard.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Entertainment Center\EAXLoadr.exe
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\zHotkey.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\pccguide.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\MediaSource5\MtdAcqu.exe
C:\Program Files\Creative\MediaSource5\CTDetctu.exe
C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:4001
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.6\THGuard.exe"
O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [pccguide.exe] C:\PROGRA~1\TRENDM~1\INTERN~2\pccguide.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MtdAcqu] "C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" /s
O4 - HKCU\..\Run: [Creative Detector U] "C:\Program Files\Creative\MediaSource5\CTDetctu.exe" /R
O4 - HKCU\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Creative MediaSource Go] "C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe" /SCB
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://mail.polarbev.com/iNotes6W.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1176516260359
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

Initially my pc was running very slow, had problems accessing websites, downloading, updating programs etc… Spysweeper acknowledged what I had suspected that I had CWS. I quarantined it, but of course, have not rid my pc of it. Please help! Thank you.
Welcome to the forums. I see nothing in your log . Looks as if spy sweeper did it's job :thumbup: If you like you can delete all it found from the quarantined section by: Open spy sweeper choose quarantined select all ( possibly a right click on the page… it's been a while since I used the program myself) Choose remove. Other than that you look clean. Let me know please so I can close this topic.
Bob4, Thank you for responding. I really appreciate your help but I don't believe I am out of the woods yet. Thursday & Friday I ran scans with Spysweeper and both times it picked up cws-aboutblank (1 item, 2 traces). This morning I did what you asked and then ran another scan with the same result. It is not going away that easily. Is there anything suspicious in my log?
No I don't see anything indicating cws or about blank.
But lets start looking deeper.


______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.
  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Issues block to clean anything with this program. It is for experts only and it is risky).

Please download to your Desktop or to your usual Download Folder.
AVG Anti-Spyware
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit.
  • Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update AVG Anti-spyware.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
______________________________
It will save a log in C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports


Exit AVG.
Reboot normaly.
Post that for me.




_________________________________
Please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer


Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.



The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:

Save the file to your desktop.

Copy and paste that information in your next post.

Post those 2 logs for me.
bob4, No problem with your first request but I cannot install AVG. I am getting the message: "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."
bob4, Yes I downloaded to C drive as always. I am sorry, I am not entirely clear on how to log in as an Administrator unless I boot in Safe mode. By the way, I have used Ewido and AVG several times over the years and have never seen this error before.
click start/control panel/

go to user accounts

click change account.

The name you logon with should say computer administrator.
Does it ?

Please post the Kasperskys scan results for me.
bob4, I installed AVG in safe mode and ran according to yopur instructions and the scan came back clean. Here is the Kaspersky log: KASPERSKY ONLINE SCANNER REPORT Sunday, April 22, 2007 11:11:46 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 23/04/2007 Kaspersky Anti-Virus database records: 300538 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target My Computer C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ Scan Statistics Total number of scanned objects 62129 Number of viruses found 0 Number of infected objects 0 / 0 Number of suspicious objects 0 Duration of the scan process 01:13:31 Infected Object Name Virus Name Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS00204828-C963-4AD3-8BB5-35029DA6687B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS017B3533-4C67-4F25-968E-C2168AA4A6A6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS01B86880-BF51-48F7-8C3C-2798394E8CE5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS029D5B7F-EF4B-4F1A-9A68-CE53604096E4.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0ABCF578-67C4-4D13-872C-033ED42A2CFA.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0D1E456E-FA17-4BDD-813D-A6ED7F4DCF31.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0F083A5B-5C19-4D7D-8FE0-7FAD0F79B440.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0FBB8953-CBB2-4E00-AD47-022012AB74D6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1BC904A5-7A9B-4FBC-ADBD-0700AF1B4035.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1CCDE80C-61E0-48D7-B215-18F828078213.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1FE8819E-52C7-4FB1-8840-ED65BAA41C26.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS24009726-EDED-432D-ADE8-110D71B42E0D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS24CAFB2A-2DE1-4353-B3B5-24E7919293A4.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS373858A8-2299-4A1B-A6B5-730933439794.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS38984886-67E7-4959-B40F-B942D3693709.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3A2DC5E8-7E43-47CD-AB8C-73FA59AFE904.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3AE45281-F0D3-4563-9C56-0F08CBCA4FF9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3C3DFD95-B71E-436B-9F5D-286B886418A8.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3DCCBB35-F8DC-4889-B02A-FB9E0DA6E689.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3EDA6E13-CA69-4E09-AEFC-2AF8F59D3332.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS43F766F3-9487-4D59-95A8-E13A47A670E2.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS47EF5B40-A903-433B-9DDD-CA7F2AA1EC1B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS48BBF95A-DE2F-47BD-9F0D-E96F2345C7FB.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4A725856-3333-4B86-BF93-5F3CE8652679.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4B735743-173B-47B5-8EDF-FFBC96AFE8BC.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4B9A137D-29DA-40AE-A103-299B5C975FEE.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS52983149-35FB-4E65-BEDB-627A6D23905D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS536542BC-6D59-419A-9B0F-47D31F899F11.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5459EEB1-8A23-4668-B13A-89F6A1D329FC.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS572DD8E7-1BDC-4555-8AC0-ED81137FD7F6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5831BC92-D4E3-4E94-8789-ECA62479FD7C.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5A4646BC-6E9A-40BE-90C8-38AE22D4D65C.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5D2BF2D4-7B30-4578-9D57-04723D5D6540.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5E0F0B84-E5E0-4E64-8CA6-544CC163A4B8.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS64C32DCC-2ABA-4DFC-B429-7B0B1CF5FB3D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS65FB06DA-A9E7-49BC-A31A-F16DDA263D4E.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS669E55A8-402F-46C5-B5D2-64697FE939C3.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS67B73E35-43A3-40B1-B0E0-7BDDFC5EB339.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS67FDDB54-EE6C-42A4-BB57-9A4B9CEFFE17.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS69B107D9-F697-4117-917A-9EDC7C5D112D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6FB88797-74AE-4317-BF3F-93894BE17A37.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS78243382-7571-432B-94B3-3AB5AED06215.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7B91DD26-F111-4A28-81E4-FA4E6592238E.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7C131F55-74FF-4A1C-BB05-692FE6A88BA7.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7DED8B46-F778-4F69-B99C-7F32F67CF2B9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8091A782-A50E-43A8-B22E-B546BE47AC67.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS81CB0EDB-DDEB-449E-9F74-DC6BF998E06E.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8535DACE-674C-4D89-ABEA-6F1E89C8C902.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8FA1FF89-9E13-43F1-BF2B-234477F73575.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS92C33CB8-AA4F-4466-A04A-71CDE2DA2BF1.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS931F3851-DD8F-4A7B-AC73-370CAC443559.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9464AD2D-0D58-469C-9F83-A7C88533C4D5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS988820D2-4ED2-4568-A891-9180DF800CE3.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9BF59C4A-4EE0-4A6C-BF2D-1271A9EB4D39.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9F6583BF-0841-4C91-AC3B-15D025DF18E9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA3FEE379-76E2-45A1-AD4A-AFCB16FCB87D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA417F230-511A-4CDE-9210-0CDEEBB12470.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA4F1A06B-B44D-4C64-AE7D-9B907492593A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA502D158-EB73-4EB0-B15D-65F4D36DFC45.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA92D492F-7245-48FF-88F1-ACF6DB4C9720.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA9C1511E-3AF4-4229-957A-02A4078E22F5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA9FF323A-4412-4A6F-A6B0-8DC36B94BDA4.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAD4B6DFF-B501-430D-A5DE-4988650FF77F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSADAE5689-86C7-44E6-BCAF-43D3CA5322E1.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSADDDEFDB-1C79-4076-B73A-C0B6EFFFC1A2.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB1EA5214-07A6-48E3-A3B7-C9D42458EA7F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB453CC98-BF1F-4246-9251-63482D07F898.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB47E0002-3915-4C74-9C88-1FA37B902C25.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB4F48893-7B1E-4365-AA63-D9FF2794CB35.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB5CC1C19-CA0A-4DFC-BD5F-F970E1A63633.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBFEA1521-B04A-4808-88BD-4CA733BB410E.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC2BFFB88-F349-4D6C-9983-C9B82153EC1D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC4B82EAB-4ACC-43FD-96F2-D7C8EF0F3B37.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC5EEC286-C736-4171-9A5F-CCD6BF6AD0AA.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC5F46883-2239-46D7-996C-708FA5BE3A20.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC927771A-A82E-49AB-903D-1932D3C63ED9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD0CE3007-EB2D-49CF-8FD6-CDF01525F378.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD410B1B7-EC13-4FE0-BA33-D9E6F6DB9A8A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD43FFA70-87B2-4EB5-8EC4-E89ACE098F23.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD8BC8ACD-3037-4E4D-B3E5-153A6AD3E527.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDDAC93A4-9F9F-4982-B2B9-478E260A2951.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDF9A4CC5-377B-4093-AD39-CF5757DC2D1E.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE7CFA1CD-4365-4F27-BC6D-F1478821EF13.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF50CCB45-3705-466E-8B90-DB269D4BCBC5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF6FEFE27-D653-4995-9EF1-79A57794A6FF.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF7548F02-2064-42DE-B278-1F120407EB26.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF9D15F0D-BA1C-48C2-8950-D90F0BB9A6E7.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFA950A69-32C4-424B-B7B8-CC3EF337DFD5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFCBDCA7C-58EF-4C24-A0ED-BD69A42E699F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFE53329C-63F5-4D37-8C44-5395D363E612.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFE5AA1A8-261C-4237-8C65-B372D819B81F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\Application Data\SPAMfighter\Logs\Agent.log.txt Object is locked skipped C:\Documents and Settings\Owner\Application Data\Webroot\Spy Sweeper\Logs70422180734.ses Object is locked skipped C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012007042220070423\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temp\Free Download Manager\tic877D.tmp Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temp\Free Download Manager\tic877E.tmp Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temp\~DF8C6D.tmp Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temp\~DFFA37.tmp Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\UserData\index.dat Object is locked skipped C:\Program Files\HP\hpcoretech\hpcmerr.log Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP19\A0001960.exe Object is locked skipped C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP19\A0001961.exe Object is locked skipped C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP19\A0001964.exe Object is locked skipped C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP19\A0001965.exe Object is locked skipped C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP19\A0002042.exe Object is locked skipped C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP19\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\ModemLog_PCI Soft Data Fax Modem with SmartCP.txt Object is locked skipped C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{73FE65C1-177F-40F8-BDDA-D491D9ECCA0A}.crmlog Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped D:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP19\change.log Object is locked skipped Scan process completed.
You installed AVG in safe mode. Were you able to update it before you ran the scan. That may or may not change the results of the scan.
Still not seeing anything though.
Can you tell me exactly what Spy Sweeper is finding and where? Good chance it's a false positve.
Possibly send me a log rom spysweeper.
I don't look at them often at all. But maybe I can figure something out if I see one.



Open SpySweeper:
  • click Options on the left side.
  • Click the Sweep Options tab.
Under What to Sweep please put a check next to the following:

  • Sweep Memory
  • Sweep Registry
  • Sweep Cookies
  • Sweep All User Accounts
  • Enable Direct Disk Sweeping
  • Sweep Contents of Compressed Files
  • Sweep for Rootkits
Please UNCHECK Do not Sweep System Restore Folder.


Click Sweep Now on the left side.

Click the Start button.

When it's done scanning, click the Next button.

Make sure everything has a check next to it, then click the Next button.

When it's done.

Click Session Log in the upper right corner, Copy everything in that window and Paste it into Notepad, saving the TXT file.

Click the Summary tab and click Finish.

Post that for me.
bob4, Yes, I installed in safe mode, restarted, updated and ran sweep. Here is the Spysweeper info: 5:12 PM: ApplicationMinimized - EXIT 5:12 PM: ApplicationMinimized - ENTER 5:10 PM: None 5:10 PM: Traces Found: 0 5:10 PM: Custom Sweep has completed. Elapsed time 00:20:09 5:10 PM: File Sweep Complete, Elapsed Time: 00:16:58 5:08 PM: Warning: SweepDirectories: Cannot find directory "j:". This directory was not added to the list of paths to be scanned. 5:08 PM: Warning: SweepDirectories: Cannot find directory "i:". This directory was not added to the list of paths to be scanned. 5:08 PM: Warning: SweepDirectories: Cannot find directory "h:". This directory was not added to the list of paths to be scanned. 5:08 PM: Warning: SweepDirectories: Cannot find directory "g:". This directory was not added to the list of paths to be scanned. 5:08 PM: Warning: SweepDirectories: Cannot find directory "f:". This directory was not added to the list of paths to be scanned. 5:08 PM: Warning: SweepDirectories: Cannot find directory "e:". This directory was not added to the list of paths to be scanned. 4:53 PM: Starting File Sweep 4:53 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00 4:53 PM: Starting Cookie Sweep 4:53 PM: Registry Sweep Complete, Elapsed Time:00:00:21 4:52 PM: Starting Registry Sweep 4:52 PM: Memory Sweep Complete, Elapsed Time: 00:02:43 4:50 PM: Starting Memory Sweep 4:50 PM: Start Custom Sweep 4:50 PM: Sweep initiated using definitions version 899 4:47 PM: ApplicationMinimized - EXIT 4:47 PM: ApplicationMinimized - EXIT 4:47 PM: ApplicationMinimized - ENTER 4:47 PM: ApplicationMinimized - ENTER 4:37 PM: None 4:37 PM: Traces Found: 0 4:37 PM: Custom Sweep has completed. Elapsed time 00:16:31 4:37 PM: File Sweep Complete, Elapsed Time: 00:13:56 4:36 PM: Warning: SweepDirectories: Cannot find directory "j:". This directory was not added to the list of paths to be scanned. 4:36 PM: Warning: SweepDirectories: Cannot find directory "i:". This directory was not added to the list of paths to be scanned. 4:36 PM: Warning: SweepDirectories: Cannot find directory "h:". This directory was not added to the list of paths to be scanned. 4:36 PM: Warning: SweepDirectories: Cannot find directory "g:". This directory was not added to the list of paths to be scanned. 4:36 PM: Warning: SweepDirectories: Cannot find directory "f:". This directory was not added to the list of paths to be scanned. 4:36 PM: Warning: SweepDirectories: Cannot find directory "e:". This directory was not added to the list of paths to be scanned. 4:23 PM: Starting File Sweep 4:23 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00 4:23 PM: Starting Cookie Sweep 4:23 PM: Registry Sweep Complete, Elapsed Time:00:00:18 4:23 PM: Starting Registry Sweep 4:23 PM: Memory Sweep Complete, Elapsed Time: 00:02:11 4:21 PM: Starting Memory Sweep 4:21 PM: Start Custom Sweep 4:21 PM: Sweep initiated using definitions version 899 4:19 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later. 4:15 PM: None 4:15 PM: Traces Found: 0 4:15 PM: Sweep Canceled 4:15 PM: Start Full Sweep 4:15 PM: Sweep initiated using definitions version 899 Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On 4:09 PM: ApplicationMinimized - EXIT 4:09 PM: ApplicationMinimized - ENTER ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 4:09 PM: Shield States 4:09 PM: Spyware Definitions: 899 4:08 PM: Spy Sweeper 5.3.2.2361 started 4:08 PM: Spy Sweeper 5.3.2.2361 started 4:08 PM: | Start of Session, Monday, April 23, 2007 | *************** Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 7:03 AM: Shield States 7:03 AM: Spyware Definitions: 899 7:01 AM: Spy Sweeper 5.3.2.2361 started 7:01 AM: Spy Sweeper 5.3.2.2361 started 7:01 AM: | Start of Session, Monday, April 23, 2007 | *************** Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 3:45 PM: Shield States 3:45 PM: Spyware Definitions: 899 3:43 PM: Spy Sweeper 5.3.2.2361 started 3:43 PM: Spy Sweeper 5.3.2.2361 started 3:43 PM: | Start of Session, Monday, April 23, 2007 | *************** Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 3:52 PM: Shield States 3:52 PM: Spyware Definitions: 899 3:50 PM: Spy Sweeper 5.3.2.2361 started 3:50 PM: Spy Sweeper 5.3.2.2361 started 3:50 PM: | Start of Session, Monday, April 23, 2007 | *************** Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 10:02 AM: Shield States 10:02 AM: Spyware Definitions: 899 10:00 AM: Spy Sweeper 5.3.2.2361 started 10:00 AM: Spy Sweeper 5.3.2.2361 started 10:00 AM: | Start of Session, Sunday, April 22, 2007 | *************** 1:54 PM: ApplicationMinimized - EXIT 1:54 PM: ApplicationMinimized - ENTER 1:54 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE 1:51 PM: ApplicationMinimized - EXIT 1:51 PM: ApplicationMinimized - ENTER 1:51 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE 1:13 PM: ApplicationMinimized - EXIT 1:13 PM: ApplicationMinimized - ENTER 1:13 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 1:07 PM: Shield States 1:07 PM: Spyware Definitions: 899 1:05 PM: Spy Sweeper 5.3.2.2361 started 1:05 PM: Spy Sweeper 5.3.2.2361 started 1:05 PM: | Start of Session, Sunday, April 22, 2007 | *************** 5:57 PM: Your definitions are up to date. 5:57 PM: Automated check for program update in progress. Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 5:57 PM: Shield States 5:57 PM: Spyware Definitions: 899 5:55 PM: Spy Sweeper 5.3.2.2361 started 5:55 PM: Spy Sweeper 5.3.2.2361 started 5:55 PM: | Start of Session, Sunday, April 22, 2007 | *************** Operation: File Access Target: Source: C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE 8:35 PM: Tamper Detection Operation: File Access Target: Source: C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE 6:40 PM: Tamper Detection Operation: File Access Target: Source: 6:40 PM: Tamper Detection Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 6:07 PM: Shield States 6:07 PM: Spyware Definitions: 899 6:07 PM: Spy Sweeper 5.3.2.2361 started 6:07 PM: Spy Sweeper 5.3.2.2361 started 6:07 PM: | Start of Session, Sunday, April 22, 2007 | *************** Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 12:08 AM: Shield States 12:08 AM: Spyware Definitions: 899 12:06 AM: Spy Sweeper 5.3.2.2361 started 12:06 AM: Spy Sweeper 5.3.2.2361 started 12:06 AM: | Start of Session, Saturday, April 21, 2007 | *************** 1:41 PM: ApplicationMinimized - EXIT 1:41 PM: ApplicationMinimized - ENTER 1:41 PM: Deletion from quarantine completed. Elapsed time 00:00:00 1:41 PM: Processing: cws-aboutblank 1:41 PM: Deletion from quarantine initiated 12:47 PM: IE Security Shield: found: C:\PROGRAM FILES\SPYWAREBLASTER\SPYWAREBLASTER.EXE – IE Security modification allowed at user request 12:18 PM: IE Security Shield: found: C:\PROGRAM FILES\SPYWAREBLASTER\SPYWAREBLASTER.EXE – IE Security modification allowed at user request 10:17 AM: ApplicationMinimized - EXIT 10:17 AM: ApplicationMinimized - ENTER 10:17 AM: Removal process completed. Elapsed time 00:00:25 10:17 AM: Quarantining All Traces: cws-aboutblank 10:17 AM: Removal process initiated 10:15 AM: Traces Found: 2 10:15 AM: Full Sweep has completed. Elapsed time 00:18:59 10:15 AM: File Sweep Complete, Elapsed Time: 00:14:39 10:14 AM: Warning: SweepDirectories: Cannot find directory "j:". This directory was not added to the list of paths to be scanned. 10:14 AM: Warning: SweepDirectories: Cannot find directory "i:". This directory was not added to the list of paths to be scanned. 10:14 AM: Warning: SweepDirectories: Cannot find directory "h:". This directory was not added to the list of paths to be scanned. 10:14 AM: Warning: SweepDirectories: Cannot find directory "g:". This directory was not added to the list of paths to be scanned. 10:14 AM: Warning: SweepDirectories: Cannot find directory "f:". This directory was not added to the list of paths to be scanned. 10:14 AM: Warning: SweepDirectories: Cannot find directory "e:". This directory was not added to the list of paths to be scanned. 10:13 AM: ApplicationMinimized - EXIT 10:13 AM: ApplicationMinimized - EXIT 10:13 AM: ApplicationMinimized - ENTER 10:13 AM: ApplicationMinimized - ENTER 10:12 AM: Warning: Failed to open file "c:\documents and settings\owner\local settings\temp\free download manager\tic6d.tmp". The operation completed successfully 10:12 AM: Warning: Failed to open file "c:\documents and settings\owner\cookies\[removed][3].txt". The operation completed successfully 10:12 AM: Warning: Failed to open file "c:\documents and settings\owner\local settings\temporary internet files\content.ie5\4esss4rv\yahoo_2.0.0-b4[1].js". The operation completed successfully 10:00 AM: Starting File Sweep 10:00 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00 10:00 AM: Starting Cookie Sweep 10:00 AM: Registry Sweep Complete, Elapsed Time:00:00:20 10:00 AM: HKLM\software\classes\clsid\{3050f406-98b5-11cf-bb82-00aa00bdce0b}\typelib\ (ID = 115159) 10:00 AM: HKCR\clsid\{3050f406-98b5-11cf-bb82-00aa00bdce0b}\typelib\ (ID = 113584) 10:00 AM: Found Adware: cws-aboutblank 10:00 AM: Starting Registry Sweep 10:00 AM: Memory Sweep Complete, Elapsed Time: 00:03:50 9:56 AM: Starting Memory Sweep 9:56 AM: Start Full Sweep 9:56 AM: Sweep initiated using definitions version 899 9:56 AM: ApplicationMinimized - EXIT 9:56 AM: ApplicationMinimized - ENTER 9:55 AM: Deletion from quarantine completed. Elapsed time 00:00:00 9:55 AM: Processing: cws-aboutblank 9:55 AM: Processing: cws-aboutblank 9:55 AM: Deletion from quarantine initiated Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 9:51 AM: Shield States 9:51 AM: Spyware Definitions: 899 9:49 AM: Spy Sweeper 5.3.2.2361 started 9:49 AM: Spy Sweeper 5.3.2.2361 started 9:49 AM: | Start of Session, Saturday, April 21, 2007 | *************** 2:14 PM: ApplicationMinimized - EXIT 2:14 PM: ApplicationMinimized - ENTER 2:02 PM: None 2:02 PM: Traces Found: 0 2:02 PM: Full Sweep has completed. Elapsed time 00:15:21 2:02 PM: File Sweep Complete, Elapsed Time: 00:11:49 2:01 PM: Warning: SweepDirectories: Cannot find directory "j:". This directory was not added to the list of paths to be scanned. 2:01 PM: Warning: SweepDirectories: Cannot find directory "i:". This directory was not added to the list of paths to be scanned. 2:01 PM: Warning: SweepDirectories: Cannot find directory "h:". This directory was not added to the list of paths to be scanned. 2:01 PM: Warning: SweepDirectories: Cannot find directory "g:". This directory was not added to the list of paths to be scanned. 2:01 PM: Warning: SweepDirectories: Cannot find directory "f:". This directory was not added to the list of paths to be scanned. 2:01 PM: Warning: SweepDirectories: Cannot find directory "e:". This directory was not added to the list of paths to be scanned. 1:50 PM: Starting File Sweep 1:50 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00 1:50 PM: Starting Cookie Sweep 1:50 PM: Registry Sweep Complete, Elapsed Time:00:00:17 1:50 PM: Starting Registry Sweep 1:50 PM: Memory Sweep Complete, Elapsed Time: 00:03:10 1:47 PM: Starting Memory Sweep 1:47 PM: Start Full Sweep 1:47 PM: Sweep initiated using definitions version 899 Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 1:46 PM: Shield States 1:46 PM: Spyware Definitions: 899 1:44 PM: Spy Sweeper 5.3.2.2361 started 1:44 PM: Spy Sweeper 5.3.2.2361 started 1:44 PM: | Start of Session, Saturday, April 21, 2007 | *************** 5:47 PM: Your definitions are up to date. 5:47 PM: Automated check for program update in progress. Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 4:59 PM: Shield States 4:59 PM: Spyware Definitions: 899 4:58 PM: Spy Sweeper 5.3.2.2361 started 4:58 PM: Spy Sweeper 5.3.2.2361 started 4:58 PM: | Start of Session, Saturday, April 21, 2007 | *************** Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 8:28 PM: Shield States 8:28 PM: Spyware Definitions: 899 8:28 PM: Spy Sweeper 5.3.2.2361 started 8:28 PM: Spy Sweeper 5.3.2.2361 started 8:28 PM: | Start of Session, Saturday, April 21, 2007 | *************** Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 8:46 PM: Shield States 8:46 PM: Spyware Definitions: 899 8:44 PM: Spy Sweeper 5.3.2.2361 started 8:44 PM: Spy Sweeper 5.3.2.2361 started 8:44 PM: | Start of Session, Saturday, April 21, 2007 | *************** Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 10:50 PM: Shield States 10:50 PM: Spyware Definitions: 899 10:48 PM: Spy Sweeper 5.3.2.2361 started 10:48 PM: Spy Sweeper 5.3.2.2361 started 10:48 PM: | Start of Session, Saturday, April 21, 2007 | *************** 6:19 AM: ApplicationMinimized - EXIT 6:19 AM: ApplicationMinimized - ENTER 6:19 AM: Ignoring Spy Sweeper subscription renewal. Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 6:03 AM: Shield States 6:03 AM: Spyware Definitions: 898 6:01 AM: Spy Sweeper 5.3.2.2361 started 6:01 AM: Spy Sweeper 5.3.2.2361 started 6:01 AM: | Start of Session, Friday, April 20, 2007 | *************** 7:30 AM: ApplicationMinimized - EXIT 7:30 AM: ApplicationMinimized - ENTER 7:30 AM: None 7:30 AM: Traces Found: 0 7:30 AM: Context File Sweep has completed. Elapsed time 00:00:00 7:30 AM: File Sweep Complete, Elapsed Time: 00:00:00 7:30 AM: Starting File Sweep 7:30 AM: Start Context File Sweep 7:30 AM: Sweep initiated using definitions version 898 Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 7:06 AM: Shield States 7:06 AM: Spyware Definitions: 898 7:04 AM: Spy Sweeper 5.3.2.2361 started 7:04 AM: Spy Sweeper 5.3.2.2361 started 7:04 AM: | Start of Session, Friday, April 20, 2007 | *************** 7:52 PM: ApplicationMinimized - EXIT 7:52 PM: ApplicationMinimized - ENTER Operation: Terminate Target: C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe Source: C:\WINDOWS\system32\csrss.exe 7:52 PM: Tamper Detection Operation: Terminate Target: C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe Source: C:\WINDOWS\system32\csrss.exe 7:52 PM: Tamper Detection 7:51 PM: IE Hijack Shield: On 7:51 PM: IE Hijack Shield: Off 7:48 PM: Removal process completed. Elapsed time 00:00:33 7:48 PM: Quarantining All Traces: cws-aboutblank 7:48 PM: Removal process initiated 7:31 PM: Traces Found: 2 7:31 PM: Full Sweep has completed. Elapsed time 00:22:47 7:31 PM: File Sweep Complete, Elapsed Time: 00:18:49 7:24 PM: Warning: TCompressedFile.GetStreams(1): Stream read error 7:24 PM: Warning: TCompressedFile.GetStreams(1): Stream read error 7:24 PM: Warning: TCompressedFile.GetStreams(1): Stream read error 7:24 PM: Warning: TCompressedFile.GetStreams(1): Stream read error 7:24 PM: Warning: SweepDirectories: Cannot find directory "j:". This directory was not added to the list of paths to be scanned. 7:24 PM: Warning: SweepDirectories: Cannot find directory "i:". This directory was not added to the list of paths to be scanned. 7:24 PM: Warning: SweepDirectories: Cannot find directory "h:". This directory was not added to the list of paths to be scanned. 7:24 PM: Warning: SweepDirectories: Cannot find directory "g:". This directory was not added to the list of paths to be scanned. 7:24 PM: Warning: SweepDirectories: Cannot find directory "f:". This directory was not added to the list of paths to be scanned. 7:24 PM: Warning: SweepDirectories: Cannot find directory "e:". This directory was not added to the list of paths to be scanned. 7:12 PM: Starting File Sweep 7:12 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00 7:12 PM: Starting Cookie Sweep 7:12 PM: Registry Sweep Complete, Elapsed Time:00:00:20 7:12 PM: HKLM\software\classes\clsid\{3050f406-98b5-11cf-bb82-00aa00bdce0b}\typelib\ (ID = 115159) 7:12 PM: HKCR\clsid\{3050f406-98b5-11cf-bb82-00aa00bdce0b}\typelib\ (ID = 113584) 7:12 PM: Found Adware: cws-aboutblank 7:12 PM: Starting Registry Sweep 7:12 PM: Memory Sweep Complete, Elapsed Time: 00:03:27 7:08 PM: Starting Memory Sweep 7:08 PM: Start Full Sweep 7:08 PM: Sweep initiated using definitions version 899 5:47 PM: Your spyware definitions have been updated. Operation: File Access Target: Source: 5:47 PM: Tamper Detection 5:47 PM: Automated check for program update in progress. Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 5:47 PM: Shield States 5:47 PM: Spyware Definitions: 898 5:45 PM: Spy Sweeper 5.3.2.2361 started 5:45 PM: Spy Sweeper 5.3.2.2361 started 5:45 PM: | Start of Session, Friday, April 20, 2007 | *************** Operation: Terminate Target: C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe Source: C:\WINDOWS\system32\csrss.exe 9:18 PM: Tamper Detection Operation: Terminate Target: C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe Source: C:\WINDOWS\system32\csrss.exe 9:18 PM: Tamper Detection Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 9:14 PM: Shield States 9:14 PM: Spyware Definitions: 899 9:14 PM: Spy Sweeper 5.3.2.2361 started 9:14 PM: Spy Sweeper 5.3.2.2361 started 9:14 PM: | Start of Session, Friday, April 20, 2007 | *************** Keylogger: On BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 9:22 PM: Shield States 9:22 PM: Spyware Definitions: 899 9:20 PM: Spy Sweeper 5.3.2.2361 started 9:20 PM: Spy Sweeper 5.3.2.2361 started 9:20 PM: | Start of Session, Friday, April 20, 2007 | ***************
Much as I suspected Spyswweeper isn't telling me where it found anything.
___________________________________
You may want to print these out or save tham as a text document on your desktop as we will be going into safe mode and this page (internet ) will not be available.


Download CWShredder Here to its own folder.

Update CWShredder
  • Open CWShredder and click I AGREE
  • Click Check For Update
  • Close CWShredder
  • Don't run it yet


___________________________
Create a new folder on your desktop call it Buster

Please download to the buster folder you just made.
AboutBuster.
  • Extract both files to that folder also


________________________________
Boot into Safe Mode:
Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.


___________________________
Now run CWShredder. Click I Agree, then Fix and then Next, let it fix everything it asks about. Reboot your computer into normal windows.



____________________________
  • Open AboutBuster and click the "Begin Removal" button. AboutBuster will finish and open a new page. Follow the instructions for protection on that page. It will shut down all Explorer windows (if open) while it works.
  • It will begin to check your computer for malicious files. If it
    asks if you would like to do a second pass, allow it to do so.
  • When it has finished, click Save Log. Post that log for me.
Note: If you receive any error messages please open the readme file in the AboutBuster folder and follow the directions provided for correcting that error.



If either of them found anything go ahead and rerun webroot Spy sweeper again and see if it detects it. I don't need to see the log this time just let me know.

Also please post a new HJT log for me.
bob4,

Logfile of HijackThis v1.99.1
Scan saved at 8:48:01 AM, on 4/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TrojanHunter 4.6\THGuard.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\zHotkey.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\pccguide.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Creative\MediaSource5\MtdAcqu.exe
C:\Program Files\Creative\MediaSource5\CTDetctu.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:4001
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.6\THGuard.exe"
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [pccguide.exe] C:\PROGRA~1\TRENDM~1\INTERN~2\pccguide.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [MtdAcqu] "C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" /s
O4 - HKCU\..\Run: [Creative Detector U] "C:\Program Files\Creative\MediaSource5\CTDetctu.exe" /R
O4 - HKCU\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://mail.polarbev.com/iNotes6W.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1176516260359
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

AboutBuster 6.06
Scan started on [4/25/2007] at [10:04:17 AM]
————————————————————-
Internet Explorer Instances Terminated!
HomeSearch Service stopped if present
————————————————————-
No Ads Found!
————————————————————-
No Files Found!
————————————————————-
Scan was COMPLETED SUCCESSFULLY at 10:06:33 AM


AboutBuster 6.06
Scan started on [4/25/2007] at [8:27:09 PM]
————————————————————-
Internet Explorer Instances Terminated!
HomeSearch Service stopped if present
————————————————————-
No Ads Found!
————————————————————-
No Files Found!
————————————————————-
Scan was COMPLETED SUCCESSFULLY at 8:29:50 PM


Also, Spysweeper came up clean!
I'm glad spysweeper came up clean. I wish I could take credit for this but I have no reason to think I did anything. :scratch:

As your log is clean your good to go.


Great news ! [external image: Posted Image]

Your log now appears to be clean.

Lets do a few things to tidy up.
Please do these in the order I suggest!


___________________________________
If we have set your computer to see all files and folders we must reprotect them.

UNDO SHOW ALL FILES
click on the My Computer icon.
Select the Tools menu and click Folder Options.
After the new window appears select the View tab.
Deselect in the checkbox labeled Display the contents of system folders.
Deselect the checkbox labeled Show hidden files and folders.
Select the checkmark from the checkbox labeled Hide file extensions for known file types.
Replace the checkmark from the checkbox labeled Hide protected operating system files.
Press the Apply button and then the OK .
Now many important files are safe.




___________________________________
Please create a 'clean' System Restore Point:
The reason for doing this is in case you need system restore you don't put back all we just took out.
Right click My Computer
Then Propeties then system restore
Place a check mark by turn off system restore
Click APPLY
Windows will give you a warning click yes
REBOOT

Now go right back to the same place and unchecksystem restore
Click APPLYand OK





___________________________________
A few things to help with possible threats
SpywareBlaster

Install SpywareBlaster

SpywareBlaster will add a large list of programs and sites to your Internet Explorer settings that will protect you from accidentally running or downloading known malicious programs.
After the installation, click Download Latest Protection Updates. When it finishes, click Enable All Protection.





___________________________________
Download and keep these updated and run weekly if you don't already have them.

Adaware
Tutorial

spybot seach & destroy
Tutorial




___________________________________
Download and Install a HOSTS File
A Hosts file is a plain text file which prevents your computer from connecting to malware and spyware sites by redirecting the connection request to 127.0.0.1, which is your local address. If you use a proxy server, or if you are on AOL, be sure to read the special instructions.
You can download the MVPS Hosts File and see a HOSTS file tutorial here :
This website also contains useful tips, and links to other resources and utilities.


___________________________________
Make your Internet Explorer more secure
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click on the Security tab
3. Click the Internet icon so it becomes highlighted.
4. Click on Default Level and click Ok
5. Click on the Custom Level button.

Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.

6. Next press the Apply button and then the OK to exit the Internet Properties page.


Safe and Happy Surfing. :)
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a valid link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used.
If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI