billyr50
sorry about taking so ;ong but I was ouy of town today. Also sorry about the computer, I have kids, LOL Hope you will bear with me as I go back to work Tuesday and I work 12 hour shifts. I will answer as soon as I can so PLEASE dont give up om me, Thanks a lot, I really appreciate this help you are giving me.
billy
PS Hope this is the right spysweeper file I was in a hurry and when I logged back in I have soooooo many things popping up. Plwase let me know when I cant turn some of those things off in my msconfig startup.
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:18 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:18 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:18 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:18 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: – BHO installation denied at user request
9:16 PM: Warning: no filename sent to VerifyFileSignature
9:16 PM: BHO Shield: found: – BHO installation denied at user request
9:16 PM: Warning: no filename sent to VerifyFileSignature
9:16 PM: BHO Shield: found: – BHO installation denied at user request
9:16 PM: Warning: no filename sent to VerifyFileSignature
9:16 PM: BHO Shield: found: – BHO installation denied at user request
9:16 PM: Warning: no filename sent to VerifyFileSignature
Keylogger: Off
E-mail Attachment: On
9:15 PM: Informational: ShieldEmail: Start monitoring port 25 for mail activities
9:15 PM: Informational: ShieldEmail: Start monitoring port 110 for mail activities
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: Off
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
File System Shield: On
Execution Shield: On
System Services Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
9:14 PM: Shield States
9:14 PM: License Check Status (0): Success
9:14 PM: Spyware Definitions: 935
9:12 PM: Spy Sweeper 5.5.1.3356 started
9:12 PM: Spy Sweeper 5.5.1.3356 started
9:12 PM: | Start of Session, Sunday, June 24, 2007 |
***************
Operation: File Access
Target:
Source: C:\DOCUME~1\JACK\LOCALS~1\TEMP\IS-HNSLM.TMP\IS-BITTQ.TMP
5:34 PM: Tamper Detection
5:31 PM: Your definitions are up to date.
5:31 PM: Automated check for program update in progress.
Keylogger: Off
5:31 PM: Informational: ShieldEmail: Start monitoring port 25 for mail activities
E-mail Attachment: On
5:31 PM: Informational: ShieldEmail: Start monitoring port 110 for mail activities
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: Off
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
File System Shield: On
Execution Shield: On
System Services Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
5:31 PM: Shield States
5:31 PM: License Check Status (0): Success
5:30 PM: Spyware Definitions: 935
5:28 PM: Spy Sweeper 5.5.1.3354 started
5:28 PM: Spy Sweeper 5.5.1.3354 started
5:28 PM: | Start of Session, Sunday, June 24, 2007 |
***************
5:45 PM: Warning: DoInject :\Device\HarddiskVolume1\WINDOWS\system32\csrss.exe
5:44 PM: Informational: ShieldEmail: Start monitoring port 25 for mail activities
Keylogger: Off
E-mail Attachment: On
5:44 PM: Informational: ShieldEmail: Start monitoring port 110 for mail activities
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: Off
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
File System Shield: On
Execution Shield: On
System Services Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
5:44 PM: Shield States
5:44 PM: License Check Status (0): Success
5:44 PM: Spyware Definitions: 935
5:41 PM: Spy Sweeper 5.5.1.3356 started
5:41 PM: Spy Sweeper 5.5.1.3356 started
5:41 PM: | Start of Session, Sunday, June 24, 2007 |
***************
5:50 PM: Program Version 5.5.1.3356 Using Spyware Definitions 935
5:50 PM: Spy Sweeper 5.5.1.3356 started
5:50 PM: | Start of Session, Sunday, June 24, 2007 |
***************
6:39 PM: Removal process completed. Elapsed time 00:01:34
6:39 PM: Preparing to restart your computer. Please wait…
6:38 PM: Quarantining All Traces: zedo cookie
6:38 PM: Quarantining All Traces: tendollars cookie
6:38 PM: Quarantining All Traces: winantiviruspro cookie
6:38 PM: Quarantining All Traces: jumptothat cookie
6:38 PM: Quarantining All Traces: realtracker cookie
6:38 PM: Quarantining All Traces: tribalfusion cookie
6:38 PM: Quarantining All Traces: adbureau cookie
6:38 PM: Quarantining All Traces: webtrendslive cookie
6:38 PM: Quarantining All Traces: reliablestats cookie
6:38 PM: Quarantining All Traces: statcounter cookie
6:38 PM: Quarantining All Traces: serving-sys cookie
6:38 PM: Quarantining All Traces: search123 cookie
6:38 PM: Quarantining All Traces: realmedia cookie
6:38 PM: Quarantining All Traces: rambler cookie
6:38 PM: Quarantining All Traces: questionmarket cookie
6:38 PM: Quarantining All Traces: pro-market cookie
6:38 PM: Quarantining All Traces: pch cookie
6:38 PM: Quarantining All Traces: overture cookie
6:38 PM: Quarantining All Traces: mygeek cookie
6:38 PM: Quarantining All Traces: mediaplex cookie
6:38 PM: Quarantining All Traces: linksynergy cookie
6:38 PM: Quarantining All Traces: ic-live cookie
6:38 PM: Quarantining All Traces: screensavers.com cookie
6:38 PM: Quarantining All Traces: epilot cookie
6:38 PM: Quarantining All Traces: enhance cookie
6:38 PM: Quarantining All Traces: ru4 cookie
6:38 PM: Quarantining All Traces: did-it cookie
6:38 PM: Quarantining All Traces: coolsavings cookie
6:38 PM: Quarantining All Traces: clickbank cookie
6:38 PM: Quarantining All Traces: casalemedia cookie
6:38 PM: Quarantining All Traces: trafficmp cookie
6:38 PM: Quarantining All Traces: burstnet cookie
6:38 PM: Quarantining All Traces: bs.serving-sys cookie
6:38 PM: Quarantining All Traces: bravenet cookie
6:38 PM: Quarantining All Traces: atwola cookie
6:38 PM: Quarantining All Traces: atlas dmt cookie
6:38 PM: Quarantining All Traces: tacoda cookie
6:38 PM: Quarantining All Traces: primaryads cookie
6:38 PM: Quarantining All Traces: advertising cookie
6:38 PM: Quarantining All Traces: cpxinteractive cookie
6:38 PM: Quarantining All Traces: adserver cookie
6:38 PM: Quarantining All Traces: searchingbooth cookie
6:38 PM: Quarantining All Traces: pointroll cookie
6:38 PM: Quarantining All Traces: addynamix cookie
6:38 PM: Quarantining All Traces: adrevolver cookie
6:38 PM: Quarantining All Traces: specificclick.com cookie
6:38 PM: Quarantining All Traces: adlegend cookie
6:38 PM: Quarantining All Traces: yieldmanager cookie
6:38 PM: Quarantining All Traces: websponsors cookie
6:38 PM: Quarantining All Traces: 2o7.net cookie
6:38 PM: Quarantining All Traces: maxifiles
6:38 PM: Quarantining All Traces: coolwebsearch (cws)
6:38 PM: Quarantining All Traces: purityscan
6:38 PM: Quarantining All Traces: trojan-phisher-us15info
6:38 PM: Quarantining All Traces: zenosearchassistant
6:38 PM: Quarantining All Traces: seekmo search assistant
6:38 PM: Quarantining All Traces: weirdontheweb
6:37 PM: Quarantining All Traces: mediapipe
6:37 PM: Quarantining All Traces: clearsearch
6:37 PM: Quarantining All Traces: whenu savenow
6:37 PM: Quarantining All Traces: pinfo dialer
6:37 PM: Quarantining All Traces: keenvalue/perfectnav
6:37 PM: Quarantining All Traces: gain - common components
6:37 PM: Quarantining All Traces: clipgenie
6:37 PM: Quarantining All Traces: bookedspace
6:37 PM: Quarantining All Traces: blazefind
6:37 PM: Quarantining All Traces: apropos
6:37 PM: Quarantining All Traces: altnet
6:37 PM: vtutr.dll is in use. It will be removed on reboot.
6:37 PM: virtumonde is in use. It will be removed on reboot.
6:37 PM: Warning: Launched explorer.exe
6:37 PM: Quarantining All Traces: virtumonde
6:37 PM: Quarantining All Traces: cydoor
6:37 PM: Quarantining All Traces: 180search assistant/zango
6:37 PM: Quarantining All Traces: internetoptimizer
6:37 PM: Removal process initiated
6:37 PM: Traces Found: 157
6:37 PM: Custom Sweep has completed. Elapsed time 00:46:16
6:37 PM: File Sweep Complete, Elapsed Time: 00:44:56
6:29 PM: zxdnt3d.cfg (ID = 91140)
5:58 PM: think-adz.lnk (ID = 372576)
5:52 PM: Starting File Sweep
5:52 PM: Warning: SweepDirectories: Cannot find directory "a:". This directory was not added to the list of paths to be scanned.
5:52 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
5:52 PM: jack@zedo[2].txt (ID = 3762)
5:52 PM: jack@zedo[1].txt (ID = 3762)
5:52 PM: Found Spy Cookie: zedo cookie
5:52 PM: [removed][1].txt (ID = 6367)
5:52 PM: Found Spy Cookie: tendollars cookie
5:52 PM: [removed][1].txt (ID = 3690)
5:52 PM: Found Spy Cookie: winantiviruspro cookie
5:52 PM: [removed][1].txt (ID = 3298)
5:52 PM: [removed][4].txt (ID = 3124)
5:52 PM: [removed][2].txt (ID = 3124)
5:52 PM: [removed][1].txt (ID = 3124)
5:52 PM: [removed][2].txt (ID = 2894)
5:52 PM: [removed][1].txt (ID = 2894)
5:52 PM: Found Spy Cookie: jumptothat cookie
5:52 PM: [removed][2].txt (ID = 2622)
5:52 PM: [removed][1].txt (ID = 2622)
5:52 PM: [removed][3].txt (ID = 2337)
5:52 PM: [removed][2].txt (ID = 2337)
5:52 PM: [removed][1].txt (ID = 3242)
5:52 PM: Found Spy Cookie: realtracker cookie
5:52 PM: jack@tribalfusion[2].txt (ID = 3589)
5:52 PM: jack@tribalfusion[1].txt (ID = 3589)
5:52 PM: Found Spy Cookie: tribalfusion cookie
5:52 PM: [removed][3].txt (ID = 2060)
5:52 PM: [removed][2].txt (ID = 2060)
5:52 PM: [removed][1].txt (ID = 2060)
5:52 PM: Found Spy Cookie: adbureau cookie
5:52 PM: jack@trafficmp[4].txt (ID = 3581)
5:52 PM: jack@trafficmp[2].txt (ID = 3581)
5:52 PM: jack@trafficmp[1].txt (ID = 3581)
5:52 PM: jack@tacoda[2].txt (ID = 6444)
5:52 PM: jack@tacoda[1].txt (ID = 6444)
5:52 PM: [removed][1].txt (ID = 3667)
5:52 PM: Found Spy Cookie: webtrendslive cookie
5:52 PM: [removed][2].txt (ID = 3254)
5:52 PM: [removed][1].txt (ID = 3254)
5:52 PM: Found Spy Cookie: reliablestats cookie
5:52 PM: jack@statcounter[2].txt (ID = 3447)
5:52 PM: jack@statcounter[1].txt (ID = 3447)
5:52 PM: Found Spy Cookie: statcounter cookie
5:52 PM: jack@specificclick[3].txt (ID = 3399)
5:52 PM: jack@specificclick[2].txt (ID = 3399)
5:52 PM: jack@specificclick[1].txt (ID = 3399)
5:52 PM: jack@serving-sys[2].txt (ID = 3343)
5:52 PM: jack@serving-sys[1].txt (ID = 3343)
5:52 PM: Found Spy Cookie: serving-sys cookie
5:52 PM: jack@search123[2].txt (ID = 3305)
5:52 PM: jack@search123[1].txt (ID = 3305)
5:52 PM: Found Spy Cookie: search123 cookie
5:52 PM: jack@screensavers[2].txt (ID = 3297)
5:52 PM: [removed][2].txt (ID = 3124)
5:52 PM: [removed][1].txt (ID = 3124)
5:52 PM: jack@realmedia[2].txt (ID = 3235)
5:52 PM: Found Spy Cookie: realmedia cookie
5:52 PM: jack@rambler[3].txt (ID = 3225)
5:52 PM: jack@rambler[2].txt (ID = 3225)
5:52 PM: Found Spy Cookie: rambler cookie
5:52 PM: jack@questionmarket[4].txt (ID = 3217)
5:52 PM: jack@questionmarket[3].txt (ID = 3217)
5:52 PM: jack@questionmarket[2].txt (ID = 3217)
5:52 PM: Found Spy Cookie: questionmarket cookie
5:52 PM: jack@pro-market[2].txt (ID = 3197)
5:52 PM: Found Spy Cookie: pro-market cookie
5:52 PM: [removed][2].txt (ID = 3106)
5:52 PM: [removed][1].txt (ID = 3106)
5:52 PM: jack@pch[2].txt (ID = 3123)
5:52 PM: jack@pch[1].txt (ID = 3123)
5:52 PM: Found Spy Cookie: pch cookie
5:52 PM: jack@pch.122.2o7[2].txt (ID = 1958)
5:52 PM: jack@pch.122.2o7[1].txt (ID = 1958)
5:52 PM: jack@overture[1].txt (ID = 3105)
5:52 PM: Found Spy Cookie: overture cookie
5:52 PM: jack@newmotioninc.112.2o7[1].txt (ID = 1958)
5:52 PM: jack@mygeek[4].txt (ID = 3041)
5:52 PM: jack@mygeek[3].txt (ID = 3041)
5:52 PM: jack@mygeek[2].txt (ID = 3041)
5:52 PM: jack@mygeek[1].txt (ID = 3041)
5:52 PM: Found Spy Cookie: mygeek cookie
5:52 PM: jack@mediaplex[2].txt (ID = 6442)
5:52 PM: jack@mediaplex[1].txt (ID = 6442)
5:52 PM: Found Spy Cookie: mediaplex cookie
5:52 PM: jack@maxim.122.2o7[1].txt (ID = 1958)
5:52 PM: jack@lsfnetwork.122.2o7[3].txt (ID = 1958)
5:52 PM: jack@lsfnetwork.122.2o7[2].txt (ID = 1958)
5:52 PM: jack@lsfnetwork.122.2o7[1].txt (ID = 1958)
5:52 PM: jack@linksynergy[1].txt (ID = 2926)
5:52 PM: Found Spy Cookie: linksynergy cookie
5:52 PM: jack@ic-live[1].txt (ID = 2821)
5:52 PM: Found Spy Cookie: ic-live cookie
5:52 PM: [removed][1].txt (ID = 3298)
5:52 PM: Found Spy Cookie: screensavers.com cookie
5:52 PM: jack@heavycom.122.2o7[1].txt (ID = 1958)
5:52 PM: jack@epilot[2].txt (ID = 2621)
5:52 PM: jack@epilot[1].txt (ID = 2621)
5:52 PM: Found Spy Cookie: epilot cookie
5:52 PM: jack@entrepreneur.122.2o7[2].txt (ID = 1958)
5:52 PM: jack@entrepreneur.122.2o7[1].txt (ID = 1958)
5:52 PM: jack@enhance[2].txt (ID = 2613)
5:52 PM: Found Spy Cookie: enhance cookie
5:52 PM: jack@electronicarts.112.2o7[2].txt (ID = 1958)
5:52 PM: jack@electronicarts.112.2o7[1].txt (ID = 1958)
5:52 PM: jack@edge.ru4[3].txt (ID = 3269)
5:52 PM: jack@edge.ru4[1].txt (ID = 3269)
5:52 PM: Found Spy Cookie: ru4 cookie
5:52 PM: jack@did-it[1].txt (ID = 2523)
5:52 PM: Found Spy Cookie: did-it cookie
5:52 PM: jack@coolsavings[1].txt (ID = 2465)
5:52 PM: Found Spy Cookie: coolsavings cookie
5:52 PM: jack@clickbank[1].txt (ID = 2398)
5:52 PM: Found Spy Cookie: clickbank cookie
5:52 PM: jack@casalemedia[3].txt (ID = 2354)
5:52 PM: jack@casalemedia[2].txt (ID = 2354)
5:52 PM: jack@casalemedia[1].txt (ID = 2354)
5:52 PM: Found Spy Cookie: casalemedia cookie
5:52 PM: [removed][3].txt (ID = 3582)
5:52 PM: [removed][2].txt (ID = 3582)
5:52 PM: Found Spy Cookie: trafficmp cookie
5:52 PM: jack@burstnet[2].txt (ID = 2336)
5:52 PM: Found Spy Cookie: burstnet cookie
5:52 PM: [removed]-sys[1].txt (ID = 2330)
5:52 PM: Found Spy Cookie: bs.serving-sys cookie
5:52 PM: jack@bravenet[2].txt (ID = 2322)
5:52 PM: Found Spy Cookie: bravenet cookie
5:52 PM: jack@blockbuster.112.2o7[1].txt (ID = 1958)
5:52 PM: jack@atwola[2].txt (ID = 2255)
5:52 PM: jack@atwola[1].txt (ID = 2255)
5:52 PM: Found Spy Cookie: atwola cookie
5:52 PM: jack@atdmt[4].txt (ID = 2253)
5:52 PM: jack@atdmt[3].txt (ID = 2253)
5:52 PM: jack@atdmt[2].txt (ID = 2253)
5:52 PM: Found Spy Cookie: atlas dmt cookie
5:52 PM: [removed][3].txt (ID = 6445)
5:52 PM: [removed][1].txt (ID = 6445)
5:52 PM: [removed][3].txt (ID = 6445)
5:52 PM: [removed][2].txt (ID = 6445)
5:52 PM: [removed][1].txt (ID = 6445)
5:52 PM: Found Spy Cookie: tacoda cookie
5:52 PM: [removed][1].txt (ID = 3190)
5:52 PM: Found Spy Cookie: primaryads cookie
5:52 PM: jack@advertising[3].txt (ID = 2175)
5:52 PM: jack@advertising[2].txt (ID = 2175)
5:52 PM: jack@advertising[1].txt (ID = 2175)
5:52 PM: Found Spy Cookie: advertising cookie
5:52 PM: [removed][3].txt (ID = 8939)
5:52 PM: [removed][2].txt (ID = 8939)
5:52 PM: Found Spy Cookie: cpxinteractive cookie
5:52 PM: jack@adserver[1].txt (ID = 2141)
5:52 PM: Found Spy Cookie: adserver cookie
5:52 PM: [removed][2].txt (ID = 3322)
5:52 PM: [removed][1].txt (ID = 3322)
5:52 PM: Found Spy Cookie: searchingbooth cookie
5:52 PM: [removed][3].txt (ID = 3148)
5:52 PM: [removed][2].txt (ID = 3148)
5:52 PM: Found Spy Cookie: pointroll cookie
5:52 PM: [removed][2].txt (ID = 2062)
5:52 PM: Found Spy Cookie: addynamix cookie
5:52 PM: jack@adrevolver[2].txt (ID = 2088)
5:52 PM: Found Spy Cookie: adrevolver cookie
5:52 PM: [removed][3].txt (ID = 3400)
5:52 PM: [removed][2].txt (ID = 3400)
5:52 PM: Found Spy Cookie: specificclick.com cookie
5:52 PM: jack@adlegend[2].txt (ID = 2074)
5:52 PM: Found Spy Cookie: adlegend cookie
5:52 PM: [removed][4].txt (ID = 3751)
5:52 PM: [removed][3].txt (ID = 3751)
5:52 PM: [removed][2].txt (ID = 3751)
5:52 PM: [removed][1].txt (ID = 3751)
5:52 PM: Found Spy Cookie: yieldmanager cookie
5:52 PM: [removed][1].txt (ID = 3665)
5:52 PM: Found Spy Cookie: websponsors cookie
5:52 PM: jack@2o7[3].txt (ID = 1957)
5:52 PM: jack@2o7[2].txt (ID = 1957)
5:52 PM: jack@2o7[1].txt (ID = 1957)
5:52 PM: Found Spy Cookie: 2o7.net cookie
5:52 PM: Starting Cookie Sweep
5:52 PM: Registry Sweep Complete, Elapsed Time:00:01:00
5:52 PM: HKU\S-1-5-21-826843164-2093118864-934546170-1004\software\microsoft\windows\currentversion\run\ || ipwins (ID = 2089537)
5:52 PM: Found Adware: maxifiles
5:52 PM: HKU\S-1-5-21-826843164-2093118864-934546170-1004\software\microsoft\windows\currentversion\run\ || rundll32 (ID = 112406)
5:52 PM: Found Adware: coolwebsearch (cws)
5:52 PM: HKLM\software\microsoft\windows\currentversion\run\ || apachinc (ID = 2243679)
5:52 PM: HKLM\software\microsoft\aoprndtws\ (ID = 2128500)
5:52 PM: HKLM\software\microsoft\windows\currentversion\uninstall\outerinfo\ (ID = 2063030)
5:52 PM: Found Adware: purityscan
5:52 PM: HKLM\system\controlset001\enum\root\legacy_msasvc\ (ID = 1847035)
5:52 PM: Found Trojan Horse: trojan-phisher-us15info
5:52 PM: HKLM\software\microsoft\windows\currentversion\uninstall\think-adz search assistant\ (ID = 1697587)
5:52 PM: HKLM\software\microsoft\windows\currentversion\uninstall\enhanced ads by think-adz\ (ID = 1697586)
5:52 PM: HKLM\software\microsoft\windows\currentversion\run\ || exploreupdsched (ID = 1581139)
5:52 PM: Found Adware: zenosearchassistant
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || seekmo (ID = 1042293)
5:51 PM: Found Adware: seekmo search assistant
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || altpayments (ID = 867147)
5:51 PM: Found Adware: weirdontheweb
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || mediapipetrayicon (ID = 867146)
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || mediapipe p2p loader (ID = 867145)
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || mediapipe (ID = 867144)
5:51 PM: Found Adware: mediapipe
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || prositefinder (ID = 776277)
5:51 PM: Found Adware: clearsearch
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || zanu (ID = 147911)
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || zango (ID = 147910)
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || vvsn (ID = 140442)
5:51 PM: Found Adware: whenu savenow
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || lisa (ID = 136750)
5:51 PM: Found Adware: pinfo dialer
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || updmgr (ID = 129511)
5:51 PM: Found Adware: keenvalue/perfectnav
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || internet optimizer (ID = 128916)
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || trickler (ID = 126781)
5:51 PM: Found Adware: gain - common components
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || webinstall2 (ID = 105923)
5:51 PM: Found Adware: clipgenie
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || bxxs5 (ID = 104881)
5:51 PM: Found Adware: bookedspace
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || rundll (ID = 104535)
5:51 PM: Found Adware: blazefind
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || autoupdater (ID = 103803)
5:51 PM: Found Adware: apropos
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || altnetpointsmanager (ID = 103518)
5:51 PM: Found Adware: altnet
5:51 PM: Memory Sweep Complete, Elapsed Time: 00:00:00
5:51 PM: Starting Registry Sweep
5:51 PM: Detected running threat: vtutr.dll (ID = 676)
5:51 PM: Found Adware: virtumonde
5:51 PM: Starting Memory Sweep
5:51 PM: HKU\S-1-5-21-826843164-2093118864-934546170-1004\software\microsoft\windows\currentversion\run\ || cydoor (ID = 1614054)
5:51 PM: Found Adware: cydoor
5:50 PM: HKLM\software\microsoft\windows\currentversion\run\ || zango (ID = 1533958)
5:50 PM: Found Adware: 180search assistant/zango
5:50 PM: Warning: TFileCountEnum.ProcessPartition: TVolume.Read: read past end of volume size: 0 reading cluster: 0
5:50 PM: HKLM\software\microsoft\windows\currentversion\run\ || internet optimizer (ID = 1193579)
5:50 PM: Found Adware: internetoptimizer
5:50 PM: Sweep initiated using definitions version 935
5:50 PM: Spy Sweeper 5.5.1.3356 started
5:50 PM: | Start of Session, Sunday, June 24, 2007 |
Logfile of HijackThis v1.99.1
Scan saved at 9:39:50 PM, on 6/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\locator.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Blubster\Blubster.exe
C:\windows\system32\kncffxl.exe
C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.iwon.com/iwon-homepage/home.jhtml
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [{E6-69-9C-C1-ZN}] c:\windows\system32\dwdsregt.exe CHD003
O4 - HKLM\..\Run: [{484E69C1-0963-1033-0803-040527030001}] "C:\Program Files\Common Files\{484E69C1-0963-1033-0803-040527030001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [{484E69C1-0962-1033-0803-040527030001}] "C:\Program Files\Common Files\{484E69C1-0962-1033-0803-040527030001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [yarlwpg] c:\windows\system32\xdwbyih.exe r
O4 - HKLM\..\Run: [wmplayer] C:\Program Files\Windows Media Player\wmplayer.exe
O4 - HKLM\..\Run: [wfxxvyt] c:\windows\system32\hfhihsf.exe r
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [vqtqakj] c:\windows\system32\ernjwo.exe r
O4 - HKLM\..\Run: [tLE] C:\documents and settings\jack\local settings\temp\tLE.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [tgragr] c:\windows\system32\yepnfes.exe r
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [RunOnce2Upd] "C:\WINDOWS\system32\KB_963493.exe"
O4 - HKLM\..\Run: [rrsrqp] c:\windows\system32\aiiebmx.exe r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ProfileWatcher] C:\Program Files\ProfileWatcher\profilewatcher.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [palxtns] c:\windows\system32\gvgpgj.exe r
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater1.03.0000.1005\en-us\msnappau.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [klsfmtg] c:\windows\system32\abyjps.exe r
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [kaxogr] c:\windows\system32\sibndlx.exe r
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [j6271132] rundll32 C:\WINDOWS\system32\j6271132.dll sook
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [isigaps] c:\windows\system32\jsbpbh.exe r
O4 - HKLM\..\Run: [iRiver Updater] C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe
O4 - HKLM\..\Run: [infamous.exe] C:\Program Files\Windows Media Player\wmplayer.exe
O4 - HKLM\..\Run: [ihkbynsd.exe] C:\Documents and Settings\All Users\Application Data\ihkbynsd.exe
O4 - HKLM\..\Run: [ietjumj] c:\windows\system32\zrrrug.exe r
O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [hegnkl] c:\windows\system32\qwzhfud.exe r
O4 - HKLM\..\Run: [gsyjth] c:\windows\system32\egdijvz.exe r
O4 - HKLM\..\Run: [gmGW] C:\documents and settings\jack\local settings\temp\gmGW.exe
O4 - HKLM\..\Run: [gatigz] c:\windows\system32\gsorklq.exe r
O4 - HKLM\..\Run: [cvcvetx] c:\windows\system32\ddvseca.exe r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [cofsumtbk] c:\windows\system32\cofsumtbk.exe cofsumtbk
O4 - HKLM\..\Run: [cgbdwwc] c:\windows\system32\kxjdlkp.exe r
O4 - HKLM\..\Run: [Blubster] C:\Program Files\Blubster\Blubster.exe SILENT
O4 - HKLM\..\Run: [bhxydp] c:\windows\system32\wexzkev.exe r
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AuditMode] C:\sysprep\factory.exe -logon
O4 - HKLM\..\Run: [ASM] "C:\Program Files\AOL\Active Security Monitor\ASMonitor.exe"
O4 - HKLM\..\Run: [alsermj] c:\windows\system32\sdtnde.exe r
O4 - HKLM\..\Run: [alqeqvc] c:\windows\system32\rjnugel.exe r
O4 - HKLM\..\Run: [aioyyms] c:\windows\system32\tonbfjh.exe r
O4 - HKLM\..\Run: [aaT] C:\documents and settings\jack\local settings\temp\aaT.exe
O4 - HKLM\..\Run: [iolo Personal Firewall®] "C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [userinit] C:\WINDOWS\system32\ntos.exe
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Oorp] "C:\PROGRA~1\COMMON~1\STEM~1\notepad.exe" -vt yazb
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Loia] C:\Documents and Settings\jack\Application Data\tcaa.exe
O4 - HKCU\..\Run: [IDMan] C:\PROGRA~1\INTERN~2\IDMan.exe /onboot
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [csrss] C:\WINDOWS\csrss.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\jack\Local Settings\Temp\TICHD003.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Kaspersky Anti-Hacker.lnk = C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~3\tools\iesdpb.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O16 - DPF: PCPitstop-Tracks-Checker - http://www.pcpitstop.com/privacy/PCPTracks.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/12119/CTSUEng.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1180221127171
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) - http://63.241.168.238/ae/ecwplugins/ncs1.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {BA61B6AE-9EDE-42EE-92C6-C938DEBCAFF3} - http://www.kerclink.com/download/setup.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.13.16/ttinst.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://ds1.downloadtech.net/cn1060/pcpowerscan.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/12119/CTPID.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinner.com/games/v51/h2hpool/h2hpool.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{57AA5BF8-81C3-4E4A-A7DD-72987CF3B47F}: NameServer = 208.67.220.220 208.67.222.222
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AFSEGTGF Windows Service - Unknown owner - C:\WINDOWS\system32\dsfms.exe (file missing)
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo DMV Service (ioloDMV) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
billy
PS Hope this is the right spysweeper file I was in a hurry and when I logged back in I have soooooo many things popping up. Plwase let me know when I cant turn some of those things off in my msconfig startup.
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:19 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:18 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:18 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:18 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:18 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: vtstq.dll– BHO installation denied at user request
9:17 PM: BHO Shield: found: – BHO installation denied at user request
9:16 PM: Warning: no filename sent to VerifyFileSignature
9:16 PM: BHO Shield: found: – BHO installation denied at user request
9:16 PM: Warning: no filename sent to VerifyFileSignature
9:16 PM: BHO Shield: found: – BHO installation denied at user request
9:16 PM: Warning: no filename sent to VerifyFileSignature
9:16 PM: BHO Shield: found: – BHO installation denied at user request
9:16 PM: Warning: no filename sent to VerifyFileSignature
Keylogger: Off
E-mail Attachment: On
9:15 PM: Informational: ShieldEmail: Start monitoring port 25 for mail activities
9:15 PM: Informational: ShieldEmail: Start monitoring port 110 for mail activities
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: Off
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
File System Shield: On
Execution Shield: On
System Services Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
9:14 PM: Shield States
9:14 PM: License Check Status (0): Success
9:14 PM: Spyware Definitions: 935
9:12 PM: Spy Sweeper 5.5.1.3356 started
9:12 PM: Spy Sweeper 5.5.1.3356 started
9:12 PM: | Start of Session, Sunday, June 24, 2007 |
***************
Operation: File Access
Target:
Source: C:\DOCUME~1\JACK\LOCALS~1\TEMP\IS-HNSLM.TMP\IS-BITTQ.TMP
5:34 PM: Tamper Detection
5:31 PM: Your definitions are up to date.
5:31 PM: Automated check for program update in progress.
Keylogger: Off
5:31 PM: Informational: ShieldEmail: Start monitoring port 25 for mail activities
E-mail Attachment: On
5:31 PM: Informational: ShieldEmail: Start monitoring port 110 for mail activities
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: Off
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
File System Shield: On
Execution Shield: On
System Services Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
5:31 PM: Shield States
5:31 PM: License Check Status (0): Success
5:30 PM: Spyware Definitions: 935
5:28 PM: Spy Sweeper 5.5.1.3354 started
5:28 PM: Spy Sweeper 5.5.1.3354 started
5:28 PM: | Start of Session, Sunday, June 24, 2007 |
***************
5:45 PM: Warning: DoInject :\Device\HarddiskVolume1\WINDOWS\system32\csrss.exe
5:44 PM: Informational: ShieldEmail: Start monitoring port 25 for mail activities
Keylogger: Off
E-mail Attachment: On
5:44 PM: Informational: ShieldEmail: Start monitoring port 110 for mail activities
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: Off
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
File System Shield: On
Execution Shield: On
System Services Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
5:44 PM: Shield States
5:44 PM: License Check Status (0): Success
5:44 PM: Spyware Definitions: 935
5:41 PM: Spy Sweeper 5.5.1.3356 started
5:41 PM: Spy Sweeper 5.5.1.3356 started
5:41 PM: | Start of Session, Sunday, June 24, 2007 |
***************
5:50 PM: Program Version 5.5.1.3356 Using Spyware Definitions 935
5:50 PM: Spy Sweeper 5.5.1.3356 started
5:50 PM: | Start of Session, Sunday, June 24, 2007 |
***************
6:39 PM: Removal process completed. Elapsed time 00:01:34
6:39 PM: Preparing to restart your computer. Please wait…
6:38 PM: Quarantining All Traces: zedo cookie
6:38 PM: Quarantining All Traces: tendollars cookie
6:38 PM: Quarantining All Traces: winantiviruspro cookie
6:38 PM: Quarantining All Traces: jumptothat cookie
6:38 PM: Quarantining All Traces: realtracker cookie
6:38 PM: Quarantining All Traces: tribalfusion cookie
6:38 PM: Quarantining All Traces: adbureau cookie
6:38 PM: Quarantining All Traces: webtrendslive cookie
6:38 PM: Quarantining All Traces: reliablestats cookie
6:38 PM: Quarantining All Traces: statcounter cookie
6:38 PM: Quarantining All Traces: serving-sys cookie
6:38 PM: Quarantining All Traces: search123 cookie
6:38 PM: Quarantining All Traces: realmedia cookie
6:38 PM: Quarantining All Traces: rambler cookie
6:38 PM: Quarantining All Traces: questionmarket cookie
6:38 PM: Quarantining All Traces: pro-market cookie
6:38 PM: Quarantining All Traces: pch cookie
6:38 PM: Quarantining All Traces: overture cookie
6:38 PM: Quarantining All Traces: mygeek cookie
6:38 PM: Quarantining All Traces: mediaplex cookie
6:38 PM: Quarantining All Traces: linksynergy cookie
6:38 PM: Quarantining All Traces: ic-live cookie
6:38 PM: Quarantining All Traces: screensavers.com cookie
6:38 PM: Quarantining All Traces: epilot cookie
6:38 PM: Quarantining All Traces: enhance cookie
6:38 PM: Quarantining All Traces: ru4 cookie
6:38 PM: Quarantining All Traces: did-it cookie
6:38 PM: Quarantining All Traces: coolsavings cookie
6:38 PM: Quarantining All Traces: clickbank cookie
6:38 PM: Quarantining All Traces: casalemedia cookie
6:38 PM: Quarantining All Traces: trafficmp cookie
6:38 PM: Quarantining All Traces: burstnet cookie
6:38 PM: Quarantining All Traces: bs.serving-sys cookie
6:38 PM: Quarantining All Traces: bravenet cookie
6:38 PM: Quarantining All Traces: atwola cookie
6:38 PM: Quarantining All Traces: atlas dmt cookie
6:38 PM: Quarantining All Traces: tacoda cookie
6:38 PM: Quarantining All Traces: primaryads cookie
6:38 PM: Quarantining All Traces: advertising cookie
6:38 PM: Quarantining All Traces: cpxinteractive cookie
6:38 PM: Quarantining All Traces: adserver cookie
6:38 PM: Quarantining All Traces: searchingbooth cookie
6:38 PM: Quarantining All Traces: pointroll cookie
6:38 PM: Quarantining All Traces: addynamix cookie
6:38 PM: Quarantining All Traces: adrevolver cookie
6:38 PM: Quarantining All Traces: specificclick.com cookie
6:38 PM: Quarantining All Traces: adlegend cookie
6:38 PM: Quarantining All Traces: yieldmanager cookie
6:38 PM: Quarantining All Traces: websponsors cookie
6:38 PM: Quarantining All Traces: 2o7.net cookie
6:38 PM: Quarantining All Traces: maxifiles
6:38 PM: Quarantining All Traces: coolwebsearch (cws)
6:38 PM: Quarantining All Traces: purityscan
6:38 PM: Quarantining All Traces: trojan-phisher-us15info
6:38 PM: Quarantining All Traces: zenosearchassistant
6:38 PM: Quarantining All Traces: seekmo search assistant
6:38 PM: Quarantining All Traces: weirdontheweb
6:37 PM: Quarantining All Traces: mediapipe
6:37 PM: Quarantining All Traces: clearsearch
6:37 PM: Quarantining All Traces: whenu savenow
6:37 PM: Quarantining All Traces: pinfo dialer
6:37 PM: Quarantining All Traces: keenvalue/perfectnav
6:37 PM: Quarantining All Traces: gain - common components
6:37 PM: Quarantining All Traces: clipgenie
6:37 PM: Quarantining All Traces: bookedspace
6:37 PM: Quarantining All Traces: blazefind
6:37 PM: Quarantining All Traces: apropos
6:37 PM: Quarantining All Traces: altnet
6:37 PM: vtutr.dll is in use. It will be removed on reboot.
6:37 PM: virtumonde is in use. It will be removed on reboot.
6:37 PM: Warning: Launched explorer.exe
6:37 PM: Quarantining All Traces: virtumonde
6:37 PM: Quarantining All Traces: cydoor
6:37 PM: Quarantining All Traces: 180search assistant/zango
6:37 PM: Quarantining All Traces: internetoptimizer
6:37 PM: Removal process initiated
6:37 PM: Traces Found: 157
6:37 PM: Custom Sweep has completed. Elapsed time 00:46:16
6:37 PM: File Sweep Complete, Elapsed Time: 00:44:56
6:29 PM: zxdnt3d.cfg (ID = 91140)
5:58 PM: think-adz.lnk (ID = 372576)
5:52 PM: Starting File Sweep
5:52 PM: Warning: SweepDirectories: Cannot find directory "a:". This directory was not added to the list of paths to be scanned.
5:52 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
5:52 PM: jack@zedo[2].txt (ID = 3762)
5:52 PM: jack@zedo[1].txt (ID = 3762)
5:52 PM: Found Spy Cookie: zedo cookie
5:52 PM: [removed][1].txt (ID = 6367)
5:52 PM: Found Spy Cookie: tendollars cookie
5:52 PM: [removed][1].txt (ID = 3690)
5:52 PM: Found Spy Cookie: winantiviruspro cookie
5:52 PM: [removed][1].txt (ID = 3298)
5:52 PM: [removed][4].txt (ID = 3124)
5:52 PM: [removed][2].txt (ID = 3124)
5:52 PM: [removed][1].txt (ID = 3124)
5:52 PM: [removed][2].txt (ID = 2894)
5:52 PM: [removed][1].txt (ID = 2894)
5:52 PM: Found Spy Cookie: jumptothat cookie
5:52 PM: [removed][2].txt (ID = 2622)
5:52 PM: [removed][1].txt (ID = 2622)
5:52 PM: [removed][3].txt (ID = 2337)
5:52 PM: [removed][2].txt (ID = 2337)
5:52 PM: [removed][1].txt (ID = 3242)
5:52 PM: Found Spy Cookie: realtracker cookie
5:52 PM: jack@tribalfusion[2].txt (ID = 3589)
5:52 PM: jack@tribalfusion[1].txt (ID = 3589)
5:52 PM: Found Spy Cookie: tribalfusion cookie
5:52 PM: [removed][3].txt (ID = 2060)
5:52 PM: [removed][2].txt (ID = 2060)
5:52 PM: [removed][1].txt (ID = 2060)
5:52 PM: Found Spy Cookie: adbureau cookie
5:52 PM: jack@trafficmp[4].txt (ID = 3581)
5:52 PM: jack@trafficmp[2].txt (ID = 3581)
5:52 PM: jack@trafficmp[1].txt (ID = 3581)
5:52 PM: jack@tacoda[2].txt (ID = 6444)
5:52 PM: jack@tacoda[1].txt (ID = 6444)
5:52 PM: [removed][1].txt (ID = 3667)
5:52 PM: Found Spy Cookie: webtrendslive cookie
5:52 PM: [removed][2].txt (ID = 3254)
5:52 PM: [removed][1].txt (ID = 3254)
5:52 PM: Found Spy Cookie: reliablestats cookie
5:52 PM: jack@statcounter[2].txt (ID = 3447)
5:52 PM: jack@statcounter[1].txt (ID = 3447)
5:52 PM: Found Spy Cookie: statcounter cookie
5:52 PM: jack@specificclick[3].txt (ID = 3399)
5:52 PM: jack@specificclick[2].txt (ID = 3399)
5:52 PM: jack@specificclick[1].txt (ID = 3399)
5:52 PM: jack@serving-sys[2].txt (ID = 3343)
5:52 PM: jack@serving-sys[1].txt (ID = 3343)
5:52 PM: Found Spy Cookie: serving-sys cookie
5:52 PM: jack@search123[2].txt (ID = 3305)
5:52 PM: jack@search123[1].txt (ID = 3305)
5:52 PM: Found Spy Cookie: search123 cookie
5:52 PM: jack@screensavers[2].txt (ID = 3297)
5:52 PM: [removed][2].txt (ID = 3124)
5:52 PM: [removed][1].txt (ID = 3124)
5:52 PM: jack@realmedia[2].txt (ID = 3235)
5:52 PM: Found Spy Cookie: realmedia cookie
5:52 PM: jack@rambler[3].txt (ID = 3225)
5:52 PM: jack@rambler[2].txt (ID = 3225)
5:52 PM: Found Spy Cookie: rambler cookie
5:52 PM: jack@questionmarket[4].txt (ID = 3217)
5:52 PM: jack@questionmarket[3].txt (ID = 3217)
5:52 PM: jack@questionmarket[2].txt (ID = 3217)
5:52 PM: Found Spy Cookie: questionmarket cookie
5:52 PM: jack@pro-market[2].txt (ID = 3197)
5:52 PM: Found Spy Cookie: pro-market cookie
5:52 PM: [removed][2].txt (ID = 3106)
5:52 PM: [removed][1].txt (ID = 3106)
5:52 PM: jack@pch[2].txt (ID = 3123)
5:52 PM: jack@pch[1].txt (ID = 3123)
5:52 PM: Found Spy Cookie: pch cookie
5:52 PM: jack@pch.122.2o7[2].txt (ID = 1958)
5:52 PM: jack@pch.122.2o7[1].txt (ID = 1958)
5:52 PM: jack@overture[1].txt (ID = 3105)
5:52 PM: Found Spy Cookie: overture cookie
5:52 PM: jack@newmotioninc.112.2o7[1].txt (ID = 1958)
5:52 PM: jack@mygeek[4].txt (ID = 3041)
5:52 PM: jack@mygeek[3].txt (ID = 3041)
5:52 PM: jack@mygeek[2].txt (ID = 3041)
5:52 PM: jack@mygeek[1].txt (ID = 3041)
5:52 PM: Found Spy Cookie: mygeek cookie
5:52 PM: jack@mediaplex[2].txt (ID = 6442)
5:52 PM: jack@mediaplex[1].txt (ID = 6442)
5:52 PM: Found Spy Cookie: mediaplex cookie
5:52 PM: jack@maxim.122.2o7[1].txt (ID = 1958)
5:52 PM: jack@lsfnetwork.122.2o7[3].txt (ID = 1958)
5:52 PM: jack@lsfnetwork.122.2o7[2].txt (ID = 1958)
5:52 PM: jack@lsfnetwork.122.2o7[1].txt (ID = 1958)
5:52 PM: jack@linksynergy[1].txt (ID = 2926)
5:52 PM: Found Spy Cookie: linksynergy cookie
5:52 PM: jack@ic-live[1].txt (ID = 2821)
5:52 PM: Found Spy Cookie: ic-live cookie
5:52 PM: [removed][1].txt (ID = 3298)
5:52 PM: Found Spy Cookie: screensavers.com cookie
5:52 PM: jack@heavycom.122.2o7[1].txt (ID = 1958)
5:52 PM: jack@epilot[2].txt (ID = 2621)
5:52 PM: jack@epilot[1].txt (ID = 2621)
5:52 PM: Found Spy Cookie: epilot cookie
5:52 PM: jack@entrepreneur.122.2o7[2].txt (ID = 1958)
5:52 PM: jack@entrepreneur.122.2o7[1].txt (ID = 1958)
5:52 PM: jack@enhance[2].txt (ID = 2613)
5:52 PM: Found Spy Cookie: enhance cookie
5:52 PM: jack@electronicarts.112.2o7[2].txt (ID = 1958)
5:52 PM: jack@electronicarts.112.2o7[1].txt (ID = 1958)
5:52 PM: jack@edge.ru4[3].txt (ID = 3269)
5:52 PM: jack@edge.ru4[1].txt (ID = 3269)
5:52 PM: Found Spy Cookie: ru4 cookie
5:52 PM: jack@did-it[1].txt (ID = 2523)
5:52 PM: Found Spy Cookie: did-it cookie
5:52 PM: jack@coolsavings[1].txt (ID = 2465)
5:52 PM: Found Spy Cookie: coolsavings cookie
5:52 PM: jack@clickbank[1].txt (ID = 2398)
5:52 PM: Found Spy Cookie: clickbank cookie
5:52 PM: jack@casalemedia[3].txt (ID = 2354)
5:52 PM: jack@casalemedia[2].txt (ID = 2354)
5:52 PM: jack@casalemedia[1].txt (ID = 2354)
5:52 PM: Found Spy Cookie: casalemedia cookie
5:52 PM: [removed][3].txt (ID = 3582)
5:52 PM: [removed][2].txt (ID = 3582)
5:52 PM: Found Spy Cookie: trafficmp cookie
5:52 PM: jack@burstnet[2].txt (ID = 2336)
5:52 PM: Found Spy Cookie: burstnet cookie
5:52 PM: [removed]-sys[1].txt (ID = 2330)
5:52 PM: Found Spy Cookie: bs.serving-sys cookie
5:52 PM: jack@bravenet[2].txt (ID = 2322)
5:52 PM: Found Spy Cookie: bravenet cookie
5:52 PM: jack@blockbuster.112.2o7[1].txt (ID = 1958)
5:52 PM: jack@atwola[2].txt (ID = 2255)
5:52 PM: jack@atwola[1].txt (ID = 2255)
5:52 PM: Found Spy Cookie: atwola cookie
5:52 PM: jack@atdmt[4].txt (ID = 2253)
5:52 PM: jack@atdmt[3].txt (ID = 2253)
5:52 PM: jack@atdmt[2].txt (ID = 2253)
5:52 PM: Found Spy Cookie: atlas dmt cookie
5:52 PM: [removed][3].txt (ID = 6445)
5:52 PM: [removed][1].txt (ID = 6445)
5:52 PM: [removed][3].txt (ID = 6445)
5:52 PM: [removed][2].txt (ID = 6445)
5:52 PM: [removed][1].txt (ID = 6445)
5:52 PM: Found Spy Cookie: tacoda cookie
5:52 PM: [removed][1].txt (ID = 3190)
5:52 PM: Found Spy Cookie: primaryads cookie
5:52 PM: jack@advertising[3].txt (ID = 2175)
5:52 PM: jack@advertising[2].txt (ID = 2175)
5:52 PM: jack@advertising[1].txt (ID = 2175)
5:52 PM: Found Spy Cookie: advertising cookie
5:52 PM: [removed][3].txt (ID = 8939)
5:52 PM: [removed][2].txt (ID = 8939)
5:52 PM: Found Spy Cookie: cpxinteractive cookie
5:52 PM: jack@adserver[1].txt (ID = 2141)
5:52 PM: Found Spy Cookie: adserver cookie
5:52 PM: [removed][2].txt (ID = 3322)
5:52 PM: [removed][1].txt (ID = 3322)
5:52 PM: Found Spy Cookie: searchingbooth cookie
5:52 PM: [removed][3].txt (ID = 3148)
5:52 PM: [removed][2].txt (ID = 3148)
5:52 PM: Found Spy Cookie: pointroll cookie
5:52 PM: [removed][2].txt (ID = 2062)
5:52 PM: Found Spy Cookie: addynamix cookie
5:52 PM: jack@adrevolver[2].txt (ID = 2088)
5:52 PM: Found Spy Cookie: adrevolver cookie
5:52 PM: [removed][3].txt (ID = 3400)
5:52 PM: [removed][2].txt (ID = 3400)
5:52 PM: Found Spy Cookie: specificclick.com cookie
5:52 PM: jack@adlegend[2].txt (ID = 2074)
5:52 PM: Found Spy Cookie: adlegend cookie
5:52 PM: [removed][4].txt (ID = 3751)
5:52 PM: [removed][3].txt (ID = 3751)
5:52 PM: [removed][2].txt (ID = 3751)
5:52 PM: [removed][1].txt (ID = 3751)
5:52 PM: Found Spy Cookie: yieldmanager cookie
5:52 PM: [removed][1].txt (ID = 3665)
5:52 PM: Found Spy Cookie: websponsors cookie
5:52 PM: jack@2o7[3].txt (ID = 1957)
5:52 PM: jack@2o7[2].txt (ID = 1957)
5:52 PM: jack@2o7[1].txt (ID = 1957)
5:52 PM: Found Spy Cookie: 2o7.net cookie
5:52 PM: Starting Cookie Sweep
5:52 PM: Registry Sweep Complete, Elapsed Time:00:01:00
5:52 PM: HKU\S-1-5-21-826843164-2093118864-934546170-1004\software\microsoft\windows\currentversion\run\ || ipwins (ID = 2089537)
5:52 PM: Found Adware: maxifiles
5:52 PM: HKU\S-1-5-21-826843164-2093118864-934546170-1004\software\microsoft\windows\currentversion\run\ || rundll32 (ID = 112406)
5:52 PM: Found Adware: coolwebsearch (cws)
5:52 PM: HKLM\software\microsoft\windows\currentversion\run\ || apachinc (ID = 2243679)
5:52 PM: HKLM\software\microsoft\aoprndtws\ (ID = 2128500)
5:52 PM: HKLM\software\microsoft\windows\currentversion\uninstall\outerinfo\ (ID = 2063030)
5:52 PM: Found Adware: purityscan
5:52 PM: HKLM\system\controlset001\enum\root\legacy_msasvc\ (ID = 1847035)
5:52 PM: Found Trojan Horse: trojan-phisher-us15info
5:52 PM: HKLM\software\microsoft\windows\currentversion\uninstall\think-adz search assistant\ (ID = 1697587)
5:52 PM: HKLM\software\microsoft\windows\currentversion\uninstall\enhanced ads by think-adz\ (ID = 1697586)
5:52 PM: HKLM\software\microsoft\windows\currentversion\run\ || exploreupdsched (ID = 1581139)
5:52 PM: Found Adware: zenosearchassistant
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || seekmo (ID = 1042293)
5:51 PM: Found Adware: seekmo search assistant
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || altpayments (ID = 867147)
5:51 PM: Found Adware: weirdontheweb
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || mediapipetrayicon (ID = 867146)
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || mediapipe p2p loader (ID = 867145)
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || mediapipe (ID = 867144)
5:51 PM: Found Adware: mediapipe
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || prositefinder (ID = 776277)
5:51 PM: Found Adware: clearsearch
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || zanu (ID = 147911)
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || zango (ID = 147910)
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || vvsn (ID = 140442)
5:51 PM: Found Adware: whenu savenow
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || lisa (ID = 136750)
5:51 PM: Found Adware: pinfo dialer
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || updmgr (ID = 129511)
5:51 PM: Found Adware: keenvalue/perfectnav
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || internet optimizer (ID = 128916)
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || trickler (ID = 126781)
5:51 PM: Found Adware: gain - common components
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || webinstall2 (ID = 105923)
5:51 PM: Found Adware: clipgenie
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || bxxs5 (ID = 104881)
5:51 PM: Found Adware: bookedspace
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || rundll (ID = 104535)
5:51 PM: Found Adware: blazefind
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || autoupdater (ID = 103803)
5:51 PM: Found Adware: apropos
5:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || altnetpointsmanager (ID = 103518)
5:51 PM: Found Adware: altnet
5:51 PM: Memory Sweep Complete, Elapsed Time: 00:00:00
5:51 PM: Starting Registry Sweep
5:51 PM: Detected running threat: vtutr.dll (ID = 676)
5:51 PM: Found Adware: virtumonde
5:51 PM: Starting Memory Sweep
5:51 PM: HKU\S-1-5-21-826843164-2093118864-934546170-1004\software\microsoft\windows\currentversion\run\ || cydoor (ID = 1614054)
5:51 PM: Found Adware: cydoor
5:50 PM: HKLM\software\microsoft\windows\currentversion\run\ || zango (ID = 1533958)
5:50 PM: Found Adware: 180search assistant/zango
5:50 PM: Warning: TFileCountEnum.ProcessPartition: TVolume.Read: read past end of volume size: 0 reading cluster: 0
5:50 PM: HKLM\software\microsoft\windows\currentversion\run\ || internet optimizer (ID = 1193579)
5:50 PM: Found Adware: internetoptimizer
5:50 PM: Sweep initiated using definitions version 935
5:50 PM: Spy Sweeper 5.5.1.3356 started
5:50 PM: | Start of Session, Sunday, June 24, 2007 |
Logfile of HijackThis v1.99.1
Scan saved at 9:39:50 PM, on 6/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\locator.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Blubster\Blubster.exe
C:\windows\system32\kncffxl.exe
C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.iwon.com/iwon-homepage/home.jhtml
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [{E6-69-9C-C1-ZN}] c:\windows\system32\dwdsregt.exe CHD003
O4 - HKLM\..\Run: [{484E69C1-0963-1033-0803-040527030001}] "C:\Program Files\Common Files\{484E69C1-0963-1033-0803-040527030001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [{484E69C1-0962-1033-0803-040527030001}] "C:\Program Files\Common Files\{484E69C1-0962-1033-0803-040527030001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [yarlwpg] c:\windows\system32\xdwbyih.exe r
O4 - HKLM\..\Run: [wmplayer] C:\Program Files\Windows Media Player\wmplayer.exe
O4 - HKLM\..\Run: [wfxxvyt] c:\windows\system32\hfhihsf.exe r
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [vqtqakj] c:\windows\system32\ernjwo.exe r
O4 - HKLM\..\Run: [tLE] C:\documents and settings\jack\local settings\temp\tLE.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [tgragr] c:\windows\system32\yepnfes.exe r
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [RunOnce2Upd] "C:\WINDOWS\system32\KB_963493.exe"
O4 - HKLM\..\Run: [rrsrqp] c:\windows\system32\aiiebmx.exe r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ProfileWatcher] C:\Program Files\ProfileWatcher\profilewatcher.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [palxtns] c:\windows\system32\gvgpgj.exe r
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater1.03.0000.1005\en-us\msnappau.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [klsfmtg] c:\windows\system32\abyjps.exe r
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [kaxogr] c:\windows\system32\sibndlx.exe r
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [j6271132] rundll32 C:\WINDOWS\system32\j6271132.dll sook
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [isigaps] c:\windows\system32\jsbpbh.exe r
O4 - HKLM\..\Run: [iRiver Updater] C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe
O4 - HKLM\..\Run: [infamous.exe] C:\Program Files\Windows Media Player\wmplayer.exe
O4 - HKLM\..\Run: [ihkbynsd.exe] C:\Documents and Settings\All Users\Application Data\ihkbynsd.exe
O4 - HKLM\..\Run: [ietjumj] c:\windows\system32\zrrrug.exe r
O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [hegnkl] c:\windows\system32\qwzhfud.exe r
O4 - HKLM\..\Run: [gsyjth] c:\windows\system32\egdijvz.exe r
O4 - HKLM\..\Run: [gmGW] C:\documents and settings\jack\local settings\temp\gmGW.exe
O4 - HKLM\..\Run: [gatigz] c:\windows\system32\gsorklq.exe r
O4 - HKLM\..\Run: [cvcvetx] c:\windows\system32\ddvseca.exe r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [cofsumtbk] c:\windows\system32\cofsumtbk.exe cofsumtbk
O4 - HKLM\..\Run: [cgbdwwc] c:\windows\system32\kxjdlkp.exe r
O4 - HKLM\..\Run: [Blubster] C:\Program Files\Blubster\Blubster.exe SILENT
O4 - HKLM\..\Run: [bhxydp] c:\windows\system32\wexzkev.exe r
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AuditMode] C:\sysprep\factory.exe -logon
O4 - HKLM\..\Run: [ASM] "C:\Program Files\AOL\Active Security Monitor\ASMonitor.exe"
O4 - HKLM\..\Run: [alsermj] c:\windows\system32\sdtnde.exe r
O4 - HKLM\..\Run: [alqeqvc] c:\windows\system32\rjnugel.exe r
O4 - HKLM\..\Run: [aioyyms] c:\windows\system32\tonbfjh.exe r
O4 - HKLM\..\Run: [aaT] C:\documents and settings\jack\local settings\temp\aaT.exe
O4 - HKLM\..\Run: [iolo Personal Firewall®] "C:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [userinit] C:\WINDOWS\system32\ntos.exe
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Oorp] "C:\PROGRA~1\COMMON~1\STEM~1\notepad.exe" -vt yazb
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Loia] C:\Documents and Settings\jack\Application Data\tcaa.exe
O4 - HKCU\..\Run: [IDMan] C:\PROGRA~1\INTERN~2\IDMan.exe /onboot
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [csrss] C:\WINDOWS\csrss.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\jack\Local Settings\Temp\TICHD003.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Kaspersky Anti-Hacker.lnk = C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~3\tools\iesdpb.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O16 - DPF: PCPitstop-Tracks-Checker - http://www.pcpitstop.com/privacy/PCPTracks.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/12119/CTSUEng.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1180221127171
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) - http://63.241.168.238/ae/ecwplugins/ncs1.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {BA61B6AE-9EDE-42EE-92C6-C938DEBCAFF3} - http://www.kerclink.com/download/setup.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.13.16/ttinst.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://ds1.downloadtech.net/cn1060/pcpowerscan.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/12119/CTPID.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinner.com/games/v51/h2hpool/h2hpool.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{57AA5BF8-81C3-4E4A-A7DD-72987CF3B47F}: NameServer = 208.67.220.220 208.67.222.222
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AFSEGTGF Windows Service - Unknown owner - C:\WINDOWS\system32\dsfms.exe (file missing)
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo DMV Service (ioloDMV) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe