Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijackthis Log


  • This topic is locked This topic is locked
9 replies to this topic

#1 mojavemystic

mojavemystic

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Ohio
  • Local time:08:18 AM

Posted 23 January 2006 - 01:36 AM

Logfile of HijackThis v1.99.1
Scan saved at 10:29:58 PM, on 1/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\??mbols\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\mmln\oana.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adb.../search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adb...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {47EA0B6D-BA83-FD07-8288-C36932D8DDE8} - C:\WINDOWS\system32\vfdtv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [Uxkgb] C:\WINDOWS\system32\??mbols\svchost.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Touh] "C:\Program Files\mmln\oana.exe" -vt ndrv
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn/insta...cdetection3.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/sj/en/check/qdiagh.cab?326
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - Unknown owner - c:\program files\mcafee.com\agent\mcdetect.exe (file missing)
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - Unknown owner - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe (file missing)
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
Spelunking Rocks!

BC AdBot (Login to Remove)

 


m

#2 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:07:18 AM

Posted 23 January 2006 - 12:33 PM

Go to the link below and download the trial version of SpySweeper:

SpySweeper http://www.webroot.com/consumer/products/s...&rc=4129&ac=tsg

* Click the Free Trial link under "SpySweeper" to download the program.
* Install it. Once the program is installed, it will open.
* It will prompt you to update to the latest definitions, click Yes.
* Once the definitions are installed, click Options on the left side.
* Click the Sweep Options tab.
* Under What to Sweep please put a check next to the following:
o Sweep Memory
o Sweep Registry
o Sweep Cookies
o Sweep All User Accounts
o Enable Direct Disk Sweeping
o Sweep Contents of Compressed Files
o Sweep for Rootkits

o Please UNCHECK Do not Sweep System Restore Folder.

* Click Sweep Now on the left side.
* Click the Start button.
* When it's done scanning, click the Next button.
* Make sure everything has a check next to it, then click the Next button.
* It will remove all of the items found.
* Click Session Log in the upper right corner, copy everything in that window.
* Click the Summary tab and click Finish.
* Paste the contents of the session log you copied into your next reply.
Also post a new Hijack This log.
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#3 mojavemystic

mojavemystic
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Ohio
  • Local time:08:18 AM

Posted 23 January 2006 - 01:55 PM

9:48 AM: | Start of Session, Monday, January 23, 2006 |
9:48 AM: Spy Sweeper started
9:48 AM: Sweep initiated using definitions version 605
9:48 AM: Starting Memory Sweep
9:48 AM: Found Adware: purityscan
9:48 AM: Detected running threat: C:\WINDOWS\system32\vfdtv.dll (ID = 230)
9:54 AM: Detected running threat: C:\Program Files\mmln\oana.exe (ID = 230)
9:55 AM: Memory Sweep Complete, Elapsed Time: 00:06:45
9:55 AM: Starting Registry Sweep
9:56 AM: Found Adware: ist powerscan
9:56 AM: HKU\WRSS_Profile_S-1-5-21-839522115-789336058-1957994488-1005\software\powerscan\ (ID = 136823)
9:56 AM: Found Adware: ist sidefind
9:56 AM: HKU\WRSS_Profile_S-1-5-21-839522115-789336058-1957994488-1005\software\microsoft\internet explorer\extensions\cmdmapping\ || {10e42047-deb9-4535-a118-b3f6ec39b807} (ID = 141778)
9:56 AM: Found Adware: internetoptimizer
9:56 AM: HKU\WRSS_Profile_S-1-5-21-839522115-789336058-1957994488-1005\software\microsoft\windows\currentversion\policies\ameopt\ (ID = 654042)
9:56 AM: HKU\WRSS_Profile_S-1-5-21-839522115-789336058-1957994488-1004\software\avenue media\ (ID = 128887)
9:56 AM: Found Adware: ist software
9:56 AM: HKU\WRSS_Profile_S-1-5-21-839522115-789336058-1957994488-1004\software\ist\ (1 subtraces) (ID = 129108)
9:56 AM: Found Adware: 180search assistant/zango
9:56 AM: HKU\WRSS_Profile_S-1-5-21-839522115-789336058-1957994488-1004\software\sais\ (11 subtraces) (ID = 135790)
9:56 AM: HKU\WRSS_Profile_S-1-5-21-839522115-789336058-1957994488-1004\software\microsoft\internet explorer\explorer bars\{8cba1b49-8144-4721-a7b1-64c578c9eed7}\ (1 subtraces) (ID = 141777)
9:56 AM: HKU\WRSS_Profile_S-1-5-21-839522115-789336058-1957994488-1004\software\microsoft\internet explorer\extensions\cmdmapping\ || {10e42047-deb9-4535-a118-b3f6ec39b807} (ID = 141778)
9:56 AM: Registry Sweep Complete, Elapsed Time:00:00:49
9:56 AM: Starting Cookie Sweep
9:56 AM: Found Spy Cookie: atwola cookie
9:56 AM: joy@ar.atwola[1].txt (ID = 2256)
9:56 AM: Found Spy Cookie: hbmediapro cookie
9:56 AM: joy@adopt.hbmediapro[1].txt (ID = 2768)
9:56 AM: Found Spy Cookie: cc214142 cookie
9:56 AM: joy@ads.cc214142[1].txt (ID = 2367)
9:56 AM: Found Spy Cookie: 888 cookie
9:56 AM: joy@888[2].txt (ID = 2019)
9:56 AM: Found Spy Cookie: yieldmanager cookie
9:56 AM: joy@ad.yieldmanager[2].txt (ID = 3751)
9:56 AM: Found Spy Cookie: belnk cookie
9:56 AM: jim johnson@belnk[1].txt (ID = 2292)
9:56 AM: Found Spy Cookie: adknowledge cookie
9:56 AM: jim johnson@adknowledge[2].txt (ID = 2072)
9:56 AM: jim johnson@ad.yieldmanager[3].txt (ID = 3751)
9:56 AM: jim johnson@atwola[1].txt (ID = 2255)
9:56 AM: jim johnson@ad.yieldmanager[2].txt (ID = 3751)
9:56 AM: Found Spy Cookie: go2net.com cookie
9:56 AM: jim johnson@go2net[1].txt (ID = 2730)
9:56 AM: Found Spy Cookie: aptimus cookie
9:56 AM: jim johnson@network.aptimus[2].txt (ID = 2235)
9:56 AM: Found Spy Cookie: ic-live cookie
9:56 AM: jim johnson@ic-live[1].txt (ID = 2821)
9:56 AM: Found Spy Cookie: exitexchange cookie
9:56 AM: jim johnson@exitexchange[1].txt (ID = 2633)
9:56 AM: Found Spy Cookie: rednova cookie
9:56 AM: jim johnson@rednova[1].txt (ID = 3245)
9:56 AM: Found Spy Cookie: banner cookie
9:56 AM: jim johnson@banner[1].txt (ID = 2276)
9:56 AM: Found Spy Cookie: infospace cookie
9:56 AM: hp authorized custom@infospace[1].txt (ID = 2865)
9:56 AM: hp authorized custom@atwola[1].txt (ID = 2255)
9:56 AM: Found Spy Cookie: nextag cookie
9:56 AM: hp authorized custom@nextag[2].txt (ID = 5014)
9:56 AM: Found Spy Cookie: go.com cookie
9:56 AM: hp authorized custom@go[2].txt (ID = 2728)
9:56 AM: hp authorized custom@ic-live[1].txt (ID = 2821)
9:56 AM: hp authorized custom@ath.belnk[2].txt (ID = 2293)
9:56 AM: hp authorized custom@atwola[3].txt (ID = 2255)
9:56 AM: hp authorized custom@dist.belnk[2].txt (ID = 2293)
9:56 AM: Found Spy Cookie: webtrendslive cookie
9:56 AM: hp authorized custom@S005-01-9-28-233860-106434[1].txt (ID = 3679)
9:56 AM: hp authorized custom@ad.yieldmanager[1].txt (ID = 3751)
9:56 AM: Found Spy Cookie: mygeek cookie
9:56 AM: hp authorized custom@mygeek[1].txt (ID = 3041)
9:56 AM: hp authorized custom@belnk[1].txt (ID = 2292)
9:56 AM: hp authorized custom@exitexchange[1].txt (ID = 2633)
9:56 AM: Found Spy Cookie: winantiviruspro cookie
9:56 AM: hp authorized custom@www.winantiviruspro[2].txt (ID = 3690)
9:56 AM: Found Spy Cookie: reliablestats cookie
9:56 AM: hp authorized custom@stats1.reliablestats[2].txt (ID = 3254)
9:56 AM: hp authorized custom@banner[1].txt (ID = 2276)
9:56 AM: Found Spy Cookie: reunion cookie
9:56 AM: hp authorized custom@reunion[2].txt (ID = 3255)
9:56 AM: Found Spy Cookie: servlet cookie
9:56 AM: hp authorized custom@servlet[1].txt (ID = 3345)
9:56 AM: Found Spy Cookie: ask cookie
9:56 AM: hp authorized custom@ask[2].txt (ID = 2245)
9:56 AM: Found Spy Cookie: dealtime cookie
9:56 AM: hp authorized custom@stat.dealtime[2].txt (ID = 2506)
9:56 AM: Found Spy Cookie: sb01 cookie
9:56 AM: hp authorized custom@jp1.sb01[2].txt (ID = 3288)
9:56 AM: Found Spy Cookie: websponsors cookie
9:56 AM: hp authorized custom@a.websponsors[1].txt (ID = 3665)
9:56 AM: Found Spy Cookie: did-it cookie
9:56 AM: hp authorized custom@did-it[1].txt (ID = 2523)
9:56 AM: Found Spy Cookie: specificclick.com cookie
9:56 AM: hp authorized custom@adopt.specificclick[1].txt (ID = 3400)
9:56 AM: Found Spy Cookie: adjuggler cookie
9:56 AM: hp authorized custom@rotator.adjuggler[1].txt (ID = 2071)
9:56 AM: hp authorized custom@dealtime[2].txt (ID = 2505)
9:56 AM: hp authorized custom@stat.dealtime[1].txt (ID = 2506)
9:56 AM: Found Spy Cookie: burstnet cookie
9:56 AM: hp authorized custom@burstnet[2].txt (ID = 2336)
9:56 AM: Found Spy Cookie: 2o7.net cookie
9:56 AM: hp authorized custom@sento.122.2o7[1].txt (ID = 1958)
9:56 AM: Found Spy Cookie: videodome cookie
9:56 AM: hp authorized custom@videodome[1].txt (ID = 3638)
9:56 AM: hp authorized custom@2o7[3].txt (ID = 1957)
9:56 AM: Cookie Sweep Complete, Elapsed Time: 00:00:04
9:56 AM: Starting File Sweep
9:56 AM: Warning: Failed to open file "c:\hiberfil.sys". Access is denied
9:56 AM: Warning: Failed to open file "c:\pagefile.sys". Access is denied
10:01 AM: Warning: Failed to open file "c:\windows\system32\config\system.log". The process cannot access the file because it is being used by another process
10:01 AM: Warning: Failed to open file "c:\windows\system32\config\software.log". The process cannot access the file because it is being used by another process
10:01 AM: Warning: Failed to open file "c:\windows\system32\config\default.log". The process cannot access the file because it is being used by another process
10:01 AM: Warning: Failed to open file "c:\windows\system32\config\sam.log". The process cannot access the file because it is being used by another process
10:01 AM: Warning: Failed to open file "c:\windows\system32\config\security.log". The process cannot access the file because it is being used by another process
10:01 AM: Warning: Failed to open file "c:\windows\system32\config\default". The process cannot access the file because it is being used by another process
10:01 AM: Warning: Failed to open file "c:\windows\system32\config\security". The process cannot access the file because it is being used by another process
10:01 AM: Warning: Failed to open file "c:\windows\system32\config\software". The process cannot access the file because it is being used by another process
10:01 AM: Warning: Failed to open file "c:\windows\system32\config\system". The process cannot access the file because it is being used by another process
10:01 AM: Warning: Failed to open file "c:\windows\system32\config\sam". The process cannot access the file because it is being used by another process
10:06 AM: Warning: Failed to open file "c:\windows\temp\zlt0043d.tmp". The process cannot access the file because it is being used by another process
10:07 AM: Warning: Failed to open file "c:\windows\softwaredistribution\eventcache\{80a691ca-24dd-4d3a-b09a-564dbe9cad70}.bin". The process cannot access the file because it is being used by another process
10:20 AM: Found Adware: lopdotcom
10:20 AM: comver.dll (ID = 111424)
10:28 AM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsac9d2b60-6561-4220-9370-2ae45aa12b3b.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb536c275-4cd8-4d8b-9143-4ee39e76fdb2.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4a362386-715d-47c1-b211-90cfa60d7a5a.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs77a61c31-9711-4c8a-b71b-56cad9a039c5.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1b42685d-6be3-4401-ad1d-4bb3bc6453ab.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6c651798-f8e0-4bee-910f-a524d916d20a.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8000f36b-0110-42f7-a258-5002decada11.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs14d12d30-01ea-4690-9718-07af6d1aeb93.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0e7c39c7-79f3-49c3-a986-60e2bf2a8b0b.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5db134bb-e592-4047-868f-d8987f510098.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsca5b759e-3fe7-4765-9706-fe83902cc2d4.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs38fa569b-72d3-4458-92c7-77a649259965.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0fe8c5b0-1afe-414c-8239-9636e3301535.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs35c2868a-b96c-428b-89bd-0883d6dabfdc.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6b18d02c-126d-42bc-be47-96072fa984f3.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb732b92e-1e59-40a4-b73e-f456832e0307.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs25c87946-0d87-425e-8842-5598cfcfe4ac.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs88cc4b25-8b21-4b3f-bed5-c6e65cc0e8b2.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3be8c7af-8e12-4299-9190-c8e14ee1fa6e.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8175cfef-2755-4e81-bcee-05dc7fa58c7d.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs9459c790-cd3c-4d55-a654-3e62d4a63e3a.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs095f5c0e-72a4-44ce-8766-05ddcc134d73.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6047b4cd-2e4f-4683-8626-3aae173fe9fd.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa275e644-14dd-481f-bd52-95c072d5144a.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6aeeff60-bc74-4d17-aa7b-e5ecfd4a48cc.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs25b070c8-8fd7-4873-9ee4-e65558cf520d.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs21f9fba9-846d-4bb3-9db7-0f5f8d4733f2.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6ad5c8fc-0366-4f64-8a68-0979b5cfa7fc.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs71976eff-c794-4aaf-9c32-0b17c45cf98f.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse7529f56-0a80-472e-8fd8-3ac5b20a583a.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5ccd4f2d-a2de-4076-bea8-47445a2bb899.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7b618711-d317-43e6-aec1-3cbdd0635edd.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs918cde05-2409-40bb-9f49-3b48069ae51d.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs698506fa-d864-42c9-802d-3516f4101fc4.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7361de53-2430-4075-bff5-ec559da06109.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs74e89997-ee3c-44b8-8ad1-b312b1920146.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbd65bbbe-db2e-437c-8a18-85052f8d3650.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf9d62590-a6bd-439d-a179-6fd4244868a8.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbda57a87-2717-4897-8ff7-f92ad8b2cb5c.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs204133db-774d-4af0-b057-96afe31bfe6a.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3431d7c3-149f-4641-acdb-a056ec79a731.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsce2b4fc3-e942-4bdf-b9f5-d22167a94951.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7a26a093-6d53-4546-8344-55ff47e85d81.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse4b0cfb6-1962-4765-90e7-7f13c80494e2.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs69d122b7-2816-4b68-b01a-df150e52ef4b.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc8cc22e2-8eab-4301-aeb4-f46873788267.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse4c92a3d-6f3a-44b2-b89b-26c32a99845a.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs233dbc25-3ba4-48f6-8cff-545fba4919a6.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1d16f0df-13d7-41a5-b46d-d363afbed8e8.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs42356d49-f63c-47f0-91ec-09abae7e4dbf.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs402e525f-a9c4-4e45-a469-effc227ebd42.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf16f1746-1229-4ad4-9aa8-1f37b934793b.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4bcdd8f8-9335-4316-97a5-54bd7fc23991.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf030a2a5-842d-4030-a4d6-c7206fca6fba.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4dd45701-47a7-4cf5-91b1-52c1345ebdcb.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3832221d-7402-491f-a427-5447dffe0bf6.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3bb72227-1d8d-48be-a551-6f25cac13a38.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs9884f256-348c-435f-b5f5-8df917dfef0d.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs00bec855-278a-4760-9041-87a3aeddb6e8.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8b4184ad-aba1-40ce-9c91-107a9629e9d8.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbf6ec6e0-f504-4306-93a2-e0e29691c987.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0d7b4e3f-546f-4d92-9d28-c796fc25f53f.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs390bb307-3b44-4e98-b0c5-6731b2d0705f.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa76752aa-b97c-4d50-a9d9-709574b3efed.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs158a14bc-6576-4cf5-8acc-533ffd89ed1e.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsfe2fc412-bf81-4630-9a8d-b16332c79f94.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs73249db6-8d3d-42f5-a34e-cda38f6fc82d.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse7d7cb46-d09d-4160-b24a-ea28523df48a.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs63c5c6e9-cd01-43eb-9d9a-1fb4f9776ec3.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbd80a9ef-356c-4be5-9f14-1ee14695b0a3.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3628c636-8ca6-4071-a7bc-de4ddbdda343.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3eec728d-7006-4d67-89d4-87f9a028ad69.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc982ab1c-0c8a-4fc4-87ad-5ea93341247e.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs83918c6a-9e32-48d0-9393-d98256cb1b01.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4c3ab8a4-d435-4224-b1e0-f43a1a22dc81.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3a9f1ff4-cffb-4b35-b330-c38d7ebdd6dc.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs91217f3e-ce68-4939-8ee4-e7e799e2bf9b.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs27a56fb8-4d59-47d1-ac40-e4ff0554fa6b.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1235acd7-5b83-4625-8ec9-24bad3e06640.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb54564f2-f0f4-4673-8ba4-1141b5b87ca1.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs31e1b264-593f-4e4f-ac13-63a551f1d21e.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs22d6e307-0349-4c25-a7ad-c9ebe432d5b5.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf500c061-9347-42f1-9515-7f49bbbd3fde.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsff67e03a-e9a0-417f-9b2b-8998d604d608.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs63d8936a-5d08-48a5-b2ad-51c80ecc88f8.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs16a4c495-b740-435f-8d45-d5be08a39a73.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs88d83788-3911-4b15-bfc5-329692a0d38c.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs75c95a64-49c2-4adb-82bb-8c8ae1cca692.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscdf97595-6411-4c06-a9f8-f9284e596ba8.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5a4c1031-1fcd-4753-8521-e5a4aec53c68.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsddd8d367-2769-4166-9c3b-077d1a389c4c.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs38bcbbbc-9f6d-4121-9161-626bfac2c435.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs13ee7db7-f69c-4616-b0d3-7ef1b81264e2.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf38192d1-9cdc-4885-a62b-8c58b4b41e74.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse549f55f-d878-493b-806f-7c350839c020.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8cb4da9c-d483-4aca-8d0f-ce077bcb46b6.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5e7ff7f3-6905-4962-8734-aecb3c3a407b.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6b5c843b-b88f-4202-82c4-8157c97429f1.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf0d3904e-023a-466a-a37c-4080dc0ead39.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3e151053-51a1-4a03-8505-4743d7698a2e.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd7a346d8-1264-4fc1-9f0e-febfc3a849d1.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs1f27c0a6-8157-4922-854e-aa4ca2f78ce7.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs24f01acd-5873-425a-b7ec-50c87558fd79.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4ea8e9a1-6bca-4476-a874-915d69f76ce9.tmp". The process cannot access the file because it is being used by another process
10:28 AM: Found Adware: shopathomeselect
10:28 AM: sahagent.exe (ID = 75884)
10:28 AM: isearchtech1005.sah (ID = 75800)
10:28 AM: update.exe (ID = 75690)
10:28 AM: sahagent[1].exe (ID = 75899)
10:28 AM: Found Adware: sexfiles dialers
10:28 AM: dating.lnk (ID = 75396)
10:29 AM: Warning: Failed to open file "c:\documents and settings\joy\ntuser.dat.log". The process cannot access the file because it is being used by another process
10:29 AM: Warning: Failed to open file "c:\documents and settings\joy\ntuser.dat". The process cannot access the file because it is being used by another process
10:29 AM: Warning: Failed to open file "c:\documents and settings\joy\local settings\temp\perflib_perfdata_788.dat". The process cannot access the file because it is being used by another process
10:29 AM: Warning: Failed to open file "c:\documents and settings\joy\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
10:29 AM: Warning: Failed to open file "c:\documents and settings\joy\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
10:29 AM: Warning: Failed to open file "c:\documents and settings\joy\application data\mozilla\firefox\profiles\sppnsdsg.default\parent.lock". The process cannot access the file because it is being used by another process
10:34 AM: Warning: Invalid Stream
10:34 AM: Warning: Invalid Stream
10:34 AM: Warning: Invalid Stream
10:34 AM: Warning: Invalid Stream
10:34 AM: Warning: Invalid Stream
10:34 AM: Warning: Unhandled Archive Type
10:34 AM: Warning: Invalid Stream
10:34 AM: Warning: Invalid Stream
10:36 AM: File Sweep Complete, Elapsed Time: 00:39:36
10:36 AM: Full Sweep has completed. Elapsed time 00:47:27
10:36 AM: Traces Found: 76
10:43 AM: Removal process initiated
10:43 AM: Quarantining All Traces: 180search assistant/zango
10:43 AM: Quarantining All Traces: lopdotcom
10:43 AM: Quarantining All Traces: purityscan
10:43 AM: Quarantining All Traces: internetoptimizer
10:43 AM: Quarantining All Traces: ist powerscan
10:43 AM: Quarantining All Traces: ist sidefind
10:43 AM: Quarantining All Traces: ist software
10:43 AM: Quarantining All Traces: sexfiles dialers
10:43 AM: Quarantining All Traces: shopathomeselect
10:43 AM: Quarantining All Traces: 2o7.net cookie
10:43 AM: Quarantining All Traces: 888 cookie
10:43 AM: Quarantining All Traces: adjuggler cookie
10:43 AM: Quarantining All Traces: adknowledge cookie
10:43 AM: Quarantining All Traces: aptimus cookie
10:43 AM: Quarantining All Traces: ask cookie
10:43 AM: Quarantining All Traces: atwola cookie
10:43 AM: Quarantining All Traces: banner cookie
10:43 AM: Quarantining All Traces: belnk cookie
10:43 AM: Quarantining All Traces: burstnet cookie
10:43 AM: Quarantining All Traces: cc214142 cookie
10:43 AM: Quarantining All Traces: dealtime cookie
10:43 AM: Quarantining All Traces: did-it cookie
10:43 AM: Quarantining All Traces: exitexchange cookie
10:43 AM: Quarantining All Traces: go.com cookie
10:43 AM: Quarantining All Traces: go2net.com cookie
10:43 AM: Quarantining All Traces: hbmediapro cookie
10:43 AM: Quarantining All Traces: ic-live cookie
10:43 AM: Quarantining All Traces: infospace cookie
10:43 AM: Quarantining All Traces: mygeek cookie
10:43 AM: Quarantining All Traces: nextag cookie
10:43 AM: Quarantining All Traces: rednova cookie
10:43 AM: Quarantining All Traces: reliablestats cookie
10:43 AM: Quarantining All Traces: reunion cookie
10:43 AM: Quarantining All Traces: sb01 cookie
10:43 AM: Quarantining All Traces: servlet cookie
10:43 AM: Quarantining All Traces: specificclick.com cookie
10:43 AM: Quarantining All Traces: videodome cookie
10:43 AM: Quarantining All Traces: websponsors cookie
10:43 AM: Quarantining All Traces: webtrendslive cookie
10:43 AM: Quarantining All Traces: winantiviruspro cookie
10:43 AM: Quarantining All Traces: yieldmanager cookie
10:44 AM: Preparing to restart your computer. Please wait...
10:44 AM: Removal process completed. Elapsed time 00:00:58
********
9:46 AM: | Start of Session, Monday, January 23, 2006 |
9:46 AM: Spy Sweeper started
9:46 AM: Sweep initiated using definitions version 605
9:46 AM: Starting Memory Sweep
9:47 AM: Sweep Canceled
9:47 AM: Memory Sweep Complete, Elapsed Time: 00:00:24
9:47 AM: Traces Found: 0
9:48 AM: | End of Session, Monday, January 23, 2006 |
********
9:45 AM: | Start of Session, Monday, January 23, 2006 |
9:45 AM: Spy Sweeper started
9:46 AM: Your spyware definitions have been updated.
9:46 AM: | End of Session, Monday, January 23, 2006 |
Spelunking Rocks!

#4 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:07:18 AM

Posted 23 January 2006 - 01:58 PM

DownLoad EasyCleaner http://www.majorgeeks.com/download414.html

Use the clear files and Unnecessary files buttons – I do not recommend
using the Duplicates files button
as many dupes are there on purpose.

Not all files will delete – that is normal.

In the unnecessary button I check the top 4 entries
========================

Post a new HiJack log
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#5 mojavemystic

mojavemystic
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Ohio
  • Local time:08:18 AM

Posted 23 January 2006 - 03:46 PM

So far so good?
By the way, I no longer have McAfee on my computer. Should I delete those files, or are they not posing a problem?
Thank you,
Joy


Logfile of HijackThis v1.99.1
Scan saved at 12:43:12 PM, on 1/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\??mbols\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adb.../search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adb...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [Uxkgb] C:\WINDOWS\system32\??mbols\svchost.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Touh] "C:\Program Files\mmln\oana.exe" -vt ndrv
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn/insta...cdetection3.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/sj/en/check/qdiagh.cab?326
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - Unknown owner - c:\program files\mcafee.com\agent\mcdetect.exe (file missing)
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - Unknown owner - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe (file missing)
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
Spelunking Rocks!

#6 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:07:18 AM

Posted 23 January 2006 - 04:38 PM

You can try – removing McAfee can be a real pain

Fix these with HJT – mark them, close IE, click fix checked

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe

O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe

O4 - HKCU\..\Run: [Uxkgb] C:\WINDOWS\system32\??mbols\svchost.exe

O4 - HKCU\..\Run: [Touh] "C:\Program Files\mmln\oana.exe" -vt ndrv

O23 - Service: McAfee WSC Integration (McDetect.exe) - Unknown owner - c:\program files\mcafee.com\agent\mcdetect.exe (file missing)

O23 - Service: McAfee Task Scheduler (McTskshd.exe) - Unknown owner - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe (file missing)

O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
===============
Click Start > Run > and type in:

services.msc

Click OK.

In the services window find this exact name

McAfee WSC Integration

Rightclick and choose "Properties". On the "General" tab under "Service Status" click the "Stop" button to stop the service. Beside "Startup Type" in the dropdown menu select "Disabled". Click Apply then OK. File-Exit the Services utility.


Repeat for - McAfee Task Scheduler - and - McAfee SecurityCenter Update Manager

DownLoad http://www.downloads.subratam.org/KillBox.zip

Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

C:\WINDOWS\system32\??mbols
C:\Program Files\mmln

Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure you don't miss any.

START – RUN – type in %temp% OK - Edit – Select all – File – Delete

Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

Empty the recycle bin
Boot and post a new log from normal NOT safe mode

Please give feedback on what worked/didn’t work and the current status of your system
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#7 mojavemystic

mojavemystic
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Ohio
  • Local time:08:18 AM

Posted 23 January 2006 - 05:53 PM

Hello,

The computer takes a long time to boot up now. Webroot/Spy Sweeper takes the longest. After it DL's, it seems to go a bit faster. Also, must manually end the program when restarting/shutting down the computer.

Everything else looks good. No more annoying firewall alerts, except from programs I recognize (so far!).

Logfile of HijackThis v1.99.1
Scan saved at 2:49:52 PM, on 1/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adb.../search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adb...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn/insta...cdetection3.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/sj/en/check/qdiagh.cab?326
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

Edited by mojavemystic, 23 January 2006 - 05:54 PM.

Spelunking Rocks!

#8 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:07:18 AM

Posted 23 January 2006 - 05:56 PM

add remove programs Remove SpySweeper - its only a 2 week trial

Clean Posted Image - If you feel it is fixed, mark it solved via thread tools above - if not what is the current situation?

Restore points
Turn off restore points, boot, turn them back on – here’s how

XP
http://service1.symantec.com/SUPPORT/tsgen...src=sec_doc_nam
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#9 mojavemystic

mojavemystic
  • Topic Starter

  • Members
  • 47 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Ohio
  • Local time:08:18 AM

Posted 23 January 2006 - 07:05 PM

:thumbsup:
Hello,

I am not sure what you mean by, "mark it solved via thread tools above."

But everything looks/acts good!

Thank you very much.

Joy
aka mojavemystic
Spelunking Rocks!

#10 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:07:18 AM

Posted 23 January 2006 - 07:22 PM

Sorry that was for another site

I'll close it here
"Nothing could be finer than to be in South Carolina ............"

Member ASAP




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users