Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected By Trustcleaner And Tracking Cookies Overture, Weborama, Yieldmanager, Advertising, Atdmt


  • This topic is locked This topic is locked
8 replies to this topic

#1 fridj39

fridj39

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 16 October 2006 - 07:35 PM

Hi there,

Please help getting rid of crap below.

I got infected by those:


Lavasoft Ad-Aware log :

Malware.Azesearch(TAC index:10):1 total references
MRU List(TAC index:0):30 total references
Tracking Cookie(TAC index:3):5 total references
TrustCleaner(TAC index:10):3 total references
Win32.TrojanDownloader.Small(TAC index:7):3 total references


Ewido Anti-Spyware log:

+ Scan result:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07A78AEA-4A54-4967-9A60-4B68592D30C7} -> Adware.TrustCleaner : No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{590FFB84-6A29-4797-9C0E-B15DF2C4CDCB} -> Adware.TrustCleaner : No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE6C16C4-16AD-47B6-B250-26AD1829E49A} -> Adware.TrustCleaner : No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{da7ff3f8-08be-4cac-bc00-94d91c6ae7f4} -> Adware.TrustCleaner : No action taken.
HKU\S-1-5-21-1644491937-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07A78AEA-4A54-4967-9A60-4B68592D30C7} -> Adware.TrustCleaner : No action taken.
HKU\S-1-5-21-1644491937-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{590FFB84-6A29-4797-9C0E-B15DF2C4CDCB} -> Adware.TrustCleaner : No action taken.
HKU\S-1-5-21-1644491937-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DA7FF3F8-08BE-4CAC-BC00-94D91C6AE7F4} -> Adware.TrustCleaner : No action taken.
HKU\S-1-5-21-1644491937-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE6C16C4-16AD-47B6-B250-26AD1829E49A} -> Adware.TrustCleaner : No action taken.
C:\Documents and Settings\Mylène\Cookies\mylène@advertising[2].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Mylène\Cookies\mylène@atdmt[1].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Jérome\Cookies\jérome@data4.perf.overture[2].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Jérome\Cookies\jérome@perf.overture[1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Jérome\Cookies\jérome@weborama[2].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\Mylène\Cookies\mylène@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : No action taken.

::Report end



Here is my High Jack This Log :
Logfile of HijackThis v1.99.1
Scan saved at 19:45:09, on 2006-10-16
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Roxio\Roxio DVDMax Player\PDVDServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Thomson\Lyra Jukebox\LyraHDTrayApp\LYRAHD2TrayApp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Softwin\BitDefender8\bdmcon.exe
C:\Program Files\Softwin\BitDefender8\bdnagent.exe
C:\WINDOWS\ASUSKBService.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Softwin\BitDefender8\bdlite.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Jérome\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {07A78AEA-4A54-4967-9A60-4B68592D30C7} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: (no name) - {FE6C16C4-16AD-47B6-B250-26AD1829E49A} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [RemoteControl] C:\Program Files\Roxio\Roxio DVDMax Player\PDVDServ.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acronis True Image Monitor] C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LyraHD2TrayApp] "C:\Program Files\Thomson\Lyra Jukebox\LyraHDTrayApp\LYRAHD2TrayApp.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender8\bdmcon.exe"
O4 - HKLM\..\Run: [BDNewsAgent] "C:\Program Files\Softwin\BitDefender8\bdnagent.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe /start
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125456173013
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: ASUS Keyboard Service (ASUSKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ASUSKBService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

BC AdBot (Login to Remove)

 


#2 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 19 October 2006 - 03:57 PM

Fix these with HiJackThis – mark them, close IE, click fix checked

O2 - BHO: (no name) - {07A78AEA-4A54-4967-9A60-4B68592D30C7} - (no file)

O2 - BHO: (no name) - {FE6C16C4-16AD-47B6-B250-26AD1829E49A} - (no file)

Go to the link below and download the trial version of SpySweeper:

SpySweeper http://www.webroot.com/consumer/products/s...4129&ac=tsg

(It's a 2 week trial.)

* Click the Try Spy Sweeper for FreeDownload the trial link.
* Install it. Once the program is installed, it will open.
* It will prompt you to update to the latest definitions, click Yes.
* Once the definitions are installed, click Options on the left side.
* Click the Sweep Options tab.
* Under What to Sweep please put a check next to the following:
o Sweep Memory
o Sweep Registry
o Sweep Cookies
o Sweep All User Accounts
o Enable Direct Disk Sweeping
o Sweep Contents of Compressed Files
o Sweep for Rootkits

o Please UNCHECK Do not Sweep System Restore Folder.

* Click Sweep Now on the left side.
* Click the Start button.
* When it's done scanning, click the Next button.
* Make sure everything has a check next to it, then click the Next button.
* It will remove all of the items found.
* Click Session Log in the upper right corner, copy everything in that window.
* Click the Summary tab and click Finish.
* Paste the contents of the session log you copied into your next reply.

Also post a new Hijack This log.
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#3 fridj39

fridj39
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 22 October 2006 - 11:10 AM

Here is Spy Sweeper Log :

12:01: Deletion from quarantine completed. Elapsed time 00:00:00
12:01: Processing: xiti cookie
12:01: Processing: atlas dmt cookie
12:01: Processing: webtrends cookie
12:01: Processing: yieldmanager cookie
12:01: Processing: aptimus cookie
12:01: Processing: aptimus cookie
12:01: Processing: pointroll cookie
12:01: Processing: pointroll cookie
12:01: Processing: overture cookie
12:01: Processing: advertising cookie
12:01: Processing: mediaplex cookie
12:01: Processing: realmedia cookie
12:01: Processing: trustin contextual ads
12:01: Processing: trustin search spoof
12:01: Processing: trustin search spoof
12:01: Processing: trustin popups
12:01: Deletion from quarantine initiated
12:00: Removal process completed. Elapsed time 00:00:26
12:00: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SSTE6.tmp". Reason: The system cannot find the file specified
12:00: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
12:00: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SSTE6.tmp". Reason: The system cannot find the file specified
12:00: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
12:00: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SSTE6.tmp". Reason: The system cannot find the file specified
12:00: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
12:00: Quarantining All Traces: xiti cookie
12:00: Quarantining All Traces: overture cookie
12:00: Quarantining All Traces: realmedia cookie
12:00: Quarantining All Traces: mediaplex cookie
12:00: Quarantining All Traces: webtrends cookie
12:00: Quarantining All Traces: atlas dmt cookie
12:00: Quarantining All Traces: aptimus cookie
12:00: Quarantining All Traces: advertising cookie
12:00: Quarantining All Traces: pointroll cookie
12:00: Quarantining All Traces: yieldmanager cookie
12:00: Quarantining All Traces: trustin contextual ads
12:00: Quarantining All Traces: trustin popups
12:00: Quarantining All Traces: trustin search spoof
12:00: Removal process initiated
11:59: Traces Found: 18
11:59: Full Sweep has completed. Elapsed time 00:20:57
11:59: File Sweep Complete, Elapsed Time: 00:18:50
Not enough storage is available to process this command
11:59: Warning: Unable to sweep compressed file: System Error. Code: 8.
Not enough storage is available to process this command
11:59: Warning: Unable to sweep compressed file: System Error. Code: 8.
Not enough storage is available to process this command
11:59: Warning: Unable to sweep compressed file: System Error. Code: 8.
Access is denied
11:58: Warning: Unable to sweep compressed file: System Error. Code: 5.
11:57: Warning: Access violation at address 00401D58 in module 'SpySweeper.exe'. Read of address 7E8E000C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:57: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
11:53: Warning: Failed to open file "c:\documents and settings\jérome\local settings\temporary internet files\content.ie5\u10jq96p\online[1].gif". The operation completed successfully
11:53: Warning: Failed to open file "c:\documents and settings\jérome\local settings\temporary internet files\content.ie5\kt6b6zo9\online[1].gif". The operation completed successfully
11:53: Warning: Failed to open file "c:\documents and settings\jérome\local settings\temporary internet files\content.ie5\bnx3ndkw\online[2].gif". The operation completed successfully
11:53: Warning: Failed to open file "c:\documents and settings\jérome\local settings\temporary internet files\content.ie5\7ygnj94l\online[1].gif". The operation completed successfully
11:53: Warning: Failed to open file "c:\documents and settings\jérome\cookies\jérome@data4.perf.overture[2].txt". The operation completed successfully
11:52: Warning: PerformFileOffsetMatch Failed to check file "c:\program files\common files\symantec shared\eengine\eraser.sys". "c:\program files\common files\symantec shared\eengine\eraser.sys": File not found
11:40: Starting File Sweep
11:40: Cookie Sweep Complete, Elapsed Time: 00:00:00
11:40: c:\documents and settings\jérome\cookies\jérome@xiti[1].txt (ID = 3717)
11:40: Found Spy Cookie: xiti cookie
11:40: c:\documents and settings\jérome\cookies\jérome@perf.overture[1].txt (ID = 3106)
11:40: c:\documents and settings\jérome\cookies\jérome@data4.perf.overture[2].txt (ID = 3106)
11:40: Found Spy Cookie: overture cookie
11:40: c:\documents and settings\jérome\cookies\jérome@ads.pointroll[2].txt (ID = 3148)
11:40: c:\documents and settings\mylène\cookies\mylène@realmedia[1].txt (ID = 3235)
11:40: Found Spy Cookie: realmedia cookie
11:40: c:\documents and settings\mylène\cookies\mylène@network.aptimus[2].txt (ID = 2235)
11:40: c:\documents and settings\mylène\cookies\mylène@mediaplex[1].txt (ID = 6442)
11:40: Found Spy Cookie: mediaplex cookie
11:40: c:\documents and settings\mylène\cookies\mylène@m.webtrends[1].txt (ID = 3669)
11:40: Found Spy Cookie: webtrends cookie
11:40: c:\documents and settings\mylène\cookies\mylène@atdmt[2].txt (ID = 2253)
11:40: Found Spy Cookie: atlas dmt cookie
11:40: c:\documents and settings\mylène\cookies\mylène@aptimus[1].txt (ID = 2233)
11:40: Found Spy Cookie: aptimus cookie
11:40: c:\documents and settings\mylène\cookies\mylène@advertising[2].txt (ID = 2175)
11:40: Found Spy Cookie: advertising cookie
11:40: c:\documents and settings\mylène\cookies\mylène@ads.pointroll[2].txt (ID = 3148)
11:40: Found Spy Cookie: pointroll cookie
11:40: c:\documents and settings\mylène\cookies\mylène@ad.yieldmanager[2].txt (ID = 3751)
11:40: Found Spy Cookie: yieldmanager cookie
11:40: Starting Cookie Sweep
11:40: Registry Sweep Complete, Elapsed Time:00:00:19
11:40: HKU\WRSS_Profile_S-1-5-21-1644491937-602609370-725345543-1004\software\trustin\search results spoofer\ (ID = 1544780)
11:40: HKU\WRSS_Profile_S-1-5-21-1644491937-602609370-725345543-1004\software\trustin\contextual ads\ (ID = 1544766)
11:40: Found Adware: trustin contextual ads
11:40: HKU\WRSS_Profile_S-1-5-21-1644491937-602609370-725345543-1004\software\microsoft\windows\currentversion\run\ || trustin popups (ID = 1544764)
11:40: Found Adware: trustin popups
11:40: HKLM\software\classes\se_spoof.spoofbho\ (ID = 1551615)
11:40: HKCR\se_spoof.spoofbho\ (ID = 1544622)
11:40: Found Adware: trustin search spoof
11:40: Starting Registry Sweep
11:40: Memory Sweep Complete, Elapsed Time: 00:01:40
11:38: Starting Memory Sweep
11:38: Sweep initiated using definitions version 783
11:38: Spy Sweeper 5.0.5.1286 started
11:38: | Start of Session, 22 octobre, 2006 |
********
11:38: | End of Session, 22 octobre, 2006 |
11:36: Your spyware definitions have been updated.
Operation: File Access
Target:
Source: C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSVCHST.EXE
11:35: Tamper Detection
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
11:35: Shield States
11:35: Spyware Definitions: 691
11:34: Spy Sweeper 5.0.5.1286 started
11:34: Spy Sweeper 5.0.5.1286 started
11:34: | Start of Session, 22 octobre, 2006 |
********



Here is my HighJackThis Log :

Logfile of HijackThis v1.99.1
Scan saved at 12:06:12, on 2006-10-22
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Roxio\Roxio DVDMax Player\PDVDServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\ASUSKBService.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Thomson\Lyra Jukebox\LyraHDTrayApp\LYRAHD2TrayApp.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Documents and Settings\Jérome\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [Control Center] "C:\Program Files\ASUS\WLAN Card Utilities\Center.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\Roxio\Roxio DVDMax Player\PDVDServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acronis True Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LyraHD2TrayApp] "C:\Program Files\Thomson\Lyra Jukebox\LyraHDTrayApp\LYRAHD2TrayApp.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Vaderetro Outlook] "C:\PROGRA~1\GOTOSO~1\VADERE~1\VrMoRegister.exe -s"
O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ASUS SmartDoctor] "C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe" /start
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125456173013
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: ASUS Keyboard Service (ASUSKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ASUSKBService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe



By the way, I removed those crap with Norton Anti-virus this week, but it came back...

#4 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 22 October 2006 - 11:22 AM

IE - Block Third party cookies
1. Click on the Tools button on the Internet Explorer tool bar.
2. Highlight and click on Internet options at the bottom of the Tools menu.
3. Select the Privacy Tab of the Internet Options menu.
4. Select the Advanced... button at the bottom of the screen.
5. Select override automatic cookie handling button.
6. To block third party cookies select block under "Third-party cookies".
7. Select "always allow session cookies".
8. Click on the OK button at the bottom of the screen.
===============
In firefox - TOOLS - OPTIONS - PRIVACY - COOKIES - Check originating site only
-----------

HOw are things?
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#5 fridj39

fridj39
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 26 October 2006 - 11:23 PM

Seems that I get rid of trustcleaner, but still have spy cookies...

here are my logs:


Ad Aware :

Ad-Aware SE Build 1.06r1
Logfile Created on:26 octobre, 2006 19:30:05
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R128 18.10.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):16 total references
Tracking Cookie(TAC index:3):2 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


2006-10-26 19:30:05 - Scan started. (Full System Scan)

MRU List Object Recognized!
Location: : C:\Documents and Settings\Jérome\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office


MRU List Object Recognized!
Location: : C:\Documents and Settings\Jérome\recent
Description : list of recently opened documents


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\adobe\acrobat reader\6.0\avgeneral\crecentfiles
Description : list of recently used files in adobe reader


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\google\navclient\1.1\history
Description : list of recently used search terms in the google toolbar


MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d


MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X


MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\mediaplayer\preferences
Description : last playlist index loaded in microsoft windows media player


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\windows\currentversion\applets\regedit
Description : last key accessed using the microsoft registry editor


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\windows\currentversion\explorer\runmru
Description : mru list for items opened in start | run


Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 716
ThreadCreationTime : 2006-10-26 21:47:30
BasePriority : Normal


#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 792
ThreadCreationTime : 2006-10-26 21:47:35
BasePriority : Normal


#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 824
ThreadCreationTime : 2006-10-26 21:47:42
BasePriority : High


#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 868
ThreadCreationTime : 2006-10-26 21:47:44
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe

#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 880
ThreadCreationTime : 2006-10-26 21:47:44
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe

#:6 [ati2evxx.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1044
ThreadCreationTime : 2006-10-26 21:47:45
BasePriority : Normal
FileVersion : 6.14.10.4131
ProductVersion : 6.14.10.4131.01
ProductName : ATI External Event Utility for WindowsNT and Windows9X
CompanyName : ATI Technologies Inc.
FileDescription : ATI External Event Utility EXE Module
InternalName : ATI2EVXX.EXE
LegalCopyright : Copyright © 1999-2004 ATI Technologies Inc.
OriginalFilename : ATI2EVXX.EXE

#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1064
ThreadCreationTime : 2006-10-26 21:47:45
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:8 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1144
ThreadCreationTime : 2006-10-26 21:47:46
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1280
ThreadCreationTime : 2006-10-26 21:47:46
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1412
ThreadCreationTime : 2006-10-26 21:47:46
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:11 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1472
ThreadCreationTime : 2006-10-26 21:47:47
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:12 [ccsvchst.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 1624
ThreadCreationTime : 2006-10-26 21:47:48
BasePriority : Normal
FileVersion : 106.0.1.10
ProductVersion : 106.0.1.10
ProductName : Symantec Security Technologies
CompanyName : Symantec Corporation
FileDescription : Symantec Service Framework
InternalName : ccSvcHst
LegalCopyright : Copyright © 2000-2006 Symantec Corporation. All rights reserved.
OriginalFilename : ccSvcHst.exe

#:13 [appsvc32.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\AppCore\
ProcessID : 1720
ThreadCreationTime : 2006-10-26 21:47:50
BasePriority : Normal
FileVersion : 1.0.00.101
ProductVersion : 1.0
ProductName : Symantec Application Core
CompanyName : Symantec Corporation
FileDescription : Symantec Application Core Service
InternalName : AppSvc32
LegalCopyright : Copyright © 1997-2006 Symantec Corporation
OriginalFilename : AppSvc32.exe

#:14 [asuskbservice.exe]
FilePath : C:\WINDOWS\
ProcessID : 1464
ThreadCreationTime : 2006-10-26 21:47:57
BasePriority : Normal
FileVersion : 1, 0, 0, 0
ProductVersion : 1, 0, 0, 0
ProductName : ASUS Keyboard Service
CompanyName : ASUSTeK COMPUTER INC.
FileDescription : ASUS Keyboard Service
InternalName : ASUSKBService
LegalCopyright : Copyright © 2004 @ASUSTeK COMPUTER INC.
OriginalFilename : ASUSKBService.exe

#:15 [aluschedulersvc.exe]
FilePath : C:\Program Files\Symantec\LiveUpdate\
ProcessID : 1540
ThreadCreationTime : 2006-10-26 21:47:57
BasePriority : Normal
FileVersion : 3.1.0.99
ProductVersion : 3.1.0.99
ProductName : LiveUpdate
CompanyName : Symantec Corporation
FileDescription : Automatic LiveUpdate Scheduler Service
InternalName : Automatic LiveUpdate Scheduler Service
LegalCopyright : Copyright © 1996-2006 Symantec Corporation
OriginalFilename : ALUSchedulerSvc.exe

#:16 [guard.exe]
FilePath : C:\Program Files\ewido anti-spyware 4.0\
ProcessID : 1632
ThreadCreationTime : 2006-10-26 21:47:57
BasePriority : Normal
FileVersion : 4, 0, 0, 172
ProductVersion : 4, 0, 0, 172
ProductName : ewido anti-spyware
CompanyName : Anti-Malware Development a.s.
FileDescription : ewido anti-spyware guard
InternalName : ewido anti-spywareguard
LegalCopyright : Copyright © 2005 Anti-Malware Development a.s.
OriginalFilename : guard.exe

#:17 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1868
ThreadCreationTime : 2006-10-26 21:47:58
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:18 [wdfmgr.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1936
ThreadCreationTime : 2006-10-26 21:47:58
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: dnsrv(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe

#:19 [spysweeper.exe]
FilePath : C:\Program Files\Webroot\Spy Sweeper\
ProcessID : 2032
ThreadCreationTime : 2006-10-26 21:48:01
BasePriority : Normal
FileVersion : 3,0,5,1286
ProductVersion : 3, 0
ProductName : Spy Sweeper SDK
CompanyName : Webroot Software, Inc.
FileDescription : Spy Sweeper Engine
LegalCopyright : Copyright © 2002 - 2006, All Rights Reserved.
LegalTrademarks : Spy Sweeper is a trademark of Webroot Software, Inc.
OriginalFilename : SpySweeper.exe

#:20 [mspmspsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 320
ThreadCreationTime : 2006-10-26 21:48:01
BasePriority : Normal
FileVersion : 7.01.00.3055
ProductVersion : 7.01.00.3055
ProductName : Microsoft ® DRM
CompanyName : Microsoft Corporation
FileDescription : WMDM PMSP Service
InternalName : MSPMSPSV.EXE
LegalCopyright : Copyright © Microsoft Corp. 1981-2000
OriginalFilename : MSPMSPSV.EXE

#:21 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1232
ThreadCreationTime : 2006-10-26 21:48:02
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe

#:22 [ati2evxx.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 3596
ThreadCreationTime : 2006-10-26 21:49:20
BasePriority : Normal
FileVersion : 6.14.10.4131
ProductVersion : 6.14.10.4131.01
ProductName : ATI External Event Utility for WindowsNT and Windows9X
CompanyName : ATI Technologies Inc.
FileDescription : ATI External Event Utility EXE Module
InternalName : ATI2EVXX.EXE
LegalCopyright : Copyright © 1999-2004 ATI Technologies Inc.
OriginalFilename : ATI2EVXX.EXE

#:23 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 3704
ThreadCreationTime : 2006-10-26 21:49:21
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE

#:24 [center.exe]
FilePath : C:\Program Files\ASUS\WLAN Card Utilities\
ProcessID : 3828
ThreadCreationTime : 2006-10-26 21:49:23
BasePriority : Normal
FileVersion : 2.1.6.6
ProductVersion : 1.0.0.0
ProductName : Wireless LAN Card Utilities
CompanyName : ASUSTeK COMPUTER INC.
FileDescription : ASUS Control Center Application
InternalName : Control Center
LegalCopyright : Copyright © 2002-2004 ASUSTeK
OriginalFilename : Center.exe

#:25 [drgtodsc.exe]
FilePath : C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\
ProcessID : 3872
ThreadCreationTime : 2006-10-26 21:49:23
BasePriority : Normal
FileVersion : 6.2.0.134
ProductVersion : 6.2.0.134
ProductName : Drag-to-Disc
CompanyName : Roxio
FileDescription : Drag To Disc Application
InternalName : D2D
LegalCopyright : Copyright © 1999-2003 Roxio, Inc.
LegalTrademarks : Copyright © 1999-2003 Roxio, Inc.
OriginalFilename : BurnCtrl.EXE

#:26 [rxmon.exe]
FilePath : C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\
ProcessID : 3880
ThreadCreationTime : 2006-10-26 21:49:23
BasePriority : Normal


#:27 [pdvdserv.exe]
FilePath : C:\Program Files\Roxio\Roxio DVDMax Player\
ProcessID : 3888
ThreadCreationTime : 2006-10-26 21:49:23
BasePriority : Normal
FileVersion : 5.00.0000
ProductVersion : 5.00.0000
ProductName : PowerDVD
CompanyName : Cyberlink Corp.
FileDescription : PowerDVD RC Service
InternalName : PowerDVD RC Service
LegalCopyright : Copyright © CyberLink Corp. 1997-2002
OriginalFilename : PDVDSERV.EXE

#:28 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 3896
ThreadCreationTime : 2006-10-26 21:49:23
BasePriority : Normal
FileVersion : 0.1.0.1622
ProductVersion : 0.1.0.1622
ProductName : RealOne Player (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2002
LegalTrademarks : RealAudio™ is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe

#:29 [trueimagemonitor.exe]
FilePath : C:\Program Files\Acronis\TrueImage\
ProcessID : 3904
ThreadCreationTime : 2006-10-26 21:49:23
BasePriority : Normal
FileVersion : 7,0,0,589
ProductVersion : 7,0,0,589
ProductName : Acronis True Image
CompanyName : Acronis
FileDescription : TrueImage
InternalName : TrueImageMonitor
LegalCopyright : Copyright © 2000-2003 Acronis.
LegalTrademarks : Acronis
OriginalFilename : TrueImageMonitor.exe
Comments : Acronis True Image

#:30 [schedhlp.exe]
FilePath : C:\Program Files\Common Files\Acronis\Schedule2\
ProcessID : 3912
ThreadCreationTime : 2006-10-26 21:49:23
BasePriority : Normal
FileVersion : 1,0,0,30
ProductVersion : 1,0,0,30
ProductName : Acronis Scheduler Helper
CompanyName : Acronis
FileDescription : Acronis Scheduler Helper
InternalName : Scheduler Helper
LegalCopyright : Copyright © 2000-2003 Acronis
LegalTrademarks : Acronis
OriginalFilename : schedhlp.exe
Comments : Acronis Scheduler Helper

#:31 [rundll32.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 3952
ThreadCreationTime : 2006-10-26 21:49:23
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : RUNDLL.EXE

#:32 [lyrahd2trayapp.exe]
FilePath : C:\Program Files\Thomson\Lyra Jukebox\LyraHDTrayApp\
ProcessID : 3960
ThreadCreationTime : 2006-10-26 21:49:24
BasePriority : Normal
FileVersion : 1. 0. 5. 0
ProductVersion : 1. 0. 5. 0
ProductName : Thomson Inc. Lyra Jukebox System Application
CompanyName : Thomson Inc.
FileDescription : Lyra Jukebox System Application
InternalName : LYRAHD2TrayApp.exe
LegalCopyright : Copyright © 2002-2005
LegalTrademarks : Copyright © 2002-2005. All rights reserved.
OriginalFilename : LYRAHD2TrayApp.exe

#:33 [cli.exe]
FilePath : C:\Program Files\ATI Technologies\ATI.ACE\
ProcessID : 3968
ThreadCreationTime : 2006-10-26 21:49:24
BasePriority : Normal


#:34 [mmtask.exe]
FilePath : C:\Program Files\Musicmatch\Musicmatch Jukebox\
ProcessID : 3984
ThreadCreationTime : 2006-10-26 21:49:24
BasePriority : Normal
FileVersion : 9.0.0.1
ProductVersion : 9.0.0.1
ProductName : Musicmatch Jukebox
CompanyName : Musicmatch Inc.
FileDescription : <Musicmatch System Tray Application>
InternalName : mmtask.exe
LegalCopyright : © Musicmatch Inc.. All rights reserved.
OriginalFilename : mmtask.exe

#:35 [em_exec.exe]
FilePath : C:\Program Files\Logitech\MouseWare\system\
ProcessID : 4004
ThreadCreationTime : 2006-10-26 21:49:24
BasePriority : Normal
FileVersion : 9.79.025
ProductVersion : 9.79.025
ProductName : MouseWare
CompanyName : Logitech Inc.
FileDescription : Logitech Events Handler Application
InternalName : Em_Exec
LegalCopyright : © 1987-2003 Logitech. All rights reserved.
LegalTrademarks : Logitech® and MouseWare® are registered trademarks of Logitech Inc.
OriginalFilename : Em_Exec.exe
Comments : Created by the MouseWare team

#:36 [ccapp.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 4000
ThreadCreationTime : 2006-10-26 21:49:24
BasePriority : Normal
FileVersion : 106.0.1.10
ProductVersion : 106.0.1.10
ProductName : Symantec Security Technologies
CompanyName : Symantec Corporation
FileDescription : Symantec User Session
InternalName : ccApp
LegalCopyright : Copyright © 2000-2006 Symantec Corporation. All rights reserved.
OriginalFilename : ccApp.exe

#:37 [vaderetro_oe.exe]
FilePath : C:\PROGRA~1\GOTOSO~1\VADERE~1\
ProcessID : 4024
ThreadCreationTime : 2006-10-26 21:49:24
BasePriority : Normal
FileVersion : 2.3.0.0
ProductVersion : 1.0.0.0

#:38 [ctfmon.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 4032
ThreadCreationTime : 2006-10-26 21:49:24
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE

#:39 [smartdoctor.exe]
FilePath : C:\Program Files\ASUS\SmartDoctor\
ProcessID : 4040
ThreadCreationTime : 2006-10-26 21:49:24
BasePriority : Normal
FileVersion : 4, 5, 2, 0
ProductVersion : 4, 5, 2, 0
ProductName : ASUS SmartDoctor
CompanyName : ASUSTeK Inc.
FileDescription : SmartDoctor
InternalName : SmartDoctor
LegalCopyright : Copyright © 2004
OriginalFilename : SmartDoctor.exe

#:40 [playlist.exe]
FilePath : C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\
ProcessID : 2092
ThreadCreationTime : 2006-10-26 21:49:28
BasePriority : Normal


#:41 [symlcsvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\
ProcessID : 2956
ThreadCreationTime : 2006-10-26 21:49:34
BasePriority : Normal
FileVersion : 1.9.1.1034
ProductVersion : 1.9.1.1034
ProductName : Symantec Core Component
CompanyName : Symantec Corporation
FileDescription : Symantec Core Component
InternalName : symlcsvc
LegalCopyright : Copyright © 2003
OriginalFilename : symlcsvc.exe

#:42 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2992
ThreadCreationTime : 2006-10-26 21:49:35
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:43 [cli.exe]
FilePath : C:\Program Files\ATI Technologies\ATI.ACE\
ProcessID : 3808
ThreadCreationTime : 2006-10-26 21:49:41
BasePriority : Normal


#:44 [cli.exe]
FilePath : C:\Program Files\ATI Technologies\ATI.ACE\
ProcessID : 3576
ThreadCreationTime : 2006-10-26 21:49:41
BasePriority : Normal


#:45 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 4056
ThreadCreationTime : 2006-10-26 23:29:48
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 16


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 16


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 16


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking Cookie Object Recognized!
Type : IECache Entry
Data : jérome@www.smartadserver[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:6
Value : Cookie:jérome@www.smartadserver.com/
Expires : 2026-10-17 11:57:04
LastSync : Hits:6
UseCount : 0
Hits : 6

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : jérome@estat[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:jérome@estat.com/
Expires : 2016-10-17 17:39:58
LastSync : Hits:1
UseCount : 0
Hits : 1

Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 2
Objects found so far: 18



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 18


Deep scanning and examining files (E:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for E:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 18


Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 18




Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 18

19:40:02 Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:09:56.703
Objects scanned:181109
Objects identified:2
Objects ignored:0
New critical objects:2



now my Spy Sweeper log :
00:12: Removal process completed. Elapsed time 00:00:24
00:12: Quarantining All Traces: fe.lea.lycos.com cookie
00:12: Removal process initiated
00:11: Traces Found: 1
00:11: Full Sweep has completed. Elapsed time 00:30:27
00:11: File Sweep Complete, Elapsed Time: 00:27:17
Not enough storage is available to process this command
00:11: Warning: Unable to sweep compressed file: System Error. Code: 8.
Not enough storage is available to process this command
00:11: Warning: Unable to sweep compressed file: System Error. Code: 8.
Not enough storage is available to process this command
00:11: Warning: Unable to sweep compressed file: System Error. Code: 8.
Access is denied
00:09: Warning: Unable to sweep compressed file: System Error. Code: 5.
00:09: Warning: Access violation at address 00401D58 in module 'SpySweeper.exe'. Read of address 7E2D000C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:08: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:08: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:08: Warning: Access violation at address 0058BE6A in module 'SpySweeper.exe'. Read of address 0000038C
00:02: Warning: Failed to open file "c:\documents and settings\jérome\local settings\temporary internet files\content.ie5\gpunsdib\online[1].gif". The operation completed successfully
00:02: Warning: Failed to open file "c:\documents and settings\jérome\local settings\temporary internet files\content.ie5\upl2n6dk\online[1].gif". The operation completed successfully
00:02: Warning: Failed to open file "c:\documents and settings\jérome\local settings\temporary internet files\content.ie5\2dszidw1\online[4].gif". The operation completed successfully
00:02: Warning: Failed to open file "c:\documents and settings\jérome\local settings\temporary internet files\content.ie5\4zybilmt\online[1].gif". The operation completed successfully
00:02: Warning: Failed to open file "c:\documents and settings\jérome\local settings\temporary internet files\content.ie5\2dszidw1\online[3].gif". The operation completed successfully
00:02: Warning: PerformFileOffsetMatch Failed to check file "c:\program files\common files\symantec shared\eengine\eraser.sys". "c:\program files\common files\symantec shared\eengine\eraser.sys": File not found
00:02: Warning: Failed to open file "c:\recycler\s-1-5-21-1644491937-602609370-725345543-1003\dc5.url". The operation completed successfully
00:02: Warning: Failed to open file "c:\recycler\s-1-5-21-1644491937-602609370-725345543-1003\dc6.url". The operation completed successfully
23:43: Starting File Sweep
23:43: Cookie Sweep Complete, Elapsed Time: 00:00:00
23:43: c:\documents and settings\jérome\cookies\jérome@fe.lea.lycos[1].txt (ID = 2660)
23:43: Found Spy Cookie: fe.lea.lycos.com cookie
23:43: Starting Cookie Sweep
23:43: Registry Sweep Complete, Elapsed Time:00:00:29
23:43: Starting Registry Sweep
23:43: Memory Sweep Complete, Elapsed Time: 00:02:32
23:40: Starting Memory Sweep
23:40: Sweep initiated using definitions version 788
23:40: Spy Sweeper 5.0.5.1286 started
23:40: | Start of Session, 26 octobre, 2006 |
********
23:40: | End of Session, 26 octobre, 2006 |
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
23:40: Shield States
23:40: Spyware Definitions: 788
23:40: Spy Sweeper 5.0.5.1286 started


Finaly, my HighJackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 00:15:54, on 2006-10-27
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\ASUSKBService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Roxio\Roxio DVDMax Player\PDVDServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Thomson\Lyra Jukebox\LyraHDTrayApp\LYRAHD2TrayApp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navw32.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\Jérome\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [Control Center] "C:\Program Files\ASUS\WLAN Card Utilities\Center.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\Roxio\Roxio DVDMax Player\PDVDServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acronis True Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LyraHD2TrayApp] "C:\Program Files\Thomson\Lyra Jukebox\LyraHDTrayApp\LYRAHD2TrayApp.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Vaderetro Outlook] "C:\PROGRA~1\GOTOSO~1\VADERE~1\VrMoRegister.exe -s"
O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ASUS SmartDoctor] "C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe" /start
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125456173013
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: ASUS Keyboard Service (ASUSKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ASUSKBService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

#6 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 27 October 2006 - 09:06 AM

IE - Block Third party cookies
1. Click on the Tools button on the Internet Explorer tool bar.
2. Highlight and click on Internet options at the bottom of the Tools menu.
3. Select the Privacy Tab of the Internet Options menu.
4. Select the Advanced... button at the bottom of the screen.
5. Select override automatic cookie handling button.
6. To block third party cookies select block under "Third-party cookies".
7. Select "always allow session cookies".
8. Click on the OK button at the bottom of the screen.
===============
In firefox - TOOLS - OPTIONS - PRIVACY - COOKIES - Check originating site only
===============

Clean Posted Image

Restore points
Turn off restore points, boot, turn them back on – here’s how

XP
http://service1.symantec.com/SUPPORT/tsgen...src=sec_doc_nam
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#7 fridj39

fridj39
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 31 October 2006 - 09:45 PM

Still have a crapy cookie...

Here is Ad Aware log :


Ad-Aware SE Build 1.06r1
Logfile Created on:31 octobre, 2006 21:01:13
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R129 26.10.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):16 total references
Tracking Cookie(TAC index:3):1 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


2006-10-31 21:01:13 - Scan started. (Full System Scan)

MRU List Object Recognized!
Location: : C:\Documents and Settings\Jérome\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office


MRU List Object Recognized!
Location: : C:\Documents and Settings\Jérome\recent
Description : list of recently opened documents


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\adobe\acrobat reader\6.0\avgeneral\crecentfiles
Description : list of recently used files in adobe reader


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\google\navclient\1.1\history
Description : list of recently used search terms in the google toolbar


MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d


MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X


MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\mediaplayer\preferences
Description : last playlist index loaded in microsoft windows media player


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\windows\currentversion\applets\regedit
Description : last key accessed using the microsoft registry editor


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened


MRU List Object Recognized!
Location: : S-1-5-21-1644491937-602609370-725345543-1003\software\microsoft\windows\currentversion\explorer\runmru
Description : mru list for items opened in start | run


Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 716
ThreadCreationTime : 2006-11-01 00:39:31
BasePriority : Normal


#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 792
ThreadCreationTime : 2006-11-01 00:39:35
BasePriority : Normal


#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 824
ThreadCreationTime : 2006-11-01 00:39:43
BasePriority : High


#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 872
ThreadCreationTime : 2006-11-01 00:39:45
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe

#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 884
ThreadCreationTime : 2006-11-01 00:39:45
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe

#:6 [ati2evxx.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1044
ThreadCreationTime : 2006-11-01 00:39:46
BasePriority : Normal
FileVersion : 6.14.10.4131
ProductVersion : 6.14.10.4131.01
ProductName : ATI External Event Utility for WindowsNT and Windows9X
CompanyName : ATI Technologies Inc.
FileDescription : ATI External Event Utility EXE Module
InternalName : ATI2EVXX.EXE
LegalCopyright : Copyright © 1999-2004 ATI Technologies Inc.
OriginalFilename : ATI2EVXX.EXE

#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1068
ThreadCreationTime : 2006-11-01 00:39:46
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:8 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1184
ThreadCreationTime : 2006-11-01 00:39:47
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1280
ThreadCreationTime : 2006-11-01 00:39:48
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1384
ThreadCreationTime : 2006-11-01 00:39:48
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:11 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1472
ThreadCreationTime : 2006-11-01 00:39:49
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:12 [ccsvchst.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 1592
ThreadCreationTime : 2006-11-01 00:39:50
BasePriority : Normal
FileVersion : 106.0.1.10
ProductVersion : 106.0.1.10
ProductName : Symantec Security Technologies
CompanyName : Symantec Corporation
FileDescription : Symantec Service Framework
InternalName : ccSvcHst
LegalCopyright : Copyright © 2000-2006 Symantec Corporation. All rights reserved.
OriginalFilename : ccSvcHst.exe

#:13 [appsvc32.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\AppCore\
ProcessID : 1704
ThreadCreationTime : 2006-11-01 00:39:52
BasePriority : Normal
FileVersion : 1.0.00.101
ProductVersion : 1.0
ProductName : Symantec Application Core
CompanyName : Symantec Corporation
FileDescription : Symantec Application Core Service
InternalName : AppSvc32
LegalCopyright : Copyright © 1997-2006 Symantec Corporation
OriginalFilename : AppSvc32.exe

#:14 [ati2evxx.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 688
ThreadCreationTime : 2006-11-01 00:39:54
BasePriority : Normal
FileVersion : 6.14.10.4131
ProductVersion : 6.14.10.4131.01
ProductName : ATI External Event Utility for WindowsNT and Windows9X
CompanyName : ATI Technologies Inc.
FileDescription : ATI External Event Utility EXE Module
InternalName : ATI2EVXX.EXE
LegalCopyright : Copyright © 1999-2004 ATI Technologies Inc.
OriginalFilename : ATI2EVXX.EXE

#:15 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 1108
ThreadCreationTime : 2006-11-01 00:39:55
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE

#:16 [center.exe]
FilePath : C:\Program Files\ASUS\WLAN Card Utilities\
ProcessID : 1500
ThreadCreationTime : 2006-11-01 00:39:56
BasePriority : Normal
FileVersion : 2.1.6.6
ProductVersion : 1.0.0.0
ProductName : Wireless LAN Card Utilities
CompanyName : ASUSTeK COMPUTER INC.
FileDescription : ASUS Control Center Application
InternalName : Control Center
LegalCopyright : Copyright © 2002-2004 ASUSTeK
OriginalFilename : Center.exe

#:17 [drgtodsc.exe]
FilePath : C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\
ProcessID : 1880
ThreadCreationTime : 2006-11-01 00:39:57
BasePriority : Normal
FileVersion : 6.2.0.134
ProductVersion : 6.2.0.134
ProductName : Drag-to-Disc
CompanyName : Roxio
FileDescription : Drag To Disc Application
InternalName : D2D
LegalCopyright : Copyright © 1999-2003 Roxio, Inc.
LegalTrademarks : Copyright © 1999-2003 Roxio, Inc.
OriginalFilename : BurnCtrl.EXE

#:18 [em_exec.exe]
FilePath : C:\Program Files\Logitech\MouseWare\system\
ProcessID : 1972
ThreadCreationTime : 2006-11-01 00:39:57
BasePriority : Normal
FileVersion : 9.79.025
ProductVersion : 9.79.025
ProductName : MouseWare
CompanyName : Logitech Inc.
FileDescription : Logitech Events Handler Application
InternalName : Em_Exec
LegalCopyright : © 1987-2003 Logitech. All rights reserved.
LegalTrademarks : Logitech® and MouseWare® are registered trademarks of Logitech Inc.
OriginalFilename : Em_Exec.exe
Comments : Created by the MouseWare team

#:19 [rxmon.exe]
FilePath : C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\
ProcessID : 1976
ThreadCreationTime : 2006-11-01 00:39:57
BasePriority : Normal


#:20 [pdvdserv.exe]
FilePath : C:\Program Files\Roxio\Roxio DVDMax Player\
ProcessID : 1992
ThreadCreationTime : 2006-11-01 00:39:57
BasePriority : Normal
FileVersion : 5.00.0000
ProductVersion : 5.00.0000
ProductName : PowerDVD
CompanyName : Cyberlink Corp.
FileDescription : PowerDVD RC Service
InternalName : PowerDVD RC Service
LegalCopyright : Copyright © CyberLink Corp. 1997-2002
OriginalFilename : PDVDSERV.EXE

#:21 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 2040
ThreadCreationTime : 2006-11-01 00:39:57
BasePriority : Normal
FileVersion : 0.1.0.1622
ProductVersion : 0.1.0.1622
ProductName : RealOne Player (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2002
LegalTrademarks : RealAudio™ is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe

#:22 [trueimagemonitor.exe]
FilePath : C:\Program Files\Acronis\TrueImage\
ProcessID : 208
ThreadCreationTime : 2006-11-01 00:39:58
BasePriority : Normal
FileVersion : 7,0,0,589
ProductVersion : 7,0,0,589
ProductName : Acronis True Image
CompanyName : Acronis
FileDescription : TrueImage
InternalName : TrueImageMonitor
LegalCopyright : Copyright © 2000-2003 Acronis.
LegalTrademarks : Acronis
OriginalFilename : TrueImageMonitor.exe
Comments : Acronis True Image

#:23 [schedhlp.exe]
FilePath : C:\Program Files\Common Files\Acronis\Schedule2\
ProcessID : 216
ThreadCreationTime : 2006-11-01 00:39:58
BasePriority : Normal
FileVersion : 1,0,0,30
ProductVersion : 1,0,0,30
ProductName : Acronis Scheduler Helper
CompanyName : Acronis
FileDescription : Acronis Scheduler Helper
InternalName : Scheduler Helper
LegalCopyright : Copyright © 2000-2003 Acronis
LegalTrademarks : Acronis
OriginalFilename : schedhlp.exe
Comments : Acronis Scheduler Helper

#:24 [rundll32.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 296
ThreadCreationTime : 2006-11-01 00:39:59
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : RUNDLL.EXE

#:25 [lyrahd2trayapp.exe]
FilePath : C:\Program Files\Thomson\Lyra Jukebox\LyraHDTrayApp\
ProcessID : 316
ThreadCreationTime : 2006-11-01 00:39:59
BasePriority : Normal
FileVersion : 1. 0. 5. 0
ProductVersion : 1. 0. 5. 0
ProductName : Thomson Inc. Lyra Jukebox System Application
CompanyName : Thomson Inc.
FileDescription : Lyra Jukebox System Application
InternalName : LYRAHD2TrayApp.exe
LegalCopyright : Copyright © 2002-2005
LegalTrademarks : Copyright © 2002-2005. All rights reserved.
OriginalFilename : LYRAHD2TrayApp.exe

#:26 [cli.exe]
FilePath : C:\Program Files\ATI Technologies\ATI.ACE\
ProcessID : 332
ThreadCreationTime : 2006-11-01 00:39:59
BasePriority : Normal


#:27 [playlist.exe]
FilePath : C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\
ProcessID : 340
ThreadCreationTime : 2006-11-01 00:39:59
BasePriority : Normal


#:28 [mmtask.exe]
FilePath : C:\Program Files\Musicmatch\Musicmatch Jukebox\
ProcessID : 352
ThreadCreationTime : 2006-11-01 00:39:59
BasePriority : Normal
FileVersion : 9.0.0.1
ProductVersion : 9.0.0.1
ProductName : Musicmatch Jukebox
CompanyName : Musicmatch Inc.
FileDescription : <Musicmatch System Tray Application>
InternalName : mmtask.exe
LegalCopyright : © Musicmatch Inc.. All rights reserved.
OriginalFilename : mmtask.exe

#:29 [ccapp.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 364
ThreadCreationTime : 2006-11-01 00:39:59
BasePriority : Normal
FileVersion : 106.0.1.10
ProductVersion : 106.0.1.10
ProductName : Symantec Security Technologies
CompanyName : Symantec Corporation
FileDescription : Symantec User Session
InternalName : ccApp
LegalCopyright : Copyright © 2000-2006 Symantec Corporation. All rights reserved.
OriginalFilename : ccApp.exe

#:30 [vaderetro_oe.exe]
FilePath : C:\PROGRA~1\GOTOSO~1\VADERE~1\
ProcessID : 744
ThreadCreationTime : 2006-11-01 00:40:00
BasePriority : Normal
FileVersion : 2.3.0.0
ProductVersion : 1.0.0.0

#:31 [ctfmon.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 780
ThreadCreationTime : 2006-11-01 00:40:00
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE

#:32 [asuskbservice.exe]
FilePath : C:\WINDOWS\
ProcessID : 804
ThreadCreationTime : 2006-11-01 00:40:00
BasePriority : Normal
FileVersion : 1, 0, 0, 0
ProductVersion : 1, 0, 0, 0
ProductName : ASUS Keyboard Service
CompanyName : ASUSTeK COMPUTER INC.
FileDescription : ASUS Keyboard Service
InternalName : ASUSKBService
LegalCopyright : Copyright © 2004 @ASUSTeK COMPUTER INC.
OriginalFilename : ASUSKBService.exe

#:33 [smartdoctor.exe]
FilePath : C:\Program Files\ASUS\SmartDoctor\
ProcessID : 836
ThreadCreationTime : 2006-11-01 00:40:00
BasePriority : Normal
FileVersion : 4, 5, 2, 0
ProductVersion : 4, 5, 2, 0
ProductName : ASUS SmartDoctor
CompanyName : ASUSTeK Inc.
FileDescription : SmartDoctor
InternalName : SmartDoctor
LegalCopyright : Copyright © 2004
OriginalFilename : SmartDoctor.exe

#:34 [aluschedulersvc.exe]
FilePath : C:\Program Files\Symantec\LiveUpdate\
ProcessID : 1232
ThreadCreationTime : 2006-11-01 00:40:00
BasePriority : Normal
FileVersion : 3.1.0.99
ProductVersion : 3.1.0.99
ProductName : LiveUpdate
CompanyName : Symantec Corporation
FileDescription : Automatic LiveUpdate Scheduler Service
InternalName : Automatic LiveUpdate Scheduler Service
LegalCopyright : Copyright © 1996-2006 Symantec Corporation
OriginalFilename : ALUSchedulerSvc.exe

#:35 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2304
ThreadCreationTime : 2006-11-01 00:40:05
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:36 [wdfmgr.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2572
ThreadCreationTime : 2006-11-01 00:40:08
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: dnsrv(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe

#:37 [spysweeper.exe]
FilePath : C:\Program Files\Webroot\Spy Sweeper\
ProcessID : 2640
ThreadCreationTime : 2006-11-01 00:40:08
BasePriority : Normal
FileVersion : 3,0,5,1286
ProductVersion : 3, 0
ProductName : Spy Sweeper SDK
CompanyName : Webroot Software, Inc.
FileDescription : Spy Sweeper Engine
LegalCopyright : Copyright © 2002 - 2006, All Rights Reserved.
LegalTrademarks : Spy Sweeper is a trademark of Webroot Software, Inc.
OriginalFilename : SpySweeper.exe

#:38 [mspmspsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2812
ThreadCreationTime : 2006-11-01 00:40:10
BasePriority : Normal
FileVersion : 7.01.00.3055
ProductVersion : 7.01.00.3055
ProductName : Microsoft ® DRM
CompanyName : Microsoft Corporation
FileDescription : WMDM PMSP Service
InternalName : MSPMSPSV.EXE
LegalCopyright : Copyright © Microsoft Corp. 1981-2000
OriginalFilename : MSPMSPSV.EXE

#:39 [symlcsvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\
ProcessID : 2872
ThreadCreationTime : 2006-11-01 00:40:11
BasePriority : Normal
FileVersion : 1.9.1.1034
ProductVersion : 1.9.1.1034
ProductName : Symantec Core Component
CompanyName : Symantec Corporation
FileDescription : Symantec Core Component
InternalName : symlcsvc
LegalCopyright : Copyright © 2003
OriginalFilename : symlcsvc.exe

#:40 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 3244
ThreadCreationTime : 2006-11-01 00:40:12
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe

#:41 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2972
ThreadCreationTime : 2006-11-01 00:39:57
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:42 [cli.exe]
FilePath : C:\Program Files\ATI Technologies\ATI.ACE\
ProcessID : 3356
ThreadCreationTime : 2006-11-01 00:39:58
BasePriority : Normal


#:43 [cli.exe]
FilePath : C:\Program Files\ATI Technologies\ATI.ACE\
ProcessID : 3364
ThreadCreationTime : 2006-11-01 00:39:58
BasePriority : Normal


#:44 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 3348
ThreadCreationTime : 2006-11-01 01:59:49
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 16


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 16


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 16


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking Cookie Object Recognized!
Type : IECache Entry
Data : jérome@ads.multimania.lycos[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:jérome@ads.multimania.lycos.fr/
Expires : 2006-10-27 18:38:56
LastSync : Hits:2
UseCount : 0
Hits : 2

Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 17



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 17


Deep scanning and examining files (E:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for E:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 17


Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 17




Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 17

21:11:14 Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:10:01.687
Objects scanned:167958
Objects identified:1
Objects ignored:0
New critical objects:1




Here is my HighJackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 21:41:57, on 2006-10-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Roxio\Roxio DVDMax Player\PDVDServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Thomson\Lyra Jukebox\LyraHDTrayApp\LYRAHD2TrayApp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ASUSKBService.exe
C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\Jérome\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Control Center] "C:\Program Files\ASUS\WLAN Card Utilities\Center.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\Roxio\Roxio DVDMax Player\PDVDServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acronis True Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LyraHD2TrayApp] "C:\Program Files\Thomson\Lyra Jukebox\LyraHDTrayApp\LYRAHD2TrayApp.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Vaderetro Outlook] "C:\PROGRA~1\GOTOSO~1\VADERE~1\VrMoRegister.exe -s"
O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ASUS SmartDoctor] "C:\Program Files\ASUS\SmartDoctor\\SmartDoctor.exe" /start
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125456173013
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: ASUS Keyboard Service (ASUSKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ASUSKBService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

#8 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 01 November 2006 - 04:38 PM

The cookie is harmless
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#9 fridj39

fridj39
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:55 PM

Posted 05 November 2006 - 12:16 PM

After some days running :

Ad Aware: no infection
Ewido Anti-Spyware: no infection
Spy Sweeper: no infection
Norton: no infection

Seems that the problem is resolved.

Thanks body for your help !! :thumbsup:




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users