1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Solved: can't get hjt to work

Discussion in 'Earlier Versions of Windows' started by stella45, Jul 21, 2006.

Thread Status:
Not open for further replies.
Advertisement
  1. stella45

    stella45 Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    157
    i'v downloaded hjt but can't get it to work.
    i had turned of mcafee virus and firewall because
    i have read on an earlier link that hjt might be regarded as
    a virus or worm or some such.
    an "unexpected error " comes up when i click on the icon.
    i am running windows me, along with aol, and the above mentioned
    mcafee.from what i've read in the links, going back over a year,
    it seems there couldn't be a worse combination !
    i dont have much on start up as far as i can tell.
    256 ram
    1.6hdd
    adsl broardband
    any ideas much appreciated.
    by the way, is it a bad idea to start aol, without ,mcafee,
    firewall and anti virus running,
    it's just that if i do,aol takes forever to load.
    i turn them on after aol has finished
    it's quicker,but are the hackers,viri even quicker?
     
  2. blues_harp28

    blues_harp28 Trusted Advisor Spam Fighter

    Joined:
    Jan 9, 2005
    Messages:
    18,565
  3. stella45

    stella45 Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    157
    thanks bluesharp
    there's seems to be a lot more running on start up than i thought,
    and somethings that sound a bit nasty
    i thought only the boxes checked in msconfig
    would show up in the log

    if you care to take a gander
    here it is
    any ideas appreciated
     
  4. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    You didn't post the log - can you also describe what is disabled in msconfig
     
  5. stella45

    stella45 Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    157
    thanks mfdn
    i noticed that too
    you got there before i could edit
    see under experience !
     
  6. stella45

    stella45 Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    157
    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\AOL SPYWARE PROTECTION\AOLSP SCHEDULER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
    C:\PROGRAM FILES\MEDIA ACCESS\MEDIAACCK.EXE
    C:\PROGRAM FILES\MEDIA ACCESS\MEDIAACCESS.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFAGENT.EXE
    C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\AOL 9.0C\WAOL.EXE
    C:\PROGRAM FILES\AOL 9.0C\SHELLMON.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\AOLTPSPD.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://results.dashbar.com/search?c=27440&b=17862&t=0&ce=DI&m=NTI2MTk4MDgw&ver=2.1.0.0
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = aol
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.bt.net/digitaldemo
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
    O2 - BHO: PosHelp - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - C:\PROGRA~1\ADVANC~1\ADVANC~1.DLL
    O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\EBAYTB.DLL
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
    O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRAM FILES\ADVANCED SEARCHBAR\ADVANCEDSEARCHBAR.DLL
    O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\EBAYTB.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\McUpdate.exe
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
    O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
    O4 - HKLM\..\Run: [VirusScan Online] C:\PROGRA~1\MCAFEE.COM\VSO\MCVSSHLD.EXE /disabled
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
    O4 - HKLM\..\Run: [Media Access] C:\PROGRAM FILES\MEDIA ACCESS\MediaAccK.exe
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
    O4 - HKLM\..\Run: [MSConfigReminder] C:\WINDOWS\SYSTEM\msconfig.exe /reminder
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    O4 - Startup: AOL Tray Icon.lnk = C:\Program Files\AOL 9.0c\aoltray.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL/SEARCH.HTML
    O8 - Extra context menu item: &eBay Search - res://C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\eBayTb.dll/RCSearch.html
    O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
    O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
    O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
    O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRAM FILES\ADVANCED SEARCHBAR\ADVANCEDSEARCHBAR.DLL
    O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRAM FILES\ADVANCED SEARCHBAR\ADVANCEDSEARCHBAR.DLL
    O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aolsvc.co.uk/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aolsvc.co.uk/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
    O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
     
  7. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    You need to enable everything in msconfig so that we can see the problems

    One of which is Media Access

    DownLoad http://www.downloads.subratam.org/KillBox.zip

    Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

    Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

    C:\PROGRAM FILES\MEDIA ACCESS

    Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure you don't miss any.

    START – RUN – type in %temp% - OK - Edit – Select all – File – Delete

    Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

    Not all temp files will delete and that is normal
    Empty the recycle bin
    Boot and post a new log from normal NOT safe mode

    Please give feedback on what worked/didn’t work and the current status of your system
     
  8. stella45

    stella45 Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    157
    hi mfdn
    thanks for reply.
    cleared out temp folder

    i downloaded killbox,tried to run it and got,this message.
    "windws cant find aol.exe this program is needed for opening files type "zip file".
    checking all the boxes in msconfig froze the system.
    had to uncheck some to get it back working.
    by the way ,where on earth do you get those "percentage"type thingies,
    can't find any such thing on my keyboard
     
  9. stella45

    stella45 Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    157
    new log
    not sure it'll be too different

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\AOL SPYWARE PROTECTION\AOLSP SCHEDULER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
    C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
    C:\PROGRAM FILES\BT VOYAGER 105 ADSL MODEM\DSLSTAT.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLDIAL.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE
    C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFAGENT.EXE
    C:\PROGRAM FILES\AOL 9.0C\WAOL.EXE
    C:\PROGRAM FILES\AOL 9.0C\SHELLMON.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\AOLTPSPD.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE
    C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://results.dashbar.com/search?c=27440&b=17862&t=0&ce=DI&m=NTI2MTk4MDgw&ver=2.1.0.0
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = aol
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.bt.net/digitaldemo
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
    O2 - BHO: PosHelp - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - C:\PROGRA~1\ADVANC~1\ADVANC~1.DLL
    O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\EBAYTB.DLL
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
    O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRAM FILES\ADVANCED SEARCHBAR\ADVANCEDSEARCHBAR.DLL
    O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\EBAYTB.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
    O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
    O4 - HKLM\..\Run: [VirusScan Online] C:\PROGRA~1\MCAFEE.COM\VSO\MCVSSHLD.EXE /disabled
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - Startup: AOL Tray Icon.lnk = C:\Program Files\AOL 9.0c\aoltray.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL/SEARCH.HTML
    O8 - Extra context menu item: &eBay Search - res://C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\eBayTb.dll/RCSearch.html
    O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
    O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
    O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
    O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRAM FILES\ADVANCED SEARCHBAR\ADVANCEDSEARCHBAR.DLL
    O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRAM FILES\ADVANCED SEARCHBAR\ADVANCEDSEARCHBAR.DLL
    O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aolsvc.co.uk/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aolsvc.co.uk/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
    O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
     
  10. stella45

    stella45 Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    157
    all that are left unchecked are:
    pc health
    load power profile
    taskmoniter
    tkbellexe
    load power profile
    camedia master
    Logfile of HijackThis v1.99.1
    Scan saved at 10:47:52, on 22/07/2006
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\AOL SPYWARE PROTECTION\AOLSP SCHEDULER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
    C:\PROGRAM FILES\BT VOYAGER 105 ADSL MODEM\DSLSTAT.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLDIAL.EXE
    C:\PROGRAM FILES\MEDIA ACCESS\MEDIAACCK.EXE
    C:\PROGRAM FILES\VOYAGERTEST\FTS.EXE
    C:\PROGRAM FILES\ROXIO\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
    C:\PROGRAM FILES\MEDIA ACCESS\MEDIAACCESS.EXE
    C:\WINDOWS\INTELSPN.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFAGENT.EXE
    C:\PROGRAM FILES\AOL 9.0C\WAOL.EXE
    C:\PROGRAM FILES\AOL 9.0C\SHELLMON.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\AOLTPSPD.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\O12JGPYF\HIJACKTHIS[1].EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://results.dashbar.com/search?c=27440&b=17862&t=0&ce=DI&m=NTI2MTk4MDgw&ver=2.1.0.0
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = aol
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.bt.net/digitaldemo
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
    O2 - BHO: PosHelp - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - C:\PROGRA~1\ADVANC~1\ADVANC~1.DLL
    O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\EBAYTB.DLL
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
    O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRAM FILES\ADVANCED SEARCHBAR\ADVANCEDSEARCHBAR.DLL
    O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\EBAYTB.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\McUpdate.exe
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
    O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
    O4 - HKLM\..\Run: [VirusScan Online] C:\PROGRA~1\MCAFEE.COM\VSO\MCVSSHLD.EXE /disabled
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [Media Access] C:\PROGRAM FILES\MEDIA ACCESS\MediaAccK.exe
    O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe"
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [SelahFrontPanel] C:\WINDOWS\Intelspn /B:Software\Intel\Selah
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\RunServices: [AolAcsDaemon1] "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE"
    O4 - Startup: AOL Tray Icon.lnk = C:\Program Files\AOL 9.0c\aoltray.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL/SEARCH.HTML
    O8 - Extra context menu item: &eBay Search - res://C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\eBayTb.dll/RCSearch.html
    O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
    O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
    O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
    O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRAM FILES\ADVANCED SEARCHBAR\ADVANCEDSEARCHBAR.DLL
    O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRAM FILES\ADVANCED SEARCHBAR\ADVANCEDSEARCHBAR.DLL
    O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aolsvc.co.uk/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aolsvc.co.uk/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
    O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net

    C:\PROGRAM FILES\MEDIA ACCESS\MEDIAACCK.EXE
    sounds scary !
    how much of these startup things do i need.
    by the way still can't do anything with killbox
    apart from the,windows cannot fined aol.exe,
    location of aol.exe; wants me to put something after a c;\ "prompt" ?
     
  11. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    Did you delete that folder

    What is uncheck in msconfig

    %% is above the 5

    Go to the link below and download the trial version of SpySweeper:

    SpySweeper http://www.webroot.com/consumer/products/spysweeper/index.html?acode=af1&rc=4129&ac=tsg

    * Click the Free Trial link under "SpySweeper" to download the program.
    * Install it. Once the program is installed, it will open.
    * It will prompt you to update to the latest definitions, click Yes.
    * Once the definitions are installed, click Options on the left side.
    * Click the Sweep Options tab.
    * Under What to Sweep please put a check next to the following:
    o Sweep Memory
    o Sweep Registry
    o Sweep Cookies
    o Sweep All User Accounts
    o Enable Direct Disk Sweeping
    o Sweep Contents of Compressed Files
    o Sweep for Rootkits

    o Please UNCHECK Do not Sweep System Restore Folder.

    * Click Sweep Now on the left side.
    * Click the Start button.
    * When it's done scanning, click the Next button.
    * Make sure everything has a check next to it, then click the Next button.
    * It will remove all of the items found.
    * Click Session Log in the upper right corner, copy everything in that window.
    * Click the Summary tab and click Finish.
    * Paste the contents of the session log you copied into your next reply.
    Also post a new Hijack This log.
     
  12. stella45

    stella45 Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    157
    hi mfdn
    emptied that temp folder
    ran spy sweeper,log below.i dont understand, what, "apps" were running .
    are incoming e-mail,and, trying to visit this site, considered to be applications?
    how do you ensure there is nothing running in the background,sorry,so many questions.
    if so i've likely wasted 2 hours running it ,grief !
    had to delete a lot of the log to"come in under ,30000 characters.only of this type :

    19:17: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs5a41bcfc-b4fa-4520-b97f-f97c0928df29.tmp". The process cannot access the file because it is being used by another process

    i have to download hjt again,i've managed to delete it !
    and try to get killbox again.

    ********

    18:12: Starting Memory Sweep
    18:21: Found Adware: winad
    18:21: Detected running threat: C:\Program Files\Media Access\MediaAccK.exe (ID = 90410)
    18:21: HKLM\Software\Microsoft\Windows\CurrentVersion\Run || Media Access (ID = 0)
    18:21: Detected running threat: C:\Program Files\Media Access\MediaAccess.exe (ID = 90396)
    18:22: Detected running threat: C:\Program Files\Media Access\MediaAccC.dll (ID = 90383)
    18:31: Memory Sweep Complete, Elapsed Time: 00:18:28
    18:31: Starting Registry Sweep
    18:32: HKCR\appid\loaderx.exe\ (1 subtraces) (ID = 147150)
    18:32: HKCR\appid\{735c5a0c-f79f-47a1-8ca1-2a2e482662a8}\ (1 subtraces) (ID = 147151)
    18:32: HKCR\clsid\{1e5f0d38-214b-4085-ad2a-d2290e6a2d2c}\ (14 subtraces) (ID = 147153)
    18:32: HKCR\mediaaccess.installer\ (5 subtraces) (ID = 147157)
    18:32: HKLM\software\classes\appid\loaderx.exe\ (1 subtraces) (ID = 147164)
    18:32: HKLM\software\classes\appid\{735c5a0c-f79f-47a1-8ca1-2a2e482662a8}\ (1 subtraces) (ID = 147165)
    18:32: HKLM\software\classes\clsid\{1e5f0d38-214b-4085-ad2a-d2290e6a2d2c}\ (14 subtraces) (ID = 147167)
    18:32: HKLM\software\classes\mediaaccess.installer\ (5 subtraces) (ID = 147171)
    18:32: HKLM\software\classes\typelib\{15696ae2-6ea4-47f4-bea6-a3d32693efc7}\ (9 subtraces) (ID = 147176)
    18:32: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediaaccx.dll\ (2 subtraces) (ID = 147191)
    18:32: HKLM\software\microsoft\windows\currentversion\run\ || media access (ID = 147202)
    18:32: HKLM\software\microsoft\windows\currentversion\uninstall\media access\ (2 subtraces) (ID = 147230)
    18:32: HKCR\typelib\{15696ae2-6ea4-47f4-bea6-a3d32693efc7}\ (9 subtraces) (ID = 147244)
    18:32: Found Adware: desktoptraffic
    18:32: HKU\.DEFAULT\eeennn\ (ID = 124993)
    18:32: Found Adware: isearch toolbar
    18:32: HKU\.DEFAULT\software\microsoft\internet explorer\extensions\cmdmapping\ || {1ae2f26c-8e23-4930-a68d-9e681a764001} (ID = 129029)
    18:32: Found Adware: dashbar
    18:32: HKU\.DEFAULT\software\microsoft\internet explorer\main\ || search bar (ID = 1027877)
    18:32: Registry Sweep Complete, Elapsed Time:00:01:53
    18:32: Starting Cookie Sweep
    18:32: Found Spy Cookie: mediaplex cookie
    18:32: [email protected][1].txt (ID = 6442)
    18:32: Found Spy Cookie: advertising cookie
    18:32: [email protected]vertising[1].txt (ID = 2175)
    18:32: Found Spy Cookie: servedby advertising cookie
    18:32: [email protected][2].txt (ID = 3335)
    18:32: Found Spy Cookie: serving-sys cookie
    18:32: [email protected][2].txt (ID = 3343)
    18:32: Found Spy Cookie: atlas dmt cookie
    18:32: [email protected][2].txt (ID = 2253)
    18:32: Found Spy Cookie: belnk cookie
    18:32: [email protected][2].txt (ID = 2292)
    18:32: Found Spy Cookie: domain sponsor cookie
    18:32: [email protected][1].txt (ID = 2533)
    18:32: Found Spy Cookie: revenue.net cookie
    18:32: [email protected][2].txt (ID = 3257)
    18:33: Found Spy Cookie: questionmarket cookie
    18:33: [email protected][1].txt (ID = 3217)
    18:33: [email protected][1].txt (ID = 2175)
    18:33: [email protected][1].txt (ID = 2293)
    18:33: Found Spy Cookie: spywarestormer cookie
    18:33: [email protected][1].txt (ID = 3417)
    18:33: Found Spy Cookie: a cookie
    18:33: [email protected][1].txt (ID = 2027)
    18:33: Found Spy Cookie: xxxtoolbar cookie
    18:33: [email protected][1].txt (ID = 3739)
    18:33: Found Spy Cookie: casalemedia cookie
    18:33: [email protected][1].txt (ID = 2354)
    18:33: Found Spy Cookie: 888 cookie
    18:33: [email protected][1].txt (ID = 2019)
    18:33: Found Spy Cookie: dashbar cookie
    18:33: [email protected][1].txt (ID = 2496)
    18:33: Found Spy Cookie: toprebates.com cookie
    18:33: [email protected][2].txt (ID = 3562)
    18:33: Found Spy Cookie: domainsponsor cookie
    18:33: [email protected][1].txt (ID = 2535)
    18:33: Found Spy Cookie: ccbill cookie
    18:33: [email protected][1].txt (ID = 2369)
    18:33: [email protected][2].txt (ID = 3335)
    18:33: Found Spy Cookie: versiontracker cookie
    18:33: [email protected][2].txt (ID = 3636)
    18:33: Found Spy Cookie: hitslink cookie
    18:33: [email protected][1].txt (ID = 2790)
    18:33: Found Spy Cookie: overture cookie
    18:33: [email protected][1].txt (ID = 3105)
    18:33: [email protected][2].txt (ID = 2027)
    18:33: [email protected][3].txt (ID = 2253)
    18:33: Found Spy Cookie: ads.adsag cookie
    18:33: [email protected][1].txt (ID = 2108)
    18:33: Found Spy Cookie: dealtime cookie
    18:33: [email protected][2].txt (ID = 2506)
    18:33: Found Spy Cookie: falkag cookie
    18:33: [email protected][2].txt (ID = 2650)
    18:33: Found Spy Cookie: onestat.com cookie
    18:33: [email protected][2].txt (ID = 3098)
    18:33: Found Spy Cookie: fastclick cookie
    18:33: [email protected][2].txt (ID = 2651)
    18:33: Found Spy Cookie: gostats cookie
    18:33: [email protected][2].txt (ID = 2748)
    18:33: Found Spy Cookie: ysbweb cookie
    18:33: [email protected][2].txt (ID = 3756)
    18:33: Found Spy Cookie: statcounter cookie
    18:33: [email protected][2].txt (ID = 3447)
    18:33: Found Spy Cookie: burstnet cookie
    18:33: [email protected][2].txt (ID = 2336)
    18:33: Found Spy Cookie: tribalfusion cookie
    18:33: [email protected][2].txt (ID = 3589)
    18:33: [email protected][5].txt (ID = 3105)
    18:33: [email protected][3].txt (ID = 3343)
    18:33: [email protected][3].txt (ID = 3447)
    18:33: [email protected][3].txt (ID = 2651)
    18:33: [email protected][2].txt (ID = 2175)
    18:33: [email protected][3].txt (ID = 6442)
    18:33: [email protected][2].txt (ID = 3447)
    18:33: [email protected][3].txt (ID = 2506)
    18:33: [email protected][2].txt (ID = 3105)
    18:33: [email protected][1].txt (ID = 3217)
    18:33: Found Spy Cookie: adviva cookie
    18:33: [email protected][1].txt (ID = 2177)
    18:33: [email protected][1].txt (ID = 3335)
    18:33: Found Spy Cookie: tacoda cookie
    18:33: [email protected][1].txt (ID = 6444)
    18:33: Found Spy Cookie: clickbank cookie
    18:33: [email protected][1].txt (ID = 2398)
    18:33: [email protected][3].txt (ID = 2293)
    18:33: Found Spy Cookie: zedo cookie
    18:33: [email protected][2].txt (ID = 3762)
    18:33: Found Spy Cookie: bs.serving-sys cookie
    18:33: [email protected][1].txt (ID = 2330)
    18:33: Found Spy Cookie: bluestreak cookie
    18:33: [email protected][1].txt (ID = 2314)
    18:33: [email protected][2].txt (ID = 3217)
    18:33: Found Spy Cookie: howstuffworks cookie
    18:33: [email protected][2].txt (ID = 2805)
    18:33: Found Spy Cookie: tradedoubler cookie
    18:33: [email protected][1].txt (ID = 3575)
    18:33: [email protected][2].txt (ID = 2650)
    18:33: [email protected][3].txt (ID = 2175)
    18:33: [email protected][3].txt (ID = 3589)
    18:33: Found Spy Cookie: webtrendslive cookie
    18:33: [email protected][2].txt (ID = 3667)
    18:33: Found Spy Cookie: myaffiliateprogram.com cookie
    18:33: [email protected]affiliateprogram[2].txt (ID = 3032)
    18:33: [email protected][3].txt (ID = 3335)
    18:33: [email protected][1].txt (ID = 2651)
    18:33: [email protected][2].txt (ID = 2314)
    18:33: Found Spy Cookie: adbureau cookie
    18:33: [email protected][2].txt (ID = 2060)
    18:33: [email protected][2].txt (ID = 3217)
    18:33: [email protected][3].txt (ID = 3447)
    18:33: Found Spy Cookie: ask cookie
    18:33: [email protected][2].txt (ID = 2245)
    18:33: [email protected][4].txt (ID = 2175)
    18:33: [email protected][3].txt (ID = 2336)
    18:33: [email protected][1].txt (ID = 2650)
    18:33: [email protected][4].txt (ID = 2293)
    18:33: Found Spy Cookie: banner cookie
    18:33: [email protected][2].txt (ID = 2276)
    18:33: [email protected][1].txt (ID = 3032)
    18:33: [email protected][1].txt (ID = 3762)
    18:33: [email protected][3].txt (ID = 3217)
    18:33: [email protected][2].txt (ID = 2806)
    18:33: [email protected][3].txt (ID = 6444)
    18:33: [email protected][1].txt (ID = 2805)
    18:33: [email protected][1].txt (ID = 2276)
    18:33: [email protected][1].txt (ID = 3106)
    18:33: [email protected][1].txt (ID = 3106)
    18:33: [email protected][3].txt (ID = 3105)
    18:33: [email protected][1].txt (ID = 3589)
    18:33: [email protected][4].txt (ID = 3447)
    18:33: [email protected][4].txt (ID = 3343)
    18:33: Found Spy Cookie: server.iad.liveperson cookie
    18:33: [email protected][1].txt (ID = 3341)
    18:33: [email protected][1].txt (ID = 2506)
    18:33: Found Spy Cookie: hotlog cookie
    18:33: [email protected][1].txt (ID = 2801)
    18:33: [email protected][2].txt (ID = 3575)
    18:33: [email protected][2].txt (ID = 2330)
    18:33: Found Spy Cookie: webpower cookie
    18:33: [email protected][1].txt (ID = 3660)
    18:33: [email protected][2].txt (ID = 3106)
    18:33: Found Spy Cookie: hypertracker.com cookie
    18:33: [email protected][1].txt (ID = 2817)
    18:33: [email protected][3].txt (ID = 3667)
    18:33: [email protected][1].txt (ID = 2245)
    18:33: [email protected][2].txt (ID = 2398)
    18:33: Found Spy Cookie: adultfriendfinder cookie
    18:33: [email protected][2].txt (ID = 2165)
    18:33: [email protected][2].txt (ID = 6442)
    18:33: Found Spy Cookie: pcstats.com cookie
    18:33: [email protected][2].txt (ID = 3125)
    18:33: Found Spy Cookie: adtech cookie
    18:33: [email protected][2].txt (ID = 2155)
    18:33: [email protected][3].txt (ID = 3762)
    18:33: [email protected][2].txt (ID = 3106)
    18:33: [email protected][1].txt (ID = 3106)
    18:33: Found Spy Cookie: 2o7.net cookie
    18:33: [email protected][1].txt (ID = 1958)
    18:33: Found Spy Cookie: 247realmedia cookie
    18:33: [email protected][1].txt (ID = 1953)
    18:33: [email protected][3].txt (ID = 3575)
    18:33: [email protected][4].txt (ID = 2314)
    18:33: [email protected][1].txt (ID = 2505)
    18:33: [email protected][5].txt (ID = 2175)
    18:33: Found Spy Cookie: atwola cookie
    18:33: [email protected][2].txt (ID = 2255)
    18:33: [email protected][5].txt (ID = 3447)
    18:33: Found Spy Cookie: web-stat cookie
    18:33: [email protected][2].txt (ID = 3648)
    18:33: [email protected][1].txt (ID = 1958)
    18:33: [email protected][5].txt (ID = 3343)
    18:33: [email protected][2].txt (ID = 1958)
    18:33: [email protected][1].txt (ID = 1958)
    18:33: [email protected][5].txt (ID = 3217)
    18:33: [email protected][4].txt (ID = 6444)
    18:33: [email protected][4].txt (ID = 2805)
    18:33: [email protected][2].txt (ID = 1957)
    18:33: [email protected][2].txt (ID = 3126)
    18:33: Found Spy Cookie: pointroll cookie
    18:33: [email protected][1].txt (ID = 3148)
    18:33: [email protected][1].txt (ID = 3098)
    18:33: [email protected][4].txt (ID = 2506)
    18:33: Found Spy Cookie: webtrends cookie
    18:33: [email protected][1].txt (ID = 3669)
    18:33: [email protected][3].txt (ID = 2398)
    18:33: [email protected][1].txt (ID = 2337)
    18:33: Found Spy Cookie: yieldmanager cookie
    18:33: [email protected][1].txt (ID = 3751)
    18:33: [email protected][2].txt (ID = 2496)
    18:33: [email protected][5].txt (ID = 3589)
    18:33: Cookie Sweep Complete, Elapsed Time: 00:00:16
    18:33: Starting File Sweep
    18:50: Found Adware: dealhelper
    18:50: glbsnok.xml (ID = 57646)
    18:50: glbsnok1.xml (ID = 57647)
    18:50: glbsnok2.xml (ID = 57648)
    :53: toolbar.dll (ID = 64376)
    18:54: Found Adware: hotsearchbar toolbar
    18:54: hsrb.dll (ID = 62506)
    19:14: Found Adware: ist yoursitebar
    19:14: ysbactivex.inf (ID = 91034)
    19:14: hsrb.inf (ID = 62507)




    19:15: initial.inf (ID = 64361)
    19:15: Found Adware: gain - common components
    19:15: hdplugin1101.inf (ID = 61480)


















    19:17: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs9928e04b-1d16-42b6-87b7-6a5d460cf6b2.tmp". The process cannot access the file because it is being used by another process

    19:17: Found Adware: sexfiles dialers
    19:17: dating.lnk (ID = 75396)
    19:57: c:\program files\media access (4 subtraces) (ID = -2147480020)
    19:58: mediaaccess.exe (ID = 90396)
    19:58: mediaacck.exe (ID = 90410)
    19:58: HKLM\Software\Microsoft\Windows\CurrentVersion\Run || Media Access (ID = 0)
    19:58: mediaaccc.dll (ID = 90383)
    19:58: info.txt (ID = 90430)
    20:30: Warning: Invalid Stream
    20:30: Warning: Invalid Stream
    20:30: Warning: Invalid Stream
    20:30: Warning: Invalid Stream
    20:30: Warning: Invalid Stream
    20:30: Warning: Unable to sweep compressed file: Cannot open file "c:\windows\desktop\killbox.zip". Cannot acces files that are encrypted, compressed or sparse
    20:30: File Sweep Complete, Elapsed Time: 01:57:14
    20:30: Full Sweep has completed. Elapsed time 02:18:01
    20:30: Traces Found: 236
    20:34: Removal process initiated
    20:35: Quarantining All Traces: ist yoursitebar
    20:35: Quarantining All Traces: isearch toolbar
    20:35: Quarantining All Traces: winad
    20:35: Warning: Cannot create file "C:\WINDOWS\TEMP\". The system cannot find the path specified
    20:35: Warning: Cannot create file "C:\WINDOWS\TEMP\". The system cannot find the path specified
    20:35: Warning: Cannot create file "C:\WINDOWS\TEMP\". The system cannot find the path specified
    20:35: Warning: Cannot create file "C:\WINDOWS\TEMP\". The system cannot find the path specified
    20:35: Error: Cannot create file "C:\WINDOWS\TEMP\". The system cannot find the path specified.
    20:35: Failed to quarantine winad
    20:35: Failed to quarantine info.txt
    20:35: Failed to quarantine C:\Program Files\Media Access\MediaAccK.exe
    20:35: Failed to quarantine C:\Program Files\Media Access\MediaAccess.exe
    20:35: Failed to quarantine C:\Program Files\Media Access\MediaAccC.dll
    20:35: Quarantining All Traces: dealhelper
    20:36: Quarantining All Traces: desktoptraffic
    20:36: Quarantining All Traces: hotsearchbar toolbar
    20:36: Quarantining All Traces: sexfiles dialers
    20:36: Quarantining All Traces: 247realmedia cookie
    20:36: Quarantining All Traces: 2o7.net cookie
    20:36: Quarantining All Traces: 888 cookie
    20:36: Quarantining All Traces: a cookie
    20:36: Quarantining All Traces: adbureau cookie
    20:36: Quarantining All Traces: ads.adsag cookie
    20:36: Quarantining All Traces: adtech cookie
    20:36: Quarantining All Traces: adultfriendfinder cookie
    20:36: Quarantining All Traces: advertising cookie
    20:36: Quarantining All Traces: adviva cookie
    20:36: Quarantining All Traces: ask cookie
    20:36: Quarantining All Traces: atlas dmt cookie
    20:36: Quarantining All Traces: atwola cookie
    20:36: Quarantining All Traces: banner cookie
    20:36: Quarantining All Traces: belnk cookie
    20:36: Quarantining All Traces: bluestreak cookie
    20:36: Quarantining All Traces: bs.serving-sys cookie
    20:36: Quarantining All Traces: burstnet cookie
    20:36: Quarantining All Traces: casalemedia cookie
    20:36: Quarantining All Traces: ccbill cookie
    20:36: Quarantining All Traces: clickbank cookie
    20:36: Quarantining All Traces: dashbar cookie
    20:36: Quarantining All Traces: dashbar
    20:36: Quarantining All Traces: dealtime cookie
    20:36: Quarantining All Traces: domain sponsor cookie
    20:36: Quarantining All Traces: domainsponsor cookie
    20:36: Quarantining All Traces: falkag cookie
    20:36: Quarantining All Traces: fastclick cookie
    20:36: Quarantining All Traces: gain - common components
    20:36: Quarantining All Traces: gostats cookie
    20:36: Quarantining All Traces: hitslink cookie
    20:36: Quarantining All Traces: hotlog cookie
    20:36: Quarantining All Traces: howstuffworks cookie
    20:36: Quarantining All Traces: hypertracker.com cookie
    20:36: Quarantining All Traces: mediaplex cookie
    20:36: Quarantining All Traces: myaffiliateprogram.com cookie
    20:36: Quarantining All Traces: onestat.com cookie
    20:36: Quarantining All Traces: overture cookie
    20:36: Quarantining All Traces: pcstats.com cookie
    20:36: Quarantining All Traces: pointroll cookie
    20:36: Quarantining All Traces: questionmarket cookie
    20:36: Quarantining All Traces: revenue.net cookie
    20:36: Quarantining All Traces: servedby advertising cookie
    20:36: Quarantining All Traces: server.iad.liveperson cookie
    20:36: Quarantining All Traces: serving-sys cookie
    20:36: Quarantining All Traces: spywarestormer cookie
    20:36: Quarantining All Traces: statcounter cookie
    20:36: Quarantining All Traces: tacoda cookie
    20:36: Quarantining All Traces: toprebates.com cookie
    20:36: Quarantining All Traces: tradedoubler cookie
    20:36: Quarantining All Traces: tribalfusion cookie
    20:36: Quarantining All Traces: versiontracker cookie
    20:36: Quarantining All Traces: webpower cookie
    20:36: Quarantining All Traces: web-stat cookie
    20:36: Quarantining All Traces: webtrends cookie
    20:36: Quarantining All Traces: webtrendslive cookie
    20:36: Quarantining All Traces: xxxtoolbar cookie
    20:36: Quarantining All Traces: yieldmanager cookie
    20:36: Quarantining All Traces: ysbweb cookie
    20:36: Quarantining All Traces: zedo cookie
    20:37: Preparing to restart your computer. Please wait...
    20:37: Removal process completed. Elapsed time 00:03:24
    ********
    18:06: | Start of Session, 22 July 2006 |
    18:06: Spy Sweeper started
    18:08: Your spyware definitions have been updated.
    18:12: | End of Session, 22 July 2006 |
     
  13. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    You have a mess, run SpySweeper in safe mode
     
  14. stella45

    stella45 Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    157
    hi mfdn
    thank for breaking it so gently
    this is from the safe start.




    ********
    22:43: | Start of Session, 22 July 2006 |
    22:43: Spy Sweeper started
    22:43: Sweep initiated using definitions version 724
    22:43: Starting Memory Sweep
    22:45: Starting Registry Sweep
    22:45: Memory Sweep Complete, Elapsed Time: 00:00:00
    22:46: Registry Sweep Complete, Elapsed Time:00:02:50
    22:46: Starting Cookie Sweep
    22:46: Found Spy Cookie: a cookie
    22:46: [email protected][1].txt (ID = 2027)
    22:46: Found Spy Cookie: pcstats.com cookie
    22:46: pre[email protected][1].txt (ID = 3126)
    22:46: Found Spy Cookie: 2o7.net cookie
    22:46: [email protected][1].txt (ID = 1958)
    22:46: [email protected][2].txt (ID = 3125)
    22:46: Found Spy Cookie: yieldmanager cookie
    22:46: [email protected][2].txt (ID = 3751)
    22:46: Found Spy Cookie: statcounter cookie
    22:46: [email protected][2].txt (ID = 3447)
    22:46: Cookie Sweep Complete, Elapsed Time: 00:00:00
    22:46: Starting File Sweep
    22:47: Warning: Failed to open file "c:\windows\win386.swp". The process cannot access the file because it is being used by another process
    22:48: Found Adware: isearch toolbar
    22:48: a0087376.cpy (ID = 64376)
    22:48: Found Adware: winad
    22:48: a0087377.cpy (ID = 90410)
    22:48: a0087378.cpy (ID = 90396)
    22:48: a0087379.cpy (ID = 90383)
    22:48: Found Adware: hotsearchbar toolbar
    22:48: a0087380.cpy (ID = 62506)
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscscdcd1ce8-9e6f-4880-9c3a-c1bb12597696.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsaf0adc64-b61c-4484-97cf-e1d36e216b9a.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs407488f1-bffd-4696-9f43-bebb80dcafcd.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs234584d2-c24b-4a27-bdc8-bc4ef84174f2.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs1254bf95-5329-42e3-baf9-4cf7d4509bd1.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs48ef52af-7c14-467b-8850-6728e115d93e.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs54b0f8d9-6502-4a9c-a749-e46ba08a8e32.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs1e8cf154-f27b-4c66-a0b3-dfdabc1bed21.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs2c5b7ad7-2437-48f2-9865-67f4c17c25a7.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscse09a6973-35b5-4274-bf09-357f651957e5.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs112cf807-3e65-4eb6-ac08-05267c6ca869.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs151cb014-7bb7-44af-9492-5eea32e799c5.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs00199a04-c47f-4c66-9c1d-e845019360e6.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs1284411f-9cdf-49b0-8ada-058bfcc62f62.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs66269901-7a41-47a7-bc5f-26b139933b5e.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscse946d931-6486-4b75-bd7d-195a439b4a3f.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs8f6ae041-7c45-48ad-aa83-3e4ab6b1d373.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs694129bc-d4a1-4046-a2e3-a17e10a40900.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsf583fa38-8dd8-4141-b318-4f015a48674d.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs24ddce7b-7e19-4b2e-860d-4a566c95a7aa.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsc6be2e70-0940-4d93-bb71-b66cdf85816c.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscse4b48089-5d20-4481-8ec2-7c126a40dfb3.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsa18a8e41-2de5-46c5-97fe-fba885d6e744.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs63b4ab2b-7f7f-4c1f-b797-8b1f668d594a.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs409b5a2d-e102-459d-9589-dc27bb61fb65.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs5ea2c4f9-09cd-42fd-bef7-a3e6e8b88f42.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsc9f1450d-eb15-4141-b045-cb86f339ee5d.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs8a21a391-2914-4b09-879c-7c27348af435.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69aab68f-b3ed-45f8-90ab-99e4a89186c5.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs9c50b4ee-39ff-47ec-8e86-bf24b9fbe7f8.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs0a74a1b9-7536-40f5-9b98-637919c0c8ed.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs5bdbd46f-fc28-4352-8373-20847e889311.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs501bfb3c-60c7-4cca-a9ba-1b1c2df88905.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs9a12d7d9-cb6a-4301-bc29-edf36717bff7.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs64023b96-38fa-4679-a7aa-fd8c40250396.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs758b9d8c-c61f-4242-a539-681e46ffec2d.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscse2aee66b-acfc-427b-909c-3d4f71d02a37.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs8d8cc9e0-7afa-45ae-9d40-73b38b4dc86a.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs7ebda8da-378e-4d26-bc77-87de82c9d399.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs66095b12-4a9a-4429-b594-59946e14b23e.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs7f3009d2-abb6-44ba-ad15-7f1ddf73c221.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs2a7b9f6e-752a-4c46-b81d-3777fb4ec99a.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsac4cba50-875b-46e9-b1c7-5c22f670d671.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs34de2305-f9ab-4705-91c0-4cd4ef40109b.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsf1905fc2-a9b0-4bd0-847f-60591dc27a45.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsad8b4a50-27a4-4dd8-8fb1-bc7c3f0de2ba.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs455f58a5-3d20-4a8b-9dd9-4c73bc87644d.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs46cc76bc-d4d4-4dde-a535-f44840f35128.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs7656e86b-b8e2-4fa8-b4cb-678c754eb650.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs699f5246-e6dd-44c4-ab0d-45532297527d.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsd8bbe93e-e556-4da4-be87-ab3a28b476dd.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs2140214e-8718-4c34-89f3-cd687f7989f1.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsfa3d6113-eb9d-489b-95bb-424e41b80d6e.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsd85f2218-17a1-400b-85d8-51c825bb0bb2.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs2509fd82-9afc-4d2f-b7cf-3f2a08c8248d.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs156dc940-0726-4f0c-926d-b57ac34cfe63.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs0454b56e-7c9f-4d78-b989-635d66780c10.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs62487767-3172-470a-be04-2713517fd4c2.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscscdd081a9-32e7-44ba-b7eb-72f96d8fee0d.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs489eda3f-8c42-430e-8f0c-5a04b9b7130b.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsd1dd81e2-c982-42a1-8b65-99d368ea5256.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs3d41dbd1-5537-4883-9e84-c86a74334ffb.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs8b1e1600-c7d0-4755-81ca-2bbe8c5ccab9.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs12917811-b96e-4286-a526-79c1ec4b44f2.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsbef6ac41-8935-4964-a773-031ceb2784c9.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs72428ae1-431e-4b6a-b131-49cbba63a2b5.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs3c81c6cb-03f4-431e-b7ba-e0a7c28c4320.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscse4ad7bb6-4793-4753-bdda-390d95648f94.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs35358313-f674-464e-8b5e-cc6242d93a7e.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsef0f1610-1f3b-4b41-9336-80ad1b8cce47.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs70b0afdb-8917-4a4d-b990-32a01ab60da5.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs80ce6a0c-de96-467e-b96c-3310a7343a1f.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsa7c16e6c-1973-4846-8704-5ad28e12cc80.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsd61ca077-d39a-4a40-89a0-4745dcadad8e.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs8216985c-799f-4958-a778-a3f753e9ce9f.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs470c692f-954f-4d25-b652-91b199b6fe4a.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsbf8952a9-b462-46c4-8068-727698c37d96.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsf9de2556-0f83-4f60-8a7b-30e60684680a.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs444d5f39-c4a5-454b-9109-c3ea38317147.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs76402bbb-6bcf-4aed-bb0d-087a7fd8b173.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs6922e599-81d9-4cfd-a40e-f60a5fda1003.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs4897f8e7-d48b-4d3b-b952-9ad8ba45b644.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs0ec17bec-bd3a-4f08-a64d-8692d3fc154e.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsae40614b-e178-4d94-b1d6-dbecfdfc4111.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsf5fff7d9-5762-4627-8c1f-57f8d4841bf3.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs06e84a4c-1c49-44ab-928b-bc30cf92f0a6.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs861ce9f5-7809-4faa-b68e-46b7c5b1f0eb.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69ec8282-ec39-4905-811e-1e301c3902dc.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsc5f06884-66ae-407d-846a-72a706607373.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsba9a359d-cecc-4dc5-acb6-2bddb35b68b6.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsa757a1f3-0bff-4565-aea6-5b452b616a6d.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs3f4035a2-10fe-4f9c-abab-b0d5e3de9147.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs62aa56a1-9849-411c-bf9b-48e7fb2737e2.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsa72cc987-2b02-4460-92f7-5219d0d28884.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs0c6a9778-a2fe-4f76-951a-bfc34dae6adf.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsb56c0732-7caf-4151-bf39-80333fb3422f.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscscc1685b9-7d36-4cf4-896e-51fa438259d9.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs476cb41c-1cfc-44e0-ad85-dd5e0766e6fd.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsc0b5cb9a-bd6e-42d5-94a8-bc85d0b70131.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs0335b79b-14ce-42e9-a10e-ecf697813fcf.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs9c172bc8-493c-47b5-abd4-6064fbdd1ccd.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs577d1310-681f-48f6-806f-25a52800b4b8.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs7c9fb0f7-3972-413c-acd6-450837ea2edd.tmp". The process cannot access the file because it is being used by another process
    22:53: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsb346e0c3-ab11-45bb-9ba8-cf01f923335c.tmp". The process cannot access the file because it is being used by another process
    23:01: c:\program files\media access (ID = -2147480020)
    23:06: File Sweep Complete, Elapsed Time: 00:20:07
    23:06: Full Sweep has completed. Elapsed time 00:23:05
    23:06: Traces Found: 12
    ********
    20:42: | Start of Session, 22 July 2006 |
    20:42: Spy Sweeper started
    20:46: Sent error log: C:\WINDOWS\Application Data\Webroot\Spy Sweeper\Logs\bugreport.txt
    21:10: Processing Startup Alerts
    21:10: Allowed Startup entry: MSConfigReminder
    22:42: Program Version 4.5.10 (Build 731) Using Spyware Definitions 724
    22:43: | End of Session, 22 July 2006 |
     
  15. stella45

    stella45 Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    157
    heres the latest hjt log
    it looks a little short
    it was "opened with" aol


    Logfile of HijackThis v1.99.1
    Scan saved at 22:35:30, on 22/07/2006
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\AOL SPYWARE PROTECTION\AOLSP SCHEDULER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
    C:\PROGRAM FILES\BT VOYAGER 105 ADSL MODEM\DSLSTAT.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLDIAL.EXE
    C:\PROGRAM FILES\VOYAGERTEST\FTS.EXE
    C:\PROGRAM FILES\ROXIO\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
    C:\WINDOWS\INTELSPN.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\WRSSSDK.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
    C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFAGENT.EXE
    C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
    C:\PROGRAM FILES\AOL 9.0C\WAOL.EXE
    C:\PROGRAM FILES\AOL 9.0C\SHELLMON.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\AOLTPSPD.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = aol
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.bt.net/digitaldemo
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
    O2 - BHO: PosHelp - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - C:\PROGRA~1\ADVANC~1\ADVANC~1.DLL
    O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\EBAYTB.DLL
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
    O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRAM FILES\ADVANCED SEARCHBAR\ADVANCEDSEARCHBAR.DLL
    O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\EBAYTB.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
    O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
    O4 - HKLM\..\Run: [VirusScan Online] C:\PROGRA~1\MCAFEE.COM\VSO\MCVSSHLD.EXE /disabled
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe"
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [SelahFrontPanel] C:\WINDOWS\Intelspn /B:Software\Intel\Selah
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
    O4 - HKLM\..\Run: [MSConfigReminder] C:\WINDOWS\SYSTEM\msconfig.exe /reminder
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\RunServices: [AolAcsDaemon1] "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE"
    O4 - Startup: AOL Tray Icon.lnk = C:\Program Files\AOL 9.0c\aoltray.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL/SEARCH.HTML
    O8 - Extra context menu item: &eBay Search - res://C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\eBayTb.dll/RCSearch.html
    O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
    O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
    O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
    O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRAM FILES\ADVANCED SEARCHBAR\ADVANCEDSEARCHBAR.DLL
    O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRAM FILES\ADVANCED SEARCHBAR\ADVANCEDSEARCHBAR.DLL
    O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aolsvc.co.uk/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aolsvc.co.uk/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
    O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/485153

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice