Thanks for the advise, I have run a Spy Sweeper, scan and this is the report. But I did this before I removed the 04-HKCU\..\RUN:[msnmsgr] via HJT. Which I am about to do.
22:20: | Start of Session, 07 February 2006 |
22:20: Spy Sweeper started
22:20: Sweep initiated using definitions version 611
22:21: Starting Memory Sweep
22:23: Memory Sweep Complete, Elapsed Time: 00:02:39
22:23: Starting Registry Sweep
22:23: Found Adware: deskad
22:23: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/deskadx.dll\ (2 subtraces) (ID = 124926)
22:23: HKLM\software\deskad service\ (4 subtraces) (ID = 124927)
22:23: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\deskadx.dll (ID = 124930)
22:23: Found Adware: wild media - minigolf
22:23: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/wildapp.dll\ (1 subtraces) (ID = 135051)
22:23: Found Adware: wildmedia
22:23: HKCR\interface\{851f86c9-d3cc-4574-93f5-40e2d65159e4}\ (8 subtraces) (ID = 146695)
22:23: HKLM\software\classes\interface\{851f86c9-d3cc-4574-93f5-40e2d65159e4}\ (8 subtraces) (ID = 146709)
22:23: Found Adware: security2k hijacker
22:23: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objecta\ (ID = 735573)
22:23: Found Adware: directrevenue-abetterinternet
22:23: HKLM\software\microsoft\windows\currentversion\uninstall\bsto-1\ (7 subtraces) (ID = 746835)
22:23: Found Adware: systemprocess
22:23: HKLM\software\microsoft\windows\currentversion\uninstall\startup\ (2 subtraces) (ID = 860412)
22:23: Found Trojan Horse: trojan-downloader-2pursuit
22:23: HKLM\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler\ || {1b68470c-2def-493b-8a4a-8e2d81be4ea5} (ID = 910513)
22:23: Found Adware: psguard\winhound fakealert
22:23: HKLM\software\microsoft\windows\currentversion\uninstall\security toolbar\ (2 subtraces) (ID = 1035010)
22:23: HKLM\software\microsoft\windows\currentversion\uninstall\security toolbar\ || displayname (ID = 1035011)
22:23: HKLM\software\microsoft\windows\currentversion\uninstall\security toolbar\ || uninstallstring (ID = 1035012)
22:23: Found Adware: spywarestrike
22:23: HKCR\appid\spywarestrike.exe\ (1 subtraces) (ID = 1108221)
22:23: Found Adware: spywarestrike fakealert
22:23: HKCR\clsid\{0f25878f-f8ae-5d5d-2bb7-31b5f803290d}\ (19 subtraces) (ID = 1108224)
22:23: HKCR\typelib\{c1a4c0c9-dbd0-493a-93f8-0b05edc96224}\ (9 subtraces) (ID = 1108245)
22:23: HKLM\software\classes\appid\spywarestrike.exe\ (1 subtraces) (ID = 1108258)
22:23: HKLM\software\classes\clsid\{0f25878f-f8ae-5d5d-2bb7-31b5f803290d}\ (19 subtraces) (ID = 1108261)
22:23: HKLM\software\classes\typelib\{c1a4c0c9-dbd0-493a-93f8-0b05edc96224}\ (9 subtraces) (ID = 1108292)
22:23: HKLM\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler\ || {c1a2fda2-2a5b-2c8a-f2a2-ba2db3a2c31c} (ID = 1109431)
22:23: HKLM\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler\ || {c1a2fda2-1a5b-2a8f-f3a2-b22da1a3c41d} (ID = 1109570)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-500\software\aurora\ (18 subtraces) (ID = 360174)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-500\software\system process\ (1 subtraces) (ID = 860389)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-500\software\system process\ || lastptime (ID = 860390)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1007\software\aurora\ (4 subtraces) (ID = 360174)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1007\software\system process\ (1 subtraces) (ID = 860389)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1007\software\system process\ || lastptime (ID = 860390)
22:23: Found Adware: internetoptimizer
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1006\software\avenue media\ (4 subtraces) (ID = 128887)
22:23: Found Adware: 180search assistant/zango
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1006\software\180solutions\ (8 subtraces) (ID = 135617)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1006\software\aurora\ (35 subtraces) (ID = 360174)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1006\software\microsoft\windows\currentversion\run\ || internet optimizer (ID = 818746)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1006\software\system process\ (1 subtraces) (ID = 860389)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1006\software\system process\ || lastptime (ID = 860390)
22:23: Found Adware: drsnsrch.com hijack
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1005\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1005\software\microsoft\internet explorer\main\ || search bar (ID = 128206)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1005\software\microsoft\internet explorer\main\ || search page (ID = 128207)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1005\software\microsoft\internet explorer\searchurl\ (ID = 128212)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1005\software\aurora\ (29 subtraces) (ID = 360174)
22:23: Found Adware: drsnsrch hijacker
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1005\software\dsrch\ (11 subtraces) (ID = 509156)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1005\software\system process\ (1 subtraces) (ID = 860389)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1005\software\system process\ || lastptime (ID = 860390)
22:23: HKU\S-1-5-21-583907252-1677128483-839522115-1004\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
22:23: HKU\S-1-5-21-583907252-1677128483-839522115-1004\software\dsrch\ (11 subtraces) (ID = 509156)
22:23: HKU\S-1-5-21-583907252-1677128483-839522115-1004\software\system process\ (1 subtraces) (ID = 860389)
22:23: HKU\S-1-5-21-583907252-1677128483-839522115-1004\software\system process\ || lastptime (ID = 860390)
22:23: HKU\S-1-5-21-583907252-1677128483-839522115-1004\software\classes\clsid\{c1a2fda2-2a5b-2c8a-f2a2-ba2db3a2c31c}\ (3 subtraces) (ID = 1109430)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1003\software\aurora\ (3 subtraces) (ID = 360174)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1003\software\system process\ (1 subtraces) (ID = 860389)
22:23: HKU\WRSS_Profile_S-1-5-21-583907252-1677128483-839522115-1003\software\system process\ || lastptime (ID = 860390)
22:23: Registry Sweep Complete, Elapsed Time:00:00:18
22:24: Starting Cookie Sweep
22:24: Found Spy Cookie: 2o7.net cookie
22:24:
rebecca@112.2o7[1].txt (ID = 1958)
22:24:
rebecca@122.2o7[2].txt (ID = 1958)
22:24: Found Spy Cookie: 888 cookie
22:24:
rebecca@888[1].txt (ID = 2019)
22:24: Found Spy Cookie: abetterinternet cookie
22:24:
rebecca@abetterinternet[2].txt (ID = 2035)
22:24: Found Spy Cookie: yieldmanager cookie
22:24:
rebecca@ad.yieldmanager[2].txt (ID = 3751)
22:24: Found Spy Cookie: hbmediapro cookie
22:24:
rebecca@adopt.hbmediapro[2].txt (ID = 2768)
22:24: Found Spy Cookie: specificclick.com cookie
22:24:
rebecca@adopt.specificclick[2].txt (ID = 3400)
22:24: Found Spy Cookie: directtrack cookie
22:24:
rebecca@affiliatemarketing.directtrack[2].txt (ID = 2528)
22:24: Found Spy Cookie: alt cookie
22:24:
rebecca@alt[1].txt (ID = 2217)
22:24: Found Spy Cookie: atwola cookie
22:24:
rebecca@atwola[2].txt (ID = 2255)
22:24: Found Spy Cookie: azjmp cookie
22:24:
rebecca@azjmp[2].txt (ID = 2270)
22:24: Found Spy Cookie: a cookie
22:24:
rebecca@a[1].txt (ID = 2027)
22:24:
rebecca@a[2].txt (ID = 2027)
22:24: Found Spy Cookie: belnk cookie
22:24:
rebecca@belnk[1].txt (ID = 2292)
22:24: Found Spy Cookie: btgrab cookie
22:24:
rebecca@btg.btgrab[2].txt (ID = 2333)
22:24: Found Spy Cookie: burstnet cookie
22:24:
rebecca@burstnet[2].txt (ID = 2336)
22:24: Found Spy Cookie: cliks cookie
22:24:
rebecca@cliks[1].txt (ID = 2414)
22:24:
rebecca@directtrack[1].txt (ID = 2527)
22:24:
rebecca@dist.belnk[2].txt (ID = 2293)
22:24: Found Spy Cookie: go.com cookie
22:24:
rebecca@go[1].txt (ID = 2728)
22:24: Found Spy Cookie: screensavers.com cookie
22:24:
rebecca@i.screensavers[1].txt (ID = 3298)
22:24: Found Spy Cookie: touchclarity cookie
22:24:
rebecca@msn.touchclarity[1].txt (ID = 3566)
22:24: Found Spy Cookie: mywebsearch cookie
22:24:
rebecca@mywebsearch[1].txt (ID = 3051)
22:24: Found Spy Cookie: offeroptimizer cookie
22:24:
rebecca@offeroptimizer[2].txt (ID = 3087)
22:24: Found Spy Cookie: reunion cookie
22:24:
rebecca@reunion[2].txt (ID = 3255)
22:24: Found Spy Cookie: spywarestormer cookie
22:24:
rebecca@spywarestormer[1].txt (ID = 3417)
22:24: Found Spy Cookie: reliablestats cookie
22:24:
rebecca@stats1.reliablestats[1].txt (ID = 3254)
22:24:
rebecca@vmk.disney.go[1].txt (ID = 2729)
22:24:
rebecca@www.screensavers[2].txt (ID = 3298)
22:24: big
stephen@122.2o7[1].txt (ID = 1958)
22:24: big
stephen@2o7[2].txt (ID = 1957)
22:24: Found Spy Cookie: advertising cookie
22:24: big
stephen@advertising[2].txt (ID = 2175)
22:24: big
stephen@atwola[1].txt (ID = 2255)
22:24: Found Spy Cookie: sextracker cookie
22:24: big
stephen@counter11.sextracker[1].txt (ID = 3362)
22:24: Found Spy Cookie: mediaplex cookie
22:24: big
stephen@mediaplex[1].txt (ID = 6442)
22:24: Found Spy Cookie: sexlist cookie
22:24: big
stephen@sexlist[1].txt (ID = 3353)
22:24: big
stephen@sextracker[1].txt (ID = 3361)
22:24: Found Spy Cookie: xxx69 cookie
22:24: big
stephen@www.xxx69[1].txt (ID = 3732)
22:24: Cookie Sweep Complete, Elapsed Time: 00:00:02
22:24: Starting File Sweep
22:24: Found Adware: 2search
22:24: c:\windows\system32\feeds (1 subtraces) (ID = -2147476748)
22:24: c:\program files\security toolbar (2 subtraces) (ID = -2147462697)
22:25: deskadx.dll (ID = 57857)
22:25: Found Adware: lopdotcom
22:25: seek less.exe (ID = 91)
22:27: 16 1 log balm.exe (ID = 121)
22:32: sslanguage.ini (ID = 233228)
22:40: safeoozevga.exe (ID = 90)
22:41: a0107794.exe (ID = 230687)
22:42: a0107799.lnk (ID = 230683)
22:42: uninstall.bat (ID = 202688)
22:42: 20051211200813.zip (ID = 207109)
22:42: 20051213121605.zip (ID = 207109)
22:42: 20051213215054.zip (ID = 207109)
22:44: File Sweep Complete, Elapsed Time: 00:20:29
22:44: Full Sweep has completed. Elapsed time 00:23:39
22:44: Traces Found: 327
22:45: Removal process initiated
22:45: Quarantining All Traces: 180search assistant/zango
22:45: Quarantining All Traces: directrevenue-abetterinternet
22:45: Quarantining All Traces: lopdotcom
22:45: Quarantining All Traces: psguard\winhound fakealert
22:45: Quarantining All Traces: security2k hijacker
22:45: security2k hijacker is in use. It will be removed on reboot.
22:45: uninstall.bat is in use. It will be removed on reboot.
22:45: Quarantining All Traces: wildmedia
22:45: Quarantining All Traces: 2search
22:45: Quarantining All Traces: internetoptimizer
22:45: Quarantining All Traces: trojan-downloader-2pursuit
22:45: Quarantining All Traces: deskad
22:45: Quarantining All Traces: drsnsrch hijacker
22:45: Quarantining All Traces: drsnsrch.com hijack
22:45: Quarantining All Traces: spywarestrike fakealert
22:45: Quarantining All Traces: spywarestrike
22:45: Quarantining All Traces: systemprocess
22:45: Quarantining All Traces: wild media - minigolf
22:45: Quarantining All Traces: 2o7.net cookie
22:45: Quarantining All Traces: 888 cookie
22:45: Quarantining All Traces: a cookie
22:45: Quarantining All Traces: abetterinternet cookie
22:45: Quarantining All Traces: advertising cookie
22:45: Quarantining All Traces: alt cookie
22:45: Quarantining All Traces: atwola cookie
22:45: Quarantining All Traces: azjmp cookie
22:45: Quarantining All Traces: belnk cookie
22:45: Quarantining All Traces: btgrab cookie
22:45: Quarantining All Traces: burstnet cookie
22:45: Quarantining All Traces: cliks cookie
22:45: Quarantining All Traces: directtrack cookie
22:45: Quarantining All Traces: go.com cookie
22:45: Quarantining All Traces: hbmediapro cookie
22:45: Quarantining All Traces: mediaplex cookie
22:45: Quarantining All Traces: mywebsearch cookie
22:45: Quarantining All Traces: offeroptimizer cookie
22:45: Quarantining All Traces: reliablestats cookie
22:45: Quarantining All Traces: reunion cookie
22:45: Quarantining All Traces: screensavers.com cookie
22:45: Quarantining All Traces: sexlist cookie
22:45: Quarantining All Traces: sextracker cookie
22:45: Quarantining All Traces: specificclick.com cookie
22:45: Quarantining All Traces: spywarestormer cookie
22:45: Quarantining All Traces: touchclarity cookie
22:45: Quarantining All Traces: xxx69 cookie
22:45: Quarantining All Traces: yieldmanager cookie
22:47: Removal process completed. Elapsed time 00:01:53
********
22:17: | Start of Session, 07 February 2006 |
22:17: Spy Sweeper started
22:17: Sweep initiated using definitions version 611
22:17: Starting Memory Sweep
22:18: Sweep Canceled
22:18: Memory Sweep Complete, Elapsed Time: 00:00:18
22:18: Traces Found: 0
22:20: | End of Session, 07 February 2006 |
********
22:12: | Start of Session, 07 February 2006 |
22:12: Spy Sweeper started
22:13: Your spyware definitions have been updated.
22:17: | End of Session, 07 February 2006 |