07:19 : |ˇˇˇ Start of Session, fredag, 3 september 2004 ˇˇˇ| 07:19 : Spy Sweeper 3.0.0 (Build 118) started 07:19 : Updating spyware definitions 07:19 : There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later. 07:20 : |ˇˇˇ End of Session, fredag, 3 september 2004 ˇˇˇ| 07:25 : |ˇˇˇ Start of Session, fredag, 3 september 2004 ˇˇˇ| 07:25 : Spy Sweeper 3.0.0 (Build 118) started 07:26 : Found: Memory-resident Spyware Backweb, version 1 07:26 : Found: Memory-resident Spyware Backweb, version 1 07:26 : Sweep initiated using definitions version 365 07:26 : Sweeping memory for active spyware. 07:26 : Found: Memory-resident Spyware Backweb, version 1 07:26 : Memory sweep has completed. Elapsed time 00:00:05 07:26 : Registry sweep initiated. 07:26 : Found: 9 AccessMember registry traces. 07:26 : Found: 1 Alexa Toolbar registry traces. 07:26 : Found: 742 Backweb registry traces. 07:26 : Found: 3 Bargain Buddy registry traces. 07:26 : Found: 1 CAX Proxy registry traces. 07:26 : Found: 34 Cdilla registry traces. 07:26 : Found: 9 DeltaClick registry traces. 07:26 : Found: 9 Donnamf9 registry traces. 07:26 : Found: 9 Hot as Hell registry traces. 07:26 : Found: 49 Instant Access registry traces. 07:26 : Found: 3 IstBar registry traces. 07:26 : Found: 9 MoneyTree registry traces. 07:26 : Found: 1 PowerScan registry traces. 07:26 : Found: 1 Surebar registry traces. 07:26 : Found: 9 TeenXXX (TinyBar) registry traces. 07:26 : Found: 18 TIBS Dialer registry traces. 07:26 : Registry sweep completed. Elapsed time 00:00:21 07:26 : Found: 0 file traces. 07:26 : Full Sweep has completed. Elapsed time 00:00:21 0 files swept 908 spyware traces located 07:35 : Removal process initiated 07:35 : Quarantining: AccessMember 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{c7efc431-cb29-435f-8bcd-d24b77530649} 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{c7efc431-cb29-435f-8bcd-d24b77530649}\proxystubclsid 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{c7efc431-cb29-435f-8bcd-d24b77530649}\proxystubclsid32 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{c7efc431-cb29-435f-8bcd-d24b77530649}\typelib 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{c7efc431-cb29-435f-8bcd-d24b77530649}||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{c7efc431-cb29-435f-8bcd-d24b77530649}\proxystubclsid||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{c7efc431-cb29-435f-8bcd-d24b77530649}\proxystubclsid32||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{c7efc431-cb29-435f-8bcd-d24b77530649}\typelib||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{c7efc431-cb29-435f-8bcd-d24b77530649}\typelib||version 07:35 : Quarantining: Alexa Toolbar 07:35 : Registry: HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping||{c95fe080-8f5d-11d2-a20b-00aa003c157a} 07:35 : Quarantining: Bargain Buddy 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\bargain buddy 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\bargain buddy||slowinfocache 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\bargain buddy||changed 07:35 : Quarantining: CAX Proxy 07:35 : Registry: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings||proxyserver 07:35 : Quarantining: DeltaClick 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2d5b230a-4c9b-43cb-ae84-697cfab0d6d1} 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2d5b230a-4c9b-43cb-ae84-697cfab0d6d1}\proxystubclsid 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2d5b230a-4c9b-43cb-ae84-697cfab0d6d1}\proxystubclsid32 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2d5b230a-4c9b-43cb-ae84-697cfab0d6d1}\typelib 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2d5b230a-4c9b-43cb-ae84-697cfab0d6d1}||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2d5b230a-4c9b-43cb-ae84-697cfab0d6d1}\proxystubclsid||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2d5b230a-4c9b-43cb-ae84-697cfab0d6d1}\proxystubclsid32||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2d5b230a-4c9b-43cb-ae84-697cfab0d6d1}\typelib||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2d5b230a-4c9b-43cb-ae84-697cfab0d6d1}\typelib||version 07:35 : Quarantining: Donnamf9 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff} 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid32 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\typelib 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid32||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\typelib||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\typelib||version 07:35 : Quarantining: Hot as Hell 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1} 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\proxystubclsid 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\proxystubclsid32 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\typelib 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\proxystubclsid||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\proxystubclsid32||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\typelib||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\typelib||version 07:35 : Quarantining: Instant Access 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9} 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb} 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9} 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb} 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/egdhtml_1025.dll 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/egdial.dll 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/p2ecom.dll 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls||c:\winnt\system32\egdhtml_1025.dll 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls||c:\winnt\system32\egdial.dll 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls||c:\winnt\system32\p2ecom.dll 07:35 : Registry: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\wintrust\trust providers\software publishing\trust database\0||goicfboogidikkejccmclpieicihhlpo bgdjdn 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/p2ecom.dll||.owner 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/p2ecom.dll||{cefb7b49-9652-464f-8afd-a577c0500f39} 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/egdial.dll||.owner 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/egdial.dll||{94742e3f-d9a1-4780-9a87-2ffa43655da2} 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/egdhtml_1025.dll||.owner 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/egdhtml_1025.dll||{cefb7b49-9652-464f-8afd-a577c0500f39} 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\proxystubclsid 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\proxystubclsid32 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\typelib 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}||(-default-) 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\proxystubclsid||(-default-) 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\proxystubclsid32||(-default-) 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\typelib||(-default-) 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\typelib||version 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\proxystubclsid 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\proxystubclsid32 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\typelib 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}||(-default-) 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\proxystubclsid||(-default-) 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\proxystubclsid32||(-default-) 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\typelib||(-default-) 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\typelib||version 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\proxystubclsid 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\proxystubclsid32 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\typelib 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\proxystubclsid||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\proxystubclsid32||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\typelib||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\typelib||version 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\proxystubclsid 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\proxystubclsid32 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\typelib 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\proxystubclsid||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\proxystubclsid32||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\typelib||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\typelib||version 07:35 : Quarantining: IstBar 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/istactivex.dll 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/istactivex.dll||.owner 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/istactivex.dll||{018b7ec3-eeca-11d3-8e71-0000e82c6c0d} 07:35 : Quarantining: MoneyTree 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0} 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0}\proxystubclsid 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0}\proxystubclsid32 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0}\typelib 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0}||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0}\proxystubclsid||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0}\proxystubclsid32||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0}\typelib||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0}\typelib||version 07:35 : Quarantining: PowerScan 07:35 : Registry: HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main||bandrest 07:35 : Quarantining: Surebar 07:35 : Registry: HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser||{270b845c-712c-4773-bee0-ae2d2001cd0f} 07:35 : Quarantining: TeenXXX (TinyBar) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1} 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\proxystubclsid 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\proxystubclsid32 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\typelib 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\proxystubclsid||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\proxystubclsid32||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\typelib||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\typelib||version 07:35 : Quarantining: TIBS Dialer 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff} 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{db767162-0d30-4181-9ed6-8019f6452fff} 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid32 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\typelib 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{db767162-0d30-4181-9ed6-8019f6452fff}||(-default-) 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid||(-default-) 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid32||(-default-) 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\typelib||(-default-) 07:35 : Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\typelib||version 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid32 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\typelib 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid32||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\typelib||(-default-) 07:35 : Registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\typelib||version 07:35 : Cleaning Traces 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0}\typelib|| (version) 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0}\typelib 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0}\proxystubclsid32 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0}\proxystubclsid 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{eee4a2e5-9f56-432f-a6ed-f6f625b551e0} 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\typelib|| (version) 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\typelib 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid32 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{db767162-0d30-4181-9ed6-8019f6452fff} 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{c7efc431-cb29-435f-8bcd-d24b77530649}\typelib|| (version) 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{c7efc431-cb29-435f-8bcd-d24b77530649}\typelib 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{c7efc431-cb29-435f-8bcd-d24b77530649}\proxystubclsid32 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{c7efc431-cb29-435f-8bcd-d24b77530649}\proxystubclsid 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{c7efc431-cb29-435f-8bcd-d24b77530649} 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\typelib|| (version) 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\typelib 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\proxystubclsid32 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1}\proxystubclsid 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{9388907f-82f5-434d-a941-bb802c6dd7c1} 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\typelib|| (version) 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\typelib 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\proxystubclsid32 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\proxystubclsid 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb} 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\typelib|| (version) 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\typelib 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\proxystubclsid32 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\proxystubclsid 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9} 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{2d5b230a-4c9b-43cb-ae84-697cfab0d6d1}\typelib|| (version) 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{2d5b230a-4c9b-43cb-ae84-697cfab0d6d1}\typelib 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{2d5b230a-4c9b-43cb-ae84-697cfab0d6d1}\proxystubclsid32 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{2d5b230a-4c9b-43cb-ae84-697cfab0d6d1}\proxystubclsid 07:35 : Removing registry: HKEY_CLASSES_ROOT\interface\{2d5b230a-4c9b-43cb-ae84-697cfab0d6d1} 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls|| (c:\winnt\system32\p2ecom.dll) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls|| (c:\winnt\system32\egdial.dll) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls|| (c:\winnt\system32\egdhtml_1025.dll) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/p2ecom.dll 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/p2ecom.dll|| ({cefb7b49-9652-464f-8afd-a577c0500f39}) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/p2ecom.dll|| (.owner) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/egdial.dll 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/egdial.dll|| ({94742e3f-d9a1-4780-9a87-2ffa43655da2}) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/egdial.dll|| (.owner) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/egdhtml_1025.dll 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/egdhtml_1025.dll|| ({cefb7b49-9652-464f-8afd-a577c0500f39}) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/egdhtml_1025.dll|| (.owner) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/istactivex.dll 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/istactivex.dll|| ({018b7ec3-eeca-11d3-8e71-0000e82c6c0d}) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/istactivex.dll|| (.owner) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\bargain buddy|| (slowinfocache) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\bargain buddy|| (changed) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\bargain buddy 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main|| (bandrest) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\typelib|| (version) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\typelib 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid32 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{db767162-0d30-4181-9ed6-8019f6452fff}\proxystubclsid 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{db767162-0d30-4181-9ed6-8019f6452fff} 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\typelib|| (version) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\typelib 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\proxystubclsid32 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb}\proxystubclsid 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{8f0a06f6-df4d-4d54-b8ca-e8eedbae6ddb} 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\typelib|| (version) 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\typelib 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\proxystubclsid32 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9}\proxystubclsid 07:35 : Removing registry: HKEY_LOCAL_MACHINE\software\classes\interface\{2e30ac01-99d7-4e9c-b13e-94e1701b0ac9} 07:35 : Removing registry: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\wintrust\trust providers\software publishing\trust database\0|| (goicfboogidikkejccmclpieicihhlpo bgdjdn) 07:35 : Removing registry: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings|| (proxyserver) 07:35 : Removing registry: HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser|| ({270b845c-712c-4773-bee0-ae2d2001cd0f}) 07:35 : Removing registry: HKEY_CURRENT_USER\software\microsoft\internet explorer\extensions\cmdmapping|| ({c95fe080-8f5d-11d2-a20b-00aa003c157a}) 07:35 : Removal process completed. Elapsed time 00:00:05 14 items (131 traces) quarantined. 07:35 : Deletion from quarantine initiated 07:35 : Processing: Hot as Hell 07:35 : Deletion from quarantine completed. Elapsed time 00:00:00 07:36 : Deletion from quarantine initiated 07:36 : Processing: IstBar 07:36 : Deletion from quarantine completed. Elapsed time 00:00:00 07:36 : Deletion from quarantine initiated 07:36 : Processing: Bargain Buddy 07:36 : Deletion from quarantine completed. Elapsed time 00:00:00 07:36 : Deletion from quarantine initiated 07:36 : Processing: Alexa Toolbar 07:36 : Deletion from quarantine completed. Elapsed time 00:00:00 07:37 : Sweep initiated using definitions version 365 07:37 : Sweeping memory for active spyware. 07:37 : Found: Memory-resident Spyware Backweb, version 1 07:37 : Memory sweep has completed. Elapsed time 00:00:01 07:37 : Registry sweep initiated. 07:37 : Found: 504 Backweb registry traces. 07:37 : Found: 34 Cdilla registry traces. 07:37 : Registry sweep completed. Elapsed time 00:00:04 07:37 : Full sweep on all local drives initiated. 07:37 : Now sweeping drive C: 07:38 : Found: Cdilla, version 3.02 07:38 : Found System Monitor: Cdilla, version 3.02, c:\winnt\system32\drivers\cdac15ba.sys 07:39 : Found Adware: vx2 (Transponder), version 1, c:\winnt\inf\biini.inf 07:41 : Found Adware: IstBar, version 1, c:\winnt\downloaded program files\conflict.1\istactivex.dll 07:41 : Found Adware: IstBar, version 1, c:\winnt\downloaded program files\conflict.1\istactivex.inf 07:41 : Found Adware: Sexfiles Dialers, version 1, c:\winnt\downloaded program files\information.inf 07:41 : Found Adware: Surebar, version 1, c:\winnt\downloaded program files\surebar.inf 07:41 : Found Adware: 2020Search, version 1, c:\winnt\iun6002.exe 07:43 : Found Adware: Backweb, version 1, c:\documents and settings\administrator\local settings\tempiadhide3.dll 07:44 : Found Adware: PowerScan, version 1, c:\documents and settings\andrew stone\local settings\temp\powerscan.exe 07:44 : Found Adware: Backweb, version 1, c:\documents and settings\andrew stone\local settings\tempiadhide3.dll 07:49 : Found Cookie: Com.com Cookie, version 1, c:\documents and settings\andrew stone\cookies\andrew stone@com[1].txt 07:49 : Found Cookie: 2o7.net Cookie, version 1, c:\documents and settings\andrew stone\cookies\andrew stone@112.2o7[2].txt 07:49 : Found Cookie: Virtual Vegas Cookie, version 1, c:\documents and settings\andrew stone\cookies\andrew stone@www.virtualvegas[2].txt 07:49 : Found Cookie: SMNI Cookie, version 1, c:\documents and settings\andrew stone\cookies\andrew stone@smni[1].txt 07:49 : Found Cookie: l2m.net Cookie, version 1, c:\documents and settings\andrew stone\cookies\andrew stone@l2m[1].txt 07:49 : Found Cookie: BannerSpace Cookie, version 1, c:\documents and settings\andrew stone\cookies\andrew stone@bannerspace[2].txt 07:49 : Found Cookie: Passport Cookie, version 1, c:\documents and settings\andrew stone\cookies\andrew stone@passport[2].txt 07:49 : Found Cookie: Passport Cookie, version 1, c:\documents and settings\andrew stone\cookies\nya\andrew stone@passport[1].txt 07:49 : Found Cookie: Passport Cookie, version 1, c:\documents and settings\andrew stone\cookies\andrew stone@passport[5].txt 07:49 : Found Cookie: NetRatingsSelect Cookie, version 1, c:\documents and settings\andrew stone\cookies\andrew stone@nnselect[2].txt 07:49 : Found Cookie: l2m.net Cookie, version 1, c:\documents and settings\andrew stone\cookies\andrew stone@28929374a.l2m[2].txt 07:49 : Found Cookie: Mircx Cookie, version 1, c:\documents and settings\andrew stone\cookies\andrew stone@pop.mircx[1].txt 07:49 : Found System Monitor: Cdilla, version 3.02, c:\program files\common files\macrovision shared\safecast\install\cdac14ba.dll 07:49 : Found System Monitor: Cdilla, version 3.02, c:\program files\common files\macrovision shared\safecast\install\cdac13ba.exe 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\initdata\data\genflash\1\gen.bif 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\initdata\data\genflash\1\gen.bis 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\initdata\data\genflash\1\info.iad 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\initdata\data\browser.htm 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\initdata\data\cert.db 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\initdata\data\infocenter.htm 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\6.1.4.37-7288971l\program\loading.htm 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\6.1.4.37-7288971l\program\pacsupport.js 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\6.1.4.37-7288971l\program\bwmib.dll 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\bw_install.log 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\users\default\data\genflash\1\gen.bif 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\users\default\data\genflash\1\gen.bis 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\users\default\data\genflash\1\info.iad 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\users\default\data\browser.htm 07:51 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\users\default\data\infocenter.htm 07:53 : Found System Monitor: Cdilla, version 3.02, c:\program files\autodesk architectural desktop 2004\cdac14ba.dll 07:53 : Found: Instant Access, version 1 08:00 : Found: 45 file traces. 08:00 : Full Sweep has completed. Elapsed time 00:22:37 116 910 files swept 580 spyware traces located 08:04 : Removal process initiated 08:04 : Quarantining: Com.com Cookie 08:04 : Cookie: c:\documents and settings\andrew stone\cookies\andrew stone@com[1].txt 08:04 : Quarantining: Instant Access 08:04 : Folder: c:\program files\instant access 08:04 : Quarantining: IstBar 08:04 : File: c:\winnt\downloaded program files\conflict.1\istactivex.dll 08:04 : File: c:\winnt\downloaded program files\conflict.1\istactivex.inf 08:04 : Quarantining: l2m.net Cookie 08:04 : Cookie: c:\documents and settings\andrew stone\cookies\andrew stone@l2m[1].txt 08:04 : Cookie: c:\documents and settings\andrew stone\cookies\andrew stone@28929374a.l2m[2].txt 08:04 : Quarantining: Mircx Cookie 08:04 : Cookie: c:\documents and settings\andrew stone\cookies\andrew stone@pop.mircx[1].txt 08:04 : Quarantining: NetRatingsSelect Cookie 08:04 : Cookie: c:\documents and settings\andrew stone\cookies\andrew stone@nnselect[2].txt 08:04 : Quarantining: Passport Cookie 08:04 : Cookie: c:\documents and settings\andrew stone\cookies\andrew stone@passport[2].txt 08:04 : Cookie: c:\documents and settings\andrew stone\cookies\nya\andrew stone@passport[1].txt 08:04 : Cookie: c:\documents and settings\andrew stone\cookies\andrew stone@passport[5].txt 08:04 : Quarantining: PowerScan 08:04 : File: c:\documents and settings\andrew stone\local settings\temp\powerscan.exe 08:04 : Quarantining: Sexfiles Dialers 08:04 : File: c:\winnt\downloaded program files\information.inf 08:04 : Quarantining: SMNI Cookie 08:04 : Cookie: c:\documents and settings\andrew stone\cookies\andrew stone@smni[1].txt 08:04 : Quarantining: Surebar 08:04 : File: c:\winnt\downloaded program files\surebar.inf 08:04 : Quarantining: Virtual Vegas Cookie 08:04 : Cookie: c:\documents and settings\andrew stone\cookies\andrew stone@www.virtualvegas[2].txt 08:04 : Quarantining: vx2 (Transponder) 08:04 : File: c:\winnt\inf\biini.inf 08:04 : Cleaning Traces 08:04 : Removing file: c:\winnt\inf\biini.inf 08:04 : Removing file: c:\documents and settings\andrew stone\cookies\andrew stone@www.virtualvegas[2].txt 08:04 : Removing file: c:\winnt\downloaded program files\surebar.inf 08:04 : Removing file: c:\documents and settings\andrew stone\cookies\andrew stone@smni[1].txt 08:04 : Removing file: c:\winnt\downloaded program files\information.inf 08:04 : Removing file: c:\documents and settings\andrew stone\local settings\temp\powerscan.exe 08:04 : Removing file: c:\documents and settings\andrew stone\cookies\andrew stone@passport[5].txt 08:04 : Removing file: c:\documents and settings\andrew stone\cookies\nya\andrew stone@passport[1].txt 08:04 : Removing file: c:\documents and settings\andrew stone\cookies\andrew stone@passport[2].txt 08:04 : Removing file: c:\documents and settings\andrew stone\cookies\andrew stone@nnselect[2].txt 08:04 : Removing file: c:\documents and settings\andrew stone\cookies\andrew stone@pop.mircx[1].txt 08:04 : Removing file: c:\documents and settings\andrew stone\cookies\andrew stone@28929374a.l2m[2].txt 08:04 : Removing file: c:\documents and settings\andrew stone\cookies\andrew stone@l2m[1].txt 08:04 : Removing file: c:\winnt\downloaded program files\conflict.1\istactivex.inf 08:04 : Removing file: c:\winnt\downloaded program files\conflict.1\istactivex.dll 08:04 : Removing file: c:\documents and settings\andrew stone\cookies\andrew stone@com[1].txt 08:04 : Folder: c:\program files\instant access 08:04 : Removal process completed. Elapsed time 00:00:00 13 items (17 traces) quarantined. 08:05 : Deletion from quarantine initiated 08:05 : Processing: Sexfiles Dialers 08:05 : Deletion from quarantine completed. Elapsed time 00:00:00 08:05 : Deletion from quarantine initiated 08:05 : Processing: IstBar 08:05 : Deletion from quarantine completed. Elapsed time 00:00:00 08:05 : Deletion from quarantine initiated 08:05 : Processing: Com.com Cookie 08:05 : Deletion from quarantine completed. Elapsed time 00:00:00 08:06 : Deletion from quarantine initiated 08:06 : Processing: vx2 (Transponder) 08:06 : Deletion from quarantine completed. Elapsed time 00:00:00 08:07 : |ˇˇˇ End of Session, fredag, 3 september 2004 ˇˇˇ| 10:16 : |ˇˇˇ Start of Session, lördag, 4 september 2004 ˇˇˇ| 10:16 : Spy Sweeper 3.0.0 (Build 118) started 10:17 : Found: Memory-resident Spyware Backweb, version 1 11:43 : Sweep initiated using definitions version 365 11:43 : Sweeping memory for active spyware. 11:43 : Found: Memory-resident Spyware Backweb, version 1 11:43 : Memory sweep has completed. Elapsed time 00:00:03 11:43 : Registry sweep initiated. 11:43 : Found: 754 Backweb registry traces. 11:43 : Found: 34 Cdilla registry traces. 11:43 : Registry sweep completed. Elapsed time 00:00:06 11:43 : Full sweep on all local drives initiated. 11:43 : Now sweeping drive C: 11:44 : Found: Cdilla, version 3.02 11:44 : Found System Monitor: Cdilla, version 3.02, c:\winnt\system32\drivers\cdac15ba.sys 11:49 : Found Adware: 2020Search, version 1, c:\winnt\iun6002.exe 11:52 : Found Adware: Backweb, version 1, c:\documents and settings\administrator\local settings\tempiadhide3.dll 11:54 : Found Adware: Backweb, version 1, c:\documents and settings\andrew stone\local settings\tempiadhide3.dll 12:02 : Found Cookie: 2o7.net Cookie, version 1, c:\documents and settings\andrew stone\cookies\andrew stone@112.2o7[2].txt 12:02 : Found Cookie: BannerSpace Cookie, version 1, c:\documents and settings\andrew stone\cookies\andrew stone@bannerspace[2].txt 12:02 : Found System Monitor: Cdilla, version 3.02, c:\program files\common files\macrovision shared\safecast\install\cdac14ba.dll 12:02 : Found System Monitor: Cdilla, version 3.02, c:\program files\common files\macrovision shared\safecast\install\cdac13ba.exe 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\initdata\data\genflash\1\gen.bif 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\initdata\data\genflash\1\gen.bis 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\initdata\data\genflash\1\info.iad 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\initdata\data\browser.htm 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\initdata\data\cert.db 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\initdata\data\infocenter.htm 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\6.1.4.37-7288971l\program\loading.htm 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\6.1.4.37-7288971l\program\pacsupport.js 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\6.1.4.37-7288971l\program\bwmib.dll 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\bw_install.log 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\users\default\data\genflash\1\gen.bif 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\users\default\data\genflash\1\gen.bis 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\users\default\data\genflash\1\info.iad 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\users\default\data\browser.htm 12:07 : Found Adware: Backweb, version 1, c:\program files\kodak\kodak software updater\7288971\users\default\data\infocenter.htm 12:08 : Found System Monitor: Cdilla, version 3.02, c:\program files\autodesk architectural desktop 2004\cdac14ba.dll 12:21 : Found: 28 file traces. 12:21 : Full Sweep has completed. Elapsed time 00:37:58 116 935 files swept 813 spyware traces located