spysweeper log
********
3:28 PM: |··· Start of Session, Wednesday, August 10, 2005 ···|
3:28 PM: Spy Sweeper started
3:28 PM: Sweep initiated using definitions version 512
3:28 PM: Starting Memory Sweep
3:31 PM: Memory Sweep Complete, Elapsed Time: 00:02:53
3:31 PM: Starting Registry Sweep
3:31 PM: Found Adware: icannnews
3:31 PM: HKCR\activexctrl\ (3 subtraces) (ID = 169450)
3:31 PM: HKCR\clsid\{3bfadce2-1141-4b81-8878-49af625f0fdc}\ (3 subtraces) (ID = 169451)
3:31 PM: HKCR\interface\{980ad470-04ea-4d1d-bd26-e178b7bda6d8}\ (8 subtraces) (ID = 169454)
3:31 PM: HKCR\interface\{fd39937a-c583-4aac-9332-8a3e44988a67}\ (8 subtraces) (ID = 169455)
3:31 PM: HKCR\typelib\{ee5ac3d6-6f43-4047-af0a-d66fc2cf8f42}\ (9 subtraces) (ID = 169456)
3:31 PM: HKLM\software\classes\activexctrl\ (3 subtraces) (ID = 169457)
3:31 PM: HKLM\software\classes\clsid\{3bfadce2-1141-4b81-8878-49af625f0fdc}\ (3 subtraces) (ID = 169458)
3:31 PM: HKLM\software\classes\interface\{980ad470-04ea-4d1d-bd26-e178b7bda6d8}\ (8 subtraces) (ID = 169461)
3:31 PM: HKLM\software\classes\interface\{fd39937a-c583-4aac-9332-8a3e44988a67}\ (8 subtraces) (ID = 169462)
3:31 PM: HKLM\software\classes\typelib\{ee5ac3d6-6f43-4047-af0a-d66fc2cf8f42}\ (9 subtraces) (ID = 169463)
3:31 PM: Registry Sweep Complete, Elapsed Time:00:00:29
3:31 PM: Starting Cookie Sweep
3:31 PM: Found Spy Cookie: belnk cookie
3:31 PM: user@belnk[1].txt (ID = 2292)
3:31 PM:
[email protected][2].txt (ID = 2293)
3:31 PM: Found Spy Cookie: questionmarket cookie
3:31 PM: user@questionmarket[1].txt (ID = 3217)
3:31 PM: Found Spy Cookie: 2o7.net cookie
3:31 PM: user@2o7[1].txt (ID = 1957)
3:31 PM: Found Spy Cookie: centrport net cookie
3:31 PM: user@centrport[2].txt (ID = 2374)
3:31 PM: Found Spy Cookie: go.com cookie
3:31 PM:
[email protected][2].txt (ID = 2729)
3:31 PM: user@go[1].txt (ID = 2728)
3:31 PM:
[email protected][1].txt (ID = 2729)
3:31 PM:
[email protected][2].txt (ID = 2729)
3:31 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
3:31 PM: Starting File Sweep
3:31 PM: Warning: Failed to open file "c:\pagefile.sys". Access is denied
3:31 PM: Warning: Failed to open file "c:\hiberfil.sys". Access is denied
3:32 PM: Warning: Failed to open file "c:\windows\system32\config\system.log". The process cannot access the file because it is being used by another process
3:32 PM: Warning: Failed to open file "c:\windows\system32\config\software.log". The process cannot access the file because it is being used by another process
3:32 PM: Warning: Failed to open file "c:\windows\system32\config\default.log". The process cannot access the file because it is being used by another process
3:32 PM: Warning: Failed to open file "c:\windows\system32\config\security". The process cannot access the file because it is being used by another process
3:32 PM: Warning: Failed to open file "c:\windows\system32\config\sam". The process cannot access the file because it is being used by another process
3:32 PM: Warning: Failed to open file "c:\windows\system32\config\sam.log". The process cannot access the file because it is being used by another process
3:32 PM: Warning: Failed to open file "c:\windows\system32\config\security.log". The process cannot access the file because it is being used by another process
3:32 PM: Warning: Failed to open file "c:\windows\system32\config\system". The process cannot access the file because it is being used by another process
3:32 PM: Warning: Failed to open file "c:\windows\system32\config\software". The process cannot access the file because it is being used by another process
3:32 PM: Warning: Failed to open file "c:\windows\system32\config\default". The process cannot access the file because it is being used by another process
3:34 PM: Warning: Failed to open file "c:\windows\softwaredistribution\eventcache\{49fa30b4-c0c1-4de0-9e4c-72d20a6b5256}.bin". The process cannot access the file because it is being used by another process
3:35 PM: Found Adware: bargain buddy
3:35 PM: setup.inf (ID = 50870)
3:35 PM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat". The process cannot access the file because it is being used by another process
3:35 PM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
3:35 PM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
3:35 PM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
3:35 PM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat". The process cannot access the file because it is being used by another process
3:35 PM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
3:35 PM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
3:35 PM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
3:35 PM: Warning: Failed to open file "c:\documents and settings\user\ntuser.dat". The process cannot access the file because it is being used by another process
3:35 PM: Warning: Failed to open file "c:\documents and settings\user\ntuser.dat.log". The process cannot access the file because it is being used by another process
3:35 PM: Warning: Failed to open file "c:\documents and settings\user\local settings\temp\perflib_perfdata_640.dat". The process cannot access the file because it is being used by another process
3:35 PM: Warning: Failed to open file "c:\documents and settings\user\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
3:35 PM: Warning: Failed to open file "c:\documents and settings\user\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
3:36 PM: Warning: Failed to open file "c:\program files\common files\symantec shared\ccpd-lc\symlcrst.dll". The process cannot access the file because it is being used by another process
3:43 PM: Found Adware: powerscan
3:43 PM: power scan.lnk (ID = 72676)
3:43 PM: Found Adware: ipinsight
3:43 PM: conscorr.inf (ID = 64277)
3:43 PM: Found Adware: abetterinternet
3:43 PM: localnrd.inf (ID = 83368)
3:47 PM: File Sweep Complete, Elapsed Time: 00:15:40
3:47 PM: Full Sweep has completed. Elapsed time 00:19:09
3:47 PM: Traces Found: 85
3:57 PM: Removal process initiated
3:58 PM: Quarantining All Traces: icannnews
3:58 PM: Quarantining All Traces: belnk cookie
3:58 PM: Quarantining All Traces: questionmarket cookie
3:58 PM: Quarantining All Traces: 2o7.net cookie
3:58 PM: Quarantining All Traces: centrport net cookie
3:58 PM: Quarantining All Traces: go.com cookie
3:58 PM: Quarantining All Traces: bargain buddy
3:58 PM: Quarantining All Traces: powerscan
3:58 PM: Quarantining All Traces: ipinsight
3:58 PM: Quarantining All Traces: abetterinternet
3:58 PM: Removal process completed. Elapsed time 00:00:10
********
3:26 PM: |··· Start of Session, Wednesday, August 10, 2005 ···|
3:26 PM: Spy Sweeper started
3:28 PM: |··· End of Session, Wednesday, August 10, 2005 ···|