Hey UKBiker, i did what you said. When i went into the session log on spysweeper, it shows all the logs that it has done but i dont really see the one i just completed. Ill post the entire thing at the bottom of this below the HJT log, but i dont know if you really need any of it. I havnt gotten a pop-up yet since i logged on to here to post this message so thats awesome! I may be clean or almost cleaned! Thanks so much thus far. Oh, and by the way, my computer has randomly shut down twice (once shut down, once restarted) out of nowhere. I dont know if that has to do with stuff ive been doing or whatever, but it hasnt ever done that before. Im not worried about it, but just incase you needed to know. Anyway, here are the logs...
Logfile of HijackThis v1.99.1
Scan saved at 11:32:44 PM, on 8/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HiJackTHis\HijackThis.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} -
http://www.icannnews.../ST/ActiveX.ocxO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft...free/asinst.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} -
http://winfixer.com/...nnerInstall.cabO23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Cadence License Manager - GLOBEtrotter Software Inc. - C:\OrCAD\license_manager\lmgrd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
And now the extremely long log of spy sweeper (all logs put in one, sorry)
********
10:52 AM: |··· Start of Session, Sunday, August 07, 2005 ···|
10:52 AM: Spy Sweeper started
10:52 AM: Sweep initiated using definitions version 511
10:52 AM: Starting Memory Sweep
10:52 AM: Warning: Failed to check file "C:\WINDOWS\system32\newrszht.dll". Cannot open file "C:\WINDOWS\system32\newrszht.dll". The process cannot access the file because it is being used by another process
10:52 AM: Found Adware: icannnews
10:52 AM: Detected running threat: C:\WINDOWS\system32\newrszht.dll (ID = 51)
10:52 AM: Warning: Failed to check file "C:\WINDOWS\system32\pxlstore.dll". Cannot open file "C:\WINDOWS\system32\pxlstore.dll". The process cannot access the file because it is being used by another process
10:52 AM: Detected running threat: C:\WINDOWS\system32\pxlstore.dll (ID = 51)
10:54 AM: Warning: Failed to check file "C:\WINDOWS\system32\newrszht.dll". Cannot open file "C:\WINDOWS\system32\newrszht.dll". The process cannot access the file because it is being used by another process
10:56 AM: Memory Sweep Complete, Elapsed Time: 00:03:59
10:56 AM: Starting Registry Sweep
10:56 AM: Found Adware: addestroyer
10:56 AM: HKCR\clsid\{d52433a9-a44c-43ab-a013-24b3c756dd2b}\ (13 subtraces) (ID = 102729)
10:56 AM: HKLM\software\classes\clsid\{d52433a9-a44c-43ab-a013-24b3c756dd2b}\ (13 subtraces) (ID = 102738)
10:56 AM: Found Adware: apropos
10:56 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\aprps\ (7 subtraces) (ID = 103740)
10:56 AM: HKLM\software\aprps\ (8 subtraces) (ID = 103741)
10:56 AM: Found Adware: begin2search
10:56 AM: HKCR\btnetw.amo.1\ (3 subtraces) (ID = 104095)
10:56 AM: Found Adware: hotsearchbar toolbar
10:56 AM: HKCR\btnetw.amo\ (5 subtraces) (ID = 104096)
10:56 AM: HKCR\btnetw.amo\ (5 subtraces) (ID = 104096)
10:56 AM: HKCR\btnetw.iiittt.1\ (3 subtraces) (ID = 104097)
10:56 AM: HKCR\btnetw.iiittt\ (5 subtraces) (ID = 104098)
10:56 AM: HKCR\btnetw.iiittt\ (5 subtraces) (ID = 104098)
10:56 AM: HKCR\btnetw.momo.1\ (3 subtraces) (ID = 104099)
10:56 AM: HKCR\btnetw.momo\ (5 subtraces) (ID = 104100)
10:56 AM: HKCR\btnetw.momo\ (5 subtraces) (ID = 104100)
10:56 AM: HKCR\btnetw.ohb.1\ (3 subtraces) (ID = 104101)
10:56 AM: HKCR\btnetw.ohb\ (5 subtraces) (ID = 104102)
10:56 AM: HKCR\btnetw.ohb\ (5 subtraces) (ID = 104102)
10:56 AM: HKCR\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 104109)
10:56 AM: HKCR\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 104109)
10:56 AM: HKCR\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 104118)
10:56 AM: HKCR\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 104118)
10:56 AM: HKCR\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 104119)
10:56 AM: HKCR\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 104119)
10:56 AM: HKCR\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 104120)
10:56 AM: HKCR\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 104120)
10:56 AM: HKCR\interface\{6b882c34-a832-4f5b-bef1-7e198be3f094}\ (8 subtraces) (ID = 104124)
10:56 AM: HKCR\interface\{9b6b4031-1d6d-4c65-acba-021916853822}\ (8 subtraces) (ID = 104126)
10:56 AM: HKCR\interface\{9ff60a27-0c0c-4a6a-a15f-b21b644d67bb}\ (8 subtraces) (ID = 104127)
10:56 AM: HKCR\interface\{15d53b86-e055-43b1-bbee-a91a0f37bd2a}\ (8 subtraces) (ID = 104128)
10:56 AM: HKCR\interface\{f3c41c1d-22f1-4692-8a7a-88de70a2e9e2}\ (8 subtraces) (ID = 104139)
10:56 AM: HKCR\interface\{fa6fa7a5-2c49-4567-ba74-6dd1c36099ee}\ (8 subtraces) (ID = 104141)
10:56 AM: HKLM\software\classes\btnetw.amo.1\ (3 subtraces) (ID = 104145)
10:56 AM: HKLM\software\classes\btnetw.amo\ (5 subtraces) (ID = 104146)
10:56 AM: HKLM\software\classes\btnetw.amo\ (5 subtraces) (ID = 104146)
10:56 AM: HKLM\software\classes\btnetw.iiittt.1\ (3 subtraces) (ID = 104147)
10:56 AM: HKLM\software\classes\btnetw.iiittt\ (5 subtraces) (ID = 104148)
10:56 AM: HKLM\software\classes\btnetw.iiittt\ (5 subtraces) (ID = 104148)
10:56 AM: HKLM\software\classes\btnetw.momo.1\ (3 subtraces) (ID = 104149)
10:56 AM: HKLM\software\classes\btnetw.momo\ (5 subtraces) (ID = 104150)
10:56 AM: HKLM\software\classes\btnetw.momo\ (5 subtraces) (ID = 104150)
10:56 AM: HKLM\software\classes\btnetw.ohb.1\ (3 subtraces) (ID = 104151)
10:56 AM: HKLM\software\classes\btnetw.ohb\ (5 subtraces) (ID = 104152)
10:56 AM: HKLM\software\classes\btnetw.ohb\ (5 subtraces) (ID = 104152)
10:56 AM: HKLM\software\classes\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 104159)
10:56 AM: HKLM\software\classes\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 104159)
10:56 AM: HKLM\software\classes\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 104168)
10:56 AM: HKLM\software\classes\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 104168)
10:56 AM: HKLM\software\classes\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 104169)
10:56 AM: HKLM\software\classes\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 104169)
10:56 AM: HKLM\software\classes\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 104170)
10:56 AM: HKLM\software\classes\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 104170)
10:56 AM: HKLM\software\classes\interface\{6b882c34-a832-4f5b-bef1-7e198be3f094}\ (8 subtraces) (ID = 104174)
10:56 AM: HKLM\software\classes\interface\{9b6b4031-1d6d-4c65-acba-021916853822}\ (8 subtraces) (ID = 104176)
10:56 AM: HKLM\software\classes\interface\{9ff60a27-0c0c-4a6a-a15f-b21b644d67bb}\ (8 subtraces) (ID = 104177)
10:56 AM: HKLM\software\classes\interface\{15d53b86-e055-43b1-bbee-a91a0f37bd2a}\ (8 subtraces) (ID = 104178)
10:56 AM: HKLM\software\classes\interface\{f3c41c1d-22f1-4692-8a7a-88de70a2e9e2}\ (8 subtraces) (ID = 104189)
10:56 AM: HKLM\software\classes\interface\{fa6fa7a5-2c49-4567-ba74-6dd1c36099ee}\ (8 subtraces) (ID = 104191)
10:56 AM: HKLM\software\classes\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 104195)
10:56 AM: HKLM\software\classes\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 104195)
10:56 AM: HKCR\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 104238)
10:56 AM: HKCR\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 104238)
10:56 AM: Found Adware: bookedspace
10:56 AM: HKLM\software\configuration manager\cfgmgr52\ (368 subtraces) (ID = 104873)
10:56 AM: Found Adware: browseraid
10:56 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\a70f6a1d-0195-42a2-934c-d8ac0f7c08eb\ (1 subtraces) (ID = 105078)
10:56 AM: Found Adware: cas
10:56 AM: HKCR\clsid\{8293d547-38dd-4325-b35a-f1817edfa5fc}\ (11 subtraces) (ID = 105365)
10:56 AM: HKCR\typelib\{d4c89c18-b4f3-46a9-8800-e9e7a55afbd9}\ (9 subtraces) (ID = 105366)
10:56 AM: HKLM\software\classes\clsid\{8293d547-38dd-4325-b35a-f1817edfa5fc}\ (11 subtraces) (ID = 105368)
10:56 AM: HKLM\software\classes\typelib\{d4c89c18-b4f3-46a9-8800-e9e7a55afbd9}\ (9 subtraces) (ID = 105369)
10:56 AM: Found Adware: clearsearch
10:56 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\microsoft\internet explorer\new windows\allow\ || 69.28.210.175 (ID = 105744)
10:56 AM: Found Adware: cws-aboutblank
10:56 AM: HKCR\protocols\filter\text/html\ (2 subtraces) (ID = 114343)
10:56 AM: HKLM\software\classes\protocols\filter\text/html\ (2 subtraces) (ID = 115907)
10:56 AM: Found Adware: delfin
10:56 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\mvu\ (5 subtraces) (ID = 124884)
10:56 AM: HKLM\software\vidctrl\ (3 subtraces) (ID = 124897)
10:56 AM: Found Adware: ieplugin
10:56 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\intexp\ (10 subtraces) (ID = 128173)
10:56 AM: Found Adware: drsnsrch.com hijack
10:56 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
10:56 AM: Found Adware: redzip toolbar
10:56 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\microsoft\windows\currentversion\explorer\ || insid (ID = 139328)
10:56 AM: Found Adware: screensavers
10:56 AM: HKCR\clsid\{722d2939-a14a-41a9-9eac-ab8f4e295819}\ (14 subtraces) (ID = 140550)
10:56 AM: HKCR\clsid\{88d758a3-d33b-45fd-91e3-67749b4057fa}\ (14 subtraces) (ID = 140551)
10:56 AM: HKCR\interface\{760aca60-79c3-4875-9d19-b14a5b3fea77}\ (8 subtraces) (ID = 140552)
10:56 AM: HKCR\interface\{883ea659-ed80-46f9-9ed2-83327f67789f}\ (8 subtraces) (ID = 140553)
10:56 AM: HKCR\interface\{b64c73d7-459e-4816-91f9-1348f8e36984}\ (8 subtraces) (ID = 140554)
10:56 AM: HKLM\software\classes\clsid\{722d2939-a14a-41a9-9eac-ab8f4e295819}\ (14 subtraces) (ID = 140555)
10:56 AM: HKLM\software\classes\clsid\{88d758a3-d33b-45fd-91e3-67749b4057fa}\ (14 subtraces) (ID = 140556)
10:56 AM: HKLM\software\classes\interface\{760aca60-79c3-4875-9d19-b14a5b3fea77}\ (8 subtraces) (ID = 140557)
10:56 AM: HKLM\software\classes\interface\{883ea659-ed80-46f9-9ed2-83327f67789f}\ (8 subtraces) (ID = 140558)
10:56 AM: HKLM\software\classes\interface\{b64c73d7-459e-4816-91f9-1348f8e36984}\ (8 subtraces) (ID = 140559)
10:56 AM: HKLM\software\classes\screensaversinstaller.installer.1\ (3 subtraces) (ID = 140560)
10:56 AM: HKLM\software\classes\screensaversinstaller.installer\ (5 subtraces) (ID = 140561)
10:56 AM: HKLM\software\classes\screensaversinstaller.sinstaller.1\ (3 subtraces) (ID = 140562)
10:56 AM: HKLM\software\classes\screensaversinstaller.sinstaller.1\clsid\ (1 subtraces) (ID = 140563)
10:56 AM: HKLM\software\classes\screensaversinstaller.sinstaller\ (5 subtraces) (ID = 140564)
10:56 AM: HKLM\software\classes\typelib\{0ab5b0d8-2b74-4c1c-8fa4-e52550b8b45b}\ (9 subtraces) (ID = 140565)
10:56 AM: HKLM\software\microsoft\code store database\distribution units\{88d758a3-d33b-45fd-91e3-67749b4057fa}\ (9 subtraces) (ID = 140566)
10:56 AM: HKLM\software\screensavers.com\ (14 subtraces) (ID = 140569)
10:56 AM: HKCR\screensaversinstaller.installer.1\ (3 subtraces) (ID = 140570)
10:56 AM: HKCR\screensaversinstaller.installer\ (5 subtraces) (ID = 140571)
10:56 AM: HKCR\screensaversinstaller.sinstaller.1\ (3 subtraces) (ID = 140572)
10:56 AM: HKCR\screensaversinstaller.sinstaller.1\clsid\ (1 subtraces) (ID = 140573)
10:56 AM: HKCR\screensaversinstaller.sinstaller\ (5 subtraces) (ID = 140574)
10:56 AM: HKCR\typelib\{0ab5b0d8-2b74-4c1c-8fa4-e52550b8b45b}\ (9 subtraces) (ID = 140575)
10:56 AM: Found Adware: searchtoolbar
10:56 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\{12ee7a5e-0674-42f9-a76b-000000004d00}\ (3 subtraces) (ID = 141347)
10:56 AM: Found Adware: visfx
10:56 AM: HKLM\software\microsoft\windows\currentversion\uninstall\visfx\ (2 subtraces) (ID = 145734)
10:56 AM: HKCR\activexctrl\ (3 subtraces) (ID = 169450)
10:56 AM: HKCR\clsid\{3bfadce2-1141-4b81-8878-49af625f0fdc}\ (3 subtraces) (ID = 169451)
10:56 AM: HKCR\clsid\{4208fb4d-4e53-4f5a-bf7a-3e047ddb5281}\ (21 subtraces) (ID = 169452)
10:56 AM: HKCR\interface\{980ad470-04ea-4d1d-bd26-e178b7bda6d8}\ (8 subtraces) (ID = 169454)
10:56 AM: HKCR\interface\{fd39937a-c583-4aac-9332-8a3e44988a67}\ (8 subtraces) (ID = 169455)
10:56 AM: HKCR\typelib\{ee5ac3d6-6f43-4047-af0a-d66fc2cf8f42}\ (9 subtraces) (ID = 169456)
10:56 AM: HKLM\software\classes\activexctrl\ (3 subtraces) (ID = 169457)
10:56 AM: HKLM\software\classes\clsid\{3bfadce2-1141-4b81-8878-49af625f0fdc}\ (3 subtraces) (ID = 169458)
10:56 AM: HKLM\software\classes\clsid\{4208fb4d-4e53-4f5a-bf7a-3e047ddb5281}\ (21 subtraces) (ID = 169459)
10:56 AM: HKLM\software\classes\interface\{980ad470-04ea-4d1d-bd26-e178b7bda6d8}\ (8 subtraces) (ID = 169461)
10:56 AM: HKLM\software\classes\interface\{fd39937a-c583-4aac-9332-8a3e44988a67}\ (8 subtraces) (ID = 169462)
10:56 AM: HKLM\software\classes\typelib\{ee5ac3d6-6f43-4047-af0a-d66fc2cf8f42}\ (9 subtraces) (ID = 169463)
10:56 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\cas\client\ (1 subtraces) (ID = 359309)
10:56 AM: Found Adware: personal money tree
10:56 AM: HKCR\clsid\{d1a3a43b-05a1-40cd-834c-053e6c03b258}\ (7 subtraces) (ID = 359438)
10:56 AM: HKCR\comparishopper.application\ (3 subtraces) (ID = 359439)
10:56 AM: HKLM\software\classes\clsid\{d1a3a43b-05a1-40cd-834c-053e6c03b258}\ (7 subtraces) (ID = 359441)
10:56 AM: HKLM\software\classes\comparishopper.application\ (3 subtraces) (ID = 359442)
10:56 AM: Found Adware: shopnavupdater
10:56 AM: HKCR\clsid\{00027925-0017-4faf-9539-90e4ac0b9ec5}\ (11 subtraces) (ID = 359486)
10:56 AM: HKCR\clsid\{5e0910c6-9e45-481c-a2ec-0ec29c96ebeb}\ (11 subtraces) (ID = 359487)
10:56 AM: HKCR\clsid\{8f7d96aa-489a-4194-ab34-21ef42507932}\ (13 subtraces) (ID = 359488)
10:56 AM: HKCR\clsid\{79406f24-8e95-4af8-9fef-2ea2b504e707}\ (13 subtraces) (ID = 359489)
10:56 AM: HKCR\clsid\{b424e2aa-4466-41ca-8194-5a83995a9b15}\ (11 subtraces) (ID = 359490)
10:56 AM: HKCR\snb.band\ (5 subtraces) (ID = 359491)
10:56 AM: HKCR\sntb.bottomframe\ (5 subtraces) (ID = 359492)
10:56 AM: HKCR\sntb.leftframe\ (5 subtraces) (ID = 359493)
10:56 AM: HKCR\sntb.popupbrowser\ (5 subtraces) (ID = 359494)
10:56 AM: HKCR\sntb.popupwindow\ (5 subtraces) (ID = 359495)
10:56 AM: HKLM\software\classes\clsid\{00027925-0017-4faf-9539-90e4ac0b9ec5}\ (11 subtraces) (ID = 359496)
10:56 AM: HKLM\software\classes\clsid\{5e0910c6-9e45-481c-a2ec-0ec29c96ebeb}\ (11 subtraces) (ID = 359497)
10:56 AM: HKLM\software\classes\clsid\{8f7d96aa-489a-4194-ab34-21ef42507932}\ (13 subtraces) (ID = 359498)
10:56 AM: HKLM\software\classes\clsid\{79406f24-8e95-4af8-9fef-2ea2b504e707}\ (13 subtraces) (ID = 359499)
10:56 AM: HKLM\software\classes\clsid\{b424e2aa-4466-41ca-8194-5a83995a9b15}\ (11 subtraces) (ID = 359500)
10:56 AM: HKLM\software\classes\snb.band\ (5 subtraces) (ID = 359501)
10:56 AM: HKLM\software\classes\sntb.bottomframe\ (5 subtraces) (ID = 359502)
10:56 AM: HKLM\software\classes\sntb.leftframe\ (5 subtraces) (ID = 359503)
10:56 AM: HKLM\software\classes\sntb.popupbrowser.1\ (3 subtraces) (ID = 359504)
10:56 AM: HKLM\software\classes\sntb.popupbrowser\ (5 subtraces) (ID = 359505)
10:56 AM: HKLM\software\classes\sntb.popupwindow.1\ (3 subtraces) (ID = 359506)
10:56 AM: HKLM\software\classes\sntb.popupwindow\ (5 subtraces) (ID = 359507)
10:56 AM: HKLM\software\classes\typelib\{46bd3f46-6e46-43d2-a69d-fd8c05044475}\ (9 subtraces) (ID = 359508)
10:56 AM: HKCR\typelib\{46bd3f46-6e46-43d2-a69d-fd8c05044475}\ (9 subtraces) (ID = 359513)
10:56 AM: Found Adware: abetterinternet
10:56 AM: HKCR\aurorahandlerdll.aurorahandlerdllobj\ (5 subtraces) (ID = 359578)
10:56 AM: HKCR\aurorahandlerdll.aurorahandlerdllobj.1\ (3 subtraces) (ID = 359584)
10:56 AM: HKCR\clsid\{4aa870ac-8427-42a4-b92e-ecd956197489}\ (11 subtraces) (ID = 359588)
10:56 AM: HKLM\software\classes\aurorahandlerdll.aurorahandlerdllobj\ (5 subtraces) (ID = 359725)
10:56 AM: HKLM\software\classes\aurorahandlerdll.aurorahandlerdllobj.1\ (3 subtraces) (ID = 359731)
10:56 AM: HKLM\software\classes\clsid\{4aa870ac-8427-42a4-b92e-ecd956197489}\ (11 subtraces) (ID = 359735)
10:56 AM: HKLM\software\classes\typelib\{6d992911-b563-47fc-ab29-437f42d1c729}\ (9 subtraces) (ID = 359756)
10:56 AM: HKCR\aurorahandlerdll.aurorahandlerdllobj\ (5 subtraces) (ID = 360169)
10:56 AM: HKCR\clsid\{4aa870ac-8427-42a4-b92e-ecd956197489}\ (11 subtraces) (ID = 360170)
10:56 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\cmapp\ (5 subtraces) (ID = 381792)
10:56 AM: Found Trojan Horse: sysnet
10:56 AM: HKLM\software\microsoft\windows\currentversion\uninstall\sysnet\ (2 subtraces) (ID = 381857)
10:56 AM: HKCR\interface\{544b6a3f-4024-4403-9661-69b8410be505}\ (8 subtraces) (ID = 479497)
10:56 AM: HKCR\typelib\{6d992911-b563-47fc-ab29-437f42d1c729}\ (9 subtraces) (ID = 480791)
10:56 AM: HKCR\main.mimefilter\ (5 subtraces) (ID = 498504)
10:56 AM: HKLM\software\classes\main.mimefilter\ (5 subtraces) (ID = 498516)
10:56 AM: HKCR\main.mimefilter\ (5 subtraces) (ID = 499294)
10:56 AM: HKLM\software\classes\main.mimefilter\ (5 subtraces) (ID = 499295)
10:56 AM: Found Adware: rich editor
10:56 AM: HKCR\clsid\{71d1708f-973d-4600-af01-ad86688403ae}\ (11 subtraces) (ID = 544813)
10:56 AM: HKCR\typelib\{34a35bbb-8c19-4482-864c-290bd8dd6a5d}\ (9 subtraces) (ID = 544913)
10:56 AM: HKLM\software\classes\clsid\{71d1708f-973d-4600-af01-ad86688403ae}\ (11 subtraces) (ID = 550504)
10:56 AM: HKLM\software\microsoft\windows\currentversion\app paths\lanbrd\ (2 subtraces) (ID = 550562)
10:56 AM: HKLM\software\microsoft\windows\currentversion\app paths\lanbrup\ (2 subtraces) (ID = 550565)
10:56 AM: HKLM\software\classes\typelib\{34a35bbb-8c19-4482-864c-290bd8dd6a5d}\ (9 subtraces) (ID = 550573)
10:56 AM: HKLM\system\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\lanbrup.exe\ (1 subtraces) (ID = 552678)
10:56 AM: Registry Sweep Complete, Elapsed Time:00:00:15
10:56 AM: Starting Cookie Sweep
10:56 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
10:56 AM: Starting File Sweep
10:56 AM: c:\documents and settings\all users\application data\addestroyer (1 subtraces) (ID = -2147481464)
10:56 AM: Found Adware: virtualbouncer
10:56 AM: c:\documents and settings\all users\application data\vbouncer (ID = -2147480097)
10:56 AM: Found Trojan Horse: trojan-downloader-bookedspace
10:56 AM: c:\windows\cfgmgr52 (105 subtraces) (ID = -2147479590)
10:56 AM: c:\windows\system32\vidctrl (ID = -2147481117)
10:56 AM: c:\documents and settings\all users\application data\nsv (17 subtraces) (ID = -2147481136)
10:56 AM: c:\windows\system32\nsvsvc (1 subtraces) (ID = -2147481119)
10:56 AM: c:\program files\asys (2 subtraces) (ID = -2147477847)
10:56 AM: Found Adware: shopathomeselect
10:56 AM: c:\windows\system32\sahimages (6 subtraces) (ID = -2147480329)
10:56 AM: c:\program files\aprps (12 subtraces) (ID = -2147481420)
10:56 AM: lanbruns.exe (ID = 122360)
10:57 AM: Found Adware: comet cursor
10:57 AM: cc_43.pnf (ID = 53470)
11:05 AM: Warning: Failed to read file "c:\windows\system32\newrszht.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
11:05 AM: bwedsvc.exe (ID = 110132)
11:07 AM: vfx8.0-1.exe (ID = 110122)
11:07 AM: tqrmsrv.dll (ID = 120432)
11:09 AM: stb.exe (ID = 123417)
11:09 AM: rsipxmib.dll (ID = 125214)
11:09 AM: Warning: Failed to read file "c:\documents and settings\cody neslen\local settings\temp\perflib_perfdata_5bc.dat". System Error. Code: 32.
The process cannot access the file because it is being used by another process
11:09 AM: Warning: Failed to read file "c:\windows\system32\pxlstore.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
11:09 AM: wmv1920.dbd (ID = 57692)
11:09 AM: wmv2007.dbd (ID = 57693)
11:09 AM: stlb2.xml (ID = 51947)
11:09 AM: csbjmon.dll (ID = 120432)
11:09 AM: Found Adware: purityscan
11:09 AM: shex.exe (ID = 94438)
11:09 AM: Found Adware: upspiral toolbar
11:09 AM: unist2.exe (ID = 82040)
11:09 AM: Found Adware: quicklink search toolbar
11:09 AM: uninst.exe (ID = 73428)
11:09 AM: cbtsrv.dll (ID = 120432)
11:09 AM: Found Adware: 180search assistant/zango
11:09 AM: cxtpls.dll (ID = 120160)
11:09 AM: Found Trojan Horse: trojan downloader pops-stop
11:09 AM: installerv4.exe (ID = 122359)
11:10 AM: wingenerics.dll (ID = 50187)
11:10 AM: tepvipno.dll (ID = 125444)
11:10 AM: mkgmbi.dll (ID = 119159)
11:10 AM: ttext.dll (ID = 75991)
11:10 AM: wirelanb.dll (ID = 125490)
11:10 AM: cxtpls.exe (ID = 120161)
11:10 AM: Found Trojan Horse: trojan-downloader-pacisoft
11:10 AM: xboxab.ico (ID = 113921)
11:10 AM: sony psp1.ico (ID = 125992)
11:10 AM: virushunter4.ico (ID = 113920)
11:10 AM: ringtone2.ico (ID = 125993)
11:10 AM: cqcmcuqs.dat (ID = 121494)
11:10 AM: kill all spyware.ico (ID = 125994)
11:10 AM: sinstaller.inf (ID = 74756)
11:10 AM: wmv0204.ddx (ID = 57686)
11:10 AM: wmv0504.ddx (ID = 57686)
11:10 AM: wmv0904.ddx (ID = 57691)
11:10 AM: wmv0412.ddx (ID = 57686)
11:10 AM: wmv0106.ddx (ID = 57679)
11:10 AM: wmv1204.ddx (ID = 57686)
11:10 AM: wmv1125.ddx (ID = 57685)
11:10 AM: wmv1909.ddx (ID = 57691)
11:10 AM: wmv0315.ddx (ID = 57686)
11:10 AM: Found Adware: adlogix
11:10 AM: pjnumb.xml (ID = 49280)
11:10 AM: File Sweep Complete, Elapsed Time: 00:14:22
11:10 AM: Full Sweep has completed. Elapsed time 00:18:44
11:10 AM: Traces Found: 1941
12:47 PM: Removal process initiated
12:48 PM: Quarantining All Traces: icannnews
12:48 PM: Warning: Could not create quarantine file for: C:\WINDOWS\system32\newrszht.dll File locked exclusively. Restoration will not be possible.
12:48 PM: Warning: Could not create quarantine file for: C:\WINDOWS\system32\pxlstore.dll File locked exclusively. Restoration will not be possible.
12:49 PM: icannnews is in use. It will be removed on reboot.
12:49 PM: C:\WINDOWS\system32\newrszht.dll is in use. It will be removed on reboot.
12:49 PM: C:\WINDOWS\system32\pxlstore.dll is in use. It will be removed on reboot.
12:49 PM: Quarantining All Traces: addestroyer
12:49 PM: Quarantining All Traces: apropos
12:49 PM: Quarantining All Traces: begin2search
12:49 PM: Quarantining All Traces: hotsearchbar toolbar
12:49 PM: Quarantining All Traces: bookedspace
12:49 PM: Quarantining All Traces: browseraid
12:49 PM: Quarantining All Traces: cas
12:49 PM: Quarantining All Traces: clearsearch
12:49 PM: Quarantining All Traces: cws-aboutblank
12:49 PM: Quarantining All Traces: delfin
12:49 PM: Quarantining All Traces: ieplugin
12:49 PM: Quarantining All Traces: drsnsrch.com hijack
12:49 PM: Quarantining All Traces: redzip toolbar
12:49 PM: Quarantining All Traces: screensavers
12:49 PM: Quarantining All Traces: searchtoolbar
12:49 PM: Quarantining All Traces: visfx
12:49 PM: Quarantining All Traces: personal money tree
12:49 PM: Quarantining All Traces: shopnavupdater
12:49 PM: Quarantining All Traces: abetterinternet
12:49 PM: Quarantining All Traces: sysnet
12:49 PM: Quarantining All Traces: rich editor
12:49 PM: Quarantining All Traces: virtualbouncer
12:49 PM: Quarantining All Traces: trojan-downloader-bookedspace
12:49 PM: Quarantining All Traces: shopathomeselect
12:49 PM: Quarantining All Traces: comet cursor
12:49 PM: Quarantining All Traces: purityscan
12:49 PM: Quarantining All Traces: upspiral toolbar
12:49 PM: Quarantining All Traces: quicklink search toolbar
12:49 PM: Quarantining All Traces: 180search assistant/zango
12:49 PM: Quarantining All Traces: trojan downloader pops-stop
12:49 PM: Quarantining All Traces: trojan-downloader-pacisoft
12:49 PM: Quarantining All Traces: adlogix
12:50 PM: Removal process completed. Elapsed time 00:02:17
********
2:14 AM: |··· Start of Session, Sunday, August 07, 2005 ···|
2:14 AM: Spy Sweeper started
2:14 AM: Sweep initiated using definitions version 511
2:14 AM: Starting Memory Sweep
2:15 AM: Warning: Failed to check file "C:\WINDOWS\system32\newrszht.dll". Cannot open file "C:\WINDOWS\system32\newrszht.dll". The process cannot access the file because it is being used by another process
2:15 AM: Found Adware: icannnews
2:15 AM: Detected running threat: C:\WINDOWS\system32\newrszht.dll (ID = 51)
2:15 AM: Warning: Failed to check file "C:\WINDOWS\system32\pxlstore.dll". Cannot open file "C:\WINDOWS\system32\pxlstore.dll". The process cannot access the file because it is being used by another process
2:15 AM: Detected running threat: C:\WINDOWS\system32\pxlstore.dll (ID = 51)
2:17 AM: Warning: Failed to check file "C:\WINDOWS\system32\newrszht.dll". Cannot open file "C:\WINDOWS\system32\newrszht.dll". The process cannot access the file because it is being used by another process
2:18 AM: Memory Sweep Complete, Elapsed Time: 00:03:28
2:18 AM: Starting Registry Sweep
2:18 AM: Found Adware: addestroyer
2:18 AM: HKCR\clsid\{d52433a9-a44c-43ab-a013-24b3c756dd2b}\ (13 subtraces) (ID = 102729)
2:18 AM: HKLM\software\classes\clsid\{d52433a9-a44c-43ab-a013-24b3c756dd2b}\ (13 subtraces) (ID = 102738)
2:18 AM: Found Adware: apropos
2:18 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\aprps\ (7 subtraces) (ID = 103740)
2:18 AM: HKLM\software\aprps\ (8 subtraces) (ID = 103741)
2:18 AM: Found Adware: begin2search
2:18 AM: HKCR\btnetw.amo.1\ (3 subtraces) (ID = 104095)
2:18 AM: Found Adware: hotsearchbar toolbar
2:18 AM: HKCR\btnetw.amo\ (5 subtraces) (ID = 104096)
2:18 AM: HKCR\btnetw.amo\ (5 subtraces) (ID = 104096)
2:18 AM: HKCR\btnetw.iiittt.1\ (3 subtraces) (ID = 104097)
2:18 AM: HKCR\btnetw.iiittt\ (5 subtraces) (ID = 104098)
2:18 AM: HKCR\btnetw.iiittt\ (5 subtraces) (ID = 104098)
2:18 AM: HKCR\btnetw.momo.1\ (3 subtraces) (ID = 104099)
2:18 AM: HKCR\btnetw.momo\ (5 subtraces) (ID = 104100)
2:18 AM: HKCR\btnetw.momo\ (5 subtraces) (ID = 104100)
2:18 AM: HKCR\btnetw.ohb.1\ (3 subtraces) (ID = 104101)
2:18 AM: HKCR\btnetw.ohb\ (5 subtraces) (ID = 104102)
2:18 AM: HKCR\btnetw.ohb\ (5 subtraces) (ID = 104102)
2:18 AM: HKCR\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 104109)
2:18 AM: HKCR\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 104109)
2:18 AM: HKCR\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 104118)
2:18 AM: HKCR\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 104118)
2:18 AM: HKCR\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 104119)
2:18 AM: HKCR\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 104119)
2:18 AM: HKCR\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 104120)
2:18 AM: HKCR\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 104120)
2:18 AM: HKCR\interface\{6b882c34-a832-4f5b-bef1-7e198be3f094}\ (8 subtraces) (ID = 104124)
2:18 AM: HKCR\interface\{9b6b4031-1d6d-4c65-acba-021916853822}\ (8 subtraces) (ID = 104126)
2:18 AM: HKCR\interface\{9ff60a27-0c0c-4a6a-a15f-b21b644d67bb}\ (8 subtraces) (ID = 104127)
2:18 AM: HKCR\interface\{15d53b86-e055-43b1-bbee-a91a0f37bd2a}\ (8 subtraces) (ID = 104128)
2:18 AM: HKCR\interface\{f3c41c1d-22f1-4692-8a7a-88de70a2e9e2}\ (8 subtraces) (ID = 104139)
2:18 AM: HKCR\interface\{fa6fa7a5-2c49-4567-ba74-6dd1c36099ee}\ (8 subtraces) (ID = 104141)
2:18 AM: HKLM\software\classes\btnetw.amo.1\ (3 subtraces) (ID = 104145)
2:18 AM: HKLM\software\classes\btnetw.amo\ (5 subtraces) (ID = 104146)
2:18 AM: HKLM\software\classes\btnetw.amo\ (5 subtraces) (ID = 104146)
2:18 AM: HKLM\software\classes\btnetw.iiittt.1\ (3 subtraces) (ID = 104147)
2:18 AM: HKLM\software\classes\btnetw.iiittt\ (5 subtraces) (ID = 104148)
2:18 AM: HKLM\software\classes\btnetw.iiittt\ (5 subtraces) (ID = 104148)
2:18 AM: HKLM\software\classes\btnetw.momo.1\ (3 subtraces) (ID = 104149)
2:18 AM: HKLM\software\classes\btnetw.momo\ (5 subtraces) (ID = 104150)
2:18 AM: HKLM\software\classes\btnetw.momo\ (5 subtraces) (ID = 104150)
2:18 AM: HKLM\software\classes\btnetw.ohb.1\ (3 subtraces) (ID = 104151)
2:18 AM: HKLM\software\classes\btnetw.ohb\ (5 subtraces) (ID = 104152)
2:18 AM: HKLM\software\classes\btnetw.ohb\ (5 subtraces) (ID = 104152)
2:18 AM: HKLM\software\classes\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 104159)
2:18 AM: HKLM\software\classes\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 104159)
2:18 AM: HKLM\software\classes\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 104168)
2:18 AM: HKLM\software\classes\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 104168)
2:18 AM: HKLM\software\classes\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 104169)
2:18 AM: HKLM\software\classes\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 104169)
2:18 AM: HKLM\software\classes\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 104170)
2:18 AM: HKLM\software\classes\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 104170)
2:18 AM: HKLM\software\classes\interface\{6b882c34-a832-4f5b-bef1-7e198be3f094}\ (8 subtraces) (ID = 104174)
2:18 AM: HKLM\software\classes\interface\{9b6b4031-1d6d-4c65-acba-021916853822}\ (8 subtraces) (ID = 104176)
2:18 AM: HKLM\software\classes\interface\{9ff60a27-0c0c-4a6a-a15f-b21b644d67bb}\ (8 subtraces) (ID = 104177)
2:18 AM: HKLM\software\classes\interface\{15d53b86-e055-43b1-bbee-a91a0f37bd2a}\ (8 subtraces) (ID = 104178)
2:18 AM: HKLM\software\classes\interface\{f3c41c1d-22f1-4692-8a7a-88de70a2e9e2}\ (8 subtraces) (ID = 104189)
2:18 AM: HKLM\software\classes\interface\{fa6fa7a5-2c49-4567-ba74-6dd1c36099ee}\ (8 subtraces) (ID = 104191)
2:18 AM: HKLM\software\classes\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 104195)
2:18 AM: HKLM\software\classes\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 104195)
2:18 AM: HKCR\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 104238)
2:18 AM: HKCR\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 104238)
2:18 AM: Found Adware: bookedspace
2:18 AM: HKLM\software\configuration manager\cfgmgr52\ (368 subtraces) (ID = 104873)
2:18 AM: Found Adware: browseraid
2:18 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\a70f6a1d-0195-42a2-934c-d8ac0f7c08eb\ (1 subtraces) (ID = 105078)
2:18 AM: Found Adware: cas
2:18 AM: HKCR\clsid\{8293d547-38dd-4325-b35a-f1817edfa5fc}\ (11 subtraces) (ID = 105365)
2:18 AM: HKCR\typelib\{d4c89c18-b4f3-46a9-8800-e9e7a55afbd9}\ (9 subtraces) (ID = 105366)
2:18 AM: HKLM\software\classes\clsid\{8293d547-38dd-4325-b35a-f1817edfa5fc}\ (11 subtraces) (ID = 105368)
2:18 AM: HKLM\software\classes\typelib\{d4c89c18-b4f3-46a9-8800-e9e7a55afbd9}\ (9 subtraces) (ID = 105369)
2:18 AM: Found Adware: clearsearch
2:18 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\microsoft\internet explorer\new windows\allow\ || 69.28.210.175 (ID = 105744)
2:18 AM: Found Adware: cws-aboutblank
2:18 AM: HKCR\protocols\filter\text/html\ (2 subtraces) (ID = 114343)
2:18 AM: HKLM\software\classes\protocols\filter\text/html\ (2 subtraces) (ID = 115907)
2:18 AM: Found Adware: delfin
2:18 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\mvu\ (5 subtraces) (ID = 124884)
2:18 AM: HKLM\software\vidctrl\ (3 subtraces) (ID = 124897)
2:18 AM: Found Adware: ieplugin
2:18 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\intexp\ (10 subtraces) (ID = 128173)
2:18 AM: Found Adware: drsnsrch.com hijack
2:18 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
2:18 AM: Found Adware: redzip toolbar
2:18 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\microsoft\windows\currentversion\explorer\ || insid (ID = 139328)
2:18 AM: Found Adware: screensavers
2:18 AM: HKCR\clsid\{722d2939-a14a-41a9-9eac-ab8f4e295819}\ (14 subtraces) (ID = 140550)
2:18 AM: HKCR\clsid\{88d758a3-d33b-45fd-91e3-67749b4057fa}\ (14 subtraces) (ID = 140551)
2:18 AM: HKCR\interface\{760aca60-79c3-4875-9d19-b14a5b3fea77}\ (8 subtraces) (ID = 140552)
2:18 AM: HKCR\interface\{883ea659-ed80-46f9-9ed2-83327f67789f}\ (8 subtraces) (ID = 140553)
2:18 AM: HKCR\interface\{b64c73d7-459e-4816-91f9-1348f8e36984}\ (8 subtraces) (ID = 140554)
2:18 AM: HKLM\software\classes\clsid\{722d2939-a14a-41a9-9eac-ab8f4e295819}\ (14 subtraces) (ID = 140555)
2:18 AM: HKLM\software\classes\clsid\{88d758a3-d33b-45fd-91e3-67749b4057fa}\ (14 subtraces) (ID = 140556)
2:18 AM: HKLM\software\classes\interface\{760aca60-79c3-4875-9d19-b14a5b3fea77}\ (8 subtraces) (ID = 140557)
2:18 AM: HKLM\software\classes\interface\{883ea659-ed80-46f9-9ed2-83327f67789f}\ (8 subtraces) (ID = 140558)
2:18 AM: HKLM\software\classes\interface\{b64c73d7-459e-4816-91f9-1348f8e36984}\ (8 subtraces) (ID = 140559)
2:18 AM: HKLM\software\classes\screensaversinstaller.installer.1\ (3 subtraces) (ID = 140560)
2:18 AM: HKLM\software\classes\screensaversinstaller.installer\ (5 subtraces) (ID = 140561)
2:18 AM: HKLM\software\classes\screensaversinstaller.sinstaller.1\ (3 subtraces) (ID = 140562)
2:18 AM: HKLM\software\classes\screensaversinstaller.sinstaller.1\clsid\ (1 subtraces) (ID = 140563)
2:18 AM: HKLM\software\classes\screensaversinstaller.sinstaller\ (5 subtraces) (ID = 140564)
2:18 AM: HKLM\software\classes\typelib\{0ab5b0d8-2b74-4c1c-8fa4-e52550b8b45b}\ (9 subtraces) (ID = 140565)
2:18 AM: HKLM\software\microsoft\code store database\distribution units\{88d758a3-d33b-45fd-91e3-67749b4057fa}\ (9 subtraces) (ID = 140566)
2:18 AM: HKLM\software\screensavers.com\ (14 subtraces) (ID = 140569)
2:18 AM: HKCR\screensaversinstaller.installer.1\ (3 subtraces) (ID = 140570)
2:18 AM: HKCR\screensaversinstaller.installer\ (5 subtraces) (ID = 140571)
2:18 AM: HKCR\screensaversinstaller.sinstaller.1\ (3 subtraces) (ID = 140572)
2:18 AM: HKCR\screensaversinstaller.sinstaller.1\clsid\ (1 subtraces) (ID = 140573)
2:18 AM: HKCR\screensaversinstaller.sinstaller\ (5 subtraces) (ID = 140574)
2:18 AM: HKCR\typelib\{0ab5b0d8-2b74-4c1c-8fa4-e52550b8b45b}\ (9 subtraces) (ID = 140575)
2:18 AM: Found Adware: searchtoolbar
2:18 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\{12ee7a5e-0674-42f9-a76b-000000004d00}\ (3 subtraces) (ID = 141347)
2:18 AM: Found Adware: visfx
2:18 AM: HKLM\software\microsoft\windows\currentversion\uninstall\visfx\ (2 subtraces) (ID = 145734)
2:18 AM: HKCR\activexctrl\ (3 subtraces) (ID = 169450)
2:18 AM: HKCR\clsid\{3bfadce2-1141-4b81-8878-49af625f0fdc}\ (3 subtraces) (ID = 169451)
2:18 AM: HKCR\clsid\{4208fb4d-4e53-4f5a-bf7a-3e047ddb5281}\ (21 subtraces) (ID = 169452)
2:18 AM: HKCR\interface\{980ad470-04ea-4d1d-bd26-e178b7bda6d8}\ (8 subtraces) (ID = 169454)
2:18 AM: HKCR\interface\{fd39937a-c583-4aac-9332-8a3e44988a67}\ (8 subtraces) (ID = 169455)
2:18 AM: HKCR\typelib\{ee5ac3d6-6f43-4047-af0a-d66fc2cf8f42}\ (9 subtraces) (ID = 169456)
2:18 AM: HKLM\software\classes\activexctrl\ (3 subtraces) (ID = 169457)
2:18 AM: HKLM\software\classes\clsid\{3bfadce2-1141-4b81-8878-49af625f0fdc}\ (3 subtraces) (ID = 169458)
2:18 AM: HKLM\software\classes\clsid\{4208fb4d-4e53-4f5a-bf7a-3e047ddb5281}\ (21 subtraces) (ID = 169459)
2:18 AM: HKLM\software\classes\interface\{980ad470-04ea-4d1d-bd26-e178b7bda6d8}\ (8 subtraces) (ID = 169461)
2:18 AM: HKLM\software\classes\interface\{fd39937a-c583-4aac-9332-8a3e44988a67}\ (8 subtraces) (ID = 169462)
2:18 AM: HKLM\software\classes\typelib\{ee5ac3d6-6f43-4047-af0a-d66fc2cf8f42}\ (9 subtraces) (ID = 169463)
2:18 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\cas\client\ (1 subtraces) (ID = 359309)
2:18 AM: Found Adware: personal money tree
2:18 AM: HKCR\clsid\{d1a3a43b-05a1-40cd-834c-053e6c03b258}\ (7 subtraces) (ID = 359438)
2:18 AM: HKCR\comparishopper.application\ (3 subtraces) (ID = 359439)
2:18 AM: HKLM\software\classes\clsid\{d1a3a43b-05a1-40cd-834c-053e6c03b258}\ (7 subtraces) (ID = 359441)
2:18 AM: HKLM\software\classes\comparishopper.application\ (3 subtraces) (ID = 359442)
2:18 AM: Found Adware: shopnavupdater
2:18 AM: HKCR\clsid\{00027925-0017-4faf-9539-90e4ac0b9ec5}\ (11 subtraces) (ID = 359486)
2:18 AM: HKCR\clsid\{5e0910c6-9e45-481c-a2ec-0ec29c96ebeb}\ (11 subtraces) (ID = 359487)
2:18 AM: HKCR\clsid\{8f7d96aa-489a-4194-ab34-21ef42507932}\ (13 subtraces) (ID = 359488)
2:18 AM: HKCR\clsid\{79406f24-8e95-4af8-9fef-2ea2b504e707}\ (13 subtraces) (ID = 359489)
2:18 AM: HKCR\clsid\{b424e2aa-4466-41ca-8194-5a83995a9b15}\ (11 subtraces) (ID = 359490)
2:18 AM: HKCR\snb.band\ (5 subtraces) (ID = 359491)
2:18 AM: HKCR\sntb.bottomframe\ (5 subtraces) (ID = 359492)
2:18 AM: HKCR\sntb.leftframe\ (5 subtraces) (ID = 359493)
2:18 AM: HKCR\sntb.popupbrowser\ (5 subtraces) (ID = 359494)
2:18 AM: HKCR\sntb.popupwindow\ (5 subtraces) (ID = 359495)
2:18 AM: HKLM\software\classes\clsid\{00027925-0017-4faf-9539-90e4ac0b9ec5}\ (11 subtraces) (ID = 359496)
2:18 AM: HKLM\software\classes\clsid\{5e0910c6-9e45-481c-a2ec-0ec29c96ebeb}\ (11 subtraces) (ID = 359497)
2:18 AM: HKLM\software\classes\clsid\{8f7d96aa-489a-4194-ab34-21ef42507932}\ (13 subtraces) (ID = 359498)
2:18 AM: HKLM\software\classes\clsid\{79406f24-8e95-4af8-9fef-2ea2b504e707}\ (13 subtraces) (ID = 359499)
2:18 AM: HKLM\software\classes\clsid\{b424e2aa-4466-41ca-8194-5a83995a9b15}\ (11 subtraces) (ID = 359500)
2:18 AM: HKLM\software\classes\snb.band\ (5 subtraces) (ID = 359501)
2:18 AM: HKLM\software\classes\sntb.bottomframe\ (5 subtraces) (ID = 359502)
2:18 AM: HKLM\software\classes\sntb.leftframe\ (5 subtraces) (ID = 359503)
2:18 AM: HKLM\software\classes\sntb.popupbrowser.1\ (3 subtraces) (ID = 359504)
2:18 AM: HKLM\software\classes\sntb.popupbrowser\ (5 subtraces) (ID = 359505)
2:18 AM: HKLM\software\classes\sntb.popupwindow.1\ (3 subtraces) (ID = 359506)
2:18 AM: HKLM\software\classes\sntb.popupwindow\ (5 subtraces) (ID = 359507)
2:18 AM: HKLM\software\classes\typelib\{46bd3f46-6e46-43d2-a69d-fd8c05044475}\ (9 subtraces) (ID = 359508)
2:18 AM: HKCR\typelib\{46bd3f46-6e46-43d2-a69d-fd8c05044475}\ (9 subtraces) (ID = 359513)
2:18 AM: Found Adware: abetterinternet
2:18 AM: HKCR\aurorahandlerdll.aurorahandlerdllobj\ (5 subtraces) (ID = 359578)
2:18 AM: HKCR\aurorahandlerdll.aurorahandlerdllobj.1\ (3 subtraces) (ID = 359584)
2:18 AM: HKCR\clsid\{4aa870ac-8427-42a4-b92e-ecd956197489}\ (11 subtraces) (ID = 359588)
2:18 AM: HKLM\software\classes\aurorahandlerdll.aurorahandlerdllobj\ (5 subtraces) (ID = 359725)
2:18 AM: HKLM\software\classes\aurorahandlerdll.aurorahandlerdllobj.1\ (3 subtraces) (ID = 359731)
2:18 AM: HKLM\software\classes\clsid\{4aa870ac-8427-42a4-b92e-ecd956197489}\ (11 subtraces) (ID = 359735)
2:18 AM: HKLM\software\classes\typelib\{6d992911-b563-47fc-ab29-437f42d1c729}\ (9 subtraces) (ID = 359756)
2:18 AM: HKCR\aurorahandlerdll.aurorahandlerdllobj\ (5 subtraces) (ID = 360169)
2:18 AM: HKCR\clsid\{4aa870ac-8427-42a4-b92e-ecd956197489}\ (11 subtraces) (ID = 360170)
2:18 AM: HKU\S-1-5-21-1844237615-630328440-725345543-1003\software\cmapp\ (5 subtraces) (ID = 381792)
2:18 AM: Found Trojan Horse: sysnet
2:18 AM: HKLM\software\microsoft\windows\currentversion\uninstall\sysnet\ (2 subtraces) (ID = 381857)
2:18 AM: HKCR\interface\{544b6a3f-4024-4403-9661-69b8410be505}\ (8 subtraces) (ID = 479497)
2:18 AM: HKCR\typelib\{6d992911-b563-47fc-ab29-437f42d1c729}\ (9 subtraces) (ID = 480791)
2:18 AM: HKCR\main.mimefilter\ (5 subtraces) (ID = 498504)
2:18 AM: HKLM\software\classes\main.mimefilter\ (5 subtraces) (ID = 498516)
2:18 AM: HKCR\main.mimefilter\ (5 subtraces) (ID = 499294)
2:18 AM: HKLM\software\classes\main.mimefilter\ (5 subtraces) (ID = 499295)
2:18 AM: Found Adware: rich editor
2:18 AM: HKCR\clsid\{71d1708f-973d-4600-af01-ad86688403ae}\ (11 subtraces) (ID = 544813)
2:18 AM: HKCR\typelib\{34a35bbb-8c19-4482-864c-290bd8dd6a5d}\ (9 subtraces) (ID = 544913)
2:18 AM: HKLM\software\classes\clsid\{71d1708f-973d-4600-af01-ad86688403ae}\ (11 subtraces) (ID = 550504)
2:18 AM: HKLM\software\microsoft\windows\currentversion\app paths\lanbrd\ (2 subtraces) (ID = 550562)
2:18 AM: HKLM\software\microsoft\windows\currentversion\app paths\lanbrup\ (2 subtraces) (ID = 550565)
2:18 AM: HKLM\software\classes\typelib\{34a35bbb-8c19-4482-864c-290bd8dd6a5d}\ (9 subtraces) (ID = 550573)
2:18 AM: HKLM\system\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\lanbrup.exe\ (1 subtraces) (ID = 552678)
2:18 AM: Registry Sweep Complete, Elapsed Time:00:00:13
2:18 AM: Starting Cookie Sweep
2:18 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
2:18 AM: Starting File Sweep
2:18 AM: c:\windows\system32\vidctrl (ID = -2147481117)
2:18 AM: c:\windows\system32\nsvsvc (1 subtraces) (ID = -2147481119)
2:18 AM: c:\documents and settings\all users\application data\nsv (17 subtraces) (ID = -2147481136)
2:18 AM: c:\documents and settings\all users\application data\addestroyer (1 subtraces) (ID = -2147481464)
2:18 AM: Found Adware: virtualbouncer
2:18 AM: c:\documents and settings\all users\application data\vbouncer (ID = -2147480097)
2:18 AM: Found Trojan Horse: trojan-downloader-bookedspace
2:18 AM: c:\windows\cfgmgr52 (105 subtraces) (ID = -2147479590)
2:18 AM: c:\program files\aprps (12 subtraces) (ID = -2147481420)
2:18 AM: Found Adware: shopathomeselect
2:18 AM: c:\windows\system32\sahimages (6 subtraces) (ID = -2147480329)
2:18 AM: c:\program files\asys (2 subtraces) (ID = -2147477847)
2:19 AM: lanbruns.exe (ID = 122360)
2:19 AM: Found Adware: comet cursor
2:19 AM: cc_43.pnf (ID = 53470)
2:19 AM: Warning: Failed to read file "c:\documents and settings\cody neslen\local settings\temp\perflib_perfdata_5bc.dat". System Error. Code: 32.
The process cannot access the file because it is being used by another process
2:31 AM: Warning: Failed to read file "c:\windows\system32\newrszht.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
2:31 AM: bwedsvc.exe (ID = 110132)
2:35 AM: vfx8.0-1.exe (ID = 110122)
2:35 AM: tqrmsrv.dll (ID = 120432)
2:38 AM: stb.exe (ID = 123417)
2:38 AM: rsipxmib.dll (ID = 125214)
2:38 AM: wmv1920.dbd (ID = 57692)
2:38 AM: Warning: Failed to read file "c:\windows\system32\pxlstore.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
2:38 AM: wmv2007.dbd (ID = 57693)
2:38 AM: stlb2.xml (ID = 51947)
2:38 AM: csbjmon.dll (ID = 120432)
2:38 AM: Found Adware: purityscan
2:38 AM: shex.exe (ID = 94438)
2:38 AM: Found Adware: upspiral toolbar
2:38 AM: unist2.exe (ID = 82040)
2:38 AM: Found Adware: quicklink search toolbar
2:38 AM: uninst.exe (ID = 73428)
2:38 AM: cbtsrv.dll (ID = 120432)
2:38 AM: Found Adware: 180search assistant/zango
2:38 AM: cxtpls.dll (ID = 120160)
2:38 AM: Found Trojan Horse: trojan downloader pops-stop
2:38 AM: installerv4.exe (ID = 122359)
2:39 AM: wingenerics.dll (ID = 50187)
2:39 AM: tepvipno.dll (ID = 125444)
2:39 AM: mkgmbi.dll (ID = 119159)
2:39 AM: ttext.dll (ID = 75991)
2:39 AM: wirelanb.dll (ID = 125490)
2:39 AM: cxtpls.exe (ID = 120161)
2:39 AM: Found Trojan Horse: trojan-downloader-pacisoft
2:39 AM: xboxab.ico (ID = 113921)
2:39 AM: sony psp1.ico (ID = 125992)
2:39 AM: virushunter4.ico (ID = 113920)
2:39 AM: ringtone2.ico (ID = 125993)
2:39 AM: cqcmcuqs.dat (ID = 121494)
2:39 AM: kill all spyware.ico (ID = 125994)
2:39 AM: sinstaller.inf (ID = 74756)
2:39 AM: wmv0204.ddx (ID = 57686)
2:39 AM: wmv0504.ddx (ID = 57686)
2:39 AM: wmv0904.ddx (ID = 57691)
2:39 AM: wmv0412.ddx (ID = 57686)
2:39 AM: wmv0106.ddx (ID = 57679)
2:39 AM: wmv1204.ddx (ID = 57686)
2:39 AM: wmv1125.ddx (ID = 57685)
2:39 AM: wmv1909.ddx (ID = 57691)
2:39 AM: wmv0315.ddx (ID = 57686)
2:39 AM: Found Adware: adlogix
2:39 AM: pjnumb.xml (ID = 49280)
2:39 AM: File Sweep Complete, Elapsed Time: 00:21:04
2:39 AM: Full Sweep has completed. Elapsed time 00:24:53
2:39 AM: Traces Found: 1941
10:52 AM: |··· End of Session, Sunday, August 07, 2005 ···|
********
2:13 AM: |··· Start of Session, Sunday, August 07, 2005 ···|
2:13 AM: Spy Sweeper started
2:13 AM: Processing Hosts File Alerts
2:13 AM: Fixed Hosts File entry: HP000D9D21DF18
2:14 AM: |··· End of Session, Sunday, August 07, 2005 ···|