Loads of stuff here. Thanks, again for helping.
Results of Spysweep, Kaspersky and Panda:
Spysweep:
11:16 AM: |··· Start of Session, Saturday, August 06, 2005 ···|
11:16 AM: Spy Sweeper started
11:16 AM: Sweep initiated using definitions version 511
11:17 AM: Starting Memory Sweep
11:17 AM: Warning: Failed to check file "C:\WINDOWS\SYSTEM32\reched20.dll". Cannot open file "C:\WINDOWS\SYSTEM32\reched20.dll". The process cannot access the file because it is being used by another process
11:17 AM: Found Adware: icannnews
11:17 AM: Detected running threat: C:\WINDOWS\SYSTEM32\reched20.dll (ID = 51)
11:17 AM: Warning: Failed to check file "C:\WINDOWS\SYSTEM32\tQpi3.dll". Cannot open file "C:\WINDOWS\SYSTEM32\tQpi3.dll". The process cannot access the file because it is being used by another process
11:17 AM: Detected running threat: C:\WINDOWS\SYSTEM32\tQpi3.dll (ID = 51)
11:18 AM: Warning: Failed to check file "C:\WINDOWS\SYSTEM32\reched20.dll". Cannot open file "C:\WINDOWS\SYSTEM32\reched20.dll". The process cannot access the file because it is being used by another process
11:18 AM: Memory Sweep Complete, Elapsed Time: 00:01:30
11:18 AM: Starting Registry Sweep
11:18 AM: Registry Sweep Complete, Elapsed Time:00:00:12
11:18 AM: Starting Cookie Sweep
11:18 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
11:18 AM: Starting File Sweep
11:19 AM: Warning: Failed to read file "c:\windows\temp\perflib_perfdata_5cc.dat". System Error. Code: 32.
The process cannot access the file because it is being used by another process
11:19 AM: Found Adware: upspiral toolbar
11:19 AM: 00004782.exe (ID = 82040)
11:20 AM: Warning: Failed to read file "c:\windows\system32\reched20.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
11:21 AM: Warning: Failed to read file "c:\windows\system32\tqpi3.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
11:22 AM: __delete_on_reboot__sarvdeps.dll (ID = 125214)
11:23 AM: Found Adware: begin2search
11:23 AM: 00004798.ico (ID = 51041)
11:23 AM: Found Trojan Horse: trojan-downloader-pacisoft
11:23 AM: 00004424.ico (ID = 113921)
11:23 AM: 00004422.ico (ID = 125992)
11:23 AM: Found Adware: browseraid
11:23 AM: 00004390.xml (ID = 51947)
11:23 AM: 00004420.ico (ID = 113920)
11:23 AM: Found Trojan Horse: downloadul
11:23 AM: 00004807.inf (ID = 59212)
11:23 AM: File Sweep Complete, Elapsed Time: 00:05:06
11:23 AM: Full Sweep has completed. Elapsed time 00:06:59
11:23 AM: Traces Found: 10
11:25 AM: Removal process initiated
11:25 AM: Quarantining All Traces: icannnews
11:25 AM: Warning: Could not create quarantine file for: C:\WINDOWS\SYSTEM32\reched20.dll File locked exclusively. Restoration will not be possible.
11:25 AM: Warning: Could not create quarantine file for: C:\WINDOWS\SYSTEM32\tQpi3.dll File locked exclusively. Restoration will not be possible.
11:25 AM: icannnews is in use. It will be removed on reboot.
11:25 AM: C:\WINDOWS\SYSTEM32\reched20.dll is in use. It will be removed on reboot.
11:25 AM: C:\WINDOWS\SYSTEM32\tQpi3.dll is in use. It will be removed on reboot.
11:25 AM: Quarantining All Traces: upspiral toolbar
11:25 AM: Quarantining All Traces: begin2search
11:25 AM: Quarantining All Traces: trojan-downloader-pacisoft
11:25 AM: Quarantining All Traces: browseraid
11:25 AM: Quarantining All Traces: downloadul
11:25 AM: Warning: Quarantine process could not restart Explorer.
11:26 AM: Removal process completed. Elapsed time 00:01:18
********
10:50 AM: |··· Start of Session, Saturday, August 06, 2005 ···|
10:50 AM: Spy Sweeper started
10:50 AM: Sweep initiated using definitions version 511
10:50 AM: Starting Memory Sweep
10:51 AM: Warning: Failed to check file "C:\WINDOWS\SYSTEM32\tQpi3.dll". Cannot open file "C:\WINDOWS\SYSTEM32\tQpi3.dll". The process cannot access the file because it is being used by another process
10:51 AM: Found Adware: icannnews
10:51 AM: Detected running threat: C:\WINDOWS\SYSTEM32\tQpi3.dll (ID = 51)
10:51 AM: Warning: Failed to check file "C:\WINDOWS\SYSTEM32\nyobjapi.dll". Cannot open file "C:\WINDOWS\SYSTEM32\nyobjapi.dll". The process cannot access the file because it is being used by another process
10:51 AM: Detected running threat: C:\WINDOWS\SYSTEM32\nyobjapi.dll (ID = 51)
10:52 AM: Memory Sweep Complete, Elapsed Time: 00:01:30
10:52 AM: Starting Registry Sweep
10:52 AM: Found Adware: addestroyer
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\vb and vba program settings\addestroyer\ (3 subtraces) (ID = 102749)
10:52 AM: Found Adware: bookedspace
10:52 AM: HKLM\software\configuration manager\cfgmgr52\ (312 subtraces) (ID = 104873)
10:52 AM: Found Adware: browseraid
10:52 AM: HKU\S-1-5-21-1260153011-1797618588-3831952528-1006\software\a70f6a1d-0195-42a2-934c-d8ac0f7c08eb\ (1 subtraces) (ID = 105078)
10:52 AM: Found Adware: cas
10:52 AM: HKCR\typelib\{d4c89c18-b4f3-46a9-8800-e9e7a55afbd9}\ (9 subtraces) (ID = 105366)
10:52 AM: HKLM\software\classes\typelib\{d4c89c18-b4f3-46a9-8800-e9e7a55afbd9}\ (9 subtraces) (ID = 105369)
10:52 AM: Found Adware: clearsearch
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\microsoft\internet explorer\new windows\allow\ || 69.28.210.175 (ID = 105744)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\new windows\allow\ || 69.28.210.175 (ID = 105744)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\microsoft\internet explorer\new windows\allow\ || 69.28.210.175 (ID = 105744)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\microsoft\internet explorer\new windows\allow\ || 69.28.210.175 (ID = 105744)
10:52 AM: Found Adware: elitebar
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\lq\ (22 subtraces) (ID = 125741)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\lq\ (22 subtraces) (ID = 125741)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\lq\ (22 subtraces) (ID = 125741)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1010\software\lq\ (5 subtraces) (ID = 125741)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1011\software\lq\ (22 subtraces) (ID = 125741)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\lq\ (22 subtraces) (ID = 125741)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\microsoft\internet explorer\toolbar\webbrowser\ || {825cf5bd-8862-4430-b771-0c15c5ca8def} (ID = 125745)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\toolbar\webbrowser\ || {825cf5bd-8862-4430-b771-0c15c5ca8def} (ID = 125745)
10:52 AM: Found Adware: elitebar searchmiracle hijacker
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\ || searchurl (ID = 125775)
10:52 AM: Found Adware: ieplugin
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\intexp\ (7 subtraces) (ID = 128173)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\intexp\ (2 subtraces) (ID = 128173)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\intexp\ (2 subtraces) (ID = 128173)
10:52 AM: HKLM\software\microsoft\internet explorer\toolbar\ || {2cde1a7d-a478-4291-bf31-e1b4c16f92eb} (ID = 128178)
10:52 AM: Found Adware: drsnsrch.com hijack
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\main\ || search bar (ID = 128206)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\microsoft\internet explorer\main\ || search page (ID = 128207)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\main\ || search page (ID = 128207)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\microsoft\internet explorer\searchurl\ (2 subtraces) (ID = 128212)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\searchurl\ (2 subtraces) (ID = 128212)
10:52 AM: Found Adware: internetoptimizer
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\avenue media\ (ID = 128887)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\avenue media\ (ID = 128887)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\avenue media\ (7 subtraces) (ID = 128887)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1011\software\avenue media\ (6 subtraces) (ID = 128887)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\avenue media\ (11 subtraces) (ID = 128887)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\policies\avenue media\ (ID = 128928)
10:52 AM: Found Adware: istbar
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\ist\ (1 subtraces) (ID = 129108)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\ist\ (5 subtraces) (ID = 129108)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\ist\ (1 subtraces) (ID = 129108)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\ist\ (1 subtraces) (ID = 129108)
10:52 AM: Found Adware: lopdotcom
10:52 AM: HKU\S-1-5-18\software\microsoft\windows\currentversion\run\ || aida (ID = 130496)
10:52 AM: Found Adware: 180search assistant/zango
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\sais\ (11 subtraces) (ID = 135790)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\sais\ (14 subtraces) (ID = 135790)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\sais\ (22 subtraces) (ID = 135790)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\sais\ (19 subtraces) (ID = 135790)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\salm\ (11 subtraces) (ID = 135792)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1011\software\salm\ (19 subtraces) (ID = 135792)
10:52 AM: Found Trojan Horse: trojan-downloader-pacisoft
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\psof1\ (15 subtraces) (ID = 136530)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\psof1\ (16 subtraces) (ID = 136530)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\psof1\ (2 subtraces) (ID = 136530)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\psof1\ (2 subtraces) (ID = 136530)
10:52 AM: Found Adware: powerscan
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\powerscan\ (ID = 136823)
10:52 AM: Found Adware: redzip toolbar
10:52 AM: HKU\S-1-5-21-1260153011-1797618588-3831952528-1006\software\microsoft\windows\currentversion\explorer\ || insid (ID = 139328)
10:52 AM: Found System Monitor: sc-keylog
10:52 AM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\explorer\ (6 subtraces) (ID = 140468)
10:52 AM: Found Adware: searchtoolbar
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\{12ee7a5e-0674-42f9-a76b-000000004d00}\ (3 subtraces) (ID = 141347)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1010\software\{12ee7a5e-0674-42f9-a76b-000000004d00}\ (3 subtraces) (ID = 141347)
10:52 AM: Found Adware: bho_sidefind
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\explorer bars\{8cba1b49-8144-4721-a7b1-64c578c9eed7}\ (1 subtraces) (ID = 141777)
10:52 AM: HKU\S-1-5-21-1260153011-1797618588-3831952528-1006\software\microsoft\internet explorer\extensions\cmdmapping\ || {10e42047-deb9-4535-a118-b3f6ec39b807} (ID = 141778)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\microsoft\internet explorer\extensions\cmdmapping\ || {10e42047-deb9-4535-a118-b3f6ec39b807} (ID = 141778)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\extensions\cmdmapping\ || {10e42047-deb9-4535-a118-b3f6ec39b807} (ID = 141778)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\microsoft\internet explorer\extensions\cmdmapping\ || {10e42047-deb9-4535-a118-b3f6ec39b807} (ID = 141778)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\microsoft\internet explorer\extensions\cmdmapping\ || {10e42047-deb9-4535-a118-b3f6ec39b807} (ID = 141778)
10:52 AM: Found Adware: surfsidekick
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\urlsearchhooks\ || {02ee5b04-f144-47bb-83fb-a60bd91b74a9} (ID = 143397)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\windows\currentversion\run\ || surfsidekick 3 (ID = 143403)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\surfsidekick3\ (3 subtraces) (ID = 143412)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\surfsidekick3\ (3 subtraces) (ID = 143412)
10:52 AM: Found Trojan Horse: trojan-backdoor-soundcheck
10:52 AM: HKLM\system\currentcontrolset\services\msdirectx\ (7 subtraces) (ID = 144200)
10:52 AM: Found Adware: virtualbouncer
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\vb and vba program settings\vbouncer\ (8 subtraces) (ID = 145564)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\vb and vba program settings\vbouncer\ (8 subtraces) (ID = 145564)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\vb and vba program settings\vbouncer\ (7 subtraces) (ID = 145564)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\vb and vba program settings\vbouncer\ (7 subtraces) (ID = 145564)
10:52 AM: Found Adware: winad
10:52 AM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediaaccx.dll\ (2 subtraces) (ID = 147191)
10:52 AM: Found Adware: yoursitebar
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\toolbar\webbrowser\ || {86227d9c-0efe-4f8a-aa55-30386a3f5686} (ID = 147853)
10:52 AM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\ysbactivex.dll (ID = 147857)
10:52 AM: HKLM\software\yoursitebar\ (6 subtraces) (ID = 147860)
10:52 AM: HKCR\activexctrl\ (3 subtraces) (ID = 169450)
10:52 AM: HKCR\interface\{980ad470-04ea-4d1d-bd26-e178b7bda6d8}\ (8 subtraces) (ID = 169454)
10:52 AM: HKCR\interface\{fd39937a-c583-4aac-9332-8a3e44988a67}\ (8 subtraces) (ID = 169455)
10:52 AM: HKCR\typelib\{ee5ac3d6-6f43-4047-af0a-d66fc2cf8f42}\ (9 subtraces) (ID = 169456)
10:52 AM: HKLM\software\classes\activexctrl\ (3 subtraces) (ID = 169457)
10:52 AM: HKLM\software\classes\interface\{980ad470-04ea-4d1d-bd26-e178b7bda6d8}\ (8 subtraces) (ID = 169461)
10:52 AM: HKLM\software\classes\interface\{fd39937a-c583-4aac-9332-8a3e44988a67}\ (8 subtraces) (ID = 169462)
10:52 AM: HKLM\software\classes\typelib\{ee5ac3d6-6f43-4047-af0a-d66fc2cf8f42}\ (9 subtraces) (ID = 169463)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\cas\client\ (11 subtraces) (ID = 359309)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\cas\client\ (11 subtraces) (ID = 359309)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\windows\currentversion\run\ || cas client (ID = 359312)
10:52 AM: Found Adware: shopnavupdater
10:52 AM: HKCR\snb.band\ (5 subtraces) (ID = 359491)
10:52 AM: HKCR\sntb.bottomframe\ (5 subtraces) (ID = 359492)
10:52 AM: HKCR\sntb.leftframe\ (5 subtraces) (ID = 359493)
10:52 AM: HKCR\sntb.popupbrowser\ (5 subtraces) (ID = 359494)
10:52 AM: HKCR\sntb.popupwindow\ (5 subtraces) (ID = 359495)
10:52 AM: HKLM\software\classes\snb.band\ (5 subtraces) (ID = 359501)
10:52 AM: HKLM\software\classes\sntb.bottomframe\ (5 subtraces) (ID = 359502)
10:52 AM: HKLM\software\classes\sntb.leftframe\ (5 subtraces) (ID = 359503)
10:52 AM: HKLM\software\classes\sntb.popupbrowser\ (5 subtraces) (ID = 359505)
10:52 AM: HKLM\software\classes\sntb.popupwindow\ (5 subtraces) (ID = 359507)
10:52 AM: HKLM\software\classes\typelib\{46bd3f46-6e46-43d2-a69d-fd8c05044475}\ (9 subtraces) (ID = 359508)
10:52 AM: HKCR\typelib\{46bd3f46-6e46-43d2-a69d-fd8c05044475}\ (9 subtraces) (ID = 359513)
10:52 AM: Found Adware: abetterinternet
10:52 AM: HKLM\software\classes\typelib\{6d992911-b563-47fc-ab29-437f42d1c729}\ (9 subtraces) (ID = 359756)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\aurorahandler\ (3 subtraces) (ID = 360172)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\aurorahandler\ (21 subtraces) (ID = 360172)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\aurora\ (1 subtraces) (ID = 360174)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\aurora\ (1 subtraces) (ID = 360174)
10:52 AM: Found Adware: rich editor
10:52 AM: HKCR\lowsol.richeditor\ (5 subtraces) (ID = 372961)
10:52 AM: HKCR\typelib\{33add70f-53ab-4f97-b4b6-997881820f6d}\ (9 subtraces) (ID = 373009)
10:52 AM: HKLM\software\microsoft\windows\currentversion\app paths\richedtr\ (2 subtraces) (ID = 373109)
10:52 AM: HKLM\software\microsoft\windows\currentversion\app paths\richup\ || path (ID = 373114)
10:52 AM: HKLM\software\riched\ (12 subtraces) (ID = 373158)
10:52 AM: HKLM\software\classes\lowsol.richeditor\ (5 subtraces) (ID = 373176)
10:52 AM: HKLM\software\classes\typelib\{33add70f-53ab-4f97-b4b6-997881820f6d}\ (9 subtraces) (ID = 373224)
10:52 AM: HKCR\interface\{544b6a3f-4024-4403-9661-69b8410be505}\ (8 subtraces) (ID = 479497)
10:52 AM: HKCR\typelib\{6d992911-b563-47fc-ab29-437f42d1c729}\ (9 subtraces) (ID = 480791)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\aurorahandler\ (3 subtraces) (ID = 480802)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\aurorahandler\ (21 subtraces) (ID = 480802)
10:52 AM: Found Adware: drsnsrch hijacker
10:52 AM: HKU\S-1-5-21-1260153011-1797618588-3831952528-1006\software\dsrch\ (11 subtraces) (ID = 509156)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\aurorahandler\ || aut9i1m4eofsfinalad (ID = 512963)
10:52 AM: Registry Sweep Complete, Elapsed Time:00:00:16
10:52 AM: Starting Cookie Sweep
10:52 AM: Found Spy Cookie: abetterinternet cookie
10:52 AM: sr@abetterinternet[2].txt (ID = 2035)
10:52 AM: Found Spy Cookie: yieldmanager cookie
10:52 AM:
[email protected][1].txt (ID = 3751)
10:52 AM: Found Spy Cookie: hbmediapro cookie
10:52 AM:
[email protected][2].txt (ID = 2768)
10:52 AM: Found Spy Cookie: atwola cookie
10:52 AM: sr@atwola[1].txt (ID = 2255)
10:52 AM: Found Spy Cookie: a cookie
10:52 AM: sr@a[2].txt (ID = 2027)
10:52 AM: Found Spy Cookie: belnk cookie
10:52 AM: sr@belnk[1].txt (ID = 2292)
10:52 AM: Found Spy Cookie: btgrab cookie
10:52 AM:
[email protected][2].txt (ID = 2333)
10:52 AM: Found Spy Cookie: classmates cookie
10:52 AM: sr@classmates[1].txt (ID = 2384)
10:52 AM: Found Spy Cookie: cliks cookie
10:52 AM: sr@cliks[2].txt (ID = 2414)
10:52 AM:
[email protected][2].txt (ID = 2293)
10:52 AM: Found Spy Cookie: webservicehosts cookie
10:52 AM:
[email protected][2].txt (ID = 3663)
10:52 AM: Found Spy Cookie: kmpads cookie
10:52 AM: sr@kmpads[2].txt (ID = 2909)
10:52 AM: Found Spy Cookie: offeroptimizer cookie
10:52 AM: sr@offeroptimizer[2].txt (ID = 3087)
10:52 AM: Found Spy Cookie: touchclarity cookie
10:52 AM:
[email protected][1].txt (ID = 3567)
10:52 AM: Found Spy Cookie: partypoker cookie
10:52 AM: sr@partypoker[2].txt (ID = 3111)
10:52 AM: Found Spy Cookie: 64.62.232 cookie
10:52 AM:
[email protected][1].txt (ID = 1987)
10:52 AM:
[email protected][2].txt (ID = 1987)
10:52 AM:
[email protected][3].txt (ID = 1987)
10:52 AM:
[email protected][4].txt (ID = 1987)
10:52 AM:
[email protected][6].txt (ID = 1987)
10:52 AM: Found Spy Cookie: about cookie
10:52 AM: crr@about[1].txt (ID = 2037)
10:52 AM:
[email protected][2].txt (ID = 3751)
10:52 AM: Found Spy Cookie: adknowledge cookie
10:52 AM: crr@adknowledge[1].txt (ID = 2072)
10:52 AM:
[email protected][2].txt (ID = 2768)
10:52 AM: Found Spy Cookie: hotbar cookie
10:52 AM:
[email protected][2].txt (ID = 4207)
10:52 AM: Found Spy Cookie: searchingbooth cookie
10:52 AM:
[email protected][2].txt (ID = 3322)
10:52 AM: Found Spy Cookie: aff01511 cookie
10:52 AM: crr@aff01511[1].txt (ID = 2185)
10:52 AM: Found Spy Cookie: aff6007 cookie
10:52 AM: crr@aff6007[1].txt (ID = 2193)
10:52 AM: Found Spy Cookie: deskwizz cookie
10:52 AM:
[email protected][1].txt (ID = 2518)
10:52 AM: Found Spy Cookie: ask cookie
10:52 AM: crr@ask[1].txt (ID = 2245)
10:52 AM:
[email protected][2].txt (ID = 2293)
10:52 AM: crr@atwola[1].txt (ID = 2255)
10:52 AM: Found Spy Cookie: azjmp cookie
10:52 AM: crr@azjmp[2].txt (ID = 2270)
10:52 AM:
[email protected][1].txt (ID = 3322)
10:52 AM: crr@belnk[1].txt (ID = 2292)
10:52 AM: Found Spy Cookie: burstnet cookie
10:52 AM: crr@burstnet[2].txt (ID = 2336)
10:52 AM: Found Spy Cookie: top-banners cookie
10:52 AM:
[email protected][1].txt (ID = 3548)
10:52 AM: crr@classmates[2].txt (ID = 2384)
10:52 AM: Found Spy Cookie: directtrack cookie
10:52 AM: crr@directtrack[1].txt (ID = 2527)
10:52 AM:
[email protected][1].txt (ID = 2293)
10:52 AM:
[email protected][2].txt (ID = 3663)
10:52 AM: Found Spy Cookie: dutchmen cookie
10:52 AM: crr@Dutchmen[1].txt (ID = 2545)
10:52 AM: Found Spy Cookie: go.com cookie
10:52 AM:
[email protected][1].txt (ID = 2729)
10:52 AM: Found Spy Cookie: exitexchange cookie
10:52 AM: crr@exitexchange[1].txt (ID = 2633)
10:52 AM:
[email protected][1].txt (ID = 2038)
10:52 AM: crr@go[2].txt (ID = 2728)
10:52 AM: Found Spy Cookie: spywarelabs install cookie
10:52 AM:
[email protected][1].txt (ID = 3421)
10:52 AM: crr@kmpads[2].txt (ID = 2909)
10:52 AM: Found Spy Cookie: zango cookie
10:52 AM:
[email protected][1].txt (ID = 3761)
10:52 AM:
[email protected][1].txt (ID = 3548)
10:52 AM: Found Spy Cookie: mygeek cookie
10:52 AM: crr@mygeek[1].txt (ID = 3041)
10:52 AM: Found Spy Cookie: aptimus cookie
10:52 AM:
[email protected][2].txt (ID = 2235)
10:52 AM: crr@offeroptimizer[1].txt (ID = 3087)
10:52 AM:
[email protected][2].txt (ID = 3567)
10:52 AM: crr@partypoker[1].txt (ID = 3111)
10:52 AM: Found Spy Cookie: paypopup cookie
10:52 AM: crr@paypopup[1].txt (ID = 3119)
10:52 AM: Found Spy Cookie: rednova cookie
10:52 AM: crr@rednova[1].txt (ID = 3245)
10:52 AM:
[email protected][2].txt (ID = 2528)
10:52 AM:
[email protected][1].txt (ID = 2729)
10:52 AM:
[email protected][1].txt (ID = 2729)
10:52 AM: Found Spy Cookie: reliablestats cookie
10:52 AM:
[email protected][1].txt (ID = 3254)
10:52 AM: Found Spy Cookie: tracking cookie
10:52 AM: crr@tracking[2].txt (ID = 3571)
10:52 AM: Found Spy Cookie: epilot cookie
10:52 AM:
[email protected][1].txt (ID = 2622)
10:52 AM: Found Spy Cookie: finditlive cookie
10:52 AM:
[email protected][2].txt (ID = 2671)
10:52 AM: Found Spy Cookie: jumptothat cookie
10:52 AM:
[email protected][2].txt (ID = 2894)
10:52 AM: Found Spy Cookie: letitfind cookie
10:52 AM:
[email protected][1].txt (ID = 2919)
10:52 AM: Found Spy Cookie: seek-media cookie
10:52 AM:
[email protected][2].txt (ID = 3328)
10:52 AM: Found Spy Cookie: seek-zone cookie
10:52 AM:
[email protected][1].txt (ID = 3330)
10:52 AM: Found Spy Cookie: sidefind cookie
10:52 AM:
[email protected][2].txt (ID = 3374)
10:52 AM: Found Spy Cookie: wesearchall cookie
10:52 AM:
[email protected][1].txt (ID = 3684)
10:52 AM: Found Spy Cookie: ysbweb cookie
10:52 AM: crr@ysbweb[1].txt (ID = 3756)
10:52 AM: Found Spy Cookie: websponsors cookie
10:52 AM:
[email protected][2].txt (ID = 3665)
10:52 AM:
[email protected][2].txt (ID = 3751)
10:52 AM: rjr@adknowledge[2].txt (ID = 2072)
10:52 AM:
[email protected][1].txt (ID = 2768)
10:52 AM:
[email protected][1].txt (ID = 2293)
10:52 AM: rjr@atwola[2].txt (ID = 2255)
10:52 AM: rjr@belnk[2].txt (ID = 2292)
10:52 AM:
[email protected][1].txt (ID = 2293)
10:52 AM: Found Spy Cookie: clickandtrack cookie
10:52 AM:
[email protected][2].txt (ID = 2397)
10:52 AM: Found Spy Cookie: com.com cookie
10:52 AM:
[email protected][2].txt (ID = 2446)
10:52 AM: rjr@mygeek[1].txt (ID = 3041)
10:52 AM:
[email protected][2].txt (ID = 3567)
10:52 AM: rjr@partypoker[2].txt (ID = 3111)
10:52 AM: Found Spy Cookie: rn11 cookie
10:52 AM: rjr@rn11[2].txt (ID = 3261)
10:52 AM: Found Spy Cookie: rightmedia cookie
10:52 AM: jay@rightmedia[2].txt (ID = 3259)
10:52 AM: Cookie Sweep Complete, Elapsed Time: 00:00:05
10:52 AM: Starting File Sweep
10:52 AM: c:\documents and settings\crr\start menu\programs\power scan (1 subtraces) (ID = -2147480462)
10:52 AM: c:\documents and settings\crr\start menu\programs\addestroyer (1 subtraces) (ID = -2147481465)
10:52 AM: Found Adware: apropos
10:52 AM: c:\documents and settings\crr\local settings\temp\autoupdate0 (2 subtraces) (ID = -2147481415)
10:52 AM: Found Trojan Horse: trojan-downloader-bookedspace
10:52 AM: c:\windows\cfgmgr52 (95 subtraces) (ID = -2147479590)
10:52 AM: c:\documents and settings\crr\start menu\programs\virtual bouncer (3 subtraces) (ID = -2147480099)
10:52 AM: Found Adware: savenow - whenusave
10:52 AM: c:\documents and settings\crr\start menu\programs\whenu (3 subtraces) (ID = -2147480383)
10:52 AM: aurora[1].exe (ID = 115288)
10:52 AM: aurora[1].exe (ID = 115288)
10:52 AM: 00002179.dll (ID = 109657)
10:53 AM: 00002180.dll (ID = 109658)
10:53 AM: Found Adware: ezula ilookup
10:53 AM: b.com (ID = 60398)
10:53 AM: cassetup.exe (ID = 107221)
10:53 AM: istsvc[1].exe (ID = 107294)
10:53 AM: activex[1].ocx (ID = 93701)
10:53 AM: istrecover[1].exe (ID = 64496)
10:53 AM: poller[1].exe (ID = 116487)
10:53 AM: aurora[1].exe (ID = 115288)
10:53 AM: svcproc[1].exe (ID = 83533)
10:53 AM: sskknwrd.dll (ID = 77733)
10:53 AM: virtual bouncer.lnk (ID = 82843)
10:53 AM: Found Adware: java byteverify
10:53 AM: classload[1].jar (ID = 64817)
10:53 AM: Found Trojan Horse: trojan downloader pops-stop
10:53 AM: thin_installer[1].exe (ID = 109660)
10:53 AM: addestroyer.lnk (ID = 49032)
10:53 AM: addestroyer.lnk (ID = 49032)
10:53 AM: Found Adware: upspiral toolbar
10:53 AM: unist2.exe (ID = 82040)
10:53 AM: 00002178.exe (ID = 109659)
10:53 AM: Found Adware: navisearch
10:53 AM: nls8039[1].exe (ID = 111973)
10:53 AM: Found Trojan Horse: trojan-downloader-mainstreamdollars
10:53 AM: 00002183.exe (ID = 107491)
10:53 AM: drpmon[1].dll (ID = 83270)
10:53 AM: 0006_regular[1].cab (ID = 64478)
10:53 AM: protector[1].exe (ID = 59987)
10:53 AM: thin_installer.exe (ID = 109660)
10:53 AM: pcs_0029[1].exe (ID = 71761)
10:53 AM: 00002160.exe (ID = 95082)
10:53 AM: appwrap[1].exe (ID = 122598)
10:53 AM: banner.exe (ID = 83143)
10:53 AM: installer[1].exe (ID = 115471)
10:54 AM: Found Adware: cashback
10:54 AM: cb8040f[1].exe (ID = 110793)
10:54 AM: Found Adware: shopathomeselect
10:54 AM: sahinstaller[1].exe (ID = 115290)
10:54 AM: Found Adware: bargain buddy
10:54 AM: installer_marketing32.exe (ID = 50685)
10:54 AM: xboxab[1].ico (ID = 113921)
10:54 AM: sony%20psp1[1].ico (ID = 125992)
10:54 AM: 00002176.exe (ID = 113942)
10:54 AM: ssk3_b5 seedcorn 4.exe (ID = 77679)
10:54 AM: Found Adware: begin2search
10:54 AM: pinkkas21[1].ico (ID = 51041)
10:54 AM: guard.tmp (ID = 125214)
10:54 AM: virushunter4[1].ico (ID = 113920)
10:54 AM: aurorahandler[1].dll (ID = 111237)
10:54 AM: stubinstaller5041[1].ex_ (ID = 107355)
10:54 AM: abiuninst[1].exe (ID = 83089)
10:54 AM: abiuninst[1].htm (ID = 83087)
10:54 AM: mediagateway2 (ID = 121286)
10:54 AM: aproposclientinstaller[1].exe (ID = 116631)
10:54 AM: del5e.tmp (ID = 107355)
10:54 AM: istdownload[1].exe (ID = 110330)
10:54 AM: iinstall.exe (ID = 110330)
10:54 AM: ssk3_b5 seedcorn 4.exe (ID = 77679)
10:54 AM: sidefind[1].exe (ID = 107461)
10:54 AM: sidefind.exe (ID = 107461)
10:54 AM: sahagent[1].exe (ID = 115273)
10:54 AM: setup.inf (ID = 50158)
10:54 AM: umqltg4cl_.exe (ID = 75603)
10:54 AM: asfjkk32.tmp (ID = 109659)
10:55 AM: wrapperouter.exe (ID = 82854)
10:55 AM: webplugin[1].cab (ID = 107277)
10:55 AM: 00004367.exe (ID = 60440)
10:55 AM: 00002164.dll (ID = 120160)
10:55 AM: del156.tmp (ID = 107355)
10:55 AM: wrapperouter.exe (ID = 82854)
10:55 AM: mediagateway2 (ID = 121286)
10:55 AM: sskknwrd.dll (ID = 77733)
10:55 AM: aurora.exe (ID = 115288)
10:55 AM: Warning: Failed to read file "c:\windows\system32\tqpi3.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
10:55 AM: res157.tmp (ID = 107353)
10:55 AM: thinst94-1inst[1].exe (ID = 120269)
10:55 AM: resc.tmp (ID = 93785)
10:56 AM: appwrap[2].exe (ID = 114110)
10:56 AM: auf0.exe (ID = 116631)
10:56 AM: 00002172.exe (ID = 93622)
10:56 AM: Found Adware: clkoptimizer
10:56 AM: f178205593.exe (ID = 93646)
10:56 AM: cassetup.exe (ID = 107221)
10:56 AM: cassetup[1].exe (ID = 107221)
10:56 AM: ysb_regular[1].cab (ID = 121230)
10:56 AM: aurora[1].exe (ID = 115288)
10:56 AM: pcs_0006[1].exe (ID = 71761)
10:56 AM: 00002182.dll (ID = 75991)
10:56 AM: thin_installer.exe (ID = 109660)
10:56 AM: ysb[1].dll (ID = 91036)
10:57 AM: auto_update_install.exe (ID = 50058)
10:57 AM: 00002161.exe (ID = 120161)
10:57 AM: 180sainstallersilsais1.exe (ID = 107349)
10:57 AM: appwrap[1].exe (ID = 60398)
10:57 AM: autoupdaterinstaller[1].exe (ID = 50055)
10:57 AM: sidefind13[1].dll (ID = 76049)
10:57 AM: power scan.lnk (ID = 72676)
10:57 AM: res5f.tmp (ID = 107353)
10:57 AM: optimize[1].exe (ID = 64089)
10:57 AM: optimize.exe (ID = 64089)
10:57 AM: bb[1].exe (ID = 50567)
10:57 AM: bb.exe (ID = 50567)
10:57 AM: package_marketing27[1].exe (ID = 110382)
10:57 AM: pinkkas21.ico (ID = 51041)
10:57 AM: xboxab.ico (ID = 113921)
10:57 AM: sony psp1.ico (ID = 125992)
10:57 AM: stlb2.xml (ID = 51947)
10:57 AM: sahagent.exe (ID = 75884)
10:57 AM: virushunter4.ico (ID = 113920)
10:57 AM: sfbho13[1].dll (ID = 76029)
10:57 AM: Warning: Failed to read file "c:\windows\system32\nyobjapi.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
10:57 AM: 180sainstallernusalm.exe (ID = 93780)
10:57 AM: f87437437.exe (ID = 93646)
10:57 AM: sskcwrd.dll (ID = 77712)
10:57 AM: sskcwrd.dll (ID = 77712)
10:57 AM: Found Adware: sexfiles dialers
10:57 AM: dating.lnk (ID = 75396)
10:57 AM: Found Adware: moneytree
10:57 AM: nem220[1].dll (ID = 64043)
10:57 AM: Found Trojan Horse: topconverting downloader
10:57 AM: website[1].ocx (ID = 79658)
10:57 AM: Found Trojan Horse: downloadul
10:57 AM: ckwsfqqk.inf (ID = 59212)
10:57 AM: Found Adware: gain-supported software
10:57 AM: bundle.inf (ID = 61287)
10:57 AM: setup.inf (ID = 50870)
10:57 AM: auto_update[1].txt (ID = 50056)
10:57 AM: sf[1].txt (ID = 110126)
10:57 AM: nls[1].cfg (ID = 114713)
10:58 AM: File Sweep Complete, Elapsed Time: 00:05:40
10:58 AM: Full Sweep has completed. Elapsed time 00:07:42
10:58 AM: Traces Found: 1394
11:06 AM: Removal process initiated
11:07 AM: Quarantining All Traces: icannnews
11:07 AM: Warning: Could not create quarantine file for: C:\WINDOWS\SYSTEM32\tQpi3.dll File locked exclusively. Restoration will not be possible.
11:07 AM: Warning: Could not create quarantine file for: C:\WINDOWS\SYSTEM32\nyobjapi.dll File locked exclusively. Restoration will not be possible.
11:07 AM: icannnews is in use. It will be removed on reboot.
11:07 AM: C:\WINDOWS\SYSTEM32\tQpi3.dll is in use. It will be removed on reboot.
11:07 AM: C:\WINDOWS\SYSTEM32\nyobjapi.dll is in use. It will be removed on reboot.
11:07 AM: Quarantining All Traces: addestroyer
11:07 AM: Quarantining All Traces: bookedspace
11:07 AM: Quarantining All Traces: browseraid
11:07 AM: Quarantining All Traces: cas
11:07 AM: Quarantining All Traces: clearsearch
11:07 AM: Quarantining All Traces: elitebar
11:07 AM: Quarantining All Traces: elitebar searchmiracle hijacker
11:07 AM: Quarantining All Traces: ieplugin
11:07 AM: Quarantining All Traces: drsnsrch.com hijack
11:07 AM: Quarantining All Traces: internetoptimizer
11:07 AM: Quarantining All Traces: istbar
11:07 AM: Quarantining All Traces: lopdotcom
11:07 AM: Quarantining All Traces: 180search assistant/zango
11:08 AM: Quarantining All Traces: trojan-downloader-pacisoft
11:08 AM: Quarantining All Traces: powerscan
11:08 AM: Quarantining All Traces: redzip toolbar
11:08 AM: Quarantining All Traces: sc-keylog
11:08 AM: Quarantining All Traces: searchtoolbar
11:08 AM: Quarantining All Traces: bho_sidefind
11:08 AM: Quarantining All Traces: surfsidekick
11:08 AM: Quarantining All Traces: trojan-backdoor-soundcheck
11:08 AM: Quarantining All Traces: virtualbouncer
11:08 AM: Quarantining All Traces: winad
11:08 AM: Quarantining All Traces: yoursitebar
11:08 AM: Quarantining All Traces: shopnavupdater
11:08 AM: Quarantining All Traces: abetterinternet
11:08 AM: Quarantining All Traces: rich editor
11:08 AM: Quarantining All Traces: drsnsrch hijacker
11:08 AM: Quarantining All Traces: abetterinternet cookie
11:08 AM: Quarantining All Traces: yieldmanager cookie
11:08 AM: Quarantining All Traces: hbmediapro cookie
11:08 AM: Quarantining All Traces: atwola cookie
11:08 AM: Quarantining All Traces: a cookie
11:08 AM: Quarantining All Traces: belnk cookie
11:08 AM: Quarantining All Traces: btgrab cookie
11:08 AM: Quarantining All Traces: classmates cookie
11:08 AM: Quarantining All Traces: cliks cookie
11:08 AM: Quarantining All Traces: webservicehosts cookie
11:08 AM: Quarantining All Traces: kmpads cookie
11:08 AM: Quarantining All Traces: offeroptimizer cookie
11:08 AM: Quarantining All Traces: touchclarity cookie
11:08 AM: Quarantining All Traces: partypoker cookie
11:08 AM: Quarantining All Traces: 64.62.232 cookie
11:08 AM: Quarantining All Traces: about cookie
11:08 AM: Quarantining All Traces: adknowledge cookie
11:08 AM: Quarantining All Traces: hotbar cookie
11:08 AM: Quarantining All Traces: searchingbooth cookie
11:08 AM: Quarantining All Traces: aff01511 cookie
11:08 AM: Quarantining All Traces: aff6007 cookie
11:08 AM: Quarantining All Traces: deskwizz cookie
11:08 AM: Quarantining All Traces: ask cookie
11:08 AM: Quarantining All Traces: azjmp cookie
11:08 AM: Quarantining All Traces: burstnet cookie
11:08 AM: Quarantining All Traces: top-banners cookie
11:08 AM: Quarantining All Traces: directtrack cookie
11:08 AM: Quarantining All Traces: dutchmen cookie
11:08 AM: Quarantining All Traces: go.com cookie
11:08 AM: Quarantining All Traces: exitexchange cookie
11:08 AM: Quarantining All Traces: spywarelabs install cookie
11:08 AM: Quarantining All Traces: zango cookie
11:08 AM: Quarantining All Traces: mygeek cookie
11:08 AM: Quarantining All Traces: aptimus cookie
11:08 AM: Quarantining All Traces: paypopup cookie
11:08 AM: Quarantining All Traces: rednova cookie
11:08 AM: Quarantining All Traces: reliablestats cookie
11:08 AM: Quarantining All Traces: tracking cookie
11:08 AM: Quarantining All Traces: epilot cookie
11:08 AM: Quarantining All Traces: finditlive cookie
11:08 AM: Quarantining All Traces: jumptothat cookie
11:08 AM: Quarantining All Traces: letitfind cookie
11:08 AM: Quarantining All Traces: seek-media cookie
11:08 AM: Quarantining All Traces: seek-zone cookie
11:08 AM: Quarantining All Traces: sidefind cookie
11:08 AM: Quarantining All Traces: wesearchall cookie
11:08 AM: Quarantining All Traces: ysbweb cookie
11:08 AM: Quarantining All Traces: websponsors cookie
11:08 AM: Quarantining All Traces: clickandtrack cookie
11:08 AM: Quarantining All Traces: com.com cookie
11:08 AM: Quarantining All Traces: rn11 cookie
11:08 AM: Quarantining All Traces: rightmedia cookie
11:08 AM: Quarantining All Traces: apropos
11:09 AM: Quarantining All Traces: trojan-downloader-bookedspace
11:09 AM: Quarantining All Traces: savenow - whenusave
11:09 AM: Quarantining All Traces: ezula ilookup
11:09 AM: Quarantining All Traces: java byteverify
11:09 AM: Quarantining All Traces: trojan downloader pops-stop
11:09 AM: Quarantining All Traces: upspiral toolbar
11:09 AM: Quarantining All Traces: navisearch
11:09 AM: Quarantining All Traces: trojan-downloader-mainstreamdollars
11:09 AM: Quarantining All Traces: cashback
11:09 AM: Quarantining All Traces: shopathomeselect
11:09 AM: Quarantining All Traces: bargain buddy
11:09 AM: Quarantining All Traces: begin2search
11:09 AM: Quarantining All Traces: clkoptimizer
11:09 AM: Quarantining All Traces: sexfiles dialers
11:09 AM: Quarantining All Traces: moneytree
11:09 AM: Quarantining All Traces: topconverting downloader
11:09 AM: Quarantining All Traces: downloadul
11:09 AM: Quarantining All Traces: gain-supported software
11:09 AM: Warning: Quarantine could not read registry value for HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\aurorahandler\aut9i1m4eofsfinalad\. Failed to export registry value "WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\aurorahandler\aut9i1m4eofsfinalad". Key/Value does not exist
11:11 AM: Removal process completed. Elapsed time 00:04:48
********
Kaspersky:
10:49 AM: |··· Start of Session, Saturday, August 06, 2005 ···|
10:49 AM: Spy Sweeper started
10:49 AM: Your spyware definitions have been updated.
10:50 AM: |··· End of Session, Saturday, August 06, 2005 ···|
11:16 AM: |··· Start of Session, Saturday, August 06, 2005 ···|
11:16 AM: Spy Sweeper started
11:16 AM: Sweep initiated using definitions version 511
11:17 AM: Starting Memory Sweep
11:17 AM: Warning: Failed to check file "C:\WINDOWS\SYSTEM32\reched20.dll". Cannot open file "C:\WINDOWS\SYSTEM32\reched20.dll". The process cannot access the file because it is being used by another process
11:17 AM: Found Adware: icannnews
11:17 AM: Detected running threat: C:\WINDOWS\SYSTEM32\reched20.dll (ID = 51)
11:17 AM: Warning: Failed to check file "C:\WINDOWS\SYSTEM32\tQpi3.dll". Cannot open file "C:\WINDOWS\SYSTEM32\tQpi3.dll". The process cannot access the file because it is being used by another process
11:17 AM: Detected running threat: C:\WINDOWS\SYSTEM32\tQpi3.dll (ID = 51)
11:18 AM: Warning: Failed to check file "C:\WINDOWS\SYSTEM32\reched20.dll". Cannot open file "C:\WINDOWS\SYSTEM32\reched20.dll". The process cannot access the file because it is being used by another process
11:18 AM: Memory Sweep Complete, Elapsed Time: 00:01:30
11:18 AM: Starting Registry Sweep
11:18 AM: Registry Sweep Complete, Elapsed Time:00:00:12
11:18 AM: Starting Cookie Sweep
11:18 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
11:18 AM: Starting File Sweep
11:19 AM: Warning: Failed to read file "c:\windows\temp\perflib_perfdata_5cc.dat". System Error. Code: 32.
The process cannot access the file because it is being used by another process
11:19 AM: Found Adware: upspiral toolbar
11:19 AM: 00004782.exe (ID = 82040)
11:20 AM: Warning: Failed to read file "c:\windows\system32\reched20.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
11:21 AM: Warning: Failed to read file "c:\windows\system32\tqpi3.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
11:22 AM: __delete_on_reboot__sarvdeps.dll (ID = 125214)
11:23 AM: Found Adware: begin2search
11:23 AM: 00004798.ico (ID = 51041)
11:23 AM: Found Trojan Horse: trojan-downloader-pacisoft
11:23 AM: 00004424.ico (ID = 113921)
11:23 AM: 00004422.ico (ID = 125992)
11:23 AM: Found Adware: browseraid
11:23 AM: 00004390.xml (ID = 51947)
11:23 AM: 00004420.ico (ID = 113920)
11:23 AM: Found Trojan Horse: downloadul
11:23 AM: 00004807.inf (ID = 59212)
11:23 AM: File Sweep Complete, Elapsed Time: 00:05:06
11:23 AM: Full Sweep has completed. Elapsed time 00:06:59
11:23 AM: Traces Found: 10
11:25 AM: Removal process initiated
11:25 AM: Quarantining All Traces: icannnews
11:25 AM: Warning: Could not create quarantine file for: C:\WINDOWS\SYSTEM32\reched20.dll File locked exclusively. Restoration will not be possible.
11:25 AM: Warning: Could not create quarantine file for: C:\WINDOWS\SYSTEM32\tQpi3.dll File locked exclusively. Restoration will not be possible.
11:25 AM: icannnews is in use. It will be removed on reboot.
11:25 AM: C:\WINDOWS\SYSTEM32\reched20.dll is in use. It will be removed on reboot.
11:25 AM: C:\WINDOWS\SYSTEM32\tQpi3.dll is in use. It will be removed on reboot.
11:25 AM: Quarantining All Traces: upspiral toolbar
11:25 AM: Quarantining All Traces: begin2search
11:25 AM: Quarantining All Traces: trojan-downloader-pacisoft
11:25 AM: Quarantining All Traces: browseraid
11:25 AM: Quarantining All Traces: downloadul
11:25 AM: Warning: Quarantine process could not restart Explorer.
11:26 AM: Removal process completed. Elapsed time 00:01:18
********
10:50 AM: |··· Start of Session, Saturday, August 06, 2005 ···|
10:50 AM: Spy Sweeper started
10:50 AM: Sweep initiated using definitions version 511
10:50 AM: Starting Memory Sweep
10:51 AM: Warning: Failed to check file "C:\WINDOWS\SYSTEM32\tQpi3.dll". Cannot open file "C:\WINDOWS\SYSTEM32\tQpi3.dll". The process cannot access the file because it is being used by another process
10:51 AM: Found Adware: icannnews
10:51 AM: Detected running threat: C:\WINDOWS\SYSTEM32\tQpi3.dll (ID = 51)
10:51 AM: Warning: Failed to check file "C:\WINDOWS\SYSTEM32\nyobjapi.dll". Cannot open file "C:\WINDOWS\SYSTEM32\nyobjapi.dll". The process cannot access the file because it is being used by another process
10:51 AM: Detected running threat: C:\WINDOWS\SYSTEM32\nyobjapi.dll (ID = 51)
10:52 AM: Memory Sweep Complete, Elapsed Time: 00:01:30
10:52 AM: Starting Registry Sweep
10:52 AM: Found Adware: addestroyer
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\vb and vba program settings\addestroyer\ (3 subtraces) (ID = 102749)
10:52 AM: Found Adware: bookedspace
10:52 AM: HKLM\software\configuration manager\cfgmgr52\ (312 subtraces) (ID = 104873)
10:52 AM: Found Adware: browseraid
10:52 AM: HKU\S-1-5-21-1260153011-1797618588-3831952528-1006\software\a70f6a1d-0195-42a2-934c-d8ac0f7c08eb\ (1 subtraces) (ID = 105078)
10:52 AM: Found Adware: cas
10:52 AM: HKCR\typelib\{d4c89c18-b4f3-46a9-8800-e9e7a55afbd9}\ (9 subtraces) (ID = 105366)
10:52 AM: HKLM\software\classes\typelib\{d4c89c18-b4f3-46a9-8800-e9e7a55afbd9}\ (9 subtraces) (ID = 105369)
10:52 AM: Found Adware: clearsearch
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\microsoft\internet explorer\new windows\allow\ || 69.28.210.175 (ID = 105744)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\new windows\allow\ || 69.28.210.175 (ID = 105744)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\microsoft\internet explorer\new windows\allow\ || 69.28.210.175 (ID = 105744)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\microsoft\internet explorer\new windows\allow\ || 69.28.210.175 (ID = 105744)
10:52 AM: Found Adware: elitebar
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\lq\ (22 subtraces) (ID = 125741)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\lq\ (22 subtraces) (ID = 125741)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\lq\ (22 subtraces) (ID = 125741)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1010\software\lq\ (5 subtraces) (ID = 125741)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1011\software\lq\ (22 subtraces) (ID = 125741)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\lq\ (22 subtraces) (ID = 125741)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\microsoft\internet explorer\toolbar\webbrowser\ || {825cf5bd-8862-4430-b771-0c15c5ca8def} (ID = 125745)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\toolbar\webbrowser\ || {825cf5bd-8862-4430-b771-0c15c5ca8def} (ID = 125745)
10:52 AM: Found Adware: elitebar searchmiracle hijacker
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\ || searchurl (ID = 125775)
10:52 AM: Found Adware: ieplugin
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\intexp\ (7 subtraces) (ID = 128173)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\intexp\ (2 subtraces) (ID = 128173)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\intexp\ (2 subtraces) (ID = 128173)
10:52 AM: HKLM\software\microsoft\internet explorer\toolbar\ || {2cde1a7d-a478-4291-bf31-e1b4c16f92eb} (ID = 128178)
10:52 AM: Found Adware: drsnsrch.com hijack
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\main\ || search bar (ID = 128206)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\microsoft\internet explorer\main\ || search page (ID = 128207)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\main\ || search page (ID = 128207)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\microsoft\internet explorer\searchurl\ (2 subtraces) (ID = 128212)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\searchurl\ (2 subtraces) (ID = 128212)
10:52 AM: Found Adware: internetoptimizer
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\avenue media\ (ID = 128887)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\avenue media\ (ID = 128887)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\avenue media\ (7 subtraces) (ID = 128887)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1011\software\avenue media\ (6 subtraces) (ID = 128887)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\avenue media\ (11 subtraces) (ID = 128887)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\policies\avenue media\ (ID = 128928)
10:52 AM: Found Adware: istbar
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\ist\ (1 subtraces) (ID = 129108)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\ist\ (5 subtraces) (ID = 129108)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\ist\ (1 subtraces) (ID = 129108)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\ist\ (1 subtraces) (ID = 129108)
10:52 AM: Found Adware: lopdotcom
10:52 AM: HKU\S-1-5-18\software\microsoft\windows\currentversion\run\ || aida (ID = 130496)
10:52 AM: Found Adware: 180search assistant/zango
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\sais\ (11 subtraces) (ID = 135790)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\sais\ (14 subtraces) (ID = 135790)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\sais\ (22 subtraces) (ID = 135790)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\sais\ (19 subtraces) (ID = 135790)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\salm\ (11 subtraces) (ID = 135792)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1011\software\salm\ (19 subtraces) (ID = 135792)
10:52 AM: Found Trojan Horse: trojan-downloader-pacisoft
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\psof1\ (15 subtraces) (ID = 136530)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\psof1\ (16 subtraces) (ID = 136530)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\psof1\ (2 subtraces) (ID = 136530)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\psof1\ (2 subtraces) (ID = 136530)
10:52 AM: Found Adware: powerscan
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\powerscan\ (ID = 136823)
10:52 AM: Found Adware: redzip toolbar
10:52 AM: HKU\S-1-5-21-1260153011-1797618588-3831952528-1006\software\microsoft\windows\currentversion\explorer\ || insid (ID = 139328)
10:52 AM: Found System Monitor: sc-keylog
10:52 AM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\explorer\ (6 subtraces) (ID = 140468)
10:52 AM: Found Adware: searchtoolbar
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\{12ee7a5e-0674-42f9-a76b-000000004d00}\ (3 subtraces) (ID = 141347)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1010\software\{12ee7a5e-0674-42f9-a76b-000000004d00}\ (3 subtraces) (ID = 141347)
10:52 AM: Found Adware: bho_sidefind
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\explorer bars\{8cba1b49-8144-4721-a7b1-64c578c9eed7}\ (1 subtraces) (ID = 141777)
10:52 AM: HKU\S-1-5-21-1260153011-1797618588-3831952528-1006\software\microsoft\internet explorer\extensions\cmdmapping\ || {10e42047-deb9-4535-a118-b3f6ec39b807} (ID = 141778)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\microsoft\internet explorer\extensions\cmdmapping\ || {10e42047-deb9-4535-a118-b3f6ec39b807} (ID = 141778)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\extensions\cmdmapping\ || {10e42047-deb9-4535-a118-b3f6ec39b807} (ID = 141778)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\microsoft\internet explorer\extensions\cmdmapping\ || {10e42047-deb9-4535-a118-b3f6ec39b807} (ID = 141778)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\microsoft\internet explorer\extensions\cmdmapping\ || {10e42047-deb9-4535-a118-b3f6ec39b807} (ID = 141778)
10:52 AM: Found Adware: surfsidekick
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\urlsearchhooks\ || {02ee5b04-f144-47bb-83fb-a60bd91b74a9} (ID = 143397)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\windows\currentversion\run\ || surfsidekick 3 (ID = 143403)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\surfsidekick3\ (3 subtraces) (ID = 143412)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\surfsidekick3\ (3 subtraces) (ID = 143412)
10:52 AM: Found Trojan Horse: trojan-backdoor-soundcheck
10:52 AM: HKLM\system\currentcontrolset\services\msdirectx\ (7 subtraces) (ID = 144200)
10:52 AM: Found Adware: virtualbouncer
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1007\software\vb and vba program settings\vbouncer\ (8 subtraces) (ID = 145564)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\vb and vba program settings\vbouncer\ (8 subtraces) (ID = 145564)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1009\software\vb and vba program settings\vbouncer\ (7 subtraces) (ID = 145564)
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-501\software\vb and vba program settings\vbouncer\ (7 subtraces) (ID = 145564)
10:52 AM: Found Adware: winad
10:52 AM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediaaccx.dll\ (2 subtraces) (ID = 147191)
10:52 AM: Found Adware: yoursitebar
10:52 AM: HKU\WRSS_Profile_S-1-5-21-1260153011-1797618588-3831952528-1008\software\microsoft\internet explorer\toolbar\webbrowser\ || {86227d9c-0efe-4f8a-aa55-30386a3f5686} (ID = 147853)
10:52 AM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\ysbactivex.dll (ID = 147857)
10:52 AM: HKLM\software\yoursitebar\ (6 subtraces) (ID = 147860)
10:52 AM: HKCR\activexctrl\ (3 subtraces) (ID = 169450)
10:52 AM: HKCR\interface\{980ad470-04ea-4d1d-bd26-e178b7bda6d8}\ (8 subtraces) (ID = 169454)
10:52 AM: HKCR\interface\{fd39937a-c583-4aac-9332-8a3e44988a67}\ (8 subtraces) (ID = 169455)
10:52 AM: HKCR\typelib\{ee5ac3d6-6f43-4047-af0a-d66fc2cf8f42}\ (9 subtraces) (ID = 169456)
10:52 AM: HKLM\software\classes\activexctrl\ (3 subtraces) (ID = 169457)
10:52 AM: HKLM\software\classes\interface\{980ad470-04ea-4d1d-bd26-e178b7bda6d8}\ (8 subtraces) (ID = 169461)
10:52 AM: H