Sessions log posted as follows BUT now I have a problem because the Spy Sweeper said:
: "Spy sweeper successfully removed a known IE hijacker. If it seems your IE ssettings such as your home page or searching capabilities have not improved, follow these steps to fix the issue:
1) Click Shields
2) Click IE tab
3) Click reset IE page settings to Defaults
Then I did the above instructions because I thought I read it said to do it , not IF the settings have not improved , and NOW I keep getting a window that says my HOSTs settings were changed. Also, my McAfee icon shows disabled, it is now black even though McAfee is running according to the Security center.
I am posting the 2nd spy sweeper as well, after IE settings were restored to defaults. Also am posting HOSTS notepad.
What should I do?
********
First spy sweeper session6:59 PM: |··· Start of Session, Thursday, August 11, 2005 ···|
6:59 PM: Spy Sweeper started
6:59 PM: Sweep initiated using definitions version 514
6:59 PM: Starting Memory Sweep
7:06 PM: Memory Sweep Complete, Elapsed Time: 00:06:50
7:06 PM: Starting Registry Sweep
7:06 PM: Found Trojan Horse: 2nd-thought
7:06 PM: HKCR\interface\{6e0ed53c-9908-49ed-b055-7cb31b162577}\ (7 subtraces) (ID = 101978)
7:06 PM: HKCR\interface\{8c53bd8e-b12d-4c8f-ad0e-c9ddc39d1273}\ (8 subtraces) (ID = 101979)
7:06 PM: HKCR\interface\{9bcdd51b-4a7b-446c-8452-d32d38004582}\ (7 subtraces) (ID = 101980)
7:06 PM: HKCR\interface\{49db48ff-02b5-4645-b676-94a4df1aa026}\ (7 subtraces) (ID = 101981)
7:06 PM: HKCR\interface\{830d3aed-2fa9-454f-b266-d931862bbf34}\ (7 subtraces) (ID = 101982)
7:06 PM: HKCR\interface\{a986f4db-792e-4571-8974-0bb6e024766f}\ (7 subtraces) (ID = 101983)
7:06 PM: HKCR\interface\{bccab53d-0895-40c3-a942-a03538ce227a}\ (7 subtraces) (ID = 101984)
7:06 PM: HKCR\interface\{c0f88e9e-dceb-4655-968a-ae508a677c39}\ (7 subtraces) (ID = 101985)
7:07 PM: HKCR\interface\{d7eac2d8-2d52-4010-a4ad-dfdf60c1706c}\ (7 subtraces) (ID = 101986)
7:07 PM: HKLM\software\classes\interface\{6e0ed53c-9908-49ed-b055-7cb31b162577}\ (7 subtraces) (ID = 101993)
7:07 PM: HKLM\software\classes\interface\{8c53bd8e-b12d-4c8f-ad0e-c9ddc39d1273}\ (8 subtraces) (ID = 101994)
7:07 PM: HKLM\software\classes\interface\{9bcdd51b-4a7b-446c-8452-d32d38004582}\ (7 subtraces) (ID = 101995)
7:07 PM: HKLM\software\classes\interface\{49db48ff-02b5-4645-b676-94a4df1aa026}\ (7 subtraces) (ID = 101996)
7:07 PM: HKLM\software\classes\interface\{830d3aed-2fa9-454f-b266-d931862bbf34}\ (7 subtraces) (ID = 101997)
7:07 PM: HKLM\software\classes\interface\{a986f4db-792e-4571-8974-0bb6e024766f}\ (7 subtraces) (ID = 101998)
7:07 PM: HKLM\software\classes\interface\{bccab53d-0895-40c3-a942-a03538ce227a}\ (7 subtraces) (ID = 101999)
7:07 PM: HKLM\software\classes\interface\{c0f88e9e-dceb-4655-968a-ae508a677c39}\ (7 subtraces) (ID = 102000)
7:07 PM: HKLM\software\classes\interface\{d7eac2d8-2d52-4010-a4ad-dfdf60c1706c}\ (7 subtraces) (ID = 102001)
7:07 PM: Found Adware: addestroyer
7:07 PM: HKCR\clsid\{417386c3-8d4a-4611-9b91-e57e89d603ac}\ (13 subtraces) (ID = 102728)
7:07 PM: HKCR\clsid\{d52433a9-a44c-43ab-a013-24b3c756dd2b}\ (13 subtraces) (ID = 102729)
7:07 PM: HKCR\interface\{10d7db96-56dc-4617-8eab-ec506abe6c7e}\ (8 subtraces) (ID = 102730)
7:07 PM: HKCR\interface\{6cdc3337-01f7-4a79-a4af-0b19303cc0be}\ (8 subtraces) (ID = 102732)
7:07 PM: HKCR\interface\{795398d0-dc2f-4118-a69c-592273ba9c2b}\ (8 subtraces) (ID = 102733)
7:07 PM: HKCR\interface\{b288f21c-a144-4ca2-9b70-8afa1fae4b06}\ (8 subtraces) (ID = 102734)
7:07 PM: HKCR\popoops2.popoops\ (3 subtraces) (ID = 102735)
7:07 PM: HKCR\swlad1.swlad\ (3 subtraces) (ID = 102736)
7:07 PM: HKLM\software\classes\clsid\{417386c3-8d4a-4611-9b91-e57e89d603ac}\ (13 subtraces) (ID = 102737)
7:07 PM: HKLM\software\classes\clsid\{d52433a9-a44c-43ab-a013-24b3c756dd2b}\ (13 subtraces) (ID = 102738)
7:07 PM: HKLM\software\classes\interface\{10d7db96-56dc-4617-8eab-ec506abe6c7e}\ (8 subtraces) (ID = 102739)
7:07 PM: HKLM\software\classes\interface\{6cdc3337-01f7-4a79-a4af-0b19303cc0be}\ (8 subtraces) (ID = 102741)
7:07 PM: HKLM\software\classes\interface\{795398d0-dc2f-4118-a69c-592273ba9c2b}\ (8 subtraces) (ID = 102742)
7:07 PM: HKLM\software\classes\interface\{b288f21c-a144-4ca2-9b70-8afa1fae4b06}\ (8 subtraces) (ID = 102743)
7:07 PM: HKLM\software\classes\popoops2.popoops\ (3 subtraces) (ID = 102744)
7:07 PM: HKLM\software\classes\swlad1.swlad\ (3 subtraces) (ID = 102745)
7:07 PM: HKLM\software\classes\typelib\{d0c29a75-7146-4737-98ee-bc4d7cf44af9}\ (9 subtraces) (ID = 102746)
7:07 PM: HKLM\software\classes\typelib\{e0d3b292-a0b0-4640-975c-2f882e039f52}\ (9 subtraces) (ID = 102747)
7:07 PM: HKCR\typelib\{d0c29a75-7146-4737-98ee-bc4d7cf44af9}\ (9 subtraces) (ID = 102750)
7:07 PM: HKCR\typelib\{e0d3b292-a0b0-4640-975c-2f882e039f52}\ (9 subtraces) (ID = 102751)
7:07 PM: Found Adware: delfin
7:07 PM: HKCR\clsid\{a8bd9566-9895-4fa3-918d-a51d4cd15865}\ (3 subtraces) (ID = 124837)
7:07 PM: HKCR\clsid\{d0070620-1e72-42e7-a14c-3a255ad31839}\ (21 subtraces) (ID = 124838)
7:07 PM: HKCR\interface\{2bb15d36-43be-4743-a3a0-3308f4b1a610}\ (8 subtraces) (ID = 124839)
7:07 PM: HKCR\interface\{41700749-a109-4254-af13-be54011e8783}\ (8 subtraces) (ID = 124840)
7:07 PM: HKLM\software\classes\clsid\{a8bd9566-9895-4fa3-918d-a51d4cd15865}\ (3 subtraces) (ID = 124841)
7:07 PM: HKLM\software\classes\clsid\{d0070620-1e72-42e7-a14c-3a255ad31839}\ (21 subtraces) (ID = 124842)
7:07 PM: HKLM\software\classes\interface\{2bb15d36-43be-4743-a3a0-3308f4b1a610}\ (8 subtraces) (ID = 124843)
7:07 PM: HKLM\software\classes\interface\{41700749-a109-4254-af13-be54011e8783}\ (8 subtraces) (ID = 124844)
7:07 PM: HKLM\software\classes\typelib\{2a7db8d1-43be-4ad3-a81e-9bb8c9d00073}\ (9 subtraces) (ID = 124845)
7:07 PM: HKLM\software\classes\vccpgdataaccess.pgdataaccessctrl.1\ (3 subtraces) (ID = 124846)
7:07 PM: HKLM\software\microsoft\windows\currentversion\uninstall\pgate\ (2 subtraces) (ID = 124881)
7:07 PM: HKU\S-1-5-21-1948358126-1296844153-3270823822-1006\software\pcsv\ (5 subtraces) (ID = 124887)
7:07 PM: HKLM\software\pcsv\ (6 subtraces) (ID = 124888)
7:07 PM: HKCR\typelib\{2a7db8d1-43be-4ad3-a81e-9bb8c9d00073}\ (9 subtraces) (ID = 124899)
7:07 PM: HKCR\vccpgdataaccess.pgdataaccessctrl.1\ (3 subtraces) (ID = 124900)
7:08 PM: Found Adware: squire webhelper
7:08 PM: HKCR\typelib\{805af2c8-98c7-4f3c-a7c9-25ebf27567f3}\ (9 subtraces) (ID = 142155)
7:08 PM: HKLM\software\classes\typelib\{805af2c8-98c7-4f3c-a7c9-25ebf27567f3}\ (9 subtraces) (ID = 142176)
7:08 PM: HKLM\software\microsoft\windows\currentversion\uninstall\sqwire\ (2 subtraces) (ID = 142190)
7:08 PM: Found Adware: websearch toolbar
7:08 PM: HKLM\software\microsoft\windows\currentversion\installer\userdata\aui\ (1 subtraces) (ID = 146479)
7:08 PM: HKCR\popoops2.popoops\ (3 subtraces) (ID = 466854)
7:08 PM: HKCR\popoops2.popoops\ (3 subtraces) (ID = 466855)
7:08 PM: HKCR\popoops2.popoops\clsid\ (1 subtraces) (ID = 466856)
7:08 PM: HKLM\software\classes\popoops2.popoops\ (3 subtraces) (ID = 466858)
7:08 PM: HKLM\software\classes\popoops2.popoops\ (3 subtraces) (ID = 466859)
7:08 PM: HKLM\software\classes\popoops2.popoops\clsid\ (1 subtraces) (ID = 466860)
7:08 PM: Registry Sweep Complete, Elapsed Time:00:01:17
7:08 PM: Starting Cookie Sweep
7:08 PM: Found Spy Cookie: websponsors cookie
7:08 PM: cheryl
[email protected][2].txt (ID = 3665)
7:08 PM: Found Spy Cookie: yieldmanager cookie
7:08 PM: cheryl
[email protected][2].txt (ID = 3751)
7:08 PM: Found Spy Cookie: specificclick.com cookie
7:08 PM: cheryl
[email protected][2].txt (ID = 3400)
7:08 PM: Found Spy Cookie: adrevolver cookie
7:08 PM: cheryl tasciotti@adrevolver[1].txt (ID = 2088)
7:08 PM: cheryl tasciotti@adrevolver[3].txt (ID = 2088)
7:08 PM: Found Spy Cookie: belointeractive cookie
7:08 PM: cheryl
[email protected][2].txt (ID = 2295)
7:08 PM: Found Spy Cookie: falkag cookie
7:08 PM: cheryl
[email protected][2].txt (ID = 2650)
7:08 PM: Found Spy Cookie: ask cookie
7:08 PM: cheryl tasciotti@ask[1].txt (ID = 2245)
7:08 PM: Found Spy Cookie: atwola cookie
7:08 PM: cheryl tasciotti@atwola[1].txt (ID = 2255)
7:08 PM: Found Spy Cookie: bannerspace cookie
7:08 PM: cheryl tasciotti@bannerspace[1].txt (ID = 2284)
7:08 PM: Found Spy Cookie: banner cookie
7:08 PM: cheryl tasciotti@banner[1].txt (ID = 2276)
7:08 PM: cheryl tasciotti@belointeractive[1].txt (ID = 2294)
7:08 PM: Found Spy Cookie: bs.serving-sys cookie
7:08 PM: cheryl
[email protected][1].txt (ID = 2330)
7:08 PM: Found Spy Cookie: burstnet cookie
7:08 PM: cheryl tasciotti@burstnet[1].txt (ID = 2336)
7:08 PM: Found Spy Cookie: zedo cookie
7:08 PM: cheryl
[email protected][1].txt (ID = 3763)
7:08 PM: cheryl
[email protected][1].txt (ID = 2295)
7:08 PM: Found Spy Cookie: iwon cookie
7:08 PM: cheryl tasciotti@iwon[2].txt (ID = 2883)
7:08 PM: Found Spy Cookie: serving-sys cookie
7:08 PM: cheryl tasciotti@serving-sys[2].txt (ID = 3343)
7:08 PM: cheryl tasciotti@zedo[2].txt (ID = 3762)
7:08 PM: Cookie Sweep Complete, Elapsed Time: 00:00:02
7:08 PM: Starting File Sweep
7:08 PM: c:\program files\common files\dpi (ID = -2147481129)
7:08 PM: c:\documents and settings\all users\application data\pcsvc (19 subtraces) (ID = -2147481135)
7:08 PM: Found Adware: clearsearch
7:08 PM: c:\program files\clearsearch (1 subtraces) (ID = -2147481257)
7:08 PM: Found Adware: keenvalue/perfectnav
7:08 PM: c:\program files\common files\updater (ID = -2147480788)
7:08 PM: c:\windows\system32\pcs (1 subtraces) (ID = -2147481121)
7:08 PM: Found Adware: apropos
7:08 PM: c:\program files\sysai (ID = -2147481417)
7:08 PM: Found Adware: targetsoft
7:08 PM: c:\program files\target soft (1 subtraces) (ID = -2147480166)
7:09 PM: Found Adware: keyhost hijacker - jraun
7:09 PM: keyactivextest.ocx (ID = 65153)
7:09 PM: ink_inkline023-t.dfn (ID = 57718)
7:09 PM: delfinst.ebd (ID = 57692)
7:09 PM: delfintg.ebd (ID = 57693)
7:09 PM: delfinlo.ebd (ID = 57687)
7:10 PM: Found Adware: mindset interactive - favoriteman
7:10 PM: vg.dat (ID = 69877)
7:11 PM: Found Adware: seekseek
7:11 PM: urls.bin (ID = 75334)
7:14 PM: vurls.bin (ID = 75336)
7:15 PM: delfinco.edx (ID = 57682)
7:15 PM: Found Adware: iwon
7:15 PM: i1initialsetup1.0.0.5.inf (ID = 64798)
7:15 PM: Found Adware: abetterinternet
7:15 PM: thin.inf (ID = 83583)
7:15 PM: delfinld.edx (ID = 57682)
7:15 PM: delfinsi.edx (ID = 57691)
7:15 PM: delfinky.edx (ID = 57685)
7:16 PM: File Sweep Complete, Elapsed Time: 00:07:43
7:16 PM: Full Sweep has completed. Elapsed time 00:16:09
7:16 PM: Traces Found: 569
7:51 PM: Removal process initiated
7:52 PM: Quarantining All Traces: 2nd-thought
7:52 PM: Quarantining All Traces: addestroyer
7:52 PM: Quarantining All Traces: delfin
7:52 PM: Quarantining All Traces: squire webhelper
7:52 PM: Quarantining All Traces: websearch toolbar
7:52 PM: Quarantining All Traces: websponsors cookie
7:52 PM: Quarantining All Traces: yieldmanager cookie
7:52 PM: Quarantining All Traces: specificclick.com cookie
7:52 PM: Quarantining All Traces: adrevolver cookie
7:52 PM: Quarantining All Traces: belointeractive cookie
7:52 PM: Quarantining All Traces: falkag cookie
7:52 PM: Quarantining All Traces: ask cookie
7:52 PM: Quarantining All Traces: atwola cookie
7:52 PM: Quarantining All Traces: bannerspace cookie
7:52 PM: Quarantining All Traces: banner cookie
7:52 PM: Quarantining All Traces: bs.serving-sys cookie
7:52 PM: Quarantining All Traces: burstnet cookie
7:52 PM: Quarantining All Traces: zedo cookie
7:52 PM: Quarantining All Traces: iwon cookie
7:52 PM: Quarantining All Traces: serving-sys cookie
7:52 PM: Quarantining All Traces: clearsearch
7:52 PM: Quarantining All Traces: keenvalue/perfectnav
7:52 PM: Quarantining All Traces: apropos
7:52 PM: Quarantining All Traces: targetsoft
7:52 PM: Quarantining All Traces: keyhost hijacker - jraun
7:52 PM: Quarantining All Traces: mindset interactive - favoriteman
7:52 PM: Quarantining All Traces: seekseek
7:52 PM: Quarantining All Traces: iwon
7:52 PM: Quarantining All Traces: abetterinternet
7:54 PM: Removal process completed. Elapsed time 00:02:33
********
Second Spy sweeper session********
8:51 PM: |··· Start of Session, Thursday, August 11, 2005 ···|
8:51 PM: Spy Sweeper started
8:51 PM: Sweep initiated using definitions version 514
8:51 PM: Starting Memory Sweep
8:57 PM: Memory Sweep Complete, Elapsed Time: 00:05:47
8:57 PM: Starting Registry Sweep
8:57 PM: Found Trojan Horse: 2nd-thought
8:57 PM: HKCR\interface\{6e0ed53c-9908-49ed-b055-7cb31b162577}\ (7 subtraces) (ID = 101978)
8:57 PM: HKCR\interface\{8c53bd8e-b12d-4c8f-ad0e-c9ddc39d1273}\ (8 subtraces) (ID = 101979)
8:57 PM: HKCR\interface\{9bcdd51b-4a7b-446c-8452-d32d38004582}\ (7 subtraces) (ID = 101980)
8:57 PM: HKCR\interface\{49db48ff-02b5-4645-b676-94a4df1aa026}\ (7 subtraces) (ID = 101981)
8:57 PM: HKCR\interface\{830d3aed-2fa9-454f-b266-d931862bbf34}\ (7 subtraces) (ID = 101982)
8:57 PM: HKCR\interface\{a986f4db-792e-4571-8974-0bb6e024766f}\ (7 subtraces) (ID = 101983)
8:57 PM: HKCR\interface\{bccab53d-0895-40c3-a942-a03538ce227a}\ (7 subtraces) (ID = 101984)
8:57 PM: HKCR\interface\{c0f88e9e-dceb-4655-968a-ae508a677c39}\ (7 subtraces) (ID = 101985)
8:57 PM: HKCR\interface\{d7eac2d8-2d52-4010-a4ad-dfdf60c1706c}\ (7 subtraces) (ID = 101986)
8:57 PM: HKLM\software\classes\interface\{6e0ed53c-9908-49ed-b055-7cb31b162577}\ (7 subtraces) (ID = 101993)
8:57 PM: HKLM\software\classes\interface\{8c53bd8e-b12d-4c8f-ad0e-c9ddc39d1273}\ (8 subtraces) (ID = 101994)
8:57 PM: HKLM\software\classes\interface\{9bcdd51b-4a7b-446c-8452-d32d38004582}\ (7 subtraces) (ID = 101995)
8:57 PM: HKLM\software\classes\interface\{49db48ff-02b5-4645-b676-94a4df1aa026}\ (7 subtraces) (ID = 101996)
8:57 PM: HKLM\software\classes\interface\{830d3aed-2fa9-454f-b266-d931862bbf34}\ (7 subtraces) (ID = 101997)
8:57 PM: HKLM\software\classes\interface\{a986f4db-792e-4571-8974-0bb6e024766f}\ (7 subtraces) (ID = 101998)
8:57 PM: HKLM\software\classes\interface\{bccab53d-0895-40c3-a942-a03538ce227a}\ (7 subtraces) (ID = 101999)
8:57 PM: HKLM\software\classes\interface\{c0f88e9e-dceb-4655-968a-ae508a677c39}\ (7 subtraces) (ID = 102000)
8:57 PM: HKLM\software\classes\interface\{d7eac2d8-2d52-4010-a4ad-dfdf60c1706c}\ (7 subtraces) (ID = 102001)
8:57 PM: Found Adware: addestroyer
8:57 PM: HKCR\clsid\{417386c3-8d4a-4611-9b91-e57e89d603ac}\ (13 subtraces) (ID = 102728)
8:57 PM: HKCR\clsid\{d52433a9-a44c-43ab-a013-24b3c756dd2b}\ (13 subtraces) (ID = 102729)
8:57 PM: HKCR\interface\{10d7db96-56dc-4617-8eab-ec506abe6c7e}\ (8 subtraces) (ID = 102730)
8:57 PM: HKCR\interface\{6cdc3337-01f7-4a79-a4af-0b19303cc0be}\ (8 subtraces) (ID = 102732)
8:57 PM: HKCR\interface\{795398d0-dc2f-4118-a69c-592273ba9c2b}\ (8 subtraces) (ID = 102733)
8:57 PM: HKCR\interface\{b288f21c-a144-4ca2-9b70-8afa1fae4b06}\ (8 subtraces) (ID = 102734)
8:57 PM: HKCR\popoops2.popoops\ (3 subtraces) (ID = 102735)
8:57 PM: HKCR\swlad1.swlad\ (3 subtraces) (ID = 102736)
8:57 PM: HKLM\software\classes\clsid\{417386c3-8d4a-4611-9b91-e57e89d603ac}\ (13 subtraces) (ID = 102737)
8:57 PM: HKLM\software\classes\clsid\{d52433a9-a44c-43ab-a013-24b3c756dd2b}\ (13 subtraces) (ID = 102738)
8:57 PM: HKLM\software\classes\interface\{10d7db96-56dc-4617-8eab-ec506abe6c7e}\ (8 subtraces) (ID = 102739)
8:57 PM: HKLM\software\classes\interface\{6cdc3337-01f7-4a79-a4af-0b19303cc0be}\ (8 subtraces) (ID = 102741)
8:57 PM: HKLM\software\classes\interface\{795398d0-dc2f-4118-a69c-592273ba9c2b}\ (8 subtraces) (ID = 102742)
8:57 PM: HKLM\software\classes\interface\{b288f21c-a144-4ca2-9b70-8afa1fae4b06}\ (8 subtraces) (ID = 102743)
8:57 PM: HKLM\software\classes\popoops2.popoops\ (3 subtraces) (ID = 102744)
8:57 PM: HKLM\software\classes\swlad1.swlad\ (3 subtraces) (ID = 102745)
8:57 PM: HKLM\software\classes\typelib\{d0c29a75-7146-4737-98ee-bc4d7cf44af9}\ (9 subtraces) (ID = 102746)
8:57 PM: HKLM\software\classes\typelib\{e0d3b292-a0b0-4640-975c-2f882e039f52}\ (9 subtraces) (ID = 102747)
8:57 PM: HKCR\typelib\{d0c29a75-7146-4737-98ee-bc4d7cf44af9}\ (9 subtraces) (ID = 102750)
8:57 PM: HKCR\typelib\{e0d3b292-a0b0-4640-975c-2f882e039f52}\ (9 subtraces) (ID = 102751)
8:57 PM: Found Adware: delfin
8:57 PM: HKCR\clsid\{a8bd9566-9895-4fa3-918d-a51d4cd15865}\ (3 subtraces) (ID = 124837)
8:57 PM: HKCR\clsid\{d0070620-1e72-42e7-a14c-3a255ad31839}\ (21 subtraces) (ID = 124838)
8:57 PM: HKCR\interface\{2bb15d36-43be-4743-a3a0-3308f4b1a610}\ (8 subtraces) (ID = 124839)
8:57 PM: HKCR\interface\{41700749-a109-4254-af13-be54011e8783}\ (8 subtraces) (ID = 124840)
8:57 PM: HKLM\software\classes\clsid\{a8bd9566-9895-4fa3-918d-a51d4cd15865}\ (3 subtraces) (ID = 124841)
8:57 PM: HKLM\software\classes\clsid\{d0070620-1e72-42e7-a14c-3a255ad31839}\ (21 subtraces) (ID = 124842)
8:57 PM: HKLM\software\classes\interface\{2bb15d36-43be-4743-a3a0-3308f4b1a610}\ (8 subtraces) (ID = 124843)
8:57 PM: HKLM\software\classes\interface\{41700749-a109-4254-af13-be54011e8783}\ (8 subtraces) (ID = 124844)
8:57 PM: HKLM\software\classes\typelib\{2a7db8d1-43be-4ad3-a81e-9bb8c9d00073}\ (9 subtraces) (ID = 124845)
8:57 PM: HKLM\software\classes\vccpgdataaccess.pgdataaccessctrl.1\ (3 subtraces) (ID = 124846)
8:57 PM: HKLM\software\microsoft\windows\currentversion\uninstall\pgate\ (2 subtraces) (ID = 124881)
8:57 PM: HKU\S-1-5-21-1948358126-1296844153-3270823822-1006\software\pcsv\ (5 subtraces) (ID = 124887)
8:57 PM: HKLM\software\pcsv\ (6 subtraces) (ID = 124888)
8:57 PM: HKCR\typelib\{2a7db8d1-43be-4ad3-a81e-9bb8c9d00073}\ (9 subtraces) (ID = 124899)
8:57 PM: HKCR\vccpgdataaccess.pgdataaccessctrl.1\ (3 subtraces) (ID = 124900)
8:57 PM: Found Adware: squire webhelper
8:57 PM: HKCR\typelib\{805af2c8-98c7-4f3c-a7c9-25ebf27567f3}\ (9 subtraces) (ID = 142155)
8:57 PM: HKLM\software\classes\typelib\{805af2c8-98c7-4f3c-a7c9-25ebf27567f3}\ (9 subtraces) (ID = 142176)
8:57 PM: HKLM\software\microsoft\windows\currentversion\uninstall\sqwire\ (2 subtraces) (ID = 142190)
8:57 PM: Found Adware: websearch toolbar
8:57 PM: HKLM\software\microsoft\windows\currentversion\installer\userdata\aui\ (1 subtraces) (ID = 146479)
8:57 PM: HKCR\popoops2.popoops\ (3 subtraces) (ID = 466854)
8:57 PM: HKCR\popoops2.popoops\ (3 subtraces) (ID = 466855)
8:57 PM: HKCR\popoops2.popoops\clsid\ (1 subtraces) (ID = 466856)
8:57 PM: HKLM\software\classes\popoops2.popoops\ (3 subtraces) (ID = 466858)
8:57 PM: HKLM\software\classes\popoops2.popoops\ (3 subtraces) (ID = 466859)
8:57 PM: HKLM\software\classes\popoops2.popoops\clsid\ (1 subtraces) (ID = 466860)
8:58 PM: Registry Sweep Complete, Elapsed Time:00:00:37
8:58 PM: Starting Cookie Sweep
8:58 PM: Found Spy Cookie: yieldmanager cookie
8:58 PM: cheryl
[email protected][1].txt (ID = 3751)
8:58 PM: Found Spy Cookie: adrevolver cookie
8:58 PM: cheryl tasciotti@adrevolver[2].txt (ID = 2088)
8:58 PM: cheryl tasciotti@adrevolver[3].txt (ID = 2088)
8:58 PM: Found Spy Cookie: belointeractive cookie
8:58 PM: cheryl
[email protected][2].txt (ID = 2295)
8:58 PM: Found Spy Cookie: atwola cookie
8:58 PM: cheryl tasciotti@atwola[1].txt (ID = 2255)
8:58 PM: cheryl tasciotti@belointeractive[1].txt (ID = 2294)
8:58 PM: Found Spy Cookie: bs.serving-sys cookie
8:58 PM: cheryl
[email protected][1].txt (ID = 2330)
8:58 PM: Found Spy Cookie: adjuggler cookie
8:58 PM: cheryl
[email protected][1].txt (ID = 2071)
8:58 PM: Found Spy Cookie: serving-sys cookie
8:58 PM: cheryl tasciotti@serving-sys[2].txt (ID = 3343)
8:58 PM: cheryl
[email protected][2].txt (ID = 2295)
8:58 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01
8:58 PM: Starting File Sweep
8:58 PM: Found Adware: targetsoft
8:58 PM: c:\program files\target soft (1 subtraces) (ID = -2147480166)
8:58 PM: c:\windows\system32\pcs (ID = -2147481121)
8:58 PM: Found Adware: apropos
8:58 PM: c:\program files\sysai (ID = -2147481417)
8:58 PM: Found Adware: keenvalue/perfectnav
8:58 PM: c:\program files\common files\updater (ID = -2147480788)
8:58 PM: c:\documents and settings\all users\application data\pcsvc (1 subtraces) (ID = -2147481135)
8:58 PM: Found Adware: clearsearch
8:58 PM: c:\program files\clearsearch (ID = -2147481257)
8:58 PM: c:\program files\common files\dpi (ID = -2147481129)
9:04 PM: File Sweep Complete, Elapsed Time: 00:06:26
9:04 PM: Full Sweep has completed. Elapsed time 00:13:06
9:04 PM: Traces Found: 526
9:18 PM: Removal process initiated
9:18 PM: Quarantining All Traces: 2nd-thought
9:18 PM: Quarantining All Traces: addestroyer
9:18 PM: Quarantining All Traces: delfin
9:18 PM: Quarantining All Traces: squire webhelper
9:18 PM: Quarantining All Traces: websearch toolbar
9:18 PM: Quarantining All Traces: yieldmanager cookie
9:18 PM: Quarantining All Traces: adrevolver cookie
9:18 PM: Quarantining All Traces: belointeractive cookie
9:18 PM: Quarantining All Traces: atwola cookie
9:18 PM: Quarantining All Traces: bs.serving-sys cookie
9:18 PM: Quarantining All Traces: adjuggler cookie
9:18 PM: Quarantining All Traces: serving-sys cookie
9:18 PM: Quarantining All Traces: targetsoft
9:18 PM: Quarantining All Traces: apropos
9:18 PM: Quarantining All Traces: keenvalue/perfectnav
9:18 PM: Quarantining All Traces: clearsearch
9:20 PM: Removal process completed. Elapsed time 00:02:54
********
HOSTS Notepad# Copyright © 1993-1999 Microsoft Corp.
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
# For example:
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
# Start of entries inserted by Spybot - Search & Destroy
# End of entries inserted by Spybot - Search & Destroy
Edited by cbt131, 11 August 2005 - 08:38 PM.