it's not dead yet! Hopefully soon! here is my spy sweeper log.
********
5:29 PM: |··· Start of Session, Thursday, September 01, 2005 ···|
5:29 PM: Spy Sweeper started
5:29 PM: Sweep initiated using definitions version 526
5:29 PM: Starting Memory Sweep
5:30 PM: Found Adware: cws_tiny0
5:30 PM: Detected running threat: C:\WINDOWS\system32\ntxd32.exe (ID = 135984)
5:30 PM: HKLM\Software\Microsoft\Windows\CurrentVersion\Run || ntxd32.exe (ID = 0)
5:31 PM: Found Adware: cws_ns3
5:31 PM: Detected running threat: C:\WINDOWS\d3lj.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\addiq32.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\d3rd32.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\appmb.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\system32\d3nk32.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\system32\ipex.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\system32\ntks32.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\addfg32.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\appym.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\msdo32.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\ntii32.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\system32\netsm.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\system32\atlcf32.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\system32\appok.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\ipgh32.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\d3pu32.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\atlav.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\system32\msfq.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\system32\msbf32.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\ipco.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\system32\appkr.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\system32\mfcuk.dll (ID = 8)
5:31 PM: Detected running threat: C:\WINDOWS\ntvb32.dll (ID = 8)
5:31 PM: Memory Sweep Complete, Elapsed Time: 00:01:42
5:31 PM: Starting Registry Sweep
5:31 PM: Found Trojan Horse: agent.ay downloader
5:31 PM: HKCR\clsid\{088bb196-6676-cb49-248d-e08b115e7e10}\ (6 subtraces) (ID = 103335)
5:31 PM: HKLM\software\classes\clsid\{088bb196-6676-cb49-248d-e08b115e7e10}\ (6 subtraces) (ID = 103344)
5:31 PM: Found Adware: coolwebsearch (cws)
5:31 PM: HKCR\clsid\{0f9a97e5-963e-75db-23f4-3897cec6b584}\ (2 subtraces) (ID = 107063)
5:31 PM: HKCR\clsid\{6a5229c9-2f01-6a52-521f-8f546ded11c7}\ (2 subtraces) (ID = 107280)
5:31 PM: HKCR\clsid\{43f226f3-3edd-1f6e-b1f9-426f80dab07e}\ (6 subtraces) (ID = 107460)
5:31 PM: HKCR\clsid\{44ce9131-e13c-d36a-083a-faff61e866ca}\ (6 subtraces) (ID = 107461)
5:31 PM: HKCR\clsid\{65d75d06-7395-6352-09cd-e13b9059efe9}\ (6 subtraces) (ID = 107500)
5:31 PM: HKCR\clsid\{66deb589-b6d4-e95e-2e36-26287464cd11}\ (6 subtraces) (ID = 107502)
5:31 PM: HKCR\clsid\{77e35b59-5dbf-ca0f-2037-00b52e21e874}\ (2 subtraces) (ID = 107523)
5:31 PM: HKCR\clsid\{211d33be-b506-603a-e0c1-e50e4d62779f}\ (6 subtraces) (ID = 107595)
5:31 PM: HKCR\clsid\{c5f30c3e-df43-3900-ba95-c664d49efbb2}\ (2 subtraces) (ID = 108051)
5:31 PM: HKCR\clsid\{d02510a9-69a7-24d5-85da-d3ec8e911c73}\ (6 subtraces) (ID = 108130)
5:31 PM: HKCR\clsid\{d75b9d6b-fb2a-ee40-24da-791d27c77147}\ (2 subtraces) (ID = 108151)
5:31 PM: HKLM\software\classes\clsid\{0f9a97e5-963e-75db-23f4-3897cec6b584}\ (2 subtraces) (ID = 108453)
5:31 PM: HKLM\software\classes\clsid\{6a5229c9-2f01-6a52-521f-8f546ded11c7}\ (2 subtraces) (ID = 108668)
5:31 PM: HKLM\software\classes\clsid\{43f226f3-3edd-1f6e-b1f9-426f80dab07e}\ (6 subtraces) (ID = 108847)
5:31 PM: HKLM\software\classes\clsid\{44ce9131-e13c-d36a-083a-faff61e866ca}\ (6 subtraces) (ID = 108848)
5:31 PM: HKLM\software\classes\clsid\{65d75d06-7395-6352-09cd-e13b9059efe9}\ (6 subtraces) (ID = 108887)
5:31 PM: HKLM\software\classes\clsid\{66deb589-b6d4-e95e-2e36-26287464cd11}\ (6 subtraces) (ID = 108889)
5:31 PM: HKLM\software\classes\clsid\{77e35b59-5dbf-ca0f-2037-00b52e21e874}\ (2 subtraces) (ID = 108910)
5:31 PM: HKLM\software\classes\clsid\{211d33be-b506-603a-e0c1-e50e4d62779f}\ (6 subtraces) (ID = 108981)
5:31 PM: HKLM\software\classes\clsid\{c5f30c3e-df43-3900-ba95-c664d49efbb2}\ (2 subtraces) (ID = 109434)
5:31 PM: HKLM\software\classes\clsid\{d02510a9-69a7-24d5-85da-d3ec8e911c73}\ (6 subtraces) (ID = 109513)
5:31 PM: HKLM\software\classes\clsid\{d75b9d6b-fb2a-ee40-24da-791d27c77147}\ (2 subtraces) (ID = 109534)
5:31 PM: Found Adware: cws-aboutblank
5:31 PM: HKCR\clsid\{53b83eba-809f-c983-5c07-4cb6e85d8f3a}\ (2 subtraces) (ID = 113323)
5:31 PM: HKLM\software\classes\clsid\{53b83eba-809f-c983-5c07-4cb6e85d8f3a}\ (2 subtraces) (ID = 114900)
5:31 PM: HKCR\clsid\{0add4d53-b7dd-20f8-2ac9-ab9cb538a46f}\ (6 subtraces) (ID = 117597)
5:31 PM: HKCR\clsid\{0b6be68e-b55a-5883-3dbc-30d73208d3e7}\ (6 subtraces) (ID = 117604)
5:31 PM: HKCR\clsid\{0b538ae6-8676-e13b-4cec-e6a75f19f1ef}\ (6 subtraces) (ID = 117607)
5:31 PM: HKCR\clsid\{011710e1-b483-710e-97e0-2570cf3083b8}\ (2 subtraces) (ID = 117636)
5:31 PM: HKCR\clsid\{04d2569c-ed83-79fb-0e43-f43dfa258774}\ (6 subtraces) (ID = 117663)
5:31 PM: HKCR\clsid\{07f0caa0-8206-9dcc-5402-d4cc24ec1764}\ (6 subtraces) (ID = 117686)
5:31 PM: HKCR\clsid\{09098a2e-29b4-d7ac-c8ec-1c448eba69e3}\ (4 subtraces) (ID = 117698)
5:31 PM: HKCR\clsid\{09248dc7-285d-a208-7675-8d1bac7208c9}\ (6 subtraces) (ID = 117699)
5:31 PM: HKCR\clsid\{1b9cee94-e0d7-13cf-2da8-ca3c766eaad0}\ (6 subtraces) (ID = 117706)
5:31 PM: HKCR\clsid\{1d232f9d-941d-5cd9-732f-8f6ec1977cf2}\ (6 subtraces) (ID = 117720)
5:31 PM: HKCR\clsid\{1de20533-9118-bf9a-a6c6-f8e881a5fd4b}\ (6 subtraces) (ID = 117724)
5:31 PM: HKCR\clsid\{1e920882-80ef-bd61-dbbd-0847c13d1197}\ (2 subtraces) (ID = 117728)
5:31 PM: HKCR\clsid\{1f846f72-8833-7b85-fbf7-b2d81d30ab82}\ (4 subtraces) (ID = 117736)
5:31 PM: HKCR\clsid\{2a97db56-e2b4-967c-af9f-07fdf74289c2}\ (6 subtraces) (ID = 117739)
5:31 PM: HKCR\clsid\{2cb60d9d-ba37-058c-7ea3-a52155f01235}\ (6 subtraces) (ID = 117754)
5:31 PM: HKCR\clsid\{2d99fd34-f395-dfb0-0852-36d4976f6e3d}\ (6 subtraces) (ID = 117765)
5:31 PM: HKCR\clsid\{2fb10b1f-e342-08a1-cbaa-d4a2cd2abac6}\ (2 subtraces) (ID = 117777)
5:31 PM: HKCR\clsid\{3e429b2a-880e-f81f-ccf2-035c43170ae9}\localserver32\ (1 subtraces) (ID = 117808)
5:31 PM: HKCR\clsid\{4e11a0fd-72a3-aef3-d4e4-e168f75a238e}\ (6 subtraces) (ID = 117854)
5:31 PM: HKCR\clsid\{4fbb115d-894b-592c-e7c1-41e7c088266f}\localserver32\ (1 subtraces) (ID = 117863)
5:31 PM: HKCR\clsid\{5da6ca48-7d98-bc0b-40ef-22ac6558668a}\ (6 subtraces) (ID = 117892)
5:31 PM: HKCR\clsid\{5f0db282-2c0a-ae7b-a81a-1451175e7cc1}\ (2 subtraces) (ID = 117907)
5:31 PM: HKCR\clsid\{5f32646e-6d3e-257c-2369-efd1a3a012f8}\ (6 subtraces) (ID = 117911)
5:31 PM: HKCR\clsid\{5fa0cf1e-5ff7-5212-6d7d-5710e683babb}\ (6 subtraces) (ID = 117913)
5:31 PM: HKCR\clsid\{6a493714-8012-621e-a09e-cd80ff52fb1f}\ (2 subtraces) (ID = 117921)
5:31 PM: HKCR\clsid\{6d012127-abb2-bf82-d02a-24cbbd599720}\ (6 subtraces) (ID = 117944)
5:31 PM: HKCR\clsid\{6ddf3af2-cb9d-199d-044c-9941e91e7cff}\ (2 subtraces) (ID = 117950)
5:31 PM: HKCR\clsid\{8bb0647d-d9c2-cb7b-7651-2618bd82261b}\ (6 subtraces) (ID = 118008)
5:31 PM: HKCR\clsid\{8c5ccfeb-d80b-9087-ae97-c7343da6efdd}\ (2 subtraces) (ID = 118016)
5:31 PM: HKCR\clsid\{8f60435f-df74-6308-e8cb-509d69906821}\ (6 subtraces) (ID = 118033)
5:31 PM: HKCR\clsid\{9d7705a4-9543-9869-8249-f62ac961bda5}\ (6 subtraces) (ID = 118057)
5:31 PM: HKCR\clsid\{9e0852d7-12f7-9aeb-b1f6-766a430f01c0}\ (2 subtraces) (ID = 118059)
5:31 PM: HKCR\clsid\{10d837d7-d6ea-8bce-37fb-e58a2e09397b}\ (6 subtraces) (ID = 118080)
5:31 PM: HKCR\clsid\{16c710fd-4c93-9c02-15fc-681df7937350}\ (6 subtraces) (ID = 118087)
5:31 PM: HKCR\clsid\{22e7067a-283f-cf1c-4373-210a97c38bdb}\ (6 subtraces) (ID = 118105)
5:31 PM: HKCR\clsid\{35cdce87-6bd6-878a-d4c9-24118a153d34}\ (6 subtraces) (ID = 118140)
5:31 PM: HKCR\clsid\{38ea95b6-06df-844e-6763-813a152d6f74}\ (2 subtraces) (ID = 118160)
5:31 PM: HKCR\clsid\{47b70b6f-a6b0-230a-43c3-9f9b5c710209}\ (6 subtraces) (ID = 118181)
5:31 PM: HKCR\clsid\{47da2122-90a1-597c-94d7-20963f392761}\ (6 subtraces) (ID = 118182)
5:31 PM: HKCR\clsid\{62b52b4d-547b-bfc7-9850-79709fdecf27}\ (6 subtraces) (ID = 118222)
5:31 PM: HKCR\clsid\{66f81d4b-90ba-d6b9-a3dd-81424b154345}\localserver32\ (1 subtraces) (ID = 118237)
5:31 PM: HKCR\clsid\{67d02480-710b-80d7-0624-27bb57b32cde}\ (6 subtraces) (ID = 118239)
5:31 PM: HKCR\clsid\{86b29a5f-cb91-3c3d-28a2-eda38c1f28a8}\ (6 subtraces) (ID = 118288)
5:31 PM: HKCR\clsid\{97e37285-b9d3-035e-821f-3ebe4f849c3d}\ (6 subtraces) (ID = 118314)
5:31 PM: HKCR\clsid\{735ddac7-f8f1-47dd-d87a-6af0100b6a48}\ (6 subtraces) (ID = 118420)
5:31 PM: HKCR\clsid\{786a41bb-009d-dd27-ea3e-15dcd01ec75c}\ (6 subtraces) (ID = 118428)
5:31 PM: HKCR\clsid\{792a038a-9c16-9885-5b25-ce939788172a}\ (5 subtraces) (ID = 118430)
5:31 PM: HKCR\clsid\{798a3875-f0cf-e2b2-3196-d55e89cdef04}\ (2 subtraces) (ID = 118434)
5:31 PM: HKCR\clsid\{841cb982-c366-4290-3f00-95a1a5f3c340}\ (6 subtraces) (ID = 118440)
5:31 PM: HKCR\clsid\{865e2cec-dcdc-cf30-c932-8a491f233655}\ (2 subtraces) (ID = 118444)
5:31 PM: HKCR\clsid\{929f8e8d-2c15-4240-e685-fa3c645381c5}\ (6 subtraces) (ID = 118454)
5:31 PM: HKCR\clsid\{966fa744-197f-e95e-eb31-73be39619de2}\ (6 subtraces) (ID = 118464)
5:31 PM: HKCR\clsid\{3757d8ec-fd1d-a2f5-366b-c8c2fee89b04}\ (6 subtraces) (ID = 118491)
5:31 PM: HKCR\clsid\{5932f9cb-e60e-11c7-5ba5-2cd8198cbdb4}\ (6 subtraces) (ID = 118512)
5:31 PM: HKCR\clsid\{7868ec16-8c67-1dbd-6d5a-ebb325881bd9}\ (6 subtraces) (ID = 118532)
5:31 PM: HKCR\clsid\{8169e4d3-2914-c956-aafe-f49d78c929a8}\ (6 subtraces) (ID = 118538)
5:31 PM: HKCR\clsid\{8669abb2-7410-3460-f449-e119dca24cc4}\ (6 subtraces) (ID = 118546)
5:31 PM: HKCR\clsid\{12130dcb-3df4-96ec-27b9-61e0d766f680}\ (6 subtraces) (ID = 118563)
5:31 PM: HKCR\clsid\{43372d0d-6ead-977a-99ee-8dfb043153ed}\ (2 subtraces) (ID = 118580)
5:31 PM: HKCR\clsid\{88289cad-8761-b286-1697-48c2e3a53747}\ (6 subtraces) (ID = 118617)
5:31 PM: HKCR\clsid\{676575dd-4d46-911d-8037-9b10d6ee8bb5}\ (ID = 118649)
5:31 PM: HKCR\clsid\{765369c1-d4e0-d6a4-69b4-6261d4e1319a}\ (5 subtraces) (ID = 118652)
5:31 PM: HKCR\clsid\{795714a8-c9c0-e8bd-30db-a0da3b603993}\ (6 subtraces) (ID = 118654)
5:31 PM: HKCR\clsid\{1082088a-e784-5093-f9a0-07e5588fa67c}\ (6 subtraces) (ID = 118664)
5:31 PM: HKCR\clsid\{1323178d-09e3-b628-cc3a-95630b64b7da}\ (6 subtraces) (ID = 118666)
5:31 PM: HKCR\clsid\{3508830d-8a20-1c38-52a8-8dc8b11ee6f4}\ (6 subtraces) (ID = 118672)
5:31 PM: HKCR\clsid\{9320654e-9dd7-7b4e-fd11-be169ac706f5}\ (6 subtraces) (ID = 118683)
5:31 PM: HKCR\clsid\{61682029-a490-5c49-d9fd-682fb2da97af}\ (6 subtraces) (ID = 118711)
5:31 PM: HKCR\clsid\{a9629e20-9b59-1f5f-58ae-e699d9122e1f}\ (6 subtraces) (ID = 118788)
5:31 PM: HKCR\clsid\{a167704a-0f01-8543-16a8-ecf3eba5dc01}\ (6 subtraces) (ID = 118792)
5:31 PM: HKCR\clsid\{a8703447-9782-72d3-aa41-606a7e155ce5}\ (6 subtraces) (ID = 118799)
5:31 PM: HKCR\clsid\{ab8789ce-01b6-4b58-c2c0-77d8144d5741}\ (6 subtraces) (ID = 118810)
5:31 PM: HKCR\clsid\{af197e67-53b8-6c01-4733-3e7c25ba3a3b}\ (6 subtraces) (ID = 118833)
5:31 PM: HKCR\clsid\{b9e19da8-10a7-4e21-2fbb-fdc66e0cc0b9}\ (2 subtraces) (ID = 118857)
5:31 PM: HKCR\clsid\{b36d5282-d413-f545-cf79-a6ce970cfebb}\ (6 subtraces) (ID = 118861)
5:31 PM: HKCR\clsid\{b78461f4-0e43-85fe-00b7-c15b18b07b4e}\ (2 subtraces) (ID = 118888)
5:31 PM: HKCR\clsid\{bc0fe7f5-ad1d-a795-c683-f3eb54072efe}\ (6 subtraces) (ID = 118910)
5:31 PM: HKCR\clsid\{c092cea0-fb34-5e12-83ed-47942941decc}\ (6 subtraces) (ID = 118940)
5:31 PM: HKCR\clsid\{c42cf26e-2b02-05de-7d7b-a16c5c2095bb}\ (11 subtraces) (ID = 118987)
5:31 PM: HKCR\clsid\{c53d27e6-2a68-7cd9-a09f-541ef27b2319}\ (6 subtraces) (ID = 118990)
5:31 PM: HKCR\clsid\{c74df792-dd4b-4b33-4d25-bb3e8a211bb3}\ (6 subtraces) (ID = 118996)
5:31 PM: HKCR\clsid\{c81edefc-5ab9-55d2-cded-3c677e07b4e6}\ (6 subtraces) (ID = 118998)
5:31 PM: HKCR\clsid\{c6984483-d454-b316-4040-575b9fb13d11}\ (6 subtraces) (ID = 119029)
5:31 PM: HKCR\clsid\{c9368290-de0b-80ff-0e2d-8933f6ca1a46}\ (6 subtraces) (ID = 119032)
5:31 PM: HKCR\clsid\{d0efc5ad-b041-13c1-482f-cf46efeff6c3}\ (6 subtraces) (ID = 119081)
5:31 PM: HKCR\clsid\{d7b5394e-d013-3545-35d0-45376236a8dc}\ (4 subtraces) (ID = 119095)
5:31 PM: HKCR\clsid\{d27dd7b4-a72b-4b66-2bd3-262b793a3c2c}\ (6 subtraces) (ID = 119105)
5:31 PM: HKCR\clsid\{d85fbaa5-5f33-6173-d800-efd4e38ae63e}\ (6 subtraces) (ID = 119113)
5:31 PM: HKCR\clsid\{d223f02d-058e-2cfe-d02d-81826009252b}\ (6 subtraces) (ID = 119115)
5:31 PM: HKCR\clsid\{d605eaff-2c3a-4619-43c1-4ffb062f68de}\ (6 subtraces) (ID = 119121)
5:31 PM: HKCR\clsid\{d4451521-f203-568e-2657-c5ad1f0b1f77}\ (2 subtraces) (ID = 119139)
5:31 PM: HKCR\clsid\{db3ff0a6-7ad3-085e-3e59-a4318e82d4a8}\ (6 subtraces) (ID = 119157)
5:31 PM: HKCR\clsid\{de064cf5-809e-a243-cc14-f5427e5967a1}\ (6 subtraces) (ID = 119183)
5:31 PM: HKCR\clsid\{df74f87a-b7c0-f480-1d25-d81a257b3152}\ (6 subtraces) (ID = 119193)
5:31 PM: HKCR\clsid\{df7066e9-8ee8-8682-f43e-2bf8e7e7d760}\ (2 subtraces) (ID = 119195)
5:31 PM: HKCR\clsid\{dfc94122-75a0-85e3-3738-430a8b983c39}\ (6 subtraces) (ID = 119197)
5:31 PM: HKCR\clsid\{e36a99d7-088f-a5e8-1ba4-87116d938d49}\ (2 subtraces) (ID = 119237)
5:31 PM: HKCR\clsid\{e404f826-abe4-d856-61ba-bcbd539933f8}\ (2 subtraces) (ID = 119254)
5:31 PM: HKCR\clsid\{e24280f1-5872-dd80-6349-14510dfcb851}\ (6 subtraces) (ID = 119267)
5:31 PM: HKCR\clsid\{e365460d-7563-2763-5e38-85f172854eac}\ (6 subtraces) (ID = 119270)
5:31 PM: HKCR\clsid\{e647591b-d33e-72b8-a7f0-9d55c2a7369d}\ (6 subtraces) (ID = 119273)
5:31 PM: HKCR\clsid\{e9342878-fcea-230b-e4d2-5712935070ea}\ (25 subtraces) (ID = 119278)
5:31 PM: HKCR\clsid\{eceaf197-b6ef-9e38-0846-ff3bb03983ad}\ (6 subtraces) (ID = 119305)
5:31 PM: HKCR\clsid\{edb7ff48-2cc7-7131-a993-53c8f83dd550}\ (6 subtraces) (ID = 119311)
5:31 PM: HKCR\clsid\{f0d9b410-3c4f-707c-2e2d-529e64aa2118}\ (2 subtraces) (ID = 119339)
5:31 PM: HKCR\clsid\{f065e398-2acb-9034-8b2a-28a827ff521f}\ (6 subtraces) (ID = 119343)
5:31 PM: HKCR\clsid\{f3dd5740-8c65-5ff3-1225-f170898543b8}\ (25 subtraces) (ID = 119354)
5:31 PM: HKCR\clsid\{f6eb941e-9dcd-6e07-e139-d2ab90baae62}\ (6 subtraces) (ID = 119366)
5:31 PM: HKCR\clsid\{f7dfcd4f-46cd-bda8-264c-0a68205f4979}\ (6 subtraces) (ID = 119370)
5:31 PM: HKCR\clsid\{f704a16d-ba8a-0dd4-cb9e-f0fa4a957d8d}\ (6 subtraces) (ID = 119390)
5:31 PM: HKCR\clsid\{f2352fd0-b78a-fc66-ee98-5dfbf99e1f48}\ (5 subtraces) (ID = 119400)
5:31 PM: HKCR\clsid\{f317424c-8ecc-86c7-5e5b-7aa1bd81d1c4}\ (6 subtraces) (ID = 119409)
5:31 PM: HKCR\clsid\{f6802757-10ab-dbc8-719a-c48394d31082}\ (6 subtraces) (ID = 119413)
5:31 PM: HKCR\clsid\{fa986cde-0fa2-33a9-ecfd-8291dfa81985}\ (6 subtraces) (ID = 119419)
5:31 PM: HKCR\clsid\{fb277f1b-89b6-a114-dd01-ec507a933f39}\ (2 subtraces) (ID = 119426)
5:31 PM: HKCR\clsid\{fc92c3de-f786-c2a4-4565-359ecf140e14}\ (6 subtraces) (ID = 119436)
5:31 PM: HKLM\software\classes\clsid\{0add4d53-b7dd-20f8-2ac9-ab9cb538a46f}\ (6 subtraces) (ID = 119478)
5:31 PM: HKLM\software\classes\clsid\{0b6be68e-b55a-5883-3dbc-30d73208d3e7}\ (6 subtraces) (ID = 119484)
5:31 PM: HKLM\software\classes\clsid\{0b538ae6-8676-e13b-4cec-e6a75f19f1ef}\ (6 subtraces) (ID = 119487)
5:31 PM: HKLM\software\classes\clsid\{04d2569c-ed83-79fb-0e43-f43dfa258774}\ (6 subtraces) (ID = 119541)
5:31 PM: HKLM\software\classes\clsid\{07f0caa0-8206-9dcc-5402-d4cc24ec1764}\ (6 subtraces) (ID = 119562)
5:31 PM: HKLM\software\classes\clsid\{09098a2e-29b4-d7ac-c8ec-1c448eba69e3}\ (4 subtraces) (ID = 119573)
5:31 PM: HKLM\software\classes\clsid\{09248dc7-285d-a208-7675-8d1bac7208c9}\ (6 subtraces) (ID = 119574)
5:31 PM: HKLM\software\classes\clsid\{1b9cee94-e0d7-13cf-2da8-ca3c766eaad0}\ (6 subtraces) (ID = 119581)
5:31 PM: HKLM\software\classes\clsid\{1d232f9d-941d-5cd9-732f-8f6ec1977cf2}\ (6 subtraces) (ID = 119595)
5:31 PM: HKLM\software\classes\clsid\{1de20533-9118-bf9a-a6c6-f8e881a5fd4b}\ (6 subtraces) (ID = 119599)
5:31 PM: HKLM\software\classes\clsid\{1e920882-80ef-bd61-dbbd-0847c13d1197}\ (2 subtraces) (ID = 119603)
5:31 PM: HKLM\software\classes\clsid\{1f846f72-8833-7b85-fbf7-b2d81d30ab82}\ (4 subtraces) (ID = 119611)
5:31 PM: HKLM\software\classes\clsid\{1fe935ff-db66-ac76-99d8-18ec1f0f013c}\ (6 subtraces) (ID = 119613)
5:31 PM: HKLM\software\classes\clsid\{2a97db56-e2b4-967c-af9f-07fdf74289c2}\ (6 subtraces) (ID = 119615)
5:31 PM: HKLM\software\classes\clsid\{2cb60d9d-ba37-058c-7ea3-a52155f01235}\ (6 subtraces) (ID = 119630)
5:31 PM: HKLM\software\classes\clsid\{2d99fd34-f395-dfb0-0852-36d4976f6e3d}\ (6 subtraces) (ID = 119640)
5:31 PM: HKLM\software\classes\clsid\{2fb10b1f-e342-08a1-cbaa-d4a2cd2abac6}\ (2 subtraces) (ID = 119651)
5:31 PM: HKLM\software\classes\clsid\{3e429b2a-880e-f81f-ccf2-035c43170ae9}\localserver32\ (1 subtraces) (ID = 119681)
5:31 PM: HKLM\software\classes\clsid\{4e11a0fd-72a3-aef3-d4e4-e168f75a238e}\ (6 subtraces) (ID = 119727)
5:31 PM: HKLM\software\classes\clsid\{4fbb115d-894b-592c-e7c1-41e7c088266f}\localserver32\ (1 subtraces) (ID = 119736)
5:31 PM: HKLM\software\classes\clsid\{5da6ca48-7d98-bc0b-40ef-22ac6558668a}\ (6 subtraces) (ID = 119768)
5:31 PM: HKLM\software\classes\clsid\{5f0db282-2c0a-ae7b-a81a-1451175e7cc1}\ (2 subtraces) (ID = 119782)
5:31 PM: HKLM\software\classes\clsid\{5f32646e-6d3e-257c-2369-efd1a3a012f8}\ (6 subtraces) (ID = 119786)
5:31 PM: HKLM\software\classes\clsid\{5fa0cf1e-5ff7-5212-6d7d-5710e683babb}\ (6 subtraces) (ID = 119788)
5:31 PM: HKLM\software\classes\clsid\{6a493714-8012-621e-a09e-cd80ff52fb1f}\ (2 subtraces) (ID = 119795)
5:31 PM: HKLM\software\classes\clsid\{6d012127-abb2-bf82-d02a-24cbbd599720}\ (6 subtraces) (ID = 119818)
5:31 PM: HKLM\software\classes\clsid\{6ddf3af2-cb9d-199d-044c-9941e91e7cff}\ (2 subtraces) (ID = 119824)
5:31 PM: HKLM\software\classes\clsid\{8bb0647d-d9c2-cb7b-7651-2618bd82261b}\ (6 subtraces) (ID = 119882)
5:31 PM: HKLM\software\classes\clsid\{8c5ccfeb-d80b-9087-ae97-c7343da6efdd}\ (2 subtraces) (ID = 119890)
5:31 PM: HKLM\software\classes\clsid\{8f60435f-df74-6308-e8cb-509d69906821}\ (6 subtraces) (ID = 119907)
5:31 PM: HKLM\software\classes\clsid\{9d7705a4-9543-9869-8249-f62ac961bda5}\ (6 subtraces) (ID = 119929)
5:31 PM: HKLM\software\classes\clsid\{9e0852d7-12f7-9aeb-b1f6-766a430f01c0}\ (2 subtraces) (ID = 119931)
5:31 PM: HKLM\software\classes\clsid\{10d837d7-d6ea-8bce-37fb-e58a2e09397b}\ (6 subtraces) (ID = 119952)
5:31 PM: HKLM\software\classes\clsid\{16c710fd-4c93-9c02-15fc-681df7937350}\ (6 subtraces) (ID = 119958)
5:31 PM: HKLM\software\classes\clsid\{22e7067a-283f-cf1c-4373-210a97c38bdb}\ (6 subtraces) (ID = 119975)
5:31 PM: HKLM\software\classes\clsid\{35cdce87-6bd6-878a-d4c9-24118a153d34}\ (6 subtraces) (ID = 120009)
5:31 PM: HKLM\software\classes\clsid\{47b70b6f-a6b0-230a-43c3-9f9b5c710209}\ (6 subtraces) (ID = 120039)
5:31 PM: HKLM\software\classes\clsid\{47da2122-90a1-597c-94d7-20963f392761}\ (6 subtraces) (ID = 120040)
5:31 PM: HKLM\software\classes\clsid\{62b52b4d-547b-bfc7-9850-79709fdecf27}\ (6 subtraces) (ID = 120079)
5:31 PM: HKLM\software\classes\clsid\{66f81d4b-90ba-d6b9-a3dd-81424b154345}\localserver32\ (1 subtraces) (ID = 120094)
5:31 PM: HKLM\software\classes\clsid\{67d02480-710b-80d7-0624-27bb57b32cde}\ (6 subtraces) (ID = 120096)
5:31 PM: HKLM\software\classes\clsid\{86b29a5f-cb91-3c3d-28a2-eda38c1f28a8}\ (6 subtraces) (ID = 120144)
5:31 PM: HKLM\software\classes\clsid\{97e37285-b9d3-035e-821f-3ebe4f849c3d}\ (6 subtraces) (ID = 120169)
5:31 PM: HKLM\software\classes\clsid\{735ddac7-f8f1-47dd-d87a-6af0100b6a48}\ (6 subtraces) (ID = 120268)
5:31 PM: HKLM\software\classes\clsid\{786a41bb-009d-dd27-ea3e-15dcd01ec75c}\ (6 subtraces) (ID = 120276)
5:31 PM: HKLM\software\classes\clsid\{792a038a-9c16-9885-5b25-ce939788172a}\ (5 subtraces) (ID = 120278)
5:31 PM: HKLM\software\classes\clsid\{841cb982-c366-4290-3f00-95a1a5f3c340}\ (6 subtraces) (ID = 120287)
5:31 PM: HKLM\software\classes\clsid\{865e2cec-dcdc-cf30-c932-8a491f233655}\ (2 subtraces) (ID = 120291)
5:31 PM: HKLM\software\classes\clsid\{929f8e8d-2c15-4240-e685-fa3c645381c5}\ (6 subtraces) (ID = 120301)
5:31 PM: HKLM\software\classes\clsid\{966fa744-197f-e95e-eb31-73be39619de2}\ (6 subtraces) (ID = 120311)
5:31 PM: HKLM\software\classes\clsid\{3757d8ec-fd1d-a2f5-366b-c8c2fee89b04}\ (6 subtraces) (ID = 120338)
5:31 PM: HKLM\software\classes\clsid\{5932f9cb-e60e-11c7-5ba5-2cd8198cbdb4}\localserver32\ (1 subtraces) (ID = 120359)
5:31 PM: HKLM\software\classes\clsid\{7868ec16-8c67-1dbd-6d5a-ebb325881bd9}\ (6 subtraces) (ID = 120379)
5:31 PM: HKLM\software\classes\clsid\{8169e4d3-2914-c956-aafe-f49d78c929a8}\ (6 subtraces) (ID = 120384)
5:31 PM: HKLM\software\classes\clsid\{8669abb2-7410-3460-f449-e119dca24cc4}\ (6 subtraces) (ID = 120392)
5:31 PM: HKLM\software\classes\clsid\{12130dcb-3df4-96ec-27b9-61e0d766f680}\ (6 subtraces) (ID = 120410)
5:31 PM: HKLM\software\classes\clsid\{43372d0d-6ead-977a-99ee-8dfb043153ed}\ (2 subtraces) (ID = 120427)
5:31 PM: HKLM\software\classes\clsid\{88289cad-8761-b286-1697-48c2e3a53747}\ (6 subtraces) (ID = 120464)
5:31 PM: HKLM\software\classes\clsid\{676575dd-4d46-911d-8037-9b10d6ee8bb5}\ (ID = 120496)
5:31 PM: HKLM\software\classes\clsid\{765369c1-d4e0-d6a4-69b4-6261d4e1319a}\ (5 subtraces) (ID = 120499)
5:31 PM: HKLM\software\classes\clsid\{795714a8-c9c0-e8bd-30db-a0da3b603993}\ (6 subtraces) (ID = 120501)
5:31 PM: HKLM\software\classes\clsid\{1082088a-e784-5093-f9a0-07e5588fa67c}\ (6 subtraces) (ID = 120510)
5:31 PM: HKLM\software\classes\clsid\{1323178d-09e3-b628-cc3a-95630b64b7da}\ (6 subtraces) (ID = 120511)
5:31 PM: HKLM\software\classes\clsid\{3508830d-8a20-1c38-52a8-8dc8b11ee6f4}\ (6 subtraces) (ID = 120517)
5:31 PM: HKLM\software\classes\clsid\{9320654e-9dd7-7b4e-fd11-be169ac706f5}\ (6 subtraces) (ID = 120528)
5:31 PM: HKLM\software\classes\clsid\{61682029-a490-5c49-d9fd-682fb2da97af}\ (6 subtraces) (ID = 120553)
5:31 PM: HKLM\software\classes\clsid\{a9629e20-9b59-1f5f-58ae-e699d9122e1f}\ (6 subtraces) (ID = 120627)
5:31 PM: HKLM\software\classes\clsid\{a167704a-0f01-8543-16a8-ecf3eba5dc01}\ (6 subtraces) (ID = 120631)
5:31 PM: HKLM\software\classes\clsid\{a8703447-9782-72d3-aa41-606a7e155ce5}\ (6 subtraces) (ID = 120637)
5:31 PM: HKLM\software\classes\clsid\{ab8789ce-01b6-4b58-c2c0-77d8144d5741}\ (6 subtraces) (ID = 120649)
5:31 PM: HKLM\software\classes\clsid\{af197e67-53b8-6c01-4733-3e7c25ba3a3b}\ (6 subtraces) (ID = 120672)
5:31 PM: HKLM\software\classes\clsid\{b9e19da8-10a7-4e21-2fbb-fdc66e0cc0b9}\ (2 subtraces) (ID = 120696)
5:31 PM: HKLM\software\classes\clsid\{b36d5282-d413-f545-cf79-a6ce970cfebb}\ (6 subtraces) (ID = 120700)
5:31 PM: HKLM\software\classes\clsid\{b78461f4-0e43-85fe-00b7-c15b18b07b4e}\ (2 subtraces) (ID = 120726)
5:31 PM: HKLM\software\classes\clsid\{bc0fe7f5-ad1d-a795-c683-f3eb54072efe}\ (6 subtraces) (ID = 120747)
5:31 PM: HKLM\software\classes\clsid\{c092cea0-fb34-5e12-83ed-47942941decc}\ (6 subtraces) (ID = 120776)
5:31 PM: HKLM\software\classes\clsid\{c42cf26e-2b02-05de-7d7b-a16c5c2095bb}\ (11 subtraces) (ID = 120824)
5:31 PM: HKLM\software\classes\clsid\{c53d27e6-2a68-7cd9-a09f-541ef27b2319}\ (6 subtraces) (ID = 120827)
5:31 PM: HKLM\software\classes\clsid\{c74df792-dd4b-4b33-4d25-bb3e8a211bb3}\ (6 subtraces) (ID = 120833)
5:31 PM: HKLM\software\classes\clsid\{c81edefc-5ab9-55d2-cded-3c677e07b4e6}\ (6 subtraces) (ID = 120835)
5:31 PM: HKLM\software\classes\clsid\{c6984483-d454-b316-4040-575b9fb13d11}\ (6 subtraces) (ID = 120866)
5:31 PM: HKLM\software\classes\clsid\{c9368290-de0b-80ff-0e2d-8933f6ca1a46}\ (6 subtraces) (ID = 120869)
5:31 PM: HKLM\software\classes\clsid\{d0efc5ad-b041-13c1-482f-cf46efeff6c3}\ (6 subtraces) (ID = 120917)
5:31 PM: HKLM\software\classes\clsid\{d7b5394e-d013-3545-35d0-45376236a8dc}\ (4 subtraces) (ID = 120931)
5:31 PM: HKLM\software\classes\clsid\{d27dd7b4-a72b-4b66-2bd3-262b793a3c2c}\ (6 subtraces) (ID = 120941)
5:31 PM: HKLM\software\classes\clsid\{d85fbaa5-5f33-6173-d800-efd4e38ae63e}\ (6 subtraces) (ID = 120949)
5:31 PM: HKLM\software\classes\clsid\{d223f02d-058e-2cfe-d02d-81826009252b}\ (6 subtraces) (ID = 120951)
5:31 PM: HKLM\software\classes\clsid\{d605eaff-2c3a-4619-43c1-4ffb062f68de}\ (6 subtraces) (ID = 120957)
5:31 PM: HKLM\software\classes\clsid\{d4451521-f203-568e-2657-c5ad1f0b1f77}\ (2 subtraces) (ID = 120975)
5:31 PM: HKLM\software\classes\clsid\{db3ff0a6-7ad3-085e-3e59-a4318e82d4a8}\ (6 subtraces) (ID = 120993)
5:31 PM: HKLM\software\classes\clsid\{de064cf5-809e-a243-cc14-f5427e5967a1}\ (6 subtraces) (ID = 121020)
5:31 PM: HKLM\software\classes\clsid\{df74f87a-b7c0-f480-1d25-d81a257b3152}\ (6 subtraces) (ID = 121029)
5:31 PM: HKLM\software\classes\clsid\{dfc94122-75a0-85e3-3738-430a8b983c39}\ (6 subtraces) (ID = 121032)
5:31 PM: HKLM\software\classes\clsid\{e36a99d7-088f-a5e8-1ba4-87116d938d49}\ (2 subtraces) (ID = 121071)
5:31 PM: HKLM\software\classes\clsid\{e404f826-abe4-d856-61ba-bcbd539933f8}\ (2 subtraces) (ID = 121088)
5:31 PM: HKLM\software\classes\clsid\{e24280f1-5872-dd80-6349-14510dfcb851}\ (6 subtraces) (ID = 121099)
5:31 PM: HKLM\software\classes\clsid\{e365460d-7563-2763-5e38-85f172854eac}\ (6 subtraces) (ID = 121102)
5:31 PM: HKLM\software\classes\clsid\{e647591b-d33e-72b8-a7f0-9d55c2a7369d}\ (6 subtraces) (ID = 121105)
5:31 PM: HKLM\software\classes\clsid\{e9342878-fcea-230b-e4d2-5712935070ea}\ (25 subtraces) (ID = 121110)
5:31 PM: HKLM\software\classes\clsid\{eceaf197-b6ef-9e38-0846-ff3bb03983ad}\ (6 subtraces) (ID = 121136)
5:31 PM: HKLM\software\classes\clsid\{edb7ff48-2cc7-7131-a993-53c8f83dd550}\ (6 subtraces) (ID = 121142)
5:31 PM: HKLM\software\classes\clsid\{f0d9b410-3c4f-707c-2e2d-529e64aa2118}\ (2 subtraces) (ID = 121169)
5:31 PM: HKLM\software\classes\clsid\{f065e398-2acb-9034-8b2a-28a827ff521f}\ (6 subtraces) (ID = 121173)
5:31 PM: HKLM\software\classes\clsid\{f3dd5740-8c65-5ff3-1225-f170898543b8}\ (25 subtraces) (ID = 121183)
5:31 PM: HKLM\software\classes\clsid\{f6eb941e-9dcd-6e07-e139-d2ab90baae62}\ (6 subtraces) (ID = 121195)
5:31 PM: HKLM\software\classes\clsid\{f7dfcd4f-46cd-bda8-264c-0a68205f4979}\ (6 subtraces) (ID = 121199)
5:31 PM: HKLM\software\classes\clsid\{f704a16d-ba8a-0dd4-cb9e-f0fa4a957d8d}\ (6 subtraces) (ID = 121218)
5:31 PM: HKLM\software\classes\clsid\{f2352fd0-b78a-fc66-ee98-5dfbf99e1f48}\ (5 subtraces) (ID = 121227)
5:31 PM: HKLM\software\classes\clsid\{f317424c-8ecc-86c7-5e5b-7aa1bd81d1c4}\ (6 subtraces) (ID = 121236)
5:31 PM: HKLM\software\classes\clsid\{f6802757-10ab-dbc8-719a-c48394d31082}\ (6 subtraces) (ID = 121240)
5:31 PM: HKLM\software\classes\clsid\{fa986cde-0fa2-33a9-ecfd-8291dfa81985}\ (6 subtraces) (ID = 121245)
5:31 PM: HKLM\software\classes\clsid\{fb277f1b-89b6-a114-dd01-ec507a933f39}\ (2 subtraces) (ID = 121251)
5:31 PM: HKLM\software\classes\clsid\{fc92c3de-f786-c2a4-4565-359ecf140e14}\ (6 subtraces) (ID = 121261)
5:31 PM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{e9342878-fcea-230b-e4d2-5712935070ea}\ (1 subtraces) (ID = 123185)
5:31 PM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{f3dd5740-8c65-5ff3-1225-f170898543b8}\ (1 subtraces) (ID = 123226)
5:31 PM: HKLM\software\microsoft\windows\currentversion\uninstall\hsa\ (2 subtraces) (ID = 123379)
5:31 PM: HKLM\software\microsoft\windows\currentversion\uninstall\se\ (2 subtraces) (ID = 123380)
5:31 PM: HKLM\software\microsoft\windows\currentversion\uninstall\sw\ (2 subtraces) (ID = 123381)
5:31 PM: Found Adware: cws_ns3 hijacker
5:31 PM: HKU\S-1-5-21-1093769409-3884940249-2795263750-500\software\microsoft\internet explorer\main\ || search bar (ID = 123390)
5:31 PM: HKU\S-1-5-18\software\microsoft\internet explorer\main\ || search bar (ID = 123390)
5:31 PM: HKU\S-1-5-21-1093769409-3884940249-2795263750-500\software\microsoft\internet explorer\main\ || search page (ID = 123391)
5:31 PM: HKU\S-1-5-18\software\microsoft\internet explorer\main\ || search page (ID = 123391)
5:31 PM: HKLM\software\microsoft\internet explorer\main\ || default_search_url (ID = 123394)
5:31 PM: HKLM\software\microsoft\internet explorer\main\ || search bar (ID = 123395)
5:31 PM: HKLM\software\microsoft\internet explorer\main\ || search page (ID = 123396)
5:31 PM: HKU\S-1-5-21-1093769409-3884940249-2795263750-500\software\microsoft\internet explorer\search\ || searchassistant (ID = 123398)
5:31 PM: HKLM\software\microsoft\internet explorer\search\ || searchassistant (ID = 123399)
5:31 PM: HKCR\clsid\{1c1f1b09-c5de-0c47-b128-b83f5668eb83}\ (2 subtraces) (ID = 123822)
5:31 PM: HKCR\clsid\{2a6a2eff-2fc6-683c-5911-bb1ac07e5964}\ (6 subtraces) (ID = 123826)
5:31 PM: HKCR\clsid\{5b9a8be3-69a5-661b-3bb5-fa99e29d5453}\ (6 subtraces) (ID = 123842)
5:31 PM: HKCR\clsid\{5c2b2d9c-60fc-5f4c-5894-68eb7dfa3935}\ (2 subtraces) (ID = 123845)
5:31 PM: HKCR\clsid\{7da446bf-5485-78f9-cc9a-2a02c93519e4}\ (6 subtraces) (ID = 123852)
5:31 PM: HKCR\clsid\{7dfa112f-21b6-72ce-a5de-09feaf22c151}\ (2 subtraces) (ID = 123853)
5:31 PM: HKCR\clsid\{8a0fedbb-3762-aeb7-e85e-6bcc16f76759}\ (6 subtraces) (ID = 123856)
5:31 PM: HKCR\clsid\{8d1df6ce-07e4-c211-83f6-537e054edc98}\ (6 subtraces) (ID = 123862)
5:31 PM: HKCR\clsid\{9b9d4a7d-1232-e364-432d-b58ecfae5af4}\ (6 subtraces) (ID = 123866)
5:31 PM: HKCR\clsid\{33ebb320-a2d5-6fd7-6d31-ba458c872abd}\ (2 subtraces) (ID = 123879)
5:31 PM: HKCR\clsid\{64ab146b-0c39-dec3-5aed-e2da773c655f}\ (6 subtraces) (ID = 123888)
5:31 PM: HKCR\clsid\{69c2d4b0-ce91-aab5-0bb5-4f75b848492d}\ (6 subtraces) (ID = 123892)
5:31 PM: HKCR\clsid\{226ef23f-8451-8515-bc02-3d0252c01453}\ (2 subtraces) (ID = 123906)
5:31 PM: HKCR\clsid\{497aeaf3-0f8f-a4b6-48f2-a80144d90604}\ (4 subtraces) (ID = 123915)
5:31 PM: HKCR\clsid\{59935bc1-5f4b-96f1-f3b6-c6b36821d102}\ (6 subtraces) (ID = 123942)
5:31 PM: HKCR\clsid\{a45c982e-5e8a-94c9-33a0-1f6e1789ac7e}\ (6 subtraces) (ID = 123957)
5:31 PM: HKCR\clsid\{a72caeb7-7e44-7941-564b-a741d28b01db}\ (6 subtraces) (ID = 123959)
5:31 PM: HKCR\clsid\{a4589c07-991d-8034-c12e-69c0d5455dea}\ (6 subtraces) (ID = 123961)
5:31 PM: HKCR\clsid\{b7abd257-6e0c-e7f0-26f5-0315127e44c2}\ (6 subtraces) (ID = 123971)
5:31 PM: HKCR\clsid\{bfb13f83-4e3b-a3c3-d100-fee3424cd9c0}\ (6 subtraces) (ID = 123985)
5:31 PM: HKCR\clsid\{da826568-8230-c8bc-199c-3e738a0e5a48}\ (6 subtraces) (ID = 124012)
5:31 PM: HKCR\clsid\{eac3a0ef-0931-c087-dd54-10e2ce664097}\ (6 subtraces) (ID = 124027)
5:31 PM: HKCR\clsid\{f80f0d50-2d6c-75c3-606a-3dfe0f4fc5d0}\ (2 subtraces) (ID = 124034)
5:31 PM: HKCR\clsid\{f2903213-c2d0-b852-f56d-8b10d6c8c121}\ (2 subtraces) (ID = 124037)
5:31 PM: HKLM\software\classes\clsid\{1c1f1b09-c5de-0c47-b128-b83f5668eb83}\ (2 subtraces) (ID = 124057)
5:31 PM: HKLM\software\classes\clsid\{2a6a2eff-2fc6-683c-5911-bb1ac07e5964}\ (6 subtraces) (ID = 124061)
5:31 PM: HKLM\software\classes\clsid\{5b9a8be3-69a5-661b-3bb5-fa99e29d5453}\ (6 subtraces) (ID = 124077)
5:31 PM: HKLM\software\classes\clsid\{5c2b2d9c-60fc-5f4c-5894-68eb7dfa3935}\ (2 subtraces) (ID = 124079)
5:31 PM: HKLM\software\classes\clsid\{7da446bf-5485-78f9-cc9a-2a02c93519e4}\ (6 subtraces) (ID = 124086)
5:31 PM: HKLM\software\classes\clsid\{7dfa112f-21b6-72ce-a5de-09feaf22c151}\ (2 subtraces) (ID = 124087)
5:31 PM: HKLM\software\classes\clsid\{8a0fedbb-3762-aeb7-e85e-6bcc16f76759}\ (6 subtraces) (ID = 124090)
5:31 PM: HKLM\software\classes\clsid\{8d1df6ce-07e4-c211-83f6-537e054edc98}\ (6 subtraces) (ID = 124096)
5:31 PM: HKLM\software\classes\clsid\{9b9d4a7d-1232-e364-432d-b58ecfae5af4}\ (6 subtraces) (ID = 124099)
5:31 PM: HKLM\software\classes\clsid\{33ebb320-a2d5-6fd7-6d31-ba458c872abd}\ (2 subtraces) (ID = 124112)
5:31 PM: HKLM\software\classes\clsid\{64ab146b-0c39-dec3-5aed-e2da773c655f}\ (6 subtraces) (ID = 124120)
5:31 PM: HKLM\software\classes\clsid\{69c2d4b0-ce91-aab5-0bb5-4f75b848492d}\ (6 subtraces) (ID = 124124)
5:31 PM: HKLM\software\classes\clsid\{226ef23f-8451-8515-bc02-3d0252c01453}\ (2 subtraces) (ID = 124137)
5:31 PM: HKLM\software\classes\clsid\{497aeaf3-0f8f-a4b6-48f2-a80144d90604}\ (4 subtraces) (ID = 124146)
5:31 PM: HKLM\software\classes\clsid\{59935bc1-5f4b-96f1-f3b6-c6b36821d102}\ (6 subtraces) (ID = 124170)
5:31 PM: HKLM\software\classes\clsid\{98832348-0e38-d102-51a5-517934760119}\ (6 subtraces) (ID = 124179)
5:31 PM: HKLM\software\classes\clsid\{a45c982e-5e8a-94c9-33a0-1f6e1789ac7e}\ (6 subtraces) (ID = 124186)
5:31 PM: HKLM\software\classes\clsid\{a72caeb7-7e44-7941-564b-a741d28b01db}\ (6 subtraces) (ID = 124188)
5:31 PM: HKLM\software\classes\clsid\{a4589c07-991d-8034-c12e-69c0d5455dea}\ (6 subtraces) (ID = 124190)
5:31 PM: HKLM\software\classes\clsid\{b7abd257-6e0c-e7f0-26f5-0315127e44c2}\ (6 subtraces) (ID = 124201)
5:31 PM: HKLM\software\classes\clsid\{bfb13f83-4e3b-a3c3-d100-fee3424cd9c0}\ (6 subtraces) (ID = 124214)
5:31 PM: HKLM\software\classes\clsid\{da826568-8230-c8bc-199c-3e738a0e5a48}\ (6 subtraces) (ID = 124241)
5:31 PM: HKLM\software\classes\clsid\{eac3a0ef-0931-c087-dd54-10e2ce664097}\ (6 subtraces) (ID = 124255)
5:31 PM: HKLM\software\classes\clsid\{f80f0d50-2d6c-75c3-606a-3dfe0f4fc5d0}\ (2 subtraces) (ID = 124262)
5:31 PM: HKLM\software\classes\clsid\{f2903213-c2d0-b852-f56d-8b10d6c8c121}\ (2 subtraces) (ID = 124264)
5:31 PM: Found Trojan Horse: trojan-downloader-winshow
5:31 PM: HKCR\clsid\{fd3ea93f-bce8-a28b-aa76-2d55e711675b}\ (4 subtraces) (ID = 144887)
5:31 PM: HKLM\software\classes\clsid\{fd3ea93f-bce8-a28b-aa76-2d55e711675b}\ (4 subtraces) (ID = 144894)
5:31 PM: Found Trojan Horse: trojan_downloader_tibser
5:31 PM: HKCR\clsid\{4ee6b1b9-e3c3-db03-16bb-541af46efca3}\ (6 subtraces) (ID = 145073)
5:31 PM: HKCR\clsid\{375c6816-55d9-3eb5-0b65-51f231799585}\ (6 subtraces) (ID = 145079)
5:31 PM: HKCR\clsid\{d29fdf9c-92f0-18bd-01ed-22a5dbb07081}\ (2 subtraces) (ID = 145087)
5:31 PM: HKCR\clsid\{e4c72eda-8bdb-7d77-0f8c-37f041df909d}\ (6 subtraces) (ID = 145088)
5:31 PM: HKLM\software\classes\clsid\{4ee6b1b9-e3c3-db03-16bb-541af46efca3}\ (6 subtraces) (ID = 145090)
5:31 PM: HKLM\software\classes\clsid\{375c6816-55d9-3eb5-0b65-51f231799585}\ (6 subtraces) (ID = 145096)
5:31 PM: HKLM\software\classes\clsid\{d29fdf9c-92f0-18bd-01ed-22a5dbb07081}\ (2 subtraces) (ID = 145104)
5:31 PM: HKLM\software\classes\clsid\{e4c72eda-8bdb-7d77-0f8c-37f041df909d}\ (6 subtraces) (ID = 145105)
5:31 PM: Found Adware: tvmedia
5:31 PM: HKCR\clsid\{39036bd7-3708-ac69-49ca-78f80350cdf7}\ (6 subtraces) (ID = 145302)
5:31 PM: HKLM\software\classes\clsid\{39036bd7-3708-ac69-49ca-78f80350cdf7}\ (6 subtraces) (ID = 145306)
5:31 PM: Found Adware: winad
5:31 PM: HKLM\software\microsoft\code store database\distribution units\{15ad6789-cdb4-47e1-a9da-992ee8e6bad6}\ (9 subtraces) (ID = 147185)
5:31 PM: Found Adware: psguard
5:31 PM: HKCR\clsid\{057e242f-2947-4e0a-8e61-a11345d97ea6}\ (ID = 487711)
5:31 PM: HKLM\software\classes\clsid\{057e242f-2947-4e0a-8e61-a11345d97ea6}\ (ID = 488236)
5:31 PM: HKLM\software\classes\clsid\{17e02586-a91d-4a9d-a74e-187b05dffe6f}\ (5 subtraces) (ID = 703881)
5:31 PM: HKLM\software\classes\clsid\{1bd98dfd-2da9-4c54-85d7-be03a0f9c487}\ (5 subtraces) (ID = 703887)
5:31 PM: HKLM\software\classes\clsid\{1c94ea51-3800-4f08-b5dc-a5b67823ffea}\ (5 subtraces) (ID = 703893)
5:31 PM: HKLM\software\classes\clsid\{20d1af34-6e19-42d8-af9f-bdfbe45c2454}\ (5 subtraces) (ID = 703899)
5:31 PM: HKLM\software\classes\clsid\{21e132c9-1f98-4151-bdad-7d9b49c60a8e}\ (5 subtraces) (ID = 703905)
5:31 PM: HKLM\software\classes\clsid\{23f7ad29-f51a-4ba1-be70-143b1cb25bd1}\ (5 subtraces) (ID = 703911)
5:31 PM: HKLM\software\classes\clsid\{2c59d5ec-6b91-4896-bd6f-5f121d87a7f8}\ (5 subtraces) (ID = 703917)
5:31 PM: HKLM\software\classes\clsid\{2f34e0e0-f0bb-477f-afb8-509262fa0ad1}\ (15 subtraces) (ID = 703923)
5:31 PM: HKLM\software\classes\clsid\{35ed274e-3f42-4a78-bbdc-3b7d73e85578}\ (5 subtraces) (ID = 703939)
5:31 PM: HKLM\software\classes\clsid\{3d74d140-f780-4ae3-8d6d-f8dc39107213}\ (5 subtraces) (ID = 703945)
5:31 PM: HKLM\software\classes\clsid\{49443d6e-ce4e-47a9-8deb-f5774ce14984}\ (15 subtraces) (ID = 703951)
5:31 PM: HKLM\software\classes\clsid\{52034ad2-914c-4634-b375-9299631e5525}\ (15 subtraces) (ID = 703967)
5:31 PM: HKLM\software\classes\clsid\{7702c521-76ae-42c0-a181-3b5a96c2eef7}\ (5 subtraces) (ID = 703983)
5:31 PM: HKLM\software\classes\clsid\{7adda344-1d36-4446-9f4b-b2351fb19efd}\ (15 subtraces) (ID = 703989)
5:31 PM: HKLM\software\classes\clsid\{7d98221e-af8f-4d29-8bb1-1dfabc288173}\ (15 subtraces) (ID = 704005)
5:31 PM: HKLM\software\classes\clsid\{9746b450-6064-4ec8-9480-72a289aa2237}\ (5 subtraces) (ID = 704021)
5:31 PM: HKLM\software\classes\clsid\{c5a40fce-0a0f-40ca-985e-661c28b5b431}\ (15 subtraces) (ID = 704027)
5:31 PM: HKLM\software\classes\clsid\{c7f22879-7151-4c71-8c50-9557afda66c6}\ (5 subtraces) (ID = 704043)
5:31 PM: HKLM\software\classes\clsid\{ca5e7959-60b5-47b7-80ac-1606309733f3}\ (5 subtraces) (ID = 704049)
5:31 PM: HKLM\software\classes\clsid\{ceabf027-6cdc-4d47-adf6-ac5d065826a6}\ (15 subtraces) (ID = 704055)
5:31 PM: HKLM\software\classes\clsid\{e5d78bd8-3874-4aa0-9d45-cfb79382c484}\ (15 subtraces) (ID = 704077)
5:31 PM: HKCR\clsid\{15dc7116-e58e-4395-a45a-a1c99b17c030}\ (6 subtraces) (ID = 704636)
5:31 PM: HKCR\clsid\{17e02586-a91d-4a9d-a74e-187b05dffe6f}\ (5 subtraces) (ID = 704643)
5:31 PM: HKCR\clsid\{1bd98dfd-2da9-4c54-85d7-be03a0f9c487}\ (5 subtraces) (ID = 704649)
5:31 PM: HKCR\clsid\{1c94ea51-3800-4f08-b5dc-a5b67823ffea}\ (5 subtraces) (ID = 704655)
5:31 PM: HKCR\clsid\{20d1af34-6e19-42d8-af9f-bdfbe45c2454}\ (5 subtraces) (ID = 704661)
5:31 PM: HKCR\clsid\{21e132c9-1f98-4151-bdad-7d9b49c60a8e}\ (5 subtraces) (ID = 704667)
5:31 PM: HKCR\clsid\{23f7ad29-f51a-4ba1-be70-143b1cb25bd1}\ (5 subtraces) (ID = 704673)
5:31 PM: HKCR\clsid\{2c59d5ec-6b91-4896-bd6f-5f121d87a7f8}\ (5 subtraces) (ID = 704679)
5:31 PM: HKCR\clsid\{2f34e0e0-f0bb-477f-afb8-509262fa0ad1}\ (15 subtraces) (ID = 704685)
5:31 PM: HKCR\clsid\{35ed274e-3f42-4a78-bbdc-3b7d73e85578}\ (5 subtraces) (ID = 704701)
5:31 PM: HKCR\clsid\{3d74d140-f780-4ae3-8d6d-f8dc39107213}\ (5 subtraces) (ID = 704707)
5:31 PM: HKCR\clsid\{49443d6e-ce4e-47a9-8deb-f5774ce14984}\ (15 subtraces) (ID = 704713)
5:31 PM: HKCR\clsid\{52034ad2-914c-4634-b375-9299631e5525}\ (15 subtraces) (ID = 704729)
5:31 PM: HKCR\clsid\{7702c521-76ae-42c0-a181-3b5a96c2eef7}\ (5 subtraces) (ID = 704745)
5:31 PM: HKCR\clsid\{7adda344-1d36-4446-9f4b-b2351fb19efd}\ (15 subtraces) (ID = 704751)
5:31 PM: HKCR\clsid\{7d98221e-af8f-4d29-8bb1-1dfabc288173}\ (15 subtraces) (ID = 704767)
5:31 PM: HKCR\clsid\{9746b450-6064-4ec8-9480-72a289aa2237}\ (5 subtraces) (ID = 704783)
5:31 PM: HKCR\clsid\{c5a40fce-0a0f-40ca-985e-661c28b5b431}\ (15 subtraces) (ID = 704789)
5:31 PM: HKCR\clsid\{c7f22879-7151-4c71-8c50-9557afda66c6}\ (5 subtraces) (ID = 704805)
5:31 PM: HKCR\clsid\{ca5e7959-60b5-47b7-80ac-1606309733f3}\ (5 subtraces) (ID = 704811)
5:31 PM: HKCR\clsid\{ceabf027-6cdc-4d47-adf6-ac5d065826a6}\ (15 subtraces) (ID = 704817)
5:31 PM: HKCR\clsid\{e0aa0493-c410-4cbd-b1db-1723374fa8e0}\ (5 subtraces) (ID = 704833)
5:31 PM: HKCR\clsid\{e5d78bd8-3874-4aa0-9d45-cfb79382c484}\ (15 subtraces) (ID = 704839)
5:31 PM: Registry Sweep Complete, Elapsed Time:00:00:15
5:31 PM: Starting Cookie Sweep
5:31 PM: Found Spy Cookie: addynamix cookie
5:31 PM:
[email protected][1].txt (ID = 2062)
5:31 PM: Found Spy Cookie: atlas dmt cookie
5:31 PM: administrator@atdmt[2].txt (ID = 2253)
5:31 PM: Found Spy Cookie: cnt cookie
5:31 PM: administrator@cnt[1].txt (ID = 2422)
5:31 PM: Found Spy Cookie: overture cookie
5:31 PM:
[email protected][1].txt (ID = 3106)
5:31 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
5:31 PM: Starting File Sweep
5:32 PM: c:\documents and settings\administrator\application data\shudder global limited (11 subtraces) (ID = -2147473536)
5:32 PM: c:\documents and settings\administrator\application data\shudder global limited\psguard (10 subtraces) (ID = -2147475035)
5:32 PM: c:\documents and settings\administrator\application data\winds_24 (ID = -2147481201)
5:32 PM: setuplog.txt:rkwswe (ID = 135288)
5:32 PM: q814995.log:zmomux (ID = 138517)
5:32 PM: netbl32.exe (ID = 135288)
5:32 PM: dhcpupg.log:ddzod (ID = 135984)
5:32 PM: kb842773.log:lamapg (ID = 138517)
5:32 PM: odbc.ini:tqsoqf (ID = 135288)
5:32 PM: sntgl.txt:awrnd (ID = 138517)
5:32 PM: com+.log:nkyyc (ID = 138517)
5:32 PM: wmsyspr9.prx:dhifz (ID = 138517)
5:32 PM: kb823182.log:ndsgth (ID = 135288)
5:32 PM: nqbob.txt:swqsmx (ID = 135288)
5:32 PM: cmsetacl.log:tzrrx (ID = 138517)
5:32 PM: mfcol32.exe (ID = 136491)
5:32 PM: mhttm.log:vsomgk (ID = 135984)
5:32 PM: d3xc.exe (ID = 136491)
5:32 PM: Warning: Failed to read file "c:\windows\:oqtnfu". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: eufin.log:csezi (ID = 135984)
5:32 PM: explorer.scf:udvxc (ID = 138517)
5:32 PM: kb890859.log:ywuno (ID = 138517)
5:32 PM: iedit.ini:qhttd (ID = 138517)
5:32 PM: appfk32.exe (ID = 136491)
5:32 PM: reglocs.old:sxicod (ID = 138517)
5:32 PM: iskps.log:wreqa (ID = 138517)
5:32 PM: iput.exe (ID = 143085)
5:32 PM: q329112.log:tvrpy (ID = 135984)
5:32 PM: q331958.log:dmawl (ID = 138517)
5:32 PM: phreq.log:hypkk (ID = 138517)
5:32 PM: netec32.exe (ID = 143085)
5:32 PM: addbp.exe (ID = 135984)
5:32 PM: awppu.txt:drysp (ID = 138517)
5:32 PM: ctdv10k1.cdf:snqmhm (ID = 138517)
5:32 PM: uywar.log:vcnai (ID = 135984)
5:32 PM: sbwin.ini:fdjrm (ID = 138517)
5:32 PM: Warning: Failed to read file "c:\windows\:yshbe". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: wints32.exe (ID = 143085)
5:32 PM: rlxiv.dat:sowfk (ID = 135984)
5:32 PM: Found Adware: security iguard
5:32 PM: chmhelp.chm (ID = 75238)
5:32 PM: ierl32.exe (ID = 143085)
5:32 PM: cfqnd.log:tltvr (ID = 135984)
5:32 PM: kb828028.log:kczjb (ID = 138517)
5:32 PM: medblker.log:dtkmp (ID = 138517)
5:32 PM: dallt.log:pjccf (ID = 138517)
5:32 PM: hdupn.log:uhqzh (ID = 135984)
5:32 PM: ctdv10k2.cdf:hlcvw (ID = 138517)
5:32 PM: cror32.exe (ID = 135984)
5:32 PM: mzjdc.txt:yoyej (ID = 138517)
5:32 PM: vb.ini:xxoqh (ID = 138517)
5:32 PM: winnt32.log:rqrsc (ID = 138517)
5:32 PM: kb885884.log:jhgcn (ID = 138517)
5:32 PM: quicken.ini:rcnct (ID = 138517)
5:32 PM: hydys.dat:utrwq (ID = 135984)
5:32 PM: eljwv.txt:xlekj (ID = 138517)
5:32 PM: Warning: Failed to read file "c:\windows\:cwjxoh". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: Warning: Failed to read file "c:\windows\". System Error. Code: 3.
The system cannot find the path specified
5:32 PM: appbg32.exe (ID = 138517)
5:32 PM: sdkhv32.exe (ID = 138517)
5:32 PM: netts32.exe (ID = 138517)
5:32 PM: efolu.log:ormnh (ID = 135984)
5:32 PM: phreq.log:eyows (ID = 135984)
5:32 PM: aufme.dat:zcrcq (ID = 138517)
5:32 PM: jhztx.txt:ayioe (ID = 135984)
5:32 PM: q815485.log:raicp (ID = 135984)
5:32 PM: mpaqd.txt:ybkcj (ID = 138517)
5:32 PM: imsins.bak:gvvln (ID = 135984)
5:32 PM: addfg32.exe (ID = 135984)
5:32 PM: Warning: Failed to read file "c:\windows\:dtroe". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: Warning: Failed to read file "c:\windows\:onvex". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: dmkdx.log:mzrmm (ID = 135984)
5:32 PM: d3lj.exe (ID = 135984)
5:32 PM: Warning: Failed to read file "c:\windows\:zuozil". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: hpqins01.dat:mdwew (ID = 138517)
5:32 PM: control.ini:qifjg (ID = 138517)
5:32 PM: hpzmdl01.dat:dceaa (ID = 138517)
5:32 PM: Warning: Failed to read file "c:\windows\:cvolz". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: ivwsm.log:gcyxx (ID = 138517)
5:32 PM: auigv.log:hodxd (ID = 138517)
5:32 PM: nyqvj.log:autmt (ID = 138517)
5:32 PM: nhldr.log:nhius (ID = 138517)
5:32 PM: kb885836.log:hcenj (ID = 138517)
5:32 PM: fbkgd.log:ctbnr (ID = 135984)
5:32 PM: kb891781.log:xzsjt (ID = 138517)
5:32 PM: netfxocm.log:vgcgv (ID = 138517)
5:32 PM: kb893803.log:ztnwa (ID = 138517)
5:32 PM: popcinfo.dat:tmwib (ID = 138517)
5:32 PM: kb826939.log:rqnqa (ID = 135984)
5:32 PM: phreq.log:qbdok (ID = 138517)
5:32 PM: Warning: Failed to read file "c:\windows\:mgmnqb". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: hdupn.log:jtnkw (ID = 138517)
5:32 PM: ivwsm.log:vkaqs (ID = 135984)
5:32 PM: exdfp.log:rcpit (ID = 138517)
5:32 PM: ykmyd.log:aprfo (ID = 138517)
5:32 PM: kb890859.log:flurim (ID = 138517)
5:32 PM: lktnj.txt:hiiyy (ID = 135984)
5:32 PM: wiaservc.log:dcoer (ID = 135984)
5:32 PM: kb893803.log:ckflg (ID = 138517)
5:32 PM: mozver.dat:ikoax (ID = 138517)
5:32 PM: vbaddin.ini:orwrn (ID = 138517)
5:32 PM: kb842773.log:gbazb (ID = 138517)
5:32 PM: quvzz.txt:dohcb (ID = 138517)
5:32 PM: gydsd.log:zgsnt (ID = 135984)
5:32 PM: kusbb.txt:gsulv (ID = 135984)
5:32 PM: addhf32.exe (ID = 138517)
5:32 PM: Warning: Failed to read file "c:\windows\:hqalt". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: auigv.log:jujyq (ID = 138517)
5:32 PM: bnrrx.log:oyvau (ID = 138517)
5:32 PM: setuperr.log:znreha (ID = 135288)
5:32 PM: kb890923.log:ypbyi (ID = 135984)
5:32 PM: q331958.log:nkfrf (ID = 138517)
5:32 PM: ctdvaudy.cdf:tivru (ID = 138517)
5:32 PM: ypflj.txt:rrrlk (ID = 138517)
5:32 PM: Warning: Failed to read file "c:\windows\:rglhj". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: mfcly.exe (ID = 135984)
5:32 PM: Warning: Failed to read file "c:\windows\:urnqw". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: kb893066.log:hhepq (ID = 138517)
5:32 PM: eimve.log:hskfr (ID = 138517)
5:32 PM: msmqinst.log:ggftn (ID = 138517)
5:32 PM: vbaddin.ini:xlqcg (ID = 138517)
5:32 PM: Warning: Failed to read file "c:\windows\:ghret". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: smscfg.ini:qsqej (ID = 138517)
5:32 PM: fnpai.txt:glppb (ID = 135984)
5:32 PM: ykmyd.log:jubse (ID = 135984)
5:32 PM: q329256.log:hqrge (ID = 138517)
5:32 PM: apiki32.exe (ID = 135984)
5:32 PM: kxmcn.log:rtjyb (ID = 135984)
5:32 PM: mldat.dat:qlzol (ID = 138517)
5:32 PM: orun32.isu:wzqum (ID = 138517)
5:32 PM: msmqinst.log:ojyerm (ID = 138517)
5:32 PM: dtcinstall.log:wvrqpq (ID = 138517)
5:32 PM: Warning: Failed to read file "c:\windows\:qeipq". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: kb838358.log:gvgfg (ID = 138517)
5:32 PM: hpoins03.dat:rohoo (ID = 138517)
5:32 PM: jhztx.txt:eekqe (ID = 138517)
5:32 PM: lwhum.log:rvvly (ID = 138517)
5:32 PM: Warning: Failed to read file "c:\windows\". System Error. Code: 3.
The system cannot find the path specified
5:32 PM: Warning: Failed to read file "c:\windows\:ethto". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: kusbb.txt:ngmno (ID = 138517)
5:32 PM: hpzmdl01.dat:qhuqy (ID = 138517)
5:32 PM: nsw.log:rdshy (ID = 135984)
5:32 PM: msmqinst.log:zrwxf (ID = 138517)
5:32 PM: aucfg.ini:zumlg (ID = 135984)
5:32 PM: vjgqv.log:hvmeuf (ID = 135288)
5:32 PM: netul.exe (ID = 135984)
5:32 PM: tabletoc.log:amugz (ID = 138517)
5:32 PM: nteh32.exe (ID = 136491)
5:32 PM: dallt.log:zwyci (ID = 138517)
5:32 PM: knfcw.log:rkihx (ID = 138517)
5:32 PM: regopt.log:sytai (ID = 135984)
5:32 PM: upgrade.txt:eppkv (ID = 138517)
5:32 PM: crnk.exe (ID = 138517)
5:32 PM: sysqv32.exe (ID = 138517)
5:32 PM: Warning: Failed to read file "c:\windows\:iullo". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: tniot.txt:balqk (ID = 138517)
5:32 PM: kb885836.log:bwybx (ID = 138517)
5:32 PM: msmqinst.log:xlajj (ID = 138517)
5:32 PM: ielj32.exe (ID = 138517)
5:32 PM: cdplayer.ini:mwkgk (ID = 135984)
5:32 PM: setuperr.log:dgtji (ID = 138517)
5:32 PM: cfqnd.log:gbnko (ID = 138517)
5:32 PM: hpimdl01.dat:yohll (ID = 138517)
5:32 PM: hydys.dat:ytuzn (ID = 138517)
5:32 PM: kb896422.log:pgiqy (ID = 138517)
5:32 PM: medblker.log:ktqus (ID = 135984)
5:32 PM: faxsetup.log:rbaai (ID = 138517)
5:32 PM: kb832418.log:wvdhx (ID = 135984)
5:32 PM: iis6.log:irgvig (ID = 135288)
5:32 PM: quicken.ini:doiph (ID = 138517)
5:32 PM: gogbo.log:rahel (ID = 135984)
5:32 PM: awppu.txt:wcuaa (ID = 138517)
5:32 PM: Warning: Failed to read file "c:\windows\:ddwnm". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: kb893066.log:lxwne (ID = 138517)
5:32 PM: hmqnp.txt:yidlg (ID = 138517)
5:32 PM: kb899588.log:azjpx (ID = 138517)
5:32 PM: mssh32.exe (ID = 138517)
5:32 PM: hmssb.txt:lcvjj (ID = 138517)
5:32 PM: kb890047.log:ashzr (ID = 138517)
5:32 PM: winzn32.exe (ID = 135984)
5:32 PM: uzkua.log:qrsinu (ID = 135984)
5:32 PM: tabletoc.log:wtfiz (ID = 138517)
5:32 PM: orncu.log:tmwqn (ID = 138517)
5:32 PM: lwhum.log:pkzrn (ID = 135984)
5:32 PM: jyrxp.log:vyrmq (ID = 135984)
5:32 PM: regopt.log:oclvy (ID = 135984)
5:32 PM: mfcic32.exe (ID = 138517)
5:32 PM: ntdv32.exe (ID = 138517)
5:32 PM: kb832418.log:mdzvk (ID = 138517)
5:32 PM: Warning: Failed to read file "c:\windows\:irgifv". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: kb893756.log:ycgsz (ID = 135984)
5:32 PM: uiypi.dat:dzraw (ID = 138517)
5:32 PM: q329256.log:rfthb (ID = 135984)
5:32 PM: d3er.exe (ID = 135984)
5:32 PM: Warning: Failed to read file "c:\windows\:jtfrk". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: upgrade.txt:zdpxf (ID = 135984)
5:32 PM: hpoins03.dat:rzbnv (ID = 138517)
5:32 PM: kb823182.log:zfayy (ID = 138517)
5:32 PM: Warning: Failed to read file "c:\windows\:hxnse". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: vb.ini:yxkga (ID = 138517)
5:32 PM: wmsetup10.log:vpwxy (ID = 138517)
5:32 PM: winnt32.log:fpttu (ID = 138517)
5:32 PM: quicken.ini:fdlmd (ID = 135984)
5:32 PM: orun32.ini:qvuiy (ID = 135984)
5:32 PM: kb838358.log:txjgz (ID = 135984)
5:32 PM: mzjdc.txt:lnfti (ID = 138517)
5:32 PM: orun32.ini:nwbpb (ID = 135984)
5:32 PM: Warning: Failed to read file "c:\windows\:lrcgb". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: kb896423.log:mfwct (ID = 135984)
5:32 PM: lktnj.txt:cibnf (ID = 135984)
5:32 PM: control.ini:qoczn (ID = 135984)
5:32 PM: vjgqv.log:nqing (ID = 138517)
5:32 PM: zuozi.log:wsqvu (ID = 135984)
5:32 PM: Warning: Failed to read file "c:\windows\:iqkzj". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: Warning: Failed to read file "c:\windows\:yfiin". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: kb824920.log:aogor (ID = 135984)
5:32 PM: nhldr.log:qqeuf (ID = 138517)
5:32 PM: ctdv10k2.cdf:koucm (ID = 135984)
5:32 PM: Warning: Failed to read file "c:\windows\". System Error. Code: 3.
The system cannot find the path specified
5:32 PM: Warning: Failed to read file "c:\windows\:ooxmh". System Error. Code: 123.
The filename, directory name, or volume label syntax is incorrect
5:32 PM: ctdv10k1.cdf:dkzsj (ID = 135984)
5:32 PM: directx.log:rfzyy (ID = 135984)
5:32 PM: crsw.exe (ID = 138517)
5:33 PM: kb885884.log:rikkb (ID = 138517)
5:33 PM: dallt.log:koqie (ID = 135984)
5:33 PM: orncu.log:qmyxa (ID = 135984)
5:33 PM: appmb.exe (ID = 135984)
5:33 PM: Warning: Failed to read file "c:\windows\:rruts". System Error. Code: