8:00 PM: |··· Start of Session, Thursday, September 22, 2005 ···|
8:00 PM: Spy Sweeper started
8:00 PM: Sweep initiated using definitions version 539
8:00 PM: Starting Memory Sweep
8:04 PM: Memory Sweep Complete, Elapsed Time: 00:04:11
8:04 PM: Starting Registry Sweep
8:04 PM: Found Adware: addestroyer
8:04 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\vb and vba program settings\addestroyer\ (3 subtraces) (ID = 102749)
8:04 PM: Found Adware: altnet
8:04 PM: HKLM\software\altnet\ (8 subtraces) (ID = 103481)
8:04 PM: Found Adware: apropos
8:04 PM: HKLM\software\aprps\ (2 subtraces) (ID = 103741)
8:04 PM: Found Adware: begin2search
8:04 PM: HKCR\interface\{6b882c34-a832-4f5b-bef1-7e198be3f094}\ (8 subtraces) (ID = 104124)
8:04 PM: HKCR\interface\{9b6b4031-1d6d-4c65-acba-021916853822}\ (8 subtraces) (ID = 104126)
8:04 PM: HKCR\interface\{9ff60a27-0c0c-4a6a-a15f-b21b644d67bb}\ (8 subtraces) (ID = 104127)
8:04 PM: HKCR\interface\{15d53b86-e055-43b1-bbee-a91a0f37bd2a}\ (8 subtraces) (ID = 104128)
8:04 PM: HKCR\interface\{f3c41c1d-22f1-4692-8a7a-88de70a2e9e2}\ (8 subtraces) (ID = 104139)
8:04 PM: HKCR\interface\{fa6fa7a5-2c49-4567-ba74-6dd1c36099ee}\ (8 subtraces) (ID = 104141)
8:04 PM: HKLM\software\classes\interface\{6b882c34-a832-4f5b-bef1-7e198be3f094}\ (8 subtraces) (ID = 104174)
8:04 PM: HKLM\software\classes\interface\{9b6b4031-1d6d-4c65-acba-021916853822}\ (8 subtraces) (ID = 104176)
8:04 PM: HKLM\software\classes\interface\{9ff60a27-0c0c-4a6a-a15f-b21b644d67bb}\ (8 subtraces) (ID = 104177)
8:04 PM: HKLM\software\classes\interface\{15d53b86-e055-43b1-bbee-a91a0f37bd2a}\ (8 subtraces) (ID = 104178)
8:04 PM: HKLM\software\classes\interface\{f3c41c1d-22f1-4692-8a7a-88de70a2e9e2}\ (8 subtraces) (ID = 104189)
8:04 PM: HKLM\software\classes\interface\{fa6fa7a5-2c49-4567-ba74-6dd1c36099ee}\ (8 subtraces) (ID = 104191)
8:05 PM: Found Adware: browseraid
8:05 PM: HKCR\appid\{87690003-2714-45e7-8a1b-dc0658de778c}\ (1 subtraces) (ID = 105031)
8:05 PM: HKCR\interface\{f8d96098-e9f7-42e1-88f3-a3719d70ea8d}\ (8 subtraces) (ID = 105074)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\microsoft\windows\currentversion\updt\ (1 subtraces) (ID = 105189)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\microsoft\windows\currentversion\updt\ (1 subtraces) (ID = 105189)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\{2cf0b992-5eeb-4143-99c0-5297ef71f444}\ (2 subtraces) (ID = 105190)
8:05 PM: Found Adware: cydoor peer-to-peer dependency
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\kazaa\promotions\cydoor\ (420 subtraces) (ID = 124527)
8:05 PM: Found Adware: delfin
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\mvu\ (5 subtraces) (ID = 124884)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\tat\ (5 subtraces) (ID = 124894)
8:05 PM: Found Adware: deskad
8:05 PM: HKCR\deskadx.installer\ (1 subtraces) (ID = 124925)
8:05 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/deskadx.dll\ (2 subtraces) (ID = 124926)
8:05 PM: HKLM\software\classes\deskadx.installer\ (1 subtraces) (ID = 124928)
8:05 PM: Found Adware: downloadware
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\medialoads\ (12 subtraces) (ID = 125355)
8:05 PM: Found Adware: esyndicate bho
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\esyn\ (7 subtraces) (ID = 125844)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\esyn\ (7 subtraces) (ID = 125844)
8:05 PM: Found Adware: ezula ilookup
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\microsoft\windows\currentversion\run\ || ezmmod (ID = 126293)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\microsoft\windows\currentversion\run\ || ezwo (ID = 126294)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\web offer\ (11 subtraces) (ID = 126300)
8:05 PM: Found Adware: flashtrack
8:05 PM: HKCR\interface\{28168cce-5310-4f12-ab58-9da99a55aaeb}\ (8 subtraces) (ID = 126531)
8:05 PM: HKLM\software\classes\interface\{28168cce-5310-4f12-ab58-9da99a55aaeb}\ (8 subtraces) (ID = 126537)
8:05 PM: HKLM\software\classes\typelib\{1bd49631-ae36-42f4-a37b-ca7f53146821}\ (9 subtraces) (ID = 126538)
8:05 PM: HKLM\software\fen\ (7 subtraces) (ID = 126539)
8:05 PM: HKCR\typelib\{1bd49631-ae36-42f4-a37b-ca7f53146821}\ (9 subtraces) (ID = 126562)
8:05 PM: Found Adware: ie driver
8:05 PM: HKU\.default\software\microsoft\internet explorer\extensions\cmdmapping\ || {120e090d-9136-4b78-8258-f0b44b4bd2ac} (ID = 127909)
8:05 PM: HKU\S-1-5-18\software\microsoft\internet explorer\extensions\cmdmapping\ || {120e090d-9136-4b78-8258-f0b44b4bd2ac} (ID = 127930)
8:05 PM: Found Adware: ieplugin
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\intexp\ (7 subtraces) (ID = 128173)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\intexp\ (1 subtraces) (ID = 128173)
8:05 PM: Found Adware: drsnsrch.com hijack
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\microsoft\internet explorer\main\ || search bar (ID = 128206)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\microsoft\internet explorer\main\ || search page (ID = 128207)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\microsoft\internet explorer\searchurl\ (2 subtraces) (ID = 128212)
8:05 PM: Found Adware: instafinder
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\instafink\ (21 subtraces) (ID = 128666)
8:05 PM: Found Adware: internetoptimizer
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\avenue media\ (ID = 128887)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\policies\avenue media\ (ID = 128928)
8:05 PM: Found Adware: keenvalue/perfectnav
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\intermixmedia\ (ID = 129439)
8:05 PM: Found Adware: megasear toolbar
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\megasear toolbar\ (23 subtraces) (ID = 134923)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\microsoft\internet explorer\toolbar\webbrowser\ || {4e7bd74f-2b8d-469e-c0ff-fa7fb592bf30} (ID = 134930)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\microsoft\internet explorer\toolbar\webbrowser\ || {4e7bd74f-2b8d-469e-c0ff-fa7fb592bf30} (ID = 134930)
8:05 PM: Found Adware: 180search assistant/zango
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\salm\ (16 subtraces) (ID = 135792)
8:05 PM: Found Trojan Horse: trojan-downloader-pacisoft
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\psof1\ (12 subtraces) (ID = 136530)
8:05 PM: Found Adware: redzip toolbar
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\microsoft\windows\currentversion\explorer\ || insid (ID = 139328)
8:05 PM: Found Adware: relatedlinks bho
8:05 PM: HKCR\interface\{e82431bf-e8a2-45ca-8361-e5517588cda1}\ (8 subtraces) (ID = 139367)
8:05 PM: HKLM\software\classes\interface\{e82431bf-e8a2-45ca-8361-e5517588cda1}\ (8 subtraces) (ID = 139376)
8:05 PM: Found Adware: rx toolbar
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\rx toolbar\ (8 subtraces) (ID = 140298)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\microsoft\internet explorer\toolbar\webbrowser\ || {25d8bacf-3de2-4b48-ae22-d659b8d835b0} (ID = 140301)
8:05 PM: Found Adware: bho_sep
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\sep\ (9 subtraces) (ID = 141642)
8:05 PM: Found Adware: surfsidekick
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\microsoft\internet explorer\urlsearchhooks\ || {02ee5b04-f144-47bb-83fb-a60bd91b74a9} (ID = 143397)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\microsoft\windows\currentversion\run\ || surfsidekick 3 (ID = 143403)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\surfsidekick2\ (3 subtraces) (ID = 143410)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\surfsidekick3\ (3 subtraces) (ID = 143412)
8:05 PM: Found Adware: virtualbouncer
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\vb and vba program settings\vbouncer\ (8 subtraces) (ID = 145564)
8:05 PM: Found Adware: abetterinternet
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\localnrd\ (35 subtraces) (ID = 145919)
8:05 PM: Found Adware: websearch toolbar
8:05 PM: HKLM\system\currentcontrolset\enum\root\legacy_wintoolssvc\ (8 subtraces) (ID = 146518)
8:05 PM: Found Adware: wildmedia
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\microsoft\internet explorer\main\ || updater2 (ID = 146720)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\microsoft\internet explorer\main\ || updater2 (ID = 146720)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\microsoft\internet explorer\main\ || updater (ID = 146721)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\microsoft\internet explorer\main\ || updater (ID = 146721)
8:05 PM: HKLM\software\microsoft\windows\currentversion\uninstall\wbcm\ (3 subtraces) (ID = 146959)
8:05 PM: Found Adware: winad
8:05 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediaaccx.dll\ (2 subtraces) (ID = 147191)
8:05 PM: Found Adware: windows afa internet enhancement
8:05 PM: HKLM\software\microsoft\windows\currentversion\uninstall\wafaie\ (1 subtraces) (ID = 147277)
8:05 PM: Found Adware: cas
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\cas\client\ (11 subtraces) (ID = 359309)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\microsoft\windows\currentversion\run\ || cas client (ID = 359312)
8:05 PM: Found Adware: shopnavupdater
8:05 PM: HKCR\snb.band\ (3 subtraces) (ID = 359491)
8:05 PM: HKCR\sntb.bottomframe\ (3 subtraces) (ID = 359492)
8:05 PM: HKCR\sntb.leftframe\ (3 subtraces) (ID = 359493)
8:05 PM: HKCR\sntb.popupbrowser\ (3 subtraces) (ID = 359494)
8:05 PM: HKCR\sntb.popupwindow\ (3 subtraces) (ID = 359495)
8:05 PM: HKLM\software\classes\snb.band\ (3 subtraces) (ID = 359501)
8:05 PM: HKLM\software\classes\sntb.bottomframe\ (3 subtraces) (ID = 359502)
8:05 PM: HKLM\software\classes\sntb.leftframe\ (3 subtraces) (ID = 359503)
8:05 PM: HKLM\software\classes\sntb.popupbrowser\ (3 subtraces) (ID = 359505)
8:05 PM: HKLM\software\classes\sntb.popupwindow\ (3 subtraces) (ID = 359507)
8:05 PM: HKLM\software\classes\typelib\{46bd3f46-6e46-43d2-a69d-fd8c05044475}\ (9 subtraces) (ID = 359508)
8:05 PM: HKCR\typelib\{46bd3f46-6e46-43d2-a69d-fd8c05044475}\ (9 subtraces) (ID = 359513)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\aurora\ (29 subtraces) (ID = 360174)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\aurora\ (27 subtraces) (ID = 360174)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\ (19 subtraces) (ID = 386817)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\ || bmk (ID = 386818)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\id\ (4 subtraces) (ID = 386819)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\id\ || geo (ID = 386820)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\path\ (3 subtraces) (ID = 386824)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\path\ || imagespath (ID = 386825)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\path\ || genun (ID = 386826)
8:05 PM: HKCR\typelib\{1bd49631-ae36-42f4-a37b-ca7f53146821}\ (9 subtraces) (ID = 449649)
8:05 PM: HKCR\typelib\{1bd49631-ae36-42f4-a37b-ca7f53146821}\1.0\ (8 subtraces) (ID = 449650)
8:05 PM: HKCR\typelib\{1bd49631-ae36-42f4-a37b-ca7f53146821}\1.0\0\ (2 subtraces) (ID = 449652)
8:05 PM: HKCR\typelib\{1bd49631-ae36-42f4-a37b-ca7f53146821}\1.0\0\win32\ (1 subtraces) (ID = 449653)
8:05 PM: HKCR\typelib\{1bd49631-ae36-42f4-a37b-ca7f53146821}\1.0\flags\ (1 subtraces) (ID = 449655)
8:05 PM: HKCR\typelib\{1bd49631-ae36-42f4-a37b-ca7f53146821}\1.0\helpdir\ (1 subtraces) (ID = 449657)
8:05 PM: HKLM\software\classes\typelib\{1bd49631-ae36-42f4-a37b-ca7f53146821}\ (9 subtraces) (ID = 465256)
8:05 PM: HKLM\software\classes\typelib\{1bd49631-ae36-42f4-a37b-ca7f53146821}\1.0\ (8 subtraces) (ID = 465257)
8:05 PM: HKLM\software\classes\typelib\{1bd49631-ae36-42f4-a37b-ca7f53146821}\1.0\0\ (2 subtraces) (ID = 465259)
8:05 PM: HKLM\software\classes\typelib\{1bd49631-ae36-42f4-a37b-ca7f53146821}\1.0\0\win32\ (1 subtraces) (ID = 465260)
8:05 PM: HKLM\software\classes\typelib\{1bd49631-ae36-42f4-a37b-ca7f53146821}\1.0\flags\ (1 subtraces) (ID = 465262)
8:05 PM: HKLM\software\classes\typelib\{1bd49631-ae36-42f4-a37b-ca7f53146821}\1.0\helpdir\ (1 subtraces) (ID = 465264)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\ (30 subtraces) (ID = 466658)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\ || strup (ID = 466659)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\id\ || l_up (ID = 466669)
8:05 PM: Found Adware: drsnsrch hijacker
8:05 PM: HKCR\dsrch.band\ (3 subtraces) (ID = 509134)
8:05 PM: HKCR\dsrch.bottomframe\ (3 subtraces) (ID = 509135)
8:05 PM: HKCR\dsrch.leftframe\ (3 subtraces) (ID = 509136)
8:05 PM: HKCR\dsrch.popupbrowser\ (3 subtraces) (ID = 509137)
8:05 PM: HKCR\dsrch.popupwindow\ (3 subtraces) (ID = 509138)
8:05 PM: HKCR\typelib\{8f73ac0f-5769-4282-8762-b396a3bff377}\ (9 subtraces) (ID = 509153)
8:05 PM: HKU\S-1-5-21-757298511-2304659736-1445258045-1006\software\dsrch\ (11 subtraces) (ID = 509156)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\dsrch\ (11 subtraces) (ID = 509156)
8:05 PM: HKLM\software\classes\dsrch.band\ (3 subtraces) (ID = 509171)
8:05 PM: HKLM\software\classes\dsrch.leftframe\ (3 subtraces) (ID = 509179)
8:05 PM: HKLM\software\classes\dsrch.popupbrowser\ (3 subtraces) (ID = 509185)
8:05 PM: HKLM\software\classes\dsrch.popupwindow\ (3 subtraces) (ID = 509191)
8:05 PM: HKCR\dsrch.band\curver\ (1 subtraces) (ID = 509362)
8:05 PM: HKCR\dsrch.bottomframe\curver\ (1 subtraces) (ID = 509364)
8:05 PM: HKCR\dsrch.leftframe\curver\ (1 subtraces) (ID = 509366)
8:05 PM: HKCR\dsrch.popupbrowser\curver\ (1 subtraces) (ID = 509368)
8:05 PM: HKCR\dsrch.popupwindow\curver\ (1 subtraces) (ID = 509370)
8:05 PM: Found Adware: rich editor
8:05 PM: HKCR\typelib\{34a35bbb-8c19-4482-864c-290bd8dd6a5d}\ (9 subtraces) (ID = 544913)
8:05 PM: HKLM\software\microsoft\windows\currentversion\app paths\lanbrd\ (1 subtraces) (ID = 550562)
8:05 PM: HKLM\software\microsoft\windows\currentversion\app paths\lanbrup\ (1 subtraces) (ID = 550565)
8:05 PM: HKLM\software\classes\typelib\{34a35bbb-8c19-4482-864c-290bd8dd6a5d}\ (9 subtraces) (ID = 550573)
8:05 PM: HKLM\system\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\lanbrup.exe\ (1 subtraces) (ID = 552678)
8:05 PM: HKCR\pool.lanbridge\ (3 subtraces) (ID = 608249)
8:05 PM: HKLM\software\classes\pool.lanbridge\ (3 subtraces) (ID = 609138)
8:05 PM: HKLM\software\classes\typelib\{34a35bbb-8c19-4482-864c-290bd8dd6a5d}\1.0\ (8 subtraces) (ID = 609169)
8:05 PM: HKLM\software\lanbridge\ (27 subtraces) (ID = 609177)
8:05 PM: HKLM\software\microsoft\windows\currentversion\uninstall\lanbridge\ (1 subtraces) (ID = 609194)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\ (30 subtraces) (ID = 639279)
8:05 PM: HKLM\software\classes\dsrch.bottomframe\ (3 subtraces) (ID = 646382)
8:05 PM: HKLM\software\classes\typelib\{8f73ac0f-5769-4282-8762-b396a3bff377}\ (9 subtraces) (ID = 646384)
8:05 PM: HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1007\software\microsoft\windows\currentversion\policies\ameopt\ (ID = 654042)
8:05 PM: Found Adware: appliedsearch
8:05 PM: HKCR\interface\{6600d22d-083f-11d6-99de-d172e92ebc2a}\ (8 subtraces) (ID = 661011)
8:05 PM: HKCR\interface\{6600d22e-083f-11d6-99de-d172e92ebc2a}\ (8 subtraces) (ID = 661020)
8:05 PM: HKLM\software\classes\interface\{6600d22d-083f-11d6-99de-d172e92ebc2a}\ (8 subtraces) (ID = 661094)
8:05 PM: HKLM\software\classes\interface\{6600d22e-083f-11d6-99de-d172e92ebc2a}\ (8 subtraces) (ID = 661103)
8:05 PM: Found Adware: visfx
8:05 PM: HKLM\software\microsoft\windows\currentversion\uninstall\ovmon\ (1 subtraces) (ID = 712951)
8:05 PM: Registry Sweep Complete, Elapsed Time:00:00:54
8:05 PM: Starting Cookie Sweep
8:05 PM: Found Spy Cookie: about cookie
8:05 PM: brenda brown@about[2].txt (ID = 2037)
8:05 PM: Found Spy Cookie: yieldmanager cookie
8:05 PM: brenda
[email protected][2].txt (ID = 3751)
8:05 PM: Found Spy Cookie: adknowledge cookie
8:05 PM: brenda brown@adknowledge[2].txt (ID = 2072)
8:05 PM: Found Spy Cookie: adrevolver cookie
8:05 PM: brenda brown@adrevolver[2].txt (ID = 2088)
8:05 PM: brenda brown@adrevolver[3].txt (ID = 2088)
8:05 PM: Found Spy Cookie: addynamix cookie
8:05 PM: brenda
[email protected][2].txt (ID = 2062)
8:05 PM: Found Spy Cookie: ask cookie
8:05 PM: brenda brown@ask[1].txt (ID = 2245)
8:05 PM: Found Spy Cookie: atwola cookie
8:05 PM: brenda brown@atwola[1].txt (ID = 2255)
8:05 PM: Found Spy Cookie: banner cookie
8:05 PM: brenda brown@banner[2].txt (ID = 2276)
8:05 PM: brenda
[email protected][2].txt (ID = 2038)
8:05 PM: Found Spy Cookie: belnk cookie
8:05 PM: brenda brown@belnk[1].txt (ID = 2292)
8:05 PM: Found Spy Cookie: bluestreak cookie
8:05 PM: brenda brown@bluestreak[2].txt (ID = 2314)
8:05 PM: Found Spy Cookie: burstnet cookie
8:05 PM: brenda brown@burstnet[1].txt (ID = 2336)
8:05 PM: brenda
[email protected][2].txt (ID = 2293)
8:05 PM: brenda
[email protected][1].txt (ID = 2038)
8:05 PM: Found Spy Cookie: screensavers.com cookie
8:05 PM: brenda
[email protected][1].txt (ID = 3298)
8:05 PM: Found Spy Cookie: paypopup cookie
8:05 PM: brenda brown@paypopup[2].txt (ID = 3119)
8:05 PM: Found Spy Cookie: realmedia cookie
8:05 PM: brenda brown@realmedia[1].txt (ID = 3235)
8:05 PM: Found Spy Cookie: starware.com cookie
8:05 PM: brenda brown@starware[2].txt (ID = 3441)
8:05 PM: Found Spy Cookie: tmpad cookie
8:05 PM: brenda brown@tmpad[1].txt (ID = 3545)
8:05 PM: Found Spy Cookie: tracking cookie
8:05 PM: brenda brown@tracking[1].txt (ID = 3571)
8:05 PM: Found Spy Cookie: trafficmp cookie
8:05 PM: brenda brown@trafficmp[1].txt (ID = 3581)
8:05 PM: Found Spy Cookie: burstbeacon cookie
8:05 PM: brenda
[email protected][1].txt (ID = 2335)
8:05 PM: brenda
[email protected][1].txt (ID = 2337)
8:05 PM: brenda
[email protected][1].txt (ID = 3298)
8:05 PM: Found Spy Cookie: websponsors cookie
8:05 PM: courtney
[email protected][2].txt (ID = 3665)
8:05 PM: courtney brown@about[2].txt (ID = 2037)
8:05 PM: courtney
[email protected][1].txt (ID = 3751)
8:05 PM: courtney brown@belnk[1].txt (ID = 2292)
8:05 PM: Found Spy Cookie: com.com cookie
8:05 PM: courtney brown@com[2].txt (ID = 2445)
8:05 PM: courtney
[email protected][2].txt (ID = 2293)
8:05 PM: courtney
[email protected][2].txt (ID = 2038)
8:05 PM: Found Spy Cookie: spywarestormer cookie
8:05 PM: courtney brown@spywarestormer[2].txt (ID = 3417)
8:05 PM: Cookie Sweep Complete, Elapsed Time: 00:00:02
8:05 PM: Starting File Sweep
8:06 PM: c:\program files\appliedsearch_autoinstall (3 subtraces) (ID = -2147474739)
8:06 PM: Found Adware: elitebar
8:06 PM: c:\windows\etb (7 subtraces) (ID = -2147476235)
8:06 PM: Found Adware: winantispyware 2005
8:06 PM: c:\program files\common files\winsoftware (ID = -2147476682)
8:06 PM: f4e8be38-d514-4ea1-bc6b-c72b66 (ID = 83087)
8:06 PM: Found Adware: broadcastpc
8:06 PM: tvlistings.dll (ID = 140448)
8:06 PM: 5b359d15-ea11-44c1-8ed8-b79515 (ID = 57725)
8:06 PM: Found Trojan Horse: peper trojan
8:06 PM: yfk8.cu6 (ID = 72367)
8:06 PM: 541816c0-171e-4c93-b2d2-f3a90f (ID = 83087)
8:06 PM: dae569c6-580c-47c9-9acc-173ec9 (ID = 51856)
8:06 PM: 05f1502c-727d-4f4b-b1b9-f6694f (ID = 120693)
8:06 PM: tab_0.mht (ID = 51850)
8:07 PM: Found Adware: diamond deal casino
8:07 PM: vegasred.exe (ID = 59042)
8:07 PM: Found Adware: tvmedia
8:07 PM: 35ea0cc6-4834-413e-ac99-9a5254 (ID = 81783)
8:07 PM: 54acc826-a8ab-418a-a0eb-9efeec (ID = 120693)
8:07 PM: ea146c18-7109-49f0-9182-266cef (ID = 114990)
8:07 PM: Found Adware: bonzi buddy
8:07 PM: bbshortcut.ico (ID = 51620)
8:07 PM: cdmodem6.exe (ID = 62709)
8:07 PM: cabinet2.exe (ID = 62709)
8:08 PM: 07a987d4-5462-4088-9556-e8cdd1 (ID = 83087)
8:08 PM: ni.mht (ID = 51847)
8:08 PM: interop.shdocvw.dll (ID = 51845)
8:08 PM: wingenerics.dll (ID = 50187)
8:09 PM: c5d5ce7d-bc75-4cc6-9d89-376c89 (ID = 51856)
8:09 PM: ziplib.dll (ID = 112763)
8:09 PM: Found Adware: upspiral toolbar
8:09 PM: unist2.exe.tcf (ID = 82040)
8:09 PM: bk.exe (ID = 136396)
8:09 PM: bpcv2.plugins.dll (ID = 140447)
8:10 PM: Found Adware: clkoptimizer
8:10 PM: cmxaora.exe (ID = 146385)
8:10 PM: axinterop.shdocvw.dll (ID = 51810)
8:10 PM: sskknwrd.dll (ID = 77733)
8:10 PM: updaterinstall_108.exe (ID = 65013)
8:10 PM: tvsv2.dll (ID = 140449)
8:10 PM: cea5da35-a823-426f-88c0-523f4a (ID = 75991)
8:10 PM: gwqml.dll (ID = 146381)
8:11 PM: bar.dll (ID = 137713)
8:11 PM: medialoads.lnk (ID = 59302)
8:11 PM: lbbho.ini (ID = 73732)
8:11 PM: sskcwrd.dll (ID = 77712)
8:11 PM: satmat.ini (ID = 83499)
8:11 PM: satmat.inf (ID = 83498)
8:11 PM: 02769ed1-6c4c-4544-9035-e3bbed (ID = 85808)
8:11 PM: belt.inf (ID = 83154)
8:11 PM: biini.inf (ID = 83199)
8:11 PM: polall1r.inf (ID = 83425)
8:11 PM: sepsd.bin (ID = 75367)
8:11 PM: File Sweep Complete, Elapsed Time: 00:05:52
8:11 PM: Full Sweep has completed. Elapsed time 00:11:10
8:11 PM: Traces Found: 1465
8:13 PM: Removal process initiated
8:13 PM: Quarantining All Traces: addestroyer
8:13 PM: Quarantining All Traces: altnet
8:13 PM: Quarantining All Traces: apropos
8:13 PM: Quarantining All Traces: begin2search
8:13 PM: Quarantining All Traces: browseraid
8:14 PM: Quarantining All Traces: cydoor peer-to-peer dependency
8:14 PM: Quarantining All Traces: delfin
8:14 PM: Quarantining All Traces: deskad
8:14 PM: Quarantining All Traces: downloadware
8:14 PM: Quarantining All Traces: esyndicate bho
8:14 PM: Quarantining All Traces: ezula ilookup
8:14 PM: Quarantining All Traces: flashtrack
8:14 PM: Quarantining All Traces: ie driver
8:14 PM: Quarantining All Traces: ieplugin
8:14 PM: Quarantining All Traces: drsnsrch.com hijack
8:14 PM: Quarantining All Traces: instafinder
8:14 PM: Quarantining All Traces: internetoptimizer
8:14 PM: Quarantining All Traces: keenvalue/perfectnav
8:14 PM: Quarantining All Traces: megasear toolbar
8:14 PM: Quarantining All Traces: 180search assistant/zango
8:14 PM: Quarantining All Traces: trojan-downloader-pacisoft
8:14 PM: Quarantining All Traces: redzip toolbar
8:14 PM: Quarantining All Traces: relatedlinks bho
8:14 PM: Quarantining All Traces: rx toolbar
8:14 PM: Quarantining All Traces: bho_sep
8:14 PM: Quarantining All Traces: surfsidekick
8:14 PM: Quarantining All Traces: virtualbouncer
8:14 PM: Quarantining All Traces: abetterinternet
8:14 PM: Quarantining All Traces: websearch toolbar
8:14 PM: Quarantining All Traces: wildmedia
8:14 PM: Quarantining All Traces: winad
8:14 PM: Quarantining All Traces: windows afa internet enhancement
8:14 PM: Quarantining All Traces: cas
8:14 PM: Quarantining All Traces: shopnavupdater
8:14 PM: Quarantining All Traces: drsnsrch hijacker
8:14 PM: Quarantining All Traces: rich editor
8:14 PM: Quarantining All Traces: appliedsearch
8:14 PM: Quarantining All Traces: visfx
8:14 PM: Quarantining All Traces: about cookie
8:14 PM: Quarantining All Traces: yieldmanager cookie
8:14 PM: Quarantining All Traces: adknowledge cookie
8:14 PM: Quarantining All Traces: adrevolver cookie
8:14 PM: Quarantining All Traces: addynamix cookie
8:14 PM: Quarantining All Traces: ask cookie
8:14 PM: Quarantining All Traces: atwola cookie
8:14 PM: Quarantining All Traces: banner cookie
8:14 PM: Quarantining All Traces: belnk cookie
8:14 PM: Quarantining All Traces: bluestreak cookie
8:14 PM: Quarantining All Traces: burstnet cookie
8:14 PM: Quarantining All Traces: screensavers.com cookie
8:14 PM: Quarantining All Traces: paypopup cookie
8:14 PM: Quarantining All Traces: realmedia cookie
8:14 PM: Quarantining All Traces: starware.com cookie
8:14 PM: Quarantining All Traces: tmpad cookie
8:14 PM: Quarantining All Traces: tracking cookie
8:14 PM: Quarantining All Traces: trafficmp cookie
8:14 PM: Quarantining All Traces: burstbeacon cookie
8:14 PM: Quarantining All Traces: websponsors cookie
8:14 PM: Quarantining All Traces: com.com cookie
8:14 PM: Quarantining All Traces: spywarestormer cookie
8:14 PM: Quarantining All Traces: elitebar
8:14 PM: Quarantining All Traces: winantispyware 2005
8:14 PM: Quarantining All Traces: broadcastpc
8:14 PM: Quarantining All Traces: peper trojan
8:14 PM: Quarantining All Traces: diamond deal casino
8:14 PM: Quarantining All Traces: tvmedia
8:14 PM: Quarantining All Traces: bonzi buddy
8:14 PM: Quarantining All Traces: upspiral toolbar
8:14 PM: Quarantining All Traces: clkoptimizer
8:14 PM: Warning: Quarantine could not read registry value for HKU\S-1-5-18\software\microsoft\internet explorer\extensions\cmdmapping\{120e090d-9136-4b78-8258-f0b44b4bd2ac}\. Failed to export registry value "S-1-5-18\software\microsoft\internet explorer\extensions\cmdmapping\{120e090d-9136-4b78-8258-f0b44b4bd2ac}". Key/Value does not exist
8:14 PM: Warning: Failed to remove "HKEY_USERS\S-1-5-18\software\microsoft\internet explorer\extensions\cmdmapping\{120e090d-9136-4b78-8258-f0b44b4bd2ac}".
8:14 PM: Warning: Quarantine could not read registry value for HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\bmk\. Failed to export registry value "WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\bmk". Key/Value does not exist
8:14 PM: Warning: Quarantine could not read registry value for HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\id\geo\. Failed to export registry value "WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\id\geo". Key/Value does not exist
8:14 PM: Warning: Quarantine could not read registry value for HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\id\l_up\. Failed to export registry value "WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\id\l_up". Key/Value does not exist
8:14 PM: Warning: Quarantine could not read registry value for HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\path\genun\. Failed to export registry value "WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\path\genun". Key/Value does not exist
8:14 PM: Warning: Quarantine could not read registry value for HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\path\imagespath\. Failed to export registry value "WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\setup\path\imagespath". Key/Value does not exist
8:14 PM: Warning: Quarantine could not read registry value for HKU\WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\strup\. Failed to export registry value "WRSS_Profile_S-1-5-21-757298511-2304659736-1445258045-1008\software\ezula\strup". Key/Value does not exist
8:16 PM: Removal process completed. Elapsed time 00:02:56
********
7:59 PM: |··· Start of Session, Thursday, September 22, 2005 ···|
7:59 PM: Spy Sweeper started
8:00 PM: |··· End of Session, Thursday, September 22, 2005 ···|