********
3:13 PM: | Start of Session, Monday, October 17, 2005 |
3:13 PM: Spy Sweeper started
3:13 PM: Sweep initiated using definitions version 555
3:13 PM: Starting Memory Sweep
3:14 PM: Memory Sweep Complete, Elapsed Time: 00:01:18
3:14 PM: Starting Registry Sweep
3:14 PM: Registry Sweep Complete, Elapsed Time:00:00:27
3:14 PM: Starting Cookie Sweep
3:14 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
3:15 PM: Starting File Sweep
3:29 PM: Warning: Failed to access drive F:
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Found Adware: exact cashback/bargain buddy
3:29 PM: exactadvertisingbargainsbuddy12.zip (ID = 50547)
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Found Adware: webhancer
3:29 PM: webhancer1.zip (ID = 83822)
3:29 PM: webhancer2.zip (ID = 83813)
3:29 PM: Found Adware: powerscan
3:29 PM: isearchtechpowerscan9.zip (ID = 72676)
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Warning: Invalid file - not a PKZip file
3:29 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: powerscan.zip (ID = 72676)
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Warning: Invalid file - not a PKZip file
3:30 PM: Found Adware: twain-tech
3:30 PM: vxf2.zip (ID = 81841)
3:30 PM: Found Adware: sexfiles dialers
3:30 PM: isearchtechsidefind23.zip (ID = 75396)
3:31 PM: exactadvertisingbargainsbuddy13.zip (ID = 50877)
3:31 PM: Found Adware: ist istbar
3:31 PM: isearchtechistsvc.zip (ID = 64660)
3:31 PM: isearchtechpowerscan.zip (ID = 72676)
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: isearchtechpowerscan1.zip (ID = 72678)
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: Warning: Invalid file - not a PKZip file
3:31 PM: File Sweep Complete, Elapsed Time: 00:16:44
3:31 PM: Full Sweep has completed. Elapsed time 00:18:38
3:31 PM: Traces Found: 11
5:09 PM: Removal process initiated
5:09 PM: Quarantining All Traces: ist istbar
5:09 PM: Quarantining All Traces: exact cashback/bargain buddy
5:09 PM: Quarantining All Traces: powerscan
5:09 PM: Quarantining All Traces: sexfiles dialers
5:09 PM: Quarantining All Traces: twain-tech
5:09 PM: Quarantining All Traces: webhancer
5:09 PM: Removal process completed. Elapsed time 00:00:13
********
10:50 PM: | Start of Session, Sunday, October 16, 2005 |
10:50 PM: Spy Sweeper started
10:50 PM: Sweep initiated using definitions version 555
10:50 PM: Starting Memory Sweep
10:51 PM: Memory Sweep Complete, Elapsed Time: 00:01:11
10:51 PM: Starting Registry Sweep
10:51 PM: Found Adware: mirar webband
10:51 PM: HKCR\clsid\{8a0dcbda-6e20-489c-9041-c1e8a0352e75}\ (10 subtraces) (ID = 135064)
10:51 PM: HKCR\clsid\{9a9c9b68-f908-4aab-8d0c-10ea8997f37e}\ (9 subtraces) (ID = 135065)
10:51 PM: HKCR\clsid\{9a9c9b69-f908-4aab-8d0c-10ea8997f37e}\ (6 subtraces) (ID = 135066)
10:51 PM: HKCR\interface\{6e4c7afc-9915-4036-b7f9-8b3f1710788f}\ (8 subtraces) (ID = 135069)
10:51 PM: HKCR\interface\{54b287f9-fd90-4457-b65e-cb91560c021d}\ (8 subtraces) (ID = 135070)
10:51 PM: HKCR\interface\{1037b06c-84b7-4240-8d80-485810a0497d}\ (8 subtraces) (ID = 135071)
10:51 PM: HKCR\interface\{224302b0-94e9-45c2-9e5b-ba989ee556e1}\ (8 subtraces) (ID = 135072)
10:51 PM: HKCR\nn_bar_dummy.nn_bardummy.1\ (3 subtraces) (ID = 135075)
10:51 PM: HKCR\nn_bar_dummy.nn_bardummy\ (5 subtraces) (ID = 135076)
10:51 PM: HKLM\software\classes\clsid\{8a0dcbda-6e20-489c-9041-c1e8a0352e75}\ (10 subtraces) (ID = 135077)
10:51 PM: HKLM\software\classes\clsid\{9a9c9b68-f908-4aab-8d0c-10ea8997f37e}\ (9 subtraces) (ID = 135078)
10:51 PM: HKLM\software\classes\clsid\{9a9c9b69-f908-4aab-8d0c-10ea8997f37e}\ (6 subtraces) (ID = 135079)
10:51 PM: HKLM\software\classes\interface\{6e4c7afc-9915-4036-b7f9-8b3f1710788f}\ (8 subtraces) (ID = 135082)
10:51 PM: HKLM\software\classes\interface\{54b287f9-fd90-4457-b65e-cb91560c021d}\ (8 subtraces) (ID = 135083)
10:51 PM: HKLM\software\classes\interface\{1037b06c-84b7-4240-8d80-485810a0497d}\ (8 subtraces) (ID = 135084)
10:51 PM: HKLM\software\classes\interface\{224302b0-94e9-45c2-9e5b-ba989ee556e1}\ (8 subtraces) (ID = 135085)
10:51 PM: HKLM\software\classes\nn_bar_dummy.nn_bardummy.1\ (3 subtraces) (ID = 135088)
10:51 PM: HKLM\software\classes\nn_bar_dummy.nn_bardummy\ (5 subtraces) (ID = 135089)
10:51 PM: HKLM\software\classes\nn_bar_dummy.nn_bardummy\clsid\ (1 subtraces) (ID = 135090)
10:51 PM: HKLM\software\classes\nn_bar_dummy.nn_bardummy\curver\ (1 subtraces) (ID = 135091)
10:51 PM: HKLM\software\classes\typelib\{566dede9-9ed8-45da-9be6-9b2eeab17f49}\ (9 subtraces) (ID = 135092)
10:51 PM: HKLM\software\classes\typelib\{f8310e7d-4c4d-46a4-a068-b5bb99411cc7}\ (9 subtraces) (ID = 135093)
10:51 PM: HKLM\software\microsoft\windows\currentversion\uninstall\{8a0dcbda-6e20-489c-9041-c1e8a0352e75}\ (2 subtraces) (ID = 135119)
10:51 PM: HKCR\typelib\{566dede9-9ed8-45da-9be6-9b2eeab17f49}\ (9 subtraces) (ID = 135121)
10:51 PM: HKCR\typelib\{f8310e7d-4c4d-46a4-a068-b5bb99411cc7}\ (9 subtraces) (ID = 135122)
10:51 PM: Found Adware: shopathomeselect
10:51 PM: HKLM\software\microsoft\windows\currentversion\run\ || sahbundle (ID = 141704)
10:51 PM: HKLM\software\vgroup\ (22 subtraces) (ID = 141734)
10:51 PM: HKLM\software\vgroup\sahagent\ (19 subtraces) (ID = 396143)
10:51 PM: Found Adware: bookedspace
10:51 PM: HKLM\software\microsoft\windows\currentversion\internet settings\zonemap\domains\net-nucleus.com\ (1 subtraces) (ID = 662284)
10:51 PM: Found Adware: clkoptimizer
10:51 PM: HKLM\software\qstat\ (5 subtraces) (ID = 769771)
10:51 PM: HKLM\software\qstat\ || brr (ID = 877670)
10:51 PM: Registry Sweep Complete, Elapsed Time:00:00:27
10:51 PM: Starting Cookie Sweep
10:51 PM: Found Spy Cookie: yieldmanager cookie
10:51 PM:
[email protected][1].txt (ID = 3751)
10:51 PM: Found Spy Cookie: adknowledge cookie
10:51 PM: owner@adknowledge[2].txt (ID = 2072)
10:51 PM: Found Spy Cookie: adrevolver cookie
10:51 PM: owner@adrevolver[1].txt (ID = 2088)
10:51 PM: owner@adrevolver[3].txt (ID = 2088)
10:51 PM: Found Spy Cookie: cc214142 cookie
10:51 PM:
[email protected][2].txt (ID = 2367)
10:51 PM: Found Spy Cookie: pointroll cookie
10:51 PM:
[email protected][2].txt (ID = 3148)
10:51 PM: Found Spy Cookie: adserver cookie
10:51 PM: owner@adserver[2].txt (ID = 2141)
10:51 PM: Found Spy Cookie: ask cookie
10:51 PM: owner@ask[1].txt (ID = 2245)
10:51 PM: Found Spy Cookie: belnk cookie
10:51 PM:
[email protected][2].txt (ID = 2293)
10:51 PM: Found Spy Cookie: banner cookie
10:51 PM: owner@banner[1].txt (ID = 2276)
10:51 PM: owner@belnk[1].txt (ID = 2292)
10:51 PM: Found Spy Cookie: bluestreak cookie
10:51 PM: owner@bluestreak[1].txt (ID = 2314)
10:51 PM: Found Spy Cookie: casalemedia cookie
10:51 PM: owner@casalemedia[1].txt (ID = 2354)
10:51 PM:
[email protected][2].txt (ID = 2293)
10:51 PM: Found Spy Cookie: military cookie
10:51 PM: owner@military[1].txt (ID = 2996)
10:51 PM: Found Spy Cookie: nextag cookie
10:51 PM: owner@nextag[2].txt (ID = 5014)
10:51 PM: Found Spy Cookie: questionmarket cookie
10:51 PM: owner@questionmarket[1].txt (ID = 3217)
10:51 PM: Found Spy Cookie: realmedia cookie
10:51 PM: owner@realmedia[1].txt (ID = 3235)
10:51 PM: Found Spy Cookie: statcounter cookie
10:51 PM: owner@statcounter[2].txt (ID = 3447)
10:51 PM: Found Spy Cookie: tradedoubler cookie
10:51 PM: owner@tradedoubler[1].txt (ID = 3575)
10:51 PM: Found Spy Cookie: tribalfusion cookie
10:51 PM: owner@tribalfusion[1].txt (ID = 3589)
10:51 PM: Found Spy Cookie: burstbeacon cookie
10:51 PM:
[email protected][1].txt (ID = 2335)
10:51 PM:
[email protected][1].txt (ID = 2142)
10:51 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01
10:52 PM: Starting File Sweep
10:57 PM: dc23.dll (ID = 150833)
10:58 PM: dc24.cpl (ID = 150831)
10:58 PM: dc25.dll (ID = 70014)
10:59 PM: f4540171.exe (ID = 146393)
10:59 PM: Warning: Failed to access drive F:
10:59 PM: File Sweep Complete, Elapsed Time: 00:07:48
10:59 PM: Full Sweep has completed. Elapsed time 00:09:35
10:59 PM: Traces Found: 275
11:04 PM: Removal process initiated
11:04 PM: Quarantining All Traces: mirar webband
11:04 PM: Quarantining All Traces: shopathomeselect
11:04 PM: Quarantining All Traces: bookedspace
11:04 PM: Quarantining All Traces: clkoptimizer
11:04 PM: Quarantining All Traces: yieldmanager cookie
11:04 PM: Quarantining All Traces: adknowledge cookie
11:04 PM: Quarantining All Traces: adrevolver cookie
11:04 PM: Quarantining All Traces: cc214142 cookie
11:04 PM: Quarantining All Traces: pointroll cookie
11:04 PM: Quarantining All Traces: adserver cookie
11:04 PM: Quarantining All Traces: ask cookie
11:04 PM: Quarantining All Traces: belnk cookie
11:04 PM: Quarantining All Traces: banner cookie
11:04 PM: Quarantining All Traces: bluestreak cookie
11:04 PM: Quarantining All Traces: casalemedia cookie
11:04 PM: Quarantining All Traces: military cookie
11:04 PM: Quarantining All Traces: nextag cookie
11:04 PM: Quarantining All Traces: questionmarket cookie
11:04 PM: Quarantining All Traces: realmedia cookie
11:04 PM: Quarantining All Traces: statcounter cookie
11:04 PM: Quarantining All Traces: tradedoubler cookie
11:04 PM: Quarantining All Traces: tribalfusion cookie
11:04 PM: Quarantining All Traces: burstbeacon cookie
11:04 PM: Removal process completed. Elapsed time 00:00:35
3:10 PM: Program Version 4.5.3 (Build 560) Using Spyware Definitions 555
3:12 PM: Updating spyware definitions
3:12 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
3:13 PM: | End of Session, Monday, October 17, 2005 |
********
9:49 PM: | Start of Session, Sunday, October 16, 2005 |
9:49 PM: Spy Sweeper started
9:49 PM: Sweep initiated using definitions version 555
9:49 PM: Starting Memory Sweep
9:50 PM: Found Adware: shopathomeselect
9:50 PM: Detected running threat: C:\Documents and Settings\Owner\Local Settings\Temp\3THSLATV.dll (ID = 125428)
9:50 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
9:50 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
9:55 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
9:55 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
9:55 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
9:55 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
9:57 PM: Memory Sweep Complete, Elapsed Time: 00:08:38
9:57 PM: Starting Registry Sweep
9:58 PM: Found Adware: mirar webband
9:58 PM: HKCR\clsid\{8a0dcbda-6e20-489c-9041-c1e8a0352e75}\ (10 subtraces) (ID = 135064)
9:58 PM: HKCR\clsid\{9a9c9b68-f908-4aab-8d0c-10ea8997f37e}\ (9 subtraces) (ID = 135065)
9:58 PM: HKCR\clsid\{9a9c9b69-f908-4aab-8d0c-10ea8997f37e}\ (6 subtraces) (ID = 135066)
9:58 PM: HKCR\interface\{6e4c7afc-9915-4036-b7f9-8b3f1710788f}\ (8 subtraces) (ID = 135069)
9:58 PM: HKCR\interface\{54b287f9-fd90-4457-b65e-cb91560c021d}\ (8 subtraces) (ID = 135070)
9:58 PM: HKCR\interface\{1037b06c-84b7-4240-8d80-485810a0497d}\ (8 subtraces) (ID = 135071)
9:58 PM: HKCR\interface\{224302b0-94e9-45c2-9e5b-ba989ee556e1}\ (8 subtraces) (ID = 135072)
9:58 PM: HKCR\nn_bar_dummy.nn_bardummy.1\ (3 subtraces) (ID = 135075)
9:58 PM: HKCR\nn_bar_dummy.nn_bardummy\ (5 subtraces) (ID = 135076)
9:58 PM: HKLM\software\classes\clsid\{8a0dcbda-6e20-489c-9041-c1e8a0352e75}\ (10 subtraces) (ID = 135077)
9:58 PM: HKLM\software\classes\clsid\{9a9c9b68-f908-4aab-8d0c-10ea8997f37e}\ (9 subtraces) (ID = 135078)
9:58 PM: HKLM\software\classes\clsid\{9a9c9b69-f908-4aab-8d0c-10ea8997f37e}\ (6 subtraces) (ID = 135079)
9:58 PM: HKLM\software\classes\interface\{6e4c7afc-9915-4036-b7f9-8b3f1710788f}\ (8 subtraces) (ID = 135082)
9:58 PM: HKLM\software\classes\interface\{54b287f9-fd90-4457-b65e-cb91560c021d}\ (8 subtraces) (ID = 135083)
9:58 PM: HKLM\software\classes\interface\{1037b06c-84b7-4240-8d80-485810a0497d}\ (8 subtraces) (ID = 135084)
9:58 PM: HKLM\software\classes\interface\{224302b0-94e9-45c2-9e5b-ba989ee556e1}\ (8 subtraces) (ID = 135085)
9:58 PM: HKLM\software\classes\nn_bar_dummy.nn_bardummy.1\ (3 subtraces) (ID = 135088)
9:58 PM: HKLM\software\classes\nn_bar_dummy.nn_bardummy\ (5 subtraces) (ID = 135089)
9:58 PM: HKLM\software\classes\nn_bar_dummy.nn_bardummy\clsid\ (1 subtraces) (ID = 135090)
9:58 PM: HKLM\software\classes\nn_bar_dummy.nn_bardummy\curver\ (1 subtraces) (ID = 135091)
9:58 PM: HKLM\software\classes\typelib\{566dede9-9ed8-45da-9be6-9b2eeab17f49}\ (9 subtraces) (ID = 135092)
9:58 PM: HKLM\software\classes\typelib\{f8310e7d-4c4d-46a4-a068-b5bb99411cc7}\ (9 subtraces) (ID = 135093)
9:58 PM: HKLM\software\microsoft\windows\currentversion\uninstall\{8a0dcbda-6e20-489c-9041-c1e8a0352e75}\ (2 subtraces) (ID = 135119)
9:58 PM: HKCR\typelib\{566dede9-9ed8-45da-9be6-9b2eeab17f49}\ (9 subtraces) (ID = 135121)
9:58 PM: HKCR\typelib\{f8310e7d-4c4d-46a4-a068-b5bb99411cc7}\ (9 subtraces) (ID = 135122)
9:58 PM: HKLM\software\microsoft\windows\currentversion\run\ || sahbundle (ID = 141704)
9:58 PM: HKLM\software\vgroup\ (21 subtraces) (ID = 141734)
9:58 PM: HKLM\software\vgroup\sahagent\ (18 subtraces) (ID = 396143)
9:58 PM: Found Adware: bookedspace
9:58 PM: HKLM\software\microsoft\windows\currentversion\internet settings\zonemap\domains\net-nucleus.com\ (1 subtraces) (ID = 662284)
9:58 PM: Found Adware: clkoptimizer
9:58 PM: HKLM\software\qstat\ (5 subtraces) (ID = 769771)
9:58 PM: HKLM\software\qstat\ || brr (ID = 877670)
9:59 PM: Registry Sweep Complete, Elapsed Time:00:01:32
9:59 PM: Starting Cookie Sweep
9:59 PM: Found Spy Cookie: yieldmanager cookie
9:59 PM:
[email protected][2].txt (ID = 3751)
9:59 PM: Found Spy Cookie: adknowledge cookie
9:59 PM: owner@adknowledge[1].txt (ID = 2072)
9:59 PM: Found Spy Cookie: adrevolver cookie
9:59 PM: owner@adrevolver[1].txt (ID = 2088)
9:59 PM: owner@adrevolver[3].txt (ID = 2088)
9:59 PM: Found Spy Cookie: cc214142 cookie
9:59 PM:
[email protected][2].txt (ID = 2367)
9:59 PM: Found Spy Cookie: adserver cookie
9:59 PM: owner@adserver[1].txt (ID = 2141)
9:59 PM: Found Spy Cookie: ask cookie
9:59 PM: owner@ask[1].txt (ID = 2245)
9:59 PM: Found Spy Cookie: belnk cookie
9:59 PM:
[email protected][2].txt (ID = 2293)
9:59 PM: Found Spy Cookie: banner cookie
9:59 PM: owner@banner[1].txt (ID = 2276)
9:59 PM: owner@belnk[1].txt (ID = 2292)
9:59 PM: Found Spy Cookie: bluestreak cookie
9:59 PM: owner@bluestreak[1].txt (ID = 2314)
9:59 PM:
[email protected][2].txt (ID = 2293)
9:59 PM: Found Spy Cookie: military cookie
9:59 PM: owner@military[1].txt (ID = 2996)
9:59 PM: Found Spy Cookie: nextag cookie
9:59 PM: owner@nextag[2].txt (ID = 5014)
9:59 PM: Found Spy Cookie: questionmarket cookie
9:59 PM: owner@questionmarket[1].txt (ID = 3217)
9:59 PM: Found Spy Cookie: realmedia cookie
9:59 PM: owner@realmedia[2].txt (ID = 3235)
9:59 PM: Found Spy Cookie: statcounter cookie
9:59 PM: owner@statcounter[2].txt (ID = 3447)
9:59 PM: Found Spy Cookie: tradedoubler cookie
9:59 PM: owner@tradedoubler[1].txt (ID = 3575)
9:59 PM: Found Spy Cookie: tribalfusion cookie
9:59 PM: owner@tribalfusion[1].txt (ID = 3589)
9:59 PM: Found Spy Cookie: burstbeacon cookie
9:59 PM:
[email protected][1].txt (ID = 2335)
9:59 PM:
[email protected][1].txt (ID = 2142)
9:59 PM: Cookie Sweep Complete, Elapsed Time: 00:00:03
9:59 PM: Starting File Sweep
10:00 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:00 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:00 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:00 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:05 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:05 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:05 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:05 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:10 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:10 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:10 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:10 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:12 PM: wuauclt.dll (ID = 150833)
10:13 PM: vgactl.cpl (ID = 150831)
10:14 PM: windmy.dll (ID = 70014)
10:14 PM: 3thslatv.dll (ID = 125428)
10:15 PM: f4540171.exe (ID = 146393)
10:15 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:15 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:15 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:15 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:20 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:20 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:20 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:20 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:25 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:25 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:25 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:25 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:30 PM: Found System Monitor: potentially rootkit-masked files
10:30 PM: 0000409d_4344abe5_0001ab3f (ID = 0)
10:30 PM: 00004dc8_434e0977_0004c4b4 (ID = 0)
10:30 PM: 000039ce_43496744_000ec82e (ID = 0)
10:30 PM: 000022ee_43464335_000a7d8c (ID = 0)
10:30 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:30 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:30 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:30 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
10:30 PM: 00005772_4348e5c1_00066ff3 (ID = 0)
10:31 PM: 000032c1_43462903_000a4083 (ID = 0)
10:31 PM: 00004e45_43461657_00000000 (ID = 0)
10:31 PM: 00000035_4346180f_0001ab3f (ID = 0)
10:32 PM: 0000261e_4343906f_0005f5e1 (ID = 0)
10:32 PM: 00001a49_43438fa8_000d59f8 (ID = 0)
10:32 PM: 00000732_43464221_0006ea05 (ID = 0)
10:32 PM: 00003ef6_434715dd_000a7d8c (ID = 0)
10:32 PM: 00003c61_434da2ea_000c65d4 (ID = 0)
10:32 PM: 00005cfd_4344ab9b_00081b32 (ID = 0)
10:33 PM: 0000441d_4348eeba_0002dc6c (ID = 0)
10:33 PM: 0000691d_434c1e17_000b71b0 (ID = 0)
10:33 PM: 00000f3e_43471514_00090f56 (ID = 0)
10:33 PM: 000072ae_434b3f14_000b71b0 (ID = 0)
10:33 PM: 00007eb7_4351d986_000ca2dd (ID = 0)
10:33 PM: 000022ee_4343f490_00090f56 (ID = 0)
10:34 PM: 00003bf6_434616c7_00066ff3 (ID = 0)
10:34 PM: 00006e5d_4344aada_0001ab3f (ID = 0)
10:34 PM: 0000409d_43507baf_00094c5f (ID = 0)
10:34 PM: 0000798b_43461714_0001e848 (ID = 0)
10:34 PM: 00005dd5_4345d2e2_000501bd (ID = 0)
10:35 PM: 00005064_43463d5b_00053ec6 (ID = 0)
10:35 PM: 0000567e_43462a5d_000e1113 (ID = 0)
10:35 PM: 0000074d_4351c09c_0006acfc (ID = 0)
10:35 PM: 00006df1_4350835b_000a4083 (ID = 0)
10:36 PM: 0000409d_43445185_00090f56 (ID = 0)
10:36 PM: 00002b0f_43446c4e_000d59f8 (ID = 0)
10:36 PM: 00005ea5_434b1ebd_0002dc6c (ID = 0)
10:36 PM: 00004ae1_43519ad5_0007de29 (ID = 0)
10:37 PM: 00002c49_4351d9da_000e8b25 (ID = 0)
10:37 PM: Sweep Canceled
10:37 PM: 000050bf_434e1280_0005b8d8 (ID = 0)
10:37 PM: 000050bf_4351918e_000d9701 (ID = 0)
10:37 PM: 0000759a_434815af_000f0537 (ID = 0)
10:37 PM: 00005d03_434640db_000d59f8 (ID = 0)
10:37 PM: 00006586_43481f1e_0007270e (ID = 0)
10:37 PM: 00000029_434612aa_00007a12 (ID = 0)
10:38 PM: 00007a74_4344ce4e_0009c671 (ID = 0)
10:38 PM: 000039b3_43458b18_00089544 (ID = 0)
10:38 PM: 00001db5_4346ed41_0006acfc (ID = 0)
10:38 PM: 0000030a_434c3eb2_000a037a (ID = 0)
10:38 PM: 00005422_434616ef_000501bd (ID = 0)
10:38 PM: 000072b1_43481d88_00031975 (ID = 0)
10:38 PM: 00005e14_434c40df_0005f5e1 (ID = 0)
10:39 PM: 00004e45_434ec185_0004c4b4 (ID = 0)
10:39 PM: 00005579_434b1329_000487ab (ID = 0)
10:39 PM: 00006443_43481576_000bebc2 (ID = 0)
10:39 PM: 00003a8d_434af688_00053ec6 (ID = 0)
10:39 PM: 00003d6c_434a7a20_000ca2dd (ID = 0)
10:40 PM: 00000d66_434c42b4_00076417 (ID = 0)
10:40 PM: 00005753_43507c04_000cdfe6 (ID = 0)
10:40 PM: 00003d6c_4343aa27_000ca2dd (ID = 0)
10:40 PM: 000012c2_434b7e91_000a7d8c (ID = 0)
10:40 PM: 00005878_43438f92_00007a12 (ID = 0)
10:40 PM: 00005789_4349ac02_0007de29 (ID = 0)
10:41 PM: 00006b72_434af4c9_0001e848 (ID = 0)
10:41 PM: 00001350_4349ad59_00031975 (ID = 0)
10:41 PM: 00003f0e_43483b8e_0004c4b4 (ID = 0)
10:41 PM: 00000b31_4349aba9_00098968 (ID = 0)
10:41 PM: 00000fbf_434c41d2_0002dc6c (ID = 0)
10:41 PM: 00000677_4348176a_000d59f8 (ID = 0)
10:42 PM: 0000030a_434a078d_00016e36 (ID = 0)
10:42 PM: 0000513e_4348ea2e_0006ea05 (ID = 0)
10:42 PM: 000001eb_434a1384_00022551 (ID = 0)
10:42 PM: 0000798b_4343f539_000c65d4 (ID = 0)
10:42 PM: 00004d06_43438f32_0007de29 (ID = 0)
10:42 PM: 000023c9_434451a1_000f0537 (ID = 0)
10:43 PM: 00004db7_43438f32_0008d24d (ID = 0)
10:43 PM: 00005d03_434a0727_00053ec6 (ID = 0)
10:43 PM: 00002350_4347158f_00040d99 (ID = 0)
10:43 PM: 000054de_4349b2b3_0001ab3f (ID = 0)
10:43 PM: 000019da_434c046c_0005b8d8 (ID = 0)
10:43 PM: 00000fbf_4348319e_0007a120 (ID = 0)
10:43 PM: 00006014_43481cb6_000af79e (ID = 0)
10:44 PM: 00003cd5_43518c18_000e8b25 (ID = 0)
10:44 PM: 00003d6c_4351d45f_000b71b0 (ID = 0)
10:44 PM: 00006ad4_434617ec_0001ab3f (ID = 0)
10:45 PM: 00005f49_43507b6c_000a4083 (ID = 0)
10:45 PM: 00000bdb_4344615a_000cdfe6 (ID = 0)
10:45 PM: 00007e87_43438f28_000b71b0 (ID = 0)
10:45 PM: 000015d5_43483f8e_0002dc6c (ID = 0)
10:45 PM: 0000759a_43438f88_00076417 (ID = 0)
10:45 PM: 00005e73_43463f9f_00090f56 (ID = 0)
10:45 PM: 000075ec_434b7f6e_0003567e (ID = 0)
10:46 PM: 00002277_43484d51_0007de29 (ID = 0)
10:46 PM: 000026e9_434eb5a7_000a037a (ID = 0)
10:46 PM: 00005d03_435149d7_00022551 (ID = 0)
10:46 PM: 0000773b_43458faf_00040d99 (ID = 0)
10:47 PM: 00004f2b_4344bf1b_000b34a7 (ID = 0)
10:47 PM: 00004d8e_4344c0c0_000aba95 (ID = 0)
10:47 PM: 00005968_434c05e7_000a4083 (ID = 0)
10:47 PM: 00006952_43454626_00000000 (ID = 0)
10:49 PM: Program Version 4.5.3 (Build 560) Using Spyware Definitions 555
10:50 PM: | End of Session, Sunday, October 16, 2005 |
********
7:54 PM: | Start of Session, Sunday, October 16, 2005 |
7:54 PM: Spy Sweeper started
7:54 PM: Sweep initiated using definitions version 555
7:54 PM: Starting Memory Sweep
7:56 PM: Memory Sweep Complete, Elapsed Time: 00:01:10
7:56 PM: Starting Registry Sweep
7:56 PM: Found Adware: apropos
7:56 PM: HKLM\software\aprps\ (2 subtraces) (ID = 103741)
7:56 PM: Found Adware: begin2search
7:56 PM: HKCR\btnetw.amo.1\ (3 subtraces) (ID = 104095)
7:56 PM: HKCR\btnetw.amo\ (5 subtraces) (ID = 104096)
7:56 PM: Found Adware: hotsearchbar toolbar
7:56 PM: HKCR\btnetw.amo\ (5 subtraces) (ID = 104096)
7:56 PM: HKCR\btnetw.iiittt.1\ (3 subtraces) (ID = 104097)
7:56 PM: HKCR\btnetw.iiittt\ (5 subtraces) (ID = 104098)
7:56 PM: HKCR\btnetw.iiittt\ (5 subtraces) (ID = 104098)
7:56 PM: HKCR\btnetw.momo.1\ (3 subtraces) (ID = 104099)
7:56 PM: HKCR\btnetw.momo\ (5 subtraces) (ID = 104100)
7:56 PM: HKCR\btnetw.momo\ (5 subtraces) (ID = 104100)
7:56 PM: HKCR\btnetw.ohb.1\ (3 subtraces) (ID = 104101)
7:56 PM: HKCR\btnetw.ohb\ (5 subtraces) (ID = 104102)
7:56 PM: HKCR\btnetw.ohb\ (5 subtraces) (ID = 104102)
7:56 PM: HKCR\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 104109)
7:56 PM: HKCR\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 104109)
7:56 PM: HKCR\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 104118)
7:56 PM: HKCR\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 104118)
7:56 PM: HKCR\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 104119)
7:56 PM: HKCR\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 104119)
7:56 PM: HKCR\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 104120)
7:56 PM: HKCR\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 104120)
7:56 PM: HKCR\interface\{6b882c34-a832-4f5b-bef1-7e198be3f094}\ (8 subtraces) (ID = 104124)
7:56 PM: HKCR\interface\{9b6b4031-1d6d-4c65-acba-021916853822}\ (8 subtraces) (ID = 104126)
7:56 PM: HKCR\interface\{9ff60a27-0c0c-4a6a-a15f-b21b644d67bb}\ (8 subtraces) (ID = 104127)
7:56 PM: HKCR\interface\{15d53b86-e055-43b1-bbee-a91a0f37bd2a}\ (8 subtraces) (ID = 104128)
7:56 PM: HKCR\interface\{f3c41c1d-22f1-4692-8a7a-88de70a2e9e2}\ (8 subtraces) (ID = 104139)
7:56 PM: HKCR\interface\{fa6fa7a5-2c49-4567-ba74-6dd1c36099ee}\ (8 subtraces) (ID = 104141)
7:56 PM: HKLM\software\classes\btnetw.amo.1\ (3 subtraces) (ID = 104145)
7:56 PM: HKLM\software\classes\btnetw.amo\ (5 subtraces) (ID = 104146)
7:56 PM: HKLM\software\classes\btnetw.amo\ (5 subtraces) (ID = 104146)
7:56 PM: HKLM\software\classes\btnetw.iiittt.1\ (3 subtraces) (ID = 104147)
7:56 PM: HKLM\software\classes\btnetw.iiittt\ (5 subtraces) (ID = 104148)
7:56 PM: HKLM\software\classes\btnetw.iiittt\ (5 subtraces) (ID = 104148)
7:56 PM: HKLM\software\classes\btnetw.momo.1\ (3 subtraces) (ID = 104149)
7:56 PM: HKLM\software\classes\btnetw.momo\ (5 subtraces) (ID = 104150)
7:56 PM: HKLM\software\classes\btnetw.momo\ (5 subtraces) (ID = 104150)
7:56 PM: HKLM\software\classes\btnetw.ohb.1\ (3 subtraces) (ID = 104151)
7:56 PM: HKLM\software\classes\btnetw.ohb\ (5 subtraces) (ID = 104152)
7:56 PM: HKLM\software\classes\btnetw.ohb\ (5 subtraces) (ID = 104152)
7:56 PM: HKLM\software\classes\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 104159)
7:56 PM: HKLM\software\classes\clsid\{9ade0443-2ab2-4b23-a3f8-ac520773de12}\ (11 subtraces) (ID = 104159)
7:56 PM: HKLM\software\classes\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 104168)
7:56 PM: HKLM\software\classes\clsid\{bc54b24c-5a97-4c19-9181-8b8a05b2e931}\ (11 subtraces) (ID = 104168)
7:56 PM: HKLM\software\classes\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 104169)
7:56 PM: HKLM\software\classes\clsid\{bd9584ef-c28c-4f6d-8d49-0cee3c0e442f}\ (22 subtraces) (ID = 104169)
7:56 PM: HKLM\software\classes\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 104170)
7:56 PM: HKLM\software\classes\clsid\{c7888681-1a83-4c14-b9a5-95f91240b44f}\ (11 subtraces) (ID = 104170)
7:56 PM: HKLM\software\classes\interface\{6b882c34-a832-4f5b-bef1-7e198be3f094}\ (8 subtraces) (ID = 104174)
7:56 PM: HKLM\software\classes\interface\{9b6b4031-1d6d-4c65-acba-021916853822}\ (8 subtraces) (ID = 104176)
7:56 PM: HKLM\software\classes\interface\{9ff60a27-0c0c-4a6a-a15f-b21b644d67bb}\ (8 subtraces) (ID = 104177)
7:56 PM: HKLM\software\classes\interface\{15d53b86-e055-43b1-bbee-a91a0f37bd2a}\ (8 subtraces) (ID = 104178)
7:56 PM: HKLM\software\classes\interface\{f3c41c1d-22f1-4692-8a7a-88de70a2e9e2}\ (8 subtraces) (ID = 104189)
7:56 PM: HKLM\software\classes\interface\{fa6fa7a5-2c49-4567-ba74-6dd1c36099ee}\ (8 subtraces) (ID = 104191)
7:56 PM: HKLM\software\classes\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 104195)
7:56 PM: HKLM\software\classes\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 104195)
7:56 PM: HKCR\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 104238)
7:56 PM: HKCR\typelib\{bf56be6a-0aea-45f3-8b10-7312876584a8}\ (9 subtraces) (ID = 104238)
7:56 PM: Found Adware: cws_easy-search.biz hijacker
7:56 PM: HKLM\software\microsoft\windows\currentversion\run\ || games acceleration (ID = 117153)
7:56 PM: HKLM\software\microsoft\windows\currentversion\run\ || internet connection wizard (ID = 117154)
7:56 PM: HKLM\software\microsoft\windows\currentversion\run\ || internet mail and news (ID = 117155)
7:56 PM: HKLM\software\microsoft\windows\currentversion\run\ || microsoft internet acceleration utility (ID = 117156)
7:56 PM: HKLM\software\microsoft\windows\currentversion\run\ || microsoft management console (ID = 117157)
7:56 PM: HKLM\software\microsoft\windows\currentversion\run\ || multimedia extensions (ID = 117158)
7:56 PM: Found Adware: drsnsrch.com hijack
7:56 PM: HKLM\software\microsoft\internet explorer\main\ || search page (ID = 128209)
7:56 PM: HKLM\software\microsoft\internet explorer\search\ || customizesearch (ID = 128210)
7:56 PM: HKLM\software\microsoft\internet explorer\search\ || searchassistant (ID = 128211)
7:56 PM: Found Adware: mirar webband
7:56 PM: HKLM\software\relatedpageinstall\ (6 subtraces) (ID = 135120)
7:56 PM: Found Trojan Horse: trojan-downloader-pacisoft
7:56 PM: HKLM\software\microsoft\code store database\distribution units\{972bb342-14a7-4660-83c1-51ddbee171db}\ (8 subtraces) (ID = 136524)
7:56 PM: Found Adware: purityscan
7:56 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\mediaticketsinstaller.ocx (ID = 139077)
7:56 PM: Found Adware: media-motor
7:56 PM: HKLM\software\mm\ (1 subtraces) (ID = 140211)
7:56 PM: Found Adware: search fast communicator toolbar
7:56 PM: HKCR\communicator.communicator\ (3 subtraces) (ID = 140680)
7:56 PM: HKCR\clsid\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb429}\ (6 subtraces) (ID = 140682)
7:56 PM: HKCR\clsid\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb42a}\ (6 subtraces) (ID = 140683)
7:56 PM: HKCR\communicator.communicatormenu button\ (3 subtraces) (ID = 140684)
7:56 PM: HKCR\communicator.communicatortoggle button\ (3 subtraces) (ID = 140685)
7:56 PM: HKLM\software\classes\communicator.communicatormenu button\ (3 subtraces) (ID = 140686)
7:56 PM: HKLM\software\classes\communicator.communicatortoggle button\ (3 subtraces) (ID = 140687)
7:56 PM: HKLM\software\classes\communicator.communicator\ (3 subtraces) (ID = 140691)
7:56 PM: HKLM\software\classes\clsid\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb429}\ (6 subtraces) (ID = 140693)
7:56 PM: HKLM\software\classes\clsid\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb42a}\ (6 subtraces) (ID = 140694)
7:56 PM: HKU\.default\software\communicator toolbar\ (9 subtraces) (ID = 140696)
7:56 PM: HKU\.default\software\microsoft\internet explorer\toolbar\webbrowser\ || {4e7bd74f-2b8d-469e-8dbc-a42eb79cb428} (ID = 140697)
7:56 PM: Found Adware: surfsidekick
7:56 PM: HKLM\software\microsoft\windows\currentversion\run\ || surfsidekick 3 (ID = 143406)
7:56 PM: HKLM\software\surfsidekick3\ (2 subtraces) (ID = 143413)
7:56 PM: Found Adware: delfin
7:56 PM: HKLM\software\wincin\ (2 subtraces) (ID = 359317)
7:56 PM: Found Adware: winad
7:56 PM: HKLM\software\media gateway\ (2 subtraces) (ID = 359545)
7:56 PM: HKCR\mediagatewayx.installer\ (3 subtraces) (ID = 372857)
7:56 PM: HKCR\mediagatewayx.installer\clsid\ (1 subtraces) (ID = 372859)
7:56 PM: HKLM\software\classes\mediagatewayx.installer\ (3 subtraces) (ID = 398902)
7:56 PM: HKLM\software\classes\mediagatewayx.installer\clsid\ (1 subtraces) (ID = 398904)
7:56 PM: Found Adware: drsnsrch hijacker
7:56 PM: HKCR\dsrch.band\ (5 subtraces) (ID = 509134)
7:56 PM: HKCR\typelib\{8f73ac0f-5769-4282-8762-b396a3bff377}\ (9 subtraces) (ID = 509153)
7:56 PM: HKLM\software\classes\dsrch.band\ (5 subtraces) (ID = 509171)
7:56 PM: HKCR\dsrch.band\clsid\ (1 subtraces) (ID = 509361)
7:56 PM: HKCR\dsrch.band\curver\ (1 subtraces) (ID = 509362)
7:56 PM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{00f1d395-4744-40f0-a611-980f61ae2c59}\ (ID = 513230)
7:56 PM: Found Adware: clkoptimizer
7:56 PM: HKLM\software\microsoft\windows\currentversion\run\ || winsync (ID = 601545)
7:56 PM: HKLM\software\classes\typelib\{8f73ac0f-5769-4282-8762-b396a3bff377}\ (9 subtraces) (ID = 646384)
7:56 PM: Found Adware: visfx
7:56 PM: HKLM\software\microsoft\windows\currentversion\uninstall\ovmon\ (2 subtraces) (ID = 712951)
7:56 PM: Found Adware: abetterinternet
7:56 PM: HKLM\software\microsoft\windows\currentversion\uninstall\bsto-1\ (7 subtraces) (ID = 746835)
7:56 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mm81.ocx\ (2 subtraces) (ID = 762354)
7:56 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediagatewayx.dll\ (2 subtraces) (ID = 763026)
7:56 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\mediagatewayx.dll (ID = 763028)
7:56 PM: HKLM\software\qstat\ (5 subtraces) (ID = 769771)
7:56 PM: HKCR\clsid\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8}\ (6 subtraces) (ID = 815132)
7:56 PM: HKLM\software\classes\clsid\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8}\ (6 subtraces) (ID = 815145)
7:56 PM: Found Adware: 180search assistant/zango
7:56 PM: HKLM\software\microsoft\code store database\distribution units\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8}\ (10 subtraces) (ID = 832871)
7:56 PM: Found Adware: shopathomeselect
7:56 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/grinstall7.dll\ (2 subtraces) (ID = 836092)
7:56 PM: HKLM\software\microsoft\windows\currentversion\run\ || apd123 (ID = 861469)
7:56 PM: HKLM\software\qstat\ || brr (ID = 877670)
7:56 PM: HKU\WRSS_Profile_S-1-5-21-2801439982-3646181656-3495054330-500\software\microsoft\internet explorer\urlsearchhooks\ || {02ee5b04-f144-47bb-83fb-a60bd91b74a9} (ID = 143397)
7:56 PM: HKU\WRSS_Profile_S-1-5-21-2801439982-3646181656-3495054330-500\software\microsoft\windows\currentversion\run\ || surfsidekick 3 (ID = 143403)
7:56 PM: HKU\WRSS_Profile_S-1-5-21-2801439982-3646181656-3495054330-500\software\surfsidekick3\ (3 subtraces) (ID = 143412)
7:56 PM: Found Adware: cws-aboutblank
7:56 PM: HKU\S-1-5-21-2801439982-3646181656-3495054330-1003\software\microsoft\internet explorer\main\ || search bar_bak (ID = 115924)
7:56 PM: HKU\S-1-5-21-2801439982-3646181656-3495054330-1003\software\microsoft\internet explorer\main\ || search page_bak (ID = 115925)
7:56 PM: HKU\S-1-5-21-2801439982-3646181656-3495054330-1003\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
7:56 PM: HKU\S-1-5-21-2801439982-3646181656-3495054330-1003\software\psof1\ (10 subtraces) (ID = 136530)
7:56 PM: HKU\S-1-5-21-2801439982-3646181656-3495054330-1003\software\communicator toolbar\ (9 subtraces) (ID = 140688)
7:56 PM: HKU\S-1-5-21-2801439982-3646181656-3495054330-1003\software\microsoft\internet explorer\toolbar\webbrowser\ || {4e7bd74f-2b8d-469e-8dbc-a42eb79cb428} (ID = 140689)
7:56 PM: HKU\S-1-5-21-2801439982-3646181656-3495054330-1003\software\surfsidekick3\ (3 subtraces) (ID = 143412)
7:56 PM: HKU\S-1-5-21-2801439982-3646181656-3495054330-1003\software\microsoft\internet explorer\main\ || search page_bak (ID = 774883)
7:56 PM: HKU\S-1-5-18\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
7:56 PM: HKU\S-1-5-18\software\communicator toolbar\ (9 subtraces) (ID = 140688)
7:56 PM: HKU\S-1-5-18\software\microsoft\internet explorer\toolbar\webbrowser\ || {4e7bd74f-2b8d-469e-8dbc-a42eb79cb428} (ID = 140689)
7:56 PM: HKU\S-1-5-18\software\dsrch\ (7 subtraces) (ID = 509156)
7:56 PM: Registry Sweep Complete, Elapsed Time:00:00:31
7:56 PM: Starting Cookie Sweep
7:56 PM: Found Spy Cookie: 888 cookie
7:56 PM: owner@888[1].txt (ID = 2019)
7:56 PM: Found Spy Cookie: yieldmanager cookie
7:56 PM:
[email protected][2].txt (ID = 3751)
7:56 PM: Found Spy Cookie: adknowledge cookie
7:56 PM: owner@adknowledge[1].txt (ID = 2072)
7:56 PM: Found Spy Cookie: adrevolver cookie
7:56 PM: owner@adrevolver[2].txt (ID = 2088)
7:56 PM: owner@adrevolver[3].txt (ID = 2088)
7:56 PM: Found Spy Cookie: adserver cookie
7:56 PM: owner@adserver[2].txt (ID = 2141)
7:56 PM: Found Spy Cookie: advertising cookie
7:56 PM: owner@advertising[1].txt (ID = 2175)
7:56 PM: Found Spy Cookie: ask cookie
7:56 PM: owner@ask[1].txt (ID = 2245)
7:56 PM: Found Spy Cookie: atlas dmt cookie
7:56 PM: owner@atdmt[2].txt (ID = 2253)
7:56 PM: Found Spy Cookie: belnk cookie
7:56 PM:
[email protected][2].txt (ID = 2293)
7:56 PM: Found Spy Cookie: banner cookie
7:56 PM: owner@banner[1].txt (ID = 2276)
7:56 PM: owner@belnk[1].txt (ID = 2292)
7:56 PM: Found Spy Cookie: bluestreak cookie
7:56 PM: owner@bluestreak[1].txt (ID = 2314)
7:56 PM: Found Spy Cookie: casalemedia cookie
7:56 PM: owner@casalemedia[2].txt (ID = 2354)
7:56 PM:
[email protected][2].txt (ID = 2293)
7:56 PM: Found Spy Cookie: fastclick cookie
7:56 PM: owner@fastclick[1].txt (ID = 2651)
7:56 PM: Found Spy Cookie: overture cookie
7:56 PM:
[email protected][1].txt (ID = 3106)
7:56 PM: Found Spy Cookie: questionmarket cookie
7:56 PM: owner@questionmarket[1].txt (ID = 3217)
7:56 PM: Found Spy Cookie: realmedia cookie
7:56 PM: owner@realmedia[1].txt (ID = 3235)
7:56 PM: Found Spy Cookie: adjuggler cookie
7:56 PM:
[email protected][1].txt (ID = 2071)
7:56 PM: Found Spy Cookie: servedby advertising cookie
7:56 PM:
[email protected][2].txt (ID = 3335)
7:56 PM: Found Spy Cookie: reliablestats cookie
7:56 PM:
[email protected][2].txt (ID = 3254)
7:56 PM: Found Spy Cookie: tradedoubler cookie
7:56 PM: owner@tradedoubler[1].txt (ID = 3575)
7:56 PM: Found Spy Cookie: trafficmp cookie
7:56 PM: owner@trafficmp[2].txt (ID = 3581)
7:56 PM: Found Spy Cookie: myaffiliateprogram.com cookie
7:56 PM:
[email protected][2].txt (ID = 3032)
7:56 PM: Found Spy Cookie: zedo cookie
7:56 PM: owner@zedo[2].txt (ID = 3762)
7:56 PM: system@casalemedia[1].txt (ID = 2354)
7:56 PM: system@zedo[2].txt (ID = 3762)
7:56 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01
7:56 PM: Starting File Sweep
7:57 PM: c:\documents and settings\all users\application data\vidctrl (1 subtraces) (ID = -2147477475)
7:57 PM: Found Adware: cws_ns3
7:57 PM: wmprfptb.prx:ypgwmu (ID = 56287)
7:57 PM: preuninstallcom.exe (ID = 74818)
7:57 PM: Found Adware: coolwebsearch (cws)
7:57 PM: wmprfjpn.prx:foorkk (ID = 54051)
7:57 PM: vmmreg32.dll:jmucx (ID = 56447)
7:57 PM: Found Trojan Horse: lzio
7:57 PM: qekrmujx.exe (ID = 159311)
7:57 PM: HKLM\Software\Microsoft\Windows\CurrentVersion\Run || qekrmujx (ID = 0)
7:57 PM: blue lace 16.bmp:pyxtq (ID = 56447)
7:58 PM: Found Adware: winantispyware 2005
7:58 PM: uwfx5lp_0001_0715netinstaller.exe (ID = 114990)
7:58 PM: wmprfesp.prx:qnkqv (ID = 56447)
7:58 PM: wmprfheb.prx:incwp (ID = 56447)
7:58 PM: wmprfkor.prx:bovbr (ID = 56447)
7:58 PM: uclvf.exe (ID = 159311)
7:58 PM: sskknwrd.dll (ID = 77733)
7:58 PM: msnavpklog.txt:vcelr (ID = 56711)
7:58 PM: mnlwmv.exe (ID = 159311)
7:58 PM: HKLM\Software\Microsoft\Windows\CurrentVersion\Run || mnlwmv (ID = 0)
7:58 PM: m67m.inf (ID = 74028)
7:58 PM: ocgen.log:faalko (ID = 56287)
7:59 PM: stb.exe (ID = 94666)
7:59 PM: ssk.exe (ID = 163864)
7:59 PM: uwfx5lp_0001_0715netinstaller.exe (ID = 114990)
7:59 PM: mediagatewayx.dll (ID = 156819)
7:59 PM: mediaticketsinstaller.inf (ID = 73158)
8:00 PM: sskknwrd.dll (ID = 77733)
8:00 PM: msxmidi.exe.js:gwqvn (ID = 55098)
8:01 PM: auhccup1.dll:jpxurb (ID = 56287)
8:01 PM: active setup log.txt:rofppq (ID = 54051)
8:01 PM: Found Trojan Horse: trojan-downloader-mainstreamdollars
8:01 PM: btnetw3-995329.exe (ID = 155333)
8:01 PM: rifqr.exe (ID = 159311)
8:01 PM: HKLM\Software\Microsoft\Windows\CurrentVersion\Run || rifqr (ID = 0)
8:02 PM: wingenerics.dll (ID = 50187)
8:02 PM: comsetup.log:xdsnj (ID = 53966)
8:02 PM: ocmsn.log:jsouf (ID = 56447)
8:02 PM: orun32.isu:uurmb (ID = 53966)
8:03 PM: wmprfrus.prx:vpdtr (ID = 56447)
8:03 PM: mqjwnm.exe (ID = 159311)
8:03 PM: HKLM\Software\Microsoft\Windows\CurrentVersion\Run || mqjwnm (ID = 0)
8:04 PM: sskcwrd.dll (ID = 77712)
8:04 PM: Warning: Failed to access drive F:
8:04 PM: File Sweep Complete, Elapsed Time: 00:08:08
8:04 PM: Full Sweep has completed. Elapsed time 00:09:59
8:04 PM: Traces Found: 844
8:15 PM: Removal process initiated
8:15 PM: Quarantining All Traces: apropos
8:15 PM: Quarantining All Traces: begin2search
8:15 PM: Quarantining All Traces: hotsearchbar toolbar
8:16 PM: Quarantining All Traces: cws_easy-search.biz hijacker
8:16 PM: Quarantining All Traces: drsnsrch.com hijack
8:16 PM: Quarantining All Traces: mirar webband
8:16 PM: Quarantining All Traces: trojan-downloader-pacisoft
8:16 PM: Quarantining All Traces: purityscan
8:16 PM: Quarantining All Traces: media-motor
8:16 PM: Quarantining All Traces: search fast communicator toolbar
8:16 PM: Warning: Quarantine could not read registry value for HKU\.default\software\microsoft\internet explorer\toolbar\webbrowser\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb428}\. Failed to export registry value ".default\software\microsoft\internet explorer\toolbar\webbrowser\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb428}". Key/Value does not exist
8:16 PM: Quarantining All Traces: surfsidekick
8:17 PM: Quarantining All Traces: delfin
8:17 PM: Quarantining All Traces: winad
8:17 PM: Quarantining All Traces: drsnsrch hijacker
8:17 PM: Quarantining All Traces: clkoptimizer
8:17 PM: Quarantining All Traces: visfx
8:17 PM: Quarantining All Traces: abetterinternet
8:17 PM: Quarantining All Traces: 180search assistant/zango
8:17 PM: Quarantining All Traces: shopathomeselect
8:17 PM: Quarantining All Traces: cws-aboutblank
8:17 PM: Warning: Quarantine could not read registry value for HKU\S-1-5-21-2801439982-3646181656-3495054330-1003\software\microsoft\internet explorer\main\search page_bak\. Failed to export registry value "S-1-5-21-2801439982-3646181656-3495054330-1003\software\microsoft\internet explorer\main\search page_bak". Key/Value does not exist
8:17 PM: Quarantining All Traces: 888 cookie
8:17 PM: Quarantining All Traces: yieldmanager cookie
8:17 PM: Quarantining All Traces: adknowledge cookie
8:17 PM: Quarantining All Traces: adrevolver cookie
8:17 PM: Quarantining All Traces: adserver cookie
8:17 PM: Quarantining All Traces: advertising cookie
8:17 PM: Quarantining All Traces: ask cookie
8:17 PM: Quarantining All Traces: atlas dmt cookie
8:17 PM: Quarantining All Traces: belnk cookie
8:17 PM: Quarantining All Traces: banner cookie
8:17 PM: Quarantining All Traces: bluestreak cookie
8:17 PM: Quarantining All Traces: casalemedia cookie
8:17 PM: Quarantining All Traces: fastclick cookie
8:17 PM: Quarantining All Traces: overture cookie
8:17 PM: Quarantining All Traces: questionmarket cookie
8:17 PM: Quarantining All Traces: realmedia cookie
8:17 PM: Quarantining All Traces: adjuggler cookie
8:17 PM: Quarantining All Traces: servedby advertising cookie
8:17 PM: Quarantining All Traces: reliablestats cookie
8:17 PM: Quarantining All Traces: tradedoubler cookie
8:17 PM: Quarantining All Traces: trafficmp cookie
8:17 PM: Quarantining All Traces: myaffiliateprogram.com cookie
8:17 PM: Quarantining All Traces: zedo cookie
8:17 PM: Quarantining All Traces: cws_ns3
8:18 PM: Quarantining All Traces: coolwebsearch (cws)
8:18 PM: Quarantining All Traces: lzio
8:18 PM: Quarantining All Traces: winantispyware 2005
8:18 PM: Quarantining All Traces: trojan-downloader-mainstreamdollars
8:18 PM: Removal process completed. Elapsed time 00:03:14
8:19 PM: Program Version 4.5.3 (Build 560) Using Spyware Definitions 555
9:44 PM: IE Security Shield: found: C:\WINDOWS\ELITEMEDIAPOP.EXE -- IE Security modification denied
9:45 PM: IE Security Shield: found: C:\WINDOWS\ELITEMEDIAPOP.EXE -- IE Security modification denied
9:45 PM: ActiveX Shield: found: Adware: mirar webband, version 1.0.0.0 -- Installation denied
9:45 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
9:45 PM: The Spy Communication shield has blocked access to: downloads.shopathomeselect.com
9:45 PM: BHO Shield: found: WinNB57.dll-- BHO installation denied at user request
9:45 PM: BHO Shield: found: WinNB57.dll-- BHO installation denied at user request
9:45 PM: IE Security Shield: found: C:\WINDOWS\ELITEMEDIAPOP.EXE -- IE Security modification denied
9:49 PM: Memory Shield: Found: Memory-resident threat shopathomeselect, version 1.0.0.0
9:49 PM: Detected running threat: shopathomeselect
9:49 PM: | End of Session, Sunday, October 16, 2005 |
********
7:36 PM: | Start of Session, Sunday, October 16, 2005 |
7:36 PM: Spy Sweeper started
7:36 PM: Sweep initiated using definitions version 555
7:36 PM: Starting Memory Sweep
7:36 PM: Sweep Canceled
7:36 PM: Memory Sweep Complete, Elapsed Time: 00:00:07
7:36 PM: Traces Found: 0
7:54 PM: Program Version 4.5.3 (Build 560) Using Spyware Definitions 555
7:54 PM: | End of Session, Sunday, October 16, 2005 |
********
9:25 PM: | Start of Session, Friday, October 14, 2005 |
9:25 PM: Spy Sweeper started
9:25 PM: Sweep initiated using definitions version 555
9:25 PM: Starting Memory Sweep
9:27 PM: Sweep Canceled
9:27 PM: Memory Sweep Complete, Elapsed Time: 00:01:36
9:27 PM: Traces Found: 0
9:40 AM: Memory Shield: Found: Memory-resident threat lzio, version 1.0.0.0
9:40 AM: Detected running threat: lzio
11:21 AM: Ignored memory-resident threat: lzio
11:21 AM: The Spy Communication shield has blocked access to: paypopup.com
11:21 AM: The Spy Communication shield has blocked access to: paypopup.com
11:26 AM: The Spy Communication shield has blocked access to: focusin.ads.targetnet.com
11:26 AM: The Spy Communication shield has blocked access to: focusin.ads.targetnet.com
4:36 PM: ActiveX Shield: found: Adware: winad, version 1.0.0.0 -- Installation denied
4:37 PM: Spy Installation Shield: found: Adware: winad, version 1.0.0.0 -- Execution Denied
4:37 PM: Processing Startup Alerts
4:37 PM: Removed Startup entry: mnlwmv
5:27 PM: Memory Shield: Found: Memory-resident threat lzio, version 1.0.0.0
5:27 PM: Detected running threat: lzio
5:27 PM: Ignored memory-resident threat: lzio
7:38 PM: Memory Shield: Found: Memory-resident threat lzio, version 1.0.0.0
7:38 PM: Detected running threat: lzio
7:38 PM: Ignored memory-resident threat: lzio
7:50 PM: Memory Shield: Found: Memory-resident threat lzio, version 1.0.0.0
7:50 PM: Detected running threat: lzio
7:50 PM: Ignored memory-resident threat: lzio
9:06 PM: The Spy Communication shield has blocked access to: updates.lzio.com
9:06 PM: The Spy Communication shield has blocked access to: updates.lzio.com
9:08 PM: The Spy Communication shield has blocked access to: count.exitexchange.com
9:08 PM: The Spy Communication shield has blocked access to: count.exitexchange.com
9:14 PM: The Spy Communication shield has blocked access to: paypopup.com
9:14 PM: The Spy Communication shield has blocked access to: paypopup.com
9:17 PM: Memory Shield: Found: Memory-resident threat lzio, version 1.0.0.0
9:17 PM: Detected running threat: lzio
9:17 PM: Ignored memory-resident threat: lzio
9:27 PM: Memory Shield: Found: Memory-resident threat lzio, version 1.0.0.0
9:27 PM: Detected running threat: lzio
9:27 PM: Ignored memory-resident threat: lzio
12:25 AM: The Spy Communication shield has blocked access to: paypopup.com
12:25 AM: The Spy Communication shield has blocked access to: paypopup.com
2:25 AM: The Spy Communication shield has blocked access to: paypopup.com
2:25 AM: The Spy Communication shield has blocked access to: paypopup.com
5:25 AM: The Spy Communication shield has blocked access to: paypopup.com
5:25 AM: The Spy Communication shield has blocked access to: paypopup.com
9:25 AM: The Spy Communication shield has blocked access to: paypopup.com
9:25 AM: The Spy Communication shield has blocked access to: paypopup.com
11:58 AM: IE Security Shield: found: C:\WINDOWS\SYSTEM32\RUNDLL32.EXE -- IE Security modification allowed at user request
12:10 PM: Error: Access violation at address 0055E852 in module 'WRSSSDK.exe'. Read of address 00000004.
3:45 PM: Updating spyware definitions
3:45 PM: Your definitions are up to date.
3:45 PM: Updating spyware definitions
3:45 PM: Your definitions are up to date.
3:45 PM: Updating spyware definitions
3:45 PM: Your definitions are up to date.
3:49 PM: Memory Shield: Found: Memory-resident threat lzio, version 1.0.0.0
3:49 PM: Detected running threat: lzio
3:49 PM: Ignored memory-resident threat: lzio
7:35 PM: Updating spyware definitions
7:35 PM: Your definitions are up to date.
7:35 PM: Updating spyware definitions
7:35 PM: Your definitions are up to date.
7:36 PM: Only Sweep Folders Where Threats Are Known to Reside
7:36 PM: | End of Session, Sunday, October 16, 2005 |
********
9:25 PM: | Start of Session, Friday, October 14, 2005 |
9:25 PM: Spy Sweeper started
9:25 PM: Sweep initiated using definitions version 555
9:25 PM: Starting Memory Sweep
9:25 PM: Sweep Canceled
9:25 PM: Memory Sweep Complete, Elapsed Time: 00:00:19
9:25 PM: Traces Found: 0
9:25 PM: Only Sweep Folders Where Threats Are Known to Reside
9:25 PM: | End of Session, Friday, October 14, 2005 |
********
6:15 PM: | Start of Session, Friday, October 14, 2005 |
6:15 PM: Spy Sweeper started
6:15 PM: Sweep initiated using definitions version 555
6:15 PM: Starting Memory Sweep
6:15 PM: Sweep Canceled
6:15 PM: Memory Sweep Complete, Elapsed Time: 00:00:03
6:15 PM: Traces Found: 0
9:06 PM: The Spy Communication shield has blocked access to: updates.lzio.com
9:06 PM: The Spy Communication shield has blocked access to: updates.lzio.com
9:06 PM: The Spy Communication shield has blocked access to: count.exitexchange.com
9:06 PM: The Spy Communication shield has blocked access to: count.exitexchange.com
9:07 PM: Processing Startup Alerts
9:07 PM: Removed Startup entry: mnlwmv
9:08 PM: The Spy Communication shield has blocked access to: count.exitexchange.com
9:08 PM: The Spy Communication shield has blocked access to: count.exitexchange.com
9:12 PM: The Spy Communication shi