********
2:42 PM: | Start of Session, Sunday, October 30, 2005 |
2:42 PM: Spy Sweeper started
2:42 PM: Sweep initiated using definitions version 564
2:42 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:42 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:42 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:42 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:42 PM: Starting Memory Sweep
2:43 PM: Found Adware: icannnews
2:43 PM: Detected running threat: C:\WINDOWS\system32\svrstr.dll (ID = 83)
2:43 PM: Detected running threat: C:\WINDOWS\system32\l40u0ed9eh0.dll (ID = 83)
2:43 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:43 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:43 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:43 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:44 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:44 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:44 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:44 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:46 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:46 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:46 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:46 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:46 PM: Memory Sweep Complete, Elapsed Time: 00:04:09
2:46 PM: Starting Registry Sweep
2:47 PM: Found Adware: linkmaker
2:47 PM: HKLM\software\classes\typelib\{423550e9-2f83-4678-9929-c1774088b180}\ (9 subtraces) (ID = 129743)
2:47 PM: HKCR\typelib\{423550e9-2f83-4678-9929-c1774088b180}\ (9 subtraces) (ID = 129750)
2:47 PM: Found Adware: 180search assistant/zango
2:47 PM: HKCR\clientax.requiredcomponent.1\ (3 subtraces) (ID = 135597)
2:47 PM: HKCR\clientax.requiredcomponent\ (5 subtraces) (ID = 135598)
2:47 PM: HKCR\clsid\{0ac49246-419b-4ee0-8917-8818daad6a4e}\ (17 subtraces) (ID = 135599)
2:47 PM: HKCR\clsid\{21b4acc4-8874-4aec-aeac-f567a249b4d4}\ (9 subtraces) (ID = 135601)
2:47 PM: HKCR\ncmyb.sabho.1\ (3 subtraces) (ID = 135611)
2:47 PM: HKCR\ncmyb.sabho\ (5 subtraces) (ID = 135612)
2:47 PM: HKLM\software\classes\clientax.requiredcomponent.1\ (3 subtraces) (ID = 135622)
2:47 PM: HKLM\software\classes\clientax.requiredcomponent\ (5 subtraces) (ID = 135623)
2:47 PM: HKLM\software\classes\clsid\{0ac49246-419b-4ee0-8917-8818daad6a4e}\ (17 subtraces) (ID = 135624)
2:47 PM: HKLM\software\classes\clsid\{21b4acc4-8874-4aec-aeac-f567a249b4d4}\ (9 subtraces) (ID = 135625)
2:47 PM: HKLM\software\classes\ncmyb.sabho.1\ (3 subtraces) (ID = 135632)
2:47 PM: HKLM\software\classes\ncmyb.sabho\ (5 subtraces) (ID = 135633)
2:47 PM: Found Adware: targetsoft
2:47 PM: HKLM\software\microsoft\windows\currentversion\uninstall\tsl installer\ (1 subtraces) (ID = 143608)
2:47 PM: Found Adware: targetsaver
2:47 PM: HKLM\software\microsoft\windows\currentversion\uninstall\tsl installer\ (1 subtraces) (ID = 143608)
2:47 PM: Found Adware: ist yoursitebar
2:47 PM: HKCR\interface\{03b800f9-2536-4441-8cda-2a3e6d15b4f8}\ (8 subtraces) (ID = 147832)
2:47 PM: HKCR\interface\{dfbcc1eb-b149-487e-80c1-cc1562021542}\ (8 subtraces) (ID = 147835)
2:47 PM: HKLM\software\classes\interface\{03b800f9-2536-4441-8cda-2a3e6d15b4f8}\ (8 subtraces) (ID = 147838)
2:47 PM: HKLM\software\classes\interface\{dfbcc1eb-b149-487e-80c1-cc1562021542}\ (8 subtraces) (ID = 147841)
2:47 PM: HKLM\software\classes\typelib\{4ee12b71-aa5e-45ec-8666-2db3ad3fdf44}\ (7 subtraces) (ID = 147842)
2:47 PM: Found Adware: ist software
2:47 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/ysbactivex.dll\ (2 subtraces) (ID = 147854)
2:47 PM: HKCR\typelib\{4ee12b71-aa5e-45ec-8666-2db3ad3fdf44}\ (7 subtraces) (ID = 147861)
2:47 PM: HKCR\typelib\{68bf4626-d66b-4383-a6af-62e57e9b6cd4}\ (7 subtraces) (ID = 147926)
2:47 PM: HKCR\interface\{f1f1e775-1b21-454d-8d38-7c16519969e5}\ (8 subtraces) (ID = 169517)
2:47 PM: HKLM\software\classes\interface\{f1f1e775-1b21-454d-8d38-7c16519969e5}\ (8 subtraces) (ID = 169520)
2:47 PM: Found Adware: quicklink search toolbar
2:47 PM: HKCR\clsid\{8b6da27e-7f64-4694-8f8f-dc87ab8c6b22}\ (8 subtraces) (ID = 359437)
2:47 PM: HKLM\software\classes\clsid\{8b6da27e-7f64-4694-8f8f-dc87ab8c6b22}\ (8 subtraces) (ID = 359440)
2:47 PM: HKCR\quicklinks.linktracker.1\ (3 subtraces) (ID = 359448)
2:47 PM: HKCR\quicklinks.linktracker\ (3 subtraces) (ID = 359449)
2:47 PM: HKCR\quicklinks.quicklinksfilter.1\ (3 subtraces) (ID = 359450)
2:47 PM: HKCR\quicklinks.quicklinksfilter\ (3 subtraces) (ID = 359451)
2:47 PM: HKLM\software\classes\quicklinks.linktracker.1\ (3 subtraces) (ID = 359452)
2:47 PM: HKLM\software\classes\quicklinks.linktracker\ (3 subtraces) (ID = 359453)
2:47 PM: HKLM\software\classes\quicklinks.quicklinksfilter.1\ (3 subtraces) (ID = 359454)
2:47 PM: HKLM\software\classes\quicklinks.quicklinksfilter\ (3 subtraces) (ID = 359455)
2:47 PM: HKLM\software\classes\typelib\{68bf4626-d66b-4383-a6af-62e57e9b6cd4}\ (7 subtraces) (ID = 396447)
2:47 PM: HKCR\clsid\{3551784b-e99a-474f-b782-3ec814442918}\ (10 subtraces) (ID = 727328)
2:47 PM: HKLM\software\classes\clsid\{3551784b-e99a-474f-b782-3ec814442918}\ (10 subtraces) (ID = 727357)
2:47 PM: HKCR\qlink.qlfilter\ (3 subtraces) (ID = 890588)
2:47 PM: HKCR\qlink.qlfilter.1\ (3 subtraces) (ID = 890592)
2:47 PM: HKCR\qlink.qlhelper\ (3 subtraces) (ID = 890596)
2:47 PM: HKCR\qlink.qlhelper.1\ (3 subtraces) (ID = 890600)
2:47 PM: HKCR\clsid\{aa3c0ffe-758e-4c41-b1b9-2d711915a938}\ (5 subtraces) (ID = 890604)
2:47 PM: HKCR\clsid\{e225ab73-4d7e-45f7-9425-47d2f7c7a8ab}\ (7 subtraces) (ID = 890613)
2:47 PM: HKCR\typelib\{090712ed-1622-4227-94d3-f573a9c2577f}\ (7 subtraces) (ID = 890624)
2:47 PM: HKLM\software\classes\qlink.qlfilter\ (3 subtraces) (ID = 890661)
2:47 PM: HKLM\software\classes\qlink.qlfilter.1\ (3 subtraces) (ID = 890665)
2:47 PM: HKLM\software\classes\qlink.qlhelper\ (3 subtraces) (ID = 890669)
2:47 PM: HKLM\software\classes\qlink.qlhelper.1\ (3 subtraces) (ID = 890673)
2:47 PM: HKLM\software\classes\clsid\{aa3c0ffe-758e-4c41-b1b9-2d711915a938}\ (5 subtraces) (ID = 890677)
2:47 PM: HKLM\software\classes\clsid\{e225ab73-4d7e-45f7-9425-47d2f7c7a8ab}\ (7 subtraces) (ID = 890686)
2:47 PM: Found Adware: instant access
2:47 PM: HKLM\software\classes\clsid\{e225ab73-4d7e-45f7-9425-47d2f7c7a8ab}\progid\ (1 subtraces) (ID = 890691)
2:47 PM: HKLM\software\classes\typelib\{090712ed-1622-4227-94d3-f573a9c2577f}\ (7 subtraces) (ID = 890697)
2:47 PM: HKLM\software\microsoft\windows\currentversion\explorer\browser qlhelper objects\{aa3c0ffe-758e-4c41-b1b9-2d711915a938}\ (ID = 909564)
2:47 PM: HKU\S-1-5-21-602162358-746137067-1343024091-1003\software\tsl2\ (1 subtraces) (ID = 143616)
2:47 PM: Registry Sweep Complete, Elapsed Time:00:00:17
2:47 PM: Starting Cookie Sweep
2:47 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
2:47 PM: Starting File Sweep
2:47 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:47 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:47 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:47 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:47 PM: a0038159.dll (ID = 78253)
2:48 PM: Found Adware: ist sidefind
2:48 PM: a0020567.dll (ID = 157822)
2:48 PM: a0038474.exe (ID = 168232)
2:48 PM: a0038475.exe (ID = 131326)
2:48 PM: a0035849.dll (ID = 181444)
2:48 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:48 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:48 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:48 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:48 PM: Found Adware: internetoptimizer
2:48 PM: a0020572.exe (ID = 122872)
2:48 PM: backup-20051027-153416-489.dll (ID = 181444)
2:49 PM: Found Adware: spysheriff
2:49 PM: a0034343.exe (ID = 178643)
2:49 PM: Found Adware: sp2ms
2:49 PM: a0033814.exe (ID = 148760)
2:49 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:49 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:49 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:49 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:50 PM: a0036899.exe (ID = 178643)
2:50 PM: a0036783.exe (ID = 178643)
2:51 PM: Found Adware: ist istbar
2:51 PM: jfghjhhfgudk.exe (ID = 181597)
2:51 PM: msresearch.exe.q_2cf9cf0_q (ID = 148760)
2:51 PM: a0020568.exe (ID = 154905)
2:51 PM: a0020526.exe (ID = 141831)
2:51 PM: Found Adware: surf accuracy
2:51 PM: uninstall.exe (ID = 156655)
2:51 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:51 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:51 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:51 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:51 PM: preuninstallql.exe (ID = 131326)
2:51 PM: a0021727.exe (ID = 73428)
2:51 PM: a0020623.exe (ID = 161561)
2:51 PM: glf63glf63.exe (ID = 166444)
2:51 PM: a0038202.exe (ID = 78285)
2:51 PM: drsmartload.exe (ID = 178567)
2:52 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:52 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:52 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:52 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:52 PM: a0033804.exe (ID = 144585)
2:52 PM: a0037036.dll (ID = 181444)
2:53 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:53 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:53 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:53 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:54 PM: a0020571.dll (ID = 161559)
2:55 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:55 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:55 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:55 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:55 PM: mrwzm.exe.q_18d06000_q (ID = 107479)
2:55 PM: Found Adware: look2me
2:55 PM: a0034511.dll (ID = 163672)
2:55 PM: Found Adware: apropos
2:55 PM: wingenerics.dll (ID = 50187)
2:56 PM: a0036805.dll (ID = 163672)
2:56 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:56 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:56 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:56 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:57 PM: res34.tmp (ID = 107353)
2:57 PM: installer.exe (ID = 168558)
2:57 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:57 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:57 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:57 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:57 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:57 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:57 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:57 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:58 PM: Found Trojan Horse: trojan-downloader-nextern
2:58 PM: drin.exe (ID = 168231)
2:59 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:59 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:59 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:59 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:59 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:59 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:59 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:59 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:59 PM: a0035859.dll (ID = 163672)
2:59 PM: dc13.exe (ID = 168232)
3:00 PM: a0038430.exe (ID = 166444)
3:00 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:00 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:00 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:00 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:00 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:00 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:00 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:00 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:00 PM: a0034334.exe (ID = 178643)
3:00 PM: a0034351.exe (ID = 73428)
3:00 PM: a0033816.exe (ID = 148759)
3:00 PM: a0038429.exe (ID = 166206)
3:01 PM: a0038165.exe (ID = 64496)
3:01 PM: a0033818.exe (ID = 107479)
3:01 PM: a0034346.exe (ID = 178643)
3:01 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:01 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:01 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:01 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:01 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:01 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:01 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:01 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:01 PM: firaflib.dll (ID = 163672)
3:01 PM: mq4sdmod.dll (ID = 163672)
3:01 PM: sogina.dll (ID = 163672)
3:02 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:02 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:02 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:02 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:02 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:02 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:02 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:02 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:03 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:04 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:04 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:04 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:04 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:04 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:04 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:04 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:04 PM: Found Adware: isearch desktop search
3:04 PM: mte3ndi6odoxng.exe (ID = 178687)
3:04 PM: Found Adware: powerscan
3:04 PM: a0021728.exe (ID = 72675)
3:04 PM: Found Adware: personal money tree
3:04 PM: pmt.exe (ID = 137597)
3:05 PM: a0038086.exe (ID = 178643)
3:05 PM: a0037970.exe (ID = 178643)
3:05 PM: sp2update00.exe.q_2cf5760_q (ID = 148759)
3:05 PM: jfghjfgudk.exe (ID = 181597)
3:05 PM: d3c6f.tmp (ID = 153752)
3:05 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:05 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:05 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:05 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:05 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:05 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:05 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:05 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:06 PM: f1f5e.tmp (ID = 168162)
3:06 PM: a0037992.dll (ID = 163672)
3:06 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:06 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:06 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:06 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:06 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:06 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:06 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:06 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:07 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:07 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:07 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:07 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:09 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:09 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:10 PM: a0020569.exe (ID = 72679)
3:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:10 PM: stimgvw.dll (ID = 163672)
3:11 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:11 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:11 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:11 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:12 PM: a0038197.exe (ID = 78284)
3:12 PM: a0038199.exe (ID = 78246)
3:12 PM: tsuninst.exe (ID = 78276)
3:13 PM: tsupdate_4_0_3_9_b2.exe (ID = 78281)
3:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:13 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:13 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:14 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:14 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:14 PM: tsinstall_4_0_3_8_b17.exe (ID = 78267)
3:14 PM: 180sainstallersilsais1.exe (ID = 107349)
3:15 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:15 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:15 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:15 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:15 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:15 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:15 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:15 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:16 PM: a0033871.dll (ID = 163672)
3:17 PM: a0021475.dll (ID = 157821)
3:17 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:17 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:17 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:17 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:17 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:17 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:17 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:17 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:18 PM: a0038164.exe (ID = 64496)
3:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:19 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:19 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:19 PM: Found Adware: isearch toolbar
3:19 PM: cmdinst.exe (ID = 154747)
3:19 PM: a0037046.dll (ID = 163672)
3:20 PM: iinstall.exe (ID = 181597)
3:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:20 PM: sais.exe (ID = 93787)
3:20 PM: saishook.dll (ID = 70604)
3:20 PM: sais_gdf.dat (ID = 93789)
3:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:20 PM: qlink32.dll (ID = 153756)
3:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:22 PM: Found System Monitor: potentially rootkit-masked files
3:22 PM: wsnetcfg.exe (ID = 0)
3:22 PM: lz3owser.exe (ID = 0)
3:22 PM: ace.dll (ID = 0)
3:22 PM: data.bin (ID = 0)
3:22 PM: rdbslm75.sys (ID = 0)
3:22 PM: ipnfil32.exe (ID = 0)
3:22 PM: ai_30-10-2005.log (ID = 0)
3:22 PM: ai_26-10-2005.log (ID = 0)
3:22 PM: ai_29-10-2005.log (ID = 0)
3:22 PM: ai_27-10-2005.log (ID = 0)
3:22 PM: ai_28-10-2005.log (ID = 0)
3:22 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:22 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:22 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:22 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:22 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:22 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:22 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:22 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:23 PM: Warning: Unhandled Archive Type
3:24 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:24 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:24 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:24 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:24 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:24 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:24 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:24 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:26 PM: Warning: Unhandled Archive Type
3:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:26 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:26 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:26 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:26 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:27 PM: Warning: Invalid Stream
3:27 PM: Warning: Invalid Stream
3:27 PM: Warning: Invalid Stream
3:27 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:27 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:28 PM: File Sweep Complete, Elapsed Time: 00:40:44
3:28 PM: Full Sweep has completed. Elapsed time 00:45:15
3:28 PM: Traces Found: 448
3:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:28 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:28 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:28 PM: Removal process initiated
3:29 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:29 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:30 PM: Quarantining All Traces: potentially rootkit-masked files
3:30 PM: potentially rootkit-masked files is in use. It will be removed on reboot.
3:30 PM: wsnetcfg.exe is in use. It will be removed on reboot.
3:30 PM: lz3owser.exe is in use. It will be removed on reboot.
3:30 PM: ace.dll is in use. It will be removed on reboot.
3:30 PM: data.bin is in use. It will be removed on reboot.
3:30 PM: rdbslm75.sys is in use. It will be removed on reboot.
3:30 PM: ipnfil32.exe is in use. It will be removed on reboot.
3:30 PM: ai_30-10-2005.log is in use. It will be removed on reboot.
3:30 PM: ai_26-10-2005.log is in use. It will be removed on reboot.
3:30 PM: ai_29-10-2005.log is in use. It will be removed on reboot.
3:30 PM: ai_27-10-2005.log is in use. It will be removed on reboot.
3:30 PM: ai_28-10-2005.log is in use. It will be removed on reboot.
3:30 PM: Quarantining All Traces: look2me
3:30 PM: Quarantining All Traces: spysheriff
3:30 PM: Quarantining All Traces: 180search assistant/zango
3:30 PM: Quarantining All Traces: apropos
3:30 PM: apropos is in use. It will be removed on reboot.
3:30 PM: wingenerics.dll is in use. It will be removed on reboot.
3:30 PM: Quarantining All Traces: icannnews
3:30 PM: icannnews is in use. It will be removed on reboot.
3:30 PM: C:\WINDOWS\system32\svrstr.dll is in use. It will be removed on reboot.
3:30 PM: C:\WINDOWS\system32\l40u0ed9eh0.dll is in use. It will be removed on reboot.
3:30 PM: Quarantining All Traces: instant access
3:30 PM: Quarantining All Traces: internetoptimizer
3:30 PM: Quarantining All Traces: isearch desktop search
3:30 PM: Quarantining All Traces: isearch toolbar
3:30 PM: Quarantining All Traces: ist istbar
3:30 PM: Quarantining All Traces: ist sidefind
3:30 PM: Quarantining All Traces: ist software
3:30 PM: Quarantining All Traces: ist yoursitebar
3:31 PM: Quarantining All Traces: linkmaker
3:31 PM: Quarantining All Traces: personal money tree
3:31 PM: Quarantining All Traces: powerscan
3:31 PM: Quarantining All Traces: quicklink search toolbar
3:31 PM: Quarantining All Traces: sp2ms
3:31 PM: Quarantining All Traces: surf accuracy
3:31 PM: Quarantining All Traces: targetsaver
3:31 PM: Quarantining All Traces: targetsoft
3:31 PM: Quarantining All Traces: trojan-downloader-nextern
3:31 PM: Warning: Launched explorer.exe
3:31 PM: Warning: Quarantine process could not restart Explorer.
3:31 PM: Removal process completed. Elapsed time 00:02:46
********
2:25 PM: | Start of Session, Sunday, October 30, 2005 |
2:25 PM: Spy Sweeper started
2:26 PM: Your spyware definitions have been updated.
2:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:28 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:28 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:29 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:29 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:31 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:31 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:33 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:33 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:36 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:36 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:37 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:37 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:39 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:39 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:39 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:39 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:40 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:40 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:40 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:40 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:41 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:41 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
2:41 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:41 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
2:42 PM: | End of Session, Sunday, October 30, 2005 |
Edited by Slyphox, 30 October 2005 - 02:43 PM.