********
7:13 PM: | Start of Session, Thursday, November 10, 2005 |
7:13 PM: Spy Sweeper started
7:13 PM: Sweep initiated using definitions version 571
7:13 PM: Starting Memory Sweep
7:14 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:14 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:14 PM: Found Adware: icannnews
7:14 PM: Detected running threat: C:\WINDOWS\system32\guard.tmp (ID = 83)
7:14 PM: Found Adware: virtumonde
7:14 PM: Detected running threat: C:\WINDOWS\system32\ddccy.dll (ID = 77)
7:14 PM: Detected running threat: C:\WINDOWS\system32\kt48l7hu1.dll (ID = 83)
7:15 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:15 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:15 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:15 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:15 PM: Detected running threat: C:\WINDOWS\system32\cxyptui.dll (ID = 83)
7:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:17 PM: Memory Sweep Complete, Elapsed Time: 00:03:46
7:17 PM: Starting Registry Sweep
7:18 PM: Found Adware: look2me
7:18 PM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\h323tsp\ (6 subtraces) (ID = 129939)
7:18 PM: HKCR\msevents.msevents\ (5 subtraces) (ID = 749130)
7:18 PM: HKCR\msevents.msevents.1\ (3 subtraces) (ID = 749136)
7:18 PM: HKLM\software\classes\msevents.msevents\ (5 subtraces) (ID = 749153)
7:18 PM: HKLM\software\classes\msevents.msevents.1\ (3 subtraces) (ID = 749157)
7:18 PM: Found Adware: ist yoursitebar
7:18 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\conflict.1\ysbactivex.dll (ID = 762453)
7:18 PM: HKCR\clsid\{52b1dfc7-aafc-4362-b103-868b0683c697}\ (12 subtraces) (ID = 812324)
7:18 PM: HKLM\software\classes\clsid\{52b1dfc7-aafc-4362-b103-868b0683c697}\ (12 subtraces) (ID = 812338)
7:18 PM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{52b1dfc7-aafc-4362-b103-868b0683c697}\ (ID = 812351)
7:18 PM: Found Trojan Horse: 2nd-thought
7:18 PM: HKU\S-1-5-21-579048704-2228840358-292467358-1003\software\winupdt\ (2 subtraces) (ID = 102022)
7:18 PM: Registry Sweep Complete, Elapsed Time:00:00:27
7:18 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:18 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:18 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:18 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:18 PM: Starting Cookie Sweep
7:18 PM: Found Spy Cookie: primaryads cookie
7:18 PM: owner@1.primaryads[2].txt (ID = 3190)
7:18 PM: Found Spy Cookie: 10101 cookie
7:18 PM: owner@10101[1].txt (ID = 1917)
7:18 PM: Found Spy Cookie: 10102 cookie
7:18 PM: owner@10102[2].txt (ID = 1919)
7:18 PM: Found Spy Cookie: 10105 cookie
7:18 PM: owner@10105[2].txt (ID = 1923)
7:18 PM: Found Spy Cookie: 2o7.net cookie
7:18 PM: owner@2o7[2].txt (ID = 1957)
7:18 PM: Found Spy Cookie: 365 cookie
7:18 PM: owner@365[1].txt (ID = 1963)
7:18 PM: Found Spy Cookie: 382 cookie
7:18 PM: owner@382[1].txt (ID = 1965)
7:18 PM: Found Spy Cookie: 3 cookie
7:18 PM: owner@3[2].txt (ID = 1959)
7:18 PM: Found Spy Cookie: 412 cookie
7:18 PM: owner@412[1].txt (ID = 1969)
7:18 PM: Found Spy Cookie: 5 cookie
7:18 PM: owner@5[2].txt (ID = 1979)
7:18 PM: Found Spy Cookie: 64.62.232 cookie
7:18 PM: owner@64.62.232[1].txt (ID = 1987)
7:18 PM: owner@64.62.232[2].txt (ID = 1987)
7:18 PM: owner@64.62.232[3].txt (ID = 1987)
7:18 PM: owner@64.62.232[4].txt (ID = 1987)
7:18 PM: owner@64.62.232[6].txt (ID = 1987)
7:18 PM: Found Spy Cookie: 69.28.210 cookie
7:18 PM: owner@69.28.210[1].txt (ID = 2003)
7:18 PM: Found Spy Cookie: 735 cookie
7:18 PM: owner@735[1].txt (ID = 2009)
7:18 PM: Found Spy Cookie: 80503492 cookie
7:18 PM: owner@80503492[1].txt (ID = 2013)
7:18 PM: Found Spy Cookie: 888 cookie
7:18 PM: owner@888[1].txt (ID = 2019)
7:18 PM: owner@888[2].txt (ID = 2019)
7:18 PM: Found Spy Cookie: websponsors cookie
7:18 PM: owner@a.websponsors[2].txt (ID = 3665)
7:18 PM: Found Spy Cookie: abetterinternet cookie
7:18 PM: owner@abetterinternet[2].txt (ID = 2035)
7:18 PM: owner@abetterinternet[3].txt (ID = 2035)
7:18 PM: Found Spy Cookie: about cookie
7:18 PM: owner@about[2].txt (ID = 2037)
7:18 PM: Found Spy Cookie: yieldmanager cookie
7:18 PM: owner@ad.yieldmanager[2].txt (ID = 3751)
7:18 PM: owner@ad.yieldmanager[3].txt (ID = 3751)
7:18 PM: owner@adam.about[1].txt (ID = 2038)
7:18 PM: Found Spy Cookie: adecn cookie
7:18 PM: owner@adecn[1].txt (ID = 2063)
7:18 PM: Found Spy Cookie: adknowledge cookie
7:18 PM: owner@adknowledge[2].txt (ID = 2072)
7:18 PM: owner@adknowledge[3].txt (ID = 2072)
7:18 PM: Found Spy Cookie: adlegend cookie
7:18 PM: owner@adlegend[1].txt (ID = 2074)
7:18 PM: owner@adlegend[2].txt (ID = 2074)
7:18 PM: Found Spy Cookie: hbmediapro cookie
7:18 PM: owner@adopt.hbmediapro[1].txt (ID = 2768)
7:18 PM: owner@adopt.hbmediapro[3].txt (ID = 2768)
7:18 PM: Found Spy Cookie: hotbar cookie
7:18 PM: owner@adopt.hotbar[2].txt (ID = 4207)
7:18 PM: Found Spy Cookie: precisead cookie
7:18 PM: owner@adopt.precisead[2].txt (ID = 3182)
7:18 PM: Found Spy Cookie: specificclick.com cookie
7:18 PM: owner@adopt.specificclick[1].txt (ID = 3400)
7:18 PM: owner@adopt.specificclick[2].txt (ID = 3400)
7:18 PM: Found Spy Cookie: adprofile cookie
7:18 PM: owner@adprofile[2].txt (ID = 2084)
7:18 PM: Found Spy Cookie: cc214142 cookie
7:18 PM: owner@ads.cc214142[2].txt (ID = 2367)
7:18 PM: Found Spy Cookie: adultfriendfinder cookie
7:18 PM: owner@adultfriendfinder[1].txt (ID = 2165)
7:18 PM: Found Spy Cookie: advertising cookie
7:18 PM: owner@advertising[2].txt (ID = 2175)
7:18 PM: Found Spy Cookie: affiliate cookie
7:18 PM: owner@affiliate[2].txt (ID = 2199)
7:18 PM: Found Spy Cookie: atwola cookie
7:18 PM: owner@ar.atwola[1].txt (ID = 2256)
7:18 PM: Found Spy Cookie: falkag cookie
7:18 PM: owner@as-eu.falkag[1].txt (ID = 2650)
7:18 PM: Found Spy Cookie: ask cookie
7:18 PM: owner@ask[1].txt (ID = 2245)
7:18 PM: owner@ask[2].txt (ID = 2245)
7:18 PM: Found Spy Cookie: atlas dmt cookie
7:18 PM: owner@atdmt[2].txt (ID = 2253)
7:18 PM: Found Spy Cookie: belnk cookie
7:18 PM: owner@ath.belnk[2].txt (ID = 2293)
7:18 PM: owner@atwola[1].txt (ID = 2255)
7:18 PM: owner@atwola[2].txt (ID = 2255)
7:18 PM: owner@atwola[3].txt (ID = 2255)
7:18 PM: owner@atwola[4].txt (ID = 2255)
7:18 PM: Found Spy Cookie: azjmp cookie
7:18 PM: owner@azjmp[1].txt (ID = 2270)
7:18 PM: owner@azjmp[2].txt (ID = 2270)
7:18 PM: Found Spy Cookie: a cookie
7:18 PM: owner@a[1].txt (ID = 2027)
7:18 PM: owner@a[2].txt (ID = 2027)
7:18 PM: Found Spy Cookie: searchingbooth cookie
7:18 PM: owner@banners.searchingbooth[1].txt (ID = 3322)
7:18 PM: Found Spy Cookie: banners cookie
7:18 PM: owner@banners[1].txt (ID = 2282)
7:18 PM: Found Spy Cookie: banner cookie
7:18 PM: owner@banner[1].txt (ID = 2276)
7:18 PM: owner@banner[2].txt (ID = 2276)
7:18 PM: owner@belnk[1].txt (ID = 2292)
7:18 PM: owner@belnk[3].txt (ID = 2292)
7:18 PM: Found Spy Cookie: btgrab cookie
7:18 PM: owner@btg.btgrab[1].txt (ID = 2333)
7:18 PM: Found Spy Cookie: burstnet cookie
7:18 PM: owner@burstnet[2].txt (ID = 2336)
7:18 PM: Found Spy Cookie: top-banners cookie
7:18 PM: owner@campaigns.top-banners[1].txt (ID = 3548)
7:18 PM: Found Spy Cookie: casalemedia cookie
7:18 PM: owner@casalemedia[1].txt (ID = 2354)
7:18 PM: Found Spy Cookie: cassava cookie
7:18 PM: owner@cassava[1].txt (ID = 2362)
7:18 PM: Found Spy Cookie: centrport net cookie
7:18 PM: owner@centrport[2].txt (ID = 2374)
7:18 PM: Found Spy Cookie: cliks cookie
7:18 PM: owner@cliks[2].txt (ID = 2414)
7:18 PM: owner@cliks[3].txt (ID = 2414)
7:18 PM: Found Spy Cookie: columbiahouse cookie
7:18 PM: owner@columbiahouse[2].txt (ID = 2443)
7:18 PM: Found Spy Cookie: controlsearch cookie
7:18 PM: owner@controlsearch[1].txt (ID = 2463)
7:18 PM: Found Spy Cookie: tickle cookie
7:18 PM: owner@cookie.tickle[1].txt (ID = 3530)
7:18 PM: Found Spy Cookie: webtrendslive cookie
7:18 PM: owner@dcskj8813erp17fjun7lek17w_1p6b[1].txt (ID = 3675)
7:18 PM: Found Spy Cookie: dianesdes cookie
7:18 PM: owner@dianesdes[1].txt (ID = 2521)
7:18 PM: Found Spy Cookie: directtrack cookie
7:18 PM: owner@directtrack[1].txt (ID = 2527)
7:18 PM: owner@dist.belnk[1].txt (ID = 2293)
7:18 PM: owner@dist.belnk[2].txt (ID = 2293)
7:18 PM: Found Spy Cookie: dlmax cookie
7:18 PM: owner@dlm.dlmax[2].txt (ID = 2532)
7:18 PM: Found Spy Cookie: dutchmen cookie
7:18 PM: owner@Dutchmen[2].txt (ID = 2545)
7:18 PM: owner@eforcemedia.directtrack[2].txt (ID = 2528)
7:18 PM: Found Spy Cookie: exitexchange cookie
7:18 PM: owner@exitexchange[2].txt (ID = 2633)
7:18 PM: Found Spy Cookie: experclick cookie
7:18 PM: owner@experclick[2].txt (ID = 2639)
7:18 PM: Found Spy Cookie: go.com cookie
7:18 PM: owner@familyfun.go[2].txt (ID = 2729)
7:18 PM: Found Spy Cookie: fastclick cookie
7:18 PM: owner@fastclick[2].txt (ID = 2651)
7:18 PM: owner@go[1].txt (ID = 2728)
7:18 PM: Found Spy Cookie: starware.com cookie
7:18 PM: owner@h.starware[2].txt (ID = 3442)
7:18 PM: Found Spy Cookie: clickandtrack cookie
7:18 PM: owner@hits.clickandtrack[1].txt (ID = 2397)
7:18 PM: owner@hits.clickandtrack[2].txt (ID = 2397)
7:18 PM: Found Spy Cookie: homestore cookie
7:18 PM: owner@homestore[2].txt (ID = 2793)
7:18 PM: Found Spy Cookie: hypertracker.com cookie
7:18 PM: owner@hypertracker[2].txt (ID = 2817)
7:18 PM: Found Spy Cookie: screensavers.com cookie
7:18 PM: owner@i.screensavers[1].txt (ID = 3298)
7:18 PM: owner@i.screensavers[2].txt (ID = 3298)
7:18 PM: Found Spy Cookie: ic-live cookie
7:18 PM: owner@ic-live[1].txt (ID = 2821)
7:18 PM: owner@jas.familyfun.go[1].txt (ID = 2729)
7:18 PM: Found Spy Cookie: sb01 cookie
7:18 PM: owner@jp1.sb01[1].txt (ID = 3288)
7:18 PM: Found Spy Cookie: mcverry cookie
7:18 PM: owner@mcverry[1].txt (ID = 2970)
7:18 PM: owner@media.top-banners[1].txt (ID = 3548)
7:18 PM: Found Spy Cookie: metareward.com cookie
7:18 PM: owner@metareward[1].txt (ID = 2990)
7:18 PM: owner@msnportal.112.2o7[1].txt (ID = 1958)
7:18 PM: Found Spy Cookie: nextag cookie
7:18 PM: owner@nextag[1].txt (ID = 5014)
7:18 PM: Found Spy Cookie: offeroptimizer cookie
7:18 PM: owner@offeroptimizer[1].txt (ID = 3087)
7:18 PM: owner@offeroptimizer[2].txt (ID = 3087)
7:18 PM: owner@offeroptimizer[4].txt (ID = 3087)
7:18 PM: Found Spy Cookie: touchclarity cookie
7:18 PM: owner@partypoker.touchclarity[1].txt (ID = 3567)
7:18 PM: Found Spy Cookie: partypoker cookie
7:18 PM: owner@partypoker[1].txt (ID = 3111)
7:18 PM: Found Spy Cookie: paypopup cookie
7:18 PM: owner@paypopup[1].txt (ID = 3119)
7:18 PM: owner@popunder.paypopup[1].txt (ID = 3120)
7:18 PM: Found Spy Cookie: questionmarket cookie
7:18 PM: owner@questionmarket[1].txt (ID = 3217)
7:18 PM: Found Spy Cookie: realmedia cookie
7:18 PM: owner@realmedia[2].txt (ID = 3235)
7:18 PM: Found Spy Cookie: rednova cookie
7:18 PM: owner@rednova[1].txt (ID = 3245)
7:18 PM: owner@register.go[1].txt (ID = 2729)
7:18 PM: Found Spy Cookie: rightmedia cookie
7:18 PM: owner@rightmedia[2].txt (ID = 3259)
7:18 PM: Found Spy Cookie: rn11 cookie
7:18 PM: owner@rn11[2].txt (ID = 3261)
7:18 PM: owner@rn11[3].txt (ID = 3261)
7:18 PM: Found Spy Cookie: urllogic cookie
7:18 PM: owner@s.urllogic[2].txt (ID = 3617)
7:18 PM: Found Spy Cookie: search123 cookie
7:18 PM: owner@search123[2].txt (ID = 3305)
7:18 PM: Found Spy Cookie: servedby advertising cookie
7:18 PM: owner@servedby.advertising[1].txt (ID = 3335)
7:18 PM: Found Spy Cookie: snakeman cookie
7:18 PM: owner@Snakeman[1].txt (ID = 3391)
7:18 PM: owner@spanish.about[1].txt (ID = 2038)
7:18 PM: Found Spy Cookie: spywarestormer cookie
7:18 PM: owner@spywarestormer[1].txt (ID = 3417)
7:18 PM: owner@starware[2].txt (ID = 3441)
7:18 PM: owner@starware[3].txt (ID = 3441)
7:18 PM: Found Spy Cookie: dealtime cookie
7:18 PM: owner@stat.dealtime[2].txt (ID = 2506)
7:18 PM: Found Spy Cookie: statstracking cookie
7:18 PM: owner@stats-tracking[2].txt (ID = 3453)
7:18 PM: Found Spy Cookie: reliablestats cookie
7:18 PM: owner@stats1.reliablestats[1].txt (ID = 3254)
7:18 PM: owner@stats1.reliablestats[3].txt (ID = 3254)
7:18 PM: Found Spy Cookie: stlyrics cookie
7:18 PM: owner@stlyrics[2].txt (ID = 3461)
7:18 PM: Found Spy Cookie: tradedoubler cookie
7:18 PM: owner@tradedoubler[1].txt (ID = 3575)
7:18 PM: Found Spy Cookie: trafficmp cookie
7:18 PM: owner@trafficmp[2].txt (ID = 3581)
7:18 PM: owner@video.movies.go[1].txt (ID = 2729)
7:18 PM: Found Spy Cookie: videodome cookie
7:18 PM: owner@videodome[1].txt (ID = 3638)
7:18 PM: Found Spy Cookie: wizzle cookie
7:18 PM: owner@wizzle[1].txt (ID = 3695)
7:18 PM: Found Spy Cookie: brazilwelcomesyou cookie
7:18 PM: owner@www.brazilwelcomesyou[1].txt (ID = 2325)
7:18 PM: Found Spy Cookie: burstbeacon cookie
7:18 PM: owner@www.burstbeacon[2].txt (ID = 2335)
7:18 PM: Found Spy Cookie: checknfind cookie
7:18 PM: owner@www.checknfind[2].txt (ID = 2379)
7:18 PM: Found Spy Cookie: eadexchange cookie
7:18 PM: owner@www.eadexchange[2].txt (ID = 2556)
7:18 PM: Found Spy Cookie: find-direct cookie
7:18 PM: owner@www.find-direct[2].txt (ID = 2667)
7:18 PM: Found Spy Cookie: letitfind cookie
7:18 PM: owner@www.letitfind[2].txt (ID = 2919)
7:18 PM: Found Spy Cookie: myaffiliateprogram.com cookie
7:18 PM: owner@www.myaffiliateprogram[2].txt (ID = 3032)
7:18 PM: owner@www.screensavers[1].txt (ID = 3298)
7:18 PM: owner@www.starware[1].txt (ID = 3442)
7:18 PM: Found Spy Cookie: thecoolbar cookie
7:18 PM: owner@www.thecoolbar[2].txt (ID = 3522)
7:18 PM: Found Spy Cookie: toprebates.com cookie
7:18 PM: owner@www.toprebates[2].txt (ID = 3562)
7:18 PM: Found Spy Cookie: topseeker cookie
7:18 PM: owner@www.topseeker[1].txt (ID = 3564)
7:18 PM: Found Spy Cookie: winantiviruspro cookie
7:18 PM: owner@www.winantiviruspro[2].txt (ID = 3690)
7:18 PM: owner@www.winantiviruspro[3].txt (ID = 3690)
7:18 PM: Found Spy Cookie: xzoomy cookie
7:18 PM: owner@www.xzoomy[1].txt (ID = 3742)
7:18 PM: Found Spy Cookie: franklinsurveys cookie
7:18 PM: owner@www2.franklinsurveys[1].txt (ID = 2691)
7:18 PM: owner@yieldmanager[2].txt (ID = 3749)
7:18 PM: Cookie Sweep Complete, Elapsed Time: 00:00:05
7:18 PM: Starting File Sweep
7:18 PM: Found Adware: fizzlebar
7:18 PM: c:\program files\fwbartemp (2 subtraces) (ID = -2147468666)
7:18 PM: c:\windows\bundles (8 subtraces) (ID = -2147481535)
7:18 PM: Found Adware: ietoolbar
7:18 PM: c:\program files\mbkwbar (2 subtraces) (ID = -2147480848)
7:18 PM: Found Adware: search3 toolbar
7:18 PM: c:\program files\search3 toolbar (1 subtraces) (ID = -2147480360)
7:18 PM: Found Adware: abcsearch
7:18 PM: c:\documents and settings\all users\application data\msw (7 subtraces) (ID = -2147481510)
7:18 PM: Found Adware: shopathomeselect
7:18 PM: temp.frc10c (ID = 164522)
7:18 PM: appwrap[1].exe (ID = 65722)
7:18 PM: toc_0032.exe (ID = 48357)
7:18 PM: bw2.com (ID = 65722)
7:18 PM: Found Adware: directrevenue-abetterinternet
7:18 PM: aurareco.exe (ID = 83135)
7:18 PM: toc_0035[1].exe (ID = 48357)
7:18 PM: toc_0035.exe (ID = 48357)
7:18 PM: 8cm6uf0h.dat (ID = 159521)
7:18 PM: Found Trojan Horse: alwaysupdatednews
7:18 PM: aun_0001[1].exe (ID = 49884)
7:19 PM: mbkwnst.cab (ID = 63429)
7:19 PM: ysbactivex.dll (ID = 91027)
7:19 PM: vnpodbc.dll (ID = 154598)
7:19 PM: Found Trojan Horse: trojan-downloader-pacisoft
7:19 PM: pcs_0006[1].exe (ID = 71760)
7:19 PM: aun_0018[1].exe (ID = 49884)
7:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:19 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:19 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:19 PM: Found Adware: ieplugin
7:19 PM: enhupdt.exe (ID = 63349)
7:19 PM: toc_0032.exe (ID = 48357)
7:19 PM: dlmax.cab (ID = 83262)
7:19 PM: toc_0035.exe (ID = 48357)
7:19 PM: dlmax.dll (ID = 83265)
7:19 PM: toc_0035[1].exe (ID = 48357)
7:19 PM: toc_0032.exe (ID = 48357)
7:19 PM: aun_0001[1].exe (ID = 49884)
7:19 PM: aurareco.exe (ID = 83135)
7:19 PM: tlext.dll (ID = 93700)
7:19 PM: ugat.dll (ID = 93700)
7:19 PM: upgrade.exe (ID = 75963)
7:19 PM: enhupdt.exe (ID = 63349)
7:19 PM: aurareco.exe (ID = 83135)
7:19 PM: aurareco.exe (ID = 83135)
7:19 PM: aurareco.exe (ID = 83135)
7:19 PM: ysbactivex.dll (ID = 91017)
7:19 PM: Found Adware: dealhelper
7:19 PM: zibjtpu2.xml (ID = 57651)
7:19 PM: aun_0001[1].exe (ID = 49884)
7:20 PM: enhtb.exe (ID = 63347)
7:20 PM: aurareco.exe (ID = 83135)
7:20 PM: aun_0029[1].exe (ID = 49884)
7:20 PM: searchbar.exe (ID = 61060)
7:20 PM: mbkwnst.cab (ID = 63429)
7:20 PM: aurareco.exe (ID = 83135)
7:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:20 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:20 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:20 PM: Found Adware: apropos
7:20 PM: aproposclientinstaller[1].exe (ID = 50020)
7:20 PM: aurareco.exe (ID = 83135)
7:20 PM: aurareco.exe (ID = 83135)
7:20 PM: Found Adware: my daily horoscope
7:20 PM: setup_silent_26221.exe (ID = 70252)
7:20 PM: aurareco.exe (ID = 83135)
7:20 PM: aurareco.exe (ID = 83135)
7:20 PM: inst28[1].exe (ID = 49893)
7:20 PM: Found Adware: searchforit
7:20 PM: ven_d1.exe (ID = 75081)
7:21 PM: bsfi1001.exe (ID = 164522)
7:21 PM: wmplayer.exe.tmp (ID = 49893)
7:21 PM: msw.exe (ID = 48566)
7:21 PM: msw_uninstall.exe (ID = 48573)
7:21 PM: aun_0029[1].exe (ID = 49884)
7:21 PM: aproposclientinstaller[1].exe (ID = 50020)
7:21 PM: aurareco.exe (ID = 83135)
7:21 PM: enhupdt.exe (ID = 63349)
7:21 PM: pcs_0006[1].exe (ID = 71760)
7:21 PM: track6[1].chm (ID = 71766)
7:21 PM: aun_0018[1].exe (ID = 49884)
7:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:22 PM: zibjtpk2.xml (ID = 57648)
7:22 PM: appwrap[1].exe (ID = 65739)
7:22 PM: uqandlg.dll (ID = 154598)
7:22 PM: icont.exe (ID = 65739)
7:22 PM: kl68g2p1.dat (ID = 159521)
7:22 PM: Found Adware: bookedspace
7:22 PM: eijbhnzc.exe (ID = 51662)
7:22 PM: aun_0001.exe (ID = 49884)
7:22 PM: enhupdt.exe (ID = 63349)
7:22 PM: inst12[1].exe (ID = 49891)
7:22 PM: zibjtpk.xml (ID = 57646)
7:22 PM: zibjtpk1.xml (ID = 57647)
7:22 PM: i7c228of.dat (ID = 75949)
7:22 PM: ca2.dll (ID = 94667)
7:22 PM: sfi2.dll (ID = 112321)
7:22 PM: mbkwnst.cab (ID = 63429)
7:22 PM: Found Adware: isearch toolbar
7:22 PM: cmdinst.exe (ID = 154747)
7:22 PM: jt2m07f1e.dll (ID = 154598)
7:22 PM: installer.exe (ID = 93698)
7:22 PM: Found Adware: 180search assistant/zango
7:22 PM: res422.tmp (ID = 107353)
7:22 PM: upd209.exe (ID = 153729)
7:22 PM: zibjtpu1.xml (ID = 57650)
7:22 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:23 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:23 PM: t8uafh8t.dat (ID = 75949)
7:23 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:23 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:23 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:23 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:23 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:23 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:23 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:23 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:23 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:23 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:23 PM: inst28[1].exe (ID = 49893)
7:23 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:23 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:23 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:23 PM: enhtb.dll (ID = 63346)
7:23 PM: ietoolbar.dll (ID = 63423)
7:23 PM: search3.dll (ID = 74840)
7:23 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:23 PM: mbkwbar.exe (ID = 63427)
7:23 PM: bman.exe (ID = 48559)
7:23 PM: toc_0035.exe (ID = 48357)
7:23 PM: enhuninstall.exe (ID = 63348)
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: cohelper.exe (ID = 61054)
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: doprpres.dll (ID = 154598)
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: track6[1].chm (ID = 71766)
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation denied at user request
7:24 PM: BHO Shield: found: ddccy.dll-- BHO installation allowed at user request
7:24 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:24 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:24 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:24 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:24 PM: zibjtpu.xml (ID = 57649)
7:24 PM: sjlsrv32.dll (ID = 154598)
7:25 PM: Found Adware: internetoptimizer
7:25 PM: cfin (ID = 64026)
7:25 PM: Found Adware: powerscan
7:25 PM: power scan.lnk (ID = 72676)
7:25 PM: inst12[1].exe (ID = 49891)
7:25 PM: cfout.txt (ID = 64027)
7:25 PM: track6[1].chm (ID = 71766)
7:25 PM: runsearch.exe (ID = 74842)
7:25 PM: aproposclientinstaller[1].exe (ID = 50020)
7:25 PM: Found Adware: ezula ilookup
7:25 PM: vl_ezstub.exe (ID = 60659)
7:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:26 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:26 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:26 PM: Found Adware: websearch toolbar
7:26 PM: tbuninst.exe (ID = 85854)
7:26 PM: lsp_setup.exe (ID = 75818)
7:26 PM: inst28[1].exe (ID = 49893)
7:26 PM: Found Adware: ipinsight
7:26 PM: conscorr.ini (ID = 64264)
7:26 PM: dlmax.inf (ID = 83267)
7:26 PM: fellymedia1002.sah (ID = 75733)
7:26 PM: conscorr.inf (ID = 64277)
7:26 PM: wininit.ini (ID = 63389)
7:26 PM: conscorr.inf (ID = 64277)
7:26 PM: zibjtpdk.xml (ID = 57645)
7:26 PM: conscorr.ini (ID = 64264)
7:26 PM: conscorr.ini (ID = 64264)
7:26 PM: h63v2629j_.ini (ID = 75785)
7:26 PM: conscorr.inf (ID = 64277)
7:26 PM: dlmax.inf (ID = 83267)
7:26 PM: uu1en13ec_.ini (ID = 75964)
7:26 PM: setup4003.ini (ID = 75708)
7:26 PM: fellymedia1002.sah (ID = 75733)
7:26 PM: dlmax.inf (ID = 83267)
7:26 PM: fellymedia1002.sah (ID = 75733)
7:26 PM: dlmax.inf (ID = 83267)
7:26 PM: conscorr.inf (ID = 64277)
7:27 PM: File Sweep Complete, Elapsed Time: 00:08:52
7:27 PM: Full Sweep has completed. Elapsed time 00:13:20
7:27 PM: Traces Found: 361
7:27 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:27 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:27 PM: Removal process initiated
7:27 PM: Quarantining All Traces: 180search assistant/zango
7:27 PM: Quarantining All Traces: 2nd-thought
7:27 PM: Quarantining All Traces: directrevenue-abetterinternet
7:28 PM: Quarantining All Traces: icannnews
7:28 PM: icannnews is in use. It will be removed on reboot.
7:28 PM: C:\WINDOWS\system32\guard.tmp is in use. It will be removed on reboot.
7:28 PM: C:\WINDOWS\system32\kt48l7hu1.dll is in use. It will be removed on reboot.
7:28 PM: C:\WINDOWS\system32\cxyptui.dll is in use. It will be removed on reboot.
7:28 PM: Quarantining All Traces: look2me
7:28 PM: Quarantining All Traces: virtumonde
7:28 PM: virtumonde is in use. It will be removed on reboot.
7:28 PM: C:\WINDOWS\system32\ddccy.dll is in use. It will be removed on reboot.
7:28 PM: Quarantining All Traces: websearch toolbar
7:28 PM: Quarantining All Traces: alwaysupdatednews
7:28 PM: Quarantining All Traces: apropos
7:28 PM: Quarantining All Traces: internetoptimizer
7:28 PM: Quarantining All Traces: searchforit
7:28 PM: Quarantining All Traces: trojan-downloader-pacisoft
7:28 PM: Quarantining All Traces: abcsearch
7:28 PM: Quarantining All Traces: bookedspace
7:28 PM: Quarantining All Traces: dealhelper
7:28 PM: Quarantining All Traces: ezula ilookup
7:28 PM: ezula ilookup is in use. It will be removed on reboot.
7:28 PM: vl_ezstub.exe is in use. It will be removed on reboot.
7:28 PM: Quarantining All Traces: fizzlebar
7:28 PM: Quarantining All Traces: ieplugin
7:28 PM: Quarantining All Traces: ietoolbar
7:28 PM: Quarantining All Traces: ipinsight
7:28 PM: Quarantining All Traces: isearch toolbar
7:28 PM: Quarantining All Traces: ist yoursitebar
7:28 PM: Quarantining All Traces: my daily horoscope
7:28 PM: my daily horoscope is in use. It will be removed on reboot.
7:28 PM: setup_silent_26221.exe is in use. It will be removed on reboot.
7:28 PM: Quarantining All Traces: powerscan
7:28 PM: Quarantining All Traces: search3 toolbar
7:28 PM: search3 toolbar is in use. It will be removed on reboot.
7:28 PM: runsearch.exe is in use. It will be removed on reboot.
7:28 PM: Quarantining All Traces: shopathomeselect
7:28 PM: Quarantining All Traces: 10101 cookie
7:28 PM: Quarantining All Traces: 10102 cookie
7:28 PM: Quarantining All Traces: 10105 cookie
7:28 PM: Quarantining All Traces: 2o7.net cookie
7:28 PM: Quarantining All Traces: 3 cookie
7:28 PM: Quarantining All Traces: 365 cookie
7:28 PM: Quarantining All Traces: 382 cookie
7:28 PM: Quarantining All Traces: 412 cookie
7:28 PM: Quarantining All Traces: 5 cookie
7:28 PM: Quarantining All Traces: 64.62.232 cookie
7:28 PM: Quarantining All Traces: 69.28.210 cookie
7:28 PM: Quarantining All Traces: 735 cookie
7:28 PM: Quarantining All Traces: 80503492 cookie
7:28 PM: Quarantining All Traces: 888 cookie
7:28 PM: Quarantining All Traces: a cookie
7:28 PM: Quarantining All Traces: abetterinternet cookie
7:28 PM: Quarantining All Traces: about cookie
7:28 PM: Quarantining All Traces: adecn cookie
7:28 PM: Quarantining All Traces: adknowledge cookie
7:28 PM: Quarantining All Traces: adlegend cookie
7:28 PM: Quarantining All Traces: adprofile cookie
7:28 PM: Quarantining All Traces: adultfriendfinder cookie
7:28 PM: Quarantining All Traces: advertising cookie
7:28 PM: Quarantining All Traces: affiliate cookie
7:28 PM: Quarantining All Traces: ask cookie
7:28 PM: Quarantining All Traces: atlas dmt cookie
7:28 PM: Quarantining All Traces: atwola cookie
7:28 PM: Quarantining All Traces: azjmp cookie
7:28 PM: Quarantining All Traces: banner cookie
7:28 PM: Quarantining All Traces: banners cookie
7:28 PM: Quarantining All Traces: belnk cookie
7:28 PM: Quarantining All Traces: brazilwelcomesyou cookie
7:28 PM: Quarantining All Traces: btgrab cookie
7:28 PM: Quarantining All Traces: burstbeacon cookie
7:28 PM: Quarantining All Traces: burstnet cookie
7:28 PM: Quarantining All Traces: casalemedia cookie
7:28 PM: Quarantining All Traces: cassava cookie
7:28 PM: Quarantining All Traces: cc214142 cookie
7:28 PM: Quarantining All Traces: centrport net cookie
7:28 PM: Quarantining All Traces: checknfind cookie
7:28 PM: Quarantining All Traces: clickandtrack cookie
7:28 PM: Quarantining All Traces: cliks cookie
7:28 PM: Quarantining All Traces: columbiahouse cookie
7:28 PM: Quarantining All Traces: controlsearch cookie
7:28 PM: Quarantining All Traces: dealtime cookie
7:28 PM: Quarantining All Traces: dianesdes cookie
7:28 PM: Quarantining All Traces: directtrack cookie
7:28 PM: Quarantining All Traces: dlmax cookie
7:28 PM: Quarantining All Traces: dutchmen cookie
7:28 PM: Quarantining All Traces: eadexchange cookie
7:28 PM: Quarantining All Traces: exitexchange cookie
7:28 PM: Quarantining All Traces: experclick cookie
7:28 PM: Quarantining All Traces: falkag cookie
7:28 PM: Quarantining All Traces: fastclick cookie
7:28 PM: Quarantining All Traces: find-direct cookie
7:28 PM: Quarantining All Traces: franklinsurveys cookie
7:28 PM: Quarantining All Traces: go.com cookie
7:28 PM: Quarantining All Traces: hbmediapro cookie
7:28 PM: Quarantining All Traces: homestore cookie
7:28 PM: Quarantining All Traces: hotbar cookie
7:28 PM: Quarantining All Traces: hypertracker.com cookie
7:28 PM: Quarantining All Traces: ic-live cookie
7:28 PM: Quarantining All Traces: letitfind cookie
7:28 PM: Quarantining All Traces: mcverry cookie
7:28 PM: Quarantining All Traces: metareward.com cookie
7:28 PM: Quarantining All Traces: myaffiliateprogram.com cookie
7:28 PM: Quarantining All Traces: nextag cookie
7:28 PM: Quarantining All Traces: offeroptimizer cookie
7:28 PM: Quarantining All Traces: partypoker cookie
7:28 PM: Quarantining All Traces: paypopup cookie
7:28 PM: Quarantining All Traces: precisead cookie
7:28 PM: Quarantining All Traces: primaryads cookie
7:28 PM: Quarantining All Traces: questionmarket cookie
7:28 PM: Quarantining All Traces: realmedia cookie
7:28 PM: Quarantining All Traces: rednova cookie
7:28 PM: Quarantining All Traces: reliablestats cookie
7:28 PM: Quarantining All Traces: rightmedia cookie
7:28 PM: Quarantining All Traces: rn11 cookie
7:28 PM: Quarantining All Traces: sb01 cookie
7:28 PM: Quarantining All Traces: screensavers.com cookie
7:28 PM: Quarantining All Traces: search123 cookie
7:28 PM: Quarantining All Traces: searchingbooth cookie
7:28 PM: Quarantining All Traces: servedby advertising cookie
7:28 PM: Quarantining All Traces: snakeman cookie
7:28 PM: Quarantining All Traces: specificclick.com cookie
7:28 PM: Quarantining All Traces: spywarestormer cookie
7:28 PM: Quarantining All Traces: starware.com cookie
7:28 PM: Quarantining All Traces: statstracking cookie
7:28 PM: Quarantining All Traces: stlyrics cookie
7:28 PM: Quarantining All Traces: thecoolbar cookie
7:28 PM: Quarantining All Traces: tickle cookie
7:28 PM: Quarantining All Traces: top-banners cookie
7:28 PM: Quarantining All Traces: toprebates.com cookie
7:28 PM: Quarantining All Traces: topseeker cookie
7:28 PM: Quarantining All Traces: touchclarity cookie
7:28 PM: Quarantining All Traces: tradedoubler cookie
7:28 PM: Quarantining All Traces: trafficmp cookie
7:28 PM: Quarantining All Traces: urllogic cookie
7:28 PM: Quarantining All Traces: videodome cookie
7:28 PM: Quarantining All Traces: websponsors cookie
7:28 PM: Quarantining All Traces: webtrendslive cookie
7:28 PM: Quarantining All Traces: winantiviruspro cookie
7:28 PM: Quarantining All Traces: wizzle cookie
7:28 PM: Quarantining All Traces: xzoomy cookie
7:28 PM: Quarantining All Traces: yieldmanager cookie
7:29 PM: Removal process completed. Elapsed time 00:01:42
********
7:13 PM: | Start of Session, Thursday, November 10, 2005 |
7:13 PM: Spy Sweeper started
7:13 PM: Your spyware definitions have been updated.
7:13 PM: | End of Session, Thursday, November 10, 2005 |
Logfile of HijackThis v1.99.1
Scan saved at 7:34:07 PM, on 11/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\LTMSG.exe
C:\progra~1\scansoft\paperp~1\pptd40nt.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\AOL\1131425274\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1131425274\ee\AOLServiceHost.exe
c:\program files\common files\aol\1131425274\ee\services\antiSpywareApp\ver2_0_7\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1131425274\ee\AOLServiceHost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Common Files\Aol\aoltpspd.exe
C:\Documents and Settings\Owner\Desktop\Fixs\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://broadband.zoo...n.com/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://qus10.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PaperPort PTD] c:\progra~1\scansoft\paperp~1\pptd40nt.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1131425274\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) -
http://esupport.aol....oach_core_1.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) -
http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} -
http://hoylegames.si...cherControl.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) -
http://www.disney.go...GameManager.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) -
http://ax.phobos.app.../ITDetector.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: BrSplService (Brother XP spl Service) - Unknown owner - C:\WINDOWS\system32\brsvc01a.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe