Hi,
Looks like those entries are back. Below is the log. This time when I deleted them in safe mode and reran HJT right then in safe mode, the entries were not there. Last time when I deleted them they reappeared immediately in safe mode. My internet explorer, was according to spysweeper, hijacked when I first started trying to clean up the mess that was this computer. Could this be related? I have included below (after the HJT log) the spysweeper logs for when I first ran it when the computer was really messed up.
Those two programs, Panda and Housecall still did not run. I let the computer sit for about an hour this time.
I did finish up the ccleaner stuff and it appeared to take care of all those issues.
Thanks
Jenny
Logfile of HijackThis v1.99.1
Scan saved at 2:21:34 PM, on 11/28/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\HPBPRO.EXE
C:\WINDOWS\SYSTEM\HPBOID.EXE
C:\PROGRAM FILES\WEBSVR\SYSTEM\INETSW95.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCTSKSHD.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
C:\PROGRAM FILES\SONY\SONICSTAGE\SSAAD.EXE
C:\WINDOWS\STARTUPMONITOR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFAGENT.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\WRSSSDK.EXE
C:\PROGRAM FILES\CCLEANER\CCLEANER.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCSHLD9X.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\OASCLNT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/home.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
N3 - Netscape 7: user_pref("browser.startup.homepage", "
http://www.comcast.net/home.html"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\brkvft1w.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRAM%20FILES%5CNETSCAPE%5CNETSCAPE%206%5Csearchplugins%5CSBWeb_01.src"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\brkvft1w.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
O4 - HKLM\..\Run: [Microsoft WebServer] C:\Program Files\WebSvr\System\svctrl /init
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [MCTskShd] C:\PROGRA~1\MCAFEE.COM\AGENT\mctskshd.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [OmgStartup] C:\Program Files\Common Files\Sony Shared\OpenMG\OmgStartup.exe
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\SONY\SONICS~1\SSAAD.EXE
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
O4 - HKLM\..\RunServices: [RNBOStart] C:\WINDOWS\SYSTEM\RNBOSENT\SENTSTRT.EXE
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [HP Port Resolver] C:\WINDOWS\SYSTEM\hpbpro.exe
O4 - HKLM\..\RunServices: [HP Status Server] C:\WINDOWS\SYSTEM\hpboid.exe
O4 - HKLM\..\RunServices: [Microsoft WebServer] C:\Program Files\WebSvr\System\inetsw95 -w3svc
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [McShld9x] C:\Program Files\McAfee.com\VSO\mcshld9x.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\COMMON\YHEXBMESUS.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\COMMON\YHEXBMESUS.DLL
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL
O9 - Extra button: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://download.mcaf...,26/mcgdmgr.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcaf...99/mcinsctl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
Session Log of Spysweeper when I first used it when computer was really really messed up.
********
2:22 AM: | Start of Session, Wednesday, November 23, 2005 |
2:22 AM: Spy Sweeper started
2:22 AM: Sweep initiated using definitions version 575
2:22 AM: Starting Memory Sweep
2:28 AM: Memory Sweep Complete, Elapsed Time: 00:06:32
2:28 AM: Starting Registry Sweep
2:28 AM: Found Trojan Horse: alwaysupdatednews
2:28 AM: HKU\.default\software\aun\ (4 subtraces) (ID = 103537)
2:28 AM: Found Adware: apropos
2:28 AM: HKCR\clsid\{b5ab638f-d76c-415b-a8f2-f3ceac502212}\ (7 subtraces) (ID = 103726)
2:28 AM: HKLM\software\classes\clsid\{b5ab638f-d76c-415b-a8f2-f3ceac502212}\ (7 subtraces) (ID = 103764)
2:28 AM: HKLM\software\classes\interface\{bc333116-6ea1-40a1-9d07-ecb192db8cea}\ (5 subtraces) (ID = 103774)
2:29 AM: Found Adware: cws-aboutblank
2:29 AM: HKCR\protocols\filter\text/html\ (2 subtraces) (ID = 114343)
2:29 AM: HKLM\software\classes\protocols\filter\text/html\ (2 subtraces) (ID = 115907)
2:29 AM: Found Adware: dealhelper
2:29 AM: HKLM\software\microsoft\windows\currentversion\uninstall\windh\ (3 subtraces) (ID = 124816)
2:29 AM: Found Adware: delfin
2:29 AM: HKLM\software\dvx\ (ID = 124854)
2:29 AM: HKLM\software\skin\ (1 subtraces) (ID = 124892)
2:29 AM: Found Adware: searchpounders hijacker
2:29 AM: HKLM\software\microsoft\windows\currentversion\uninstall\system monitor for windows 98/nt/xp/2000/2003_is1\ (14 subtraces) (ID = 141288)
2:29 AM: Found Adware: searchtoolbar
2:29 AM: HKU\.default\software\{12ee7a5e-0674-42f9-a76b-000000004d00}\ (3 subtraces) (ID = 141323)
2:30 AM: Found Trojan Horse: trojan-downloader-spywarewall
2:30 AM: HKLM\software\spywarewall\ (2 subtraces) (ID = 144793)
2:30 AM: HKLM\software\microsoft\windows\currentversion\uninstall\spywarewall\ (1 subtraces) (ID = 359536)
2:30 AM: Found Adware: visfx
2:30 AM: HKLM\software\microsoft\windows\currentversion\uninstall\ovmon\ (2 subtraces) (ID = 712951)
2:30 AM: Found Adware: safesurf
2:30 AM: HKCR\funtools.picshow\ (5 subtraces) (ID = 730902)
2:30 AM: HKCR\funtools.picshow.1\ (3 subtraces) (ID = 730908)
2:30 AM: HKCR\clsid\{4487598c-2ec7-43a2-870e-6d8d720fdd9f}\ (11 subtraces) (ID = 730912)
2:30 AM: HKCR\typelib\{7638761f-0ce1-4e68-9692-d623527a6b7b}\ (9 subtraces) (ID = 730924)
2:30 AM: HKLM\software\classes\funtools.picshow\ (5 subtraces) (ID = 730957)
2:30 AM: HKLM\software\classes\funtools.picshow.1\ (3 subtraces) (ID = 730963)
2:30 AM: HKLM\software\classes\clsid\{4487598c-2ec7-43a2-870e-6d8d720fdd9f}\ (11 subtraces) (ID = 730967)
2:30 AM: HKLM\software\classes\typelib\{7638761f-0ce1-4e68-9692-d623527a6b7b}\ (9 subtraces) (ID = 730979)
2:30 AM: HKLM\software\picshow\ (42 subtraces) (ID = 730989)
2:30 AM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{4487598c-2ec7-43a2-870e-6d8d720fdd9f}\ (ID = 730994)
2:30 AM: Found Adware: cas
2:30 AM: HKCR\typelib\{1b8b502e-465b-4022-be4f-fb6d9f808a18}\ (9 subtraces) (ID = 820387)
2:30 AM: HKLM\software\classes\typelib\{1b8b502e-465b-4022-be4f-fb6d9f808a18}\ (9 subtraces) (ID = 820540)
2:30 AM: HKLM\ovmon\ (ID = 826847)
2:30 AM: Found Adware: ezula ilookup
2:30 AM: HKLM\software\microsoft\webext\ (1 subtraces) (ID = 828947)
2:30 AM: Found Trojan Horse: 2nd-thought
2:30 AM: HKU\.DEFAULT\software\bundles\ (87 subtraces) (ID = 101988)
2:30 AM: HKU\.DEFAULT\software\aun\ (4 subtraces) (ID = 103544)
2:30 AM: Found Adware: browseraid
2:30 AM: HKU\.DEFAULT\software\a70f6a1d-0195-42a2-934c-d8ac0f7c08eb\ (1 subtraces) (ID = 105078)
2:30 AM: HKU\.DEFAULT\software\{12ee7a5e-0674-42f9-a76b-000000004d00}\ (3 subtraces) (ID = 141347)
2:30 AM: HKU\.DEFAULT\software\vb and vba program settings\spywarewall\ (3 subtraces) (ID = 144795)
2:30 AM: HKU\.DEFAULT\software\cmapp\ (ID = 381792)
2:30 AM: Registry Sweep Complete, Elapsed Time:00:01:32
2:30 AM: Starting Cookie Sweep
2:30 AM: Found Spy Cookie: atwola cookie
2:30 AM: allen design@atwola[2].txt (ID = 2255)
2:30 AM: Found Spy Cookie: cc214142 cookie
2:30 AM: allen design@ads.cc214142[2].txt (ID = 2367)
2:30 AM: Found Spy Cookie: belnk cookie
2:30 AM: anyuser@ath.belnk[1].txt (ID = 2293)
2:30 AM: Found Spy Cookie: ask cookie
2:30 AM: allen design@ask[2].txt (ID = 2245)
2:30 AM: Found Spy Cookie: go.com cookie
2:30 AM: allen design@go[2].txt (ID = 2728)
2:30 AM: Found Spy Cookie: partypoker cookie
2:30 AM: allen design@partypoker[2].txt (ID = 3111)
2:30 AM: Found Spy Cookie: ru4 cookie
2:30 AM: anyuser@edge.ru4[1].txt (ID = 3269)
2:30 AM: allen design@belnk[1].txt (ID = 2292)
2:30 AM: allen design@dist.belnk[2].txt (ID = 2293)
2:30 AM: Found Spy Cookie: banner cookie
2:30 AM: allen design@banner[2].txt (ID = 2276)
2:30 AM: Found Spy Cookie: questionmarket cookie
2:30 AM: anyuser@questionmarket[1].txt (ID = 3217)
2:30 AM: Found Spy Cookie: directtrack cookie
2:30 AM: allen design@directtrack[1].txt (ID = 2527)
2:30 AM: allen design@rapidresponse.directtrack[2].txt (ID = 2528)
2:30 AM: Found Spy Cookie: gamespy cookie
2:30 AM: allen design@gamespy[1].txt (ID = 2719)
2:30 AM: Found Spy Cookie: burstnet cookie
2:30 AM: anyuser@burstnet[2].txt (ID = 2336)
2:30 AM: Found Spy Cookie: servlet cookie
2:30 AM: anyuser@servlet[2].txt (ID = 3345)
2:30 AM: Found Spy Cookie: adknowledge cookie
2:30 AM: anyuser@adknowledge[1].txt (ID = 2072)
2:30 AM: Found Spy Cookie: nextag cookie
2:30 AM: allen design@nextag[1].txt (ID = 5014)
2:30 AM: anyuser@go[2].txt (ID = 2728)
2:30 AM: Found Spy Cookie: pointroll cookie
2:30 AM: anyuser@ads.pointroll[2].txt (ID = 3148)
2:30 AM: anyuser@nextag[3].txt (ID = 5014)
2:30 AM: anyuser@servlet[3].txt (ID = 3345)
2:30 AM: Found Spy Cookie: 2o7.net cookie
2:30 AM: anyuser@2o7[2].txt (ID = 1957)
2:30 AM: anyuser@ask[1].txt (ID = 2245)
2:30 AM: allen design@servlet[2].txt (ID = 3345)
2:30 AM: anyuser@dist.belnk[1].txt (ID = 2293)
2:30 AM: anyuser@belnk[2].txt (ID = 2292)
2:30 AM: Found Spy Cookie: reunion cookie
2:30 AM: anyuser@reunion[2].txt (ID = 3255)
2:30 AM: allen design@adknowledge[2].txt (ID = 2072)
2:30 AM: Found Spy Cookie: webtrendslive cookie
2:30 AM: allen design@dcs8ir0f010000oyioyaka1kl_8j7n[1].txt (ID = 3673)
2:30 AM: Found Spy Cookie: yieldmanager cookie
2:30 AM: allen design@ad.yieldmanager[1].txt (ID = 3751)
2:30 AM: anyuser@nextag[2].txt (ID = 5014)
2:30 AM: anyuser@ad.yieldmanager[2].txt (ID = 3751)
2:30 AM: Found Spy Cookie: specificclick.com cookie
2:30 AM: anyuser@adopt.specificclick[1].txt (ID = 3400)
2:30 AM: anyuser@dcs8ir0f010000oyioyaka1kl_8j7n[2].txt (ID = 3673)
2:30 AM: Cookie Sweep Complete, Elapsed Time: 00:00:05
2:30 AM: Starting File Sweep
2:30 AM: Warning: Failed to open file "c:\windows\win386.swp". The process cannot access the file because
it is being used by another process
2:36 AM: Found Adware: 180search assistant/zango
2:36 AM: c:\windows\system\fleok (ID = -2147480556)
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfe1-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfe2-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfe3-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfe4-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfe5-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfe6-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfe7-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfe8-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfe9-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfea-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfeb-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfec-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfed-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfee-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfef-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bff0-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bff1-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bff2-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bff3-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bff4-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bff5-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bff6-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bff7-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bff8-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bff9-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bffa-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bffb-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bffc-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bffd-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bffe-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9bfff-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c000-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c001-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c002-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c003-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c004-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c005-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c006-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c007-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c008-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c009-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c00a-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c00b-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c00c-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c00d-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c00e-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c00f-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c010-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c011-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c012-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c013-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c014-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c015-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c016-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c017-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c018-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c019-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c01a-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c01b-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c01c-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c01d-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c01e-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c01f-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c020-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c021-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c022-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c023-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c024-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c025-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c026-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c027-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c028-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c029-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c02a-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c02b-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c02c-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c02d-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c02e-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c02f-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c030-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c031-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c032-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c033-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c034-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c035-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c036-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c037-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c038-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c039-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c03a-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c03b-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c03c-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c03d-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c03e-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c03f-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c040-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c041-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c042-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c043-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c044-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c045-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c046-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c047-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
2:41 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs69c9c048-5bc7-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
3:06 AM: c:\windows\bundles (64 subtraces) (ID = -2147481535)
3:20 AM: c:\program files\spywarewall (ID = -2147475376)
3:29 AM: c:\program files\popupwall (ID = -2147479837)
3:29 AM: c:\program files\fcengine (1 subtraces) (ID = -2147471607)
3:29 AM: c:\program files\cmsystem (1 subtraces) (ID = -2147471610)
3:32 AM: File Sweep Complete, Elapsed Time: 01:02:20
3:32 AM: Full Sweep has completed. Elapsed time 01:10:30
3:32 AM: Traces Found: 409
3:33 AM: Removal process initiated
3:33 AM: Quarantining All Traces: 180search assistant/zango
3:33 AM: Quarantining All Traces: 2nd-thought
3:33 AM: Quarantining All Traces: cws-aboutblank
3:33 AM: Quarantining All Traces: visfx
3:33 AM: Quarantining All Traces: alwaysupdatednews
3:33 AM: Quarantining All Traces: apropos
3:33 AM: Quarantining All Traces: cas
3:33 AM: Quarantining All Traces: trojan-downloader-spywarewall
3:33 AM: Quarantining All Traces: browseraid
3:33 AM: Quarantining All Traces: dealhelper
3:33 AM: Quarantining All Traces: delfin
3:33 AM: Warning: Failed to export "HKEY_LOCAL_MACHINE\software\dvx\": An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
3:33 AM: Failed to quarantine delfin
3:33 AM: Failed to quarantine HKLM: software\dvx\
3:33 AM: Quarantining All Traces: ezula ilookup
3:33 AM: Warning: Failed to export "HKEY_LOCAL_MACHINE\software\microsoft\webext\": An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
3:33 AM: Failed to quarantine ezula ilookup
3:33 AM: Failed to quarantine HKLM: software\microsoft\webext\
3:33 AM: Quarantining All Traces: safesurf
3:33 AM: Quarantining All Traces: searchpounders hijacker
3:33 AM: Quarantining All Traces: searchtoolbar
3:33 AM: Quarantining All Traces: 2o7.net cookie
3:33 AM: Quarantining All Traces: adknowledge cookie
3:33 AM: Quarantining All Traces: ask cookie
3:33 AM: Quarantining All Traces: atwola cookie
3:33 AM: Quarantining All Traces: banner cookie
3:33 AM: Quarantining All Traces: belnk cookie
3:33 AM: Quarantining All Traces: burstnet cookie
3:33 AM: Quarantining All Traces: cc214142 cookie
3:33 AM: Quarantining All Traces: directtrack cookie
3:33 AM: Quarantining All Traces: gamespy cookie
3:33 AM: Quarantining All Traces: go.com cookie
3:33 AM: Quarantining All Traces: nextag cookie
3:33 AM: Quarantining All Traces: partypoker cookie
3:33 AM: Quarantining All Traces: pointroll cookie
3:33 AM: Quarantining All Traces: questionmarket cookie
3:33 AM: Quarantining All Traces: reunion cookie
3:33 AM: Quarantining All Traces: ru4 cookie
3:33 AM: Quarantining All Traces: servlet cookie
3:33 AM: Quarantining All Traces: specificclick.com cookie
3:33 AM: Quarantining All Traces: webtrendslive cookie
3:33 AM: Quarantining All Traces: yieldmanager cookie
3:34 AM: Removal process completed. Elapsed time 00:00:28
8:00 PM: Processing Startup Alerts
8:00 PM: Allowed Startup entry: Run StartupMonitor
9:13 AM: IE Tracking Cookies Shield: Removed atwola cookie
9:13 AM: IE Tracking Cookies Shield: Removed apmebf cookie
********
7:35 AM: | Start of Session, Tuesday, November 22, 2005 |
7:35 AM: Spy Sweeper started
7:35 AM: Sweep initiated using definitions version 575
7:35 AM: Starting Memory Sweep
7:42 AM: Memory Sweep Complete, Elapsed Time: 00:06:56
7:42 AM: Starting Registry Sweep
7:42 AM: Found Trojan Horse: alwaysupdatednews
7:42 AM: HKU\.default\software\aun\ (4 subtraces) (ID = 103537)
7:42 AM: Found Adware: apropos
7:42 AM: HKCR\clsid\{b5ab638f-d76c-415b-a8f2-f3ceac502212}\ (7 subtraces) (ID = 103726)
7:42 AM: HKLM\software\classes\clsid\{b5ab638f-d76c-415b-a8f2-f3ceac502212}\ (7 subtraces) (ID = 103764)
7:42 AM: HKLM\software\classes\interface\{bc333116-6ea1-40a1-9d07-ecb192db8cea}\ (5 subtraces) (ID = 103774)
7:43 AM: Found Adware: cws-aboutblank
7:43 AM: HKCR\protocols\filter\text/html\ (2 subtraces) (ID = 114343)
7:43 AM: HKLM\software\classes\protocols\filter\text/html\ (2 subtraces) (ID = 115907)
7:43 AM: Found Adware: dealhelper
7:43 AM: HKLM\software\microsoft\windows\currentversion\uninstall\windh\ (3 subtraces) (ID = 124816)
7:43 AM: Found Adware: delfin
7:43 AM: HKLM\software\dvx\ (ID = 124854)
7:43 AM: HKLM\software\skin\ (1 subtraces) (ID = 124892)
7:43 AM: Found Adware: searchpounders hijacker
7:43 AM: HKLM\software\microsoft\windows\currentversion\uninstall\system monitor for windows 98/nt/xp/2000/2003_is1\ (14 subtraces) (ID = 141288)
7:43 AM: Found Adware: searchtoolbar
7:43 AM: HKU\.default\software\{12ee7a5e-0674-42f9-a76b-000000004d00}\ (3 subtraces) (ID = 141323)
7:43 AM: Found Trojan Horse: trojan-downloader-spywarewall
7:43 AM: HKLM\software\spywarewall\ (2 subtraces) (ID = 144793)
7:44 AM: HKLM\software\microsoft\windows\currentversion\uninstall\spywarewall\ (1 subtraces) (ID = 359536)
7:44 AM: Found Adware: visfx
7:44 AM: HKLM\software\microsoft\windows\currentversion\uninstall\ovmon\ (2 subtraces) (ID = 712951)
7:44 AM: Found Adware: safesurf
7:44 AM: HKCR\funtools.picshow\ (5 subtraces) (ID = 730902)
7:44 AM: HKCR\funtools.picshow.1\ (3 subtraces) (ID = 730908)
7:44 AM: HKCR\clsid\{4487598c-2ec7-43a2-870e-6d8d720fdd9f}\ (11 subtraces) (ID = 730912)
7:44 AM: HKCR\typelib\{7638761f-0ce1-4e68-9692-d623527a6b7b}\ (9 subtraces) (ID = 730924)
7:44 AM: HKLM\software\classes\funtools.picshow\ (5 subtraces) (ID = 730957)
7:44 AM: HKLM\software\classes\funtools.picshow.1\ (3 subtraces) (ID = 730963)
7:44 AM: HKLM\software\classes\clsid\{4487598c-2ec7-43a2-870e-6d8d720fdd9f}\ (11 subtraces) (ID = 730967)
7:44 AM: HKLM\software\classes\typelib\{7638761f-0ce1-4e68-9692-d623527a6b7b}\ (9 subtraces) (ID = 730979)
7:44 AM: HKLM\software\picshow\ (42 subtraces) (ID = 730989)
7:44 AM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{4487598c-2ec7-43a2-870e-6d8d720fdd9f}\ (ID = 730994)
7:44 AM: Found Adware: cas
7:44 AM: HKCR\typelib\{1b8b502e-465b-4022-be4f-fb6d9f808a18}\ (9 subtraces) (ID = 820387)
7:44 AM: HKLM\software\classes\typelib\{1b8b502e-465b-4022-be4f-fb6d9f808a18}\ (9 subtraces) (ID = 820540)
7:44 AM: HKLM\ovmon\ (ID = 826847)
7:44 AM: Found Adware: ezula ilookup
7:44 AM: HKLM\software\microsoft\webext\ (1 subtraces) (ID = 828947)
7:44 AM: Found Trojan Horse: 2nd-thought
7:44 AM: HKU\.DEFAULT\software\bundles\ (87 subtraces) (ID = 101988)
7:44 AM: HKU\.DEFAULT\software\aun\ (4 subtraces) (ID = 103544)
7:44 AM: Found Adware: browseraid
7:44 AM: HKU\.DEFAULT\software\a70f6a1d-0195-42a2-934c-d8ac0f7c08eb\ (1 subtraces) (ID = 105078)
7:44 AM: HKU\.DEFAULT\software\{12ee7a5e-0674-42f9-a76b-000000004d00}\ (3 subtraces) (ID = 141347)
7:44 AM: HKU\.DEFAULT\software\vb and vba program settings\spywarewall\ (3 subtraces) (ID = 144795)
7:44 AM: HKU\.DEFAULT\software\cmapp\ (ID = 381792)
7:44 AM: HKU\.DEFAULT\software\microsoft\windows\currentversion\run\ || fcengine (ID = 820437)
7:44 AM: Registry Sweep Complete, Elapsed Time:00:01:26
7:44 AM: Starting Cookie Sweep
7:44 AM: Found Spy Cookie: atwola cookie
7:44 AM: allen design@atwola[2].txt (ID = 2255)
7:44 AM: Found Spy Cookie: cc214142 cookie
7:44 AM: allen design@ads.cc214142[2].txt (ID = 2367)
7:44 AM: Found Spy Cookie: belnk cookie
7:44 AM: anyuser@ath.belnk[1].txt (ID = 2293)
7:44 AM: Found Spy Cookie: ask cookie
7:44 AM: allen design@ask[2].txt (ID = 2245)
7:44 AM: Found Spy Cookie: go.com cookie
7:44 AM: allen design@go[2].txt (ID = 2728)
7:44 AM: Found Spy Cookie: partypoker cookie
7:44 AM: allen design@partypoker[2].txt (ID = 3111)
7:44 AM: Found Spy Cookie: ru4 cookie
7:44 AM: anyuser@edge.ru4[1].txt (ID = 3269)
7:44 AM: allen design@belnk[1].txt (ID = 2292)
7:44 AM: allen design@dist.belnk[2].txt (ID = 2293)
7:44 AM: Found Spy Cookie: banner cookie
7:44 AM: allen design@banner[2].txt (ID = 2276)
7:44 AM: Found Spy Cookie: questionmarket cookie
7:44 AM: anyuser@questionmarket[1].txt (ID = 3217)
7:44 AM: Found Spy Cookie: directtrack cookie
7:44 AM: allen design@directtrack[1].txt (ID = 2527)
7:44 AM: allen design@rapidresponse.directtrack[2].txt (ID = 2528)
7:44 AM: Found Spy Cookie: gamespy cookie
7:44 AM: allen design@gamespy[1].txt (ID = 2719)
7:44 AM: Found Spy Cookie: burstnet cookie
7:44 AM: anyuser@burstnet[2].txt (ID = 2336)
7:44 AM: Found Spy Cookie: servlet cookie
7:44 AM: anyuser@servlet[2].txt (ID = 3345)
7:44 AM: Found Spy Cookie: adknowledge cookie
7:44 AM: anyuser@adknowledge[1].txt (ID = 2072)
7:44 AM: Found Spy Cookie: nextag cookie
7:44 AM: allen design@nextag[1].txt (ID = 5014)
7:44 AM: anyuser@go[2].txt (ID = 2728)
7:44 AM: Found Spy Cookie: pointroll cookie
7:44 AM: anyuser@ads.pointroll[2].txt (ID = 3148)
7:44 AM: anyuser@nextag[3].txt (ID = 5014)
7:44 AM: anyuser@servlet[3].txt (ID = 3345)
7:44 AM: Found Spy Cookie: 2o7.net cookie
7:44 AM: anyuser@2o7[2].txt (ID = 1957)
7:44 AM: anyuser@ask[1].txt (ID = 2245)
7:44 AM: allen design@servlet[2].txt (ID = 3345)
7:44 AM: anyuser@dist.belnk[1].txt (ID = 2293)
7:44 AM: anyuser@belnk[2].txt (ID = 2292)
7:44 AM: Found Spy Cookie: reunion cookie
7:44 AM: anyuser@reunion[2].txt (ID = 3255)
7:44 AM: allen design@adknowledge[2].txt (ID = 2072)
7:44 AM: Found Spy Cookie: webtrendslive cookie
7:44 AM: allen design@dcs8ir0f010000oyioyaka1kl_8j7n[1].txt (ID = 3673)
7:44 AM: Found Spy Cookie: yieldmanager cookie
7:44 AM: allen design@ad.yieldmanager[1].txt (ID = 3751)
7:44 AM: anyuser@nextag[2].txt (ID = 5014)
7:44 AM: anyuser@ad.yieldmanager[2].txt (ID = 3751)
7:44 AM: Found Spy Cookie: specificclick.com cookie
7:44 AM: anyuser@adopt.specificclick[1].txt (ID = 3400)
7:44 AM: anyuser@dcs8ir0f010000oyioyaka1kl_8j7n[2].txt (ID = 3673)
7:44 AM: Cookie Sweep Complete, Elapsed Time: 00:00:06
7:44 AM: Starting File Sweep
7:44 AM: Warning: Failed to open file "c:\windows\win386.swp". The process cannot access the file because
it is being used by another process
7:49 AM: winupdt.bin (ID = 48364)
7:49 AM: Found Adware: adlogix
7:49 AM: idtkeb.xml (ID = 49280)
7:49 AM: egmsba.xml (ID = 49218)
7:49 AM: egmsbb.xml (ID = 49280)
7:49 AM: fozdtxk.xml (ID = 57646)
7:49 AM: fozdtxk1.xml (ID = 57647)
7:49 AM: fozdtxk2.xml (ID = 57648)
7:49 AM: stlb2.xml (ID = 51946)
7:49 AM: norisuni.exe (ID = 138284)
7:49 AM: Found Adware: 180search assistant/zango
7:49 AM: c:\windows\system\fleok (ID = -2147480556)
7:53 AM: adlinstallwin32.exe (ID = 49165)
7:53 AM: Found Adware: purityscan
7:53 AM: beryllium.exe (ID = 72939)
7:53 AM: wincmapp.exe (ID = 145805)
7:53 AM: stb.exe (ID = 138172)
7:53 AM: upd0002.exe (ID = 156532)
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06501-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06502-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06503-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06504-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06505-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06506-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06507-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06508-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06509-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f0650a-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f0650b-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f0650c-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f0650d-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f0650e-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f0650f-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06510-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06511-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06512-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06513-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06514-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscs07f06515-5b2a-11da-99e7-00e0294d6894.tmp". The process cannot access the file because
it is being used by another process
7:54 AM: Warning: Failed to open file "c: