I've yet to have a pop-up or redirect since…Waiting for the ball to drop
Logfile of HijackThis v1.99.1
Scan saved at 2:57:08 PM, on 20/05/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\AOL 8.0\aoltray.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\DllHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Iain\My Documents\Hijack this\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.cbc.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.cbc.ca/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0\aoltray.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Norton Confidence Online - {144FDEB7-A23D-4D39-A00E-AA44195535B6} - C:\WINDOWS\wcidButton.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid;=0x409
O16 - DPF: {CCC46940-DED0-476C-A27E-115B10DAE0B4} -
https://td.nortonconfidenceonline.com/plug-in/NCO/WSAS.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
********
9:43 AM: | Start of Session, May 20, 2006 |
9:43 AM: Spy Sweeper started
9:43 AM: Sweep initiated using definitions version 682
9:43 AM: Starting Memory Sweep
9:48 AM: Memory Sweep Complete, Elapsed Time: 00:04:06
9:48 AM: Starting Registry Sweep
9:48 AM: Found Adware: blazefind
9:48 AM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/bridge.dll\ (2 subtraces) (ID = 104526)
9:48 AM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\bridge.dll (ID = 104541)
9:48 AM: Found Adware: websearch toolbar
9:48 AM: HKLM\system\currentcontrolset\enum\root\legacy_wintoolssvc\ (8 subtraces) (ID = 146518)
9:48 AM: Found Adware: winad
9:48 AM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/winadtoolsx.dll\ || .owner (ID = 147196)
9:48 AM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/winadtoolsx.dll\ || {15ad4789-cdb4-47e1-a9da-992ee8e6bad6} (ID = 147197)
9:48 AM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\winadtoolsx.dll (ID = 147225)
9:48 AM: Found Adware: directrevenue-abetterinternet
9:48 AM: HKU\WRSS_Profile_S-1-5-21-1152283195-3815273060-1028051869-500\software\aurora\ (18 subtraces) (ID = 360174)
9:48 AM: Found Adware: browseraid
9:48 AM: HKU\WRSS_Profile_S-1-5-21-1152283195-3815273060-1028051869-1009\software\a70f6a1d-0195-42a2-934c-d8ac0f7c08eb\ (1 subtraces) (ID = 105078)
9:48 AM: Found Adware: searchtoolbar
9:48 AM: HKU\WRSS_Profile_S-1-5-21-1152283195-3815273060-1028051869-1009\software\{12ee7a5e-0674-42f9-a76b-000000004d00}\ (5 subtraces) (ID = 141347)
9:48 AM: HKU\WRSS_Profile_S-1-5-21-1152283195-3815273060-1028051869-1009\software\toolbar\ (28 subtraces) (ID = 146513)
9:48 AM: Found Adware: wildmedia
9:48 AM: HKU\WRSS_Profile_S-1-5-21-1152283195-3815273060-1028051869-1009\software\microsoft\internet explorer\main\ || updater2 (ID = 146720)
9:48 AM: HKU\WRSS_Profile_S-1-5-21-1152283195-3815273060-1028051869-1009\software\microsoft\internet explorer\main\ || updater (ID = 146721)
9:48 AM: HKU\WRSS_Profile_S-1-5-21-1152283195-3815273060-1028051869-1009\software\toolbar\ (28 subtraces) (ID = 646239)
9:48 AM: HKU\S-1-5-21-1152283195-3815273060-1028051869-1008\software\a70f6a1d-0195-42a2-934c-d8ac0f7c08eb\ (1 subtraces) (ID = 105078)
9:48 AM: Found Adware: cws-aboutblank
9:48 AM: HKU\S-1-5-21-1152283195-3815273060-1028051869-1008\software\microsoft\internet explorer\main\ || search bar_bak (ID = 115924)
9:48 AM: HKU\S-1-5-21-1152283195-3815273060-1028051869-1008\software\microsoft\internet explorer\main\ || search page_bak (ID = 115925)
9:48 AM: HKU\S-1-5-21-1152283195-3815273060-1028051869-1008\software\microsoft\internet explorer\main\ || search page_bak (ID = 774883)
9:48 AM: Registry Sweep Complete, Elapsed Time:00:00:16
9:48 AM: Starting Cookie Sweep
9:48 AM: Found Spy Cookie: 247realmedia cookie
9:48 AM: jessamyn@247realmedia[2].txt (ID = 1953)
9:48 AM: Found Spy Cookie: 2o7.net cookie
9:48 AM: jessamyn@2o7[1].txt (ID = 1957)
9:48 AM: Found Spy Cookie: 190dotcom cookie
9:48 AM: jessamyn@69.50.190[2].txt (ID = 1936)
9:48 AM: Found Spy Cookie: 7search cookie
9:48 AM: jessamyn@7search[2].txt (ID = 2011)
9:48 AM: Found Spy Cookie: 888 cookie
9:48 AM: jessamyn@888[1].txt (ID = 2019)
9:48 AM: jessamyn@888[3].txt (ID = 2019)
9:48 AM: Found Spy Cookie: go.com cookie
9:48 AM: [removed][2].txt (ID = 2729)
9:48 AM: Found Spy Cookie: about cookie
9:48 AM: jessamyn@about[2].txt (ID = 2037)
9:48 AM: Found Spy Cookie: accoona cookie
9:48 AM: jessamyn@accoona[2].txt (ID = 2041)
9:48 AM: Found Spy Cookie: yieldmanager cookie
9:48 AM: [removed][1].txt (ID = 3751)
9:48 AM: Found Spy Cookie: adknowledge cookie
9:48 AM: jessamyn@adknowledge[1].txt (ID = 2072)
9:48 AM: Found Spy Cookie: adlegend cookie
9:48 AM: jessamyn@adlegend[2].txt (ID = 2074)
9:48 AM: Found Spy Cookie: hbmediapro cookie
9:48 AM: [removed][2].txt (ID = 2768)
9:48 AM: Found Spy Cookie: precisead cookie
9:48 AM: [removed][2].txt (ID = 3182)
9:48 AM: Found Spy Cookie: addynamix cookie
9:48 AM: [removed][2].txt (ID = 2062)
9:48 AM: Found Spy Cookie: belointeractive cookie
9:48 AM: [removed][2].txt (ID = 2295)
9:48 AM: Found Spy Cookie: adreactor cookie
9:48 AM: [removed][1].txt (ID = 2087)
9:48 AM: Found Spy Cookie: adultfriendfinder cookie
9:48 AM: jessamyn@adultfriendfinder[2].txt (ID = 2165)
9:48 AM: Found Spy Cookie: apmebf cookie
9:48 AM: jessamyn@apmebf[2].txt (ID = 2229)
9:48 AM: Found Spy Cookie: atlas dmt cookie
9:48 AM: jessamyn@atdmt[2].txt (ID = 2253)
9:48 AM: Found Spy Cookie: belnk cookie
9:48 AM: [removed][2].txt (ID = 2293)
9:48 AM: Found Spy Cookie: atwola cookie
9:48 AM: jessamyn@atwola[1].txt (ID = 2255)
9:48 AM: Found Spy Cookie: azjmp cookie
9:48 AM: jessamyn@azjmp[2].txt (ID = 2270)
9:48 AM: Found Spy Cookie: a cookie
9:48 AM: jessamyn@a[1].txt (ID = 2027)
9:48 AM: jessamyn@a[2].txt (ID = 2027)
9:48 AM: jessamyn@a[3].txt (ID = 2027)
9:48 AM: jessamyn@a[4].txt (ID = 2027)
9:48 AM: Found Spy Cookie: banners cookie
9:48 AM: jessamyn@banners[2].txt (ID = 2282)
9:48 AM: Found Spy Cookie: banner cookie
9:48 AM: jessamyn@banner[1].txt (ID = 2276)
9:48 AM: jessamyn@belnk[1].txt (ID = 2292)
9:48 AM: jessamyn@belointeractive[1].txt (ID = 2294)
9:48 AM: Found Spy Cookie: bizrate cookie
9:48 AM: jessamyn@bizrate[1].txt (ID = 2308)
9:48 AM: Found Spy Cookie: bs.serving-sys cookie
9:48 AM: [removed]-sys[1].txt (ID = 2330)
9:48 AM: Found Spy Cookie: btgrab cookie
9:48 AM: [removed][1].txt (ID = 2333)
9:48 AM: Found Spy Cookie: goclick cookie
9:48 AM: [removed][1].txt (ID = 2733)
9:48 AM: Found Spy Cookie: casalemedia cookie
9:48 AM: jessamyn@casalemedia[1].txt (ID = 2354)
9:48 AM: Found Spy Cookie: cassava cookie
9:48 AM: jessamyn@cassava[1].txt (ID = 2362)
9:48 AM: Found Spy Cookie: cliks cookie
9:48 AM: jessamyn@cliks[2].txt (ID = 2414)
9:48 AM: Found Spy Cookie: cnt cookie
9:48 AM: jessamyn@cnt[2].txt (ID = 2422)
9:48 AM: Found Spy Cookie: contextuads cookie
9:48 AM: jessamyn@contextuads[1].txt (ID = 2461)
9:48 AM: Found Spy Cookie: sextracker cookie
9:48 AM: [removed][1].txt (ID = 3362)
9:48 AM: [removed][1].txt (ID = 3362)
9:48 AM: [removed][1].txt (ID = 3362)
9:48 AM: Found Spy Cookie: overture cookie
9:48 AM: [removed][1].txt (ID = 3106)
9:48 AM: [removed][1].txt (ID = 3106)
9:48 AM: Found Spy Cookie: dealtime cookie
9:48 AM: jessamyn@dealtime[2].txt (ID = 2505)
9:48 AM: [removed][1].txt (ID = 2293)
9:48 AM: Found Spy Cookie: findwhat cookie
9:48 AM: jessamyn@findwhat[1].txt (ID = 2674)
9:48 AM: Found Spy Cookie: touchclarity cookie
9:48 AM: [removed][1].txt (ID = 3566)
9:48 AM: Found Spy Cookie: go2net.com cookie
9:48 AM: jessamyn@go2net[1].txt (ID = 2730)
9:48 AM: jessamyn@go[2].txt (ID = 2728)
9:48 AM: Found Spy Cookie: screensavers.com cookie
9:48 AM: [removed][2].txt (ID = 3298)
9:48 AM: Found Spy Cookie: infospace cookie
9:48 AM: jessamyn@infospace[2].txt (ID = 2865)
9:48 AM: Found Spy Cookie: kmpads cookie
9:48 AM: jessamyn@kmpads[1].txt (ID = 2909)
9:48 AM: Found Spy Cookie: kount cookie
9:48 AM: jessamyn@kount[1].txt (ID = 2911)
9:48 AM: Found Spy Cookie: linksynergy cookie
9:48 AM: jessamyn@linksynergy[1].txt (ID = 2926)
9:48 AM: jessamyn@marketlive.122.2o7[1].txt (ID = 1958)
9:48 AM: Found Spy Cookie: mediaplex cookie
9:48 AM: jessamyn@mediaplex[1].txt (ID = 6442)
9:48 AM: Found Spy Cookie: metareward.com cookie
9:48 AM: jessamyn@metareward[2].txt (ID = 2990)
9:48 AM: Found Spy Cookie: mygeek cookie
9:48 AM: jessamyn@mygeek[1].txt (ID = 3041)
9:48 AM: Found Spy Cookie: nextag cookie
9:48 AM: jessamyn@nextag[2].txt (ID = 5014)
9:48 AM: Found Spy Cookie: offeroptimizer cookie
9:48 AM: jessamyn@offeroptimizer[2].txt (ID = 3087)
9:48 AM: jessamyn@overture[1].txt (ID = 3105)
9:48 AM: [removed][1].txt (ID = 3567)
9:48 AM: Found Spy Cookie: partypoker cookie
9:48 AM: jessamyn@partypoker[2].txt (ID = 3111)
9:48 AM: [removed][1].txt (ID = 3106)
9:48 AM: Found Spy Cookie: qksrv cookie
9:48 AM: jessamyn@qksrv[2].txt (ID = 3213)
9:48 AM: Found Spy Cookie: realmedia cookie
9:48 AM: jessamyn@realmedia[1].txt (ID = 3235)
9:48 AM: Found Spy Cookie: rightmedia cookie
9:48 AM: jessamyn@rightmedia[2].txt (ID = 3259)
9:48 AM: Found Spy Cookie: rn11 cookie
9:48 AM: jessamyn@rn11[2].txt (ID = 3261)
9:48 AM: [removed][1].txt (ID = 2729)
9:48 AM: Found Spy Cookie: server.iad.liveperson cookie
9:48 AM: [removed][1].txt (ID = 3341)
9:48 AM: Found Spy Cookie: serving-sys cookie
9:48 AM: jessamyn@serving-sys[1].txt (ID = 3343)
9:48 AM: Found Spy Cookie: sexlist cookie
9:48 AM: jessamyn@sexlist[1].txt (ID = 3353)
9:48 AM: jessamyn@sextracker[2].txt (ID = 3361)
9:48 AM: Found Spy Cookie: spykiller cookie
9:48 AM: jessamyn@spykiller[1].txt (ID = 3413)
9:48 AM: Found Spy Cookie: spywarestormer cookie
9:48 AM: jessamyn@spywarestormer[2].txt (ID = 3417)
9:48 AM: [removed][2].txt (ID = 2506)
9:48 AM: Found Spy Cookie: clicktracks cookie
9:48 AM: [removed][1].txt (ID = 2407)
9:48 AM: Found Spy Cookie: tacoda cookie
9:48 AM: jessamyn@tacoda[2].txt (ID = 6444)
9:48 AM: Found Spy Cookie: tracking cookie
9:48 AM: jessamyn@tracking[2].txt (ID = 3571)
9:48 AM: [removed][1].txt (ID = 2038)
9:48 AM: Found Spy Cookie: joetec.net cookie
9:48 AM: [removed][1].txt (ID = 2890)
9:48 AM: Found Spy Cookie: hermoment.com cookie
9:48 AM: [removed][1].txt (ID = 2774)
9:48 AM: [removed][1].txt (ID = 3298)
9:48 AM: Found Spy Cookie: claxonmedia cookie
9:48 AM: [removed][1].txt (ID = 2388)
9:48 AM: [removed][2].txt (ID = 2389)
9:48 AM: [removed][2].txt (ID = 2387)
9:48 AM: Found Spy Cookie: xiti cookie
9:48 AM: jessamyn@xiti[1].txt (ID = 3717)
9:48 AM: Found Spy Cookie: zango cookie
9:48 AM: jessamyn@zango[1].txt (ID = 3760)
9:48 AM: Found Spy Cookie: zedo cookie
9:48 AM: jessamyn@zedo[1].txt (ID = 3762)
9:48 AM: Found Spy Cookie: zserv cookie
9:48 AM: [removed][1].txt (ID = 3769)
9:48 AM: [removed][2].txt (ID = 3751)
9:48 AM: Found Spy Cookie: specificclick.com cookie
9:48 AM: [removed][1].txt (ID = 3400)
9:48 AM: iain@cbs.112.2o7[1].txt (ID = 1958)
9:48 AM: iain@tacoda[1].txt (ID = 6444)
9:48 AM: Cookie Sweep Complete, Elapsed Time: 00:00:09
9:48 AM: Starting File Sweep
10:09 AM: Found Trojan Horse: trojan-downloader-ruin
10:09 AM: dmusu.exe (ID = 147)
10:12 AM: csari.exe (ID = 246)
10:23 AM: Found Adware: 180search assistant/zango
10:23 AM: salm_gdf.dat (ID = 93789)
10:23 AM: Warning: Unhandled Archive Type
10:23 AM: Warning: Unhandled Archive Type
10:23 AM: Warning: Unhandled Archive Type
10:23 AM: Warning: Unhandled Archive Type
10:23 AM: Warning: Unhandled Archive Type
10:23 AM: Warning: Unhandled Archive Type
10:23 AM: Warning: Unhandled Archive Type
10:23 AM: Warning: Unhandled Archive Type
10:23 AM: Warning: Unhandled Archive Type
10:23 AM: Warning: Unhandled Archive Type
10:23 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:24 AM: Warning: Unhandled Archive Type
10:25 AM: File Sweep Complete, Elapsed Time: 00:36:29
10:25 AM: Full Sweep has completed. Elapsed time 00:41:04
10:25 AM: Traces Found: 207
2:49 PM: Removal process initiated
2:49 PM: Quarantining All Traces: 180search assistant/zango
2:49 PM: Quarantining All Traces: cws-aboutblank
2:49 PM: Quarantining All Traces: directrevenue-abetterinternet
2:49 PM: Quarantining All Traces: trojan-downloader-ruin
2:49 PM: Quarantining All Traces: websearch toolbar
2:49 PM: Quarantining All Traces: wildmedia
2:49 PM: Quarantining All Traces: blazefind
2:49 PM: Quarantining All Traces: winad
2:49 PM: Quarantining All Traces: browseraid
2:49 PM: Quarantining All Traces: searchtoolbar
2:49 PM: Quarantining All Traces: 190dotcom cookie
2:49 PM: Quarantining All Traces: 247realmedia cookie
2:49 PM: Quarantining All Traces: 2o7.net cookie
2:49 PM: Quarantining All Traces: 7search cookie
2:49 PM: Quarantining All Traces: 888 cookie
2:49 PM: Quarantining All Traces: a cookie
2:49 PM: Quarantining All Traces: about cookie
2:49 PM: Quarantining All Traces: accoona cookie
2:49 PM: Quarantining All Traces: addynamix cookie
2:49 PM: Quarantining All Traces: adknowledge cookie
2:49 PM: Quarantining All Traces: adlegend cookie
2:49 PM: Quarantining All Traces: adreactor cookie
2:49 PM: Quarantining All Traces: adultfriendfinder cookie
2:49 PM: Quarantining All Traces: apmebf cookie
2:49 PM: Quarantining All Traces: atlas dmt cookie
2:49 PM: Quarantining All Traces: atwola cookie
2:49 PM: Quarantining All Traces: azjmp cookie
2:49 PM: Quarantining All Traces: banner cookie
2:49 PM: Quarantining All Traces: banners cookie
2:49 PM: Quarantining All Traces: belnk cookie
2:49 PM: Quarantining All Traces: belointeractive cookie
2:49 PM: Quarantining All Traces: bizrate cookie
2:49 PM: Quarantining All Traces: bs.serving-sys cookie
2:49 PM: Quarantining All Traces: btgrab cookie
2:49 PM: Quarantining All Traces: casalemedia cookie
2:49 PM: Quarantining All Traces: cassava cookie
2:49 PM: Quarantining All Traces: claxonmedia cookie
2:49 PM: Quarantining All Traces: clicktracks cookie
2:49 PM: Quarantining All Traces: cliks cookie
2:49 PM: Quarantining All Traces: cnt cookie
2:49 PM: Quarantining All Traces: contextuads cookie
2:49 PM: Quarantining All Traces: dealtime cookie
2:49 PM: Quarantining All Traces: findwhat cookie
2:49 PM: Quarantining All Traces: go.com cookie
2:49 PM: Quarantining All Traces: go2net.com cookie
2:49 PM: Quarantining All Traces: goclick cookie
2:49 PM: Quarantining All Traces: hbmediapro cookie
2:49 PM: Quarantining All Traces: hermoment.com cookie
2:49 PM: Quarantining All Traces: infospace cookie
2:49 PM: Quarantining All Traces: joetec.net cookie
2:49 PM: Quarantining All Traces: kmpads cookie
2:49 PM: Quarantining All Traces: kount cookie
2:49 PM: Quarantining All Traces: linksynergy cookie
2:49 PM: Quarantining All Traces: mediaplex cookie
2:49 PM: Quarantining All Traces: metareward.com cookie
2:49 PM: Quarantining All Traces: mygeek cookie
2:49 PM: Quarantining All Traces: nextag cookie
2:49 PM: Quarantining All Traces: offeroptimizer cookie
2:49 PM: Quarantining All Traces: overture cookie
2:49 PM: Quarantining All Traces: partypoker cookie
2:49 PM: Quarantining All Traces: precisead cookie
2:49 PM: Quarantining All Traces: qksrv cookie
2:49 PM: Quarantining All Traces: realmedia cookie
2:49 PM: Quarantining All Traces: rightmedia cookie
2:49 PM: Quarantining All Traces: rn11 cookie
2:49 PM: Quarantining All Traces: screensavers.com cookie
2:49 PM: Quarantining All Traces: server.iad.liveperson cookie
2:49 PM: Quarantining All Traces: serving-sys cookie
2:49 PM: Quarantining All Traces: sexlist cookie
2:49 PM: Quarantining All Traces: sextracker cookie
2:49 PM: Quarantining All Traces: specificclick.com cookie
2:49 PM: Quarantining All Traces: spykiller cookie
2:49 PM: Quarantining All Traces: spywarestormer cookie
2:49 PM: Quarantining All Traces: tacoda cookie
2:49 PM: Quarantining All Traces: touchclarity cookie
2:49 PM: Quarantining All Traces: tracking cookie
2:49 PM: Quarantining All Traces: xiti cookie
2:49 PM: Quarantining All Traces: yieldmanager cookie
2:49 PM: Quarantining All Traces: zango cookie
2:49 PM: Quarantining All Traces: zedo cookie
2:49 PM: Quarantining All Traces: zserv cookie
2:49 PM: Removal process completed. Elapsed time 00:00:42
********
9:41 AM: | Start of Session, May 20, 2006 |
9:41 AM: Spy Sweeper started
9:42 AM: Your spyware definitions have been updated.
9:43 AM: | End of Session, May 20, 2006 |