here is the spy sweeper session log:
Part 1
********
15:09: | Start of Session, 09 April 2006 |
15:09: Spy Sweeper started
15:09: Sweep initiated using definitions version 652
15:09: Starting Memory Sweep
15:17: Memory Sweep Complete, Elapsed Time: 00:07:36
15:17: Starting Registry Sweep
15:17: Found Adware: blazefind
15:17: HKCR\admilliservx.installer\ (3 subtraces) (ID = 104436)
15:17: HKLM\software\classes\admilliservx.installer\ (3 subtraces) (ID = 104466)
15:17: HKLM\software\classes\winservadx.installer\ (3 subtraces) (ID = 104512)
15:17: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/admilliservx.dll\ (2 subtraces) (ID = 104525)
15:17: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\admilliservx.dll (ID = 104540)
15:17: HKCR\winservadx.installer\ (3 subtraces) (ID = 104577)
15:17: Found Adware: blazefind_adstat
15:17: HKLM\software\classes\winformx.installer\ (3 subtraces) (ID = 104587)
15:17: HKCR\winformx.installer\ (3 subtraces) (ID = 104593)
15:17: Found Adware: elitemediagroup-mediamotor
15:17: HKLM\software\classes\typelib\{466c63ac-f26e-49f1-861a-e07da768a46a}\ (9 subtraces) (ID = 140131)
15:17: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/m67m.ocx\ (2 subtraces) (ID = 140170)
15:17: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\m67m.ocx (ID = 140199)
15:17: HKCR\typelib\{466c63ac-f26e-49f1-861a-e07da768a46a}\ (9 subtraces) (ID = 140223)
15:17: Found Trojan Horse: topconverting downloader
15:17: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\loader2.ocx (ID = 143829)
15:17: Found Trojan Horse: trojan_backdoor_retro64
15:17: HKCR\interface\{450b9e4d-4014-4de3-b34e-014a81468293}\ (8 subtraces) (ID = 144995)
15:17: HKLM\software\classes\interface\{450b9e4d-4014-4de3-b34e-014a81468293}\ (8 subtraces) (ID = 145000)
15:17: HKLM\software\classes\typelib\{c7f00a9a-f1bc-436e-82c7-e8cae6fd67f7}\ (9 subtraces) (ID = 145003)
15:17: HKCR\typelib\{c7f00a9a-f1bc-436e-82c7-e8cae6fd67f7}\ (9 subtraces) (ID = 145004)
15:17: Found Adware: winad
15:17: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediaaccx.dll\ (2 subtraces) (ID = 147191)
15:17: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\mediaaccx.dll (ID = 147221)
15:17: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediagatewayx.dll\ (2 subtraces) (ID = 763026)
15:17: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\mediagatewayx.dll (ID = 763028)
15:17: Found Adware: command
15:17: HKLM\software\microsoft\windows\currentversion\uninstall\{3877c2cd-f137-4144-bdb2-0a811492f920}\ (7 subtraces) (ID = 892523)
15:17: Found Adware: dollarrevenue
15:17: HKLM\software\policies\ || {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} (ID = 916803)
15:17: HKLM\software\microsoft\windows\currentversion\uninstall\{3877c2cd-f137-4144-bdb2-0a811492f920}\ || nomodify (ID = 958653)
15:17: HKLM\software\microsoft\windows\currentversion\uninstall\{3877c2cd-f137-4144-bdb2-0a811492f920}\ || noremove (ID = 958654)
15:17: HKLM\software\microsoft\windows\currentversion\uninstall\{3877c2cd-f137-4144-bdb2-0a811492f920}\ || norepair (ID = 958655)
15:17: HKLM\software\policies\ || {6bf52a52-394a-11d3-b153-00c04f79faa6} (ID = 967836)
15:17: HKCR\appid\{d28cd14c-50be-4cfa-951e-b37f25da3472}\ (1 subtraces) (ID = 1023385)
15:17: HKCR\typelib\{981bda1d-c8ad-46ff-be2c-fddd859ac6f5}\ (9 subtraces) (ID = 1023387)
15:17: HKLM\software\classes\typelib\{981bda1d-c8ad-46ff-be2c-fddd859ac6f5}\ (9 subtraces) (ID = 1023399)
15:17: HKLM\software\policies\ || {645ff040-5081-101b-9f08-00aa002f954e} (ID = 1036890)
15:17: HKCR\appid\activex.dll\ || appid (ID = 1049592)
15:17: HKLM\software\classes\appid\{d28cd14c-50be-4cfa-951e-b37f25da3472}\ (1 subtraces) (ID = 1049593)
15:17: HKLM\software\classes\appid\activex.dll\ || appid (ID = 1049594)
15:17: Found Adware: zquest
15:17: HKLM\software\microsoft\windows\currentversion\uninstall\dh\ (2 subtraces) (ID = 1057035)
15:17: HKCR\clsid\{6001cdf7-6f45-471b-a203-0225615e35a7}\ (4 subtraces) (ID = 1074389)
15:17: HKLM\software\classes\clsid\{6001cdf7-6f45-471b-a203-0225615e35a7}\ (4 subtraces) (ID = 1074513)
15:17: HKLM\software\microsoft\windows\currentversion\uninstall\{a394e835-c8d6-4b4b-884b-d2709059f3be}\ (7 subtraces) (ID = 1110756)
15:17: HKLM\software\microsoft\drsmartload2\ (1 subtraces) (ID = 1134137)
15:17: HKLM\software\microsoft\windows\currentversion\uninstall\{3877c2cd-f137-4144-bdb2-0a811492f920}\ || uninstallstring (ID = 1134952)
15:17: Found Adware: winantispyware 2005
15:17: HKCR\uwfx6pcheck.uwfx6pcheck.1\ (2 subtraces) (ID = 1136990)
15:17: HKLM\software\classes\uwfx6pcheck.uwfx6pcheck.1\ (2 subtraces) (ID = 1137248)
15:17: Found Adware: maxifiles
15:17: HKCR\xbtb04715.ietoolbar.1\ (3 subtraces) (ID = 1156344)
15:17: HKCR\xbtb04715.ietoolbar\ (5 subtraces) (ID = 1156348)
15:17: HKCR\toolband.xbtb04715.1\ (3 subtraces) (ID = 1156354)
15:17: HKCR\toolband.xbtb04715\ (5 subtraces) (ID = 1156358)
15:17: HKCR\xbtb04715.xbtb04715.1\ (3 subtraces) (ID = 1156364)
15:17: HKCR\xbtb04715.xbtb04715\ (5 subtraces) (ID = 1156368)
15:17: HKCR\typelib\{75e46ee7-404b-48ec-9326-c654f21f65bf}\ (9 subtraces) (ID = 1156391)
15:17: HKLM\software\classes\toolband.xbtb04715\ (5 subtraces) (ID = 1156475)
15:17: HKLM\software\classes\xbtb04715.xbtb04715.1\ (3 subtraces) (ID = 1156481)
15:17: HKLM\software\classes\xbtb04715.xbtb04715\ (5 subtraces) (ID = 1156485)
15:17: HKLM\software\classes\typelib\{75e46ee7-404b-48ec-9326-c654f21f65bf}\ (9 subtraces) (ID = 1156508)
15:17: HKLM\software\microsoft\windows\currentversion\uninstall\xbtb04715.xbtb04715toolbar\ (2 subtraces) (ID = 1156519)
15:17: HKLM\software\classes\xbtb04715.ietoolbar.1\ (3 subtraces) (ID = 1156524)
15:17: HKLM\software\classes\xbtb04715.ietoolbar\ (5 subtraces) (ID = 1156528)
15:17: HKLM\software\classes\toolband.xbtb04715.1\ (3 subtraces) (ID = 1156534)
15:17: Found Adware: topsearch
15:17: HKLM\software\topmoxie\topsearch\ (2 subtraces) (ID = 1180367)
15:17: HKLM\software\winfixer_free\ (ID = 1201404)
15:17: Found Adware: internetoptimizer
15:17: HKU\WRSS_Profile_S-1-5-21-1292428093-789336058-682003330-1006\software\avenue media\ (7 subtraces) (ID = 128887)
15:17: HKU\WRSS_Profile_S-1-5-21-1292428093-789336058-682003330-1006\software\microsoft\windows\currentversion\run\ || internet optimizer (ID = 818746)
15:17: Found Adware: cws-aboutblank
15:17: HKU\S-1-5-21-1292428093-789336058-682003330-1004\software\microsoft\internet explorer\main\ || homeoldsp (ID = 115923)
15:17: Found Adware: freshbar
15:17: HKU\S-1-5-21-1292428093-789336058-682003330-1004\software\microsoft\internet explorer\vd\ (ID = 126699)
15:17: Found Adware: findthewebsiteyouneed hijack
15:17: HKU\S-1-5-21-1292428093-789336058-682003330-1004\software\microsoft\internet explorer\search\searchassistant explorer\main\ || default_search_url (ID = 555437)
15:17: HKU\S-1-5-21-1292428093-789336058-682003330-1004\software\microsoft\internet explorer\desktop\components\0\ || source (ID = 1140816)
15:17: HKU\S-1-5-21-1292428093-789336058-682003330-1004\software\xbtb04715\ (71 subtraces) (ID = 1156401)
15:17: HKU\S-1-5-18\software\microsoft\internet explorer\desktop\components\0\ || source (ID = 1140816)
15:17: Registry Sweep Complete, Elapsed Time:00:00:41
15:17: Starting Cookie Sweep
15:17: Found Spy Cookie: a cookie
15:17:
miyoko@a[1].txt (ID = 2027)
15:17: Found Spy Cookie: touchclarity cookie
15:17:
miyoko@barclays.touchclarity[1].txt (ID = 3566)
15:17: Found Spy Cookie: delfinproject cookie
15:17:
miyoko@delfinproject[1].txt (ID = 2509)
15:17: Found Spy Cookie: exitexchange cookie
15:17:
miyoko@exitexchange[1].txt (ID = 2633)
15:17:
miyoko@msn.touchclarity[1].txt (ID = 3566)
15:17:
miyoko@theaa.touchclarity[1].txt (ID = 3566)
15:17: Found Spy Cookie: 247realmedia cookie
15:17: mark the
killer@247realmedia[2].txt (ID = 1953)
15:17: Found Spy Cookie: 2o7.net cookie
15:17: mark the
killer@2o7[2].txt (ID = 1957)
15:17: Found Spy Cookie: about cookie
15:17: mark the
killer@about[1].txt (ID = 2037)
15:17: Found Spy Cookie: yieldmanager cookie
15:17: mark the
killer@ad.yieldmanager[2].txt (ID = 3751)
15:17: Found Spy Cookie: adrevolver cookie
15:17: mark the
killer@adrevolver[1].txt (ID = 2088)
15:17: mark the
killer@adrevolver[2].txt (ID = 2088)
15:17: Found Spy Cookie: adtech cookie
15:17: mark the
killer@adtech[2].txt (ID = 2155)
15:17: Found Spy Cookie: advertising cookie
15:17: mark the
killer@advertising[1].txt (ID = 2175)
15:17: Found Spy Cookie: adviva cookie
15:17: mark the
killer@adviva[2].txt (ID = 2177)
15:17: Found Spy Cookie: apmebf cookie
15:17: mark the
killer@apmebf[1].txt (ID = 2229)
15:17: Found Spy Cookie: atwola cookie
15:17: mark the
killer@ar.atwola[1].txt (ID = 2256)
15:17: Found Spy Cookie: atlas dmt cookie
15:17: mark the
killer@atdmt[2].txt (ID = 2253)
15:17: mark the
killer@atwola[1].txt (ID = 2255)
15:17: mark the
killer@a[1].txt (ID = 2027)
15:17: Found Spy Cookie: bluestreak cookie
15:17: mark the
killer@bluestreak[1].txt (ID = 2314)
15:17: Found Spy Cookie: bs.serving-sys cookie
15:17: mark the
killer@bs.serving-sys[2].txt (ID = 2330)
15:17: Found Spy Cookie: casalemedia cookie
15:17: mark the
killer@casalemedia[2].txt (ID = 2354)
15:17: mark the
killer@compsimgames.about[2].txt (ID = 2038)
15:17: Found Spy Cookie: fastclick cookie
15:17: mark the
killer@fastclick[2].txt (ID = 2651)
15:17: Found Spy Cookie: maxserving cookie
15:17: mark the
killer@maxserving[1].txt (ID = 2966)
15:17: Found Spy Cookie: mediaplex cookie
15:17: mark the
killer@mediaplex[1].txt (ID = 6442)
15:17: Found Spy Cookie: questionmarket cookie
15:17: mark the
killer@questionmarket[1].txt (ID = 3217)
15:17: Found Spy Cookie: realmedia cookie
15:17: mark the
killer@realmedia[2].txt (ID = 3235)
15:17: Found Spy Cookie: serving-sys cookie
15:17: mark the
killer@serving-sys[2].txt (ID = 3343)
15:17: Found Spy Cookie: statcounter cookie
15:17: mark the
killer@statcounter[1].txt (ID = 3447)
15:17: Found Spy Cookie: tradedoubler cookie
15:17: mark the
killer@tradedoubler[1].txt (ID = 3575)
15:17: Found Spy Cookie: tribalfusion cookie
15:17: mark the
killer@tribalfusion[1].txt (ID = 3589)
15:17: Found Spy Cookie: top-banners cookie
15:17:
system@media.top-banners[1].txt (ID = 3548)
15:17: Cookie Sweep Complete, Elapsed Time: 00:00:07
15:17: Starting File Sweep
15:18: c:\program files\common files\winfixer 2006 (ID = -2147458863)
15:18: c:\program files\winfixer_2006 (ID = -2147458870)
15:19: a0157335.exe (ID = 275855)
15:19: a0157337.exe (ID = 275854)
15:19: a0141630.exe (ID = 133210)
15:19: uwfx6_0001_n69m1503netinstaller.exe (ID = 269738)
15:19: Found Adware: effective-i toolbar
15:19: a0141624.exe (ID = 59853)
15:20: Found Trojan Horse: rbot
15:20: a0158872.exe (ID = 269648)
15:20: Found Adware: surfsidekick
15:20: a0141932.dll (ID = 242398)
15:20: uwfx6_0001_n69m1503netinstaller.exe (ID = 269738)
15:21: a0157509.dll (ID = 273539)
15:21: a0160269.exe (ID = 244762)
15:21: a0150862.vbs (ID = 231442)
15:21: Found Adware: 180search assistant/zango
15:21: saap.log (ID = 70593)
15:21: saap_gdf.dat (ID = 70595)
15:22: Found Adware: delfin
15:22: a0146566.exe (ID = 164938)
15:22: a0158869.exe (ID = 231443)
15:22: uwfx6_0001_n69m1503netinstaller.exe (ID = 269738)
15:23: Found Adware: look2me
15:23: a0141934.dll (ID = 163672)
15:23: uwfx6_0001_n69m1503netinstaller.exe (ID = 269738)
15:23: uwfx6_0001_n69m1503netinstaller.exe (ID = 269738)
15:23: uwfx6_0001_n69m1503netinstaller.exe (ID = 269738)
15:23: uwfx6_0001_n69m1503netinstaller.exe (ID = 269738)
15:23: a0146565.ocx (ID = 194608)
15:24: uwfx6_0001_n69m1503netinstaller.exe (ID = 269738)
15:25: Found Trojan Horse: trojan downloader matcash
15:25: a0157852.exe (ID = 246327)
15:26: a0146505.dll (ID = 208494)
15:27: a0157853.exe (ID = 246327)
15:27: a0157336.exe (ID = 275853)
15:29: aa765b4f-9aea-4b69-8ea3-6cf20f (ID = 244763)
15:31: winfixer2006freeinstall[1].cab (ID = 269737)
15:32: winfixer2006freeinstall[3].cab (ID = 269737)
15:35: newname7[1].exe (ID = 275855)
15:35: a0160336.vbs (ID = 231442)
15:39: a0157508.exe (ID = 273538)
15:39: a0146480.dll (ID = 242398)
15:39: winfixer2006freeinstall[2].cab (ID = 269737)
15:40: a0150861.exe (ID = 231443)
15:40: a0146477.exe (ID = 242428)
15:41: winfixer2006freeinstall[4].cab (ID = 269737)
15:42: a0141979.dll (ID = 163672)
15:43: a0146507.exe (ID = 208497)
15:43: a0144435.exe (ID = 194610)
15:45: a0146563.dll (ID = 194609)
15:46: a0144453.dll (ID = 159)
15:46: saapau.dat (ID = 70594)
15:46: a0155305.dll (ID = 159)
15:46: a0157517.dll (ID = 273831)
15:46: Found Adware: deskwizz
15:46: a0157854.exe (ID = 240959)
15:46: a0142129.dll (ID = 159)
15:47: a0144151.dll (ID = 159)
15:47: a0146481.dll (ID = 242399)
15:47: a0141930.dll (ID = 163672)
15:48: salm_kyf_update.dat (ID = 93790)
15:48: backup-20060403-164846-717.dll (ID = 244763)
15:48: a0155303.dll (ID = 163672)
15:48: a0157851.exe (ID = 269649)
15:48: a0153087.sys (ID = 238540)
15:49: Found Adware: whenu savenow
15:49: a0153088.exe (ID = 74460)
15:49: a0144434.dll (ID = 159)
15:49: a0146585.dll (ID = 159)
15:49: a0155304.dll (ID = 163672)
15:50: Found Adware: webhancer
15:50: a0157340.exe (ID = 267157)
15:50: a0157770.exe (ID = 185254)
15:50: a0157772.exe (ID = 244762)
15:50: a0160334.exe (ID = 144946)
15:51: a0146587.dll (ID = 159)
15:52: a0153086.dll (ID = 238551)
15:52: a0159908.dll (ID = 244763)
15:52: a0141622.exe (ID = 216718)
15:52: a0141931.exe (ID = 242428)
15:52: a0158867.exe (ID = 269649)
15:52: Found Adware: whenu save
15:52: a0153021.dll (ID = 182873)
15:52: Found Adware: purityscan
15:52: a0158868.exe (ID = 271320)
15:53: a0160270.dll (ID = 159)
15:54: a0155292.dll (ID = 163672)
15:54: a0141593.exe (ID = 185254)
15:55: a0148691.exe (ID = 238538)
15:55: a0144401.dll (ID = 159)
15:56: a0141626.dll (ID = 166754)
15:56: Found Adware: mirar webband
15:56: a0141625.exe (ID = 133208)
15:56: a0141629.dll (ID = 133227)
15:57: saap_kyf.dat (ID = 70596)
15:57: a0141617.exe (ID = 168558)
15:57: Found Adware: wildmedia
15:57: update10[1].xml (ID = 88967)
15:58: a0150191.exe (ID = 252966)
15:59: a0141634.exe (ID = 212831)
15:59: a0146586.dll (ID = 159)
16:00: a0146561.dll (ID = 159)
16:00: a0144422.dll (ID = 159)
16:00: a0141631.exe (ID = 212828)
16:00: a0141633.exe (ID = 212830)