07:47: Traces Found: 24 07:47: Full Sweep has completed. Elapsed time 00:12:50 07:47: File Sweep Complete, Elapsed Time: 00:07:53 07:47: C:\Documents and Settings\Malekal_morte\Start Menu\Programs\SearchPorn\Uninstall.lnk (1 subtraces) (ID = 2147595702) 07:44: Warning: SweepDirectories: Cannot find directory "d:". This directory was not added to the list of paths to be scanned. 07:44: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\ssms1743307d-2381-49c0-b99c-99f3d00353f6.tmp". The operation completed successfully 07:44: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\ssms20031f20-dab9-4944-8b7a-826c3a237bb4.tmp". The operation completed successfully 07:44: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\ssms92a19f58-a708-4595-8ec9-dc630446aaae.tmp". The operation completed successfully 07:44: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\ssmsf6b7a549-7ca1-43f1-bd8f-7dd504dfc299.tmp". The operation completed successfully 07:44: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\ssmsa6ef42bf-8ccb-405c-a2dd-507d9a21fda5.tmp". The operation completed successfully 07:44: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\ssmsba6c2d97-301f-4eee-8c20-ff487c51e462.tmp". The operation completed successfully 07:43: c:\windows\system32\kdnts.exe (ID = 1339216) 07:40: C:\Documents and Settings\Malekal_morte\Local Settings\Temp\bis1.exe (ID = 435542) 07:39: C:\Documents and Settings\All Users\Application Data\Bind army eggs joy (1 subtraces) (ID = 2147573865) 07:39: C:\Program Files\SearchPorn (1 subtraces) (ID = 2147595702) 07:39: C:\Documents and Settings\Malekal_morte\Start Menu\Programs\SearchPorn (1 subtraces) (ID = 2147595729) 07:39: Starting File Sweep 07:39: Warning: SweepDirectories: Cannot find directory "a:". This directory was not added to the list of paths to be scanned. 07:39: Cookie Sweep Complete, Elapsed Time: 00:00:00 07:39: c:\documents and settings\malekal_morte\cookies\malekal_morte@0[3].txt (ID = 3282) 07:39: c:\documents and settings\malekal_morte\cookies\malekal_morte@0[2].txt (ID = 3282) 07:39: Found Spy Cookie: sandboxer cookie 07:39: Starting Cookie Sweep 07:39: Registry Sweep Complete, Elapsed Time:00:00:22 07:39: HKU\S-1-5-21-1214440339-1454471165-682003330-1003\software\searchporn\ (ID = 3545302) 07:39: HKU\S-1-5-21-1214440339-1454471165-682003330-1003\software\microsoft\internet explorer\main\ || start page (ID = 2436132) 07:39: HKLM\software\microsoft\windows\currentversion\uninstall\searchporn\ (ID = 3545292) 07:39: HKLM\software\classes\searchporn\ (ID = 3545286) 07:39: Found Trojan Horse: trojan-dnschanger 07:39: HKLM\software\classes\e404.e404mgr.1\ (ID = 3260818) 07:39: HKLM\software\classes\e404.e404mgr\ (ID = 3260812) 07:39: Found Adware: e404 07:39: HKCR\msvps.msvpsapp\ (ID = 3047939) 07:39: HKLM\software\microsoft\windows\currentversion\run\ || eggs joy math type (ID = 2939636) 07:39: Found Adware: lopdotcom 07:39: HKLM\software\classes\msvps.msvpsapp\ (ID = 2335901) 07:39: Found Trojan Horse: trojan-ace-x 07:39: HKLM\software\classes\msvps.msvpsapp\ (ID = 2335901) 07:39: HKLM\software\microsoft\windows\currentversion\uninstall\windows safety alert\ (ID = 2118088) 07:39: Found Trojan Horse: trojan-downloader-zlob 07:39: Starting Registry Sweep 07:39: Memory Sweep Complete, Elapsed Time: 00:04:13 07:36: Detected running threat: C:\WINDOWS\system32\khfgdcy.dll (ID = 676) 07:36: Found Adware: virtumonde 07:34: Starting Memory Sweep 07:34: Start Full Sweep 07:34: Sweep initiated using definitions version 1094 07:34: Your definitions are up to date. Keylogger: Off E-mail Attachment: On 07:34: Informational: ShieldEmail: Start monitoring port 25 for mail activities 07:34: Informational: ShieldEmail: Start monitoring port 110 for mail activities BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On File System Shield: On Execution Shield: On System Services Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 07:34: Shield States 07:33: License Check Status (0): Success 07:33: Spyware Definitions: 1094 07:32: Spy Sweeper 5.5.7.124 started 07:32: Spy Sweeper 5.5.7.124 started 07:32: | Start of Session, dimanche 24 février 2008 | ***************