Scan initialized on 5/16/03 5:02:46 PM ================================================= Started memory scan ==================== Processes Currently Running #:1 (KERNEL32.DLL) #:2 (MSGSRV32.EXE) #:3 (MPREXE.EXE) #:4 (mmtask.tsk) #:5 (NWRECMSG.EXE) #:6 (WINVNC.EXE) #:7 (WM95.EXE) #:8 (EXPLORER.EXE) #:9 (RPCSS.EXE) #:10 (SYSTRAY.EXE) #:11 (STIMON.EXE) #:12 (PHOTOED.EXE) #:13 (VFP6.EXE) #:14 (CUTFTP32.EXE) #:15 (IEXPLORE.EXE) #:16 (PSTORES.EXE) #:17 (DDHELP.EXE) #:18 (REALSCHED.EXE) #:19 (FRONTPG.EXE) #:20 (NOTEPAD.EXE) #:21 (SPYNUKER.EXE) Memory scan result : Total modules found :22 Suspicious modules found: Scan complete Started registry scan ==================== Registry Key Type = Alexa: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}\] Registry scan result: Suspicious keys found :1 Scan complete Started Cookie scan ==================== bfast Cookie:C:\WINDOWS\Cookies\rick@bfast[2].txt advertising Cookie:C:\WINDOWS\Cookies\rick@advertising[1].txt advertising Cookie:C:\WINDOWS\Cookies\rick@servedby.advertising[2].txt hitbox Cookie:C:\WINDOWS\Cookies\rick@hitbox[2].txt hitbox Cookie:C:\WINDOWS\Cookies\rick@ehg-lexnex.hitbox[1].txt hitbox Cookie:C:\WINDOWS\Cookies\rick@hg1.hitbox[2].txt hitbox Cookie:C:\WINDOWS\Cookies\rick@ehg-amtransair.hitbox[1].txt hitbox Cookie:C:\WINDOWS\Cookies\admin@ehg-j2.hitbox[1].txt hitbox Cookie:C:\WINDOWS\Cookies\admin@hitbox[2].txt qksrv Cookie:C:\WINDOWS\Cookies\rick@www.qksrv[1].txt qksrv Cookie:C:\WINDOWS\Cookies\admin@www.qksrv[1].txt affiliate Cookie:C:\WINDOWS\Cookies\rick@affiliates.allposters[1].txt Doubleclick Cookie:C:\WINDOWS\Cookies\admin@doubleclick[1].txt Doubleclick Cookie:C:\WINDOWS\Cookies\rick@doubleclick[1].txt S005 Cookie:C:\WINDOWS\Cookies\rick@S005-01-8-18-223912-97663[1].txt atdmt Cookie:C:\WINDOWS\Cookies\rick@atdmt[2].txt atdmt Cookie:C:\WINDOWS\Cookies\admin@atdmt[2].txt webtrendslive Cookie:C:\WINDOWS\Cookies\rick@statse.webtrendslive[1].txt mediaplex Cookie:C:\WINDOWS\Cookies\admin@mediaplex[1].txt mediaplex Cookie:C:\WINDOWS\Cookies\rick@mediaplex[2].txt x10 Cookie:C:\WINDOWS\Cookies\rick@x10[1].txt x10 Cookie:C:\WINDOWS\Cookies\rick@x10[3].txt Cookie scan results: Suspicious cookies found:22 Scan complete Started folder scan ==================== Folder scan result: Suspicious folders found :0 Started file scan ==================== bfast file:C:\WINDOWS\Cookies\rick@bfast[2].txt FileSize :0 kb Last accessed :4/24/03 1:47:46 PM Build : OS :- advertising file:C:\WINDOWS\Cookies\rick@advertising[1].txt FileSize :0 kb Last accessed :4/24/03 1:45:44 PM Build : OS :- advertising file:C:\WINDOWS\Cookies\rick@servedby.advertising[2].txt FileSize :1 kb Last accessed :5/16/03 2:43:14 PM Build : OS :- hitbox file:C:\WINDOWS\Cookies\rick@hitbox[2].txt FileSize :0 kb Last accessed :5/16/03 4:45:18 PM Build : OS :- hitbox file:C:\WINDOWS\Cookies\rick@ehg-lexnex.hitbox[1].txt FileSize :0 kb Last accessed :4/22/03 11:24:54 PM Build : OS :- hitbox file:C:\WINDOWS\Cookies\rick@hg1.hitbox[2].txt FileSize :0 kb Last accessed :5/16/03 4:45:18 PM Build : OS :- hitbox file:C:\WINDOWS\Cookies\rick@ehg-amtransair.hitbox[1].txt FileSize :0 kb Last accessed :4/24/03 8:56:06 PM Build : OS :- hitbox file:C:\WINDOWS\Cookies\admin@ehg-j2.hitbox[1].txt FileSize :0 kb Last accessed :5/9/03 10:22:42 PM Build : OS :- hitbox file:C:\WINDOWS\Cookies\admin@hitbox[2].txt FileSize :0 kb Last accessed :5/9/03 10:14:50 PM Build : OS :- qksrv file:C:\WINDOWS\Cookies\rick@www.qksrv[1].txt FileSize :0 kb Last accessed :4/22/03 8:45:26 PM Build : OS :- qksrv file:C:\WINDOWS\Cookies\admin@www.qksrv[1].txt FileSize :0 kb Last accessed :5/9/03 11:47:36 PM Build : OS :- affiliate file:C:\WINDOWS\Cookies\rick@affiliates.allposters[1].txt FileSize :0 kb Last accessed :5/10/03 2:39:58 PM Build : OS :- Doubleclick file:C:\WINDOWS\Cookies\admin@doubleclick[1].txt FileSize :0 kb Last accessed :4/19/03 2:45:14 AM Build : OS :- Doubleclick file:C:\WINDOWS\Cookies\rick@doubleclick[1].txt FileSize :0 kb Last accessed :4/21/03 6:17:50 PM Build : OS :- S005 file:C:\WINDOWS\Cookies\rick@S005-01-8-18-223912-97663[1].txt FileSize :0 kb Last accessed :4/24/03 6:38:24 PM Build : OS :- atdmt file:C:\WINDOWS\Cookies\rick@atdmt[2].txt FileSize :0 kb Last accessed :4/21/03 4:20:42 PM Build : OS :- atdmt file:C:\WINDOWS\Cookies\admin@atdmt[2].txt FileSize :0 kb Last accessed :5/14/03 6:34:30 PM Build : OS :- webtrendslive file:C:\WINDOWS\Cookies\rick@statse.webtrendslive[1].txt FileSize :0 kb Last accessed :4/24/03 6:37:40 PM Build : OS :- mediaplex file:C:\WINDOWS\Cookies\admin@mediaplex[1].txt FileSize :0 kb Last accessed :4/19/03 6:34:46 AM Build : OS :- mediaplex file:C:\WINDOWS\Cookies\rick@mediaplex[2].txt FileSize :0 kb Last accessed :4/24/03 9:38:10 PM Build : OS :- x10 file:C:\WINDOWS\Cookies\rick@x10[1].txt FileSize :1 kb Last accessed :4/24/03 3:19:30 PM Build : OS :- x10 file:C:\WINDOWS\Cookies\rick@x10[3].txt FileSize :0 kb Last accessed :4/24/03 3:15:32 PM Build : OS :- Lop.com file:C:\WINDOWS\Favorites\Imported bookmarks\Personal Toolbar Folder\Channels\Games.url FileSize :0 kb Last accessed :5/4/99 2:38:18 PM Build : OS :- Lop.com file:C:\Program Files\REAL\RealPlayer\DataCache\webresources\dnserror.htm FileSize :0 kb Last accessed :7/17/02 3:29:00 PM Build : OS :- File scan result : Suspicious files found :24 Scan complete ========================================================== Spyware components found total: 25 ========================================================== Task completed on 5:44:37 PM Done ========================================================== Application Version: 1.10.0 ========================================================== Major Version: 4 Minor Version: 10 Build Number Version: 1998 Platform ID: 1 Service Pack Major: 0 Service Pack Minor: 0 Suite Mask: 0 Platform: Windows 98 Platform Version: Windows 98 v4.10, Build 1998 OS Product Name: Unknown CSD Version: Is Windows XP: False Is Windows 2K: False Is Windows NT: False Is Windows 9x: True Is Windows 95: True Is Windows 98: True Is Windows Me: False ==========================================================