Ad-Aware SE Log File., Aurora Popups. |
![]() ![]() |
Ad-Aware SE Log File., Aurora Popups. |
Apr 21 2005, 02:50 PM
Post
#1
|
|
|
New Member ![]() Posts: 2 OS: windows xp |
Ad-Aware SE Build 1.05 Logfile Created on:Thursday, April 21, 2005 3:09:51 PM Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R40 20.04.2005 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» AltnetBDE(TAC index:4):4 total references MRU List(TAC index:0):26 total references Tracking Cookie(TAC index:3):8 total references Windows(TAC index:3):1 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Definition File: ========================= Definitions File Loaded: Reference Number : SE1R40 20.04.2005 Internal build : 47 File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref File size : 461235 Bytes Total size : 1395231 Bytes Signature data size : 1364710 Bytes Reference data size : 30009 Bytes Signatures total : 38921 Fingerprints total : 813 Fingerprints size : 29073 Bytes Target categories : 15 Target families : 650 Memory + processor status: ========================== Number of processors : 1 Processor architecture : Intel Pentium IV Memory available:37 % Total physical memory:260096 kb Available physical memory:94060 kb Total page file size:636968 kb Available on page file:390056 kb Total virtual memory:2097024 kb Available virtual memory:2045224 kb OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600) Ad-Aware SE Settings =========================== Set : Search for negligible risk entries Set : Move deleted files to Recycle Bin Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan within archives Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Obtain command line of scanned processes Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Write-protect system files after repair (Hosts file, etc.) Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects 4-21-2005 3:09:51 PM - Scan started. (Custom mode) Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] ModuleName : \SystemRoot\System32\smss.exe Command Line : n/a ProcessID : 616 ThreadCreationTime : 4-21-2005 7:41:27 PM BasePriority : Normal #:2 [csrss.exe] ModuleName : \??\C:\WINDOWS\system32\csrss.exe Command Line : C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestTh ProcessID : 664 ThreadCreationTime : 4-21-2005 7:41:28 PM BasePriority : Normal #:3 [winlogon.exe] ModuleName : \??\C:\WINDOWS\system32\winlogon.exe Command Line : winlogon.exe ProcessID : 688 ThreadCreationTime : 4-21-2005 7:41:28 PM BasePriority : High #:4 [services.exe] ModuleName : C:\WINDOWS\system32\services.exe Command Line : C:\WINDOWS\system32\services.exe ProcessID : 732 ThreadCreationTime : 4-21-2005 7:41:29 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : services.exe #:5 [lsass.exe] ModuleName : C:\WINDOWS\system32\lsass.exe Command Line : C:\WINDOWS\system32\lsass.exe ProcessID : 744 ThreadCreationTime : 4-21-2005 7:41:29 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:6 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost -k DcomLaunch ProcessID : 924 ThreadCreationTime : 4-21-2005 7:41:31 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:7 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost -k rpcss ProcessID : 1000 ThreadCreationTime : 4-21-2005 7:41:31 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [svchost.exe] ModuleName : C:\WINDOWS\System32\svchost.exe Command Line : C:\WINDOWS\System32\svchost.exe -k netsvcs ProcessID : 1096 ThreadCreationTime : 4-21-2005 7:41:31 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:9 [svchost.exe] ModuleName : C:\WINDOWS\System32\svchost.exe Command Line : C:\WINDOWS\System32\svchost.exe -k NetworkService ProcessID : 1196 ThreadCreationTime : 4-21-2005 7:41:32 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:10 [svchost.exe] ModuleName : C:\WINDOWS\System32\svchost.exe Command Line : C:\WINDOWS\System32\svchost.exe -k LocalService ProcessID : 1300 ThreadCreationTime : 4-21-2005 7:41:32 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:11 [lexbces.exe] ModuleName : C:\WINDOWS\system32\LEXBCES.EXE Command Line : C:\WINDOWS\system32\LEXBCES.EXE ProcessID : 1444 ThreadCreationTime : 4-21-2005 7:41:34 PM BasePriority : Normal FileVersion : 9.45 ProductVersion : 9.45 ProductName : MarkVision for Windows (32 bit) CompanyName : Lexmark International, Inc. FileDescription : LexBce Service InternalName : LexBce Service LegalCopyright : © 1993 - 2004 Lexmark International, Inc. OriginalFilename : LexBceS.exe #:12 [lexpps.exe] ModuleName : C:\WINDOWS\system32\LEXPPS.EXE Command Line : LEXPPS.EXE ProcessID : 1480 ThreadCreationTime : 4-21-2005 7:41:34 PM BasePriority : Normal FileVersion : 9.45 ProductVersion : 9.45 ProductName : MarkVision for Windows (32 bit) CompanyName : Lexmark International, Inc. FileDescription : LEXPPS.EXE InternalName : LEXPPS LegalCopyright : © 1993 - 2004 Lexmark International, Inc. OriginalFilename : LEXPPS.EXE Comments : MarkVision for Windows '95 New P2P Server (32-bit) #:13 [spoolsv.exe] ModuleName : C:\WINDOWS\system32\spoolsv.exe Command Line : C:\WINDOWS\system32\spoolsv.exe ProcessID : 1488 ThreadCreationTime : 4-21-2005 7:41:34 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : spoolsv.exe #:14 [ccproxy.exe] ModuleName : C:\Program Files\Common Files\Symantec Shared\ccProxy.exe Command Line : "C:\Program Files\Common Files\Symantec Shared\ccProxy.exe" ProcessID : 164 ThreadCreationTime : 4-21-2005 7:41:39 PM BasePriority : Normal FileVersion : 2.1.2.800 ProductVersion : 2.1.2.800 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client Network Proxy Service InternalName : ccProxy LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccProxy.exe #:15 [ccsetmgr.exe] ModuleName : C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe Command Line : "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" ProcessID : 196 ThreadCreationTime : 4-21-2005 7:41:39 PM BasePriority : Normal FileVersion : 2.1.0.610 ProductVersion : 2.1.0.610 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client Settings Manager Service InternalName : ccSetMgr LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccSetMgr.exe #:16 [navapsvc.exe] ModuleName : C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe Command Line : "C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe" ProcessID : 240 ThreadCreationTime : 4-21-2005 7:41:39 PM BasePriority : Normal FileVersion : 10.00.13 ProductVersion : 10.00.13 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Auto-Protect Service InternalName : NAVAPSVC LegalCopyright : Norton AntiVirus 2004 for Windows 98/ME/2000/XP Copyright © 2003 Symantec Corporation. All rights reserved. OriginalFilename : NAVAPSVC.EXE #:17 [sndsrvc.exe] ModuleName : C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe Command Line : "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe" ProcessID : 600 ThreadCreationTime : 4-21-2005 7:41:39 PM BasePriority : Normal FileVersion : 5.3.2.67 ProductVersion : 5.3 ProductName : Symantec Security Drivers CompanyName : Symantec Corporation FileDescription : Network Driver Service InternalName : SndSrvc LegalCopyright : Copyright 2002, 2003 Symantec Corporation OriginalFilename : SndSrvc.exe #:18 [svchost.exe] ModuleName : C:\WINDOWS\System32\svchost.exe Command Line : C:\WINDOWS\System32\svchost.exe -k imgsvc ProcessID : 660 ThreadCreationTime : 4-21-2005 7:41:40 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:19 [ccevtmgr.exe] ModuleName : C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe Command Line : "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" ProcessID : 948 ThreadCreationTime : 4-21-2005 7:41:40 PM BasePriority : Normal FileVersion : 2.1.0.610 ProductVersion : 2.1.0.610 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client Event Manager Service InternalName : ccEvtMgr LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccEvtMgr.exe #:20 [explorer.exe] ModuleName : C:\WINDOWS\Explorer.exe Command Line : Explorer.exe C:\WINDOWS\Nail.exe ProcessID : 1904 ThreadCreationTime : 4-21-2005 7:41:45 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE #:21 [hkcmd.exe] ModuleName : C:\WINDOWS\System32\hkcmd.exe Command Line : "C:\WINDOWS\System32\hkcmd.exe" ProcessID : 1996 ThreadCreationTime : 4-21-2005 7:41:48 PM BasePriority : Normal FileVersion : 3.0.0.3762 ProductVersion : 7.0.0.3762 ProductName : Intel® Common User Interface CompanyName : Intel Corporation FileDescription : hkcmd Module InternalName : HKCMD LegalCopyright : Copyright 1999-2002, Intel Corporation OriginalFilename : HKCMD.EXE #:22 [jusched.exe] ModuleName : C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe Command Line : "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" ProcessID : 2012 ThreadCreationTime : 4-21-2005 7:41:49 PM BasePriority : Normal #:23 [intelmem.exe] ModuleName : C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe Command Line : "C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" ProcessID : 2020 ThreadCreationTime : 4-21-2005 7:41:49 PM BasePriority : Normal FileVersion : 0, 1, 0, 10 ProductVersion : 0, 1, 0, 10 ProductName : Intel Modem Event Monitor Application CompanyName : Intel Corporation FileDescription : Modem Event Monitor Application InternalName : Modem Event Monitor LegalCopyright : Copyright © 2003 OriginalFilename : IntelMEM.exe #:24 [pcmservice.exe] ModuleName : C:\Program Files\Dell\Media Experience\PCMService.exe Command Line : "C:\Program Files\Dell\Media Experience\PCMService.exe" ProcessID : 2028 ThreadCreationTime : 4-21-2005 7:41:49 PM BasePriority : Normal FileVersion : 1.0.1611 ProductVersion : 1.0.1611 ProductName : PCM2Launcher Application CompanyName : CyberLink Corp. FileDescription : PowerCinema Resident Program for Dell InternalName : PowerCinema Resident Program for Dell LegalCopyright : Copyright c 2003 CyberLink Corp. OriginalFilename : PCM2Launcher.EXE #:25 [tfswctrl.exe] ModuleName : C:\WINDOWS\system32\dla\tfswctrl.exe Command Line : "C:\WINDOWS\system32\dla\tfswctrl.exe" ProcessID : 2036 ThreadCreationTime : 4-21-2005 7:41:49 PM BasePriority : Normal FileVersion : 1.04.07b CompanyName : Sonic Solutions FileDescription : Drive Letter Access Component LegalCopyright : Copyright © 2004 Sonic Solutions #:26 [ccapp.exe] ModuleName : C:\Program Files\Common Files\Symantec Shared\ccApp.exe Command Line : "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" ProcessID : 2060 ThreadCreationTime : 4-21-2005 7:41:49 PM BasePriority : Normal FileVersion : 2.1.0.610 ProductVersion : 2.1.0.610 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client User Session InternalName : ccApp LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccApp.exe #:27 [support.exe] ModuleName : C:\Program Files\Common Files\Dell\EUSW\Support.exe Command Line : "C:\Program Files\Common Files\Dell\EUSW\Support.exe" ProcessID : 2084 ThreadCreationTime : 4-21-2005 7:41:49 PM BasePriority : Normal FileVersion : 2, 1, 1, 0 ProductVersion : 1, 0, 0, 1 ProductName : Dell Support CompanyName : Dell FileDescription : Support InternalName : Support LegalCopyright : Copyright © 2002 OriginalFilename : Support.exe #:28 [viewmgr.exe] ModuleName : C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe Command Line : "C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" ProcessID : 2100 ThreadCreationTime : 4-21-2005 7:41:49 PM BasePriority : Normal FileVersion : 2, 0, 0, 42 ProductVersion : 2, 0, 0, 42 ProductName : Viewpoint Manager CompanyName : Viewpoint Corporation FileDescription : ViewMgr InternalName : Viewpoint Manager LegalCopyright : Copyright © 2004 OriginalFilename : ViewMgr.exe Comments : Viewpoint Manager #:29 [qttask.exe] ModuleName : C:\Program Files\QuickTime\qttask.exe Command Line : "C:\Program Files\QuickTime\qttask.exe" -atboottime ProcessID : 2112 ThreadCreationTime : 4-21-2005 7:41:49 PM BasePriority : Normal FileVersion : 6.5.1 ProductVersion : QuickTime 6.5.1 ProductName : QuickTime CompanyName : Apple Computer, Inc. InternalName : QuickTime Task LegalCopyright : © Apple Computer, Inc. 2001-2004 OriginalFilename : QTTask.exe #:30 [notifyalert.exe] ModuleName : c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe Command Line : "c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe" timer ProcessID : 2300 ThreadCreationTime : 4-21-2005 7:41:52 PM BasePriority : Normal #:31 [gcasserv.exe] ModuleName : C:\Program Files\Microsoft AntiSpyware\gcasServ.exe Command Line : "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" ProcessID : 2308 ThreadCreationTime : 4-21-2005 7:41:52 PM BasePriority : Idle FileVersion : 1.00.0509 ProductVersion : 1.00.0509 ProductName : Microsoft AntiSpyware (Beta 1) CompanyName : Microsoft Corporation FileDescription : Microsoft AntiSpyware Service InternalName : gcasServ LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved. LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet is a trademark of Microsoft Corporation. OriginalFilename : gcasServ.exe #:32 [alg.exe] ModuleName : C:\WINDOWS\System32\alg.exe Command Line : C:\WINDOWS\System32\alg.exe ProcessID : 2504 ThreadCreationTime : 4-21-2005 7:41:56 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Application Layer Gateway Service InternalName : ALG.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ALG.exe #:33 [gcasdtserv.exe] ModuleName : C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe Command Line : "C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe" ProcessID : 3048 ThreadCreationTime : 4-21-2005 7:42:02 PM BasePriority : Normal FileVersion : 1.00.0509 ProductVersion : 1.00.0509 ProductName : Microsoft AntiSpyware (Beta 1) CompanyName : Microsoft Corporation FileDescription : Microsoft AntiSpyware Data Service InternalName : gcasDtServ LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved. LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet is a trademark of Microsoft Corporation. OriginalFilename : gcasDtServ.exe #:34 [iexplore.exe] ModuleName : C:\Program Files\Internet Explorer\iexplore.exe Command Line : "C:\Program Files\Internet Explorer\iexplore.exe" ProcessID : 1320 ThreadCreationTime : 4-21-2005 7:43:04 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE #:35 [aim.exe] ModuleName : C:\Program Files\AIM\aim.exe Command Line : "C:\Program Files\AIM\aim.exe" ProcessID : 3292 ThreadCreationTime : 4-21-2005 7:43:58 PM BasePriority : Normal FileVersion : 5.5.3598 ProductVersion : 5.5.3598 ProductName : AOL Instant Messenger CompanyName : America Online, Inc. FileDescription : AOL Instant Messenger InternalName : AIM LegalCopyright : Copyright © 1996-2004 America Online, Inc. OriginalFilename : AIM.EXE #:36 [notepad.exe] ModuleName : C:\WINDOWS\system32\NOTEPAD.EXE Command Line : "C:\WINDOWS\system32\NOTEPAD.EXE" C:\Documents and Settings\Kristina Bain\Local Settings\Temporary Internet Files\Content.IE5\GTWNWRGB\hijackthis.log ProcessID : 2684 ThreadCreationTime : 4-21-2005 7:57:10 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Notepad InternalName : Notepad LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : NOTEPAD.EXE #:37 [ad-aware.exe] ModuleName : C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe Command Line : "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" ProcessID : 2204 ThreadCreationTime : 4-21-2005 8:02:04 PM BasePriority : Normal FileVersion : 6.2.0.206 ProductVersion : VI.Second Edition ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Windows Object Recognized! Type : RegData Data : explorer.exe c:\windows\nail.exe Category : Vulnerability Comment : Shell Possibly Compromised Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\windows nt\currentversion\winlogon Value : Shell Data : explorer.exe c:\windows\nail.exe Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 1 Objects found so far: 1 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 1 MRU List Object Recognized! Location: : C:\Documents and Settings\Kristina Bain\recent Description : list of recently opened documents MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\windows\currentversion\applets\wordpad\recent file list Description : list of recent files opened using wordpad MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\windows\currentversion\explorer\runmru Description : mru list for items opened in start | run MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\search assistant\acmru Description : list of recent search terms used with the search assistant MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru Description : list of recently saved files, stored according to file extension MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru Description : list of recent programs opened MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\windows\currentversion\explorer\recentdocs Description : list of recent documents opened MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\internet explorer\main Description : last save directory used in microsoft internet explorer MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\corel\user assistant\12\recent work\wordperfect\last opened Description : list of recently opened documents in corel wordperfect MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\internet explorer Description : last download directory used in microsoft internet explorer MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\corel\user assistant\12\recent work\wordperfect\last opened Description : list of recently opened documents in corel wordperfect MRU List Object Recognized! Location: : software\microsoft\directdraw\mostrecentapplication Description : most recent application to use microsoft directdraw MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\microsoft management console\recent file list Description : list of recent snap-ins used in the microsoft management console MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\internet explorer\typedurls Description : list of recently entered addresses in microsoft internet explorer MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\jasc\paint shop pro 7\recent file list Description : list of recently used files in jasc paint shop pro MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\directinput\mostrecentapplication Description : most recent application to use microsoft directinput MRU List Object Recognized! Location: : software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct3d MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\jasc\paint shop pro 7\general Description : last save as directory used in jasc paint shop pro MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\mediaplayer\preferences Description : last playlist index loaded in microsoft windows media player MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\windows\currentversion\applets\regedit Description : last key accessed using the microsoft registry editor MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\directinput\mostrecentapplication Description : most recent application to use microsoft directinput MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\mediaplayer\preferences Description : last playlist loaded in microsoft windows media player MRU List Object Recognized! Location: : software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct X MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general Description : windows media sdk MRU List Object Recognized! Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general Description : windows media sdk MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\windows media\wmsdk\general Description : windows media sdk Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie Object Recognized! Type : IECache Entry Data : kristina bain@atdmt[1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:kristina bain@atdmt.com/ Expires : 4-19-2010 7:00:00 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : kristina bain@tribalfusion[1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:kristina bain@tribalfusion.com/ Expires : 12-31-2037 7:00:00 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : kristina bain@servedby.advertising[2].txt Category : Data Miner Comment : Hits:5 Value : Cookie:kristina bain@servedby.advertising.com/ Expires : 5-21-2005 2:44:14 PM LastSync : Hits:5 UseCount : 0 Hits : 5 Tracking Cookie Object Recognized! Type : IECache Entry Data : kristina bain@2o7[2].txt Category : Data Miner Comment : Hits:2 Value : Cookie:kristina bain@2o7.net/ Expires : 4-20-2010 2:15:04 PM LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking Cookie Object Recognized! Type : IECache Entry Data : kristina bain@edge.ru4[2].txt Category : Data Miner Comment : Hits:2 Value : Cookie:kristina bain@edge.ru4.com/ Expires : 4-14-2035 12:27:58 AM LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking Cookie Object Recognized! Type : IECache Entry Data : kristina bain@trafficmp[1].txt Category : Data Miner Comment : Hits:5 Value : Cookie:kristina bain@trafficmp.com/ Expires : 4-21-2006 12:40:46 AM LastSync : Hits:5 UseCount : 0 Hits : 5 Tracking Cookie Object Recognized! Type : IECache Entry Data : kristina bain@advertising[1].txt Category : Data Miner Comment : Hits:6 Value : Cookie:kristina bain@advertising.com/ Expires : 4-20-2010 2:39:12 PM LastSync : Hits:6 UseCount : 0 Hits : 6 Tracking Cookie Object Recognized! Type : IECache Entry Data : kristina bain@247realmedia[1].txt Category : Data Miner Comment : Hits:2 Value : Cookie:kristina bain@247realmedia.com/ Expires : 12-31-2010 7:00:00 PM LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 8 Objects found so far: 35 Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Object "asm.exe" found in this archive. AltnetBDE Object Recognized! Type : File Data : asmfiles.cab Category : Data Miner Comment : Object "asm.exe" found in this archive. Object : C:\Documents and Settings\Kristina Bain\Local Settings\Temp\ Object "asmps.dll" found in this archive. AltnetBDE Object Recognized! Type : File Data : asmfiles.cab Category : Data Miner Comment : Object "asmps.dll" found in this archive. Object : C:\Documents and Settings\Kristina Bain\Local Settings\Temp\ AltnetBDE Object Recognized! Type : File Data : A0024344.exe Category : Data Miner Comment : Object : C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP165\ FileVersion : 1, 0, 0, 55 ProductVersion : 1, 0, 0, 0 ProductName : Altnet Sharing Manager FileDescription : Altnet Sharing Manager InternalName : ASM LegalCopyright : Copyright 2003 OriginalFilename : ASM.EXE AltnetBDE Object Recognized! Type : File Data : A0024345.dll Category : Data Miner Comment : Object : C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP165\ FileVersion : 1, 0, 0, 5 ProductVersion : 1, 0, 0, 0 InternalName : ASMPS LegalCopyright : Copyright 2003 OriginalFilename : ASMPS.DLL Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 39 Scanning Hosts file...... Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 1 entries scanned. New critical objects:0 Objects found so far: 39 Performing conditional scans... »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 39 3:28:04 PM Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:18:13.359 Objects scanned:135058 Objects identified:13 Objects ignored:0 New critical objects:13 |
|
|
Apr 21 2005, 03:44 PM
Post
#2
|
|
![]() Member ![]() ![]() ![]() Posts: 135 OS: XP Home |
saturn,
Now some of the items displayed in your log are all in the restore folder. XP has the capability called System Restore. My advice is to empty the system restore folder and the create a new restore point. To do this Click Start, and then right-click My Computer. Click Properties. Click the System Restore tab. Check Turn off System Restore. Click Apply, and then click OK. Restart the computer. All data, including the items and registry entries will be removed from the restore folder. After restarting the computer, "Re-enable System Restore" before going any further you need now to create a fresh restore point please can you clear out your cache folder ie: temporary internet folder There are some free programs that you can use that will do that for you if needed like CCleaner also please can you make sure that you still have “Ticks by these : "Unload recognized processes during scanning", "Let Windows remove files in use after reboot." to do this Open Ad-aware SE Click “settings” (the Gear) then Click “Tweaks“, then click “Scanning Engine” Tick ."Unload recognized processes during scanning" Then Click “Cleaning Engine” And Tick "Let Windows remove files in use after reboot." then Click “proceed”. now use the WebUpDate (to make sure you are upto date) if you want to clean your PC then scan by doing a "Full Scan" then and once the scan has finished mark and remove the items then Reboot (ie: Re-start your PC) Then re-scan doing a "Full Scan" and then post your logfile here by using the Add-Reply Feature . Please NOTE from the AAW SE help file, if you set "Read current settings from system:" under "default settings" in Ad-Aware SE, QUOTE Default IE Pages Default homepage: Ad-Aware SE uses the defined homepage when recovering from a browser hijack Default Search Engine: Ad-Aware SE uses the defined search engine when recovering from a browser hijack GR@PH;<'S |
|
|
Apr 24 2005, 05:18 PM
Post
#3
|
|
|
New Member ![]() Posts: 2 OS: windows xp |
I did all of the following you posted above. Here's my Ad-Aware Log File.
d-Aware SE Build 1.05 Logfile Created on:Sunday, April 24, 2005 5:55:54 PM Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R40 20.04.2005 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» MRU List(TAC index:0):8 total references Windows(TAC index:3):1 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Definition File: ========================= Definitions File Loaded: Reference Number : SE1R40 20.04.2005 Internal build : 47 File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref File size : 461235 Bytes Total size : 1395231 Bytes Signature data size : 1364710 Bytes Reference data size : 30009 Bytes Signatures total : 38921 Fingerprints total : 813 Fingerprints size : 29073 Bytes Target categories : 15 Target families : 650 Memory + processor status: ========================== Number of processors : 1 Processor architecture : Intel Pentium IV Memory available:10 % Total physical memory:260096 kb Available physical memory:25620 kb Total page file size:637032 kb Available on page file:413240 kb Total virtual memory:2097024 kb Available virtual memory:2047924 kb OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600) Ad-Aware SE Settings =========================== Set : Search for negligible risk entries Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan within archives Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Obtain command line of scanned processes Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Write-protect system files after repair (Hosts file, etc.) Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects 4-24-2005 5:55:54 PM - Scan started. (Full System Scan) MRU List Object Recognized! Location: : C:\Documents and Settings\Kristina Bain\recent Description : list of recently opened documents MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\corel\user assistant\12\recent work\wordperfect\last opened Description : list of recently opened documents in corel wordperfect MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\corel\user assistant\12\recent work\wordperfect\last opened Description : list of recently opened documents in corel wordperfect MRU List Object Recognized! Location: : software\microsoft\directdraw\mostrecentapplication Description : most recent application to use microsoft directdraw MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\internet explorer\typedurls Description : list of recently entered addresses in microsoft internet explorer MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general Description : windows media sdk MRU List Object Recognized! Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general Description : windows media sdk MRU List Object Recognized! Location: : S-1-5-21-231337324-1321008711-4134764321-1007\software\microsoft\windows media\wmsdk\general Description : windows media sdk Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] ModuleName : \SystemRoot\System32\smss.exe Command Line : n/a ProcessID : 620 ThreadCreationTime : 4-24-2005 10:53:39 PM BasePriority : Normal #:2 [csrss.exe] ModuleName : \??\C:\WINDOWS\system32\csrss.exe Command Line : C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestTh ProcessID : 668 ThreadCreationTime : 4-24-2005 10:53:41 PM BasePriority : Normal #:3 [winlogon.exe] ModuleName : \??\C:\WINDOWS\system32\winlogon.exe Command Line : winlogon.exe ProcessID : 692 ThreadCreationTime : 4-24-2005 10:53:41 PM BasePriority : High #:4 [services.exe] ModuleName : C:\WINDOWS\system32\services.exe Command Line : C:\WINDOWS\system32\services.exe ProcessID : 736 ThreadCreationTime : 4-24-2005 10:53:42 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : services.exe #:5 [lsass.exe] ModuleName : C:\WINDOWS\system32\lsass.exe Command Line : C:\WINDOWS\system32\lsass.exe ProcessID : 748 ThreadCreationTime : 4-24-2005 10:53:42 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:6 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost -k DcomLaunch ProcessID : 928 ThreadCreationTime : 4-24-2005 10:53:43 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:7 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost -k rpcss ProcessID : 992 ThreadCreationTime : 4-24-2005 10:53:43 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [svchost.exe] ModuleName : C:\WINDOWS\System32\svchost.exe Command Line : C:\WINDOWS\System32\svchost.exe -k netsvcs ProcessID : 1088 ThreadCreationTime : 4-24-2005 10:53:44 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:9 [svchost.exe] ModuleName : C:\WINDOWS\System32\svchost.exe Command Line : C:\WINDOWS\System32\svchost.exe -k NetworkService ProcessID : 1180 ThreadCreationTime : 4-24-2005 10:53:44 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:10 [svchost.exe] ModuleName : C:\WINDOWS\System32\svchost.exe Command Line : C:\WINDOWS\System32\svchost.exe -k LocalService ProcessID : 1280 ThreadCreationTime : 4-24-2005 10:53:45 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:11 [lexbces.exe] ModuleName : C:\WINDOWS\system32\LEXBCES.EXE Command Line : C:\WINDOWS\system32\LEXBCES.EXE ProcessID : 1428 ThreadCreationTime : 4-24-2005 10:53:46 PM BasePriority : Normal FileVersion : 9.45 ProductVersion : 9.45 ProductName : MarkVision for Windows (32 bit) CompanyName : Lexmark International, Inc. FileDescription : LexBce Service InternalName : LexBce Service LegalCopyright : © 1993 - 2004 Lexmark International, Inc. OriginalFilename : LexBceS.exe #:12 [lexpps.exe] ModuleName : C:\WINDOWS\system32\LEXPPS.EXE Command Line : LEXPPS.EXE ProcessID : 1472 ThreadCreationTime : 4-24-2005 10:53:46 PM BasePriority : Normal FileVersion : 9.45 ProductVersion : 9.45 ProductName : MarkVision for Windows (32 bit) CompanyName : Lexmark International, Inc. FileDescription : LEXPPS.EXE InternalName : LEXPPS LegalCopyright : © 1993 - 2004 Lexmark International, Inc. OriginalFilename : LEXPPS.EXE Comments : MarkVision for Windows '95 New P2P Server (32-bit) #:13 [spoolsv.exe] ModuleName : C:\WINDOWS\system32\spoolsv.exe Command Line : C:\WINDOWS\system32\spoolsv.exe ProcessID : 1480 ThreadCreationTime : 4-24-2005 10:53:46 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : spoolsv.exe #:14 [ccproxy.exe] ModuleName : C:\Program Files\Common Files\Symantec Shared\ccProxy.exe Command Line : "C:\Program Files\Common Files\Symantec Shared\ccProxy.exe" ProcessID : 188 ThreadCreationTime : 4-24-2005 10:53:52 PM BasePriority : Normal FileVersion : 2.1.2.800 ProductVersion : 2.1.2.800 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client Network Proxy Service InternalName : ccProxy LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccProxy.exe #:15 [ccsetmgr.exe] ModuleName : C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe Command Line : "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" ProcessID : 368 ThreadCreationTime : 4-24-2005 10:53:53 PM BasePriority : Normal FileVersion : 2.1.0.610 ProductVersion : 2.1.0.610 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client Settings Manager Service InternalName : ccSetMgr LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccSetMgr.exe #:16 [navapsvc.exe] ModuleName : C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe Command Line : "C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe" ProcessID : 544 ThreadCreationTime : 4-24-2005 10:53:54 PM BasePriority : Normal FileVersion : 10.00.13 ProductVersion : 10.00.13 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Auto-Protect Service InternalName : NAVAPSVC LegalCopyright : Norton AntiVirus 2004 for Windows 98/ME/2000/XP Copyright © 2003 Symantec Corporation. All rights reserved. OriginalFilename : NAVAPSVC.EXE #:17 [explorer.exe] ModuleName : C:\WINDOWS\Explorer.exe Command Line : Explorer.exe C:\WINDOWS\Nail.exe ProcessID : 604 ThreadCreationTime : 4-24-2005 10:53:54 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE #:18 [sndsrvc.exe] ModuleName : C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe Command Line : "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe" ProcessID : 1176 ThreadCreationTime : 4-24-2005 10:53:55 PM BasePriority : Normal FileVersion : 5.3.2.67 ProductVersion : 5.3 ProductName : Symantec Security Drivers CompanyName : Symantec Corporation FileDescription : Network Driver Service InternalName : SndSrvc LegalCopyright : Copyright 2002, 2003 Symantec Corporation OriginalFilename : SndSrvc.exe #:19 [svchost.exe] ModuleName : C:\WINDOWS\System32\svchost.exe Command Line : C:\WINDOWS\System32\svchost.exe -k imgsvc ProcessID : 1388 ThreadCreationTime : 4-24-2005 10:53:56 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:20 [ccevtmgr.exe] ModuleName : C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe Command Line : "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" ProcessID : 1608 ThreadCreationTime : 4-24-2005 10:53:56 PM BasePriority : Normal FileVersion : 2.1.0.610 ProductVersion : 2.1.0.610 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client Event Manager Service InternalName : ccEvtMgr LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccEvtMgr.exe #:21 [hkcmd.exe] ModuleName : C:\WINDOWS\System32\hkcmd.exe Command Line : "C:\WINDOWS\System32\hkcmd.exe" ProcessID : 1728 ThreadCreationTime : 4-24-2005 10:53:57 PM BasePriority : Normal FileVersion : 3.0.0.3762 ProductVersion : 7.0.0.3762 ProductName : Intel® Common User Interface CompanyName : Intel Corporation FileDescription : hkcmd Module InternalName : HKCMD LegalCopyright : Copyright 1999-2002, Intel Corporation OriginalFilename : HKCMD.EXE #:22 [jusched.exe] ModuleName : C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe Command Line : "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" ProcessID : 1752 ThreadCreationTime : 4-24-2005 10:53:57 PM BasePriority : Normal #:23 [intelmem.exe] ModuleName : C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe Command Line : "C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" ProcessID : 1780 ThreadCreationTime : 4-24-2005 10:53:58 PM BasePriority : Normal FileVersion : 0, 1, 0, 10 ProductVersion : 0, 1, 0, 10 ProductName : Intel Modem Event Monitor Application CompanyName : Intel Corporation FileDescription : Modem Event Monitor Application InternalName : Modem Event Monitor LegalCopyright : Copyright © 2003 OriginalFilename : IntelMEM.exe #:24 [pcmservice.exe] ModuleName : C:\Program Files\Dell\Media Experience\PCMService.exe Command Line : "C:\Program Files\Dell\Media Experience\PCMService.exe" ProcessID : 1796 ThreadCreationTime : 4-24-2005 10:53:58 PM BasePriority : Normal FileVersion : 1.0.1611 ProductVersion : 1.0.1611 ProductName : PCM2Launcher Application CompanyName : CyberLink Corp. FileDescription : PowerCinema Resident Program for Dell InternalName : PowerCinema Resident Program for Dell LegalCopyright : Copyright c 2003 CyberLink Corp. OriginalFilename : PCM2Launcher.EXE #:25 [tfswctrl.exe] ModuleName : C:\WINDOWS\system32\dla\tfswctrl.exe Command Line : "C:\WINDOWS\system32\dla\tfswctrl.exe" ProcessID : 1804 ThreadCreationTime : 4-24-2005 10:53:58 PM BasePriority : Normal FileVersion : 1.04.07b CompanyName : Sonic Solutions FileDescription : Drive Letter Access Component LegalCopyright : Copyright © 2004 Sonic Solutions #:26 [sgtray.exe] ModuleName : C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe Command Line : "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r ProcessID : 1816 ThreadCreationTime : 4-24-2005 10:53:58 PM BasePriority : Normal FileVersion : 1.01.32a CompanyName : Sonic Solutions FileDescription : Sonic Update Manager LegalCopyright : Copyright © 2002 Sonic Solutions #:27 [ccapp.exe] ModuleName : C:\Program Files\Common Files\Symantec Shared\ccApp.exe Command Line : "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" ProcessID : 1832 ThreadCreationTime : 4-24-2005 10:53:58 PM BasePriority : Normal FileVersion : 2.1.0.610 ProductVersion : 2.1.0.610 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client User Session InternalName : ccApp LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccApp.exe #:28 [wuauclt.exe] ModuleName : C:\WINDOWS\system32\wuauclt.exe Command Line : "C:\WINDOWS\system32\wuauclt.exe" /RunStoreAsComServer Local\[440]SUSDSba0fc02cb5151e409fba918319b18047 ProcessID : 1840 ThreadCreationTime : 4-24-2005 10:53:58 PM BasePriority : Normal FileVersion : 5.4.3790.2182 built by: srv03_rtm(ntvbl04) ProductVersion : 5.4.3790.2182 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Automatic Updates InternalName : wuauclt.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : wuauclt.exe #:29 [support.exe] ModuleName : C:\Program Files\Common Files\Dell\EUSW\Support.exe Command Line : "C:\Program Files\Common Files\Dell\EUSW\Support.exe" ProcessID : 1856 ThreadCreationTime : 4-24-2005 10:53:59 PM BasePriority : Normal FileVersion : 2, 1, 1, 0 ProductVersion : 1, 0, 0, 1 ProductName : Dell Support CompanyName : Dell FileDescription : Support InternalName : Support LegalCopyright : Copyright © 2002 OriginalFilename : Support.exe #:30 [viewmgr.exe] ModuleName : C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe Command Line : "C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" ProcessID : 1904 ThreadCreationTime : 4-24-2005 10:53:59 PM BasePriority : Normal FileVersion : 2, 0, 0, 42 ProductVersion : 2, 0, 0, 42 ProductName : Viewpoint Manager CompanyName : Viewpoint Corporation FileDescription : ViewMgr InternalName : Viewpoint Manager LegalCopyright : Copyright © 2004 OriginalFilename : ViewMgr.exe Comments : Viewpoint Manager #:31 [qttask.exe] ModuleName : C:\Program Files\QuickTime\qttask.exe Command Line : "C:\Program Files\QuickTime\qttask.exe" -atboottime ProcessID : 1912 ThreadCreationTime : 4-24-2005 10:53:59 PM BasePriority : Normal FileVersion : 6.5.1 ProductVersion : QuickTime 6.5.1 ProductName : QuickTime CompanyName : Apple Computer, Inc. InternalName : QuickTime Task LegalCopyright : © Apple Computer, Inc. 2001-2004 OriginalFilename : QTTask.exe #:32 [gcasserv.exe] ModuleName : C:\Program Files\Microsoft AntiSpyware\gcasServ.exe Command Line : "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" ProcessID : 1920 ThreadCreationTime : 4-24-2005 10:53:59 PM BasePriority : Idle FileVersion : 1.00.0509 ProductVersion : 1.00.0509 ProductName : Microsoft AntiSpyware (Beta 1) CompanyName : Microsoft Corporation FileDescription : Microsoft AntiSpyware Service InternalName : gcasServ LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved. LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet is a trademark of Microsoft Corporation. OriginalFilename : gcasServ.exe #:33 [notifyalert.exe] ModuleName : c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe Command Line : "c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe" timer ProcessID : 308 ThreadCreationTime : 4-24-2005 10:54:02 PM BasePriority : Normal #:34 [gcasdtserv.exe] ModuleName : C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe Command Line : "C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe" ProcessID : 1656 ThreadCreationTime : 4-24-2005 10:54:08 PM BasePriority : Normal FileVersion : 1.00.0509 ProductVersion : 1.00.0509 ProductName : Microsoft AntiSpyware (Beta 1) CompanyName : Microsoft Corporation FileDescription : Microsoft AntiSpyware Data Service InternalName : gcasDtServ LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved. LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet is a trademark of Microsoft Corporation. OriginalFilename : gcasDtServ.exe #:35 [alg.exe] ModuleName : C:\WINDOWS\System32\alg.exe Command Line : C:\WINDOWS\System32\alg.exe ProcessID : 3092 ThreadCreationTime : 4-24-2005 10:54:37 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Application Layer Gateway Service InternalName : ALG.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ALG.exe #:36 [msmsgs.exe] ModuleName : C:\Program Files\Messenger\msmsgs.exe Command Line : "C:\Program Files\Messenger\msmsgs.exe" -Embedding ProcessID : 3208 ThreadCreationTime : 4-24-2005 10:54:40 PM BasePriority : Normal FileVersion : 4.7.3001 ProductVersion : Version 4.7.3001 ProductName : Messenger CompanyName : Microsoft Corporation FileDescription : Windows Messenger InternalName : msmsgs LegalCopyright : Copyright © Microsoft Corporation 2004 LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries. OriginalFilename : msmsgs.exe #:37 [wmiprvse.exe] ModuleName : C:\WINDOWS\System32\wbem\wmiprvse.exe Command Line : C:\WINDOWS\System32\wbem\wmiprvse.exe -Embedding ProcessID : 3636 ThreadCreationTime : 4-24-2005 10:54:50 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : WMI InternalName : Wmiprvse.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : Wmiprvse.exe #:38 [ad-aware.exe] ModuleName : C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe Command Line : "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" ProcessID : 2068 ThreadCreationTime : 4-24-2005 10:55:33 PM BasePriority : Normal FileVersion : 6.2.0.206 ProductVersion : VI.Second Edition ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 8 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Windows Object Recognized! Type : RegData Data : explorer.exe c:\windows\nail.exe Category : Vulnerability Comment : Shell Possibly Compromised Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\windows nt\currentversion\winlogon Value : Shell Data : explorer.exe c:\windows\nail.exe Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 1 Objects found so far: 9 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 9 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 9 Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 9 Scanning Hosts file...... Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 1 entries scanned. New critical objects:0 Objects found so far: 9 Performing conditional scans... »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 9 6:09:50 PM Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:13:56.734 Objects scanned:127857 Objects identified:1 Objects ignored:0 New critical objects:1 |
|
|
Apr 25 2005, 09:44 AM
Post
#4
|
|
![]() Visiting Staff Posts: 4,746 From: Finland OS: XP Home - SP2 |
Hi. Do this; after performed your "Full system scan", select "Scan summary" - tab, and delete mru item's. That shouldn't be a problem. After this, close your Ad-aware, and try couple of these online scans, here; - F-secure; http://support.f-secure.com/en/home/ols.shtml - Trend micro (recommended); http://fi.trendmicro-europe.com/consumer/p |