Ad-Aware Log File [CLOSED], Request Analysis |
![]() ![]() |
Ad-Aware Log File [CLOSED], Request Analysis |
May 10 2005, 12:37 PM
Post
#1
|
|
|
New Member ![]() Posts: 3 OS: XP |
Ad-Aware SE Build 1.05
Logfile Created on:Tuesday, May 10, 2005 12:18:06 PM Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R44 10.05.2005 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» MRU List(TAC index:0):27 total references Possible Browser Hijack attempt(TAC index:3):2 total references Tracking Cookie(TAC index:3):2 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Definition File: ========================= Definitions File Loaded: Reference Number : SE1R43 06.05.2005 Internal build : 50 File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal \defs.ref File size : 467649 Bytes Total size : 1414672 Bytes Signature data size : 1383852 Bytes Reference data size : 30308 Bytes Signatures total : 39494 Fingerprints total : 847 Fingerprints size : 28739 Bytes Target categories : 15 Target families : 663 5-10-2005 12:08:07 PM Performing WebUpdate... Installing Update... Definitions File Loaded: Reference Number : SE1R44 10.05.2005 Internal build : 52 File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal \defs.ref File size : 470885 Bytes Total size : 1423894 Bytes Signature data size : 1392940 Bytes Reference data size : 30442 Bytes Signatures total : 39753 Fingerprints total : 872 Fingerprints size : 29756 Bytes Target categories : 15 Target families : 668 5-10-2005 12:08:15 PM Success Update successfully downloaded and installed. Memory + processor status: ========================== Number of processors : 1 Processor architecture : Non Intel Memory available:46 % Total physical memory:523496 kb Available physical memory:238416 kb Total page file size:1276972 kb Available on page file:1027096 kb Total virtual memory:2097024 kb Available virtual memory:2043692 kb OS:Microsoft Windows XP Professional Service Pack 2 (Build 2600) Ad-Aware SE Settings =========================== Set : Search for negligible risk entries Set : Move deleted files to Recycle Bin Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan within archives Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Obtain command line of scanned processes Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Write-protect system files after repair (Hosts file, etc.) Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects 5-10-2005 12:18:06 PM - Scan started. (Custom mode) Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] ModuleName : \SystemRoot\System32\smss.exe Command Line : n/a ProcessID : 752 ThreadCreationTime : 5-10-2005 4:23:51 PM BasePriority : Normal #:2 [csrss.exe] ModuleName : \??\C:\WINDOWS\system32\csrss.exe Command Line : C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestTh ProcessID : 824 ThreadCreationTime : 5-10-2005 4:23:53 PM BasePriority : Normal #:3 [winlogon.exe] ModuleName : \??\C:\WINDOWS\system32\winlogon.exe Command Line : winlogon.exe ProcessID : 852 ThreadCreationTime : 5-10-2005 4:23:56 PM BasePriority : High #:4 [services.exe] ModuleName : C:\WINDOWS\system32\services.exe Command Line : C:\WINDOWS\system32\services.exe ProcessID : 896 ThreadCreationTime : 5-10-2005 4:23:56 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : services.exe #:5 [lsass.exe] ModuleName : C:\WINDOWS\system32\lsass.exe Command Line : C:\WINDOWS\system32\lsass.exe ProcessID : 908 ThreadCreationTime : 5-10-2005 4:23:56 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:6 [ati2evxx.exe] ModuleName : C:\WINDOWS\system32\Ati2evxx.exe Command Line : C:\WINDOWS\system32\Ati2evxx.exe ProcessID : 1072 ThreadCreationTime : 5-10-2005 4:23:57 PM BasePriority : Normal #:7 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost -k DcomLaunch ProcessID : 1084 ThreadCreationTime : 5-10-2005 4:23:57 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost -k rpcss ProcessID : 1168 ThreadCreationTime : 5-10-2005 4:23:58 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:9 [svchost.exe] ModuleName : C:\WINDOWS\System32\svchost.exe Command Line : C:\WINDOWS\System32\svchost.exe -k netsvcs ProcessID : 1204 ThreadCreationTime : 5-10-2005 4:23:58 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:10 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost.exe -k NetworkService ProcessID : 1260 ThreadCreationTime : 5-10-2005 4:23:58 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:11 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost.exe -k LocalService ProcessID : 1452 ThreadCreationTime : 5-10-2005 4:23:59 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:12 [ati2evxx.exe] ModuleName : C:\WINDOWS\system32\Ati2evxx.exe Command Line : Ati2evxx.exe -Client ProcessID : 1556 ThreadCreationTime : 5-10-2005 4:23:59 PM BasePriority : Normal #:13 [explorer.exe] ModuleName : C:\WINDOWS\Explorer.EXE Command Line : C:\WINDOWS\Explorer.EXE ProcessID : 1644 ThreadCreationTime : 5-10-2005 4:23:59 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE #:14 [spoolsv.exe] ModuleName : C:\WINDOWS\system32\spoolsv.exe Command Line : C:\WINDOWS\system32\spoolsv.exe ProcessID : 1836 ThreadCreationTime : 5-10-2005 4:24:00 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : spoolsv.exe #:15 [scardsvr.exe] ModuleName : C:\WINDOWS\System32\SCardSvr.exe Command Line : C:\WINDOWS\System32\SCardSvr.exe ProcessID : 1884 ThreadCreationTime : 5-10-2005 4:24:00 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Smart Card Resource Management Server InternalName : SCardSvr.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : SCardSvr.exe #:16 [avgamsvr.exe] ModuleName : C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe Command Line : C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe ProcessID : 1968 ThreadCreationTime : 5-10-2005 4:24:00 PM BasePriority : Normal FileVersion : 7,1,0,307 ProductVersion : 7.1.0.307 ProductName : AVG Anti-Virus System CompanyName : GRISOFT, s.r.o. FileDescription : AVG Alert Manager InternalName : avgamsvr LegalCopyright : Copyright © 2005, GRISOFT, s.r.o. OriginalFilename : avgamsvr.EXE #:17 [avgupsvc.exe] ModuleName : C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe Command Line : C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe ProcessID : 1980 ThreadCreationTime : 5-10-2005 4:24:00 PM BasePriority : Normal FileVersion : 7,1,0,285 ProductVersion : 7.1.0.285 ProductName : AVG 7.0 Anti-Virus System CompanyName : GRISOFT, s.r.o. FileDescription : AVG Update Service InternalName : avgupsvc LegalCopyright : Copyright © 2004, GRISOFT, s.r.o. OriginalFilename : avgupdsvc.EXE #:18 [ctsvccda.exe] ModuleName : C:\WINDOWS\system32\CTSvcCDA.EXE Command Line : C:\WINDOWS\system32\CTSvcCDA.EXE ProcessID : 1992 ThreadCreationTime : 5-10-2005 4:24:00 PM BasePriority : Normal FileVersion : 1.0.1.0 ProductVersion : 1.0.0.0 ProductName : Creative Service for CDROM Access CompanyName : Creative Technology Ltd FileDescription : Creative Service for CDROM Access InternalName : CTsvcCDAEXE LegalCopyright : Copyright © Creative Technology Ltd., 1999. All rights reserved. OriginalFilename : CTsvcCDA.EXE #:19 [mdm.exe] ModuleName : C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE Command Line : "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" ProcessID : 176 ThreadCreationTime : 5-10-2005 4:24:00 PM BasePriority : Normal FileVersion : 7.00.9466 ProductVersion : 7.00.9466 ProductName : Microsoft® Visual Studio .NET CompanyName : Microsoft Corporation FileDescription : Machine Debug Manager InternalName : mdm.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : mdm.exe #:20 [snmp.exe] ModuleName : C:\WINDOWS\System32\snmp.exe Command Line : C:\WINDOWS\System32\snmp.exe ProcessID : 284 ThreadCreationTime : 5-10-2005 4:24:01 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : SNMP Service InternalName : snmp.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : snmp.exe #:21 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost.exe -k imgsvc ProcessID : 372 ThreadCreationTime : 5-10-2005 4:24:01 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:22 [wltrysvc.exe] ModuleName : C:\WINDOWS\System32\WLTRYSVC.EXE Command Line : C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe ProcessID : 464 ThreadCreationTime : 5-10-2005 4:24:01 PM BasePriority : Normal #:23 [mspmspsv.exe] ModuleName : C:\WINDOWS\system32\MsPMSPSv.exe Command Line : C:\WINDOWS\system32\MsPMSPSv.exe ProcessID : 500 ThreadCreationTime : 5-10-2005 4:24:01 PM BasePriority : Normal FileVersion : 7.00.00.1954 ProductVersion : 7.00.00.1954 ProductName : Microsoft ® DRM CompanyName : Microsoft Corporation FileDescription : WMDM PMSP Service InternalName : MSPMSPSV.EXE LegalCopyright : Copyright © Microsoft Corp. 1981-2000 OriginalFilename : MSPMSPSV.EXE #:24 [bcmwltry.exe] ModuleName : C:\WINDOWS\System32\bcmwltry.exe Command Line : C:\WINDOWS\System32\bcmwltry.exe ProcessID : 552 ThreadCreationTime : 5-10-2005 4:24:02 PM BasePriority : Normal FileVersion : 3.40.67.0 ProductVersion : 3.40.67.0 ProductName : Dell Wireless WLAN Card Wireless Network Tray Applet CompanyName : Dell Computer Corporation FileDescription : Dell Wireless WLAN Card Wireless Network Tray Applet InternalName : bcmwltry.exe LegalCopyright : 1998-2003, Dell Computer Corporation All Rights Reserved. OriginalFilename : bcmwltry.exe #:25 [alg.exe] ModuleName : C:\WINDOWS\System32\alg.exe Command Line : C:\WINDOWS\System32\alg.exe ProcessID : 1488 ThreadCreationTime : 5-10-2005 4:24:05 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Application Layer Gateway Service InternalName : ALG.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ALG.exe #:26 [apoint.exe] ModuleName : C:\Program Files\Apoint\Apoint.exe Command Line : "C:\Program Files\Apoint\Apoint.exe" ProcessID : 536 ThreadCreationTime : 5-10-2005 4:24:06 PM BasePriority : Normal FileVersion : 5.5.101.123 ProductVersion : 5.5.101.123 ProductName : Alps Pointing-device Driver CompanyName : Alps Electric Co., Ltd. FileDescription : Alps Pointing-device Driver InternalName : Alps Pointing-device Driver LegalCopyright : Copyright © 1999-2003 Alps Electric Co., Ltd. OriginalFilename : Apoint.exe #:27 [jusched.exe] ModuleName : C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe Command Line : "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" ProcessID : 724 ThreadCreationTime : 5-10-2005 4:24:06 PM BasePriority : Normal #:28 [atiptaxx.exe] ModuleName : C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe Command Line : "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" ProcessID : 792 ThreadCreationTime : 5-10-2005 4:24:06 PM BasePriority : Normal FileVersion : 6.14.10.5113 ProductVersion : 6.14.10.5113 ProductName : ATI Desktop Component CompanyName : ATI Technologies, Inc. FileDescription : ATI Desktop Control Panel InternalName : Atiptaxx.exe LegalCopyright : Copyright © 1998-2004 ATI Technologies Inc. OriginalFilename : Atiptaxx.exe #:29 [tfswctrl.exe] ModuleName : C:\WINDOWS\system32\dla\tfswctrl.exe Command Line : "C:\WINDOWS\system32\dla\tfswctrl.exe" ProcessID : 1236 ThreadCreationTime : 5-10-2005 4:24:06 PM BasePriority : Normal FileVersion : 1.04.07b CompanyName : Sonic Solutions FileDescription : Drive Letter Access Component LegalCopyright : Copyright © 2004 Sonic Solutions #:30 [pcmservice.exe] ModuleName : C:\Program Files\Dell\Media Experience\PCMService.exe Command Line : "C:\Program Files\Dell\Media Experience\PCMService.exe" ProcessID : 1328 ThreadCreationTime : 5-10-2005 4:24:06 PM BasePriority : Normal FileVersion : 1.0.1611 ProductVersion : 1.0.1611 ProductName : PCM2Launcher Application CompanyName : CyberLink Corp. FileDescription : PowerCinema Resident Program for Dell InternalName : PowerCinema Resident Program for Dell LegalCopyright : Copyright c 2003 CyberLink Corp. OriginalFilename : PCM2Launcher.EXE #:31 [dvdlauncher.exe] ModuleName : C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe Command Line : "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" ProcessID : 1316 ThreadCreationTime : 5-10-2005 4:24:06 PM BasePriority : Normal FileVersion : 3.00.0000 ProductVersion : 3.00.0000 ProductName : Cyberlink PowerCinema 3.0 CompanyName : CyberLink Corp. FileDescription : CyberLink PowerCinema Resident Program InternalName : CyberLink PowerCinema Resident Program LegalCopyright : Copyright © 2003 CyberLink Corp. OriginalFilename : DVDLauncher.EXE #:32 [quickset.exe] ModuleName : C:\Program Files\Dell\QuickSet\quickset.exe Command Line : "C:\Program Files\Dell\QuickSet\quickset.exe" ProcessID : 1368 ThreadCreationTime : 5-10-2005 4:24:06 PM BasePriority : Normal FileVersion : 1, 0, 0, 1 ProductVersion : 1, 0, 0, 1 ProductName : QuickSet Application FileDescription : QuickSet MFC Application InternalName : direct LegalCopyright : Copyright © 2001 OriginalFilename : direct.EXE #:33 [support.exe] ModuleName : C:\Program Files\Common Files\Dell\EUSW\Support.exe Command Line : "C:\Program Files\Common Files\Dell\EUSW\Support.exe" ProcessID : 1376 ThreadCreationTime : 5-10-2005 4:24:07 PM BasePriority : Normal FileVersion : 2, 1, 1, 0 ProductVersion : 1, 0, 0, 1 ProductName : Dell Support CompanyName : Dell FileDescription : Support InternalName : Support LegalCopyright : Copyright © 2002 OriginalFilename : Support.exe #:34 [avgcc.exe] ModuleName : C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe Command Line : "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP ProcessID : 1508 ThreadCreationTime : 5-10-2005 4:24:07 PM BasePriority : Normal FileVersion : 7,1,0,307 ProductVersion : 7.1.0.307 ProductName : AVG Anti-Virus System CompanyName : GRISOFT, s.r.o. FileDescription : AVG Control Center InternalName : AvgCC LegalCopyright : Copyright © 2005, GRISOFT, s.r.o. OriginalFilename : AvgCC.EXE #:35 [hpztsb10.exe] ModuleName : C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe Command Line : "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" ProcessID : 1600 ThreadCreationTime : 5-10-2005 4:24:07 PM BasePriority : Normal FileVersion : 2.323.0.0 ProductVersion : 2.323.0.0 ProductName : HP DeskJet CompanyName : HP LegalCopyright : Copyright © Hewlett-Packard Company 1999-2004 #:36 [hpwuschd.exe] ModuleName : C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe Command Line : "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" ProcessID : 1448 ThreadCreationTime : 5-10-2005 4:24:07 PM BasePriority : Normal #:37 [hpotdd01.exe] ModuleName : C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe Command Line : "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" ProcessID : 1632 ThreadCreationTime : 5-10-2005 4:24:07 PM BasePriority : Normal FileVersion : 1, 0, 0, 1 ProductVersion : 1, 0, 0, 1 ProductName : Hewlett-Packard hpotdd01 CompanyName : Hewlett-Packard FileDescription : hpotdd01 InternalName : hpotdd01 LegalCopyright : Copyright © 2002 OriginalFilename : hpotdd01.exe #:38 [winpatrol.exe] ModuleName : C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe Command Line : "C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe" ProcessID : 1576 ThreadCreationTime : 5-10-2005 4:24:07 PM BasePriority : Normal FileVersion : 8, 1, 2, 0 ProductVersion : 8.1.2.0 ProductName : WinPatrol Monitor CompanyName : BillP Studios FileDescription : WinPatrol System Monitor InternalName : WinPatrol Monitor LegalCopyright : Copyright © 1997- 2004 BillP Studios OriginalFilename : Scotty Comments : Let Scotty the Windows Watchdog patrol your system. #:39 [realsched.exe] ModuleName : C:\Program Files\Common Files\Real\Update_OB\realsched.exe Command Line : "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot ProcessID : 1636 ThreadCreationTime : 5-10-2005 4:24:07 PM BasePriority : Normal FileVersion : 0.1.0.3208 ProductVersion : 0.1.0.3208 ProductName : RealPlayer (32-bit) CompanyName : RealNetworks, Inc. FileDescription : RealNetworks Scheduler InternalName : schedapp LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004 LegalTrademarks : RealAudio is a trademark of RealNetworks, Inc. OriginalFilename : realsched.exe #:40 [ctfmon.exe] ModuleName : C:\WINDOWS\system32\ctfmon.exe Command Line : "C:\WINDOWS\system32\ctfmon.exe" ProcessID : 1364 ThreadCreationTime : 5-10-2005 4:24:07 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : CTF Loader InternalName : CTFMON LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : CTFMON.EXE #:41 [mtdacq.exe] ModuleName : C:\Program Files\Creative\Shared Files\Media Sniffer\MtdAcq.EXE Command Line : "C:\Program Files\Creative\Shared Files\Media Sniffer\MtdAcq.EXE" /s ProcessID : 1292 ThreadCreationTime : 5-10-2005 4:24:08 PM BasePriority : Normal FileVersion : 1.1.0.0 ProductVersion : 1.0.0.0 ProductName : Metadata monitor CompanyName : Creative Technology Ltd FileDescription : Metadata monitor InternalName : MtdAcq.exe LegalCopyright : Copyright © Creative Technology Ltd., 2002. All rights reserved. OriginalFilename : MtdAcq.exe #:42 [notifyalert.exe] ModuleName : C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe Command Line : "C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe" timer ProcessID : 1300 ThreadCreationTime : 5-10-2005 4:24:08 PM BasePriority : Normal #:43 [dlg.exe] ModuleName : C:\Program Files\Digital Line Detect\DLG.exe Command Line : "C:\Program Files\Digital Line Detect\DLG.exe" ProcessID : 2072 ThreadCreationTime : 5-10-2005 4:24:08 PM BasePriority : Normal FileVersion : 1, 0, 0, 1 ProductVersion : 1, 0, 0, 1 ProductName : BVRP Software TestLine CompanyName : BVRP Software FileDescription : Digital Line Detection InternalName : TestLine LegalCopyright : Copyright © 2003 OriginalFilename : TestLine.exe #:44 [apntex.exe] ModuleName : C:\Program Files\Apoint\Apntex.exe Command Line : "Apntex.exe" ProcessID : 2116 ThreadCreationTime : 5-10-2005 4:24:09 PM BasePriority : Normal FileVersion : 5.0.1.15 ProductVersion : 5.0.1.15 ProductName : Alps Pointing-device Driver for Windows NT/2000/XP CompanyName : Alps Electric Co., Ltd. FileDescription : Alps Pointing-device Driver for Windows NT/2000/XP InternalName : Alps Pointing-device Driver for Windows NT/2000/XP LegalCopyright : Copyright © 1998-2003 Alps Electric Co., Ltd. OriginalFilename : ApntEx.exe #:45 [wmiapsrv.exe] ModuleName : C:\WINDOWS\system32\wbem\wmiapsrv.exe Command Line : C:\WINDOWS\system32\wbem\wmiapsrv.exe ProcessID : 2560 ThreadCreationTime : 5-10-2005 4:24:14 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : WMI Performance Adapter Service InternalName : WmiApSrv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : WmiApSrv.exe #:46 [wmiprvse.exe] ModuleName : C:\WINDOWS\system32\wbem\wmiprvse.exe Command Line : C:\WINDOWS\system32\wbem\wmiprvse.exe -Embedding ProcessID : 2632 ThreadCreationTime : 5-10-2005 4:24:15 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : WMI InternalName : Wmiprvse.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : Wmiprvse.exe #:47 [wmiprvse.exe] ModuleName : C:\WINDOWS\system32\wbem\wmiprvse.exe Command Line : C:\WINDOWS\system32\wbem\wmiprvse.exe -Embedding ProcessID : 3088 ThreadCreationTime : 5-10-2005 4:24:18 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : WMI InternalName : Wmiprvse.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : Wmiprvse.exe #:48 [winword.exe] ModuleName : C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Command Line : "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" -Embedding ProcessID : 1916 ThreadCreationTime : 5-10-2005 4:59:41 PM BasePriority : Normal #:49 [ad-aware.exe] ModuleName : C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe Command Line : "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" ProcessID : 2464 ThreadCreationTime : 5-10-2005 5:07:44 PM BasePriority : Normal FileVersion : 6.2.0.206 ProductVersion : VI.Second Edition ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved #:50 [dumprep.exe] ModuleName : C:\WINDOWS\system32\dumprep.exe Command Line : "C:\WINDOWS\system32\dumprep.exe" 2992 -H 2988 "Global\0314daa66c688338578" ProcessID : 416 ThreadCreationTime : 5-10-2005 5:17:09 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Error Reporting Dump Reporting Tool InternalName : DUMPREP.EXE LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : DUMPREP.EXE #:51 [dumprep.exe] ModuleName : C:\WINDOWS\system32\dumprep.exe Command Line : "C:\WINDOWS\system32\dumprep.exe" 2992 -H 2988 "Global\0317e1766c68833834c" ProcessID : 2616 ThreadCreationTime : 5-10-2005 5:17:37 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Error Reporting Dump Reporting Tool InternalName : DUMPREP.EXE LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : DUMPREP.EXE Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 MRU List Object Recognized! Location: : C:\Documents and Settings\Ken Chute\Application Data\microsoft\office\recent Description : list of recently opened documents using microsoft office MRU List Object Recognized! Location: : C:\Documents and Settings\Ken Chute\recent Description : list of recently opened documents MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\adobe\acrobat reader\5.0\avgeneral\crecentfiles Description : list of recently used files in adobe reader MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\google\navclient\1.1\history Description : list of recently used search terms in the google toolbar MRU List Object Recognized! Location: : software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct3d MRU List Object Recognized! Location: : software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct X MRU List Object Recognized! Location: : software\microsoft\directdraw\mostrecentapplication Description : most recent application to use microsoft directdraw MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\microsoft\directinput\mostrecentapplication Description : most recent application to use microsoft directinput MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\microsoft\directinput\mostrecentapplication Description : most recent application to use microsoft directinput MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\microsoft\internet explorer Description : last download directory used in microsoft internet explorer MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\microsoft\mediaplayer\preferences Description : last playlist index loaded in microsoft windows media player MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\microsoft\mediaplayer\preferences Description : last playlist loaded in microsoft windows media player MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\microsoft\microsoft management console\recent file list Description : list of recent snap-ins used in the microsoft management console MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\microsoft\office\11.0\common\open find\microsoft office word\settings\save as\file name mru Description : list of recent documents saved by microsoft word MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\microsoft\search assistant\acmru Description : list of recent search terms used with the search assistant MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\microsoft\windows\currentversion\applets\regedit Description : last key accessed using the microsoft registry editor MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\microsoft\windows\currentversion\applets\wordpad\recent file list Description : list of recent files opened using wordpad MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru Description : list of recent programs opened MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru Description : list of recently saved files, stored according to file extension MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\microsoft\windows\currentversion\explorer\recentdocs Description : list of recent documents opened MRU List Object Recognized! Location: : software\musicmatch\musicmatch jukebox\4.0\fileconv Description : file conversion location settings in musicmatch jukebox MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\realnetworks\realplayer\6.0\preferences Description : list of recent skins in realplayer MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\realnetworks\realplayer\6.0\preferences Description : list of recent clips in realplayer MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\realnetworks\realplayer\6.0\preferences Description : last login time in realplayer MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general Description : windows media sdk MRU List Object Recognized! Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general Description : windows media sdk MRU List Object Recognized! Location: : S-1-5-21-2077532245-3320608998-1530696625-1006\software\microsoft\windows media\wmsdk\general Description : windows media sdk Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie Object Recognized! Type : IECache Entry Data : ken chute@cgi-bin[2].txt Category : Data Miner Comment : Hits:2 Value : Cookie:ken chute@imrworldwide.com/cgi-bin Expires : 5-7-2015 5:32:32 PM LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking Cookie Object Recognized! Type : IECache Entry Data : ken chute@servedby.netshelter[1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:ken chute@servedby.netshelter.net/ Expires : 5-17-2005 11:06:46 AM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 2 Objects found so far: 29 Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 29 Scanning Hosts file...... Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 1 entries scanned. New critical objects:0 Objects found so far: 29 Possible Browser Hijack attempt Object Recognized! Type : File Data : box manufacturer.url Category : Misc Comment : Problematic URL discovered: http://www.kraftsolutions.com/?source=LookSmart Object : C:\Documents and Settings\Ken Chute\Favorites\Cold Pole\ Possible Browser Hijack attempt Object Recognized! Type : File Data : Best Music Link.url Category : Misc Comment : Problematic URL discovered: http://www.hitboss.com/Music/bestlink.htm Object : C:\Documents and Settings\Ken Chute\Favorites\Music and Movies\ Performing conditional scans... »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 31 12:33:19 PM Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:15:13.93 Objects scanned:132099 Objects identified:4 Objects ignored:0 New critical objects:4 |
|
|
| Guest_Andy_veal_* |
May 12 2005, 04:04 PM
Post
#2
|
|
|
Sorry for the delay in replying
If you chose to clean your computer from what Ad-aware found please follow these instructions below… Please make sure that you are using the * SE1R44 10.05.2005 * definition file. Please launch Ad-Aware SE and click on the gear to access the Configuration Menu. Please make sure that this setting is applied. Click on Tweak > Cleaning Engine > UNcheck "Always try to unload modules before deletion". Disconnect from the internet (for broadband/cable users, it is recommended that you disconnect the cable connection) and close all open browsers or other programs you have running. Please then boot into Safe Mode To clean your machine, it is highly recommended that you clean the following directory contents (but not the directory folder): Please run CCleaner to assist in this process. Download CCleaner (Setup: go to >options > settings > Uncheck "Only delete files in Windows Temp folders older than 48 hours" for cleaning malware files!) * C:\Windows\Temp\ * C:\Documents and Settings\<Your Profile>\Local Settings\Temporary Internet Files\ <- This will delete all your cached internet content including cookies. * C:\Documents and Settings\<Your Profile>\Local Settings\Temp\ * C:\Documents and Settings\<Any other users Profile>\Local Settings\Temporary Internet Files\ * C:\Documents and Settings\<Any other users Profile>\Local Settings\Temp\ * Empty your "Recycle Bin". Please run Ad-Aware SE from the command lines shown in the instructions shown below. Click "Start" > select "Run" > type the text shown in bold below (including the quotation marks and with the same spacing as shown) "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" /full +procnuke (For the Professional version) "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe" /full +procnuke (For the Plus version) "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" +procnuke (For the Personal version) Click OK. Please note that the path above is of the default installion location for Ad-aware SE, if this is different, please adjust it to the location that you have installed it to. When the scan has completed, select Next. In the Scanning Results window, select the "Scan Summary" tab. Check the box next to each "target family" you wish to remove. Click next, Click OK. If problems are caused by deleting a family, please leave it. Please shutdown/restart your computer after removal, run a new full scan and post the results as a reply. Do not launch any programs or connect to the internet at this time. Please then copy & paste the complete log file here. Don't quarantine or remove anything at this time, just post a complete logfile. This can sometimes takes 2-3 posts to get it all posted, once the "Summary of this scan" information is shown, you have posted all of your logfile. Please remember when posting another logfile keep "Search for negligible risk entries" deselected as negligible risk entries (MRU's) are not considered to be a threat. This option can be changed when choosing your scan type. Please post back here Good luck Andy |
|
|
May 12 2005, 08:20 PM
Post
#3
|
|
|
New Member ![]() Posts: 3 OS: XP |
Ad-Aware SE Build 1.05
Logfile Created on:Thursday, May 12, 2005 9:01:53 PM Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R44 10.05.2005 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» MRU List(TAC index:0):5 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Definition File: ========================= Definitions File Loaded: Reference Number : SE1R44 10.05.2005 Internal build : 52 File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal \defs.ref File size : 470885 Bytes Total size : 1423894 Bytes Signature data size : 1392940 Bytes Reference data size : 30442 Bytes Signatures total : 39753 Fingerprints total : 872 Fingerprints size : 29756 Bytes Target categories : 15 Target families : 668 Memory + processor status: ========================== Number of processors : 1 Processor architecture : Non Intel Memory available:44 % Total physical memory:523496 kb Available physical memory:226672 kb Total page file size:1276972 kb Available on page file:1026320 kb Total virtual memory:2097024 kb Available virtual memory:2047084 kb OS:Microsoft Windows XP Professional Service Pack 2 (Build 2600) Ad-Aware SE Settings =========================== Set : Search for negligible risk entries Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan within archives Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Obtain command line of scanned processes Set : Scan registry for all users instead of current user only Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Write-protect system files after repair (Hosts file, etc.) Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects 5-12-2005 9:01:53 PM - Scan started. (Full System Scan) Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] ModuleName : \SystemRoot\System32\smss.exe Command Line : n/a ProcessID : 404 ThreadCreationTime : 5-13-2005 2:00:03 AM BasePriority : Normal #:2 [csrss.exe] ModuleName : \??\C:\WINDOWS\system32\csrss.exe Command Line : C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestTh ProcessID : 656 ThreadCreationTime : 5-13-2005 2:00:06 AM BasePriority : Normal #:3 [winlogon.exe] ModuleName : \??\C:\WINDOWS\system32\winlogon.exe Command Line : winlogon.exe ProcessID : 844 ThreadCreationTime : 5-13-2005 2:00:08 AM BasePriority : High #:4 [services.exe] ModuleName : C:\WINDOWS\system32\services.exe Command Line : C:\WINDOWS\system32\services.exe ProcessID : 888 ThreadCreationTime : 5-13-2005 2:00:08 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : services.exe #:5 [lsass.exe] ModuleName : C:\WINDOWS\system32\lsass.exe Command Line : C:\WINDOWS\system32\lsass.exe ProcessID : 900 ThreadCreationTime : 5-13-2005 2:00:08 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:6 [ati2evxx.exe] ModuleName : C:\WINDOWS\system32\Ati2evxx.exe Command Line : C:\WINDOWS\system32\Ati2evxx.exe ProcessID : 1064 ThreadCreationTime : 5-13-2005 2:00:09 AM BasePriority : Normal #:7 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost -k DcomLaunch ProcessID : 1076 ThreadCreationTime : 5-13-2005 2:00:09 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost -k rpcss ProcessID : 1172 ThreadCreationTime : 5-13-2005 2:00:09 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:9 [svchost.exe] ModuleName : C:\WINDOWS\System32\svchost.exe Command Line : C:\WINDOWS\System32\svchost.exe -k netsvcs ProcessID : 1212 ThreadCreationTime : 5-13-2005 2:00:09 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:10 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost.exe -k NetworkService ProcessID : 1256 ThreadCreationTime : 5-13-2005 2:00:09 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:11 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost.exe -k LocalService ProcessID : 1340 ThreadCreationTime : 5-13-2005 2:00:10 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:12 [ati2evxx.exe] ModuleName : C:\WINDOWS\system32\Ati2evxx.exe Command Line : Ati2evxx.exe -Client ProcessID : 1696 ThreadCreationTime : 5-13-2005 2:00:11 AM BasePriority : Normal #:13 [spoolsv.exe] ModuleName : C:\WINDOWS\system32\spoolsv.exe Command Line : C:\WINDOWS\system32\spoolsv.exe ProcessID : 1768 ThreadCreationTime : 5-13-2005 2:00:11 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : spoolsv.exe #:14 [explorer.exe] ModuleName : C:\WINDOWS\Explorer.EXE Command Line : C:\WINDOWS\Explorer.EXE ProcessID : 1788 ThreadCreationTime : 5-13-2005 2:00:11 AM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE #:15 [scardsvr.exe] ModuleName : C:\WINDOWS\System32\SCardSvr.exe Command Line : C:\WINDOWS\System32\SCardSvr.exe ProcessID : 1868 ThreadCreationTime : 5-13-2005 2:00:11 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Smart Card Resource Management Server InternalName : SCardSvr.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : SCardSvr.exe #:16 [avgamsvr.exe] ModuleName : C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe Command Line : C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe ProcessID : 1980 ThreadCreationTime : 5-13-2005 2:00:12 AM BasePriority : Normal FileVersion : 7,1,0,307 ProductVersion : 7.1.0.307 ProductName : AVG Anti-Virus System CompanyName : GRISOFT, s.r.o. FileDescription : AVG Alert Manager InternalName : avgamsvr LegalCopyright : Copyright © 2005, GRISOFT, s.r.o. OriginalFilename : avgamsvr.EXE #:17 [apoint.exe] ModuleName : C:\Program Files\Apoint\Apoint.exe Command Line : "C:\Program Files\Apoint\Apoint.exe" ProcessID : 2004 ThreadCreationTime : 5-13-2005 2:00:12 AM BasePriority : Normal FileVersion : 5.5.101.123 ProductVersion : 5.5.101.123 ProductName : Alps Pointing-device Driver CompanyName : Alps Electric Co., Ltd. FileDescription : Alps Pointing-device Driver InternalName : Alps Pointing-device Driver LegalCopyright : Copyright © 1999-2003 Alps Electric Co., Ltd. OriginalFilename : Apoint.exe #:18 [jusched.exe] ModuleName : C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe Command Line : "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" ProcessID : 2012 ThreadCreationTime : 5-13-2005 2:00:12 AM BasePriority : Normal #:19 [atiptaxx.exe] ModuleName : C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe Command Line : "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" ProcessID : 2020 ThreadCreationTime : 5-13-2005 2:00:12 AM BasePriority : Normal FileVersion : 6.14.10.5113 ProductVersion : 6.14.10.5113 ProductName : ATI Desktop Component CompanyName : ATI Technologies, Inc. FileDescription : ATI Desktop Control Panel InternalName : Atiptaxx.exe LegalCopyright : Copyright © 1998-2004 ATI Technologies Inc. OriginalFilename : Atiptaxx.exe #:20 [tfswctrl.exe] ModuleName : C:\WINDOWS\system32\dla\tfswctrl.exe Command Line : "C:\WINDOWS\system32\dla\tfswctrl.exe" ProcessID : 2028 ThreadCreationTime : 5-13-2005 2:00:13 AM BasePriority : Normal FileVersion : 1.04.07b CompanyName : Sonic Solutions FileDescription : Drive Letter Access Component LegalCopyright : Copyright © 2004 Sonic Solutions #:21 [sgtray.exe] ModuleName : C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe Command Line : "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r ProcessID : 128 ThreadCreationTime : 5-13-2005 2:00:13 AM BasePriority : Normal FileVersion : 1.01.32a CompanyName : Sonic Solutions FileDescription : Sonic Update Manager LegalCopyright : Copyright © 2002 Sonic Solutions #:22 [avgupsvc.exe] ModuleName : C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe Command Line : C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe ProcessID : 112 ThreadCreationTime : 5-13-2005 2:00:13 AM BasePriority : Normal FileVersion : 7,1,0,285 ProductVersion : 7.1.0.285 ProductName : AVG 7.0 Anti-Virus System CompanyName : GRISOFT, s.r.o. FileDescription : AVG Update Service InternalName : avgupsvc LegalCopyright : Copyright © 2004, GRISOFT, s.r.o. OriginalFilename : avgupdsvc.EXE #:23 [pcmservice.exe] ModuleName : C:\Program Files\Dell\Media Experience\PCMService.exe Command Line : "C:\Program Files\Dell\Media Experience\PCMService.exe" ProcessID : 188 ThreadCreationTime : 5-13-2005 2:00:13 AM BasePriority : Normal FileVersion : 1.0.1611 ProductVersion : 1.0.1611 ProductName : PCM2Launcher Application CompanyName : CyberLink Corp. FileDescription : PowerCinema Resident Program for Dell InternalName : PowerCinema Resident Program for Dell LegalCopyright : Copyright c 2003 CyberLink Corp. OriginalFilename : PCM2Launcher.EXE #:24 [dvdlauncher.exe] ModuleName : C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe Command Line : "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" ProcessID : 164 ThreadCreationTime : 5-13-2005 2:00:13 AM BasePriority : Normal FileVersion : 3.00.0000 ProductVersion : 3.00.0000 ProductName : Cyberlink PowerCinema 3.0 CompanyName : CyberLink Corp. FileDescription : CyberLink PowerCinema Resident Program InternalName : CyberLink PowerCinema Resident Program LegalCopyright : Copyright © 2003 CyberLink Corp. OriginalFilename : DVDLauncher.EXE #:25 [ctsvccda.exe] ModuleName : C:\WINDOWS\system32\CTSvcCDA.EXE Command Line : C:\WINDOWS\system32\CTSvcCDA.EXE ProcessID : 212 ThreadCreationTime : 5-13-2005 2:00:13 AM BasePriority : Normal FileVersion : 1.0.1.0 ProductVersion : 1.0.0.0 ProductName : Creative Service for CDROM Access CompanyName : Creative Technology Ltd FileDescription : Creative Service for CDROM Access InternalName : CTsvcCDAEXE LegalCopyright : Copyright © Creative Technology Ltd., 1999. All rights reserved. OriginalFilename : CTsvcCDA.EXE #:26 [quickset.exe] ModuleName : C:\Program Files\Dell\QuickSet\quickset.exe Command Line : "C:\Program Files\Dell\QuickSet\quickset.exe" ProcessID : 240 ThreadCreationTime : 5-13-2005 2:00:13 AM BasePriority : Normal FileVersion : 1, 0, 0, 1 ProductVersion : 1, 0, 0, 1 ProductName : QuickSet Application FileDescription : QuickSet MFC Application InternalName : direct LegalCopyright : Copyright © 2001 OriginalFilename : direct.EXE #:27 [support.exe] ModuleName : C:\Program Files\Common Files\Dell\EUSW\Support.exe Command Line : "C:\Program Files\Common Files\Dell\EUSW\Support.exe" ProcessID : 252 ThreadCreationTime : 5-13-2005 2:00:13 AM BasePriority : Normal FileVersion : 2, 1, 1, 0 ProductVersion : 1, 0, 0, 1 ProductName : Dell Support CompanyName : Dell FileDescription : Support InternalName : Support LegalCopyright : Copyright © 2002 OriginalFilename : Support.exe #:28 [avgcc.exe] ModuleName : C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe Command Line : "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP ProcessID : 264 ThreadCreationTime : 5-13-2005 2:00:13 AM BasePriority : Normal FileVersion : 7,1,0,307 ProductVersion : 7.1.0.307 ProductName : AVG Anti-Virus System CompanyName : GRISOFT, s.r.o. FileDescription : AVG Control Center InternalName : AvgCC LegalCopyright : Copyright © 2005, GRISOFT, s.r.o. OriginalFilename : AvgCC.EXE #:29 [hpztsb10.exe] ModuleName : C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe Command Line : "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" ProcessID : 316 ThreadCreationTime : 5-13-2005 2:00:13 AM BasePriority : Normal FileVersion : 2.323.0.0 ProductVersion : 2.323.0.0 ProductName : HP DeskJet CompanyName : HP LegalCopyright : Copyright © Hewlett-Packard Company 1999-2004 #:30 [hpwuschd.exe] ModuleName : C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe Command Line : "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" ProcessID : 428 ThreadCreationTime : 5-13-2005 2:00:14 AM BasePriority : Normal #:31 [hpotdd01.exe] ModuleName : C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe Command Line : "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" ProcessID : 460 ThreadCreationTime : 5-13-2005 2:00:14 AM BasePriority : Normal FileVersion : 1, 0, 0, 1 ProductVersion : 1, 0, 0, 1 ProductName : Hewlett-Packard hpotdd01 CompanyName : Hewlett-Packard FileDescription : hpotdd01 InternalName : hpotdd01 LegalCopyright : Copyright © 2002 OriginalFilename : hpotdd01.exe #:32 [mdm.exe] ModuleName : C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE Command Line : "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" ProcessID : 512 ThreadCreationTime : 5-13-2005 2:00:14 AM BasePriority : Normal FileVersion : 7.00.9466 ProductVersion : 7.00.9466 ProductName : Microsoft® Visual Studio .NET CompanyName : Microsoft Corporation FileDescription : Machine Debug Manager InternalName : mdm.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : mdm.exe #:33 [winpatrol.exe] ModuleName : C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe Command Line : "C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe" ProcessID : 528 ThreadCreationTime : 5-13-2005 2:00:14 AM BasePriority : Normal FileVersion : 8, 1, 2, 0 ProductVersion : 8.1.2.0 ProductName : WinPatrol Monitor CompanyName : BillP Studios FileDescription : WinPatrol System Monitor InternalName : WinPatrol Monitor LegalCopyright : Copyright © 1997- 2004 BillP Studios OriginalFilename : Scotty Comments : Let Scotty the Windows Watchdog patrol your system. #:34 [realsched.exe] ModuleName : C:\Program Files\Common Files\Real\Update_OB\realsched.exe Command Line : "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot ProcessID : 536 ThreadCreationTime : 5-13-2005 2:00:14 AM BasePriority : Normal FileVersion : 0.1.0.3208 ProductVersion : 0.1.0.3208 ProductName : RealPlayer (32-bit) CompanyName : RealNetworks, Inc. FileDescription : RealNetworks Scheduler InternalName : schedapp LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004 LegalTrademarks : RealAudio is a trademark of RealNetworks, Inc. OriginalFilename : realsched.exe #:35 [gcasserv.exe] ModuleName : C:\Program Files\Microsoft AntiSpyware\gcasServ.exe Command Line : "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" ProcessID : 548 ThreadCreationTime : 5-13-2005 2:00:14 AM BasePriority : Idle FileVersion : 1.00.0509 ProductVersion : 1.00.0509 ProductName : Microsoft AntiSpyware (Beta 1) CompanyName : Microsoft Corporation FileDescription : Microsoft AntiSpyware Service InternalName : gcasServ LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved. LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet is a trademark of Microsoft Corporation. OriginalFilename : gcasServ.exe #:36 [ctfmon.exe] ModuleName : C:\WINDOWS\system32\ctfmon.exe Command Line : "C:\WINDOWS\system32\ctfmon.exe" ProcessID : 580 ThreadCreationTime : 5-13-2005 2:00:14 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : CTF Loader InternalName : CTFMON LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : CTFMON.EXE #:37 [mtdacq.exe] ModuleName : C:\Program Files\Creative\Shared Files\Media Sniffer\MtdAcq.EXE Command Line : "C:\Program Files\Creative\Shared Files\Media Sniffer\MtdAcq.EXE" /s ProcessID : 612 ThreadCreationTime : 5-13-2005 2:00:14 AM BasePriority : Normal FileVersion : 1.1.0.0 ProductVersion : 1.0.0.0 ProductName : Metadata monitor CompanyName : Creative Technology Ltd FileDescription : Metadata monitor InternalName : MtdAcq.exe LegalCopyright : Copyright © Creative Technology Ltd., 2002. All rights reserved. OriginalFilename : MtdAcq.exe #:38 [notifyalert.exe] ModuleName : C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe Command Line : "C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe" timer ProcessID : 704 ThreadCreationTime : 5-13-2005 2:00:15 AM BasePriority : Normal #:39 [snmp.exe] ModuleName : C:\WINDOWS\System32\snmp.exe Command Line : C:\WINDOWS\System32\snmp.exe ProcessID : 724 ThreadCreationTime : 5-13-2005 2:00:15 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : SNMP Service InternalName : snmp.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : snmp.exe #:40 [apntex.exe] ModuleName : C:\Program Files\Apoint\Apntex.exe Command Line : "Apntex.exe" ProcessID : 776 ThreadCreationTime : 5-13-2005 2:00:15 AM BasePriority : Normal FileVersion : 5.0.1.15 ProductVersion : 5.0.1.15 ProductName : Alps Pointing-device Driver for Windows NT/2000/XP CompanyName : Alps Electric Co., Ltd. FileDescription : Alps Pointing-device Driver for Windows NT/2000/XP InternalName : Alps Pointing-device Driver for Windows NT/2000/XP LegalCopyright : Copyright © 1998-2003 Alps Electric Co., Ltd. OriginalFilename : ApntEx.exe #:41 [reader_sl.exe] ModuleName : C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe Command Line : "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ProcessID : 804 ThreadCreationTime : 5-13-2005 2:00:15 AM BasePriority : Normal FileVersion : 7.0.0.0 ProductVersion : 7.0.0.0 ProductName : Adobe Acrobat CompanyName : Adobe Systems Incorporated FileDescription : Adobe Acrobat SpeedLauncher LegalCopyright : Copyright Adobe Systems Incorporated 2004 OriginalFilename : AcroSpeedLaunch.exe #:42 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost.exe -k imgsvc ProcessID : 996 ThreadCreationTime : 5-13-2005 2:00:15 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:43 [dlg.exe] ModuleName : C:\Program Files\Digital Line Detect\DLG.exe Command Line : "C:\Program Files\Digital Line Detect\DLG.exe" ProcessID : 1088 ThreadCreationTime : 5-13-2005 2:00:16 AM BasePriority : Normal FileVersion : 1, 0, 0, 1 ProductVersion : 1, 0, 0, 1 ProductName : BVRP Software TestLine CompanyName : BVRP Software FileDescription : Digital Line Detection InternalName : TestLine LegalCopyright : Copyright © 2003 OriginalFilename : TestLine.exe #:44 [wltrysvc.exe] ModuleName : C:\WINDOWS\System32\WLTRYSVC.EXE Command Line : C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe ProcessID : 1480 ThreadCreationTime : 5-13-2005 2:00:17 AM BasePriority : Normal #:45 [bcmwltry.exe] ModuleName : C:\WINDOWS\System32\bcmwltry.exe Command Line : C:\WINDOWS\System32\bcmwltry.exe ProcessID : 1564 ThreadCreationTime : 5-13-2005 2:00:17 AM BasePriority : Normal FileVersion : 3.40.67.0 ProductVersion : 3.40.67.0 ProductName : Dell Wireless WLAN Card Wireless Network Tray Applet CompanyName : Dell Computer Corporation FileDescription : Dell Wireless WLAN Card Wireless Network Tray Applet InternalName : bcmwltry.exe LegalCopyright : 1998-2003, Dell Computer Corporation All Rights Reserved. OriginalFilename : bcmwltry.exe #:46 [mspmspsv.exe] ModuleName : C:\WINDOWS\system32\MsPMSPSv.exe Command Line : C:\WINDOWS\system32\MsPMSPSv.exe ProcessID : 1576 ThreadCreationTime : 5-13-2005 2:00:18 AM BasePriority : Normal FileVersion : 7.00.00.1954 ProductVersion : 7.00.00.1954 ProductName : Microsoft ® DRM CompanyName : Microsoft Corporation FileDescription : WMDM PMSP Service InternalName : MSPMSPSV.EXE LegalCopyright : Copyright © Microsoft Corp. 1981-2000 OriginalFilename : MSPMSPSV.EXE #:47 [wmiprvse.exe] ModuleName : C:\WINDOWS\system32\wbem\wmiprvse.exe Command Line : C:\WINDOWS\system32\wbem\wmiprvse.exe -Embedding ProcessID : 2260 ThreadCreationTime : 5-13-2005 2:00:20 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : WMI InternalName : Wmiprvse.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : Wmiprvse.exe #:48 [alg.exe] ModuleName : C:\WINDOWS\System32\alg.exe Command Line : C:\WINDOWS\System32\alg.exe ProcessID : 2684 ThreadCreationTime : 5-13-2005 2:00:24 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Application Layer Gateway Service InternalName : ALG.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ALG.exe #:49 [wmiapsrv.exe] ModuleName : C:\WINDOWS\system32\wbem\wmiapsrv.exe Command Line : C:\WINDOWS\system32\wbem\wmiapsrv.exe ProcessID : 2744 ThreadCreationTime : 5-13-2005 2:00:25 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : WMI Performance Adapter Service InternalName : WmiApSrv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : WmiApSrv.exe #:50 [wmiprvse.exe] ModuleName : C:\WINDOWS\system32\wbem\wmiprvse.exe Command Line : C:\WINDOWS\system32\wbem\wmiprvse.exe -Embedding ProcessID : 2764 ThreadCreationTime : 5-13-2005 2:00:25 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : WMI InternalName : Wmiprvse.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : Wmiprvse.exe #:51 [gcasdtserv.exe] ModuleName : C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe Command Line : "C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe" ProcessID : 2952 ThreadCreationTime : 5-13-2005 2:00:26 AM BasePriority : Normal FileVersion : 1.00.0509 ProductVersion : 1.00.0509 ProductName : Microsoft AntiSpyware (Beta 1) CompanyName : Microsoft Corporation FileDescription : Microsoft AntiSpyware Data Service InternalName : gcasDtServ LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved. LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet is a trademark of Microsoft Corporation. OriginalFilename : gcasDtServ.exe #:52 [ad-aware.exe] ModuleName : C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe Command Line : "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" ProcessID : 664 ThreadCreationTime : 5-13-2005 2:00:48 AM BasePriority : Normal FileVersion : 6.2.0.206 ProductVersion : VI.Second Edition ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved #:53 [wuauclt.exe] ModuleName : C:\WINDOWS\system32\wuauclt.exe Command Line : "C:\WINDOWS\system32\wuauclt.exe" /RunStoreAsComServer Local\[4bc]SUSDS8bdc0c7732723945a7fc0020829d5d9c ProcessID : 2864 ThreadCreationTime : 5-13-2005 2:01:04 AM BasePriority : Normal FileVersion : 5.4.3790.2182 built by: srv03_rtm(ntvbl04) ProductVersion : 5.4.3790.2182 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Automatic Updates InternalName : wuauclt.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : wuauclt.exe Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 5 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 5 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 5 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 5 Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 5 Scanning Hosts file...... Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 1 entries scanned. New critical objects:0 Objects found so far: 5 Andy, Thanks for the reply....I think I did everything correctly, here is the log. Ken Performing conditional scans... »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 5 9:13:06 PM Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:11:12.788 Objects scanned:131196 Objects identified:0 Objects ignored:0 New critical objects:0 |
|
|
| Guest_Andy_veal_* |
May 18 2005, 10:38 AM
Post
#4
|
|
|
Your logfile seems clean.
Are you still having problems? To keep your computer safe -Make sure you have all critical updates installed. -To make sure that you have got a firewall running when your connected to the internet and Anti-virus software which has the latest updates. Two great sites to check for good advice and top rated software are http://members.accessbee.com/mitch/PhantomPhixer.html and http://www.spywareaid.com/index.php?file=toprated |
|
|
May 19 2005, 03:59 PM
Post
#5
|
|
|
New Member ![]() Posts: 3 OS: XP |
Andy,
Thanks very much for your time. I did a number of scans and removed some of the start up programs and it seems to be running faster now. Thanks again, Ken |
|
|
| Guest_numbnuts_* |
May 19 2005, 04:41 PM
Post
#6
|
|
|
Hello,kchute welcome to the forum..
A New Definitions file has been released ….well 2 have.. New Definitions: SE1R 46 17.05.2005 Please up date To get the update, please launch Ad-Aware SE and click on the globe icon to access the Web Update feature, And post a new logfile here.. just to be safe... Regards.. numbnts.. |
|
|
| Guest_numbnuts_* |
Jun 15 2005, 01:47 PM
Post
#7
|
|
|
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member with address of this thread. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
2 / 858 | 25th May 2005 - 08:34 AM mpk started - last by numbnuts |
|||||
![]() |
52 / 3,821 | 18th June 2005 - 11:50 PM Keithster McGraw started - last by usetobe |
|||||
![]() |
13 / 2,035 | 26th August 2005 - 01:36 AM hava33 started - last by Kat |
|||||
![]() |
2 / 1,219 | 30th May 2005 - 12:48 PM computerdude1985 started - last by don77 |
|||||
|
Time is now: 21st November 2009 - 09:32 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising