Hello again. Because of all this, I have been checking for new Ad-aware reference files everyday. Reference file 01R303 08.05.2004 loaded. Spybot, Norton, Windows are also currently updated. I downloaded and ran Kill2me.exe as directed. I also ran CWShredder again. I then rebooted and here is the Ad-aware log that showed:
Lavasoft Ad-aware Personal Build 6.181
Logfile created on :Saturday, May 08, 2004 7:20:03 PM
Created with Ad-aware Personal, free for private use.
Using reference-file :01R303 08.05.2004
______________________________________________________
Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry
Set : Scan my Hosts file
5/8/2004 7:20:03 PM - Scan started. (Smart mode)
Listing running processes
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 5/8/2004 11:08:01 PM
BasePriority : Normal
#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ThreadCreationTime : 5/8/2004 11:08:03 PM
BasePriority : High
#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 5/8/2004 11:08:03 PM
BasePriority : Normal
FileSize : 99 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 5/8/2004 11:03:10 PM
Last modified : 8/29/2002 11:00:00 AM
#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 5/8/2004 11:08:03 PM
BasePriority : Normal
FileSize : 11 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
OriginalFilename : lsass.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 5/8/2004 11:03:10 PM
Last modified : 8/29/2002 11:00:00 AM
#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 5/8/2004 11:08:04 PM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 5/8/2004 11:03:10 PM
Last modified : 8/29/2002 11:00:00 AM
#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 5/8/2004 11:08:04 PM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 5/8/2004 11:03:10 PM
Last modified : 8/29/2002 11:00:00 AM
#:7 [rundll32.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 5/8/2004 11:08:05 PM
BasePriority : Normal
FileSize : 31 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
OriginalFilename : RUNDLL.EXE
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 5/8/2004 11:19:30 PM
Last modified : 8/29/2002 11:00:00 AM
#:8 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 5/8/2004 11:08:06 PM
BasePriority : Normal
FileSize : 50 KB
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
OriginalFilename : spoolsv.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 5/8/2004 11:03:10 PM
Last modified : 8/29/2002 11:00:00 AM
#:9 [mm_tray.exe]
FilePath : C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\
ThreadCreationTime : 5/8/2004 11:08:09 PM
BasePriority : Normal
FileSize : 88 KB
FileVersion : 7.10.4053
ProductVersion : 7.10.4053
Copyright : Copyright © MUSICMATCH 1998-2001
CompanyName : MUSICMATCH, Inc.
FileDescription : mm_tray
InternalName : mm_tray
OriginalFilename : mm_tray.exe
ProductName : MUSICMATCH JUKEBOX
Created on : 12/4/2002 5:32:34 AM
Last accessed : 5/8/2004 11:08:00 PM
Last modified : 8/14/2002 11:29:26 PM
#:10 [support.exe]
FilePath : C:\Program Files\Common Files\Dell\EUSW\
ThreadCreationTime : 5/8/2004 11:08:09 PM
BasePriority : Normal
FileSize : 288 KB
FileVersion : 2, 0, 0, 34
ProductVersion : 1, 0, 0, 1
Copyright : Copyright
CompanyName : Dell
FileDescription : Support
InternalName : Support
OriginalFilename : Support.exe
ProductName : Dell Support
Created on : 8/22/2002 7:11:34 PM
Last accessed : 5/8/2004 11:08:00 PM
Last modified : 9/19/2003 7:46:26 PM
#:11 [popupkiller.exe]
FilePath : C:\Program Files\PopUp Killer\
ThreadCreationTime : 5/8/2004 11:08:09 PM
BasePriority : Normal
FileSize : 84 KB
FileVersion : 1.09.0005
ProductVersion : 1.09.0005
CompanyName : xFX JumpStart
InternalName : PopUpKiller
OriginalFilename : PopUpKiller.exe
ProductName : PopUpKiller
Created on : 9/24/1999 3:32:00 PM
Last accessed : 5/8/2004 11:18:00 PM
Last modified : 4/30/2001 8:55:06 PM
#:12 [navapw32.exe]
FilePath : C:\PROGRA~1\NORTON~2\NORTON~1\
ThreadCreationTime : 5/8/2004 11:08:09 PM
BasePriority : Normal
FileSize : 73 KB
FileVersion : 8.07.17
ProductVersion : 8.07.17
Copyright : Copyright © 2000-2002 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Agent
InternalName : NAVAPW32
OriginalFilename : NAVAPW32.EXE
ProductName : Norton AntiVirus
Created on : 8/19/2003 5:32:31 AM
Last accessed : 5/8/2004 11:08:09 PM
Last modified : 2/27/2002 3:27:58 PM
#:13 [directcd.exe]
FilePath : C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\
ThreadCreationTime : 5/8/2004 11:08:09 PM
BasePriority : Normal
FileSize : 668 KB
FileVersion : 5.3.2.34
ProductVersion : 5.3.2.34
Copyright : Copyright © 2001,2002, Roxio, Inc.
CompanyName : Roxio
FileDescription : DirectCD Application
InternalName : DirectCD
OriginalFilename : Directcd.exe
ProductName : DirectCD
Created on : 1/23/2002 3:20:16 PM
Last accessed : 5/8/2004 11:08:00 PM
Last modified : 3/23/2003 9:38:32 PM
#:14 [cfd.exe]
FilePath : C:\Program Files\BroadJump\Client Foundation\
ThreadCreationTime : 5/8/2004 11:08:09 PM
BasePriority : Normal
FileSize : 360 KB
Created on : 6/30/2003 12:09:05 AM
Last accessed : 5/8/2004 11:08:00 PM
Last modified : 9/11/2002 1:26:26 AM
#:15 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ThreadCreationTime : 5/8/2004 11:08:09 PM
BasePriority : Normal
FileSize : 148 KB
FileVersion : 0.1.0.1622
ProductVersion : 0.1.0.1622
Copyright : Copyright
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
OriginalFilename : realsched.exe
ProductName : RealOne Player (32-bit)
Created on : 7/2/2003 5:02:08 AM
Last accessed : 5/8/2004 11:08:00 PM
Last modified : 7/2/2003 5:02:08 AM
#:16 [safeenc.exe]
FilePath : C:\PROGRA~1\ERRORA~1\
ThreadCreationTime : 5/8/2004 11:08:09 PM
BasePriority : Normal
FileSize : 229 KB
Created on : 5/5/2004 9:45:24 AM
Last accessed : 5/8/2004 11:08:00 PM
Last modified : 5/8/2004 4:51:57 AM
#:17 [wtoolsa.exe]
FilePath : C:\Program Files\Common files\WinTools\
ThreadCreationTime : 5/8/2004 11:08:09 PM
BasePriority : Normal
FileSize : 429 KB
Created on : 5/6/2004 3:58:02 AM
Last accessed : 5/8/2004 11:10:33 PM
Last modified : 5/3/2004 12:41:40 PM
#:18 [washer.exe]
FilePath : C:\Program Files\Washer\
ThreadCreationTime : 5/8/2004 11:08:10 PM
BasePriority : Normal
FileSize : 2689 KB
FileVersion : 4.1.1.3
ProductVersion : 4.1
Copyright : Copyright 1998-2001 Webroot Software, Inc.
CompanyName : Webroot Software, Inc.
FileDescription : Window Washer
Created on : 12/7/2002 7:29:40 AM
Last accessed : 5/8/2004 11:08:00 PM
Last modified : 9/5/2001 8:53:32 PM
#:19 [wkcalrem.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\Works Shared\
ThreadCreationTime : 5/8/2004 11:08:11 PM
BasePriority : Normal
FileSize : 24 KB
FileVersion : 6.00.1911.0
ProductVersion : 6.00.1911.0
Copyright : Copyright
CompanyName : Microsoft
FileDescription : Microsoft
InternalName : WkCalRem
OriginalFilename : WKCALREM.EXE
ProductName : Microsoft
Created on : 8/7/2001 11:06:54 PM
Last accessed : 5/8/2004 11:20:04 PM
Last modified : 8/7/2001 11:06:54 PM
#:20 [nmain.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ThreadCreationTime : 5/8/2004 11:08:30 PM
BasePriority : Normal
FileSize : 533 KB
FileVersion : 5.01.05
ProductVersion : 5.01.05
Copyright : Copyright © 1997-2001 Symantec Corporation
CompanyName : Symantec Corporation
FileDescription : Norton Integrator
InternalName : Norton Integrator
OriginalFilename : NMAIN.EXE
ProductName : Norton Integrator
Created on : 9/28/2003 9:45:50 PM
Last accessed : 5/8/2004 11:09:51 PM
Last modified : 12/6/2001 5:34:24 PM
#:21 [cisvc.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 5/8/2004 11:09:14 PM
BasePriority : Normal
FileSize : 5 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Content Index service
InternalName : cisvc.exe
OriginalFilename : cisvc.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 5/8/2004 11:03:11 PM
Last modified : 8/29/2002 11:00:00 AM
#:22 [dcfssvc.exe]
FilePath : C:\WINDOWS\system32\drivers\
ThreadCreationTime : 5/8/2004 11:09:14 PM
BasePriority : Normal
FileSize : 156 KB
FileVersion : 1.1.4100.0
ProductVersion : 3.2.0400.0
Copyright : Copyright © Eastman Kodak Co. 2000-1
CompanyName : Eastman Kodak Company
FileDescription : Kodak DC Ring 3 Conduit (Win32)
InternalName : DcFsSvc.exe
OriginalFilename : DcFsSvc.exe
ProductName : Kodak DC File System Driver (Win32)
Created on : 10/9/2001 7:15:42 PM
Last accessed : 5/8/2004 11:03:11 PM
Last modified : 10/9/2001 7:15:42 PM
#:23 [navapsvc.exe]
FilePath : C:\Program Files\Norton SystemWorks\Norton AntiVirus\
ThreadCreationTime : 5/8/2004 11:09:14 PM
BasePriority : Normal
FileSize : 113 KB
FileVersion : 8.07.17
ProductVersion : 8.07.17
Copyright : Copyright © 2000-2002 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
OriginalFilename : NAVAPSVC.EXE
ProductName : Norton AntiVirus
Created on : 8/19/2003 5:32:31 AM
Last accessed : 5/8/2004 11:03:11 PM
Last modified : 2/27/2002 3:29:26 PM
#:24 [nprotect.exe]
FilePath : C:\Program Files\Norton SystemWorks\Norton Utilities\
ThreadCreationTime : 5/8/2004 11:09:15 PM
BasePriority : Normal
FileSize : 132 KB
FileVersion : 15.03.0.36
ProductVersion : 15.03.0.36
Copyright : Copyright © 2002 Symantec Corporation
CompanyName : Symantec Corporation
FileDescription : Norton Protection Status
InternalName : NPROTECT
OriginalFilename : NPROTECT.EXE
ProductName : Norton Utilities
Created on : 8/19/2003 5:33:08 AM
Last accessed : 5/8/2004 11:03:11 PM
Last modified : 2/5/2002 10:03:00 AM
#:25 [nvsvc32.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 5/8/2004 11:09:15 PM
BasePriority : Normal
FileSize : 80 KB
FileVersion : 6.14.10.5216
ProductVersion : 6.14.10.5216
Copyright : © NVIDIA Corporation. All rights reserved.
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA Driver Helper Service, Version 52.16
InternalName : NVSVC
OriginalFilename : nvsvc32.exe
ProductName : NVIDIA Driver Helper Service, Version 52.16
Created on : 10/6/2003 7:16:00 PM
Last accessed : 5/8/2004 11:03:12 PM
Last modified : 10/6/2003 7:16:00 PM
#:26 [nopdb.exe]
FilePath : C:\PROGRA~1\NORTON~2\SPEEDD~1\
ThreadCreationTime : 5/8/2004 11:09:18 PM
BasePriority : Normal
FileSize : 168 KB
FileVersion : 6.03.0.36
ProductVersion : 6.03.0.36
Copyright : Copyright © 2002
CompanyName : Symantec Corporation
FileDescription : NOPDB
InternalName : NOPDB
OriginalFilename : NOPDB.dll
ProductName : Norton Speed Disk
Created on : 8/19/2003 5:33:13 AM
Last accessed : 5/8/2004 11:03:12 PM
Last modified : 1/30/2002 10:00:00 AM
#:27 [wtoolss.exe]
FilePath : C:\Program Files\Common files\WinTools\
ThreadCreationTime : 5/8/2004 11:09:19 PM
BasePriority : Normal
FileSize : 75 KB
Created on : 5/6/2004 3:58:07 AM
Last accessed : 5/8/2004 11:11:28 PM
Last modified : 4/20/2004 12:01:14 PM
#:28 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-aware 6\
ThreadCreationTime : 5/8/2004 11:10:25 PM
BasePriority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 4/13/2004 12:14:27 AM
Last accessed : 5/8/2004 11:15:21 PM
Last modified : 7/13/2003 2:00:20 AM
#:29 [wsup.exe]
FilePath : C:\Program Files\Common files\WinTools\
ThreadCreationTime : 5/8/2004 11:11:27 PM
BasePriority : Normal
FileSize : 429 KB
Created on : 5/6/2004 3:58:03 AM
Last accessed : 5/8/2004 11:11:27 PM
Last modified : 5/3/2004 12:41:40 PM
#:30 [cidaemon.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 5/8/2004 11:15:42 PM
BasePriority : Idle
FileSize : 8 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Indexing Service filter daemon
InternalName : cidaemon.exe
OriginalFilename : cidaemon.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 5/8/2004 11:03:12 PM
Last modified : 8/29/2002 11:00:00 AM
#:31 [cidaemon.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 5/8/2004 11:15:43 PM
BasePriority : Idle
FileSize : 8 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Indexing Service filter daemon
InternalName : cidaemon.exe
OriginalFilename : cidaemon.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 5/8/2004 11:03:12 PM
Last modified : 8/29/2002 11:00:00 AM
#:32 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ThreadCreationTime : 5/8/2004 11:16:32 PM
BasePriority : Normal
FileSize : 89 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
OriginalFilename : IEXPLORE.EXE
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 5/8/2004 11:16:35 PM
Last modified : 8/29/2002 11:00:00 AM
#:33 [explorer.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 5/8/2004 11:19:43 PM
BasePriority : Normal
FileSize : 980 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 5/8/2004 11:19:45 PM
Last modified : 8/29/2002 11:00:00 AM
Memory scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 0
Started registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : BTIEINScriptConfigProj.BTIEINScriptConfig
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{26E8361F-BCE7-4F75-A347-98C88B418322}
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{339BB23F-A864-48C0-A59F-29EA915965EC}
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{63B78BC1-A711-4D46-AD2F-C581AC420D41}
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{8952A998-1E7E-4716-B23D-3DBE03910972}
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{F1616B86-9288-489D-B71A-0CCF2F1A89DA}
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{FF76A5DA-6158-4439-99FF-EDC1B3FE100C}
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{26E8361F-BCE7-4F75-A347-98C88B418321}
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : PROTOCOLS\Handler\tpro
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : PROTOCOLS\Name-Space Handler\res\toolbar.ResProtocol
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\BTIEIN
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\BTIEIN
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{63B78BC1-A711-4D46-AD2F-C581AC420D41}
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8952A998-1E7E-4716-B23D-3DBE03910972}
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : toolbar.ResProtocol
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Typelib\{26E8361F-BCE7-4F75-A347-98C88B418328}
IBIS Toolbar Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
Value : {339BB23F-A864-48C0-A59F-29EA915965EC}
Registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 17
Objects found so far: 17
Started deep registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Barallaboutsearching.com
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "
http://allaboutsearc...searchbar.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "
http://allaboutsearc...searchbar.html"
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\SearchSearchAssistantallaboutsearching.com
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "
http://allaboutsearc...searchbar.html"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Search
Value : SearchAssistant
Data : "
http://allaboutsearc...searchbar.html"
Deep registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 2
Objects found so far: 19
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Deep scanning and examining files (C:)
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
VX2.BetterInternet Object recognized!
Type : File
Data : 2ndsrch.dll
Object : C:\WINDOWS\System32\
FileSize : 309 KB
Created on : 5/1/2004 10:54:45 AM
Last accessed : 5/8/2004 11:08:00 PM
Last modified : 5/1/2004 10:54:45 AM
VX2.BetterInternet Object recognized!
Type : File
Data : 2zdsrch.dll
Object : C:\WINDOWS\System32\
FileSize : 309 KB
Created on : 5/4/2004 9:51:33 PM
Last accessed : 5/8/2004 11:22:15 PM
Last modified : 5/1/2004 10:54:45 AM
VX2.BetterInternet Object recognized!
Type : File
Data : altiveds.dll
Object : C:\WINDOWS\System32\
FileSize : 309 KB
Created on : 5/2/2004 4:41:25 PM
Last accessed : 5/8/2004 11:22:15 PM
Last modified : 5/1/2004 10:54:45 AM
VX2.BetterInternet Object recognized!
Type : File
Data : amvpack.dll
Object : C:\WINDOWS\System32\
FileSize : 309 KB
Created on : 5/5/2004 4:30:36 AM
Last accessed : 5/8/2004 11:22:15 PM
Last modified : 5/1/2004 10:54:45 AM
VX2.BetterInternet Object recognized!
Type : File
Data : aotiveds.dll
Object : C:\WINDOWS\System32\
FileSize : 309 KB
Created on : 5/4/2004 4:02:46 AM
Last accessed : 5/8/2004 11:22:16 PM
Last modified : 5/1/2004 10:54:45 AM
VX2.BetterInternet Object recognized!
Type : File
Data : axsldp.dll
Object : C:\WINDOWS\System32\
FileSize : 309 KB
Created on : 5/6/2004 3:48:20 AM
Last accessed : 5/8/2004 11:22:16 PM
Last modified : 5/1/2004 10:54:45 AM
IBIS Toolbar Object recognized!
Type : File
Data : btiein.dll
Object : C:\WINDOWS\System32\
FileSize : 201 KB
Created on : 5/8/2004 11:17:40 PM
Last accessed : 5/8/2004 11:17:40 PM
Last modified : 5/8/2004 11:17:40 PM
Scanning Hosts file(C:\WINDOWS\System32\drivers\etc\hosts)
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Hosts file scan result:
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
11 entries scanned.
New objects :0
Objects found so far: 26
Performing conditional scans..
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\STO
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TTOOL_UNINSTALL
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\Toolbar
IBIS Toolbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Toolbar
IBIS Toolbar Object recognized!
Type : Folder
Object : c:\program files\Toolbar
IBIS Toolbar Object recognized!
Type : File
Data : cursors
Object : c:\program files\toolbar\
Created on : 5/8/2004 11:17:45 PM
Last accessed : 5/8/2004 11:17:45 PM
Last modified : 5/8/2004 11:17:45 PM
IBIS Toolbar Object recognized!
Type : File
Data : iexploreskins.exe
Object : c:\program files\toolbar\
FileSize : 6 KB
Created on : 5/8/2004 11:17:45 PM
Last accessed : 5/8/2004 11:17:54 PM
Last modified : 3/19/2004 8:21:54 AM
IBIS Toolbar Object recognized!
Type : File
Data : rw.wzg
Object : c:\program files\toolbar\
Created on : 5/8/2004 11:17:53 PM
Last accessed : 5/8/2004 11:17:59 PM
Last modified : 5/8/2004 11:17:59 PM
IBIS Toolbar Object recognized!
Type : File
Data : skins
Object : c:\program files\toolbar\
Created on : 5/8/2004 11:17:45 PM
Last accessed : 5/8/2004 11:17:56 PM
Last modified : 5/8/2004 11:17:55 PM
IBIS Toolbar Object recognized!
Type : File
Data : temp
Object : c:\program files\toolbar\
Created on : 5/8/2004 11:17:54 PM
Last accessed : 5/8/2004 11:17:54 PM
Last modified : 5/8/2004 11:17:54 PM
IBIS Toolbar Object recognized!
Type : File
Data : toolbar.dll
Object : c:\program files\toolbar\
FileSize : 617 KB
Created on : 5/8/2004 11:17:45 PM
Last accessed : 5/8/2004 11:17:45 PM
Last modified : 5/6/2004 2:01:30 PM
IBIS Toolbar Object recognized!
Type : File
Data : xlmurin.wzg
Object : c:\program files\toolbar\
Created on : 5/8/2004 11:17:48 PM
Last accessed : 5/8/2004 11:19:46 PM
Last modified : 5/8/2004 11:19:46 PM
IBIS Toolbar Object recognized!
Type : File
Data : xzxsv.wzg
Object : c:\program files\toolbar\
Created on : 5/8/2004 11:17:53 PM
Last accessed : 5/8/2004 11:17:59 PM
Last modified : 5/8/2004 11:17:59 PM
IBIS Toolbar Object recognized!
Type : File
Data : yildhvi.olt
Object : c:\program files\toolbar\
Created on : 5/8/2004 11:17:56 PM
Last accessed : 5/8/2004 11:18:02 PM
Last modified : 5/8/2004 11:18:02 PM
IBIS Toolbar Object recognized!
Type : File
Data : frequently asked questions.url
Object : c:\documents and settings\all users\start menu\programs\web search tools\
Created on : 5/8/2004 11:17:45 PM
Last accessed : 5/8/2004 11:17:45 PM
Last modified : 5/8/2004 11:17:45 PM
IBIS Toolbar Object recognized!
Type : File
Data : home.url
Object : c:\documents and settings\all users\start menu\programs\web search tools\
Created on : 5/8/2004 11:17:45 PM
Last accessed : 5/8/2004 11:17:45 PM
Last modified : 5/8/2004 11:17:45 PM
IBIS Toolbar Object recognized!
Type : File
Data : privacy policy.url
Object : c:\documents and settings\all users\start menu\programs\web search tools\
Created on : 5/8/2004 11:17:45 PM
Last accessed : 5/8/2004 11:17:45 PM
Last modified : 5/8/2004 11:17:45 PM
IBIS Toolbar Object recognized!
Type : File
Data : terms of use.url
Object : c:\documents and settings\all users\start menu\programs\web search tools\
Created on : 5/8/2004 11:17:45 PM
Last accessed : 5/8/2004 11:17:45 PM
Last modified : 5/8/2004 11:17:45 PM
Conditional scan result:
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 18
Objects found so far: 44
7:22:55 PM Scan complete
Summary of this scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Total scanning time :00:02:51:562
Objects scanned :56478
Objects identified :44
Objects ignored :0
New objects :44
This then initiates another round of browser/homepage hijacking, pop up ads, and total rearranging of my favorites, along with addition of about 30 new ones. Also, it shuts off Norton Antivirus and blocks me from opening any Norton Program. So I reran Ad-aware and cleared everything out. This works temporarily, but if the computer is idle for any length of time, nothing works and I have to reboot and do all this again.
It is truly sad that there are people out there who actually write this kind of crap on purpose. I am thankful for this website and people here who are so willing to help. Thank you.
Zach