Here is my ad-aware log file:
Ad-Aware SE Build 1.05
Logfile Created on:Friday, April 22, 2005 4:31:12 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R40 20.04.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
180Solutions(TAC index:6):4 total references
Adintelligence.AproposToolbar(TAC index:5):1 total references
AdRotator(TAC index:6):10 total references
ClearSearch(TAC index:7):266 total references
DealHelper(TAC index:7):8 total references
Ebates MoneyMaker(TAC index:4):1 total references
Elitum.ElitebarBHO(TAC index:5):24 total references
eUniverse(TAC index:10):2 total references
Favoriteman(TAC index:8):4 total references
IBIS Toolbar(TAC index:5):28 total references
MRU List(TAC index:0):33 total references
PeopleOnPage(TAC index:9):13 total references
Possible Browser Hijack attempt(TAC index:3):5 total references
SahAgent(TAC index:9):8 total references
Tracking Cookie(TAC index:3):65 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Definition File:
=========================
Definitions File Loaded:
Reference Number : SE1R40 20.04.2005
Internal build : 47
File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
File size : 461235 Bytes
Total size : 1395231 Bytes
Signature data size : 1364710 Bytes
Reference data size : 30009 Bytes
Signatures total : 38921
Fingerprints total : 813
Fingerprints size : 29073 Bytes
Target categories : 15
Target families : 650
Memory + processor status:
==========================
Number of processors : 1
Processor architecture : Intel Pentium IV
Memory available:40 %
Total physical memory:253424 kb
Available physical memory:99788 kb
Total page file size:620964 kb
Available on page file:404300 kb
Total virtual memory:2097024 kb
Available virtual memory:2042220 kb
OS:Microsoft Windows XP Professional Service Pack 2 (Build 2600)
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Move deleted files to Recycle Bin
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Obtain command line of scanned processes
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Write-protect system files after repair (Hosts file, etc.)
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
4-22-2005 4:31:12 PM - Scan started. (Custom mode)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
ModuleName : \SystemRoot\System32\smss.exe
Command Line : n/a
ProcessID : 468
ThreadCreationTime : 4-22-2005 9:19:51 PM
BasePriority : Normal
#:2 [csrss.exe]
ModuleName : \??\C:\WINDOWS\system32\csrss.exe
Command Line : C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestTh
ProcessID : 524
ThreadCreationTime : 4-22-2005 9:19:52 PM
BasePriority : Normal
#:3 [winlogon.exe]
ModuleName : \??\C:\WINDOWS\system32\winlogon.exe
Command Line : winlogon.exe
ProcessID : 548
ThreadCreationTime : 4-22-2005 9:19:52 PM
BasePriority : High
#:4 [services.exe]
ModuleName : C:\WINDOWS\system32\services.exe
Command Line : C:\WINDOWS\system32\services.exe
ProcessID : 592
ThreadCreationTime : 4-22-2005 9:19:53 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
#:5 [lsass.exe]
ModuleName : C:\WINDOWS\system32\lsass.exe
Command Line : C:\WINDOWS\system32\lsass.exe
ProcessID : 604
ThreadCreationTime : 4-22-2005 9:19:53 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
ModuleName : C:\WINDOWS\system32\svchost.exe
Command Line : C:\WINDOWS\system32\svchost -k DcomLaunch
ProcessID : 788
ThreadCreationTime : 4-22-2005 9:19:53 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
ModuleName : C:\WINDOWS\system32\svchost.exe
Command Line : C:\WINDOWS\system32\svchost -k rpcss
ProcessID : 844
ThreadCreationTime : 4-22-2005 9:19:53 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k netsvcs
ProcessID : 908
ThreadCreationTime : 4-22-2005 9:19:53 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k NetworkService
ProcessID : 964
ThreadCreationTime : 4-22-2005 9:19:53 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k LocalService
ProcessID : 1088
ThreadCreationTime : 4-22-2005 9:19:54 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:11 [spoolsv.exe]
ModuleName : C:\WINDOWS\system32\spoolsv.exe
Command Line : C:\WINDOWS\system32\spoolsv.exe
ProcessID : 1192
ThreadCreationTime : 4-22-2005 9:19:54 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:12 [kodakccs.exe]
ModuleName : C:\WINDOWS\system32\drivers\KodakCCS.exe
Command Line : C:\WINDOWS\system32\drivers\KodakCCS.exe
ProcessID : 1376
ThreadCreationTime : 4-22-2005 9:19:57 PM
BasePriority : Normal
FileVersion : 1.1.5100.4
ProductVersion : 4.4.0.0
ProductName : Kodak DC File System Driver (Win32)
CompanyName : Eastman Kodak Company
FileDescription : Kodak DC Ring 3 Conduit (Win32)
InternalName : KodakCCS.exe
LegalCopyright : Copyright © Eastman Kodak Co. 2000-2004
OriginalFilename : DcFsSvc.exe
#:13 [alg.exe]
ModuleName : C:\WINDOWS\System32\alg.exe
Command Line : C:\WINDOWS\System32\alg.exe
ProcessID : 1936
ThreadCreationTime : 4-22-2005 9:20:01 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe
#:14 [explorer.exe]
ModuleName : C:\WINDOWS\Explorer.EXE
Command Line : C:\WINDOWS\Explorer.EXE
ProcessID : 392
ThreadCreationTime : 4-22-2005 9:20:02 PM
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
Warning! ClearSearch Object found in memory(C:\Program Files\84hjm1oq\84hjm1oq.DLL)
ClearSearch Object Recognized!
Type : Process
Data : 84hjm1oq.DLL
Category : Data Miner
Comment :
Object : C:\Program Files\84hjm1oq\
FileVersion : 1.83.0.5
ProductVersion : 1.83.0.5
InternalName : Grip.dll
OriginalFilename : Grip.dll
Comments : Build 83 E
#:15 [pccntmon.exe]
ModuleName : C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
Command Line : "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
ProcessID : 1256
ThreadCreationTime : 4-22-2005 9:20:08 PM
BasePriority : Normal
FileVersion : 5.58.0.1063
ProductVersion : 5.58
ProductName : Trend Micro OfficeScan
CompanyName : Trend Micro Inc.
FileDescription : I/O Monitor
InternalName : PCCNTMON
LegalCopyright : Copyright © 1999-2004 Trend Micro Incorporated. All rights reserved.
LegalTrademarks : Copyright © Trend Micro, Inc.
OriginalFilename : PCCNTMON.EXE
Warning! ClearSearch Object found in memory(C:\Program Files\84hjm1oq\84hjm1oq.DLL)
ClearSearch Object Recognized!
Type : Process
Data : 84hjm1oq.DLL
Category : Data Miner
Comment :
Object : C:\Program Files\84hjm1oq\
FileVersion : 1.83.0.5
ProductVersion : 1.83.0.5
InternalName : Grip.dll
OriginalFilename : Grip.dll
Comments : Build 83 E
"C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe"Process terminated successfully
#:16 [qttask.exe]
ModuleName : C:\Program Files\QuickTime\qttask.exe
Command Line : "C:\Program Files\QuickTime\qttask.exe" -atboottime
ProcessID : 1260
ThreadCreationTime : 4-22-2005 9:20:09 PM
BasePriority : Normal
FileVersion : 6.4
ProductVersion : QuickTime 6.4
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2003
OriginalFilename : QTTask.exe
Warning! ClearSearch Object found in memory(C:\Program Files\84hjm1oq\84hjm1oq.DLL)
ClearSearch Object Recognized!
Type : Process
Data : 84hjm1oq.DLL
Category : Data Miner
Comment :
Object : C:\Program Files\84hjm1oq\
FileVersion : 1.83.0.5
ProductVersion : 1.83.0.5
InternalName : Grip.dll
OriginalFilename : Grip.dll
Comments : Build 83 E
"C:\Program Files\QuickTime\qttask.exe"Process terminated successfully
#:17 [igfxtray.exe]
ModuleName : C:\WINDOWS\System32\igfxtray.exe
Command Line : "C:\WINDOWS\System32\igfxtray.exe"
ProcessID : 1240
ThreadCreationTime : 4-22-2005 9:20:09 PM
BasePriority : Normal
FileVersion : 3.0.0.3889
ProductVersion : 7.0.0.3889
ProductName : Intel® Common User Interface
CompanyName : Intel Corporation
FileDescription : igfxTray Module
InternalName : IGFXTRAY
LegalCopyright : Copyright 1999-2002, Intel Corporation
OriginalFilename : IGFXTRAY.EXE
Warning! ClearSearch Object found in memory(C:\Program Files\84hjm1oq\84hjm1oq.DLL)
ClearSearch Object Recognized!
Type : Process
Data : 84hjm1oq.DLL
Category : Data Miner
Comment :
Object : C:\Program Files\84hjm1oq\
FileVersion : 1.83.0.5
ProductVersion : 1.83.0.5
InternalName : Grip.dll
OriginalFilename : Grip.dll
Comments : Build 83 E
"C:\WINDOWS\System32\igfxtray.exe"Process terminated successfully
#:18 [hkcmd.exe]
ModuleName : C:\WINDOWS\System32\hkcmd.exe
Command Line : "C:\WINDOWS\System32\hkcmd.exe"
ProcessID : 1312
ThreadCreationTime : 4-22-2005 9:20:09 PM
BasePriority : Normal
FileVersion : 3.0.0.3889
ProductVersion : 7.0.0.3889
ProductName : Intel® Common User Interface
CompanyName : Intel Corporation
FileDescription : hkcmd Module
InternalName : HKCMD
LegalCopyright : Copyright 1999-2002, Intel Corporation
OriginalFilename : HKCMD.EXE
Warning! ClearSearch Object found in memory(C:\Program Files\84hjm1oq\84hjm1oq.DLL)
ClearSearch Object Recognized!
Type : Process
Data : 84hjm1oq.DLL
Category : Data Miner
Comment :
Object : C:\Program Files\84hjm1oq\
FileVersion : 1.83.0.5
ProductVersion : 1.83.0.5
InternalName : Grip.dll
OriginalFilename : Grip.dll
Comments : Build 83 E
"C:\WINDOWS\System32\hkcmd.exe"Process terminated successfully
#:19 [alcxmntr.exe]
ModuleName : C:\WINDOWS\ALCXMNTR.EXE
Command Line : "C:\WINDOWS\ALCXMNTR.EXE"
ProcessID : 1324
ThreadCreationTime : 4-22-2005 9:20:09 PM
BasePriority : Normal
FileVersion : 1.5
ProductVersion : 1.5
ProductName : Realtek Audio - Event Monitor
CompanyName : Realtek Semiconductor Corp.
FileDescription : Realtek Audio - Event Monitor
InternalName : Alcxmntr
LegalCopyright : Copyright © 2004 Realtek Semiconductor Corp.
OriginalFilename : Alcxmntr.exe
Warning! ClearSearch Object found in memory(C:\Program Files\84hjm1oq\84hjm1oq.DLL)
ClearSearch Object Recognized!
Type : Process
Data : 84hjm1oq.DLL
Category : Data Miner
Comment :
Object : C:\Program Files\84hjm1oq\
FileVersion : 1.83.0.5
ProductVersion : 1.83.0.5
InternalName : Grip.dll
OriginalFilename : Grip.dll
Comments : Build 83 E
"C:\WINDOWS\ALCXMNTR.EXE"Process terminated successfully
#:20 [realsched.exe]
ModuleName : C:\Program Files\Common Files\Real\Update_OB\realsched.exe
Command Line : "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
ProcessID : 1432
ThreadCreationTime : 4-22-2005 9:20:11 PM
BasePriority : Normal
FileVersion : 0.1.0.3034
ProductVersion : 0.1.0.3034
ProductName : RealPlayer (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
LegalTrademarks : RealAudio is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe
Warning! ClearSearch Object found in memory(C:\Program Files\84hjm1oq\84hjm1oq.DLL)
ClearSearch Object Recognized!
Type : Process
Data : 84hjm1oq.DLL
Category : Data Miner
Comment :
Object : C:\Program Files\84hjm1oq\
FileVersion : 1.83.0.5
ProductVersion : 1.83.0.5
InternalName : Grip.dll
OriginalFilename : Grip.dll
Comments : Build 83 E
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"Process terminated successfully
#:21 [84hjm1oq.exe]
ModuleName : C:\Program Files\84hjm1oq\84hjm1oq.exe
Command Line : "C:\Program Files\84hjm1oq\84hjm1oq.exe"
ProcessID : 1700
ThreadCreationTime : 4-22-2005 9:20:12 PM
BasePriority : Normal
FileVersion : 1, 13, 0, 5
ProductVersion : 1, 13, 0, 5
Warning! ClearSearch Object found in memory(C:\Program Files\84hjm1oq\84hjm1oq.exe)
ClearSearch Object Recognized!
Type : Process
Data : 84hjm1oq.exe
Category : Data Miner
Comment :
Object : C:\Program Files\84hjm1oq\
FileVersion : 1, 13, 0, 5
ProductVersion : 1, 13, 0, 5
"C:\Program Files\84hjm1oq\84hjm1oq.exe"Process terminated successfully
"C:\Program Files\84hjm1oq\84hjm1oq.exe"Process terminated successfully
#:22 [tmlisten.exe]
ModuleName : C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
Command Line : "C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe"
ProcessID : 1744
ThreadCreationTime : 4-22-2005 9:20:12 PM
BasePriority : Normal
#:23 [easyshare.exe]
ModuleName : C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
Command Line : "C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" -h
ProcessID : 1880
ThreadCreationTime : 4-22-2005 9:20:14 PM
BasePriority : Normal
FileVersion : 5, 0, 4, 128
ProductVersion : 4, 0, 2, 134
ProductName : Kodak EasyShare software
CompanyName : Eastman Kodak Company
FileDescription : Kodak EasyShare software
InternalName : EasyShare
LegalCopyright : Copyright © Eastman Kodak Company 2002
LegalTrademarks : EasyShare
OriginalFilename : EasyShare.exe
Warning! ClearSearch Object found in memory(C:\Program Files\84hjm1oq\84hjm1oq.DLL)
ClearSearch Object Recognized!
Type : Process
Data : 84hjm1oq.DLL
Category : Data Miner
Comment :
Object : C:\Program Files\84hjm1oq\
FileVersion : 1.83.0.5
ProductVersion : 1.83.0.5
InternalName : Grip.dll
OriginalFilename : Grip.dll
Comments : Build 83 E
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe"Process terminated successfully
#:24 [ntrtscan.exe]
ModuleName : C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
Command Line : "C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe"
ProcessID : 1892
ThreadCreationTime : 4-22-2005 9:20:14 PM
BasePriority : Normal
FileVersion : 5.58.0.1063
ProductVersion : 5.58
ProductName : Trend Micro OfficeScan
CompanyName : Trend Micro Inc.
LegalCopyright : Copyright © 1999-2004 Trend Micro Incorporated. All rights reserved.
LegalTrademarks : Copyright © Trend Micro, Inc.
#:25 [kodak software updater.exe]
ModuleName : C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
Command Line : "C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe"
ProcessID : 1932
ThreadCreationTime : 4-22-2005 9:20:14 PM
BasePriority : Normal
Warning! ClearSearch Object found in memory(C:\Program Files\84hjm1oq\84hjm1oq.DLL)
ClearSearch Object Recognized!
Type : Process
Data : 84hjm1oq.DLL
Category : Data Miner
Comment :
Object : C:\Program Files\84hjm1oq\
FileVersion : 1.83.0.5
ProductVersion : 1.83.0.5
InternalName : Grip.dll
OriginalFilename : Grip.dll
Comments : Build 83 E
#:26 [89364919.exe]
ModuleName : C:\Program Files\84hjm1oq\89364919.exe
Command Line : a b
ProcessID : 2016
ThreadCreationTime : 4-22-2005 9:20:24 PM
BasePriority : Normal
Warning! ClearSearch Object found in memory(C:\Program Files\84hjm1oq\89364919.exe)
ClearSearch Object Recognized!
Type : Process
Data : 89364919.exe
Category : Data Miner
Comment :
Object : C:\Program Files\84hjm1oq\
"C:\Program Files\84hjm1oq\89364919.exe"Process terminated successfully
"C:\Program Files\84hjm1oq\89364919.exe"Process terminated successfully
#:27 [ofcdog.exe]
ModuleName : C:\Program Files\Trend Micro\OfficeScan Client\ofcdog.exe
Command Line : "C:\Program Files\Trend Micro\OfficeScan Client\ofcdog.exe"
ProcessID : 932
ThreadCreationTime : 4-22-2005 9:20:56 PM
BasePriority : Normal
#:28 [pccntupd.exe]
ModuleName : C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe
Command Line : "C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe"
ProcessID : 1544
ThreadCreationTime : 4-22-2005 9:21:03 PM
BasePriority : Normal
#:29 [ad-aware.exe]
ModuleName : C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
Command Line : "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe"
ProcessID : 2920
ThreadCreationTime : 4-22-2005 9:22:27 PM
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Warning! ClearSearch Object found in memory(C:\Program Files\84hjm1oq\84hjm1oq.DLL)
ClearSearch Object Recognized!
Type : Process
Data : 84hjm1oq.DLL
Category : Data Miner
Comment :
Object : C:\Program Files\84hjm1oq\
FileVersion : 1.83.0.5
ProductVersion : 1.83.0.5
InternalName : Grip.dll
OriginalFilename : Grip.dll
Comments : Build 83 E
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 2
Objects found so far: 12
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
AdRotator Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{1cfb8b32-4053-4144-af6f-1540eec7f101}
AdRotator Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{1cfb8b32-4053-4144-af6f-1540eec7f101}
Value :
Elitum.ElitebarBHO Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{a9b28ef6-abf3-463b-a3d8-4d0d0badfadc}
Elitum.ElitebarBHO Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{a9b28ef6-abf3-463b-a3d8-4d0d0badfadc}
Value :
Elitum.ElitebarBHO Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{dbf33e89-1784-42ac-ade4-a428f56550a3}
Elitum.ElitebarBHO Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{dbf33e89-1784-42ac-ade4-a428f56550a3}
Value :
Elitum.ElitebarBHO Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{ca9fc31a-6f35-4493-b629-e64bd6170a17}\1.0
Elitum.ElitebarBHO Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{ca9fc31a-6f35-4493-b629-e64bd6170a17}\1.0
Value :
Elitum.ElitebarBHO Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{ca9fc31a-6f35-4493-b629-e64bd6170a17}
Elitum.ElitebarBHO Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{0a1d22c3-37be-470c-9c29-e3074ee0574b}
PeopleOnPage Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-1720583248-1557856872-312552118-1419\software\apropos
Ebates MoneyMaker Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment : "AC"
Rootkey : HKEY_USERS
Object : S-1-5-21-1720583248-1557856872-312552118-1419\software\lq
Value : AC
Elitum.ElitebarBHO Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment : "{825CF5BD-8862-4430-B771-0C15C5CA8DEF}"
Rootkey : HKEY_USERS
Object : S-1-5-21-1720583248-1557856872-312552118-1419\software\microsoft\internet explorer\toolbar\webbrowser
Value : {825CF5BD-8862-4430-B771-0C15C5CA8DEF}
Favoriteman Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment : "Counter"
Rootkey : HKEY_USERS
Object : S-1-5-21-1720583248-1557856872-312552118-1419\software\microsoft\windows
Value : Counter
Favoriteman Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment : "Server"
Rootkey : HKEY_USERS
Object : S-1-5-21-1720583248-1557856872-312552118-1419\software\microsoft\windows
Value : Server
Favoriteman Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment : "Object"
Rootkey : HKEY_USERS
Object : S-1-5-21-1720583248-1557856872-312552118-1419\software\microsoft\windows
Value : Object
Elitum.ElitebarBHO Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment : "{28CAEFF3-0F18-4036-B504-51D73BD81ABC}"
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\explorer\browser helper objects
Value : {28CAEFF3-0F18-4036-B504-51D73BD81ABC}
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 17
Objects found so far: 29
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Possible Browser Hijack attempt : S-1-5-21-1720583248-1557856872-312552118-1419\Software\Microsoft\Internet Explorer\MainSearch Pagesearchmiracle.com
Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "http://searchmiracle.com/sp.php"
Category : Data Miner
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_USERS
Object : S-1-5-21-1720583248-1557856872-312552118-1419\Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "http://searchmiracle.com/sp.php"
Possible Browser Hijack attempt : S-1-5-21-1720583248-1557856872-312552118-1419\Software\Microsoft\Internet ExplorerSearchURLsearchmiracle.com
Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "http://searchmiracle.com/sp.php"
Category : Data Miner
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_USERS
Object : S-1-5-21-1720583248-1557856872-312552118-1419\Software\Microsoft\Internet Explorer
Value : SearchURL
Data : "http://searchmiracle.com/sp.php"
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{022CF774-8F65-4A73-9B52-75898E78D31D}
ClearSearch Object Recognized!
Type : File
Data : 84hjm1oq.dll
Category : Data Miner
Comment :
Object : c:\program files\84hjm1oq\
FileVersion : 1.83.0.5
ProductVersion : 1.83.0.5
InternalName : Grip.dll
OriginalFilename : Grip.dll
Comments : Build 83 E
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{0275BDB3-D8AA-49F5-B0EA-18E4A7D4F989}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{053774E6-DDF2-4FE8-A282-5B4289A81E0F}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{056434CF-3192-4203-83CF-BD14EF798CAC}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{065DAF9C-80DA-4C0F-A1B8-E22D44E7DD83}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{07BCBD35-4823-496D-8C44-86A16E722056}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{0B98BD01-8282-43AA-B525-C087FDDA4DE1}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{0F193C05-F46B-4C24-9E02-57D2BCBC4ED5}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{1032120B-CAE8-4BC8-AA06-CD96055D3718}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{1203B831-A395-4AD6-B322-246DAA5043D8}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{1255F911-6403-44CA-97B9-A128FA165346}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{148C2E33-CDFF-46A8-ADAE-A3E86B4AAC96}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{200ADA76-8B38-4E61-B21F-CA834F952BA0}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{2481D29E-A64B-4B87-9EA6-3FE2C6406C5E}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{251B8B81-A70A-401E-9910-AE3F16C9525D}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{2AA93495-1426-4BFD-836E-3995C5F28311}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{2D0EEA51-3B28-4C7B-943C-A20237CCD1B7}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{2EF25180-F159-46F2-A983-610159DC27DF}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{2F75A37C-13A2-4575-B6C0-CE224A447B1B}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{31CA3CC8-E787-41AE-87FB-BFFC67095FA9}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{34EBA5AC-C5A0-442E-A15F-6D9BA1106BF6}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{3BEDAC46-D28D-41FC-AE0A-7BD624D214E9}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{423F833C-8696-48A4-82D3-F6ED037DE439}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{460C32D9-8915-4B58-98C5-58BB5742E567}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{5457DD25-B3D9-4963-A9C8-19EAD64F2FA0}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{5A329E52-8DD2-4D7C-99AF-EDFC074FB62C}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{5DF4B08F-1493-4E07-B9FD-EDDA69AF2F2D}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{5F0C4815-D864-4337-9BCB-BAFB854972CC}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{5F7F9DD4-DEA3-4987-91B3-0B26E7015F86}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{60F4039B-3CCA-4440-A19F-B2618BBD4E0C}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{61993B37-5603-4E3E-B920-5FCF04F7B176}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{61A6143A-0D0F-4A72-BC26-F9FAEC886B18}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{68C028FC-9C2F-4588-9B86-6AE1DEC798E2}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{72028FD1-F11F-4CE7-B47F-80078F3EFF96}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{72431A11-6AD9-4DDA-8F6F-F017C3E05326}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{731F4D97-BC07-43AA-8FC3-6C8F1347EAE1}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{86D7715E-7275-4F3A-A336-3E5B638D0832}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{8A9FA2D2-4C58-417C-A285-D6470F064761}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{92D2D76F-BD0E-42A1-8B88-0333BF3DB196}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{92E16F2F-3547-4AB3-95B0-7600A8E83B99}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{93DD81F7-4F21-413C-9F77-B76AA3C81274}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{9AFE162C-442F-4C65-9CC6-F14508E3B947}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{9CF68115-D568-4CE0-A72E-7B899DA855A4}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{A1BF837D-8AFA-4C63-8E02-2EB5EFCF4C32}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{A1DF6B1E-C2E2-4313-B4BE-0137761D0BEF}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{AD98BEA1-89B1-4433-B8A6-FE6E400E3CCF}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{AD9AE70E-B027-43BD-9618-0864398D1254}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{B0DAE697-F28F-4143-8B4A-F1459989D38D}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{B9C17B99-645F-4355-BEB2-2EED8ED4E6AF}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{BD9D5A85-87F6-43D8-9A2A-3A1374FC7F9B}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{C54A0161-4A65-47A5-9A89-70F24FC4DB3A}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{C71F0D52-FC57-409A-BB3B-34E399EE687F}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{C858A7CB-C18D-4C14-AE6A-E71398716A1C}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{CC8FA8E6-0273-4DF9-BE27-AB0603A14E82}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{D8F1C554-79E1-497B-9DA1-A104FF096F38}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{DCA9F447-23A9-4F99-B40D-81C0EAF4ADBF}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{E19B9F26-5E0F-4FA5-B8DE-42B2FD1ECE11}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{EB284001-E360-4CCF-B5FF-79C529B336D4}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{ED95BF55-5B1C-490E-94E8-194A99AA3ECE}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{EE319F8F-4D8B-46FC-B949-C6A19D52CAA9}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{FF4B04DD-71D2-4714-995C-6C3E15FEC8F0}
ClearSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : C:\Program Files\84hjm1oq\84hjm1oq.dll
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{FFFEABD4-EBB2-4916-84A8-4A560FB964BC}
AdRotator Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment : "ecdqmc"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Run
Value : ecdqmc
AdRotator Object Recognized!
Type : File
Data : ecdqmc.exe
Category : Malware
Comment :
Object : c:\windows\system32\
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
ProductName : localFilemove Application
FileDescription : localFilemove MFC Application
InternalName : localFilemove
LegalCopyright : Copyright © 2004
OriginalFilename : localFilemove.EXE
AdRotator Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment : "rvtwuc"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Run
Value : rvtwuc
AdRotator Object Recognized!
Type : File
Data : rvtwuc.exe
Category : Malware
Comment :
Object : c:\windows\system32\
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
ProductName : localFilemove Application
FileDescription : localFilemove MFC Application
InternalName : localFilemove
LegalCopyright : Copyright © 2004
OriginalFilename : localFilemove.EXE
ClearSearch Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment : "84hjm1oq"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Run
Value : 84hjm1oq
ClearSearch Object Recognized!
Type : File
Data : 84hjm1oq.exe
Category : Data Miner
Comment :
Object : c:\program files\84hjm1oq\
FileVersion : 1, 13, 0, 5
ProductVersion : 1, 13, 0, 5
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 67
Objects found so far: 100
MRU List Object Recognized!
Location: : C:\Documents and Settings\afiegel\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office
MRU List Object Recognized!
Location: : C:\Documents and Settings\afiegel\recent
Description : list of recently opened documents
MRU List Object Recognized!
Location: : S-1-5-21-1720583248-1557856872-312552118-1419\software\nico mak computing\winzip\filemenu
Description : winzip recently used archives
MRU List Object Recognized!<