I keep seeing 2 small ad popup window appear every few minutes. They both are entitled "- -" and I have tried everything I can think of to get rid of them. I am also seeing messages from one of my security programs saying I have an infected file named "Nail.exe" in my Windows folder.
I have tried using the following under Safe Mode: Spysweeper, Spywareblaster, Spywareguard, Spybot S&D, AdAware SE, and Ewido Security Suite. None seem to be effective in permanently removing this nuisance.
Here is my AdAware log file:
Ad-Aware SE Build 1.05
Logfile Created on:Tuesday, April 26, 2005 11:41:13 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R41 25.04.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie(TAC index:3):1 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Definition File:
=========================
Definitions File Loaded:
Reference Number : SE1R41 25.04.2005
Internal build : 48
File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
File size : 462131 Bytes
Total size : 1397647 Bytes
Signature data size : 1367126 Bytes
Reference data size : 30009 Bytes
Signatures total : 39003
Fingerprints total : 816
Fingerprints size : 28835 Bytes
Target categories : 15
Target families : 650
Memory + processor status:
==========================
Number of processors : 1
Processor architecture : Non Intel
Memory available:33 %
Total physical memory:523184 kb
Available physical memory:170176 kb
Total page file size:1277160 kb
Available on page file:943664 kb
Total virtual memory:2097024 kb
Available virtual memory:2044200 kb
OS:Microsoft Windows XP Home Edition Service Pack 1 (Build 2600)
Ad-Aware SE Settings
===========================
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Obtain command line of scanned processes
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Write-protect system files after repair (Hosts file, etc.)
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Play sound at scan completion if scan locates critical objects
4-26-2005 11:41:13 PM - Scan started. (Full System Scan)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
ModuleName : \SystemRoot\System32\smss.exe
Command Line : n/a
ProcessID : 644
ThreadCreationTime : 4-26-2005 11:01:48 PM
BasePriority : Normal
#:2 [csrss.exe]
ModuleName : \??\C:\WINDOWS\system32\csrss.exe
Command Line : C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestTh
ProcessID : 744
ThreadCreationTime : 4-26-2005 11:01:51 PM
BasePriority : Normal
#:3 [winlogon.exe]
ModuleName : \??\C:\WINDOWS\system32\winlogon.exe
Command Line : winlogon.exe
ProcessID : 804
ThreadCreationTime : 4-26-2005 11:02:01 PM
BasePriority : High
#:4 [services.exe]
ModuleName : C:\WINDOWS\system32\services.exe
Command Line : C:\WINDOWS\system32\services.exe
ProcessID : 848
ThreadCreationTime : 4-26-2005 11:02:02 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
#:5 [lsass.exe]
ModuleName : C:\WINDOWS\system32\lsass.exe
Command Line : C:\WINDOWS\system32\lsass.exe
ProcessID : 860
ThreadCreationTime : 4-26-2005 11:02:02 PM
BasePriority : Normal
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
ModuleName : C:\WINDOWS\system32\svchost.exe
Command Line : C:\WINDOWS\system32\svchost -k rpcss
ProcessID : 1028
ThreadCreationTime : 4-26-2005 11:02:03 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k netsvcs
ProcessID : 1128
ThreadCreationTime : 4-26-2005 11:02:03 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [s24evmon.exe]
ModuleName : C:\WINDOWS\System32\S24EvMon.exe
Command Line : C:\WINDOWS\System32\S24EvMon.exe
ProcessID : 1192
ThreadCreationTime : 4-26-2005 11:02:03 PM
BasePriority : Normal
FileVersion : 8, 0, 0, 161
ProductVersion : 8, 0, 0, 161
ProductName : Mobile Unit Support Service
CompanyName : Intel Corporation
FileDescription : Event Monitor - Supports driver extensions to NIC Driver for wireless adapters.
InternalName : S24EvMon
LegalCopyright : Copyright © 2001 - 2003 Intel Corporation, 1997 - 2001 Symbol Technologies, Inc. Portions Copyright © MIT
OriginalFilename : S24EvMon.exe
#:9 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k NetworkService
ProcessID : 1432
ThreadCreationTime : 4-26-2005 11:02:05 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k LocalService
ProcessID : 1464
ThreadCreationTime : 4-26-2005 11:02:05 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:11 [ccsetmgr.exe]
ModuleName : C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
Command Line : "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
ProcessID : 1636
ThreadCreationTime : 4-26-2005 11:02:07 PM
BasePriority : Normal
FileVersion : 2.1.0.610
ProductVersion : 2.1.0.610
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client Settings Manager Service
InternalName : ccSetMgr
LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved.
OriginalFilename : ccSetMgr.exe
#:12 [ccevtmgr.exe]
ModuleName : C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
Command Line : "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
ProcessID : 1656
ThreadCreationTime : 4-26-2005 11:02:07 PM
BasePriority : Normal
FileVersion : 2.1.0.610
ProductVersion : 2.1.0.610
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client Event Manager Service
InternalName : ccEvtMgr
LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved.
OriginalFilename : ccEvtMgr.exe
#:13 [spoolsv.exe]
ModuleName : C:\WINDOWS\system32\spoolsv.exe
Command Line : C:\WINDOWS\system32\spoolsv.exe
ProcessID : 1792
ThreadCreationTime : 4-26-2005 11:02:08 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:14 [btwdins.exe]
ModuleName : C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
Command Line : "C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe"
ProcessID : 1912
ThreadCreationTime : 4-26-2005 11:02:14 PM
BasePriority : Normal
FileVersion : 1.4.2 Build 10
ProductVersion : 1.4.2 Build 10
ProductName : Bluetooth Software 1.4.2 Build 10
CompanyName : WIDCOMM, Inc.
FileDescription : Bluetooth Support Server
InternalName : BTWDIns
LegalCopyright : Copyright WIDCOMM, Inc. 2000-2003.
OriginalFilename : BTWDIns.EXE
#:15 [cfsvcs.exe]
ModuleName : C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
Command Line : "C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe"
ProcessID : 1924
ThreadCreationTime : 4-26-2005 11:02:14 PM
BasePriority : Normal
FileVersion : 4, 50, 0, 2
ProductVersion : 4, 50, 0, 0
ProductName : ConfigFree
CompanyName : TOSHIBA CORPORATION
FileDescription : Service of ConfigFree.
InternalName : CFSvcs.exe
LegalCopyright : Copyright © 2003 TOSHIBA CORPORATION. All rights reserved.
LegalTrademarks : ConfigFree
OriginalFilename : CFSvcs.exe
Comments : Service of ConfigFree.
#:16 [dvdramsv.exe]
ModuleName : C:\WINDOWS\System32\DVDRAMSV.exe
Command Line : C:\WINDOWS\System32\DVDRAMSV.exe
ProcessID : 1960
ThreadCreationTime : 4-26-2005 11:02:14 PM
BasePriority : Normal
FileVersion : 2, 0, 7, 0
ProductVersion : 2, 0, 7, 0
CompanyName : Matsushita Electric Industrial Co., Ltd.
FileDescription : Service of RAMAsst for Windows XP
LegalCopyright : Copyright © Matsushita Electric Industrial Co., Ltd. 2002 - 2003
OriginalFilename : DVDRAMSV.EXE
#:17 [ewidoctrl.exe]
ModuleName : C:\Program Files\ewido\security suite\ewidoctrl.exe
Command Line : "C:\Program Files\ewido\security suite\ewidoctrl.exe"
ProcessID : 1988
ThreadCreationTime : 4-26-2005 11:02:14 PM
BasePriority : Normal
FileVersion : 3, 0, 0, 1
ProductVersion : 3, 0, 0, 1
ProductName : ewido control
CompanyName : ewido networks
FileDescription : ewido control
InternalName : ewido control
LegalCopyright : Copyright © 2004
OriginalFilename : ewidoctrl.exe
#:18 [ewidoguard.exe]
ModuleName : C:\Program Files\ewido\security suite\ewidoguard.exe
Command Line : n/a
ProcessID : 2000
ThreadCreationTime : 4-26-2005 11:02:14 PM
BasePriority : Normal
FileVersion : 3, 0, 0, 1
ProductVersion : 3, 0, 0, 1
ProductName : guard
CompanyName : ewido networks
FileDescription : guard
InternalName : guard
LegalCopyright : Copyright © 2004
OriginalFilename : guard.exe
#:19 [mdm.exe]
ModuleName : C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
Command Line : "C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"
ProcessID : 160
ThreadCreationTime : 4-26-2005 11:02:15 PM
BasePriority : Normal
FileVersion : 7.00.9064.9150
ProductVersion : 7.00.9064.9150
ProductName : Microsoft Development Environment
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : Copyright © Microsoft Corp. 1997-2000
OriginalFilename : mdm.exe
#:20 [navapsvc.exe]
ModuleName : C:\Program Files\Norton AntiVirus\navapsvc.exe
Command Line : "C:\Program Files\Norton AntiVirus\navapsvc.exe"
ProcessID : 216
ThreadCreationTime : 4-26-2005 11:02:15 PM
BasePriority : Normal
FileVersion : 10.00.2
ProductVersion : 10.00.2
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
LegalCopyright : Norton AntiVirus 2004 for Windows 98/ME/2000/XP Copyright © 2003 Symantec Corporation. All rights reserved.
OriginalFilename : NAVAPSVC.EXE
#:21 [nvsvc32.exe]
ModuleName : C:\WINDOWS\System32\nvsvc32.exe
Command Line : C:\WINDOWS\System32\nvsvc32.exe
ProcessID : 240
ThreadCreationTime : 4-26-2005 11:02:18 PM
BasePriority : Normal
FileVersion : 6.14.10.4562
ProductVersion : 6.14.10.4562
ProductName : NVIDIA Driver Helper Service, Version 45.62
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA Driver Helper Service, Version 45.62
InternalName : NVSVC
LegalCopyright : © NVIDIA Corporation. All rights reserved.
OriginalFilename : nvsvc32.exe
#:22 [regsrvc.exe]
ModuleName : C:\WINDOWS\System32\RegSrvc.exe
Command Line : C:\WINDOWS\System32\RegSrvc.exe
ProcessID : 292
ThreadCreationTime : 4-26-2005 11:02:18 PM
BasePriority : Normal
FileVersion : 8, 0, 0, 161
ProductVersion : 8, 0, 0, 161
ProductName : RegSrvc Module
CompanyName : Intel Corporation
FileDescription : RegSrvc Module
InternalName : RegSrvc
LegalCopyright : Copyright © 2002 - 2003 Intel Corporation
OriginalFilename : RegSrvc.EXE
#:23 [savscan.exe]
ModuleName : C:\Program Files\Norton AntiVirus\SAVScan.exe
Command Line : "C:\Program Files\Norton AntiVirus\SAVScan.exe"
ProcessID : 320
ThreadCreationTime : 4-26-2005 11:02:19 PM
BasePriority : Normal
FileVersion : 9.2.1.14
ProductVersion : 9.2
ProductName : Symantec AntiVirus AutoProtect
CompanyName : Symantec Corporation
FileDescription : Symantec AntiVirus Scanner
InternalName : SAVSCAN
LegalCopyright : Copyright © 2003 Symantec Corporation
OriginalFilename : SAVSCAN.EXE
#:24 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k imgsvc
ProcessID : 500
ThreadCreationTime : 4-26-2005 11:02:19 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:25 [swupdtmr.exe]
ModuleName : c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
Command Line : c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
ProcessID : 528
ThreadCreationTime : 4-26-2005 11:02:20 PM
BasePriority : Normal
#:26 [wdfmgr.exe]
ModuleName : C:\WINDOWS\System32\wdfmgr.exe
Command Line : C:\WINDOWS\System32\wdfmgr.exe
ProcessID : 552
ThreadCreationTime : 4-26-2005 11:02:20 PM
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe
#:27 [zcfgsvc.exe]
ModuleName : C:\WINDOWS\system32\ZCfgSvc.exe
Command Line : ZCfgSvc.exe
ProcessID : 724
ThreadCreationTime : 4-26-2005 11:03:34 PM
BasePriority : Normal
FileVersion : 8, 0, 0, 161
ProductVersion : 8, 0, 0, 161
ProductName : ZeroCfgSvc Application
CompanyName : Intel Corporation
FileDescription : ZeroCfgSvc MFC Application
InternalName : ZeroCfgSvc
LegalCopyright : Copyright © 2002 - 2003 Intel Corporation
OriginalFilename : ZeroCfgSvc.EXE
#:28 [1xconfig.exe]
ModuleName : C:\WINDOWS\System32\1XConfig.exe
Command Line : C:\WINDOWS\System32\1XConfig.exe -Embedding
ProcessID : 664
ThreadCreationTime : 4-26-2005 11:03:35 PM
BasePriority : Normal
FileVersion : 8, 0, 0, 161
ProductVersion : 8, 0, 0, 161
ProductName : 8021XConfig Module
CompanyName : Intel
FileDescription : 8021XConfig Module
InternalName : 8021XConfig
LegalCopyright : Copyright 2003
OriginalFilename : 1XConfig.EXE
Comments : Wrapper for MH. (Service COM)
#:29 [explorer.exe]
ModuleName : C:\WINDOWS\Explorer.exe
Command Line : Explorer.exe C:\WINDOWS\Nail.exe
ProcessID : 624
ThreadCreationTime : 4-26-2005 11:03:35 PM
BasePriority : Normal
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
#:30 [ezsp_px.exe]
ModuleName : C:\WINDOWS\System32\ezSP_Px.exe
Command Line : "C:\WINDOWS\System32\ezSP_Px.exe"
ProcessID : 2152
ThreadCreationTime : 4-26-2005 11:03:42 PM
BasePriority : Normal
#:31 [tpsmain.exe]
ModuleName : C:\WINDOWS\System32\TPSMain.exe
Command Line : "C:\WINDOWS\System32\TPSMain.exe"
ProcessID : 2160
ThreadCreationTime : 4-26-2005 11:03:42 PM
BasePriority : Normal
FileVersion : 1, 0, 1, 1
ProductVersion : 7, 0, 0, 0
ProductName : TOSHIBA Power Saver
CompanyName : TOSHIBA Corporation
InternalName : TPSMain
LegalCopyright : Copyright © 1998-2003 TOSHIBA Corporation
OriginalFilename : TPSMain.EXE
#:32 [touched.exe]
ModuleName : C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
Command Line : "C:\Program Files\TOSHIBA\TouchED\TouchED.Exe"
ProcessID : 2204
ThreadCreationTime : 4-26-2005 11:03:43 PM
BasePriority : Normal
FileVersion : 2, 5, 0, 0
ProductVersion : 2, 5, 0, 0
ProductName : TouchPad On/Off Utility
CompanyName : TOSHIBA Corporation
FileDescription : TouchPad On/Off Utility
InternalName : TouchED
LegalCopyright : Copyright 1998-2002 TOSHIBA Corporation. All rights reserved.
OriginalFilename : TouchED.exe
#:33 [tfnf5.exe]
ModuleName : C:\WINDOWS\System32\TFNF5.exe
Command Line : "C:\WINDOWS\System32\TFNF5.exe"
ProcessID : 2212
ThreadCreationTime : 4-26-2005 11:03:43 PM
BasePriority : Normal
FileVersion : 2, 2, 0, 0
ProductVersion : 2, 2, 0, 0
ProductName : TOSHIBA Hotkey Utility for Display Devices
CompanyName : TOSHIBA Corp.
FileDescription : TFnF5
InternalName : TFnF5
LegalCopyright : Copyright © 2001-2003
OriginalFilename : TFnF5.Exe
Comments : Hotkey (Fn+F5) for Display Devices
#:34 [tfncky.exe]
ModuleName : C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
Command Line : "C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe"
ProcessID : 2228
ThreadCreationTime : 4-26-2005 11:03:44 PM
BasePriority : Normal
FileVersion : 3.01.01
ProductVersion : 3.01.01
ProductName : TFncKy
CompanyName : TOSHIBA Corporation
FileDescription : TFncKy
InternalName : TFncKy
LegalCopyright : Copyright 2001-2003 TOSHIBA Corporation. All rights reserved.
OriginalFilename : TFncKy.EXE
#:35 [syntplpr.exe]
ModuleName : C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
Command Line : "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
ProcessID : 2236
ThreadCreationTime : 4-26-2005 11:03:44 PM
BasePriority : Normal
FileVersion : 7.5.11 30May03
ProductVersion : 7.5.11 30May03
ProductName : Progressive Touch
CompanyName : Synaptics, Inc.
FileDescription : TouchPad Driver Helper Application
InternalName : SynTPLpr
LegalCopyright : Copyright © Synaptics, Inc. 1996-2003
OriginalFilename : SynTPLpr.exe
#:36 [syntpenh.exe]
ModuleName : C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Command Line : "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
ProcessID : 2344
ThreadCreationTime : 4-26-2005 11:03:45 PM
BasePriority : Normal
FileVersion : 7.5.11 30May03
ProductVersion : 7.5.11 30May03
ProductName : Progressive Touch
CompanyName : Synaptics, Inc.
FileDescription : Synaptics TouchPad Enhancements
InternalName : Scrolleroo
LegalCopyright : Copyright © Synaptics, Inc. 1996-2003
OriginalFilename : SynTPEnh.exe
#:37 [jusched.exe]
ModuleName : C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
Command Line : "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
ProcessID : 2384
ThreadCreationTime : 4-26-2005 11:03:46 PM
BasePriority : Normal
#:38 [stacmon.exe]
ModuleName : C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
Command Line : "C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe"
ProcessID : 2392
ThreadCreationTime : 4-26-2005 11:03:46 PM
BasePriority : Normal
FileVersion : 1, 0, 0, 3
ProductVersion : 1, 0, 0, 3
ProductName : SigmaTel C-Major Audio
CompanyName : SigmaTel Inc.
InternalName : stacmon
LegalCopyright : Copyright © SigmaTel, Inc., 2003
OriginalFilename : stacmon.exe
#:39 [pinger.exe]
ModuleName : C:\toshiba\ivp\ism\pinger.exe
Command Line : "C:\toshiba\ivp\ism\pinger.exe" /run
ProcessID : 2444
ThreadCreationTime : 4-26-2005 11:03:47 PM
BasePriority : Normal
FileVersion : 3.3
ProductVersion : 3.3
ProductName : Software Upgrades
CompanyName : TOSHIBA Corporation
FileDescription : TOSHIBA Pinger
InternalName : PINGER
LegalCopyright : © 1997-2002 TOSHIBA Corporation
OriginalFilename : PINGER.EXE
Comments : With TSysSMon support.
#:40 [tpsbattm.exe]
ModuleName : C:\WINDOWS\System32\TPSBattM.exe
Command Line : "C:\WINDOWS\System32\TPSBattM.exe"
ProcessID : 2552
ThreadCreationTime : 4-26-2005 11:03:47 PM
BasePriority : Normal
FileVersion : 1, 0, 1, 0
ProductVersion : 7, 0, 0, 0
ProductName : TOSHIBA Power Saver
CompanyName : TOSHIBA Corporation
InternalName : TPSBattM
LegalCopyright : Copyright © 1998-2003 TOSHIBA Corporation
OriginalFilename : TPSBattM.exe
#:41 [ndstray.exe]
ModuleName : C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
Command Line : "C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe"
ProcessID : 2576
ThreadCreationTime : 4-26-2005 11:03:48 PM
BasePriority : Normal
FileVersion : 4, 50, 0, 105
ProductVersion : 4, 5, 0, 0
ProductName : ConfigFree Tray
CompanyName : TOSHIBA CORPORATION
FileDescription : ConfigFree Tray
InternalName : ndstray
LegalCopyright : Copyright 2002-2003 © TOSHIBA CORPORATION. All rights reserved.
OriginalFilename : NDSTray.exe
#:42 [ccapp.exe]
ModuleName : C:\Program Files\Common Files\Symantec Shared\ccApp.exe
Command Line : "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
ProcessID : 2584
ThreadCreationTime : 4-26-2005 11:03:48 PM
BasePriority : Normal
FileVersion : 2.1.0.610
ProductVersion : 2.1.0.610
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client User Session
InternalName : ccApp
LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved.
OriginalFilename : ccApp.exe
#:43 [bsclip.exe]
ModuleName : C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
Command Line : "C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe"
ProcessID : 2608
ThreadCreationTime : 4-26-2005 11:03:49 PM
BasePriority : Normal
#:44 [agrsmmsg.exe]
ModuleName : C:\WINDOWS\AGRSMMSG.exe
Command Line : "C:\WINDOWS\AGRSMMSG.exe"
ProcessID : 2620
ThreadCreationTime : 4-26-2005 11:03:49 PM
BasePriority : Normal
FileVersion : 2.1.28.2 2.1.28.2 04/18/2003 11:20:08
ProductVersion : 2.1.28.2 2.1.28.2 04/18/2003 11:20:08
ProductName : Agere SoftModem Messaging Applet
CompanyName : Agere Systems
FileDescription : SoftModem Messaging Applet
InternalName : smdmstat.exe
LegalCopyright : Copyright © Agere Systems 1998-2000
OriginalFilename : smdmstat.exe
#:45 [00thotkey.exe]
ModuleName : C:\WINDOWS\System32\00THotkey.exe
Command Line : "C:\WINDOWS\System32\00THotkey.exe"
ProcessID : 2628
ThreadCreationTime : 4-26-2005 11:03:49 PM
BasePriority : Normal
FileVersion : 1, 0, 0, 21
ProductVersion : 6, 0, 2, 0
ProductName : TOSHIBA THotkey
CompanyName : TOSHIBA Corp.
FileDescription : THotkey
InternalName : THotkey
LegalCopyright : Copyright © 1999 -2003
OriginalFilename : THotkey.exe
#:46 [wuauclt.exe]
ModuleName : C:\WINDOWS\System32\wuauclt.exe
Command Line : "C:\WINDOWS\System32\wuauclt.exe"
ProcessID : 2644
ThreadCreationTime : 4-26-2005 11:03:49 PM
BasePriority : Normal
FileVersion : 5.4.3790.2182 built by: srv03_rtm(ntvbl04)
ProductVersion : 5.4.3790.2182
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Automatic Updates
InternalName : wuauclt.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : wuauclt.exe
#:47 [viewmgr.exe]
ModuleName : C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
Command Line : "C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe"
ProcessID : 2668
ThreadCreationTime : 4-26-2005 11:03:49 PM
BasePriority : Normal
FileVersion : 2, 0, 0, 42
ProductVersion : 2, 0, 0, 42
ProductName : Viewpoint Manager
CompanyName : Viewpoint Corporation
FileDescription : ViewMgr
InternalName : Viewpoint Manager
LegalCopyright : Copyright © 2004
OriginalFilename : ViewMgr.exe
Comments : Viewpoint Manager
#:48 [lvcomsx.exe]
ModuleName : C:\WINDOWS\System32\LVCOMSX.EXE
Command Line : "C:\WINDOWS\System32\LVCOMSX.EXE"
ProcessID : 2688
ThreadCreationTime : 4-26-2005 11:03:50 PM
BasePriority : Normal
FileVersion : 8.3.0.1096
ProductVersion : 8.3.0.1096
ProductName : Logitech QuickCam
CompanyName : Logitech Inc.
FileDescription : LVCom Server
InternalName : LVComS.exe
LegalCopyright : © 1996-2004 Logitech. All rights reserved.
OriginalFilename : LVComS.exe
#:49 [logitray.exe]
ModuleName : C:\Program Files\Logitech\Video\LogiTray.exe
Command Line : "C:\Program Files\Logitech\Video\LogiTray.exe"
ProcessID : 2720
ThreadCreationTime : 4-26-2005 11:03:51 PM
BasePriority : Normal
FileVersion : 8.3.0.1098
ProductVersion : 8.3.0.1098
ProductName : Logitech QuickCam
CompanyName : Logitech Inc.
FileDescription : ImageStudio Tray Application
InternalName : LogiTray.exe
LegalCopyright : © 1996-2004 Logitech. All rights reserved.
OriginalFilename : LogiTray.exe
#:50 [msnappau.exe]
ModuleName : C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
Command Line : "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
ProcessID : 2732
ThreadCreationTime : 4-26-2005 11:03:52 PM
BasePriority : Normal
#:51 [ituneshelper.exe]
ModuleName : C:\Program Files\iTunes\iTunesHelper.exe
Command Line : "C:\Program Files\iTunes\iTunesHelper.exe"
ProcessID : 2760
ThreadCreationTime : 4-26-2005 11:03:52 PM
BasePriority : Normal
FileVersion : 4.7.1.30
ProductVersion : 4.7.1.30
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2004 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe
#:52 [qttask.exe]
ModuleName : C:\Program Files\QuickTime\qttask.exe
Command Line : "C:\Program Files\QuickTime\qttask.exe" -atboottime
ProcessID : 2780
ThreadCreationTime : 4-26-2005 11:03:52 PM
BasePriority : Normal
FileVersion : 6.5.1
ProductVersion : QuickTime 6.5.1
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2004
OriginalFilename : QTTask.exe
#:53 [vvrrdll.exe]
ModuleName : C:\WINDOWS\VVRRDLL.EXE
Command Line : "C:\WINDOWS\VVRRDLL.EXE"
ProcessID : 2796
ThreadCreationTime : 4-26-2005 11:03:52 PM
BasePriority : Normal
FileVersion : 1.00
ProductVersion : 1.00
ProductName : Update Monitor
CompanyName : UpdateMonitor
FileDescription : Update Monitor
InternalName : UpdMon
OriginalFilename : UpdMon.exe
#:54 [zglxenc.exe]
ModuleName : C:\WINDOWS\ZGLXENC.EXE
Command Line : "C:\WINDOWS\ZGLXENC.EXE"
ProcessID : 2804
ThreadCreationTime : 4-26-2005 11:03:52 PM
BasePriority : Normal
FileVersion : 1.00
ProductVersion : 1.00
ProductName : System Monitor Service
CompanyName : System Service
FileDescription : SysMon
InternalName : SysMon
OriginalFilename : SysMon.exe
#:55 [lcrdwbxglj.exe]
ModuleName : C:\WINDOWS\system\lcrdwbxglj.exe
Command Line : "C:\WINDOWS\system\lcrdwbxglj.exe"
ProcessID : 2812
ThreadCreationTime : 4-26-2005 11:03:53 PM
BasePriority : Normal
#:56 [toscdspd.exe]
ModuleName : C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
Command Line : "C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe"
ProcessID : 2828
ThreadCreationTime : 4-26-2005 11:03:54 PM
BasePriority : Normal
#:57 [ctfmon.exe]
ModuleName : C:\WINDOWS\System32\ctfmon.exe
Command Line : "C:\WINDOWS\System32\ctfmon.exe"
ProcessID : 2836
ThreadCreationTime : 4-26-2005 11:03:54 PM
BasePriority : Normal
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE
#:58 [ipodservice.exe]
ModuleName : C:\Program Files\iPod\bin\iPodService.exe
Command Line : "C:\Program Files\iPod\bin\iPodService.exe"
ProcessID : 2928
ThreadCreationTime : 4-26-2005 11:03:56 PM
BasePriority : Normal
FileVersion : 4.7.1.30
ProductVersion : 4.7.1.30
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2004 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iPodService.exe
#:59 [fxsvr2.exe]
ModuleName : C:\Program Files\Logitech\Video\FxSvr2.exe
Command Line : "C:\Program Files\Logitech\Video\FxSvr2.exe" -Embedding
ProcessID : 3164
ThreadCreationTime : 4-26-2005 11:04:02 PM
BasePriority : Normal
FileVersion : 8.3.0.1098
ProductVersion : 8.3.0.1098
ProductName : Logitech QuickCam
CompanyName : Logitech Inc.
FileDescription : QuickCam Framework Server
InternalName : FxSvr.EXE
LegalCopyright : © 1996-2004 Logitech. All rights reserved.
OriginalFilename : FxSvr.EXE
#:60 [spysweeper.exe]
ModuleName : C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Command Line : "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
ProcessID : 3948
ThreadCreationTime : 4-26-2005 11:04:30 PM
BasePriority : Normal
FileVersion : 3.5.0.198
ProductVersion : 3.5
ProductName : Spy Sweeper
CompanyName : Webroot Software, Inc.
FileDescription : Spy Sweeper
LegalCopyright : Copyright © 2001-2004 Webroot Software, Inc.
LegalTrademarks : Spy Sweeper is a trademark of Webroot Software, Inc.
#:61 [bttray.exe]
ModuleName : C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Command Line : "C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
ProcessID : 4004
ThreadCreationTime : 4-26-2005 11:04:33 PM
BasePriority : Normal
FileVersion : 1.4.2 Build 10
ProductVersion : 1.4.2 Build 10
ProductName : Bluetooth Software 1.4.2 Build 10
CompanyName : WIDCOMM, Inc.
FileDescription : Bluetooth Tray Application
InternalName : BTTray
LegalCopyright : Copyright WIDCOMM, Inc. 2000-2003.
OriginalFilename : BTTray.exe
#:62 [devdtct2.exe]
ModuleName : C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
Command Line : "C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe"
ProcessID : 4016
ThreadCreationTime : 4-26-2005 11:04:34 PM
BasePriority : High
FileVersion : 2, 4, 3, 1
ProductVersion : 2, 4, 3, 1
ProductName : Olympus Device Detector 2
CompanyName : OLYMPUS Corporation.
FileDescription : Device Detector 2
LegalCopyright : Copyright © 1999-2004 OLYMPUS Corporation.
LegalTrademarks : OLYMPUS Corporation.
OriginalFilename : DevDtct.exe
#:63 [ramasst.exe]
ModuleName : C:\WINDOWS\system32\RAMASST.exe
Command Line : "C:\WINDOWS\system32\RAMASST.exe"
ProcessID : 592
ThreadCreationTime : 4-26-2005 11:04:40 PM
BasePriority : Normal
FileVersion : 1, 0, 9, 0
ProductVersion : 1, 0, 9, 0
CompanyName : Matsushita Electric Industrial Co., Ltd.
FileDescription : CD Burning of Windows XP disabling tool for DVD MULTI Drive
LegalCopyright : Copyright © Matsushita Electric Industrial Co., Ltd. 2002 - 2003
OriginalFilename : RAMASST.EXE
#:64 [sgmain.exe]
ModuleName : C:\Program Files\SpywareGuard\sgmain.exe
Command Line : "C:\Program Files\SpywareGuard\sgmain.exe"
ProcessID : 1056
ThreadCreationTime : 4-26-2005 11:04:43 PM
BasePriority : Normal
FileVersion : 2.02.0001
ProductVersion : 2.02.0001
ProductName : SpywareGuard
FileDescription : SpywareGuard
InternalName : sgmain
LegalCopyright : Copyright © 2002-2003 Javacool Software LLC
OriginalFilename : sgmain.exe
Comments : SpywareGuard
#:65 [sgbhp.exe]
ModuleName : C:\Program Files\SpywareGuard\sgbhp.exe
Command Line : "C:\Program Files\SpywareGuard\sgbhp.exe"
ProcessID : 2104
ThreadCreationTime : 4-26-2005 11:04:53 PM
BasePriority : Normal
FileVersion : 2.02.0001
ProductVersion : 2.02.0001
ProductName : SG Browser Hijacking Protection
FileDescription : SG Browser Hijacking Protection
InternalName : sgbhp
LegalCopyright : Copyright © 2002-2003 Javacool Software LLC.
OriginalFilename : sgbhp.exe
Comments : SG Browser Hijacking Protection
#:66 [acrord32.exe]
ModuleName : C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
Command Line : "C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe" /o
ProcessID : 2636
ThreadCreationTime : 4-27-2005 12:29:48 AM
BasePriority : Normal
FileVersion : 6.0.3.2004113000
ProductVersion : 6.0.3.2004113000
ProductName : Adobe Reader
CompanyName : Adobe Systems Incorporated
FileDescription : Adobe Reader 6.0
LegalCopyright : Copyright 1984-2004 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename : AcroRd32.exe
#:67 [msmsgs.exe]
ModuleName : C:\Program Files\Messenger\msmsgs.exe
Command Line : "C:\Program Files\Messenger\msmsgs.exe" -Embedding
ProcessID : 1308
ThreadCreationTime : 4-27-2005 3:40:26 AM
BasePriority : Normal
FileVersion : 4.7.2009
ProductVersion : Version 4.7
ProductName : Messenger
CompanyName : Microsoft Corporation
FileDescription : Messenger
InternalName : msmsgs
LegalCopyright : Copyright © Microsoft Corporation 1997-2003
LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msmsgs.exe
#:68 [ad-aware.exe]
ModuleName : C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
Command Line : "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe"
ProcessID : 4056
ThreadCreationTime : 4-27-2005 3:41:01 AM
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : michael@statcounter[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:[email protected]/
Expires : 4-25-2010 9:02:52 PM
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 1
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
13 entries scanned.
New critical objects:0
Objects found so far: 1
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
11:58:47 PM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:17:33.564
Objects scanned:163863
Objects identified:1
Objects ignored:0
New critical objects:1