Thanks so much for any/all help...
Ad-Aware SE Build 1.05
Logfile Created on:Thursday, May 12, 2005 2:46:32 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R44 10.05.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Elitum.ElitebarBHO(TAC index:5):1 total references
iSearch Toolbar(TAC index:3):2 total references
MediaMotor(TAC index:8):4 total references
MRU List(TAC index:0):13 total references
Other(TAC index:5):1 total references
SahAgent(TAC index:9):2 total references
TopMoxie(TAC index:3):1 total references
WebHancer(TAC index:9):14 total references
Win32.Trojan.Delprot.a(TAC index:6):1 total references
WindUpdates(TAC index:8):2 total references
VX2(TAC index:10):9 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
5-12-2005 2:46:32 PM - Scan started. (Full System Scan)
MRU List Object Recognized!
Location: : C:\Documents and Settings\Matt Freeman\recent
Description : list of recently opened documents
MRU List Object Recognized!
Location: : S-1-5-21-117609710-1202660629-1060284298-1004
\software\google\navclient\1.1\history
Description : list of recently used search terms in the google toolbar
MRU List Object Recognized!
Location: : S-1-5-21-117609710-1202660629-1060284298-1004
\software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized!
Location: : S-1-5-21-117609710-1202660629-1060284298-1004
\software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Object Recognized!
Location: : S-1-5-21-117609710-1202660629-1060284298-1004
\software\microsoft\internet explorer
Description : last download directory used in microsoft internet
explorer
MRU List Object Recognized!
Location: : S-1-5-21-117609710-1202660629-1060284298-1004
\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet
explorer
MRU List Object Recognized!
Location: : S-1-5-21-117609710-1202660629-1060284298-1004
\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened
MRU List Object Recognized!
Location: : S-1-5-21-117609710-1202660629-1060284298-1004
\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file
extension
MRU List Object Recognized!
Location: : S-1-5-21-117609710-1202660629-1060284298-1004
\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened
MRU List Object Recognized!
Location: : S-1-5-21-117609710-1202660629-1060284298-1004
\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 404
ThreadCreationTime : 5-12-2005 7:38:44 PM
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 452
ThreadCreationTime : 5-12-2005 7:38:46 PM
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 476
ThreadCreationTime : 5-12-2005 7:38:49 PM
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 520
ThreadCreationTime : 5-12-2005 7:38:50 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 532
ThreadCreationTime : 5-12-2005 7:38:50 PM
BasePriority : Normal
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [ati2evxx.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 708
ThreadCreationTime : 5-12-2005 7:38:52 PM
BasePriority : Normal
FileVersion : 6.14.10.4109
ProductVersion : 6.14.10.4109.04
ProductName : ATI External Event Utility for WindowsNT and Windows9X
CompanyName : ATI Technologies Inc.
FileDescription : ATI External Event Utility EXE Module
InternalName : ATI2EVXX.EXE
LegalCopyright : Copyright © 1999-2004 ATI Technologies Inc.
OriginalFilename : ATI2EVXX.EXE
#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 740
ThreadCreationTime : 5-12-2005 7:38:52 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 816
ThreadCreationTime : 5-12-2005 7:38:53 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 992
ThreadCreationTime : 5-12-2005 7:38:53 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1036
ThreadCreationTime : 5-12-2005 7:38:54 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:11 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1248
ThreadCreationTime : 5-12-2005 7:38:55 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:12 [ati2evxx.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1420
ThreadCreationTime : 5-12-2005 7:38:55 PM
BasePriority : Normal
FileVersion : 6.14.10.4109
ProductVersion : 6.14.10.4109.04
ProductName : ATI External Event Utility for WindowsNT and Windows9X
CompanyName : ATI Technologies Inc.
FileDescription : ATI External Event Utility EXE Module
InternalName : ATI2EVXX.EXE
LegalCopyright : Copyright © 1999-2004 ATI Technologies Inc.
OriginalFilename : ATI2EVXX.EXE
#:13 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 1476
ThreadCreationTime : 5-12-2005 7:38:55 PM
BasePriority : Normal
FileVersion : 6.00.2800.1221 (xpsp2.030511-1403)
ProductVersion : 6.00.2800.1221
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
#:14 [regtwk.exe]
FilePath : C:\Program Files\Rage3DTweak\
ProcessID : 1696
ThreadCreationTime : 5-12-2005 7:39:02 PM
BasePriority : Normal
FileVersion : 0, 0, 0, 16
ProductVersion : 0, 0, 0, 16
ProductName : Registry Tweak
CompanyName : Byron Montgomerie
FileDescription : Taskbar icon exe
InternalName : RegTwk.exe
LegalCopyright : Copyright © 1999-2002
OriginalFilename : RegTwk.exe
Comments : Taskbar program for RegTweak
#:15 [jusched.exe]
FilePath : C:\Program Files\Java\jre1.5.0\bin\
ProcessID : 1704
ThreadCreationTime : 5-12-2005 7:39:02 PM
BasePriority : Normal
#:16 [cthelper.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1716
ThreadCreationTime : 5-12-2005 7:39:02 PM
BasePriority : Normal
FileVersion : 1, 0, 0, 2
ProductVersion : 1, 0, 0, 2
ProductName : CtHelper Application
CompanyName : Creative Technology Ltd
FileDescription : CtHelper Application
InternalName : CtHelper
LegalCopyright : Copyright © 2002
OriginalFilename : CtHelper.EXE
#:17 [cli.exe]
FilePath : C:\Program Files\ATI Technologies\ATI.ACE\
ProcessID : 1796
ThreadCreationTime : 5-12-2005 7:39:03 PM
BasePriority : Normal
#:18 [ezsp_px.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1816
ThreadCreationTime : 5-12-2005 7:39:03 PM
BasePriority : Normal
#:19 [svch0st.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1824
ThreadCreationTime : 5-12-2005 7:39:03 PM
BasePriority : Normal
#:20 [cfd.exe]
FilePath : C:\Program Files\BroadJump\Client Foundation\
ProcessID : 1852
ThreadCreationTime : 5-12-2005 7:39:04 PM
BasePriority : Normal
#:21 [devldr32.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1864
ThreadCreationTime : 5-12-2005 7:39:04 PM
BasePriority : Normal
FileVersion : 1, 0, 0, 17
ProductVersion : 1, 0, 0, 17
ProductName : Creative Ring3 NT Inteface
CompanyName : Creative Technology Ltd.
FileDescription : DevLdr32
InternalName : DevLdr
LegalCopyright : Copyright © Creative Technology Ltd. 1998-2001
OriginalFilename : DevLdr32.exe
#:22 [avgamsvr.exe]
FilePath : C:\PROGRA~1\Grisoft\AVGFRE~1\
ProcessID : 1860
ThreadCreationTime : 5-12-2005 7:39:04 PM
BasePriority : Normal
FileVersion : 7,1,0,307
ProductVersion : 7.1.0.307
ProductName : AVG Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Alert Manager
InternalName : avgamsvr
LegalCopyright : Copyright © 2005, GRISOFT, s.r.o.
OriginalFilename : avgamsvr.EXE
#:23 [delttray.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1884
ThreadCreationTime : 5-12-2005 7:39:05 PM
BasePriority : Normal
FileVersion : 5.1.0.01
ProductVersion : 5.1.0.01
ProductName : M Audio Delta Control Panel Interface System Tray Applet
CompanyName : Doug Fetter Software Wizardry
FileDescription : M Audio Delta Control Panel Interface System Tray Applet
InternalName : Delta Panel System Tray Applet
LegalCopyright : Copyright © 2002 Midiman, Inc. All rights reserved.
LegalTrademarks : M Audio is a legal trademark of MIDIMAN, Inc.
OriginalFilename : DeltTray.EXE
Comments : Developed by Doug Fetter Software Wizardry
#:24 [avgcc.exe]
FilePath : C:\PROGRA~1\Grisoft\AVGFRE~1\
ProcessID : 1920
ThreadCreationTime : 5-12-2005 7:39:06 PM
BasePriority : Normal
FileVersion : 7,1,0,307
ProductVersion : 7.1.0.307
ProductName : AVG Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Control Center
InternalName : AvgCC
LegalCopyright : Copyright © 2005, GRISOFT, s.r.o.
OriginalFilename : AvgCC.EXE
#:25 [wapr.exe]
FilePath : C:\Documents and Settings\Matt Freeman\Application Data\
ProcessID : 1964
ThreadCreationTime : 5-12-2005 7:39:08 PM
BasePriority : Normal
#:26 [m?dtc.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2008
ThreadCreationTime : 5-12-2005 7:39:08 PM
BasePriority : Normal
#:27 [avgupsvc.exe]
FilePath : C:\PROGRA~1\Grisoft\AVGFRE~1\
ProcessID : 2036
ThreadCreationTime : 5-12-2005 7:39:09 PM
BasePriority : Normal
FileVersion : 7,1,0,285
ProductVersion : 7.1.0.285
ProductName : AVG 7.0 Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Update Service
InternalName : avgupsvc
LegalCopyright : Copyright © 2004, GRISOFT, s.r.o.
OriginalFilename : avgupdsvc.EXE
#:28 [win32.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 140
ThreadCreationTime : 5-12-2005 7:39:10 PM
BasePriority : Normal
#:29 [gameutil.exe]
FilePath : C:\Program Files\rage3dtweak\
ProcessID : 220
ThreadCreationTime : 5-12-2005 7:39:14 PM
BasePriority : Normal
FileVersion : 1, 0, 0, 21
ProductVersion : 1, 0, 0, 21
ProductName : GameUtil
CompanyName : Byron Montgomerie
FileDescription : Gamma control, ATI overclock reset on resume, refresh
rate hack, per game do stuff in general
InternalName : GameUtil
LegalCopyright : Copyright © 2002
OriginalFilename : GameUtil.exe
#:30 [cli.exe]
FilePath : C:\Program Files\ATI Technologies\ATI.ACE\
ProcessID : 304
ThreadCreationTime : 5-12-2005 7:39:15 PM
BasePriority : Normal
#:31 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 336
ThreadCreationTime : 5-12-2005 7:39:15 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:32 [wdfmgr.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 392
ThreadCreationTime : 5-12-2005 7:39:16 PM
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe
#:33 [wincinemamgr.exe]
FilePath : C:\Program Files\InterVideo\Common\Bin\
ProcessID : 880
ThreadCreationTime : 5-12-2005 7:39:20 PM
BasePriority : Normal
FileVersion : 1.8.2
ProductVersion : 1, 8, 2, 0
ProductName : WinCinema Manager for InterVideo WinCinema products
CompanyName : InterVideo Inc.
FileDescription : WinCinema Manager
InternalName : WinCinema Manager
LegalCopyright : Copyright 1999-2003 InterVideo, Inc. All rights
reserved.
OriginalFilename : WinCinemaMgr.EXE
#:34 [wanmpsvc.exe]
FilePath : C:\WINDOWS\
ProcessID : 940
ThreadCreationTime : 5-12-2005 7:39:21 PM
BasePriority : Normal
FileVersion : 9, 0, 0, 0
ProductVersion : 9, 0, 0, 0
ProductName : America Online
CompanyName : America Online, Inc.
FileDescription : Wan Miniport (ATW) Service
InternalName : WanMPSvc
LegalCopyright : Copyright © 2001 America Online, Inc.
OriginalFilename : WanMPSvc.exe
#:35 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 3968
ThreadCreationTime : 5-12-2005 7:41:40 PM
BasePriority : Normal
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : IEXPLORE.EXE
#:36 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 2100
ThreadCreationTime : 5-12-2005 7:45:47 PM
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 13
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 13
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 13
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 13
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
VX2 Object Recognized!
Type : File
Data : exiysu.exe.tcf
Category : Malware
Comment :
Object : C:\WINDOWS\SYSTEM32\
FileVersion : 1, 0, 2, 17
ProductVersion : 0, 0, 7, 0
ProductName : TODO: <Product name>
CompanyName : TODO: <Company name>
FileDescription : TODO: <File description>
LegalCopyright : TODO: © <Company name>. All rights reserved.
WebHancer Object Recognized!
Type : File
Data : whInstaller.exe
Category : Data Miner
Comment :
Object : C:\WINDOWS\LastGood\
FileVersion : 1.8.1
ProductVersion : 1.8.1
ProductName : webHancer Installer
CompanyName : webHancer Corporation
FileDescription : webHancer Installer
InternalName : whInstaller
LegalCopyright : Copyright © 1999-2001 webHancer Corporation
OriginalFilename : whInstaller.exe
WebHancer Object Recognized!
Type : File
Data : webhdll.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\LastGood\
FileVersion : 3.3.0
ProductVersion : 3.3.0
ProductName : webHancer Customer Companion
CompanyName : webHancer Corporation
FileDescription : webHancer Winsock2 SPI
InternalName : webhdll
LegalCopyright : Copyright © 1999-2003 webHancer Corporation
OriginalFilename : webhdll.dll
WebHancer Object Recognized!
Type : File
Data : WhAgent.exe
Category : Data Miner
Comment :
Object : C:\Program Files\whInstall\
FileVersion : 3.3.0
ProductVersion : 3.3.0
ProductName : webHancer Customer Companion
CompanyName : webHancer Corporation
FileDescription : webHancer Customer Companion
InternalName : whAgent
LegalCopyright : Copyright © 1999-2003 webHancer Corporation
OriginalFilename : whAgent.exe
WebHancer Object Recognized!
Type : File
Data : whInstaller.exe
Category : Data Miner
Comment :
Object : C:\Program Files\whInstall\
FileVersion : 3.3.0
ProductVersion : 3.3.0
ProductName : webHancer Customer Companion
CompanyName : webHancer Corporation
FileDescription : webHancer Installer
InternalName : whInstaller
LegalCopyright : Copyright © 1999-2003 webHancer Corporation
OriginalFilename : whInstaller.exe
WebHancer Object Recognized!
Type : File
Data : WhSurvey.exe
Category : Data Miner
Comment :
Object : C:\Program Files\whInstall\
FileVersion : 3.3.0
ProductVersion : 3.3.0
ProductName : webHancer Survey Companion
CompanyName : webHancer Corporation
FileDescription : webHancer Survey Companion
InternalName : whSurvey
LegalCopyright : Copyright © 1999-2003 webHancer Corporation
OriginalFilename : whSurvey.exe
WebHancer Object Recognized!
Type : File
Data : Webhdll.dll
Category : Data Miner
Comment :
Object : C:\Program Files\whInstall\
FileVersion : 3.3.0
ProductVersion : 3.3.0
ProductName : webHancer Customer Companion
CompanyName : webHancer Corporation
FileDescription : webHancer Winsock2 SPI
InternalName : webhdll
LegalCopyright : Copyright © 1999-2003 webHancer Corporation
OriginalFilename : webhdll.dll
WebHancer Object Recognized!
Type : File
Data : whiehlpr.dll
Category : Data Miner
Comment :
Object : C:\Program Files\whInstall\
FileVersion : 3.3.0
ProductVersion : 3.3.0
ProductName : webHancer Customer Companion
CompanyName : webHancer Corporation
FileDescription : webHancer IE Helper Module
InternalName : WhIeHelper
LegalCopyright : Copyright © 1999-2003 webHancer Corporation
OriginalFilename : whiehlpr.dll
VX2 Object Recognized!
Type : File
Data : thnall2c.exe
Category : Malware
Comment :
Object : C:\Documents and Settings\Matt Freeman\Local
Settings\Temp\drp68.tmp\
FileVersion : 2, 0, 1, 8
ProductVersion : 2, 0, 1, 8
ProductName : Thinstaller
CompanyName : BetterInternet, Inc.
FileDescription : www.abetterinternet.com - Utility for downloading files
and upgrading software.
InternalName : Install Utility
LegalCopyright : BetterInternet, Inc. © 2005
OriginalFilename : Thinstaller.exe
Comments : Utility for downloading files and upgrading software.
Visit www.abetterinternet.com for more info.
WindUpdates Object Recognized!
Type : File
Data : A0061656.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{157294F3-2861-44F
7-8DE4-AF2B9EB4FF0E}\RP487\
Win32.Trojan.Delprot.a Object Recognized!
Type : File
Data : A0061860.exe
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{157294F3-2861-44F
7-8DE4-AF2B9EB4FF0E}\RP487\
MediaMotor Object Recognized!
Type : File
Data : A0060817.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{157294F3-2861-44F
7-8DE4-AF2B9EB4FF0E}\RP462\
FileVersion : 0, 12, 4, 74
ProductVersion : 0, 12, 4, 74
ProductName : Ceres
CompanyName : Ceres
FileDescription : www.abetterinternet.com
InternalName : Ceres
LegalCopyright : Copyright © 2004
OriginalFilename : Ceres.dll
Comments : www.abetterinternet.com
MediaMotor Object Recognized!
Type : File
Data : A0060822.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{157294F3-2861-44F
7-8DE4-AF2B9EB4FF0E}\RP463\
FileVersion : 0, 12, 4, 74
ProductVersion : 0, 12, 4, 74
ProductName : Ceres
CompanyName : Ceres
FileDescription : www.abetterinternet.com
InternalName : Ceres
LegalCopyright : Copyright © 2004
OriginalFilename : Ceres.dll
Comments : www.abetterinternet.com
VX2 Object Recognized!
Type : File
Data : A0060870.exe
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{157294F3-2861-44F
7-8DE4-AF2B9EB4FF0E}\RP465\
FileVersion : 1, 0, 2, 17
ProductVersion : 0, 0, 7, 0
ProductName : TODO: <Product name>
CompanyName : TODO: <Company name>
FileDescription : TODO: <File description>
LegalCopyright : TODO: © <Company name>. All rights reserved.
VX2 Object Recognized!
Type : File
Data : A0060872.exe
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{157294F3-2861-44F
7-8DE4-AF2B9EB4FF0E}\RP465\
FileVersion : 0, 4, 1, 3
ProductVersion : 0, 4, 1, 3
CompanyName : FarmMext
FileDescription : www.farmmext.com
LegalCopyright : Copyright © 2002
MediaMotor Object Recognized!
Type : File
Data : A0060913.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{157294F3-2861-44F
7-8DE4-AF2B9EB4FF0E}\RP467\
FileVersion : 0, 12, 4, 74
ProductVersion : 0, 12, 4, 74
ProductName : Ceres
CompanyName : Ceres
FileDescription : www.abetterinternet.com
InternalName : Ceres
LegalCopyright : Copyright © 2004
OriginalFilename : Ceres.dll
Comments : www.abetterinternet.com
iSearch Toolbar Object Recognized!
Type : File
Data : MFEX-2.DAT
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{157294F3-2861-44F
7-8DE4-AF2B9EB4FF0E}\RP468\snapshot\
VX2 Object Recognized!
Type : File
Data : A0060928.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{157294F3-2861-44F
7-8DE4-AF2B9EB4FF0E}\RP468\
FileVersion : 0, 4, 4, 30
ProductVersion : 0, 4, 4, 30
ProductName : localnrd
CompanyName : LocalNRD
FileDescription : www.localnrd.com
InternalName : localnrd
LegalCopyright : Copyright © 2004
OriginalFilename : localnrd.dll
Comments : www.localnrd.com
Elitum.ElitebarBHO Object Recognized!
Type : File
Data : A0060929.exe
Category : Data Miner
Comment :
Object : C:\System Volume Information\_restore{157294F3-2861-44F
7-8DE4-AF2B9EB4FF0E}\RP468\
MediaMotor Object Recognized!
Type : File
Data : A0061002.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{157294F3-2861-44F
7-8DE4-AF2B9EB4FF0E}\RP471\
FileVersion : 0, 12, 4, 74
ProductVersion : 0, 12, 4, 74
ProductName : Ceres
CompanyName : Ceres
FileDescription : www.abetterinternet.com
InternalName : Ceres
LegalCopyright : Copyright © 2004
OriginalFilename : Ceres.dll
Comments : www.abetterinternet.com
iSearch Toolbar Object Recognized!
Type : File
Data : A0061341.exe
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{157294F3-2861-44F
7-8DE4-AF2B9EB4FF0E}\RP471\
TopMoxie Object Recognized!
Type : File
Data : WebRebates_CDT_InstallSilent.exe
Category : Data Miner
Comment :
Object : C:\TEMP\
VX2 Object Recognized!
Type : File
Data : lc.exe
Category : Malware
Comment :
Object : C:\TEMP\
FileVersion : 1, 0, 0, 12
ProductVersion : 1, 0, 0, 12
ProductName : Install Utility
CompanyName : BetterInternet, Inc.
FileDescription : www.abetterinternet.com - Utility for downloading files
and upgrading software.
InternalName : Install Utility
LegalCopyright : BetterInternet, Inc. © 2004
OriginalFilename : InstUtil.exe
Comments : Utility for downloading files and upgrading software.
Visit www.abetterinternet.com for more info.
SahAgent Object Recognized!
Type : File
Data : sahagent.exe
Category : Data Miner
Comment :
Object : C:\TEMP\
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 37
Deep scanning and examining files (E:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for E:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 37
Deep scanning and examining files (G:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for G:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 37
Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 37
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
VX2 Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\lastknowngoodrecovery\lastgood
Value : INF/oem14.PNF
VX2 Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\lastknowngoodrecovery\lastgood
Value : INF/oem11.PNF
VX2 Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\lastknowngoodrecovery\lastgood
Value : INF/oem12.PNF
WebHancer Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\Program Files\whInstall
WebHancer Object Recognized!
Type : File
Data : license.txt
Category : Data Miner
Comment :
Object : C:\Program Files\whinstall\
WebHancer Object Recognized!
Type : File
Data : readme.txt
Category : Data Miner
Comment :
Object : C:\Program Files\whinstall\
WebHancer Object Recognized!
Type : File
Data : whAgent.ini
Category : Data Miner
Comment :
Object : C:\Program Files\whinstall\
WebHancer Object Recognized!
Type : File
Data : whInstaller.ini
Category : Data Miner
Comment :
Object : C:\Program Files\whinstall\
WebHancer Object Recognized!
Type : File
Data : whAgent.inf
Category : Data Miner
Comment :
Object : C:\Program Files\whinstall\
WebHancer Object Recognized!
Type : File
Data : Sporder.dll
Category : Data Miner
Comment :
Object : C:\Program Files\whinstall\
FileVersion : 4.00
ProductVersion : 4.00
ProductName : Microsoft® Windows NT Operating System
CompanyName : Microsoft Corporation
FileDescription : WinSock2 reorder service providers
InternalName : sporder.dll
LegalCopyright : Copyright © Microsoft Corp. 1981-1996
OriginalFilename : sporder.dll
WindUpdates Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\downloadmanager
SahAgent Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall
Value : UninstallString
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 13
Objects found so far: 50
2:59:20 PM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:12:47.273
Objects scanned:231422
Objects identified:37
Objects ignored:0
New critical objects:37
Edited by anotherdaydown, 12 May 2005 - 02:39 PM.