Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

blue screen error[RESOLVED]


  • This topic is locked This topic is locked

#1
jono

jono

    Member

  • Member
  • PipPip
  • 12 posts
my computer shuts down and displays a blue screen error that says IRQL_IS NOT LESS THAN OR EQUAL about four hours after i turn it on. here is my ad-aware log.
Please follow my post below to submit your Ad Aware logfile. Thx :tazz:

Edited by DinoT, 24 May 2005 - 02:25 AM.

  • 0

Advertisements


#2
DinoT

DinoT

    Ad-Aware Expert

  • Member
  • PipPip
  • 17 posts
Hi, jono welcome to Geeks to go! Please follow these instructions to post your Ad Aware logfile:

Before performing a scan, be sure that you have the most recent definitions file by using WebUpdate.

(Click on the Globe icon, Click on connect, Click OK, Click Finish.)

Please set up the Configurations (Gear wheel at the top) as follows:

General Button > Safety & Settings: Check (Green) all three.
Advanced Button > Logfile Detail Level: All options under this should be checked (Green).
Tweak Button > Log Files: Please check only:

• "Include basic Ad-Aware settings in logfile"
• "Include additional Ad-Aware settings in logfile"
• "Include reference summary in log file"
Click on "Proceed"

Click on "Scan Now". Please deselect "Search for negligible risk entries" as negligible risk entries (MRU's) are not considered to be a threat.
Run the scanner using the Full Scan (Perform full system scan) mode. At the result window, please choose all Tracking Cookies (which are always safe to remove), and get rid of them.

Run the scanner using the Full Scan (Perform full system scan) mode.
When the scan has completed, click "Show Logfile"

Copy/paste the complete log file as a reply in this thread.

Do not quarantine or remove anything at this time (except for the Tracking Cookies), just post a complete logfile.

This sometimes takes 2-3 posts to get it all posted. You will know you are at the end when you see the "Summary of this scan" information has been posted.

Please post back if you have any questions. Thx :tazz:
  • 0

#3
jono

jono

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
I made the changes that you mentioned. thanks a ton.

Lavasoft Ad-Aware Personal Build 1.03
Logfile created on:Tuesday, May 24, 2005 3:59:15 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R47 24.05.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie(TAC index:3):1 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Definition File:
=========================
Definitions File Loaded:
Reference Number : SE1R46 17.05.2005
Internal build : 54
File location : C:\Program Files\Aware-Ad\defs.ref
File size : 474775 Bytes
Total size : 1435210 Bytes
Signature data size : 1404100 Bytes
Reference data size : 30598 Bytes
Signatures total : 40060
Fingerprints total : 883
Fingerprints size : 30250 Bytes
Target categories : 15
Target families : 674
(Requires Ad-Aware SE or higher)

5-24-2005 3:56:39 PM WebUpdate

Installing Update...
Definitions File Loaded:
Reference Number : SE1R47 24.05.2005
Internal build : 55
File location : C:\Program Files\Aware-Ad\defs.ref
File size : 476246 Bytes
Total size : 1439523 Bytes
Signature data size : 1408291 Bytes
Reference data size : 30720 Bytes
Signatures total : 40174
Fingerprints total : 886
Fingerprints size : 30371 Bytes
Target categories : 15
Target families : 679
(Requires Ad-Aware SE or higher)


5-24-2005 3:56:49 PM Success
Update successfully downloaded and installed.


Memory + processor status:
==========================
Number of processors : 2
Processor architecture : Intel Pentium IV
Memory available:30 %
Total physical memory:261116 kb
Available physical memory:76532 kb
Total page file size:903172 kb
Available on page file:650572 kb
Total virtual memory:2097024 kb
Available virtual memory:2041540 kb
OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)

Ad-Aware Settings
===========================
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file

Extended Ad-Aware Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Obtain command line of scanned processes
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Write-protect system files after repair (Hosts file, etc.)
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Backup current definitions file before updating
Set : Play sound at scan completion if scan locates critical objects


5-24-2005 3:59:15 PM - Scan started. (Full System Scan)

Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
ModuleName : \SystemRoot\System32\
Command Line : n/a
ProcessID : 840
ThreadCreationTime : 5-24-2005 1:54:10 PM
BasePriority : Normal


#:2 [csrss.exe]
ModuleName : \??\C:\WINDOWS\system32\
Command Line : C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestTh
ProcessID : 888
ThreadCreationTime : 5-24-2005 1:54:14 PM
BasePriority : Normal


#:3 [winlogon.exe]
ModuleName : \??\C:\WINDOWS\system32\
Command Line : winlogon.exe
ProcessID : 912
ThreadCreationTime : 5-24-2005 1:54:15 PM
BasePriority : High


#:4 [services.exe]
ModuleName : C:\WINDOWS\system32\
Command Line : C:\WINDOWS\system32\services.exe
ProcessID : 956
ThreadCreationTime : 5-24-2005 1:54:15 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe

#:5 [lsass.exe]
ModuleName : C:\WINDOWS\system32\
Command Line : C:\WINDOWS\system32\lsass.exe
ProcessID : 968
ThreadCreationTime : 5-24-2005 1:54:15 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe

#:6 [svchost.exe]
ModuleName : C:\WINDOWS\system32\
Command Line : C:\WINDOWS\system32\svchost -k DcomLaunch
ProcessID : 1124
ThreadCreationTime : 5-24-2005 1:54:15 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:7 [svchost.exe]
ModuleName : C:\WINDOWS\system32\
Command Line : C:\WINDOWS\system32\svchost -k rpcss
ProcessID : 1192
ThreadCreationTime : 5-24-2005 1:54:16 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:8 [svchost.exe]
ModuleName : C:\WINDOWS\System32\
Command Line : C:\WINDOWS\System32\svchost.exe -k netsvcs
ProcessID : 1232
ThreadCreationTime : 5-24-2005 1:54:16 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:9 [svchost.exe]
ModuleName : C:\WINDOWS\System32\
Command Line : C:\WINDOWS\System32\svchost.exe -k NetworkService
ProcessID : 1352
ThreadCreationTime : 5-24-2005 1:54:16 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:10 [svchost.exe]
ModuleName : C:\WINDOWS\System32\
Command Line : C:\WINDOWS\System32\svchost.exe -k LocalService
ProcessID : 1380
ThreadCreationTime : 5-24-2005 1:54:16 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:11 [spoolsv.exe]
ModuleName : C:\WINDOWS\system32\
Command Line : C:\WINDOWS\system32\spoolsv.exe
ProcessID : 1712
ThreadCreationTime : 5-24-2005 1:54:23 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe

#:12 [cisvc.exe]
ModuleName : C:\WINDOWS\system32\
Command Line : C:\WINDOWS\system32\cisvc.exe
ProcessID : 1812
ThreadCreationTime : 5-24-2005 1:54:23 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Content Index service
InternalName : cisvc.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : cisvc.exe

#:13 [ctsvccda.exe]
ModuleName : C:\WINDOWS\System32\
Command Line : C:\WINDOWS\System32\CTsvcCDA.exe
ProcessID : 1824
ThreadCreationTime : 5-24-2005 1:54:24 PM
BasePriority : Normal
FileVersion : 1.0.1.0
ProductVersion : 1.0.0.0
ProductName : Creative Service for CDROM Access
CompanyName : Creative Technology Ltd
FileDescription : Creative Service for CDROM Access
InternalName : CTsvcCDAEXE
LegalCopyright : Copyright © Creative Technology Ltd., 1999. All rights reserved.
OriginalFilename : CTsvcCDA.EXE

#:14 [svchost.exe]
ModuleName : C:\WINDOWS\System32\
Command Line : C:\WINDOWS\System32\svchost.exe -k imgsvc
ProcessID : 1904
ThreadCreationTime : 5-24-2005 1:54:24 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:15 [wdfmgr.exe]
ModuleName : C:\WINDOWS\system32\
Command Line : C:\WINDOWS\system32\wdfmgr.exe
ProcessID : 1988
ThreadCreationTime : 5-24-2005 1:54:24 PM
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe

#:16 [mspmspsv.exe]
ModuleName : C:\WINDOWS\System32\
Command Line : C:\WINDOWS\System32\MsPMSPSv.exe
ProcessID : 148
ThreadCreationTime : 5-24-2005 1:54:24 PM
BasePriority : Normal
FileVersion : 7.00.00.1954
ProductVersion : 7.00.00.1954
ProductName : Microsoft ® DRM
CompanyName : Microsoft Corporation
FileDescription : WMDM PMSP Service
InternalName : MSPMSPSV.EXE
LegalCopyright : Copyright © Microsoft Corp. 1981-2000
OriginalFilename : MSPMSPSV.EXE

#:17 [svchost.exe]
ModuleName : C:\WINDOWS\system32\
Command Line : C:\WINDOWS\system32\svchost.exe -k netsvcs
ProcessID : 156
ThreadCreationTime : 5-24-2005 1:54:24 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:18 [alg.exe]
ModuleName : C:\WINDOWS\System32\
Command Line : C:\WINDOWS\System32\alg.exe
ProcessID : 588
ThreadCreationTime : 5-24-2005 1:54:25 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe

#:19 [svchost.exe]
ModuleName : C:\WINDOWS\System32\
Command Line : C:\WINDOWS\System32\svchost.exe -k HTTPFilter
ProcessID : 884
ThreadCreationTime : 5-24-2005 1:54:26 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:20 [cidaemon.exe]
ModuleName : C:\WINDOWS\system32\
Command Line : "cidaemon.exe" DownLevelDaemon "c:\program files\dell\support\ui\search\catalog.wci" 196672l 1812l
ProcessID : 524
ThreadCreationTime : 5-24-2005 2:01:45 PM
BasePriority : Idle
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Indexing Service filter daemon
InternalName : cidaemon.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : cidaemon.exe

#:21 [cidaemon.exe]
ModuleName : C:\WINDOWS\system32\
Command Line : "cidaemon.exe" DownLevelDaemon "c:\system volume information\catalog.wci" 196672l 1812l
ProcessID : 1620
ThreadCreationTime : 5-24-2005 2:01:47 PM
BasePriority : Idle
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Indexing Service filter daemon
InternalName : cidaemon.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : cidaemon.exe

#:22 [explorer.exe]
ModuleName : C:\WINDOWS\
Command Line : C:\WINDOWS\Explorer.EXE
ProcessID : 940
ThreadCreationTime : 5-24-2005 2:03:24 PM
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE

#:23 [support.exe]
ModuleName : C:\Program Files\Common Files\Dell\EUSW\
Command Line : "C:\Program Files\Common Files\Dell\EUSW\Support.exe"
ProcessID : 2004
ThreadCreationTime : 5-24-2005 2:03:25 PM
BasePriority : Normal
FileVersion : 2, 1, 1, 0
ProductVersion : 1, 0, 0, 1
ProductName : Dell Support
CompanyName : Dell
FileDescription : Support
InternalName : Support
LegalCopyright : Copyright © 2002
OriginalFilename : Support.exe

#:24 [teatimer.exe]
ModuleName : C:\Program Files\Spybot - Search & Destroy\
Command Line : "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
ProcessID : 892
ThreadCreationTime : 5-24-2005 2:03:25 PM
BasePriority : Idle
FileVersion : 1, 3, 0, 12
ProductVersion : 1, 3, 0, 12
ProductName : Spybot - Search & Destroy
CompanyName : Safer Networking Limited
FileDescription : System settings protector
InternalName : TeaTimer
LegalCopyright : © 2000-2004 Patrick M. Kolla / Safer Networking Limited. Alle Rechte vorbehalten.
LegalTrademarks : "Spybot" und "Spybot - Search & Destroy" sind registrierte Warenzeichen.
OriginalFilename : TeaTimer.exe
Comments : Schützt Systemeinstellungen vor ungewollten Änderungen.

#:25 [ezsp_px.exe]
ModuleName : C:\WINDOWS\system32\
Command Line : "C:\WINDOWS\system32\ezSP_Px.exe"
ProcessID : 2000
ThreadCreationTime : 5-24-2005 2:03:25 PM
BasePriority : Normal


#:26 [notifyalert.exe]
ModuleName : C:\Program Files\Dell\Support\Alert\bin\
Command Line : "C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe" timer
ProcessID : 576
ThreadCreationTime : 5-24-2005 2:03:25 PM
BasePriority : Normal


#:27 [qttask.exe]
ModuleName : C:\Program Files\QuickTime\
Command Line : "C:\Program Files\QuickTime\qttask.exe" -atboottime
ProcessID : 2160
ThreadCreationTime : 5-24-2005 2:03:25 PM
BasePriority : Normal
FileVersion : 6.5.1
ProductVersion : QuickTime 6.5.1
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2004
OriginalFilename : QTTask.exe

#:28 [ituneshelper.exe]
ModuleName : C:\Program Files\iTunes\
Command Line : "C:\Program Files\iTunes\iTunesHelper.exe"
ProcessID : 2304
ThreadCreationTime : 5-24-2005 2:03:25 PM
BasePriority : Normal
FileVersion : 4.8.0.32
ProductVersion : 4.8.0.32
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe

#:29 [mm_tray.exe]
ModuleName : C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\
Command Line : "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
ProcessID : 2320
ThreadCreationTime : 5-24-2005 2:03:26 PM
BasePriority : Normal
FileVersion : 9.00.0156
ProductVersion : 9.00.0156
ProductName : Musicmatch Jukebox
CompanyName : Musicmatch, Inc.
FileDescription : mm_tray
InternalName : mm_tray
LegalCopyright : Copyright © Musicmatch 1998-2004
LegalTrademarks :
OriginalFilename : mm_tray.exe

#:30 [ctfmon.exe]
ModuleName : C:\WINDOWS\system32\
Command Line : "C:\WINDOWS\system32\ctfmon.exe"
ProcessID : 2328
ThreadCreationTime : 5-24-2005 2:03:26 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE

#:31 [aim.exe]
ModuleName : C:\Program Files\AIM\
Command Line : "C:\Program Files\AIM\aim.exe" -cnetwait.odl
ProcessID : 2500
ThreadCreationTime : 5-24-2005 2:03:27 PM
BasePriority : Normal
FileVersion : 5.9.3702
ProductVersion : 5.9.3702
ProductName : AOL Instant Messenger
CompanyName : America Online, Inc.
FileDescription : AOL Instant Messenger
InternalName : AIM
LegalCopyright : Copyright © 1996-2004 America Online, Inc.
OriginalFilename : AIM.EXE

#:32 [diagent.exe]
ModuleName : C:\Program Files\Creative\SBLive\Diagnostics\
Command Line : diagent.exe systray
ProcessID : 2668
ThreadCreationTime : 5-24-2005 2:03:27 PM
BasePriority : Normal
FileVersion : 1, 1, 4, 0
ProductVersion : 1.01.04
ProductName : Creative Diagnostics Agent
CompanyName : Creative Technology Ltd
FileDescription : Creative Diagnostics Agent
InternalName : Creative Diagnostics Agent
LegalCopyright : Copyright © 2002 Creative Technology Ltd
OriginalFilename : diagent.exe

#:33 [ipodservice.exe]
ModuleName : C:\Program Files\iPod\bin\
Command Line : "C:\Program Files\iPod\bin\iPodService.exe"
ProcessID : 2680
ThreadCreationTime : 5-24-2005 2:03:27 PM
BasePriority : Normal
FileVersion : 4.8.0.32
ProductVersion : 4.8.0.32
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iPodService.exe

#:34 [airplus.exe]
ModuleName : C:\Program Files\D-Link AirPlus G\
Command Line : "C:\Program Files\D-Link AirPlus G\AirPlus.exe"
ProcessID : 2712
ThreadCreationTime : 5-24-2005 2:03:28 PM
BasePriority : Normal
FileVersion : 1, 0, 0, 0
ProductVersion : 1, 0, 0, 0
ProductName : D-Link AirPlus G
CompanyName : D-Link
FileDescription : WLAN Adapter Utility
InternalName : WLANMON
LegalCopyright : Copyright © All rights reserved.
OriginalFilename : AIRPLUS.EXE

#:35 [firefox.exe]
ModuleName : C:\Program Files\Mozilla Firefox\
Command Line : "C:\Program Files\Mozilla Firefox\firefox.exe"
ProcessID : 3320
ThreadCreationTime : 5-24-2005 10:37:59 PM
BasePriority : Normal


#:36 [ad-aware.exe]
ModuleName : C:\Program Files\Aware-Ad\
Command Line : "C:\Program Files\Aware-Ad\Ad-Aware.exe"
ProcessID : 2624
ThreadCreationTime : 5-24-2005 10:51:29 PM
BasePriority : Normal
FileVersion : 6.2.0.162
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

#:37 [ebaytbdaemon.exe]
ModuleName : C:\Program Files\eBay\eBay Toolbar2\
Command Line : "C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe"
ProcessID : 1104
ThreadCreationTime : 5-24-2005 10:56:46 PM
BasePriority : Normal
FileVersion : 2, 0, 5, 0
ProductVersion : 2, 0, 5, 0
ProductName : eBay Toolbar Daemon
CompanyName : eBay
FileDescription : eBay Toolbar Daemon
InternalName : eBayTBDa
LegalCopyright : Copyright © eBay Inc. 2004
OriginalFilename : eBayTBDa.exe

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking Cookie Object Recognized!
Type : IECache Entry
Data : jonathan seclow@2o7[2].txt
Category : Data Miner
Comment : Cookie:jonathan [email protected]/
Value : Cookie:jonathan [email protected]/

Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 1



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1


Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1

4:15:15 PM Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:16:00.875
Objects scanned:245651
Objects identified:1
Objects ignored:0
New critical objects:1
  • 0

#4
DinoT

DinoT

    Ad-Aware Expert

  • Member
  • PipPip
  • 17 posts
Hi, jono, thx for supplying your log with the settings outlined :tazz:
Your logfile is showing viral infection(s)...I can't see any Anti virus software on your machine, would you like me to post a link to a recommended free solution? Just ask!
In the meantime please scan with the following online AV (Anti Virus) free scans:

http://www.ravantivirus.com/scan/

http://www.bitdefender.com/scan8/

http://support.f-sec.../home/ols.shtml

Please post back after scanning with these, allow them to clean what they will.

Feel free to delete:

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : jonathan seclow@2o7[2].txt
Category : Data Miner
Comment : Cookie:jonathan [email protected]/
Value : Cookie:jonathan [email protected]/
....to help you do this you may want to try CC Cleaner:
http://www.ccleaner.com/

It's a good utility for cleaning your system!

Once your done please post your new logfile...thx ;)

Edited by DinoT, 25 May 2005 - 03:58 AM.

  • 0

#5
jono

jono

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
I tried each of these solutions but none of them worked. Whenever I tried to use one it would always say that the program failed to load. I went through my security settings and made sure that ActiveX and Java were enabled and they were. I had MacAfee but it is out of date so it does not run anymore. As soon as i fix this problem I will buy a new subscription to MacAfee. The onling virus scan that I traditionaly use is House-Call. Is it ok if I use that? Thanks
  • 0

#6
Guest_Andy_veal_*

Guest_Andy_veal_*
  • Guest

Lavasoft Ad-Aware Plus Build 1.03


Ad-aware SE build 1.05 is the most current version,

As you are not using the latest version, please could you chose a download site to download the latest version.
Download site list

Just make sure you uninstall any old version of Ad-Aware before installing SE. After installing SE, then update your definition file * SE1R46 17.05.2005 *.

Please then rescan your computer with the full system scan option
And post your results here.

All the best

Andy
  • 0

#7
jono

jono

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Thanks, i just updated yesterday and i thought that it would be up to date.
  • 0

#8
jono

jono

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
I think there is something wrong with my Internet Exporer. I can't run any browser apps (explains why i couldn't run the virus searches) including Java. It wouldn't let me download Ad-Aware with it either so i eventually just used Firefox (my prefered browser but due to limited capatibility I do not use it all the time) and it worked easily. As soon as I finish running Ad-Aware i will post my log. Thanks
  • 0

#9
jono

jono

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Here is my updated Ad-Aware log below. Thanx :D

BTW- In the previous reply when refering to Firefox i ment compatibility instead of capability.


Ad-Aware SE Build 1.05
Logfile Created on:Wednesday, May 25, 2005 10:35:25 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R47 24.05.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
None.
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Definition File:
=========================
Definitions File Loaded:
Reference Number : SE1R8 13.09.2004
Internal build : 12
File location : C:\PROGRA~1\Lavasoft\AD-AWA~2\defs.ref
File size : 344723 Bytes
Total size : 1092481 Bytes
Signature data size : 1068971 Bytes
Reference data size : 22998 Bytes
Signatures total : 30122
Fingerprints total : 154
Fingerprints size : 7129 Bytes
Target categories : 15
Target families : 560

5-25-2005 10:29:51 PM WebUpdate

Installing Update...
Definitions File Loaded:
Reference Number : SE1R47 24.05.2005
Internal build : 55
File location : C:\PROGRA~1\Lavasoft\AD-AWA~2\defs.ref
File size : 476246 Bytes
Total size : 1439523 Bytes
Signature data size : 1408291 Bytes
Reference data size : 30720 Bytes
Signatures total : 40174
Fingerprints total : 886
Fingerprints size : 30371 Bytes
Target categories : 15
Target families : 679


5-25-2005 10:30:01 PM Success
Update successfully downlodaded and installed.


Memory + processor status:
==========================
Number of processors : 2
Processor architecture : Intel Pentium IV
Memory available:9 %
Total physical memory:261116 kb
Available physical memory:22120 kb
Total page file size:903172 kb
Available on page file:427608 kb
Total virtual memory:2097024 kb
Available virtual memory:2038228 kb
OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)

Ad-Aware SE Settings
===========================
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Obtain command line of scanned processes
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : Prior to deletion, allow unloading Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Write protect system files after repair (Hosts file etc.)
Set : Include basic settings in log file
Set : Include additional settings in log file
Set : Include reference summary in log file
Set : Play sound at scan completion if scan locates critical objects


5/25/2005 10:35:26 PM - Scan started. (Full System Scan)

Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
ModuleName : \SystemRoot\System32\smss.exe
Command Line : n/a
ProcessID : 804
ThreadCreationTime : 5/26/2005 3:27:53 AM
BasePriority : Normal


#:2 [csrss.exe]
ModuleName : \??\C:\WINDOWS\system32\csrss.exe
Command Line : C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestTh
ProcessID : 852
ThreadCreationTime : 5/26/2005 3:27:57 AM
BasePriority : Normal


#:3 [winlogon.exe]
ModuleName : \??\C:\WINDOWS\system32\winlogon.exe
Command Line : winlogon.exe
ProcessID : 876
ThreadCreationTime : 5/26/2005 3:27:57 AM
BasePriority : High


#:4 [services.exe]
ModuleName : C:\WINDOWS\system32\services.exe
Command Line : C:\WINDOWS\system32\services.exe
ProcessID : 920
ThreadCreationTime : 5/26/2005 3:27:57 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe

#:5 [lsass.exe]
ModuleName : C:\WINDOWS\system32\lsass.exe
Command Line : C:\WINDOWS\system32\lsass.exe
ProcessID : 940
ThreadCreationTime : 5/26/2005 3:27:57 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe

#:6 [svchost.exe]
ModuleName : C:\WINDOWS\system32\svchost.exe
Command Line : C:\WINDOWS\system32\svchost -k DcomLaunch
ProcessID : 1112
ThreadCreationTime : 5/26/2005 3:27:58 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:7 [svchost.exe]
ModuleName : C:\WINDOWS\system32\svchost.exe
Command Line : C:\WINDOWS\system32\svchost -k rpcss
ProcessID : 1180
ThreadCreationTime : 5/26/2005 3:27:59 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:8 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k netsvcs
ProcessID : 1348
ThreadCreationTime : 5/26/2005 3:27:59 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:9 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k NetworkService
ProcessID : 1492
ThreadCreationTime : 5/26/2005 3:27:59 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:10 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k LocalService
ProcessID : 1536
ThreadCreationTime : 5/26/2005 3:27:59 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:11 [spoolsv.exe]
ModuleName : C:\WINDOWS\system32\spoolsv.exe
Command Line : C:\WINDOWS\system32\spoolsv.exe
ProcessID : 1936
ThreadCreationTime : 5/26/2005 3:28:07 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe

#:12 [explorer.exe]
ModuleName : C:\WINDOWS\Explorer.EXE
Command Line : C:\WINDOWS\Explorer.EXE
ProcessID : 132
ThreadCreationTime : 5/26/2005 3:28:07 AM
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE

#:13 [support.exe]
ModuleName : C:\Program Files\Common Files\Dell\EUSW\Support.exe
Command Line : "C:\Program Files\Common Files\Dell\EUSW\Support.exe"
ProcessID : 224
ThreadCreationTime : 5/26/2005 3:28:08 AM
BasePriority : Normal
FileVersion : 2, 1, 1, 0
ProductVersion : 1, 0, 0, 1
ProductName : Dell Support
CompanyName : Dell
FileDescription : Support
InternalName : Support
LegalCopyright : Copyright © 2002
OriginalFilename : Support.exe

#:14 [teatimer.exe]
ModuleName : C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
Command Line : "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
ProcessID : 232
ThreadCreationTime : 5/26/2005 3:28:08 AM
BasePriority : Idle
FileVersion : 1, 3, 0, 12
ProductVersion : 1, 3, 0, 12
ProductName : Spybot - Search & Destroy
CompanyName : Safer Networking Limited
FileDescription : System settings protector
InternalName : TeaTimer
LegalCopyright : © 2000-2004 Patrick M. Kolla / Safer Networking Limited. Alle Rechte vorbehalten.
LegalTrademarks : "Spybot" und "Spybot - Search & Destroy" sind registrierte Warenzeichen.
OriginalFilename : TeaTimer.exe
Comments : Schützt Systemeinstellungen vor ungewollten Änderungen.

#:15 [notifyalert.exe]
ModuleName : C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
Command Line : "C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe" timer
ProcessID : 240
ThreadCreationTime : 5/26/2005 3:28:09 AM
BasePriority : Normal


#:16 [ezsp_px.exe]
ModuleName : C:\WINDOWS\system32\ezSP_Px.exe
Command Line : "C:\WINDOWS\system32\ezSP_Px.exe"
ProcessID : 248
ThreadCreationTime : 5/26/2005 3:28:09 AM
BasePriority : Normal


#:17 [qttask.exe]
ModuleName : C:\Program Files\QuickTime\qttask.exe
Command Line : "C:\Program Files\QuickTime\qttask.exe" -atboottime
ProcessID : 304
ThreadCreationTime : 5/26/2005 3:28:09 AM
BasePriority : Normal
FileVersion : 6.5.1
ProductVersion : QuickTime 6.5.1
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2004
OriginalFilename : QTTask.exe

#:18 [ituneshelper.exe]
ModuleName : C:\Program Files\iTunes\iTunesHelper.exe
Command Line : "C:\Program Files\iTunes\iTunesHelper.exe"
ProcessID : 312
ThreadCreationTime : 5/26/2005 3:28:09 AM
BasePriority : Normal
FileVersion : 4.8.0.32
ProductVersion : 4.8.0.32
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe

#:19 [mm_tray.exe]
ModuleName : C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
Command Line : "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
ProcessID : 320
ThreadCreationTime : 5/26/2005 3:28:09 AM
BasePriority : Normal
FileVersion : 9.00.0156
ProductVersion : 9.00.0156
ProductName : Musicmatch Jukebox
CompanyName : Musicmatch, Inc.
FileDescription : mm_tray
InternalName : mm_tray
LegalCopyright : Copyright © Musicmatch 1998-2004
LegalTrademarks :
OriginalFilename : mm_tray.exe

#:20 [ctfmon.exe]
ModuleName : C:\WINDOWS\system32\ctfmon.exe
Command Line : "C:\WINDOWS\system32\ctfmon.exe"
ProcessID : 340
ThreadCreationTime : 5/26/2005 3:28:09 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE

#:21 [aim.exe]
ModuleName : C:\Program Files\AIM\aim.exe
Command Line : "C:\Program Files\AIM\aim.exe" -cnetwait.odl
ProcessID : 372
ThreadCreationTime : 5/26/2005 3:28:09 AM
BasePriority : Normal
FileVersion : 5.9.3702
ProductVersion : 5.9.3702
ProductName : AOL Instant Messenger
CompanyName : America Online, Inc.
FileDescription : AOL Instant Messenger
InternalName : AIM
LegalCopyright : Copyright © 1996-2004 America Online, Inc.
OriginalFilename : AIM.EXE

#:22 [airplus.exe]
ModuleName : C:\Program Files\D-Link AirPlus G\AirPlus.exe
Command Line : "C:\Program Files\D-Link AirPlus G\AirPlus.exe"
ProcessID : 488
ThreadCreationTime : 5/26/2005 3:28:09 AM
BasePriority : Normal
FileVersion : 1, 0, 0, 0
ProductVersion : 1, 0, 0, 0
ProductName : D-Link AirPlus G
CompanyName : D-Link
FileDescription : WLAN Adapter Utility
InternalName : WLANMON
LegalCopyright : Copyright © All rights reserved.
OriginalFilename : AIRPLUS.EXE

#:23 [diagent.exe]
ModuleName : C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
Command Line : diagent.exe systray
ProcessID : 652
ThreadCreationTime : 5/26/2005 3:28:10 AM
BasePriority : Normal
FileVersion : 1, 1, 4, 0
ProductVersion : 1.01.04
ProductName : Creative Diagnostics Agent
CompanyName : Creative Technology Ltd
FileDescription : Creative Diagnostics Agent
InternalName : Creative Diagnostics Agent
LegalCopyright : Copyright © 2002 Creative Technology Ltd
OriginalFilename : diagent.exe

#:24 [cisvc.exe]
ModuleName : C:\WINDOWS\system32\cisvc.exe
Command Line : C:\WINDOWS\system32\cisvc.exe
ProcessID : 1848
ThreadCreationTime : 5/26/2005 3:28:13 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Content Index service
InternalName : cisvc.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : cisvc.exe

#:25 [ctsvccda.exe]
ModuleName : C:\WINDOWS\System32\CTsvcCDA.exe
Command Line : C:\WINDOWS\System32\CTsvcCDA.exe
ProcessID : 1980
ThreadCreationTime : 5/26/2005 3:28:13 AM
BasePriority : Normal
FileVersion : 1.0.1.0
ProductVersion : 1.0.0.0
ProductName : Creative Service for CDROM Access
CompanyName : Creative Technology Ltd
FileDescription : Creative Service for CDROM Access
InternalName : CTsvcCDAEXE
LegalCopyright : Copyright © Creative Technology Ltd., 1999. All rights reserved.
OriginalFilename : CTsvcCDA.EXE

#:26 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k imgsvc
ProcessID : 328
ThreadCreationTime : 5/26/2005 3:28:15 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:27 [wdfmgr.exe]
ModuleName : C:\WINDOWS\system32\wdfmgr.exe
Command Line : C:\WINDOWS\system32\wdfmgr.exe
ProcessID : 660
ThreadCreationTime : 5/26/2005 3:28:15 AM
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe

#:28 [mspmspsv.exe]
ModuleName : C:\WINDOWS\System32\MsPMSPSv.exe
Command Line : C:\WINDOWS\System32\MsPMSPSv.exe
ProcessID : 776
ThreadCreationTime : 5/26/2005 3:28:18 AM
BasePriority : Normal
FileVersion : 7.00.00.1954
ProductVersion : 7.00.00.1954
ProductName : Microsoft ® DRM
CompanyName : Microsoft Corporation
FileDescription : WMDM PMSP Service
InternalName : MSPMSPSV.EXE
LegalCopyright : Copyright © Microsoft Corp. 1981-2000
OriginalFilename : MSPMSPSV.EXE

#:29 [svchost.exe]
ModuleName : C:\WINDOWS\system32\svchost.exe
Command Line : C:\WINDOWS\system32\svchost.exe -k netsvcs
ProcessID : 856
ThreadCreationTime : 5/26/2005 3:28:18 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:30 [ipodservice.exe]
ModuleName : C:\Program Files\iPod\bin\iPodService.exe
Command Line : "C:\Program Files\iPod\bin\iPodService.exe"
ProcessID : 1716
ThreadCreationTime : 5/26/2005 3:28:20 AM
BasePriority : Normal
FileVersion : 4.8.0.32
ProductVersion : 4.8.0.32
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iPodService.exe

#:31 [alg.exe]
ModuleName : C:\WINDOWS\System32\alg.exe
Command Line : C:\WINDOWS\System32\alg.exe
ProcessID : 3484
ThreadCreationTime : 5/26/2005 3:28:24 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe

#:32 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k HTTPFilter
ProcessID : 2764
ThreadCreationTime : 5/26/2005 3:28:27 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:33 [pip.exe]
ModuleName : C:\Program Files\Microsoft Picture It! 7\Pip.exe
Command Line : "C:\Program Files\Microsoft Picture It! 7\Pip.exe"
ProcessID : 2916
ThreadCreationTime : 5/26/2005 3:33:07 AM
BasePriority : Normal
FileVersion : 7.00.0716.0
ProductVersion : 7.00.0716.0
ProductName : Microsoft Picture It! 7.0
CompanyName : Microsoft Corporation
FileDescription : Picture It! 7.0
InternalName : PIP
LegalCopyright : Copyright © 1987-2002 Microsoft Corporation.
OriginalFilename : PIP.EXE

#:34 [msworks.exe]
ModuleName : C:\Program Files\Microsoft Works\MSWorks.exe
Command Line : "C:\Program Files\Microsoft Works\MSWorks.exe" -Embedding
ProcessID : 1268
ThreadCreationTime : 5/26/2005 3:34:00 AM
BasePriority : Normal
FileVersion : 7.02.0710.1
ProductVersion : 7.02.0710.1
ProductName : Microsoft® Works 7.0
CompanyName : Microsoft® Corporation
FileDescription : Microsoft® Works Task Launcher
InternalName : MSWORKS
LegalCopyright : Copyright © Microsoft Corporation. All rights reserved.
OriginalFilename : MSWorks.exe

#:35 [cidaemon.exe]
ModuleName : C:\WINDOWS\system32\cidaemon.exe
Command Line : "cidaemon.exe" DownLevelDaemon "c:\program files\dell\support\ui\search\catalog.wci" 196672l 1848l
ProcessID : 2960
ThreadCreationTime : 5/26/2005 3:35:33 AM
BasePriority : Idle
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Indexing Service filter daemon
InternalName : cidaemon.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : cidaemon.exe

#:36 [cidaemon.exe]
ModuleName : C:\WINDOWS\system32\cidaemon.exe
Command Line : "cidaemon.exe" DownLevelDaemon "c:\system volume information\catalog.wci" 196672l 1848l
ProcessID : 1284
ThreadCreationTime : 5/26/2005 3:35:35 AM
BasePriority : Idle
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Indexing Service filter daemon
InternalName : cidaemon.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : cidaemon.exe

#:37 [ebaytbdaemon.exe]
ModuleName : C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
Command Line : "C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe"
ProcessID : 3344
ThreadCreationTime : 5/26/2005 3:51:07 AM
BasePriority : Normal
FileVersion : 2, 0, 5, 0
ProductVersion : 2, 0, 5, 0
ProductName : eBay Toolbar Daemon
CompanyName : eBay
FileDescription : eBay Toolbar Daemon
InternalName : eBayTBDa
LegalCopyright : Copyright © eBay Inc. 2004
OriginalFilename : eBayTBDa.exe

#:38 [limewire.exe]
ModuleName : C:\Program Files\LimeWire\LimeWire.exe
Command Line : "C:\Program Files\LimeWire\LimeWire.exe"
ProcessID : 188
ThreadCreationTime : 5/26/2005 4:42:08 AM
BasePriority : Normal
FileVersion : 1, 0, 0, 2
ProductVersion : 1, 0, 0, 2
ProductName : LimeWire
CompanyName : Lime Wire, LLC
FileDescription : LimeWire
InternalName : LimeWire
LegalCopyright : Copyright © 2004
OriginalFilename : LimeWire.exe
Comments : The most advanced file sharing program on the planet.

#:39 [firefox.exe]
ModuleName : C:\Program Files\Mozilla Firefox\firefox.exe
Command Line : "C:\Program Files\Mozilla Firefox\firefox.exe"
ProcessID : 3004
ThreadCreationTime : 5/26/2005 5:12:51 AM
BasePriority : Normal


#:40 [itunes.exe]
ModuleName : C:\Program Files\iTunes\iTunes.exe
Command Line : "C:\Program Files\iTunes\iTunes.exe"
ProcessID : 848
ThreadCreationTime : 5/26/2005 5:12:55 AM
BasePriority : Normal
FileVersion : 4.8.0.32
ProductVersion : 4.8.0.32
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunes
InternalName : iTunes
LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunes.exe

#:41 [ad-aware.exe]
ModuleName : C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Aware.exe
Command Line : "C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Aware.exe" +483832
ProcessID : 3516
ThreadCreationTime : 5/26/2005 5:28:14 AM
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

#:42 [hh.exe]
ModuleName : C:\WINDOWS\hh.exe
Command Line : "C:\WINDOWS\hh.exe" manual.chm
ProcessID : 3244
ThreadCreationTime : 5/26/2005 5:28:15 AM
BasePriority : Normal
FileVersion : 5.2.3790.1159 (dnsrv.040209-1620)
ProductVersion : 5.2.3790.1159
ProductName : HTML Help
CompanyName : Microsoft Corporation
FileDescription : Microsoft® HTML Help Executable
InternalName : HH 1.41
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : HH.exe

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 0
Objects found so far: 0


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 0
Objects found so far: 0


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 0
Objects found so far: 0


Started tracking cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 0
Objects found so far: 0



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk scan result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 0
Objects found so far: 0
11:01:23 PM Scan Complete

Summary of this scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:25:57.312
Objects scanned:245911
Objects identified:0
Objects ignored:0
New Critical Objects:0
  • 0

#10
jono

jono

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
i ran housecall and it found 26 viruses. it deleated them all. so far it hasn't shut down i will let you know if it happens again. thanx :tazz:
  • 0

Advertisements


#11
jono

jono

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
my computer stil shut down and displayed the same blue screen error even after housecall deleted the viruses it found. :tazz: i will run ad-aware again and post the results.
  • 0

#12
jono

jono

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
i don't know if this is helpful but i figured out that this only happens when i use internet explorer. if i use mozilla and other browsers my computer will not shut down and display this error message. :tazz: don't know why this would be. thanks, i will post a post virus scan ad-aware log when i get a chance.
  • 0

#13
Eric the Red

Eric the Red

    Member

  • Member
  • PipPip
  • 13 posts
jono,

I think that this may be a problem with your NAT address pool, please check the following.

Open the Control Panel, then "Network Connections",
Right click "Local Area Connection" and go to "Properties",
Select "Internet Protocol (TCP/IP)" and click "Properties",
Make sure that the radio button next to the entries for "Obtain IP...." and "Obtain DNS.... is selected for both the entries and hit "ok".

Give that a try and let us know how you get on.
  • 0

#14
jono

jono

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
didn't help, but it did mess up my overly complex network. :tazz:
  • 0

#15
jono

jono

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Ok, i found the problem, the last time my computer shut down i studied the error screen more carefully. On the screen it refers to mrv8k51.sys, i looked around on my computer for a while and found that mrv8k51.sys is the driver for my wireless internet pci card. ;) I got the card refurbished from a shady website for really cheap. :tazz: Will reinstalling the driver fix my problem, or will i need to purchase a new card? Thanks. ;)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP