I am posting a recent log file. I've had problems on my computer for some time, and it's been a while that I've had any time to attempt to fix it. Any help is appreciated.
Ad-Aware SE Build 1.06r1
Logfile Created on:Tuesday, July 05, 2005 11:16:23 AM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R52 30.06.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Definition File:
=========================
7-5-2005 11:11:25 AM - Definitions not loaded or invalid!
7-5-2005 11:11:28 AM WebUpdate
Installing Update...
Definitions File Loaded:
Reference Number : SE1R52 30.06.2005
Internal build : 60
File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
File size : 485588 Bytes
Total size : 1468054 Bytes
Signature data size : 1436270 Bytes
Reference data size : 31272 Bytes
Signatures total : 40920
CSI Fingerprints total : 919
CSI data size : 31888 Bytes
Target categories : 15
Target families : 697
7-5-2005 11:11:39 AM Success
Update successfully downlodaded and installed.
Memory + processor status:
==========================
Number of processors : 1
Processor architecture : Intel Pentium IV
Memory available:56 %
Total physical memory:523568 kb
Available physical memory:290824 kb
Total page file size:1280448 kb
Available on page file:1112532 kb
Total virtual memory:2097024 kb
Available virtual memory:2040064 kb
OS:Microsoft Windows XP Professional (Build 2600)
Ad-Aware SE Settings
===========================
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Obtain command line of scanned processes
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : Prior to deletion, allow unloading Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic settings in log file
Set : Include additional settings in log file
Set : Play sound at scan completion if scan locates critical objects
7/5/2005 11:16:23 AM - Scan started. (Full System Scan)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
ModuleName : \SystemRoot\System32\smss.exe
Command Line : n/a
ProcessID : 616
ThreadCreationTime : 7/5/2005 2:54:23 PM
BasePriority : Normal
#:2 [csrss.exe]
ModuleName : \??\C:\WINDOWS\system32\csrss.exe
Command Line : C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestTh
ProcessID : 696
ThreadCreationTime : 7/5/2005 2:55:26 PM
BasePriority : Normal
#:3 [winlogon.exe]
ModuleName : \??\C:\WINDOWS\system32\winlogon.exe
Command Line : winlogon.exe
ProcessID : 720
ThreadCreationTime : 7/5/2005 2:55:31 PM
BasePriority : High
#:4 [services.exe]
ModuleName : C:\WINDOWS\system32\services.exe
Command Line : C:\WINDOWS\system32\services.exe
ProcessID : 764
ThreadCreationTime : 7/5/2005 2:55:35 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
#:5 [lsass.exe]
ModuleName : C:\WINDOWS\system32\lsass.exe
Command Line : C:\WINDOWS\system32\lsass.exe
ProcessID : 776
ThreadCreationTime : 7/5/2005 2:55:35 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
ModuleName : C:\WINDOWS\system32\svchost.exe
Command Line : C:\WINDOWS\system32\svchost -k rpcss
ProcessID : 960
ThreadCreationTime : 7/5/2005 2:55:49 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k netsvcs
ProcessID : 1076
ThreadCreationTime : 7/5/2005 2:55:57 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k NetworkService
ProcessID : 1240
ThreadCreationTime : 7/5/2005 2:56:34 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k LocalService
ProcessID : 1316
ThreadCreationTime : 7/5/2005 2:57:00 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [spoolsv.exe]
ModuleName : C:\WINDOWS\system32\spoolsv.exe
Command Line : C:\WINDOWS\system32\spoolsv.exe
ProcessID : 1436
ThreadCreationTime : 7/5/2005 2:57:45 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:11 [alg.exe]
ModuleName : C:\WINDOWS\System32\alg.exe
Command Line : C:\WINDOWS\System32\alg.exe
ProcessID : 1540
ThreadCreationTime : 7/5/2005 2:57:53 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe
#:12 [netmdsb.exe]
ModuleName : C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
Command Line : "C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe"
ProcessID : 1612
ThreadCreationTime : 7/5/2005 2:57:56 PM
BasePriority : Normal
FileVersion : 2.0.03.16212
ProductVersion : 2.0.03.16212
ProductName : MD Simple Burner
CompanyName : Sony Corporation
FileDescription : MD Simple Burner
InternalName : MD Simple Burner
LegalCopyright : Copyright 2001, 2002, 2003 Sony Corporation
OriginalFilename : NetMDSB.exe
Comments : MD Simple Burner
#:13 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k imgsvc
ProcessID : 1652
ThreadCreationTime : 7/5/2005 2:58:01 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:14 [explorer.exe]
ModuleName : C:\WINDOWS\Explorer.EXE
Command Line : C:\WINDOWS\Explorer.EXE
ProcessID : 232
ThreadCreationTime : 7/5/2005 2:59:01 PM
BasePriority : Normal
FileVersion : 6.00.2600.0000 (xpclient.010817-1148)
ProductVersion : 6.00.2600.0000
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
#:15 [qttask.exe]
ModuleName : C:\Program Files\QuickTime\qttask.exe
Command Line : "C:\Program Files\QuickTime\qttask.exe" -atboottime
ProcessID : 1424
ThreadCreationTime : 7/5/2005 2:59:47 PM
BasePriority : Normal
FileVersion : 6.4
ProductVersion : QuickTime 6.4
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2003
OriginalFilename : QTTask.exe
#:16 [vkalmz.exe]
ModuleName : C:\WINDOWS\System32\vkalmz.exe
Command Line : "C:\WINDOWS\System32\vkalmz.exe" reg_run
ProcessID : 1904
ThreadCreationTime : 7/5/2005 2:59:50 PM
BasePriority : Normal
#:17 [msgplus.exe]
ModuleName : C:\Program Files\Messenger Plus! 3\MsgPlus.exe
Command Line : "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
ProcessID : 2008
ThreadCreationTime : 7/5/2005 3:00:01 PM
BasePriority : Normal
#:18 [dvpapi.exe]
ModuleName : C:\Program Files\Common Files\Command Software\dvpapi.exe
Command Line : "C:\Program Files\Common Files\Command Software\dvpapi.exe"
ProcessID : 3076
ThreadCreationTime : 7/5/2005 3:04:51 PM
BasePriority : Normal
#:19 [iexplore.exe]
ModuleName : C:\Program Files\Internet Explorer\IEXPLORE.EXE
Command Line : "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
ProcessID : 1564
ThreadCreationTime : 7/5/2005 3:06:26 PM
BasePriority : Normal
FileVersion : 6.00.2600.0000 (xpclient.010817-1148)
ProductVersion : 6.00.2600.0000
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : IEXPLORE.EXE
#:20 [iexplore.exe]
ModuleName : c:\progra~1\intern~1\iexplore.exe
Command Line : "c:\progra~1\intern~1\iexplore.exe"
ProcessID : 3120
ThreadCreationTime : 7/5/2005 3:06:58 PM
BasePriority : Normal
FileVersion : 6.00.2600.0000 (xpclient.010817-1148)
ProductVersion : 6.00.2600.0000
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : IEXPLORE.EXE
#:21 [ad-aware.exe]
ModuleName : C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
Command Line : "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe"
ProcessID : 1256
ThreadCreationTime : 7/5/2005 3:11:12 PM
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
DyFuCA Object Recognized:
Type : RegKey
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{40b1d454-9ca4-43cc-86aa-cb175eac52fb}
DyFuCA Object Recognized:
Type : RegKey
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{1c01d150-91a4-4de0-9bf8-a35d1bdf1001}
DyFuCA Object Recognized:
Type : RegKey
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : dyfuca_bh.bhobj.1
DyFuCA Object Recognized:
Type : RegKey
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : dyfuca_bh.bhobj
DyFuCA Object Recognized:
Type : RegKey
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{00000010-6f7d-442c-93e3-4a4827c2e4c8}
GetMirar Object Recognized:
Type : RegKey
Data :
TAC Index : 8
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{9a9c9b68-f908-4aab-8d0c-10ea8997f37e}
GetMirar Object Recognized:
Type : RegKey
Data :
TAC Index : 8
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{1037b06c-84b7-4240-8d80-485810a0497d}
GetMirar Object Recognized:
Type : RegKey
Data :
TAC Index : 8
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{224302b0-94e9-45c2-9e5b-ba989ee556e1}
GetMirar Object Recognized:
Type : RegKey
Data :
TAC Index : 8
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{54b287f9-fd90-4457-b65e-cb91560c021d}
GetMirar Object Recognized:
Type : RegKey
Data :
TAC Index : 8
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{6e4c7afc-9915-4036-b7f9-8b3f1710788f}
GetMirar Object Recognized:
Type : RegKey
Data :
TAC Index : 8
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : nn_bar_dummy.nn_bardummy
GetMirar Object Recognized:
Type : RegKey
Data :
TAC Index : 8
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : nn_bar_dummy.nn_bardummy.1
GetMirar Object Recognized:
Type : RegKey
Data :
TAC Index : 8
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{566dede9-9ed8-45da-9be6-9b2eeab17f49}
GetMirar Object Recognized:
Type : RegKey
Data :
TAC Index : 8
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{f8310e7d-4c4d-46a4-a068-b5bb99411cc7}
istbar Object Recognized:
Type : RegKey
Data :
TAC Index : 7
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{86227d9c-0efe-4f8a-aa55-30386a3f5686}
VX2 Object Recognized:
Type : RegKey
Data :
TAC Index : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : folder\shellex\columnhandlers\{6ec11407-5b2e-4e25-8bdf-77445b52ab37}
VX2 Object Recognized:
Type : RegKey
Data :
TAC Index : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{6ec11407-5b2e-4e25-8bdf-77445b52ab37}
DyFuCA Object Recognized:
Type : RegKey
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\policies\avenue media
DyFuCA Object Recognized:
Type : RegKey
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\ist
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\ist
Value : account_id
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\ist
Value : config
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\ist
Value : Recover
DyFuCA Object Recognized:
Type : RegKey
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\avenue media
DyFuCA Object Recognized:
Type : RegKey
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : last_conn_l
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : we
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : cdata
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : TimeOffset
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : action_url_version
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : action_url_last_chunk
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : action_url_last_full_version
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : key_file
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : kw_last_chunk
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : geourl_last_full_version
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : geourl_current_version
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : actionurl_last_full_version
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : actionurl_current_version
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : keyword_last_full_version
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : keyword_current_version
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : recent_shown
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : key_int_high
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\sais
Value : key_int_low
DyFuCA Object Recognized:
Type : RegKey
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\sais
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\sais
Value : mt2
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\sais
Value : mt3
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\sais
Value : gma
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\sais
Value : gvi
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\sais
Value : gpi
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\sais
Value : boom
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\sais
Value : boom_ver
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\sais
Value : did
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\sais
Value : duid
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\sais
Value : partner_id
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\sais
Value : product_id
DyFuCA Object Recognized:
Type : RegValue
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\sais
Value : umt
DyFuCA Object Recognized:
Type : RegKey
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\policies\avenue media
DyFuCA Object Recognized:
Type : RegKey
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\dyfuca
DyFuCA Object Recognized:
Type : RegKey
Data : DyFuCA
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : .DEFAULT\software\microsoft\windows\currentversion\uninstall\DyFuCA
DyFuCA Object Recognized:
Type : RegKey
Data : DyFuCA
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-18\software\microsoft\windows\currentversion\uninstall\DyFuCA
DyFuCA Object Recognized:
Type : RegKey
Data : DyFuCA
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-19\software\microsoft\windows\currentversion\uninstall\DyFuCA
DyFuCA Object Recognized:
Type : RegKey
Data : DyFuCA
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-20\software\microsoft\windows\currentversion\uninstall\DyFuCA
DyFuCA Object Recognized:
Type : RegKey
Data : DyFuCA
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\microsoft\windows\currentversion\uninstall\DyFuCA
DyFuCA Object Recognized:
Type : RegKey
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\explorer\browser helper objects\{00000010-6f7d-442c-93e3-4a4827c2e4c8}
DyFuCA Object Recognized:
Type : RegKey
Data :
TAC Index : 3
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\avenue media
istbar Object Recognized:
Type : RegValue
Data :
TAC Index : 7
Category : Malware
Comment : "{86227D9C-0EFE-4f8a-AA55-30386A3F5686}"
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\microsoft\internet explorer\toolbar\webbrowser
Value : {86227D9C-0EFE-4f8a-AA55-30386A3F5686}
Powerscan Object Recognized:
Type : RegValue
Data :
TAC Index : 5
Category : Malware
Comment : "account_id"
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\software\powerscan
Value : account_id
Powerscan Object Recognized:
Type : RegValue
Data :
TAC Index : 5
Category : Malware
Comment : "LoadNum"
Rootkey : HKEY_LOCAL_MACHINE
Object : software\powerscan
Value : LoadNum
Powerscan Object Recognized:
Type : RegValue
Data :
TAC Index : 5
Category : Malware
Comment : "account_id"
Rootkey : HKEY_USERS
Object : S-1-5-21-448539723-1563985344-682003330-1004\\software\powerscan
Value : account_id
Registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 68
Objects found so far: 68
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 0
Objects found so far: 68
Started tracking cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : katherine@trafficmp[2].txt
TAC Index : 3
Category : Data Miner
Comment : Hits:6
Value : Cookie:[email protected]/
Expires : 7/5/2006 11:28:48 AM
LastSync : Hits:6
UseCount : 0
Hits : 6
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : katherine@casalemedia[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Katherine\Cookies\katherine@casalemedia[1].txt
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 2
Objects found so far: 70
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@247realmedia[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@247realmedia[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@2o7[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@2o7[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@ad-logics[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@ad-logics[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@adrevolver[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@adrevolver[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@adrevolver[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@adrevolver[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@advertising[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@advertising[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@adviva[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@adviva[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@apmebf[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@apmebf[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@atdmt[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@atdmt[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@bfast[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@bfast[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@bluestreak[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@bluestreak[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@casalemedia[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@casalemedia[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@centrport[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@centrport[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@cgi-bin[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@cgi-bin[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@cgi-bin[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@cgi-bin[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@doubleclick[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@doubleclick[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@estat[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@estat[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@euniverseads[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@euniverseads[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@fastclick[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@fastclick[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@findwhat[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@findwhat[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@hitbox[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@hitbox[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@lop[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@lop[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@maxserving[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@maxserving[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@mediaplex[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@mediaplex[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@okcounter[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@okcounter[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@qksrv[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@qksrv[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@questionmarket[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@questionmarket[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@realmedia[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@realmedia[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@revenue[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@revenue[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@serving-sys[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@serving-sys[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@statcounter[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@statcounter[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@targetnet[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@targetnet[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@tickle[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@tickle[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@tradedoubler[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@tradedoubler[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@trafficmp[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@trafficmp[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@tribalfusion[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@tribalfusion[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@valueclick[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@valueclick[1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@weborama[2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@weborama[2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][2].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][2].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : [email protected][1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\[email protected][1].txt
Tracking Cookie Object Recognized:
Type : IECache Entry
Data : carmina@zedo[1].txt
TAC Index : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Carmina\Cookies\carmina@zedo[1].txt
Lop Object Recognized: