Many thanks....
HL
Ad-Aware SE Build 1.05
Logfile Created on:2005年4月23日 上午 09:57:16
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R40 20.04.2005
References detected during the scan:
Alexa(TAC index:5):1 total references
CoolWebSearch(TAC index:10):14 total references
Security iGuard(TAC index:9):1 total references
Tracking Cookie(TAC index:3):16 total references
Definition File:
=========================
Definitions File Loaded:
Reference Number : SE1R40 20.04.2005
Internal build : 47
File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
File size : 461235 Bytes
Total size : 1395231 Bytes
Signature data size : 1364710 Bytes
Reference data size : 30009 Bytes
Signatures total : 38921
Fingerprints total : 813
Fingerprints size : 29073 Bytes
Target categories : 15
Target families : 650
Memory + processor status:
==========================
Number of processors : 1
Processor architecture : Intel Pentium III
Memory available:69 %
Total physical memory:1048048 kb
Available physical memory:713808 kb
Total page file size:2522304 kb
Available on page file:2028368 kb
Total virtual memory:2097024 kb
Available virtual memory:2044968 kb
OS:Microsoft Windows 2000 Professional (Build 2195)
Ad-Aware SE Settings
===========================
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Obtain command line of scanned processes
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Play sound at scan completion if scan locates critical objects
2005-4-23 上午 09:57:16 - Scan started. (Full System Scan)
Listing running processes
#:1 [smss.exe]
ModuleName : \SystemRoot\System32\smss.exe
Command Line : n/a
ProcessID : 144
ThreadCreationTime : 2005-4-23 下午 03:56:18
BasePriority : Normal
#:2 [csrss.exe]
ModuleName : \??\C:\WINNT\system32\csrss.exe
Command Line : C:\WINNT\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequest
ProcessID : 168
ThreadCreationTime : 2005-4-23 下午 03:56:27
BasePriority : Normal
#:3 [winlogon.exe]
ModuleName : \??\C:\WINNT\system32\winlogon.exe
Command Line : winlogon.exe
ProcessID : 188
ThreadCreationTime : 2005-4-23 下午 03:56:29
BasePriority : High
#:4 [services.exe]
ModuleName : C:\WINNT\system32\services.exe
Command Line : C:\WINNT\system32\services.exe
ProcessID : 216
ThreadCreationTime : 2005-4-23 下午 03:56:30
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : services.exe
#:5 [lsass.exe]
ModuleName : C:\WINNT\system32\lsass.exe
Command Line : C:\WINNT\system32\lsass.exe
ProcessID : 228
ThreadCreationTime : 2005-4-23 下午 03:56:30
BasePriority : Normal
FileVersion : 5.00.2184.1
ProductVersion : 5.00.2184.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Executable and Server DLL (Export Version)
InternalName : lsasrv.dll and lsass.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : lsasrv.dll and lsass.exe
#:6 [svchost.exe]
ModuleName : C:\WINNT\system32\svchost.exe
Command Line : C:\WINNT\system32\svchost -k rpcss
ProcessID : 464
ThreadCreationTime : 2005-4-23 下午 03:56:33
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:7 [spoolsv.exe]
ModuleName : C:\WINNT\system32\spoolsv.exe
Command Line : C:\WINNT\system32\spoolsv.exe
ProcessID : 492
ThreadCreationTime : 2005-4-23 下午 03:56:33
BasePriority : Normal
FileVersion : 5.00.2161.1
ProductVersion : 5.00.2161.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolss.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : spoolss.exe
#:8 [svchost.exe]
ModuleName : C:\WINNT\System32\svchost.exe
Command Line : C:\WINNT\System32\svchost.exe -k netsvcs
ProcessID : 524
ThreadCreationTime : 2005-4-23 下午 03:56:33
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:9 [nvsvc32.exe]
ModuleName : C:\WINNT\System32\nvsvc32.exe
Command Line : C:\WINNT\System32\nvsvc32.exe
ProcessID : 552
ThreadCreationTime : 2005-4-23 下午 03:56:34
BasePriority : Normal
FileVersion : 6.13.10.4071
ProductVersion : 6.13.10.4071
ProductName : NVIDIA Driver Helper Service, Version 40.71
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA Driver Helper Service, Version 40.71
InternalName : NVSVC
LegalCopyright : © NVIDIA Corporation. All rights reserved.
OriginalFilename : nvsvc32.exe
#:10 [regsvc.exe]
ModuleName : C:\WINNT\system32\regsvc.exe
Command Line : C:\WINNT\system32\regsvc.exe
ProcessID : 584
ThreadCreationTime : 2005-4-23 下午 03:56:35
BasePriority : Normal
FileVersion : 5.00.2155.1
ProductVersion : 5.00.2155.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Remote Registry Service
InternalName : regsvc
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : REGSVC.EXE
#:11 [mstask.exe]
ModuleName : C:\WINNT\system32\MSTask.exe
Command Line : C:\WINNT\system32\MSTask.exe
ProcessID : 616
ThreadCreationTime : 2005-4-23 下午 03:56:35
BasePriority : Normal
FileVersion : 4.71.2137.1
ProductVersion : 4.71.2137.1
ProductName : Microsoft® Windows® Task Scheduler
CompanyName : Microsoft Corporation
FileDescription : Task Scheduler Engine
InternalName : TaskScheduler
LegalCopyright : Copyright © Microsoft Corp. 1997
OriginalFilename : mstask.exe
#:12 [tmntsrv.exe]
ModuleName : C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
Command Line : "C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe"
ProcessID : 656
ThreadCreationTime : 2005-4-23 下午 03:56:35
BasePriority : Normal
FileVersion : 9.0.5.1389
ProductVersion : 9.0.5
ProductName : Trend Pc-cillin 9.0
CompanyName : Trend Micro Inc.
FileDescription : Tmntsrv
InternalName : Tmntsrv
LegalCopyright : Copyright © 2001-2002 Trend Micro Inc. All rights reserved.
LegalTrademarks : Copyright © Trend Micro Inc.
OriginalFilename : Tmntsrv.exe
#:13 [winmgmt.exe]
ModuleName : C:\WINNT\System32\WBEM\WinMgmt.exe
Command Line : C:\WINNT\System32\WBEM\WinMgmt.exe
ProcessID : 748
ThreadCreationTime : 2005-4-23 下午 03:56:39
BasePriority : Normal
FileVersion : 1.50.1085.0001
ProductVersion : 1.50.1085.0001
ProductName : Windows Management Instrumentation
CompanyName : Microsoft Corporation
FileDescription : Windows Management Instrumentation
InternalName : WINMGMT
LegalCopyright : Copyright © Microsoft Corp. 1995-1999
#:14 [pccpfw.exe]
ModuleName : C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
Command Line : "C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe"
ProcessID : 848
ThreadCreationTime : 2005-4-23 下午 03:56:40
BasePriority : Normal
#:15 [explorer.exe]
ModuleName : C:\WINNT\explorer.exe
Command Line : "C:\WINNT\explorer.exe"
ProcessID : 1000
ThreadCreationTime : 2005-4-23 下午 03:56:45
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : EXPLORER.EXE
#:16 [taskmgru.exe]
ModuleName : C:\WINNT\System32\TASKMGRU.EXE
Command Line : "C:\WINNT\System32\TASKMGRU.EXE" open
ProcessID : 1016
ThreadCreationTime : 2005-4-23 下午 03:56:45
BasePriority : Normal
#:17 [msimn32.exe]
ModuleName : C:\WINNT\System32\MSIMN32.EXE
Command Line : "C:\WINNT\System32\MSIMN32.EXE" open
ProcessID : 1024
ThreadCreationTime : 2005-4-23 下午 03:56:46
BasePriority : Normal
#:18 [rundll32.exe]
ModuleName : C:\WINNT\System32\RunDll32.exe
Command Line : "C:\WINNT\System32\RunDll32.exe" cmicnfg.cpl,CMICtrlWnd
ProcessID : 1096
ThreadCreationTime : 2005-4-23 下午 03:56:49
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : RUNDLL.EXE
#:19 [disk_monitor.exe]
ModuleName : C:\Program Files\IC Card Reader Driver v1.8e2\Disk_Monitor.exe
Command Line : "C:\Program Files\IC Card Reader Driver v1.8e2\Disk_Monitor.exe"
ProcessID : 1048
ThreadCreationTime : 2005-4-23 下午 03:56:49
BasePriority : Normal
FileVersion : 1.6.1204.1
ProductVersion : 1.6.1204.1
ProductName : Disk Monitor
CompanyName : Neodio Corp.
FileDescription : Disk Monitor
InternalName : Disk Monitor(ECS)
LegalCopyright : Copyright © Neodio Corp. 2001
LegalTrademarks : Disk Monitor
OriginalFilename : Disk_Monitor.exe
#:20 [pccguide.exe]
ModuleName : C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe
Command Line : "C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
ProcessID : 1064
ThreadCreationTime : 2005-4-23 下午 03:56:50
BasePriority : Normal
FileVersion : 9.0.5.1389
ProductVersion : 9.0.5
ProductName : Trend Pc-cillin 9.0
CompanyName : Trend Micro Inc.
FileDescription : PCCGuide
InternalName : PCCGuide
LegalCopyright : Copyright © 2001-2002 Trend Micro Inc. All rights reserved.
LegalTrademarks : Copyright © Trend Micro Inc.
OriginalFilename : PCCGuide
#:21 [pccclient.exe]
ModuleName : C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe
Command Line : "C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
ProcessID : 1116
ThreadCreationTime : 2005-4-23 下午 03:56:50
BasePriority : Normal
FileVersion : 9.0.5.1389
ProductVersion : 9.0.5
ProductName : Trend Pc-cillin 9.0
CompanyName : Trend Micro Inc.
FileDescription : PCCClient
InternalName : PCCClient
LegalCopyright : Copyright © 2001-2002 Trend Micro Inc. All rights reserved.
LegalTrademarks : Copyright © Trend Micro Inc.
OriginalFilename : PCCClient
#:22 [pop3trap.exe]
ModuleName : C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe
Command Line : "C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
ProcessID : 1128
ThreadCreationTime : 2005-4-23 下午 03:56:50
BasePriority : Normal
FileVersion : 9.0.5.1389
ProductVersion : 9.0.5
ProductName : Trend Pc-cillin 9.0
CompanyName : Trend Micro Inc.
FileDescription : POP3Trap
InternalName : POP3Trap
LegalCopyright : Copyright © 2001-2002 Trend Micro Inc. All rights reserved.
LegalTrademarks : Copyright © Trend Micro Inc.
OriginalFilename : POP3Trap
#:23 [incd.exe]
ModuleName : C:\Program Files\Ahead\InCD\InCD.exe
Command Line : "C:\Program Files\Ahead\InCD\InCD.exe"
ProcessID : 1148
ThreadCreationTime : 2005-4-23 下午 03:56:51
BasePriority : Normal
#:24 [lvcoms.exe]
ModuleName : C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
Command Line : "C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE"
ProcessID : 1136
ThreadCreationTime : 2005-4-23 下午 03:56:52
BasePriority : Normal
FileVersion : 7.3.0.1113
ProductVersion : 7.3.0.1113
ProductName : Logitech ImageStudio
CompanyName : Logitech Inc.
FileDescription : LVCom Server
InternalName : LVComS.exe
LegalCopyright : © 1996-2002 Logitech. All rights reserved.
OriginalFilename : LVComS.exe
#:25 [logitray.exe]
ModuleName : C:\Program Files\Logitech\ImageStudio\LogiTray.exe
Command Line : "C:\Program Files\Logitech\ImageStudio\LogiTray.exe"
ProcessID : 1220
ThreadCreationTime : 2005-4-23 下午 03:56:53
BasePriority : Normal
FileVersion : 7.3.0.1113
ProductVersion : 7.3.0.1113
ProductName : Logitech ImageStudio
CompanyName : Logitech Inc.
FileDescription : ImageStudio Tray Application
InternalName : LogiTray.exe
LegalCopyright : © 1996-2002 Logitech. All rights reserved.
OriginalFilename : LogiTray.exe
#:26 [loadqm.exe]
ModuleName : C:\WINNT\loadqm.exe
Command Line : "C:\WINNT\loadqm.exe"
ProcessID : 1280
ThreadCreationTime : 2005-4-23 下午 03:56:54
BasePriority : Normal
FileVersion : 5.4.1103.3
ProductVersion : 5.4.1103.3
ProductName : QMgr Loader
CompanyName : Microsoft Corporation
FileDescription : Microsoft QMgr
InternalName : LOADQM.EXE
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : LOADQM.EXE
#:27 [ituneshelper.exe]
ModuleName : C:\Program Files\iTunes\iTunesHelper.exe
Command Line : "C:\Program Files\iTunes\iTunesHelper.exe"
ProcessID : 1320
ThreadCreationTime : 2005-4-23 下午 03:56:56
BasePriority : Normal
FileVersion : 4.6.0.15
ProductVersion : 4.6.0.15
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : c 2003-2004 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe
#:28 [qttask.exe]
ModuleName : C:\Program Files\QuickTime\qttask.exe
Command Line : "C:\Program Files\QuickTime\qttask.exe" -atboottime
ProcessID : 1184
ThreadCreationTime : 2005-4-23 下午 03:56:57
BasePriority : Normal
FileVersion : 6.5.1
ProductVersion : QuickTime 6.5.1
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : c Apple Computer, Inc. 2001-2004
OriginalFilename : QTTask.exe
#:29 [msnappau.exe]
ModuleName : C:\Program Files\MSN Apps\Updater\01.02.3000.1001\zh-tw\msnappau.exe
Command Line : "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\zh-tw\msnappau.exe"
ProcessID : 1328
ThreadCreationTime : 2005-4-23 下午 03:56:58
BasePriority : Normal
#:30 [internat.exe]
ModuleName : C:\WINNT\System32\internat.exe
Command Line : "C:\WINNT\System32\internat.exe"
ProcessID : 1336
ThreadCreationTime : 2005-4-23 下午 03:56:58
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Keyboard Language Indicator Applet
InternalName : INTERNAT
LegalCopyright : Copyright © Microsoft Corp. 1994-1999
OriginalFilename : INTERNAT.EXE
#:31 [backweb-8876480.exe]
ModuleName : C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
Command Line : "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe"
ProcessID : 1396
ThreadCreationTime : 2005-4-23 下午 03:57:00
BasePriority : Normal
#:32 [ipodservice.exe]
ModuleName : C:\Program Files\iPod\bin\iPodService.exe
Command Line : "C:\Program Files\iPod\bin\iPodService.exe"
ProcessID : 1408
ThreadCreationTime : 2005-4-23 下午 03:57:00
BasePriority : Normal
FileVersion : 4.6.0.15
ProductVersion : 4.6.0.15
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : c 2003-2004 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iPodService.exe
#:33 [skype.exe]
ModuleName : C:\Program Files\Skype\Phone\Skype.exe
Command Line : "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
ProcessID : 1432
ThreadCreationTime : 2005-4-23 下午 03:57:03
BasePriority : Normal
#:34 [robotaskbaricon.exe]
ModuleName : C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
Command Line : "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
ProcessID : 1452
ThreadCreationTime : 2005-4-23 下午 03:57:03
BasePriority : Normal
#:35 [taskmgru.exe]
ModuleName : C:\WINNT\System32\TASKMGRU.EXE
Command Line : "C:\WINNT\System32\TASKMGRU.EXE"
ProcessID : 1460
ThreadCreationTime : 2005-4-23 下午 03:57:04
BasePriority : Normal
#:36 [msimn32.exe]
ModuleName : C:\WINNT\System32\MSIMN32.EXE
Command Line : "C:\WINNT\System32\MSIMN32.EXE"
ProcessID : 1468
ThreadCreationTime : 2005-4-23 下午 03:57:04
BasePriority : Normal
#:37 [wp.exe]
ModuleName : C:\wp.exe
Command Line : "C:\wp.exe"
ProcessID : 1512
ThreadCreationTime : 2005-4-23 下午 03:57:04
BasePriority : Normal
#:38 [ud.exe]
ModuleName : C:\Program Files\United Devices\UD.EXE
Command Line : "C:\Program Files\United Devices\UD.EXE"
ProcessID : 1488
ThreadCreationTime : 2005-4-23 下午 03:57:08
BasePriority : Normal
FileVersion : 3.00.2814
ProductVersion : 3.00.2814
ProductName : UD Agent
CompanyName : United Devices, Inc.
FileDescription : United Devices
InternalName : UDagent_3801_2814
LegalCopyright : Copyright United Devices
LegalTrademarks : United Devices
OriginalFilename : UDagent_3801_2814.exe
Comments : UD Agent Version 3.0
#:39 [ud_7657531.exe]
ModuleName : C:\Program Files\United Devices\ud_7657531.exe
Command Line : ud_7657531.exe
ProcessID : 1628
ThreadCreationTime : 2005-4-23 下午 03:57:24
BasePriority : Idle
#:40 [wcgrid_rosetta.exe]
ModuleName : C:\Program Files\United Devices\ud_7657531_0.dir\WCGrid_Rosetta.exe
Command Line : "C:/Program Files/United Devices/ud_7657531_0.dir/WCGrid_Rosetta.exe" -series 0A -protein bi19 -chain 9 -nstruct 843 -constant_seed -jran 935991 -silent
ProcessID : 1608
ThreadCreationTime : 2005-4-23 下午 03:57:31
BasePriority : Idle
FileVersion : 1, 0, 0, 5
ProductName : Rosetta Fragments and Rosetta ab-initio
CompanyName : University of Washington and IBM Corporation
FileDescription : Created under grants from the National Science Foundation number MCB-9458178, the Packard Foundation, the Los Alamos National Laboratory, Office of Naval Research grant number N00014-95-1-0417, and the Howard Hughes Medical Institute
InternalName : WCGrid_Rosetta.exe
LegalCopyright : Copyright © Unversity of Washington 2000-2004 and IBM Corp. 2004. All Rights Reserved
OriginalFilename : Rosetta
#:41 [ad-aware.exe]
ModuleName : C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
Command Line : "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe"
ProcessID : 1340
ThreadCreationTime : 2005-4-23 下午 04:56:08
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright c Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
New critical objects: 0
Objects found so far: 0
Started registry scan
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{5297e905-1dfb-4a9c-9871-a4f95fd58945}
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : toolband.toolbandobj.1
CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : toolband.toolbandobj.1
Value :
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : toolband.toolbandobj
CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : toolband.toolbandobj
Value :
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{95b92d92-8b7d-4a19-a3f1-43113b4dbcaf}
CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{95b92d92-8b7d-4a19-a3f1-43113b4dbcaf}
Value :
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{0e1230f8-ea50-42a9-983c-d22abc2eed3b}
CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{0e1230f8-ea50-42a9-983c-d22abc2eed3b}
Value :
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{0b6ef17e-18e5-4449-86ea-64c82d596eae}
CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{0b6ef17e-18e5-4449-86ea-64c82d596eae}
Value :
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{b1e68d42-02c4-465b-8368-5ed9b732e22d}
CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{b1e68d42-02c4-465b-8368-5ed9b732e22d}
Value :
Security iGuard Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\rex-services
Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment : "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
Rootkey : HKEY_USERS
Object : S-1-5-21-839522115-1993962763-682003330-500\software\microsoft\internet explorer\extensions\cmdmapping
Value : {c95fe080-8f5d-11d2-a20b-00aa003c157a}
Registry Scan result:
New critical objects: 15
Objects found so far: 15
Started deep registry scan
Deep registry scan result:
New critical objects: 0
Objects found so far: 15
Started Tracking Cookie scan
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@2o7[1].txt
Category : Data Miner
Comment : Hits:4
Value : Cookie:[email protected]/
Expires : 2010-4-21 上午 01:05:46
LastSync : Hits:4
UseCount : 0
Hits : 4
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [email protected][1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:[email protected]/
Expires : 2005-5-22 上午 01:05:04
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@doubleclick[2].txt
Category : Data Miner
Comment : Hits:2
Value : Cookie:[email protected]/
Expires : 2008-4-21 上午 01:05:04
LastSync : Hits:2
UseCount : 0
Hits : 2
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [email protected][1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:[email protected]/
Expires : 2006-4-22 上午 01:04:56
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@advertising[2].txt
Category : Data Miner
Comment : Hits:2
Value : Cookie:[email protected]/
Expires : 2010-4-21 上午 01:05:04
LastSync : Hits:2
UseCount : 0
Hits : 2
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@hitbox[2].txt
Category : Data Miner
Comment : Hits:2
Value : Cookie:[email protected]/
Expires : 2006-4-22 上午 01:04:56
LastSync : Hits:2
UseCount : 0
Hits : 2
Tracking cookie scan result:
遙遙遙遙遙遙遙遙遙遙遙遙遙遙遙遙遙遙遙
New critical objects: 6
Objects found so far: 21
Deep scanning and examining files (C:)
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@2o7[1].txt
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@2o7[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [email protected][2].txt
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[email protected][2].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@advertising[2].txt
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@advertising[2].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@atdmt[2].txt
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@atdmt[2].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@bluestreak[1].txt
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@bluestreak[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@centrport[2].txt
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@centrport[2].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [email protected][1].txt
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[email protected][1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@doubleclick[1].txt
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@doubleclick[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : administrator@mediaplex[1].txt
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@mediaplex[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [email protected][2].txt
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[email protected][2].txt
Disk Scan Result for C:\
New critical objects: 0
Objects found so far: 31
Scanning Hosts file......
Hosts file location:"C:\WINNT\system32\drivers\etc\hosts".
Hosts file scan result:
1 entries scanned.
New critical objects:0
Objects found so far: 31
Performing conditional scans...
CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Enable Browser Extensions
Conditional scan result:
New critical objects: 1
Objects found so far: 32
上午 09:58:11 Scan Complete
Summary Of This Scan
Total scanning time:00:00:55.219
Objects scanned:49634
Objects identified:32
Objects ignored:0
New critical objects:32