I'm a newbie and need some help from you guys. Today my PC's antivirus prompt me that i have some trojans im my PC but quarantined already. But after few minutes another trojan captured by the antivirus, Just now i run the Ad-Aware and find Cool Web search in it. please find my ad-aware log as attached.
Ad-Aware SE Build 1.06r1
Logfile Created on:Friday, 9 December 2005 3:26:18 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R78 07.12.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
CoolWebSearch(TAC index:10):6 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
9-12-2005 3:26:18 PM - Scan started. (Full System Scan)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 152
ThreadCreationTime : 9-12-2005 6:28:19 AM
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINNT\system32\
ProcessID : 180
ThreadCreationTime : 9-12-2005 6:28:27 AM
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINNT\system32\
ProcessID : 200
ThreadCreationTime : 9-12-2005 6:28:28 AM
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINNT\system32\
ProcessID : 228
ThreadCreationTime : 9-12-2005 6:28:30 AM
BasePriority : Normal
FileVersion : 5.00.2195.6700
ProductVersion : 5.00.2195.6700
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINNT\system32\
ProcessID : 240
ThreadCreationTime : 9-12-2005 6:28:30 AM
BasePriority : Normal
FileVersion : 5.00.2195.6695
ProductVersion : 5.00.2195.6695
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Executable and Server DLL (Export Version)
InternalName : lsasrv.dll and lsass.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : lsasrv.dll and lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 400
ThreadCreationTime : 9-12-2005 6:28:34 AM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 444
ThreadCreationTime : 9-12-2005 6:28:34 AM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:8 [spoolsv.exe]
FilePath : C:\WINNT\system32\
ProcessID : 492
ThreadCreationTime : 9-12-2005 6:28:34 AM
BasePriority : Normal
FileVersion : 5.00.2195.6659
ProductVersion : 5.00.2195.6659
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolss.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : spoolss.exe
#:9 [btntservice.exe]
FilePath : C:\Program Files\IVT Corporation\BlueSoleil\
ProcessID : 596
ThreadCreationTime : 9-12-2005 6:28:45 AM
BasePriority : High
#:10 [mdm.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7Debug\
ProcessID : 636
ThreadCreationTime : 9-12-2005 6:28:45 AM
BasePriority : Normal
FileVersion : 7.00.9064.9150
ProductVersion : 7.00.9064.9150
ProductName : Microsoft Development Environment
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : Copyright © Microsoft Corp. 1997-2000
OriginalFilename : mdm.exe
#:11 [ntrtscan.exe]
FilePath : C:\Program Files\OfficeScan NT\
ProcessID : 672
ThreadCreationTime : 9-12-2005 6:28:46 AM
BasePriority : Normal
FileVersion : 5.5.0.2008
ProductVersion : 5.5
ProductName : Trend Micro OfficeScan
CompanyName : Trend Micro Inc.
LegalCopyright : Copyright © 1999-2004 Trend Micro Incorporated. All rights reserved.
LegalTrademarks : Copyright © Trend Micro, Inc.
#:12 [regsvc.exe]
FilePath : C:\WINNT\system32\
ProcessID : 764
ThreadCreationTime : 9-12-2005 6:28:48 AM
BasePriority : Normal
FileVersion : 5.00.2195.6701
ProductVersion : 5.00.2195.6701
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Remote Registry Service
InternalName : regsvc
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : REGSVC.EXE
#:13 [mstask.exe]
FilePath : C:\WINNT\system32\
ProcessID : 788
ThreadCreationTime : 9-12-2005 6:28:48 AM
BasePriority : Normal
FileVersion : 4.71.2195.6704
ProductVersion : 4.71.2195.6704
ProductName : Microsoft® Windows® Task Scheduler
CompanyName : Microsoft Corporation
FileDescription : Task Scheduler Engine
InternalName : TaskScheduler
LegalCopyright : Copyright © Microsoft Corp. 1997
OriginalFilename : mstask.exe
#:14 [tmlisten.exe]
FilePath : C:\Program Files\OfficeScan NT\
ProcessID : 352
ThreadCreationTime : 9-12-2005 6:28:49 AM
BasePriority : Normal
#:15 [winmgmt.exe]
FilePath : C:\WINNT\System32\WBEM\
ProcessID : 876
ThreadCreationTime : 9-12-2005 6:28:51 AM
BasePriority : Normal
FileVersion : 1.50.1085.0100
ProductVersion : 1.50.1085.0100
ProductName : Windows Management Instrumentation
CompanyName : Microsoft Corporation
FileDescription : Windows Management Instrumentation
InternalName : WINMGMT
LegalCopyright : Copyright © Microsoft Corp. 1995-1999
#:16 [winvnc.exe]
FilePath : C:\Program Files\ORL\VNC\
ProcessID : 916
ThreadCreationTime : 9-12-2005 6:28:55 AM
BasePriority : Normal
FileVersion : 3, 3, 3, 7
ProductVersion : 3, 3, 3, 7
ProductName : AT&T Research Labs Cambridge - WinVNC
CompanyName : AT&T Research Labs Cambridge
FileDescription : VNC server for Win32
InternalName : WinVNC
LegalCopyright : Copyright AT&T Research Labs Cambridge© 1998-2000
OriginalFilename : WinVNC.exe
#:17 [ofcdog.exe]
FilePath : C:\Program Files\OfficeScan NT\
ProcessID : 1084
ThreadCreationTime : 9-12-2005 6:28:55 AM
BasePriority : Normal
#:18 [explorer.exe]
FilePath : C:\WINNT\
ProcessID : 1260
ThreadCreationTime : 9-12-2005 6:29:07 AM
BasePriority : Normal
FileVersion : 5.00.3700.6690
ProductVersion : 5.00.3700.6690
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : EXPLORER.EXE
#:19 [winlogon.exe]
FilePath : C:\WINNT\inet20066\
ProcessID : 1420
ThreadCreationTime : 9-12-2005 6:29:23 AM
BasePriority : Normal
#:20 [pccntmon.exe]
FilePath : C:\Program Files\OfficeScan NT\
ProcessID : 1432
ThreadCreationTime : 9-12-2005 6:29:25 AM
BasePriority : Normal
FileVersion : 5.5.0.2008
ProductVersion : 5.5
ProductName : Trend Micro OfficeScan
CompanyName : Trend Micro Inc.
FileDescription : I/O Monitor
InternalName : PCCNTMON
LegalCopyright : Copyright © 1999-2004 Trend Micro Incorporated. All rights reserved.
LegalTrademarks : Copyright © Trend Micro, Inc.
OriginalFilename : PCCNTMON.EXE
#:21 [winampa.exe]
FilePath : C:\Program Files\Winamp\
ProcessID : 588
ThreadCreationTime : 9-12-2005 6:29:26 AM
BasePriority : Normal
#:22 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 696
ThreadCreationTime : 9-12-2005 6:29:27 AM
BasePriority : Normal
FileVersion : 0.1.0.3292
ProductVersion : 0.1.0.3292
ProductName : RealPlayer (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
LegalTrademarks : RealAudio is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe
#:23 [ctfmon.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1484
ThreadCreationTime : 9-12-2005 6:29:28 AM
BasePriority : Normal
FileVersion : 1.00.2409.7 built by: Lab06_N
ProductVersion : 1.00.2409.7
ProductName : Microsoft® Windows NT® Operating System
CompanyName : Microsoft Corporation
FileDescription : Cicero Loader
InternalName : CICLOAD
LegalCopyright : Copyright © Microsoft Corporation. 1981-2001
OriginalFilename : CICLOAD.EXE
#:24 [winstall.exe]
FilePath : C:\
ProcessID : 1504
ThreadCreationTime : 9-12-2005 6:29:29 AM
BasePriority : Normal
#:25 [sywsvcs.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1512
ThreadCreationTime : 9-12-2005 6:29:30 AM
BasePriority : Normal
#:26 [bluesoleil.exe]
FilePath : C:\Program Files\IVT Corporation\BlueSoleil\
ProcessID : 1584
ThreadCreationTime : 9-12-2005 6:29:34 AM
BasePriority : High
FileVersion : 1, 6, 1, 4
ProductVersion : 1, 6, 1, 4
ProductName : BlueSoleil
CompanyName : IVT Corporation
FileDescription : Bluetooth Application
InternalName : BlueSoleil
LegalCopyright : Copyright © 2000-2004
LegalTrademarks : BlueSoleil
OriginalFilename : BlueSol.exe
#:27 [ymsgr_tray.exe]
FilePath : D:\Program Files\Yahoo!\Messenger\
ProcessID : 1696
ThreadCreationTime : 9-12-2005 6:29:48 AM
BasePriority : Normal
#:28 [stisvc.exe]
FilePath : C:\WINNT\system32\
ProcessID : 652
ThreadCreationTime : 9-12-2005 6:33:58 AM
BasePriority : Normal
FileVersion : 5.00.2195.6656
ProductVersion : 5.00.2195.6656
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Still Image Devices Monitor
InternalName : STIMON
LegalCopyright : Copyright © Microsoft Corp. 1996-1997
OriginalFilename : STIMON.EXE
#:29 [iexplore.exe]
FilePath : C:\WINNT\system32\dllcache\
ProcessID : 1880
ThreadCreationTime : 9-12-2005 6:42:13 AM
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : IEXPLORE.EXE
#:30 [socks.exe]
FilePath : C:\WINNT\inet20066\
ProcessID : 852
ThreadCreationTime : 9-12-2005 6:42:16 AM
BasePriority : Normal
#:31 [iexplore.exe]
FilePath : C:\WINNT\system32\dllcache\
ProcessID : 1212
ThreadCreationTime : 9-12-2005 6:42:19 AM
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : IEXPLORE.EXE
#:32 [iexplore.exe]
FilePath : C:\WINNT\system32\dllcache\
ProcessID : 1940
ThreadCreationTime : 9-12-2005 6:42:24 AM
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : IEXPLORE.EXE
#:33 [iexplore.exe]
FilePath : C:\WINNT\system32\dllcache\
ProcessID : 1948
ThreadCreationTime : 9-12-2005 6:42:24 AM
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : IEXPLORE.EXE
#:34 [iexplore.exe]
FilePath : C:\WINNT\system32\dllcache\
ProcessID : 1956
ThreadCreationTime : 9-12-2005 6:42:24 AM
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : IEXPLORE.EXE
#:35 [iexplore.exe]
FilePath : C:\WINNT\system32\dllcache\
ProcessID : 1964
ThreadCreationTime : 9-12-2005 6:42:24 AM
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : IEXPLORE.EXE
#:36 [iexplore.exe]
FilePath : C:\WINNT\system32\dllcache\
ProcessID : 1972
ThreadCreationTime : 9-12-2005 6:42:24 AM
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : IEXPLORE.EXE
#:37 [iexplore.exe]
FilePath : C:\WINNT\system32\dllcache\
ProcessID : 1980
ThreadCreationTime : 9-12-2005 6:42:24 AM
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : IEXPLORE.EXE
#:38 [iexplore.exe]
FilePath : C:\WINNT\system32\dllcache\
ProcessID : 1988
ThreadCreationTime : 9-12-2005 6:42:24 AM
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : IEXPLORE.EXE
#:39 [iexplore.exe]
FilePath : C:\WINNT\system32\dllcache\
ProcessID : 1996
ThreadCreationTime : 9-12-2005 6:42:24 AM
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : IEXPLORE.EXE
#:40 [iexplore.exe]
FilePath : C:\WINNT\system32\dllcache\
ProcessID : 2004
ThreadCreationTime : 9-12-2005 6:42:24 AM
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : IEXPLORE.EXE
#:41 [iexplore.exe]
FilePath : C:\WINNT\system32\dllcache\
ProcessID : 2012
ThreadCreationTime : 9-12-2005 6:42:24 AM
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : IEXPLORE.EXE
#:42 [iexplore.exe]
FilePath : C:\WINNT\system32\dllcache\
ProcessID : 2020
ThreadCreationTime : 9-12-2005 6:42:24 AM
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : IEXPLORE.EXE
#:43 [iexplore.exe]
FilePath : C:\WINNT\system32\dllcache\
ProcessID : 2028
ThreadCreationTime : 9-12-2005 6:42:24 AM
BasePriority : Normal
FileVersion : 5.00.2920.0000
ProductVersion : 5.00.2920.0000
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : IEXPLORE.EXE
#:44 [firefox.exe]
FilePath : C:\Program Files\Mozilla Firefox\
ProcessID : 2748
ThreadCreationTime : 9-12-2005 7:09:50 AM
BasePriority : Normal
#:45 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 1184
ThreadCreationTime : 9-12-2005 7:24:42 AM
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
CoolWebSearch Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\explorer\browser helper objects\{5321e378-ffad-4999-8c62-03ca8155f0b3}
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 1
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Deep scanning and examining files (D:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for D:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Scanning Hosts file......
Hosts file location:"C:\WINNT\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 1
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
CoolWebSearch Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\downloadmanager
CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\windows\currentversion\run
Value : xp_system
CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\windows nt\currentversion\windows
Value : run
CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Enable Browser Extensions
CoolWebSearch Object Recognized!
Type : RegData
Data :
TAC Rating : 10
Category : Malware
Comment : PROXY ENABLED - CHECK PROXY SETTINGS - Check this item if you do not use a proxy server - If a proxy server is in use, its settings in your Internet Options need to be verified.
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\windows\currentversion\internet settings
Value : ProxyEnable
Data :
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 5
Objects found so far: 6
3:33:15 PM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:06:56.953
Objects scanned:112768
Objects identified:6
Objects ignored:0
New critical objects:6