Hi,
Thanks for the reply. I did update the last definition. I catch 13 critical adware, but everytime I use internet explorer Zeno pop reappear. I try to find a way to completely remove this anoying spyware.
Below my log file:
Ad-Aware SE Build 1.06r1
Logfile Created on:Monday, June 19, 2006 5:58:36 PM
Using definitions file:SE1R112 15.06.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Adware.ZenoSearch(TAC index:4):8 total references
MRU List(TAC index:0):14 total references
Tracking Cookie(TAC index:3):5 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Ignore spanned files when scanning cab archives
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Block pop-ups aggressively
Set : Automatically select problematic objects in results lists
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Show splash screen
Set : Backup current definitions file before updating
Set : Play sound at scan completion if scan locates critical objects
6-19-2006 5:58:36 PM - Scan started. (Full System Scan)
MRU List Object Recognized!
Location: : C:\Documents and Settings\Owner\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office
MRU List Object Recognized!
Location: : C:\Documents and Settings\Owner\recent
Description : list of recently opened documents
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Object Recognized!
Location: : S-1-5-21-1095400420-4126652087-3573823692-1003\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput
MRU List Object Recognized!
Location: : S-1-5-21-1095400420-4126652087-3573823692-1003\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput
MRU List Object Recognized!
Location: : S-1-5-21-1095400420-4126652087-3573823692-1003\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-1095400420-4126652087-3573823692-1003\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-1095400420-4126652087-3573823692-1003\software\microsoft\office\11.0\common\open find\microsoft office word\settings\open\file name mru
Description : list of recent documents opened by microsoft word
MRU List Object Recognized!
Location: : S-1-5-21-1095400420-4126652087-3573823692-1003\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened
MRU List Object Recognized!
Location: : S-1-5-21-1095400420-4126652087-3573823692-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension
MRU List Object Recognized!
Location: : S-1-5-21-1095400420-4126652087-3573823692-1003\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened
MRU List Object Recognized!
Location: : S-1-5-21-1095400420-4126652087-3573823692-1003\software\nvidia corporation\global\nview\windowmanagement
Description : nvidia nview cached application window positions
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 476
ThreadCreationTime : 6-19-2006 7:20:23 AM
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINNT\system32\
ProcessID : 584
ThreadCreationTime : 6-19-2006 7:20:27 AM
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINNT\system32\
ProcessID : 608
ThreadCreationTime : 6-19-2006 7:20:28 AM
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINNT\system32\
ProcessID : 652
ThreadCreationTime : 6-19-2006 7:20:29 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINNT\system32\
ProcessID : 664
ThreadCreationTime : 6-19-2006 7:20:29 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 828
ThreadCreationTime : 6-19-2006 7:20:30 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 876
ThreadCreationTime : 6-19-2006 7:20:31 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINNT\System32\
ProcessID : 916
ThreadCreationTime : 6-19-2006 7:20:31 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1012
ThreadCreationTime : 6-19-2006 7:20:31 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1044
ThreadCreationTime : 6-19-2006 7:20:31 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:11 [spoolsv.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1316
ThreadCreationTime : 6-19-2006 7:20:32 AM
BasePriority : Normal
FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
ProductVersion : 5.1.2600.2696
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:12 [wlservice.exe]
FilePath : C:\Program Files\Belkin\F5D7051\
ProcessID : 1420
ThreadCreationTime : 6-19-2006 7:20:33 AM
BasePriority : Normal
#:13 [wlancfgg.exe]
FilePath : C:\Program Files\Belkin\F5D7051\
ProcessID : 1436
ThreadCreationTime : 6-19-2006 7:20:33 AM
BasePriority : Normal
FileVersion : 1, 0, 7, 4
ProductVersion : 1, 0, 7, 4
ProductName : Wireless Monitor Application
FileDescription : Wireless Monitor Application
InternalName : WLanCfg
LegalCopyright : Copyright © 2002.08
OriginalFilename : WLanCfg.EXE
#:14 [inetinfo.exe]
FilePath : C:\WINNT\system32\inetsrv\
ProcessID : 1464
ThreadCreationTime : 6-19-2006 7:20:33 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Internet Information Services
CompanyName : Microsoft Corporation
FileDescription : Internet Information Services
InternalName : INETINFO.EXE
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : INETINFO.EXE
#:15 [incdsrv.exe]
FilePath : C:\Program Files\Ahead\InCD\
ProcessID : 1496
ThreadCreationTime : 6-19-2006 7:20:33 AM
BasePriority : Normal
FileVersion : 4, 0, 1, 27
ProductVersion : 4, 0, 1, 27
ProductName : AHEAD Software incdsrv
CompanyName : AHEAD Software
FileDescription : incdsrv
InternalName : incdsrv
LegalCopyright : Copyright © 2003
OriginalFilename : incdsrv.exe
#:16 [mdm.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7Debug\
ProcessID : 1516
ThreadCreationTime : 6-19-2006 7:20:33 AM
BasePriority : Normal
FileVersion : 7.10.3077
ProductVersion : 7.10.3077
ProductName : Microsoft® Visual Studio .NET
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : Copyright© Microsoft Corporation. All rights reserved.
OriginalFilename : mdm.exe
#:17 [sqlservr.exe]
FilePath : c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\
ProcessID : 1552
ThreadCreationTime : 6-19-2006 7:20:34 AM
BasePriority : Normal
FileVersion : 2005.090.1399.00
ProductVersion : 9.00.1399.06
ProductName : Microsoft SQL Server
CompanyName : Microsoft Corporation
FileDescription : SQL Server Windows NT
InternalName : SQLSERVR
LegalCopyright : © Microsoft Corp. All rights reserved.
LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation. Windows is a trademark of Microsoft Corporation
OriginalFilename : SQLSERVR.EXE
Comments : NT INTEL X86
#:18 [sqlservr.exe]
FilePath : c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\
ProcessID : 1584
ThreadCreationTime : 6-19-2006 7:20:34 AM
BasePriority : Normal
FileVersion : 2005.090.1399.00
ProductVersion : 9.00.1399.06
ProductName : Microsoft SQL Server
CompanyName : Microsoft Corporation
FileDescription : SQL Server Windows NT
InternalName : SQLSERVR
LegalCopyright : © Microsoft Corp. All rights reserved.
LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation. Windows is a trademark of Microsoft Corporation
OriginalFilename : SQLSERVR.EXE
Comments : NT INTEL X86
#:19 [nvsvc32.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1708
ThreadCreationTime : 6-19-2006 7:20:35 AM
BasePriority : Normal
FileVersion : 6.14.10.4523
ProductVersion : 6.14.10.4523
ProductName : NVIDIA Driver Helper Service, Version 45.23
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA Driver Helper Service, Version 45.23
InternalName : NVSVC
LegalCopyright : © NVIDIA Corporation. All rights reserved.
OriginalFilename : nvsvc32.exe
#:20 [sqlwriter.exe]
FilePath : c:\Program Files\Microsoft SQL Server\90\Shared\
ProcessID : 1792
ThreadCreationTime : 6-19-2006 7:20:35 AM
BasePriority : Normal
FileVersion : 2005.090.1399.00
ProductVersion : 9.00.1399.06
ProductName : Microsoft SQL Server
CompanyName : Microsoft Corporation
FileDescription : SQL Server VSS Writer
InternalName : SQLWRITER
LegalCopyright : © Microsoft Corp. All rights reserved.
LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation. Windows is a trademark of Microsoft Corporation
OriginalFilename : SQLWRITER.EXE
Comments : NT INTEL X86
#:21 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1844
ThreadCreationTime : 6-19-2006 7:20:35 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:22 [vsmon.exe]
FilePath : C:\WINNT\system32\ZoneLabs\
ProcessID : 1944
ThreadCreationTime : 6-19-2006 7:20:36 AM
BasePriority : Normal
FileVersion : 6.5.714.000
ProductVersion : 6.5.714.000
ProductName : TrueVector Service
CompanyName : Zone Labs, LLC
FileDescription : TrueVector Service
InternalName : vsmon
LegalCopyright : Copyright © 1998-2006, Zone Labs, LLC
OriginalFilename : vsmon.exe
#:23 [explorer.exe]
FilePath : C:\WINNT\
ProcessID : 548
ThreadCreationTime : 6-19-2006 7:20:38 AM
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
#:24 [cthelper.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1132
ThreadCreationTime : 6-19-2006 7:20:43 AM
BasePriority : Normal
FileVersion : 1, 0, 0, 11
ProductVersion : 1, 0, 0, 11
ProductName : CtHelper Application
CompanyName : Creative Technology Ltd
FileDescription : CtHelper MFC Application
InternalName : CtHelper
LegalCopyright : Copyright © 2002
OriginalFilename : CtHelper.EXE
#:25 [incd.exe]
FilePath : C:\Program Files\Ahead\InCD\
ProcessID : 1140
ThreadCreationTime : 6-19-2006 7:20:43 AM
BasePriority : Normal
FileVersion : 4, 0, 1, 27
ProductVersion : 4, 0, 1, 27
ProductName : InCD
CompanyName : Ahead Software AG
FileDescription : InCD
InternalName : InCD
LegalCopyright : Copyright © 2003 Ahead Software and its licensors
LegalTrademarks : InCD TM
OriginalFilename : InCD.exe
#:26 [wkufind.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\Works Shared\
ProcessID : 1164
ThreadCreationTime : 6-19-2006 7:20:43 AM
BasePriority : Normal
FileVersion : 9.00.0607.0
ProductVersion : 9.00.0607.0
ProductName : Update Detection Module
CompanyName : Microsoft® Corporation
FileDescription : Microsoft® Works Update Detection
InternalName : WkUFind
LegalCopyright : Copyright © 1987-2003 Microsoft Corporation.
OriginalFilename : WkUFind.exe
#:27 [logitray.exe]
FilePath : C:\Program Files\Logitech\ImageStudio\
ProcessID : 1232
ThreadCreationTime : 6-19-2006 7:20:44 AM
BasePriority : Normal
FileVersion : 7.3.0.1113
ProductVersion : 7.3.0.1113
ProductName : Logitech ImageStudio
CompanyName : Logitech Inc.
FileDescription : ImageStudio Tray Application
InternalName : LogiTray.exe
LegalCopyright : © 1996-2002 Logitech. All rights reserved.
OriginalFilename : LogiTray.exe
#:28 [lvcomsx.exe]
FilePath : C:\WINNT\System32\
ProcessID : 1200
ThreadCreationTime : 6-19-2006 7:20:44 AM
BasePriority : Normal
FileVersion : 8.2.0.1192
ProductVersion : 8.2.0.1192
ProductName : Logitech QuickCam
CompanyName : Logitech Inc.
FileDescription : LVCom Server
InternalName : LVComS.exe
LegalCopyright : © 1996-2004 Logitech. All rights reserved.
OriginalFilename : LVComS.exe
#:29 [logitray.exe]
FilePath : C:\Program Files\Logitech\Video\
ProcessID : 1444
ThreadCreationTime : 6-19-2006 7:20:44 AM
BasePriority : Normal
FileVersion : 8.2.0.1192
ProductVersion : 8.2.0.1192
ProductName : Logitech QuickCam
CompanyName : Logitech Inc.
FileDescription : ImageStudio Tray Application
InternalName : LogiTray.exe
LegalCopyright : © 1996-2004 Logitech. All rights reserved.
OriginalFilename : LogiTray.exe
#:30 [jusched.exe]
FilePath : C:\Program Files\Java\jre1.5.0_04\bin\
ProcessID : 1524
ThreadCreationTime : 6-19-2006 7:20:45 AM
BasePriority : Normal
#:31 [versioncuecs2tray.exe]
FilePath : C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\
ProcessID : 1684
ThreadCreationTime : 6-19-2006 7:20:45 AM
BasePriority : Normal
#:32 [acrotray.exe]
FilePath : C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\
ProcessID : 1704
ThreadCreationTime : 6-19-2006 7:20:45 AM
BasePriority : Normal
FileVersion : 7.0.7.2006011200
ProductVersion : 7.0.7.2006011200
ProductName : AcroTray - Adobe Acrobat Distiller helper application.
CompanyName : Adobe Systems Inc.
FileDescription : AcroTray
InternalName : AcroTray
LegalCopyright : Copyright 1984-2006 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename : AcroTray.exe
#:33 [ituneshelper.exe]
FilePath : C:\Program Files\iTunes\
ProcessID : 2028
ThreadCreationTime : 6-19-2006 7:20:46 AM
BasePriority : Normal
FileVersion : 6.0.4.2
ProductVersion : 6.0.4.2
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2006 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe
#:34 [zlclient.exe]
FilePath : C:\Program Files\Zone Labs\ZoneAlarm\
ProcessID : 2060
ThreadCreationTime : 6-19-2006 7:20:46 AM
BasePriority : Normal
FileVersion : 6.5.714.000
ProductVersion : 6.5.714.000
ProductName : Zone Labs Client
CompanyName : Zone Labs, LLC
FileDescription : Zone Labs Client
InternalName : zlclient
LegalCopyright : Copyright © 1998-2006, Zone Labs, LLC
OriginalFilename : zlclient.exe
#:35 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ProcessID : 2100
ThreadCreationTime : 6-19-2006 7:20:46 AM
BasePriority : Normal
FileVersion : 7.1
ProductVersion : QuickTime 7.1
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
FileDescription : QuickTime Task
InternalName : QuickTime Task
LegalCopyright : Copyright Apple Computer, Inc. 1989-2006
OriginalFilename : QTTask.exe
#:36 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 2108
ThreadCreationTime : 6-19-2006 7:20:46 AM
BasePriority : Normal
FileVersion : 0.1.0.3510
ProductVersion : 0.1.0.3510
ProductName : RealPlayer (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
LegalTrademarks : RealAudio is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe
#:37 [dwdsregt.exe]
FilePath : C:\winnt\system32\
ProcessID : 2116
ThreadCreationTime : 6-19-2006 7:20:46 AM
BasePriority : Normal
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
LegalCopyright : © 2004
#:38 [logitechdesktopmessenger.exe]
FilePath : C:\Program Files\Logitech\Desktop Messenger\8876480\Program\
ProcessID : 2156
ThreadCreationTime : 6-19-2006 7:20:47 AM
BasePriority : Normal
FileVersion : 2.30.04
ProductVersion : 2.30.04
ProductName : Logitech Desktop Messenger
CompanyName : Logitech
FileDescription : Logitech Desktop Messenger
InternalName : SyncExt
LegalCopyright : Copyright © Logitech 2000-2005. All rights reserved
OriginalFilename : SyncExt.dll
Comments : About:
www.logitech.com/ldm
Privacy Policy:
http://privacy.logitech.com#:39 [rundll32.exe]
FilePath : C:\WINNT\System32\
ProcessID : 2204
ThreadCreationTime : 6-19-2006 7:20:47 AM
BasePriority : Idle
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : RUNDLL.EXE
#:40 [skype.exe]
FilePath : C:\Program Files\Skype\Phone\
ProcessID : 2344
ThreadCreationTime : 6-19-2006 7:20:49 AM
BasePriority : Normal
#:41 [lowlight.exe]
FilePath : C:\Program Files\Logitech\ImageStudio\
ProcessID : 2424
ThreadCreationTime : 6-19-2006 7:20:50 AM
BasePriority : Normal
FileVersion : 7.3.0.1113
ProductVersion : 7.3.0.1113
ProductName : Logitech ImageStudio
CompanyName : Logitech Inc.
FileDescription : Automatic Low Light Module
InternalName : LowLight.exe
LegalCopyright : © 1996-2002 Logitech. All rights reserved.
OriginalFilename : LowLight.exe
#:42 [rundll32.exe]
FilePath : C:\WINNT\system32\
ProcessID : 2480
ThreadCreationTime : 6-19-2006 7:20:51 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : RUNDLL.EXE
#:43 [fxsvr2.exe]
FilePath : C:\Program Files\Logitech\Video\
ProcessID : 2832
ThreadCreationTime : 6-19-2006 7:20:59 AM
BasePriority : Normal
FileVersion : 8.2.0.1192
ProductVersion : 8.2.0.1192
ProductName : Logitech QuickCam
CompanyName : Logitech Inc.
FileDescription : QuickCam Framework Server
InternalName : FxSvr.EXE
LegalCopyright : © 1996-2004 Logitech. All rights reserved.
OriginalFilename : FxSvr.EXE
#:44 [webshots.scr]
FilePath : C:\WINNT\
ProcessID : 2892
ThreadCreationTime : 6-19-2006 7:21:01 AM
BasePriority : Normal
FileVersion : 2.0.0.4324
ProductVersion : 2.0.0.4324
ProductName : The Webshots Desktop
CompanyName : Webshots.com
FileDescription : Webshots Photo Manager
InternalName : Webshots2
LegalCopyright : Copyright © 2003
OriginalFilename : Webshots2.EXE
#:45 [ipodservice.exe]
FilePath : C:\Program Files\iPod\bin\
ProcessID : 3700
ThreadCreationTime : 6-19-2006 7:21:30 AM
BasePriority : Normal
FileVersion : 6.0.4.2
ProductVersion : 6.0.4.2
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2006 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iPodService.exe
#:46 [isafe.exe]
FilePath : C:\WINNT\system32\ZoneLabs\
ProcessID : 3780
ThreadCreationTime : 6-19-2006 7:21:30 AM
BasePriority : Normal
FileVersion : Version 10.67.0.0
ProductVersion : Version 10.67.0.0
ProductName : ISafe
CompanyName : Computer Associates International, Inc.
FileDescription : ISafe Service
InternalName : ISafe
LegalCopyright : © 2003 Computer Associates International, Inc.
LegalTrademarks : Vet is a trademark of Computer Associates International, Inc.
OriginalFilename : ISafe.exe
Comments : ISafe
#:47 [alg.exe]
FilePath : C:\WINNT\System32\
ProcessID : 4036
ThreadCreationTime : 6-19-2006 7:21:33 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe
#:48 [firefox.exe]
FilePath : C:\Program Files\Mozilla Firefox\
ProcessID : 2976
ThreadCreationTime : 6-19-2006 10:06:40 AM
BasePriority : Normal
#:49 [dumprep.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1028
ThreadCreationTime : 6-19-2006 4:36:06 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Error Reporting Dump Reporting Tool
InternalName : DUMPREP.EXE
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : DUMPREP.EXE
#:50 [ntvdm.exe]
FilePath : C:\WINNT\system32\
ProcessID : 900
ThreadCreationTime : 6-19-2006 4:46:06 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : NTVDM.EXE
InternalName : NTVDM.EXE
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : NTVDM.EXE
#:51 [winpat~1.exe]
FilePath : C:\PROGRA~1\BILLPS~1\WINPAT~1\
ProcessID : 3724
ThreadCreationTime : 6-19-2006 4:46:56 PM
BasePriority : Normal
FileVersion : 9, 8, 1, 0
ProductVersion : 9.8.1.0
ProductName : WinPatrol Monitor
CompanyName : BillP Studios
FileDescription : WinPatrol System Monitor
InternalName : WinPatrol Monitor
LegalCopyright : Copyright © 1997- 2005 BillP Studios
OriginalFilename : Scotty
Comments : Let Scotty the Windows Watchdog patrol your system.
#:52 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 1864
ThreadCreationTime : 6-19-2006 4:48:15 PM
BasePriority : Normal
FileVersion : 7.00.5335.5 (winmain(wmbla).060317-1722)
ProductVersion : 7.00.5335.5
ProductName : Microsoft® Internet Explorer
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : IEXPLORE.EXE
#:53 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 632
ThreadCreationTime : 6-19-2006 4:53:55 PM
BasePriority : Normal
FileVersion : 7.00.5335.5 (winmain(wmbla).060317-1722)
ProductVersion : 7.00.5335.5
ProductName : Microsoft® Internet Explorer
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : IEXPLORE.EXE
#:54 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Plus\
ProcessID : 1592
ThreadCreationTime : 6-19-2006 4:57:00 PM
BasePriority : Normal
FileVersion : 6.2.0.237
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 14
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Adware.ZenoSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 4
Category : Adware
Comment : "BrowserUpdateSched"
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\run
Value : BrowserUpdateSched
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 15
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 15
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : owner@server.iad.liveperson[3].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:28
Value : Cookie:owner@server.iad.liveperson.net/
Expires : 6-19-2007 4:49:54 PM
LastSync : Hits:28
UseCount : 0
Hits : 28
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : owner@server.iad.liveperson[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:5
Value : Cookie:owner@server.iad.liveperson.net/hc/87535706
Expires : 6-19-2007 4:50:18 PM
LastSync : Hits:5
UseCount : 0
Hits : 5
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : owner@statse.webtrendslive[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:31
Value : Cookie:owner@statse.webtrendslive.com/
Expires : 6-16-2016 5:19:12 PM
LastSync : Hits:31
UseCount : 0
Hits : 31
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : owner@statse.webtrendslive[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:33
Value : Cookie:owner@statse.webtrendslive.com/S153949
Expires : 12-31-2020 9:00:00 AM
LastSync : Hits:33
UseCount : 0
Hits : 33
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : owner@doubleclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:owner@doubleclick.net/
Expires : 6-19-2006 4:45:40 PM
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 5
Objects found so far: 20
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 20
Scanning Hosts file......
Hosts file location:"C:\WINNT\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 20
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Adware.ZenoSearch Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Adware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\enhanced ads by zeno
Adware.ZenoSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 4
Category : Adware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\enhanced ads by zeno
Value : UninstallString
Adware.ZenoSearch Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Adware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\zeno search assistant
Adware.ZenoSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 4
Category : Adware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\zeno search assistant
Value : UninstallString
Adware.ZenoSearch Object Recognized!
Type : File
Data : msnav32.ax
TAC Rating : 4
Category : Adware
Comment :
Object : C:\WINNT\system32\
Adware.ZenoSearch Object Recognized!
Type : File
Data : nt68rrtc12.sys
TAC Rating : 4
Category : Adware
Comment :
Object : C:\WINNT\system32\
Adware.ZenoSearch Object Recognized!
Type : File
Data : zxdnt3d.cfg
TAC Rating : 4
Category : Adware
Comment :
Object : C:\WINNT\system32\
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 7
Objects found so far: 27
6:31:04 PM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:32:28.125
Objects scanned:352428
Objects identified:13
Objects ignored:0
New critical objects:13