Help - Search - Members - Calendar
Full Version: FAKE AD-AWARE ON MY PC
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Resolved/Inactive HijackThis Logs
FQCS
I started up a clients computer and this is exactly what I see.
Click to view attachment

The blue screen says "warning! your're in danger! your computer is infected with spyware

Because of the misspelled words, I'm questioning the authenticity of the AdAware crash reporter and if it is even from Lavasoft. Here is the complete report:
QUOTE
An unhandled exception occured at 0x10031D26 in aawservice.exe

Exception Code : 0xc0000005
Client version : 0.734
Attached Debugger : 0

Windows Information :
---------------------
Windows Version : Windows XP (5.1)
Build Number : 2600
Service Pack : 2.0

CPU Information:
----------------
CPU Name : AMD Athlon™ 64 Processor 3500+
Type : 0
Vendor : AuthenticAMD
Family : 15
Extended Family : 0
Model : 15
Extended Model : 2
Stepping : 0

Registry Content:
-----------------
EAX : 0x0132a468
ECX : 0x00c14968
EDX : 0x05504fe0
EBX : 0x0000000b
ESP : 0x02ffec84
EBP : 0x05504fe0
ESI : 0x00c14968
EDI : 0x00c14494
EIP : 0x10031d26

Memory Usage:
-------------
Physical Memory in use : 27%
Total Physical Memory : 915888 kb
Free Physical Memory : 668572 kb
Total Virtual Memory : 2097024 kb
Free Virtual Memory : 1993632 kb
Max Page file size : 2218372 kb
Current Page file size : 2049092 kb
Free Extended memory : 0kb

Stack Information:
------------------
Total stack size : 4952

Stack Content:
--------------
10032864 00c14968 00c14968 00c14968 05504fe0 00000000
a4a9c206 00c14494 00c14968 05504fe0 0000000b 0000067c
00000008 00000000 00410041 00540057 00610072 03076ec8
00780065 00000000 00c30210 03076ec8 03000000 0304f738
00000002 00000000 00c30210 00c30178 02ffeec4 1008d218
ffffffff 10032a33 02ffed24 00000001 00c14968 05504fe0
00c13c70 0550ffd0 00c13ba0 03077901 00c14494 00c14968
10064524 02ffeeb8 05504fe0 a4a9c39a 00000010 00c13b58
0132a9b0 0000000b 00c13c70 0550ffd0 00c13c70 03077708
00c14578 00000000 00c30328 00000004 00c30178 00c304c8
03077918 00000000 00000000 03033c28 00c30178 00c302b8
0000000d 00000000 00000040 000004f8 00c3c3a0 00000000
00000001 00000480 00000000 00000000 00000004 000000de
0304fea8 00c30000 00c30178 00000770 00c304c8 03050618
00c30178 01013c30 00c30388 02ffed3c 7c9106f0 02ffee28
7c90ee18 7c910570 ffffffff 03077708 00450d09 00000042
00000000 00000000 a4a9d8a0 0304fea8 03034610 0000013c
03077700 00c30168 00000000 00000000 03077700 00000210
03077708 00450d28 00c30178 00000210 00004120 00c30000
02ffec44 0000013c 02fff1cc 7c90ee18 7c9106f0 ffffffff
7c9106eb 004522dc 00c30000 00000000 00000208 02c90cf0
030774f8 05476a94 02ffee9c 0044f024 00000208 00c3a1c0
00000000 0048d4d0 02ffeec4 0041e716 0041e764 05476878
00c13b58 0000000a 030774f8 00c3a1c0 03077708 00000000
02fff1cc 1008d311 ffffffff 100113d9 00000000 a4a9c07a
00000002 00000000 7c809a09 00000000 0000000b 00000010
02fff73c 0132a9b0 00020000 00080000 00000000 00000800
00000001 00000000 00000080 00004000 10000000 02fff23c
00008000 00800000 00010000 01338a20 0066006f 005c0074
00640041 02ffef74 00c30000 7c910732 00000003 00c30718
00c30000 00c3ba28 02ffef4c 00000002 02fff190 7c90ee18
00400000 00200000 7c910732 7c9106ab 7c9106eb 00000010
00000000 7c9105d4 7c9106ab 7c9106eb 00000008 00000000
7c9105d4 00000000 00000000 00000000 00000000 00000000
00000000 00000000 00000000 00000000 00000000 00000000
00000000 00000000 00000000 00000000 00000000 003a0049
0000005c 00000000 00000000 00000000 00000000 7c911b09
0015e4d4 00164a00 00000000 00000000 00000000 00000000
00000000 00000005 00000000 00000000 00000000 00000000
00000000 00000000 02fff044 00000000 7c9105c8 00152098
02fff110 00000000 00164a00 7c91056d 00100001 00000028
00000000 00150000 02ffee5c 00000000 02fff0b0 7c90ee18
7c9106f0 ffffffff 02fff0b0 00c30000 7c910732 00000006
00c307a8 00c30000 00c3aea8 02fff088 7ffde000 02fff2cc
7c90ee18 7c910738 ffffffff 7c910732 7c9106ab 7c9106eb
00000028 00000000 7c9105d4 0015e4c0 00000000 00000000
00c3aae0 00000038 7c00ee18 00150000 02ffeedc 7c9140bb
02fff4bc 7c90ee18 02fff104 7c911b3c 0015e4d4 00000000
02fff118 7c80eecc 0015e4d4 7c90253a 00c3b148 02fff3fc
7c80eda5 00000118 0047374c 02fff490 7c80edb8 00000018
00000000 02fff180 00000003 00000000 00000000 00c3b148
00610074 00000002 00000000 00000000 00000000 00000000
0000009a 00c000be 00000000 00c3ba28 00c30000 001a001a
00000018 a400db08 00c30000 02ffef80 02fff1a4 02fff6d8
7c90ee18 7c9106f0 ffffffff 7c9106eb 004522dc 00c30000
00000000 00000010 02fff230 00c3589c 0000001a 02fff1d8
0044f024 a4a9c04a 02fff6d8 10085f00 ffffffff 0042438d
02fff23c 00000002 00100000 10ebd997 00000003 02fff73c
00000000 a4a9c764 00c3a1c0 02fff720 00c3a1c0 00000007
00000002 10ebd997 00c3a1c0 00000000 02fff73c 000001fc
006f006c 00000067 00000000 00c3ba28 00000007 00150640
00c34a28 00c3ba18 00000000 00000000 00000000 00000000
00150178 02fff268 00000000 7c9105c8 00152098 02fff334
7c910551 00151378 7c91056d 02fff288 00000000 7c9105c8
001649f8 02fff354 7c910551 00150778 7c91056d 00164a20
00164a00 0015e4d4 00000000 00000000 00150178 00000000
00165518 00000030 00000000 02fff2d0 00000000 7c9105c8
00c3aea0 02fff39c 7c910551 00c307a8 7c91056d 00c3aea8
00c3aea8 02fff484 00150000 02fff300 00000000 7c9105c8
0015e4b8 02fff3cc 02fff314 00000000 7c9105c8 00c3b838
02fff3e0 7c910551 00c307a8 7c91056d 02fff484 00c3b840
00c3aea8 00165518 0001af4d 00000005 00000030 00150178
02fff380 7c90ee18 7c910570 ffffffff 7c91056d 7c911962
7c911993 7c97c080 00c30000 00164a20 00000038 0015e4d4
7ffd9000 02fff368 00010000 00000030 02fff2e0 7c911978
02fff3cc 7c90ee18 7c910570 ffffffff 7c91056d 00450d09
00c30000 00c30000 00450d28 a4a9c544 00c3aea8 00c3b840
02fff484 0001ee18 00000006 02fff324 02fff4bc 02fff410
7c90ee18 7c910570 ffffffff 7c91056d 00450d09 00c30000
00000000 00450d28 a4a9c2b8 02fff484 02fff484 00c3aea8
00c3aea8 02fff3f4 02fff4bc 02fff4bc 004573f0 a61e14b0
fffffffe 00450d28 00407484 00c3b840 a4a9c2a8 00c3a1c0
00000000 00c35150 01450c99 00000000 00c3b148 00000000
0015e4c0 00000001 02fff484 00c3aea8 480e94fd 00000000
02fff4c0 480e94fd 00000000 a61e1490 fffffffe 02fff484
00c3b840 00c3aea8 0045922d 00c3b840 00000000 00c3b520
0000005f 004504eb 0048a390 004504bf a4a9c248 000407d8
00160002 002e0014 01140025 02fff4a4 02fff504 0046beab
ffffffff a61e17f8 02fff514 00407b48 00c35150 0047374c
a4a9c278 00c3a1c0 0000001c 00000004 00000001 02fff4dc
0000000d 02fff6d8 004573f0 a61e1750 02fff6d8 0046cc60
ffffffff 0048a390 0000000d 0041e6ad a4a9c3b8 02fff720
00c3a1c0 0041e6cd 00000027 48161a9f 00000000 0000002a
02fff720 00c30178 00c30000 00c3ba40 ffffffff 00c35988
00000000 00000007 00000027 0000002a 0000000d 0000001c
00000003 0000006c 00000001 00000076 00000001 00000027
0000002a 0000000d 0000001c 00000003 0000006c 00000001
00000076 00000001 00000027 0000002a 0000000d 0000001c
00000003 0000006c 00000001 00000076 02fff5d4 00000000
7c9105c8 00c3af18 02fff6a0 7c910551 00c307d8 7c91056d
00c3a1c0 00c3af20 00000007 0000002a 0000000d 0000001c
00000003 0000006c 00000001 00000076 00000001 00000027
0000002a 0000000d 0000001c 00000003 0000006c 00000001
00000076 00000001 7c9106f0 00c3aae0 7c9106eb 00000038
00c30000 00000062 003a0049 00300000 003a0044 0000005c
00380032 00310020 002d0033 00c30000 0033002d 00200039
0020003a 00400000 00000030 00011a08 00000007 02fff5e4
00000000 02fff6d0 7c90ee18 7c910570 ffffffff 7c91056d
00450d09 00c30000 00000000 00450d28 a4a9c078 00c3a1c0
02fff720 00000007 00c3af20 02fff6b4 00477f94 02fffc20
a4a9c494 02fffc20 0046a3ad 00000000 00422bd6 02fff73c
a4a9c068 00c3a1c0 7c901005 02ffffb0 7c9010ed 00000008
02fff6e0 00c34a28 00000000 00c30178 00000000 00c3b840
0048d39c 002d0044 00c3af20 007e0041 002e0031 004f004c
00000012 00000017 00000001 00000000 00200065 00c3a310
00000004 00340000 00c3b840 00c3b910 002d0030 00360034
0033002d 002e0037 006f006c 7c900067 00000000 00000167
02fff790 00150640 00000000 00251f18 7c91393d 00c35990
6365446c 00000000 00150178 02007265 02fff7b8 00000000
00c35990 00251f18 7c91393d 00c3b840 00000000 02fff7d0
00000000 7c9105c8 001649f8 02fff89c 7c910551 00150778
7c91056d 00164a20 00164a00 0015e4d4 00c3b838 00000030
00150178 00c30178 00165518 00000030 00000178 02fff818
00000000 7c9105c8 00c3b838 02fff8e4 7c910551 00c307a8
7c91056d 00c3b840 00c3b840 02fff9cc 00150000 02fff848
00000000 7c9105c8 0015e4b8 02fff914 02fff85c 00000000
7c9105c8 00c3aea0 02fff928 7c910551 00c307a8 7c91056d
02fff9cc 00c3aea8 00c3b840 00165518 0001af4d 00000005
00000030 00150178 02fff8c8 7c90ee18 7c910570 ffffffff
7c91056d 7c911962 7c911993 7c97c080 00c30000 00164a20
00000038 0015e4d4 7ffd9000 02fff8b0 00010000 00000030
02fff828 7c911978 02fff914 7c90ee18 7c910570 ffffffff
7c91056d 00450d09 00c30000 00c30000 00450d28 a4a9cfbc
00c3b840 00c3aea8 02fff9cc 0001ee18 00000006 02fff86c
02fffa04 02fff958 7c90ee18 7c910570 ffffffff 7c91056d
00450d09 00c30000 00000000 00450d28 a4a9cff0 02fff9cc
02fff9cc 00c3b840 00c3b840 02fff93c 02fffa04 02fffa04
004573f0 a61e14b0 fffffffe 00450d28 00407484 00c3aea8
a4a9cfe0 00c3a1c0 00000000 00c35150 01450c99 00000000
00c3b148 00000000 0015e4c0 00000001 02fff9cc 00c3b840
480e94fd 00000000 02fffa08 480e94fd 00000000 a61e1490
fffffffe 02fff9cc 00c3aea8 00c3b840 0045922d 00c3aea8
00000000 00c3b520 0000005f 004504eb 0048a390 004504bf
a4a9cc80 000407d8 00160002 002e0014 01140025 02fff9ec
02fffa4c 0046beab ffffffff a61e17f8 02fffa5c 00407b48
00c35150 0047374c a4a9ccb0 00c3a1c0 0000001c 00000004
00000001 02fffa24 0000000d 02fffc20 004573f0 a61e1750
02fffc20 0046cc60 ffffffff 0048a390 0000000d 0041e6ad
a4a9ccf0 7c901005 02ffffb0 0041e6cd 00000027 48161a9f
00000000 0000002a 02fffdb8 00c34a38 00c30000 02fffb00
00c34628 00000028 00000000 00000007 00000027 0000002a
0000000d 0000001c 00000003 0000006c 00000001 00000076
00000001 00000027 0000002a 0000000d 0000001c 00000003
0000006c 00000001 00000076 00000001 00000027 0000002a
0000000d 0000001c 00000003 0000006c 00000001 02fffb18
00000000 7c9105c8 00c3d3d8 02fffbe4 7c910551 00c30778
7c91056d 00c3a1c0 00c3d3e0 7c9010ed 00000027 0000002a
0000000d 0000001c 00000003 0000006c 00000001 00000076
00000001 00000027 0000002a 0000000d 0000001c 00000003
0000006c 00000001 00000076 00000001 004522dc 00c3aae0
00000028 00000020 02fffdb8 00000062 7c901005 00421a75
00380030 00340030 00380032 00310020 00c30000 00320034
0033002d 00200039 0020003a 00000000 00010000 00000005
02fffb28 a4a9cd6c 02fffc14 7c90ee18 7c910570 ffffffff
7c91056d 00450d09 00c30000 00000000 00450d28 a4a9cabc
00c3a1c0 02fffdb8 7c9010ed 00478234 02fffbf8 00478236
02ffffa4 a4a9c198 7c80a027 02ffffa4 0046f65c 00000000
00424c83 00c3a1c0 a4a9caa0 00d9fb10 00c3a1a0 00c3a1c0
0048d498 00c3a1c0 0048d49c 00c3a250 00c3a1cc 00000001
00000000 00153658 00000000 00000000 00c3de60 00000004
00000000 00000000 00000000 7ffde000 0039b7c4 000000dc
000000d8 00000000 02fffd0c 7c90ee18 7c918ed0 ffffffff
7c918e74 7c90e8c4 7c918dfa 02fffd30 00c3a1a0 00c3a1c0
00000000 00000000 00000000 00000000 00000000 00000000
00000000 00000000 00000000 00000000 00000000 00000000
7ffd9000 00000000 00000000 00000000 00000000 00000000
02fffcb0 00000000 00000000 7c90ee00 7c918e00 ffffffff
7c918dfa 7c90d625 7c90eacf 02fffd30 00000001 00010017
00000000 00000000 00000000 00000000 00000000 00000000
00002000 00000100 00000500 00005000 00000100 00000100
00000c00 00000c00 00000400 00000100 00000900 00000200
00000200 00000200 00000b00 00000400 00000100 00000400
00000c00 00000900 00000200 00000900 00000b00 00000b00
00000400 00000b00 00000900 00000c00 00c30000 00000038
00000023 00000023 00000000 00000007 00c3a1c0 00000000
7c9105c8 00445ba0 00d9fad0 7c810659 0000001b 00000200
02fffffc 00000023 00000000 00002000 00000100 00000500
00005000 00000100 00000100 00000c00 00000c00 00000400
00000100 00000900 00000200 00000200 00000200 00000b00
00000400 00000100 00000400 00000c00 00000900 00000200
00000900 00000b00 00000b00 00000400 00000b00 00000900
00000c00 04040400 04040404 f0040404 f0f4f800 eff3f800
ecf0f700 e7edf500 88a6e100 fafbfd00 f1f4f800 f1f4f800
00f4f800 13001300 00006402 00000200 00000800 00000000
00002000 00000100 00000100 00001000 00000500 00000500
00000800 00000800 00000500 00000500 00000800 00000800
b8040400 00000001 25a81800 00000100 00000100 00000000
91141400 0000047c 4406b000 00d23401 00000000 8419192c
ba3b3c20 00000246 804f9cd3 841918fc 84191790 841917c4
013f7d00 01405500 8063863a 84139788 84191790 7ffd9000
805002f8 00000000 00000005 00000000 00000000 00000000
804fd1fc 806cf1b9 00000297 804fd2b8 806cf0b3 84191790
ba3b3d50 00000b00 00000200 00000301 00000000 84139788
804ffeaa 00000000 00000000 00000000 a4a9cadc ba3b3c98
02ffffdc 0046f89a 00000001 02ffffec 00445bb4 7c80b683
00c3a1c0 00d9fb10 00c3a1a0 00c3a1c0 7ffd9000 c0000005
02ffffc0 02ffe8a8

System Activity:
----------------
Process 00000000: [System Process]
Module at 0x00400000: aawservice.exe
Module at 0x7c900000: ntdll.dll
Module at 0x7c800000: kernel32.dll
Module at 0x10000000: CEAPI.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll
Module at 0x77f60000: SHLWAPI.dll
Module at 0x77f10000: GDI32.dll
Module at 0x7e410000: USER32.dll
Module at 0x77c10000: msvcrt.dll
Module at 0x71ab0000: WS2_32.dll
Module at 0x71aa0000: WS2HELP.dll
Module at 0x004a0000: PKArchive85u.dll
Module at 0x7c9c0000: SHELL32.dll
Module at 0x774e0000: ole32.dll
Module at 0x77a80000: CRYPT32.dll
Module at 0x77b20000: MSASN1.dll
Module at 0x76f60000: WLDAP32.dll
Module at 0x76bf0000: PSAPI.DLL
Module at 0x77c00000: VERSION.dll
Module at 0x771b0000: WININET.dll
Module at 0x77120000: OLEAUT32.dll
Module at 0x00350000: Update.dll
Module at 0x71ad0000: WSOCK32.dll
Module at 0x769c0000: USERENV.dll
Module at 0x773d0000: comctl32.dll
Module at 0x5d090000: comctl32.dll
Module at 0x0ffd0000: rsaenh.dll

Process 00000004: System
Current Memory usage : 232 kb
Memory usage peak : 4096 kb
Current Paged Pool usage : 0 kb
Paged Pool usage peak : 0 kb
Current Non-Paged Pool usage : 0 kb
Non-Paged Pool usage peak : 0 kb
Current Page file usage : 0 kb
Page file usage peak : 0 kb
Page Faults : 12796

Module list
Module at 0x00000000:

Process 00000254: smss.exe
Current Memory usage : 400 kb
Memory usage peak : 888 kb
Current Paged Pool usage : 6 kb
Paged Pool usage peak : 21 kb
Current Non-Paged Pool usage : 0 kb
Non-Paged Pool usage peak : 2 kb
Current Page file usage : 168 kb
Page file usage peak : 1676 kb
Page Faults : 1604

Module list
Module at 0x48580000: smss.exe
Module at 0x7c900000: ntdll.dll

Process 000002b8: csrss.exe
Current Memory usage : 2904 kb
Memory usage peak : 5368 kb
Current Paged Pool usage : 48 kb
Paged Pool usage peak : 48 kb
Current Non-Paged Pool usage : 4 kb
Non-Paged Pool usage peak : 4 kb
Current Page file usage : 1376 kb
Page file usage peak : 4792 kb
Page Faults : 3470

Module list
Module at 0x4a680000: csrss.exe
Module at 0x7c900000: ntdll.dll
Module at 0x75b40000: CSRSRV.dll
Module at 0x75b50000: basesrv.dll
Module at 0x75b60000: winsrv.dll
Module at 0x77f10000: GDI32.dll
Module at 0x7c800000: KERNEL32.dll
Module at 0x7e410000: USER32.dll
Module at 0x75e90000: sxs.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll

Process 000002d0: winlogon.exe
Current Memory usage : 1920 kb
Memory usage peak : 15624 kb
Current Paged Pool usage : 93 kb
Paged Pool usage peak : 118 kb
Current Non-Paged Pool usage : 76 kb
Non-Paged Pool usage peak : 78 kb
Current Page file usage : 6824 kb
Page file usage peak : 9276 kb
Page Faults : 7951

Module list
Module at 0x01000000: winlogon.exe
Module at 0x7c900000: ntdll.dll
Module at 0x7c800000: kernel32.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll
Module at 0x776c0000: AUTHZ.dll
Module at 0x77c10000: msvcrt.dll
Module at 0x77a80000: CRYPT32.dll
Module at 0x7e410000: USER32.dll
Module at 0x77f10000: GDI32.dll
Module at 0x77b20000: MSASN1.dll
Module at 0x75940000: NDdeApi.dll
Module at 0x75930000: PROFMAP.dll
Module at 0x5b860000: NETAPI32.dll
Module at 0x769c0000: USERENV.dll
Module at 0x76bf0000: PSAPI.DLL
Module at 0x76bc0000: REGAPI.dll
Module at 0x77920000: SETUPAPI.dll
Module at 0x77c00000: VERSION.dll
Module at 0x76360000: WINSTA.dll
Module at 0x76c30000: WINTRUST.dll
Module at 0x76c90000: IMAGEHLP.dll
Module at 0x71ab0000: WS2_32.dll
Module at 0x71aa0000: WS2HELP.dll
Module at 0x75970000: MSGINA.dll
Module at 0x7c9c0000: SHELL32.dll
Module at 0x77f60000: SHLWAPI.dll
Module at 0x5d090000: COMCTL32.dll
Module at 0x74320000: ODBC32.dll
Module at 0x763b0000: comdlg32.dll
Module at 0x773d0000: comctl32.dll
Module at 0x20000000: odbcint.dll
Module at 0x776e0000: SHSVCS.dll
Module at 0x76bb0000: sfc.dll
Module at 0x76c60000: sfc_os.dll
Module at 0x774e0000: ole32.dll
Module at 0x77b40000: Apphelp.dll
Module at 0x723d0000: WINSCARD.DLL
Module at 0x76f50000: WTSAPI32.dll
Module at 0x75e90000: sxs.dll
Module at 0x5ad70000: uxtheme.dll
Module at 0x76b40000: WINMM.dll
Module at 0x76600000: cscdll.dll
Module at 0x75950000: WlNotify.dll
Module at 0x73000000: WINSPOOL.DRV
Module at 0x71b20000: MPR.dll
Module at 0x0ffd0000: rsaenh.dll
Module at 0x01200000: WgaLogon.dll
Module at 0x77120000: OLEAUT32.dll
Module at 0x77690000: NTMARTA.DLL
Module at 0x76f60000: WLDAP32.dll
Module at 0x71bf0000: SAMLIB.dll
Module at 0x76fd0000: CLBCATQ.DLL
Module at 0x77050000: COMRes.dll
Module at 0x77a20000: cscui.dll
Module at 0x014b0000: xpsp2res.dll
Module at 0x77c70000: msv1_0.dll
Module at 0x76d60000: iphlpapi.dll

Process 000002fc: services.exe
Current Memory usage : 2996 kb
Memory usage peak : 3044 kb
Current Paged Pool usage : 32 kb
Paged Pool usage peak : 34 kb
Current Non-Paged Pool usage : 5 kb
Non-Paged Pool usage peak : 6 kb
Current Page file usage : 1624 kb
Page file usage peak : 1624 kb
Page Faults : 1099

Module list
Module at 0x01000000: services.exe
Module at 0x7c900000: ntdll.dll
Module at 0x7c800000: kernel32.dll
Module at 0x77c10000: msvcrt.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll
Module at 0x7e410000: USER32.dll
Module at 0x77f10000: GDI32.dll
Module at 0x769c0000: USERENV.dll
Module at 0x758e0000: SCESRV.dll
Module at 0x776c0000: AUTHZ.dll
Module at 0x7dba0000: umpnpmgr.dll
Module at 0x76360000: WINSTA.dll
Module at 0x5b860000: NETAPI32.dll
Module at 0x5f770000: NCObjAPI.DLL
Module at 0x76080000: MSVCP60.dll
Module at 0x5cb70000: ShimEng.dll
Module at 0x47260000: AcAdProc.dll
Module at 0x77b40000: Apphelp.dll
Module at 0x77c00000: VERSION.dll
Module at 0x77b70000: eventlog.dll
Module at 0x71ab0000: WS2_32.dll
Module at 0x71aa0000: WS2HELP.dll
Module at 0x76bf0000: PSAPI.DLL
Module at 0x76f50000: wtsapi32.dll

Process 00000308: lsass.exe
Current Memory usage : 4908 kb
Memory usage peak : 4908 kb
Current Paged Pool usage : 66 kb
Paged Pool usage peak : 68 kb
Current Non-Paged Pool usage : 6 kb
Non-Paged Pool usage peak : 8 kb
Current Page file usage : 2240 kb
Page file usage peak : 2244 kb
Page Faults : 2081

Module list
Module at 0x01000000: lsass.exe
Module at 0x7c900000: ntdll.dll
Module at 0x7c800000: kernel32.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll
Module at 0x75730000: LSASRV.dll
Module at 0x71b20000: MPR.dll
Module at 0x7e410000: USER32.dll
Module at 0x77f10000: GDI32.dll
Module at 0x77b20000: MSASN1.dll
Module at 0x77c10000: msvcrt.dll
Module at 0x5b860000: NETAPI32.dll
Module at 0x767a0000: NTDSAPI.dll
Module at 0x76f20000: DNSAPI.dll
Module at 0x71ab0000: WS2_32.dll
Module at 0x71aa0000: WS2HELP.dll
Module at 0x76f60000: WLDAP32.dll
Module at 0x71bf0000: SAMLIB.dll
Module at 0x74440000: SAMSRV.dll
Module at 0x76790000: cryptdll.dll
Module at 0x5cb70000: ShimEng.dll
Module at 0x6f880000: AcGenral.DLL
Module at 0x76b40000: WINMM.dll
Module at 0x774e0000: ole32.dll
Module at 0x77120000: OLEAUT32.dll
Module at 0x77be0000: MSACM32.dll
Module at 0x77c00000: VERSION.dll
Module at 0x7c9c0000: SHELL32.dll
Module at 0x77f60000: SHLWAPI.dll
Module at 0x769c0000: USERENV.dll
Module at 0x5ad70000: UxTheme.dll
Module at 0x773d0000: comctl32.dll
Module at 0x5d090000: comctl32.dll
Module at 0x20000000: msprivs.dll
Module at 0x71cf0000: kerberos.dll
Module at 0x77c70000: msv1_0.dll
Module at 0x76d60000: iphlpapi.dll
Module at 0x744b0000: netlogon.dll
Module at 0x767c0000: w32time.dll
Module at 0x76080000: MSVCP60.dll
Module at 0x767f0000: schannel.dll
Module at 0x77a80000: CRYPT32.dll
Module at 0x74380000: wdigest.dll
Module at 0x0ffd0000: rsaenh.dll
Module at 0x74410000: scecli.dll
Module at 0x77920000: SETUPAPI.dll

Process 000003b4: svchost.exe
Current Memory usage : 3208 kb
Memory usage peak : 3208 kb
Current Paged Pool usage : 62 kb
Paged Pool usage peak : 63 kb
Current Non-Paged Pool usage : 4 kb
Non-Paged Pool usage peak : 4 kb
Current Page file usage : 1296 kb
Page file usage peak : 1296 kb
Page Faults : 979

Module list
Module at 0x01000000: svchost.exe
Module at 0x7c900000: ntdll.dll
Module at 0x7c800000: kernel32.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll
Module at 0x5cb70000: ShimEng.dll
Module at 0x6f880000: AcGenral.DLL
Module at 0x7e410000: USER32.dll
Module at 0x77f10000: GDI32.dll
Module at 0x76b40000: WINMM.dll
Module at 0x774e0000: ole32.dll
Module at 0x77c10000: msvcrt.dll
Module at 0x77120000: OLEAUT32.dll
Module at 0x77be0000: MSACM32.dll
Module at 0x77c00000: VERSION.dll
Module at 0x7c9c0000: SHELL32.dll
Module at 0x77f60000: SHLWAPI.dll
Module at 0x769c0000: USERENV.dll
Module at 0x5ad70000: UxTheme.dll
Module at 0x773d0000: comctl32.dll
Module at 0x5d090000: comctl32.dll
Module at 0x77690000: NTMARTA.DLL
Module at 0x76f60000: WLDAP32.dll
Module at 0x71bf0000: SAMLIB.dll
Module at 0x76a80000: rpcss.dll
Module at 0x71ab0000: WS2_32.dll
Module at 0x71aa0000: WS2HELP.dll
Module at 0x20000000: xpsp2res.dll
Module at 0x76fd0000: CLBCATQ.DLL
Module at 0x77050000: COMRes.dll

Process 000003e4: svchost.exe
Current Memory usage : 3884 kb
Memory usage peak : 3884 kb
Current Paged Pool usage : 66 kb
Paged Pool usage peak : 66 kb
Current Non-Paged Pool usage : 14 kb
Non-Paged Pool usage peak : 15 kb
Current Page file usage : 1612 kb
Page file usage peak : 1612 kb
Page Faults : 1117

Module list
Module at 0x01000000: svchost.exe
Module at 0x7c900000: ntdll.dll
Module at 0x7c800000: kernel32.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll
Module at 0x5cb70000: ShimEng.dll
Module at 0x6f880000: AcGenral.DLL
Module at 0x7e410000: USER32.dll
Module at 0x77f10000: GDI32.dll
Module at 0x76b40000: WINMM.dll
Module at 0x774e0000: ole32.dll
Module at 0x77c10000: msvcrt.dll
Module at 0x77120000: OLEAUT32.dll
Module at 0x77be0000: MSACM32.dll
Module at 0x77c00000: VERSION.dll
Module at 0x7c9c0000: SHELL32.dll
Module at 0x77f60000: SHLWAPI.dll
Module at 0x769c0000: USERENV.dll
Module at 0x5ad70000: UxTheme.dll
Module at 0x773d0000: comctl32.dll
Module at 0x5d090000: comctl32.dll
Module at 0x76a80000: rpcss.dll
Module at 0x71ab0000: WS2_32.dll
Module at 0x71aa0000: WS2HELP.dll
Module at 0x20000000: xpsp2res.dll
Module at 0x0ffd0000: rsaenh.dll
Module at 0x71a50000: mswsock.dll
Module at 0x662b0000: hnetcfg.dll
Module at 0x71a90000: wshtcpip.dll
Module at 0x76f20000: DNSAPI.dll
Module at 0x76d60000: iphlpapi.dll
Module at 0x76fb0000: winrnr.dll
Module at 0x76f60000: WLDAP32.dll
Module at 0x76fc0000: rasadhlp.dll
Module at 0x76fd0000: CLBCATQ.DLL
Module at 0x77050000: COMRes.dll

Process 00000444: svchost.exe
Current Memory usage : 5900 kb
Memory usage peak : 7508 kb
Current Paged Pool usage : 80 kb
Paged Pool usage peak : 84 kb
Current Non-Paged Pool usage : 9 kb
Non-Paged Pool usage peak : 10 kb
Current Page file usage : 5356 kb
Page file usage peak : 5356 kb
Page Faults : 3847

Module list
Module at 0x01000000: svchost.exe
Module at 0x7c900000: ntdll.dll
Module at 0x7c800000: kernel32.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll
Module at 0x5cb70000: ShimEng.dll
Module at 0x6f880000: AcGenral.DLL
Module at 0x7e410000: USER32.dll
Module at 0x77f10000: GDI32.dll
Module at 0x76b40000: WINMM.dll
Module at 0x774e0000: ole32.dll
Module at 0x77c10000: msvcrt.dll
Module at 0x77120000: OLEAUT32.dll
Module at 0x77be0000: MSACM32.dll
Module at 0x77c00000: VERSION.dll
Module at 0x7c9c0000: SHELL32.dll
Module at 0x77f60000: SHLWAPI.dll
Module at 0x769c0000: USERENV.dll
Module at 0x5ad70000: UxTheme.dll
Module at 0x773d0000: comctl32.dll
Module at 0x5d090000: comctl32.dll
Module at 0x77690000: NTMARTA.DLL
Module at 0x76f60000: WLDAP32.dll
Module at 0x71bf0000: SAMLIB.dll
Module at 0x20000000: xpsp2res.dll
Module at 0x776e0000: shsvcs.dll
Module at 0x76360000: WINSTA.dll
Module at 0x5b860000: NETAPI32.dll
Module at 0x0ffd0000: rsaenh.dll
Module at 0x76d80000: dhcpcsvc.dll
Module at 0x76f20000: DNSAPI.dll
Module at 0x71ab0000: WS2_32.dll
Module at 0x71aa0000: WS2HELP.dll
Module at 0x76d60000: iphlpapi.dll
Module at 0x71a50000: mswsock.dll
Module at 0x662b0000: hnetcfg.dll
Module at 0x71a90000: wshtcpip.dll
Module at 0x7db10000: wzcsvc.dll
Module at 0x76e80000: rtutils.dll
Module at 0x76d30000: WMI.dll
Module at 0x77a80000: CRYPT32.dll
Module at 0x77b20000: MSASN1.dll
Module at 0x76f50000: WTSAPI32.dll
Module at 0x606b0000: ESENT.dll
Module at 0x76b20000: ATL.DLL
Module at 0x76b70000: rastls.dll
Module at 0x754d0000: CRYPTUI.dll
Module at 0x76c30000: WINTRUST.dll
Module at 0x76c90000: IMAGEHLP.dll
Module at 0x771b0000: WININET.dll
Module at 0x76d40000: MPRAPI.dll
Module at 0x77cc0000: ACTIVEDS.dll
Module at 0x76e10000: adsldpc.dll
Module at 0x77920000: SETUPAPI.dll
Module at 0x76ee0000: RASAPI32.dll
Module at 0x76e90000: rasman.dll
Module at 0x76eb0000: TAPI32.dll
Module at 0x767f0000: SCHANNEL.dll
Module at 0x723d0000: WinSCard.dll
Module at 0x76bd0000: raschap.dll
Module at 0x77c70000: msv1_0.dll
Module at 0x76fd0000: CLBCATQ.DLL
Module at 0x77050000: COMRes.dll

Process 00000490: svchost.exe
Current Memory usage : 2732 kb
Memory usage peak : 2744 kb
Current Paged Pool usage : 52 kb
Paged Pool usage peak : 63 kb
Current Non-Paged Pool usage : 3 kb
Non-Paged Pool usage peak : 3 kb
Current Page file usage : 1048 kb
Page file usage peak : 1072 kb
Page Faults : 726

Module list
Module at 0x01000000: svchost.exe
Module at 0x7c900000: ntdll.dll
Module at 0x7c800000: kernel32.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll
Module at 0x5cb70000: ShimEng.dll
Module at 0x6f880000: AcGenral.DLL
Module at 0x7e410000: USER32.dll
Module at 0x77f10000: GDI32.dll
Module at 0x76b40000: WINMM.dll
Module at 0x774e0000: ole32.dll
Module at 0x77c10000: msvcrt.dll
Module at 0x77120000: OLEAUT32.dll
Module at 0x77be0000: MSACM32.dll
Module at 0x77c00000: VERSION.dll
Module at 0x7c9c0000: SHELL32.dll
Module at 0x77f60000: SHLWAPI.dll
Module at 0x769c0000: USERENV.dll
Module at 0x5ad70000: UxTheme.dll
Module at 0x773d0000: comctl32.dll
Module at 0x5d090000: comctl32.dll
Module at 0x76770000: dnsrslvr.dll
Module at 0x76f20000: DNSAPI.dll
Module at 0x71ab0000: WS2_32.dll
Module at 0x71aa0000: WS2HELP.dll
Module at 0x76d60000: iphlpapi.dll

Process 000004a0: logonui.exe
Current Memory usage : 1328 kb
Memory usage peak : 4824 kb
Current Paged Pool usage : 58 kb
Paged Pool usage peak : 68 kb
Current Non-Paged Pool usage : 4 kb
Non-Paged Pool usage peak : 5 kb
Current Page file usage : 2752 kb
Page file usage peak : 2752 kb
Page Faults : 1640

Module list
Module at 0x01000000: logonui.exe
Module at 0x7c900000: ntdll.dll
Module at 0x7c800000: kernel32.dll
Module at 0x77c10000: msvcrt.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll
Module at 0x77f10000: GDI32.dll
Module at 0x7e410000: USER32.dll
Module at 0x773d0000: COMCTL32.dll
Module at 0x77f60000: SHLWAPI.dll
Module at 0x7c9c0000: SHELL32.dll
Module at 0x5b860000: NETAPI32.dll
Module at 0x774e0000: ole32.dll
Module at 0x77120000: OLEAUT32.dll
Module at 0x6c1b0000: DUSER.dll
Module at 0x76380000: MSIMG32.dll
Module at 0x74c80000: OLEACC.dll
Module at 0x76080000: MSVCP60.dll
Module at 0x5cb70000: ShimEng.dll
Module at 0x6f880000: AcGenral.DLL
Module at 0x76b40000: WINMM.dll
Module at 0x77be0000: MSACM32.dll
Module at 0x77c00000: VERSION.dll
Module at 0x769c0000: USERENV.dll
Module at 0x5ad70000: UxTheme.dll
Module at 0x76fd0000: CLBCATQ.DLL
Module at 0x77050000: COMRes.dll
Module at 0x73d70000: shgina.dll
Module at 0x76360000: WINSTA.dll

Process 00000548: svchost.exe
Current Memory usage : 2920 kb
Memory usage peak : 2920 kb
Current Paged Pool usage : 58 kb
Paged Pool usage peak : 64 kb
Current Non-Paged Pool usage : 2 kb
Non-Paged Pool usage peak : 3 kb
Current Page file usage : 1096 kb
Page file usage peak : 1096 kb
Page Faults : 766

Module list
Module at 0x01000000: svchost.exe
Module at 0x7c900000: ntdll.dll
Module at 0x7c800000: kernel32.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll
Module at 0x5cb70000: ShimEng.dll
Module at 0x6f880000: AcGenral.DLL
Module at 0x7e410000: USER32.dll
Module at 0x77f10000: GDI32.dll
Module at 0x76b40000: WINMM.dll
Module at 0x774e0000: ole32.dll
Module at 0x77c10000: msvcrt.dll
Module at 0x77120000: OLEAUT32.dll
Module at 0x77be0000: MSACM32.dll
Module at 0x77c00000: VERSION.dll
Module at 0x7c9c0000: SHELL32.dll
Module at 0x77f60000: SHLWAPI.dll
Module at 0x769c0000: USERENV.dll
Module at 0x5ad70000: UxTheme.dll
Module at 0x773d0000: comctl32.dll
Module at 0x5d090000: comctl32.dll
Module at 0x77690000: NTMARTA.DLL
Module at 0x76f60000: WLDAP32.dll
Module at 0x71bf0000: SAMLIB.dll
Module at 0x20000000: xpsp2res.dll
Module at 0x74c40000: lmhsvc.dll
Module at 0x76d60000: iphlpapi.dll
Module at 0x71ab0000: WS2_32.dll
Module at 0x71aa0000: WS2HELP.dll

Process 000005d4: userinit.exe
Current Memory usage : 2800 kb
Memory usage peak : 2800 kb
Current Paged Pool usage : 58 kb
Paged Pool usage peak : 70 kb
Current Non-Paged Pool usage : 2 kb
Non-Paged Pool usage peak : 3 kb
Current Page file usage : 936 kb
Page file usage peak : 940 kb
Page Faults : 757

Module list
Module at 0x01000000: userinit.exe
Module at 0x7c900000: ntdll.dll
Module at 0x7c800000: kernel32.dll
Module at 0x7e410000: USER32.dll
Module at 0x77f10000: GDI32.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll
Module at 0x77a80000: CRYPT32.dll
Module at 0x77c10000: msvcrt.dll
Module at 0x77b20000: MSASN1.dll
Module at 0x73000000: WINSPOOL.DRV
Module at 0x5cb70000: ShimEng.dll
Module at 0x6f880000: AcGenral.DLL
Module at 0x76b40000: WINMM.dll
Module at 0x774e0000: ole32.dll
Module at 0x77120000: OLEAUT32.dll
Module at 0x77be0000: MSACM32.dll
Module at 0x77c00000: VERSION.dll
Module at 0x7c9c0000: SHELL32.dll
Module at 0x77f60000: SHLWAPI.dll
Module at 0x769c0000: USERENV.dll
Module at 0x5ad70000: UxTheme.dll
Module at 0x773d0000: comctl32.dll
Module at 0x5d090000: comctl32.dll
Module at 0x77b40000: Apphelp.dll

Process 000005f4: explorer.exe
Current Memory usage : 13856 kb
Memory usage peak : 13856 kb
Current Paged Pool usage : 81 kb
Paged Pool usage peak : 83 kb
Current Non-Paged Pool usage : 5 kb
Non-Paged Pool usage peak : 5 kb
Current Page file usage : 11744 kb
Page file usage peak : 11772 kb
Page Faults : 3838

Module list
Module at 0x01000000: Explorer.EXE
Module at 0x7c900000: ntdll.dll
Module at 0x7c800000: kernel32.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll
Module at 0x75f80000: BROWSEUI.dll
Module at 0x77f10000: GDI32.dll
Module at 0x7e410000: USER32.dll
Module at 0x77c10000: msvcrt.dll
Module at 0x774e0000: ole32.dll
Module at 0x77f60000: SHLWAPI.dll
Module at 0x77120000: OLEAUT32.dll
Module at 0x7e290000: SHDOCVW.dll
Module at 0x77a80000: CRYPT32.dll
Module at 0x77b20000: MSASN1.dll
Module at 0x754d0000: CRYPTUI.dll
Module at 0x76c30000: WINTRUST.dll
Module at 0x76c90000: IMAGEHLP.dll
Module at 0x5b860000: NETAPI32.dll
Module at 0x771b0000: WININET.dll
Module at 0x76f60000: WLDAP32.dll
Module at 0x77c00000: VERSION.dll
Module at 0x7c9c0000: SHELL32.dll
Module at 0x5ad70000: UxTheme.dll
Module at 0x5cb70000: ShimEng.dll
Module at 0x6f880000: AcGenral.DLL
Module at 0x76b40000: WINMM.dll
Module at 0x77be0000: MSACM32.dll
Module at 0x769c0000: USERENV.dll
Module at 0x773d0000: comctl32.dll
Module at 0x5d090000: comctl32.dll
Module at 0x77b40000: appHelp.dll
Module at 0x76fd0000: CLBCATQ.DLL
Module at 0x77050000: COMRes.dll
Module at 0x77a20000: cscui.dll
Module at 0x76600000: CSCDLL.dll
Module at 0x5ba60000: themeui.dll
Module at 0x76380000: MSIMG32.dll
Module at 0x20000000: xpsp2res.dll

Process 0000067c: aawservice.exe
Current Memory usage : 27156 kb
Memory usage peak : 80984 kb
Current Paged Pool usage : 127 kb
Paged Pool usage peak : 135 kb
Current Non-Paged Pool usage : 3 kb
Non-Paged Pool usage peak : 4 kb
Current Page file usage : 25720 kb
Page file usage peak : 82772 kb
Page Faults : 38275

Module list
Module at 0x00400000: aawservice.exe
Module at 0x7c900000: ntdll.dll
Module at 0x7c800000: kernel32.dll
Module at 0x10000000: CEAPI.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll
Module at 0x77f60000: SHLWAPI.dll
Module at 0x77f10000: GDI32.dll
Module at 0x7e410000: USER32.dll
Module at 0x77c10000: msvcrt.dll
Module at 0x71ab0000: WS2_32.dll
Module at 0x71aa0000: WS2HELP.dll
Module at 0x004a0000: PKArchive85u.dll
Module at 0x7c9c0000: SHELL32.dll
Module at 0x774e0000: ole32.dll
Module at 0x77a80000: CRYPT32.dll
Module at 0x77b20000: MSASN1.dll
Module at 0x76f60000: WLDAP32.dll
Module at 0x76bf0000: PSAPI.DLL
Module at 0x77c00000: VERSION.dll
Module at 0x771b0000: WININET.dll
Module at 0x77120000: OLEAUT32.dll
Module at 0x00350000: Update.dll
Module at 0x71ad0000: WSOCK32.dll
Module at 0x769c0000: USERENV.dll
Module at 0x773d0000: comctl32.dll
Module at 0x5d090000: comctl32.dll
Module at 0x0ffd0000: rsaenh.dll

Process 000006a4: AAWTray.exe
Current Memory usage : 1252 kb
Memory usage peak : 1252 kb
Current Paged Pool usage : 59 kb
Paged Pool usage peak : 59 kb
Current Non-Paged Pool usage : 1 kb
Non-Paged Pool usage peak : 1 kb
Current Page file usage : 452 kb
Page file usage peak : 452 kb
Page Faults : 306

Module list
Module at 0x00400000: AAWTray.exe
Module at 0x7c900000: ntdll.dll
Module at 0x7c800000: kernel32.dll
Module at 0x7e410000: USER32.dll
Module at 0x77f10000: GDI32.dll
Module at 0x7c9c0000: SHELL32.dll
Module at 0x77dd0000: ADVAPI32.dll
Module at 0x77e70000: RPCRT4.dll
Module at 0x77fe0000: Secur32.dll
Module at 0x77c10000: msvcrt.dll
Module at 0x77f60000: SHLWAPI.dll
FQCS
There are other symptoms as well.
I'm getting pop ups. theonlybookmark.com has hijacked my Internet Explorer home page.

I'd really like to know who did this. Is there a name for my pain?
Blade81
Before we can help you, you need to help us by following the instructions located in this post:
Important Before You Post Read This!
Blade81
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else please begin a New Topic.

Thank You !
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.