hi again. thank you so much for your help. i wanted to try all i could to clean it before i rebooted so i have tried what you said and have my new hijackthis & ad-aware logs. please let me know if there is anything i need to do or if it is time to reboot. thanks again.
Ad-Aware SE Build 1.06r1
Logfile Created on:Saturday, 9 September 2006 4:09:34 a.m.
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R122 08.09.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Adware.Maxifiles(TAC index:5):2 total references
Adware.SafetyBar(TAC index:3):1 total references
MRU List(TAC index:0):17 total references
Tracking Cookie(TAC index:3):24 total references
Win32.Trojan.KillAV(TAC index:10):1 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
9-09-2006 4:09:34 a.m. - Scan started. (Full System Scan)
MRU List Object Recognized!
Location: : C:\Documents and Settings\Ryan\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office
MRU List Object Recognized!
Location: : C:\Documents and Settings\Ryan\recent
Description : list of recently opened documents
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Object Recognized!
Location: : S-1-5-21-74049757-502627533-162025716-1005\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-74049757-502627533-162025716-1005\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-74049757-502627533-162025716-1005\software\microsoft\mediaplayer\preferences
Description : last playlist index loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-74049757-502627533-162025716-1005\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-74049757-502627533-162025716-1005\software\microsoft\microsoft management console\recent file list
Description : list of recent snap-ins used in the microsoft management console
MRU List Object Recognized!
Location: : S-1-5-21-74049757-502627533-162025716-1005\software\microsoft\search assistant\acmru
Description : list of recent search terms used with the search assistant
MRU List Object Recognized!
Location: : S-1-5-21-74049757-502627533-162025716-1005\software\microsoft\windows\currentversion\applets\paint\recent file list
Description : list of files recently opened using microsoft paint
MRU List Object Recognized!
Location: : S-1-5-21-74049757-502627533-162025716-1005\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened
MRU List Object Recognized!
Location: : S-1-5-21-74049757-502627533-162025716-1005\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension
MRU List Object Recognized!
Location: : S-1-5-21-74049757-502627533-162025716-1005\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened
MRU List Object Recognized!
Location: : S-1-5-21-74049757-502627533-162025716-1005\software\microsoft\windows\currentversion\explorer\runmru
Description : mru list for items opened in start | run
MRU List Object Recognized!
Location: : S-1-5-21-74049757-502627533-162025716-1005\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 404
ThreadCreationTime : 8-09-2006 1:26:26 p.m.
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 460
ThreadCreationTime : 8-09-2006 1:26:29 p.m.
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 492
ThreadCreationTime : 8-09-2006 1:26:30 p.m.
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 536
ThreadCreationTime : 8-09-2006 1:26:31 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 556
ThreadCreationTime : 8-09-2006 1:26:31 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 700
ThreadCreationTime : 8-09-2006 1:26:33 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 780
ThreadCreationTime : 8-09-2006 1:26:34 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 816
ThreadCreationTime : 8-09-2006 1:26:34 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 864
ThreadCreationTime : 8-09-2006 1:26:34 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 892
ThreadCreationTime : 8-09-2006 1:26:35 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:11 [lexbces.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1044
ThreadCreationTime : 8-09-2006 1:26:38 p.m.
BasePriority : Normal
FileVersion : 7.1
ProductVersion : 7.1
ProductName : MarkVision for Windows (32 bit)
CompanyName : Lexmark International, Inc.
FileDescription : LexBce Service
InternalName : LexBce Service
LegalCopyright : © 1993 - 2001 Lexmark International, Inc.
OriginalFilename : LexBceS.exe
#:12 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1080
ThreadCreationTime : 8-09-2006 1:26:39 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
ProductVersion : 5.1.2600.2696
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:13 [nhksrv.exe]
FilePath : C:\Apps\ActivBoard\
ProcessID : 1184
ThreadCreationTime : 8-09-2006 1:26:42 p.m.
BasePriority : Normal
#:14 [avgamsvr.exe]
FilePath : C:\PROGRA~1\Grisoft\AVGFRE~1\
ProcessID : 1252
ThreadCreationTime : 8-09-2006 1:26:43 p.m.
BasePriority : Normal
FileVersion : 7,1,0,365
ProductVersion : 7.1.0.365
ProductName : AVG Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Alert Manager
InternalName : avgamsvr
LegalCopyright : Copyright © 2005, GRISOFT, s.r.o.
OriginalFilename : avgamsvr.EXE
#:15 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 1356
ThreadCreationTime : 8-09-2006 1:26:44 p.m.
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
#:16 [avgupsvc.exe]
FilePath : C:\PROGRA~1\Grisoft\AVGFRE~1\
ProcessID : 1444
ThreadCreationTime : 8-09-2006 1:26:47 p.m.
BasePriority : Normal
FileVersion : 7,1,0,349
ProductVersion : 7.1.0.349
ProductName : AVG 7.0 Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Update Service
InternalName : avgupsvc
LegalCopyright : Copyright © 2005, GRISOFT, s.r.o.
OriginalFilename : avgupdsvc.EXE
#:17 [avgemc.exe]
FilePath : C:\PROGRA~1\Grisoft\AVGFRE~1\
ProcessID : 1472
ThreadCreationTime : 8-09-2006 1:26:47 p.m.
BasePriority : Normal
FileVersion : 7,1,0,400
ProductVersion : 7.1.0.400
ProductName : AVG Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG E-Mail Scanner
InternalName : avgemc
LegalCopyright : Copyright © 2006, GRISOFT, s.r.o.
OriginalFilename : avgemc.exe
#:18 [crypserv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1492
ThreadCreationTime : 8-09-2006 1:26:48 p.m.
BasePriority : High
FileVersion : 5.4.0
ProductVersion : 5.4
ProductName : CrypKey Software Licensing System
CompanyName : Kenonic Controls Ltd.
FileDescription : CrypKey NT Service
InternalName : crypserv
LegalCopyright : Copyright © 2000
LegalTrademarks : CrypKey
OriginalFilename : crypserv.exe
Comments : Operates in all directories, not just configured ones. Directory configuration only used for fille clean up and uninstall. 0/3 fixed problem with other partitions. 0/6 fixed problem with short paths
#:19 [slserv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1548
ThreadCreationTime : 8-09-2006 1:26:49 p.m.
BasePriority : Normal
#:20 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1572
ThreadCreationTime : 8-09-2006 1:26:50 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:21 [wdfmgr.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1600
ThreadCreationTime : 8-09-2006 1:26:50 p.m.
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe
#:22 [monitor.exe]
FilePath : C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\
ProcessID : 1804
ThreadCreationTime : 8-09-2006 1:26:58 p.m.
BasePriority : Normal
FileVersion : 8.0.0.0
ProductVersion : 8.0.0.0
ProductName : Ulead Photo Explorer
CompanyName : Ulead Systems, Inc.
FileDescription : MONITOR
InternalName : MONITOR
LegalCopyright : Copyright c1992-2001. Ulead Systems, Inc. All rights reserved.
LegalTrademarks : Ulead Systems, MediaStudio and PhotoImpact are registered trademarks of Ulead Systems, Inc.
OriginalFilename : MONITOR.EXE
#:23 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 1816
ThreadCreationTime : 8-09-2006 1:26:58 p.m.
BasePriority : Normal
FileVersion : 0.1.0.3208
ProductVersion : 0.1.0.3208
ProductName : RealPlayer (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
LegalTrademarks : RealAudio is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe
#:24 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ProcessID : 1824
ThreadCreationTime : 8-09-2006 1:26:58 p.m.
BasePriority : Normal
FileVersion : 7.0.3
ProductVersion : QuickTime 7.0.3
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
FileDescription : QuickTime Task
InternalName : QuickTime Task
LegalCopyright : Copyright Apple Computer, Inc. 1989-2005
OriginalFilename : QTTask.exe
#:25 [pwrisovm.exe]
FilePath : G:\Program Files\PowerISO\
ProcessID : 1840
ThreadCreationTime : 8-09-2006 1:26:58 p.m.
BasePriority : Normal
FileVersion : 3, 0, 0, 0
ProductVersion : 3, 0, 0, 0
ProductName : PowerISO Virtual Drive Manager
CompanyName : PowerISO Computing, Inc.
FileDescription : PowerISO Virtual Drive Manager
InternalName : PowerISO Virtual Drive Manager
LegalCopyright : Copyright © 2004-2006
OriginalFilename : PWRISOVM.EXE
Comments :
http://www.poweriso.com#:26 [lxsupmon.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1916
ThreadCreationTime : 8-09-2006 1:26:59 p.m.
BasePriority : Normal
FileVersion : 2.2.64.1
ProductVersion : 2.2.64.1
ProductName : Lexmark Supplies Monitor
CompanyName : Lexmark International Inc.
FileDescription : Supplies Monitor
InternalName : LXSUPMON
LegalCopyright : Copyright © 2000
OriginalFilename : LXSUPMON.RC
#:27 [igfxtray.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1928
ThreadCreationTime : 8-09-2006 1:26:59 p.m.
BasePriority : Normal
FileVersion : 3,0,0,1132
ProductVersion : 7,0,0,1132
ProductName : Intel® Common User Interface
CompanyName : Intel Corporation
FileDescription : igfxTray Module
InternalName : IGFXTRAY
LegalCopyright : Copyright 1999-2001, Intel Corporation
OriginalFilename : IGFXTRAY.EXE
#:28 [hkcmd.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1940
ThreadCreationTime : 8-09-2006 1:27:00 p.m.
BasePriority : Normal
FileVersion : 3,0,0,1132
ProductVersion : 7,0,0,1132
ProductName : Intel® Common User Interface
CompanyName : Intel Corporation
FileDescription : hkcmd Module
InternalName : HKCMD
LegalCopyright : Copyright 1999-2001, Intel Corporation
OriginalFilename : HKCMD.EXE
#:29 [em_exec.exe]
FilePath : C:\PROGRA~1\MOUSEW~1\SYSTEM\
ProcessID : 1968
ThreadCreationTime : 8-09-2006 1:27:00 p.m.
BasePriority : Normal
FileVersion : 9.40.139
ProductVersion : 9.40
ProductName : MouseWare
CompanyName : Logitech Inc.
FileDescription : Control Center
InternalName : EM_EXEC
LegalCopyright : Copyright © Logitech Inc. 1987-2001.
LegalTrademarks : Logitech® and MouseWare® are registered trademarks of Logitech Inc.
OriginalFilename : EM_EXEC.CPP
Comments : Created by the MouseWare Team
#:30 [mmkeybd.exe]
FilePath : C:\Apps\ActivBoard\
ProcessID : 1992
ThreadCreationTime : 8-09-2006 1:27:00 p.m.
BasePriority : Normal
FileVersion : 1.00
ProductVersion : 1.00
ProductName : Netropa Hot Key
CompanyName : Netropa Corp.
FileDescription : Netropa® Hot Key
InternalName : Netropa Hot Key
LegalCopyright : Copyright © 2000-2001 Netropa Corp.
OriginalFilename : nhk.exe
#:31 [jusched.exe]
FilePath : C:\Program Files\Java\jre1.5.0_06\bin\
ProcessID : 2000
ThreadCreationTime : 8-09-2006 1:27:00 p.m.
BasePriority : Normal
#:32 [avgcc.exe]
FilePath : C:\PROGRA~1\Grisoft\AVGFRE~1\
ProcessID : 2008
ThreadCreationTime : 8-09-2006 1:27:01 p.m.
BasePriority : Normal
FileVersion : 7,1,0,405
ProductVersion : 7.1.0.405
ProductName : AVG Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Control Center
InternalName : AvgCC
LegalCopyright : Copyright © 2006, GRISOFT, s.r.o.
OriginalFilename : AvgCC.EXE
#:33 [wkcalrem.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\Works Shared\
ProcessID : 184
ThreadCreationTime : 8-09-2006 1:27:04 p.m.
BasePriority : Normal
FileVersion : 6.00.1828.1
ProductVersion : 6.00.1828.1
ProductName : Microsoft® Works 6.0
CompanyName : Microsoft® Corporation
FileDescription : Microsoft® Works Calendar Reminder Service
InternalName : WkCalRem
LegalCopyright : Copyright © Microsoft Corporation 1987-2000. All rights reserved.
OriginalFilename : WKCALREM.EXE
#:34 [slipaccel.exe]
FilePath : C:\Program Files\SlipStream Web Accelerator\
ProcessID : 204
ThreadCreationTime : 8-09-2006 1:27:05 p.m.
BasePriority : Normal
ProductName : SlipStream Web Accelerator
CompanyName : SlipStream Data Inc.
FileDescription : SlipStream Web Accelerator Client Application
InternalName : SlipStream Web Accelerator
LegalCopyright : Copyright © 2002
#:35 [traymon.exe]
FilePath : C:\Apps\ActivBoard\
ProcessID : 228
ThreadCreationTime : 8-09-2006 1:27:06 p.m.
BasePriority : Normal
#:36 [osd.exe]
FilePath : C:\Apps\ActivBoard\
ProcessID : 348
ThreadCreationTime : 8-09-2006 1:27:09 p.m.
BasePriority : Normal
FileVersion : 2.02
ProductVersion : 2.02
ProductName : Onscreen Display
CompanyName : Netropa Corp.
FileDescription : Netropa® Onscreen Display
InternalName : OSD
LegalCopyright : Copyright © 1997-2001 Netropa Corp.
OriginalFilename : osd.exe
#:37 [watch.exe]
FilePath : C:\WINDOWS\twain_32\B12U12K\
ProcessID : 428
ThreadCreationTime : 8-09-2006 1:27:10 p.m.
BasePriority : Normal
FileVersion : 2, 3, 2, 7
ProductVersion : 2, 3, 2, 7
ProductName : Watch Dog
CompanyName : Common Group
FileDescription : Watch Dog
InternalName : Tiffany
LegalCopyright : Copyright © 1998
OriginalFilename : WATCH.EXE
#:38 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1800
ThreadCreationTime : 8-09-2006 1:27:25 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe
#:39 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 3688
ThreadCreationTime : 8-09-2006 4:09:17 p.m.
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 17
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 17
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 17
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@edge.ru4[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:ryan@edge.ru4.com/
Expires : 1-09-2036 12:48:22 a.m.
LastSync : Hits:3
UseCount : 0
Hits : 3
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@instadia[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:8
Value : Cookie:ryan@instadia.net/
Expires : 30-08-2008 6:41:12 p.m.
LastSync : Hits:8
UseCount : 0
Hits : 8
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@zedo[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:18
Value : Cookie:ryan@zedo.com/
Expires : 6-09-2016 12:48:22 a.m.
LastSync : Hits:18
UseCount : 0
Hits : 18
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@ehg-wizardsofthecoast.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:12
Value : Cookie:ryan@ehg-wizardsofthecoast.hitbox.com/
Expires : 8-09-2007 6:53:00 p.m.
LastSync : Hits:12
UseCount : 0
Hits : 12
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@fastclick[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:23
Value : Cookie:ryan@fastclick.net/
Expires : 7-09-2008 6:59:48 p.m.
LastSync : Hits:23
UseCount : 0
Hits : 23
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@fad-608.iad6.targetnet[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:ryan@fad-608.iad6.targetnet.com/
Expires : 17-09-2006 8:35:28 a.m.
LastSync : Hits:3
UseCount : 0
Hits : 3
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@maxserving[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:ryan@maxserving.com/
Expires : 5-09-2016 8:51:18 a.m.
LastSync : Hits:2
UseCount : 0
Hits : 2
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@mediaplex[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:ryan@mediaplex.com/
Expires : 22-06-2009 12:00:00 p.m.
LastSync : Hits:2
UseCount : 0
Hits : 2
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@tribalfusion[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:ryan@tribalfusion.com/
Expires : 1-01-2038 12:00:00 p.m.
LastSync : Hits:3
UseCount : 0
Hits : 3
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@vegasred[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:9
Value : Cookie:ryan@vegasred.com/
Expires : 30-10-2025 6:36:26 p.m.
LastSync : Hits:9
UseCount : 0
Hits : 9
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@2o7[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:7
Value : Cookie:ryan@2o7.net/
Expires : 8-09-2011 1:18:58 a.m.
LastSync : Hits:7
UseCount : 0
Hits : 7
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@advertising[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:92
Value : Cookie:ryan@advertising.com/
Expires : 7-09-2011 6:30:32 p.m.
LastSync : Hits:92
UseCount : 0
Hits : 92
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@targetnet[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:21
Value : Cookie:ryan@targetnet.com/
Expires : 18-05-2033 3:33:20 p.m.
LastSync : Hits:21
UseCount : 0
Hits : 21
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@serving-sys[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:5
Value : Cookie:ryan@serving-sys.com/
Expires : 1-01-2038 10:00:00 a.m.
LastSync : Hits:5
UseCount : 0
Hits : 5
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@atdmt[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:ryan@atdmt.com/
Expires : 7-09-2011 12:00:00 p.m.
LastSync : Hits:3
UseCount : 0
Hits : 3
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@ads.addynamix[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:ryan@ads.addynamix.com/
Expires : 9-09-2006 8:30:44 p.m.
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@adserver.adreactor[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:ryan@adserver.adreactor.com/
Expires : 3-09-2007 9:16:04 a.m.
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@perf.overture[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:ryan@perf.overture.com/
Expires : 8-09-2010 12:44:22 a.m.
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@www.vegasred[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:ryan@www.vegasred.com/
Expires : 31-08-2011 2:36:26 p.m.
LastSync : Hits:3
UseCount : 0
Hits : 3
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@casalemedia[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:30
Value : Cookie:ryan@casalemedia.com/
Expires : 25-08-2007 2:47:14 p.m.
LastSync : Hits:30
UseCount : 0
Hits : 30
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@doubleclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:ryan@doubleclick.net/
Expires : 8-09-2009 1:09:46 a.m.
LastSync : Hits:3
UseCount : 0
Hits : 3
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@~~local~~[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:ryan@~~local~~/
Expires : 15-09-2006 11:51:48 a.m.
LastSync : Hits:4
UseCount : 0
Hits : 4
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@ads.pointroll[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:ryan@ads.pointroll.com/
Expires : 1-01-2010 12:00:00 p.m.
LastSync : Hits:4
UseCount : 0
Hits : 4
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 23
Objects found so far: 40
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Win32.Trojan.KillAV Object Recognized!
Type : File
Data : b122.exe
TAC Rating : 10
Category : Virus
Comment :
Object : C:\Documents and Settings\Ryan\Local Settings\Temp\
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : ryan@maxserving[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Ryan\Local Settings\Temp\Cookies\ryan@maxserving[1].txt
Adware.SafetyBar Object Recognized!
Type : File
Data : A0299853.dll
TAC Rating : 3
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{B8E8BA2B-D174-4B63-94F8-468C63A711EE}\RP890\
Adware.Maxifiles Object Recognized!
Type : File
Data : A0311150.exe
TAC Rating : 5
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{B8E8BA2B-D174-4B63-94F8-468C63A711EE}\RP900\
Adware.Maxifiles Object Recognized!
Type : File
Data : A0311151.dll
TAC Rating : 5
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{B8E8BA2B-D174-4B63-94F8-468C63A711EE}\RP900\
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 45
Deep scanning and examining files (E:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for E:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 45
Deep scanning and examining files (G:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for G:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 45
Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
0 entries scanned.
New critical objects:0
Objects found so far: 45
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 45
4:32:25 a.m. Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:22:51.203
Objects scanned:183574
Objects identified:28
Objects ignored:0
New critical objects:28