Help - Search - Members - Calendar
Full Version: REMOVING SPYWARES
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Resolved/Inactive General Support Issues
Khaliq
Ad-Aware SE Build 1.06r1
Logfile Created on:Friday, September 15, 2006 10:57:59 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R123 14.09.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):2 total references
Tracking Cookie(TAC index:3):1 total references
Win32.Trojandownloader.Zlob(TAC index:10):5 total references
VirusBlast(TAC index:3):3 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Create log file for removal operations
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


9-15-2006 10:57:59 PM - Scan started. (Smart mode)

Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 376
ThreadCreationTime : 9-15-2006 3:02:13 PM
BasePriority : Normal


#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 432
ThreadCreationTime : 9-15-2006 3:02:16 PM
BasePriority : Normal


#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 456
ThreadCreationTime : 9-15-2006 3:02:17 PM
BasePriority : High


#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 500
ThreadCreationTime : 9-15-2006 3:02:17 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe

#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 512
ThreadCreationTime : 9-15-2006 3:02:17 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe

#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 664
ThreadCreationTime : 9-15-2006 3:02:18 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 740
ThreadCreationTime : 9-15-2006 3:02:18 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 780
ThreadCreationTime : 9-15-2006 3:02:18 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:9 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 820
ThreadCreationTime : 9-15-2006 3:02:19 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:10 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 864
ThreadCreationTime : 9-15-2006 3:02:19 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:11 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1072
ThreadCreationTime : 9-15-2006 3:02:21 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe

#:12 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 1176
ThreadCreationTime : 9-15-2006 3:02:22 PM
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE

#:13 [aswupdsv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 1296
ThreadCreationTime : 9-15-2006 3:02:22 PM
BasePriority : Normal


#:14 [ashserv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 1384
ThreadCreationTime : 9-15-2006 3:02:24 PM
BasePriority : High
FileVersion : 4, 7, 844, 0
ProductVersion : 4, 7, 0, 0
ProductName : avast! Antivirus
FileDescription : avast! antivirus service
InternalName : aswServ
LegalCopyright : Copyright © 2006 ALWIL Software
OriginalFilename : aswServ.exe

#:15 [dslagent.exe]
FilePath : C:\Program Files\Huawei\MT882\
ProcessID : 1424
ThreadCreationTime : 9-15-2006 3:02:28 PM
BasePriority : Normal


#:16 [myagtsvc.exe]
FilePath : C:\Program Files\McAfee\Managed VirusScan\Agent\
ProcessID : 1456
ThreadCreationTime : 9-15-2006 3:02:28 PM
BasePriority : Normal
FileVersion : 4.0.0.358
ProductVersion : 4.0.0
ProductName : McAfee® Total Protection for Small Business
CompanyName : McAfee, Inc.
FileDescription : McAfee Managed Services Agent
InternalName : myAgtSvc
LegalCopyright : ©1995-2006 McAfee, Inc. All Rights Reserved.
LegalTrademarks : McAfee and VirusScan are registered trademarks of McAfee, Inc. and/or its affiliates in the US and/or other countries. ©1995-2006 McAfee, Inc. All Rights Reserved.
OriginalFilename : myAgtSvc.exe

#:17 [quran_ar.exe]
FilePath : C:\Program Files\Quran_AR\
ProcessID : 1472
ThreadCreationTime : 9-15-2006 3:02:28 PM
BasePriority : Normal
FileVersion : 1.00
ProductVersion : 1.00
ProductName : Quran Auto Reciter
CompanyName : Search Truth Technologies
InternalName : Quran_AR
OriginalFilename : Quran_AR.exe
Comments : Quran Auto Reciter is used to listen the Holy Quran automatically at a specific time.

#:18 [prayertimes.exe]
FilePath : C:\Program Files\Playnetics\Prayer Times Software\
ProcessID : 1480
ThreadCreationTime : 9-15-2006 3:02:29 PM
BasePriority : Normal
FileVersion : 1.1.2.0
ProductVersion : 1.0.0.0
ProductName : Prayer Times Software
CompanyName : Playnetics Ltd (UK)
FileDescription : Prayer Times Software Version 1.0
LegalCopyright : © 2006 Playnetics Ltd (UK)

#:19 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 1488
ThreadCreationTime : 9-15-2006 3:02:29 PM
BasePriority : Normal
FileVersion : 0.1.0.3510
ProductVersion : 0.1.0.3510
ProductName : RealPlayer (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
LegalTrademarks : RealAudio™ is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe

#:20 [ashdisp.exe]
FilePath : C:\PROGRA~1\ALWILS~1\Avast4\
ProcessID : 1628
ThreadCreationTime : 9-15-2006 3:02:35 PM
BasePriority : Normal
FileVersion : 5, 0, 0, 0
ProductVersion : 5, 0, 0, 0
ProductName : avast! Antivirus
FileDescription : avast! service GUI component
InternalName : aswDisp
LegalCopyright : Copyright © 2006 ALWIL Software
OriginalFilename : aswDisp.exe

#:21 [virus-burst.exe]
FilePath : C:\Program Files\Virus-Burst\
ProcessID : 1660
ThreadCreationTime : 9-15-2006 3:02:36 PM
BasePriority : Normal
FileVersion : 6.0.0.0
ProductVersion : 6.0.0.0
ProductName : VirusBurst
CompanyName : VirusBurst.com
FileDescription : Anti- spyware and adware
InternalName : VirusBurst.exe
LegalCopyright : © VirusBurst.com. All rights reserved.
OriginalFilename : VirusBurst.exe

VirusBlast Object Recognized!
Type : Process
Data : Virus-Burst.exe
TAC Rating : 3
Category : Malware
Comment : VirusBurst.exe.dmp
Object : C:\Program Files\Virus-Burst\
FileVersion : 6.0.0.0
ProductVersion : 6.0.0.0
ProductName : VirusBurst
CompanyName : VirusBurst.com
FileDescription : Anti- spyware and adware
InternalName : VirusBurst.exe
LegalCopyright : © VirusBurst.com. All rights reserved.
OriginalFilename : VirusBurst.exe

Warning! VirusBlast Object found in memory(C:\Program Files\Virus-Burst\Virus-Burst.exe)

"C:\Program Files\Virus-Burst\Virus-Burst.exe"Process terminated successfully
"C:\Program Files\Virus-Burst\Virus-Burst.exe"Process terminated successfully

#:22 [spy-heal.exe]
FilePath : C:\Program Files\Spy-Heal\
ProcessID : 1680
ThreadCreationTime : 9-15-2006 3:02:37 PM
BasePriority : Normal
FileVersion : 2.0.0.0
ProductVersion : 2.0.0.0
ProductName : SpyHeal
CompanyName : SpyHeal
FileDescription : Anti- spyware and adware
InternalName : spyheal.exe
LegalCopyright : © SpyHeal. All rights reserved.
OriginalFilename : spyheal.exe

#:23 [ymsgr_tray.exe]
FilePath : C:\Program Files\Yahoo!\Messenger\
ProcessID : 396
ThreadCreationTime : 9-15-2006 3:05:10 PM
BasePriority : Normal


#:24 [ashmaisv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 1124
ThreadCreationTime : 9-15-2006 3:05:26 PM
BasePriority : Normal


#:25 [ashwebsv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 1412
ThreadCreationTime : 9-15-2006 3:05:32 PM
BasePriority : Normal


#:26 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2116
ThreadCreationTime : 9-15-2006 3:05:38 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe

#:27 [wuauclt.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2420
ThreadCreationTime : 9-15-2006 3:07:05 PM
BasePriority : Normal
FileVersion : 5.8.0.2469 built by: lab01_n(wmbla)
ProductVersion : 5.8.0.2469
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Automatic Updates
InternalName : wuauclt.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : wuauclt.exe

#:28 [mcshield.exe]
FilePath : C:\Program Files\McAfee\Managed VirusScan\VScan\
ProcessID : 624
ThreadCreationTime : 9-15-2006 3:28:50 PM
BasePriority : High


#:29 [myagttry.exe]
FilePath : C:\Program Files\McAfee\Managed VirusScan\Agent\
ProcessID : 264
ThreadCreationTime : 9-15-2006 3:29:49 PM
BasePriority : Normal
FileVersion : 4.0.0.358
ProductVersion : 4.0.0
ProductName : McAfee® Total Protection for Small Business
CompanyName : McAfee, Inc.
FileDescription : myAgtTry Module
InternalName : myAgtTry
LegalCopyright : ©1995-2006 McAfee, Inc. All Rights Reserved.
LegalTrademarks : McAfee and VirusScan are registered trademarks of McAfee, Inc. and/or its affiliates in the US and/or other countries. ©1995-2006 McAfee, Inc. All Rights Reserved.
OriginalFilename : myAgtTry.exe

#:30 [ntvdm.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2708
ThreadCreationTime : 9-15-2006 4:06:39 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : NTVDM.EXE
InternalName : NTVDM.EXE
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : NTVDM.EXE

#:31 [hh.exe]
FilePath : C:\WINDOWS\
ProcessID : 3328
ThreadCreationTime : 9-15-2006 4:40:47 PM
BasePriority : Normal
FileVersion : 5.2.3790.1159 (dnsrv.040209-1620)
ProductVersion : 5.2.3790.1159
ProductName : HTML Help
CompanyName : Microsoft Corporation
FileDescription : Microsoft® HTML Help Executable
InternalName : HH 1.41
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : HH.exe

#:32 [hh.exe]
FilePath : C:\WINDOWS\
ProcessID : 3540
ThreadCreationTime : 9-15-2006 4:44:27 PM
BasePriority : Normal
FileVersion : 5.2.3790.1159 (dnsrv.040209-1620)
ProductVersion : 5.2.3790.1159
ProductName : HTML Help
CompanyName : Microsoft Corporation
FileDescription : Microsoft® HTML Help Executable
InternalName : HH 1.41
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : HH.exe

#:33 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 3656
ThreadCreationTime : 9-15-2006 4:46:02 PM
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : IEXPLORE.EXE

Win32.Trojandownloader.Zlob Object Recognized!
Type : Process
Data : isaddon.dll
TAC Rating : 10
Category : Malware
Comment : isaddon.dll.dmp
Object : C:\Program Files\iCodecPack\


Warning! Win32.Trojandownloader.Zlob Object found in memory(C:\Program Files\iCodecPack\isaddon.dll)


#:34 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 800
ThreadCreationTime : 9-15-2006 5:13:46 PM
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : IEXPLORE.EXE

Win32.Trojandownloader.Zlob Object Recognized!
Type : Process
Data : isaddon.dll
TAC Rating : 10
Category : Malware
Comment : isaddon.dll.dmp
Object : C:\Program Files\iCodecPack\


Warning! Win32.Trojandownloader.Zlob Object found in memory(C:\Program Files\iCodecPack\isaddon.dll)


#:35 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 3912
ThreadCreationTime : 9-15-2006 5:25:47 PM
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 3


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Win32.Trojandownloader.Zlob Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{202a961f-23ae-42b1-9505-ffe3c818d717}

VirusBlast Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{ccfb2b33-f4db-b63d-abdc-c7384ed93b34}

VirusBlast Object Recognized!
Type : RegValue
Data :
TAC Rating : 3
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{ccfb2b33-f4db-b63d-abdc-c7384ed93b34}
Value : AppID

Win32.Trojandownloader.Zlob Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\explorer\browser helper objects\{202a961f-23ae-42b1-9505-ffe3c818d717}

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 4
Objects found so far: 7


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 7


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking Cookie Object Recognized!
Type : IECache Entry
Data : khaliq@atdmt[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:khaliq@atdmt.com/
Expires : 9-12-2011 5:30:00 AM
LastSync : Hits:2
UseCount : 0
Hits : 2

Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 8



Deep scanning and examining files...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 8

Disk Scan Result for C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 8

Disk Scan Result for C:\DOCUME~1\khaliq\LOCALS~1\Temp\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 8


Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 8



MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw


MRU List Object Recognized!
Location: : S-1-5-21-73586283-842925246-1957994488-1003\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer



Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Win32.Trojandownloader.Zlob Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : vsenchancer.chl

Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 11

11:03:17 PM Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:05:18.97
Objects scanned:78680
Objects identified:7
Objects ignored:0
New critical objects:7
LS CalamityJane
Hi ,

Apologies for the late reply, we've been quite swamped in here as you can probably see.

I'm now subscribed to this topic so I will receive a notice from the board as soon as you reply, so I can be here much more quickly than it has taken to get to your new topic.

You are scanning in Smart mode and you really need to choose a full system scan in safe mode

Bur first, please first UPDATE your Ad-Aware program to the latest definition files: SE1R124 19.09.2006 as this had some new detections for some of the VirusBurst variants like the one you have.

Then run a Full System scan in SAFE MODE

You can usually do this by restarting your computer and continually tapping F8 until a menu appears. Highlight Safe Mode and hit enter.

How to start the computer in Safe mode
http://service1.symantec.com/SUPPORT/tsgen...src=sec_doc_nam

Remove any critical objects found.

Reboot back into normal mode. Post both that latest Ad-Aware scan log and let us know if that resolves the problem?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.