Tracking Cookie Object Recognized!
Type : IECache Entry
Data : tu anh@ads.addynamix[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:5
Value : Cookie:tu anh@ads.addynamix.com/
Expires : 10/9/2006 8:54:10 PM
LastSync : Hits:5
UseCount : 0
Hits : 5
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : tu anh@www.globaladvertisingservices[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:71
Value : Cookie:tu anh@www.globaladvertisingservices.info/
Expires : 10/21/2006 3:07:50 PM
LastSync : Hits:71
UseCount : 0
Hits : 71
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : tu anh@2o7[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:tu anh@2o7.net/
Expires : 10/12/2011 9:50:36 PM
LastSync : Hits:3
UseCount : 0
Hits : 3
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : tu anh@as-us.falkag[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:192
Value : Cookie:tu anh@as-us.falkag.net/
Expires : 10/13/2007 6:09:20 PM
LastSync : Hits:192
UseCount : 0
Hits : 192
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : tu anh@server.iad.liveperson[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:9
Value : Cookie:tu anh@server.iad.liveperson.net/
Expires : 10/8/2007 11:08:54 AM
LastSync : Hits:9
UseCount : 0
Hits : 9
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : tu anh@tribalfusion[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:9
Value : Cookie:tu anh@tribalfusion.com/
Expires : 12/31/2037 8:00:00 PM
LastSync : Hits:9
UseCount : 0
Hits : 9
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : tu anh@pmads.valuead[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:tu anh@pmads.valuead.com/
Expires : 12/31/2020 8:00:00 PM
LastSync : Hits:4
UseCount : 0
Hits : 4
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : tu anh@ehg-lowermybills.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:tu anh@ehg-lowermybills.hitbox.com/
Expires : 10/14/2007 1:15:06 AM
LastSync : Hits:3
UseCount : 0
Hits : 3
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : tu anh@mediaplex[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:8
Value : Cookie:tu anh@mediaplex.com/
Expires : 6/21/2009 8:00:00 PM
LastSync : Hits:8
UseCount : 0
Hits : 8
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : tu anh@perf.overture[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:7
Value : Cookie:tu anh@perf.overture.com/
Expires : 10/6/2010 6:15:40 PM
LastSync : Hits:7
UseCount : 0
Hits : 7
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 35
Objects found so far: 81
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Adware.DollarRevenue Object Recognized!
Type : File
Data : deskbar.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\
Adware.DollarRevenue Object Recognized!
Type : File
Data : deskbar.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\Program Files\Deskbar\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Win32.Trojan.Downloader Object Recognized!
Type : File
Data : A0050807.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP218\
FileVersion : 1.00.0022
ProductVersion : 1.00.0022
ProductName : tapeG22
InternalName : tapeG22
OriginalFilename : tapeG22.exe
Win32.Trojan.Downloader Object Recognized!
Type : File
Data : A0050808.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP218\
FileVersion : 1.00.0022
ProductVersion : 1.00.0022
ProductName : tapeG22
InternalName : tapeG22
OriginalFilename : tapeG22.exe
Win32.Trojan.Downloader Object Recognized!
Type : File
Data : A0050813.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP218\
FileVersion : 1.00.0022
ProductVersion : 1.00.0022
ProductName : tapeG22
InternalName : tapeG22
OriginalFilename : tapeG22.exe
Win32.Trojan.Downloader Object Recognized!
Type : File
Data : A0050872.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP218\
FileVersion : 1.00.0008
ProductVersion : 1.00.0008
ProductName : Luiz08
InternalName : Luiz08
OriginalFilename : Luiz08.exe
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0050911.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP218\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Adware.ToolbarDeepDive Object Recognized!
Type : File
Data : A0050914.exe
TAC Rating : 8
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP218\
Win32.Trojan.Downloader Object Recognized!
Type : File
Data : A0051917.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP219\
FileVersion : 1.00.0008
ProductVersion : 1.00.0008
ProductName : Luiz08
InternalName : Luiz08
OriginalFilename : Luiz08.exe
Win32.Trojan.Downloader Object Recognized!
Type : File
Data : A0051973.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP220\
FileVersion : 1.00.0008
ProductVersion : 1.00.0008
ProductName : Luiz08
InternalName : Luiz08
OriginalFilename : Luiz08.exe
Win32.Trojan.Downloader Object Recognized!
Type : File
Data : A0052029.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP221\
FileVersion : 1.00.0008
ProductVersion : 1.00.0008
ProductName : Luiz08
InternalName : Luiz08
OriginalFilename : Luiz08.exe
Win32.Trojan.Downloader Object Recognized!
Type : File
Data : A0052083.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP221\
FileVersion : 1.00.0008
ProductVersion : 1.00.0008
ProductName : Luiz08
InternalName : Luiz08
OriginalFilename : Luiz08.exe
Adware.CasClient Object Recognized!
Type : File
Data : A0052124.exe
TAC Rating : 5
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP221\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0052180.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP222\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0052245.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP224\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0052303.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP226\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0059585.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP226\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Win32.Trojan.Downloader Object Recognized!
Type : File
Data : A0060657.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP226\
FileVersion : 1.00.0008
ProductVersion : 1.00.0008
ProductName : Luiz08
InternalName : Luiz08
OriginalFilename : Luiz08.exe
WinFixer Object Recognized!
Type : File
Data : A0060729.dll
TAC Rating : 10
Category : Misc
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP226\
FileVersion : 0.1.4.0
ProductVersion : 0.1.4.0
ProductName : CRXML
CompanyName : WinSofware
FileDescription : CRXML component
InternalName : CryptoXML.dll
LegalCopyright : © 2005 WinSofware. All rights reserved.
OriginalFilename : CryptoXML.dll
WinFixer Object Recognized!
Type : File
Data : A0060730.exe
TAC Rating : 10
Category : Misc
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP226\
FileVersion : 1.0.1.0
ProductVersion : 1.0.1.0
WinAntiVirusPro Object Recognized!
Type : File
Data : A0060733.sys
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP226\
FileVersion : 1.0.2.0
ProductVersion : 1.0.2.0
CompanyName : WinSoftware Ltd
FileDescription : File Creation Filter Driver
LegalCopyright : Copyright © WinSoftware Ltd 2005
OriginalFilename : wff.sys
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0060815.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP226\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0060816.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP226\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0060853.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP227\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0060854.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP227\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Win32.Trojan.Downloader Object Recognized!
Type : File
Data : A0060861.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP228\
FileVersion : 1.00.0029
ProductVersion : 1.00.0029
ProductName : Ggees29
InternalName : Ggees29
OriginalFilename : Ggees29.exe
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0060869.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP228\
Adware.Look2Me Object Recognized!
Type : File
Data : A0060888.dll
TAC Rating : 7
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP229\
Adware.Look2Me Object Recognized!
Type : File
Data : A0060893.dll
TAC Rating : 7
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP229\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0060899.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP229\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0061026.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP230\
Adware.Look2Me Object Recognized!
Type : File
Data : A0061049.dll
TAC Rating : 7
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP231\
Adware.Look2Me Object Recognized!
Type : File
Data : A0061050.dll
TAC Rating : 7
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP231\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0061057.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP231\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0062056.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP231\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0062076.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP232\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0062118.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP234\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0062119.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP234\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0062143.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP235\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0062144.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP235\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Win32.Trojan.Downloader Object Recognized!
Type : File
Data : A0062159.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP235\
FileVersion : 1.00.0008
ProductVersion : 1.00.0008
ProductName : Luiz08
InternalName : Luiz08
OriginalFilename : Luiz08.exe
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0062168.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP235\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0062169.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP235\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Adware.Look2Me Object Recognized!
Type : File
Data : A0062176.exe
TAC Rating : 7
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP235\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0062179.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP236\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0062197.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP236\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0063229.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP236\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0063270.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP236\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0064292.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP236\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0064355.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP237\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0064356.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP237\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0065373.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP238\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0065374.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP238\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0065388.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP238\
FileVersion : 1.00.0253
ProductVersion : 1.00.0253
ProductName : Project1
CompanyName : de5
InternalName : Project1
OriginalFilename : Project1.exe
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0065394.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP238\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0065401.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP238\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0065436.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{490DF1D0-950A-4279-B26B-1FC6A2A5A243}\RP238\
FileVersion : 1.00.0183
ProductVersion : 1.00.0183
ProductName : Project1
CompanyName : fdslj reditf8eru8turdtreduj54tr8u548
InternalName : kybrdff_18_a
OriginalFilename : kybrdff_18_a.exe
Adware.Look2Me Object Recognized!
Type : File
Data : icont.exe
TAC Rating : 7
Category : Adware
Comment :
Object : C:\WINDOWS\
IEHijacker.ZestyFind Object Recognized!
Type : File
Data : iconu.exe
TAC Rating : 6
Category : Malware
Comment :
Object : C:\WINDOWS\
Adware.Look2Me Object Recognized!
Type : File
Data : AppWrap[1].exe
TAC Rating : 7
Category : Adware
Comment :
Object : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8167WTYR\
IEHijacker.ZestyFind Object Recognized!
Type : File
Data : AppWrap[2].exe
TAC Rating : 6
Category : Malware
Comment :
Object : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\CLU3GX6V\
Adware.Look2Me Object Recognized!
Type : File
Data : n28olcl31fq.dll
TAC Rating : 7
Category : Adware
Comment :
Object : C:\WINDOWS\system32\
IEHijacker.ZestyFind Object Recognized!
Type : File
Data : bw2.com
TAC Rating : 6
Category : Malware
Comment :
Object : C:\WINDOWS\Temp\
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 144
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
0 entries scanned.
New critical objects:0
Objects found so far: 144
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WebHancer Object Recognized!
Type : Folder
TAC Rating : 9
Category : Data Miner
Comment : WebHancer
Object : C:\Program Files\webHancer
WebHancer Object Recognized!
Type : File
Data : webhdll.dll
TAC Rating : 9
Category : Data Miner
Comment :
Object : C:\Program Files\webhancer\programs\
FileVersion : 3.9.2
ProductVersion : 3.9.2
ProductName : webHancer Customer Companion
CompanyName : webHancer Corporation
FileDescription : webHancer Winsock2 SPI
InternalName : webhdll
LegalCopyright : Copyright © 1999-2006 webHancer Corporation
OriginalFilename : webhdll.dll
Win32.Trojan.Downloader Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\system
Win32.Trojan.Downloader Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\system\sysuid
Win32.Trojan.Downloader Object Recognized!
Type : File
Data : guard.tmp
TAC Rating : 10
Category : Malware
Comment :
Object : c:\windows\system32\
WinFixer Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Misc
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\currentcontrolset\enum\root\legacy_df_kmd
WinFixer Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Misc
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\controlset001\enum\root\legacy_df_kmd
Other Object Recognized!
Type : File
Data : DESKBAR.EXE-38CDF805.pf
TAC Rating : 7
Category : Malware
Comment :
Object : C:\WINDOWS\prefetch\
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 8
Objects found so far: 152
2:44:06 AM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:16:40.172
Objects scanned:130343
Objects identified:135
Objects ignored:0
New critical objects:135
........
And here's the hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 2:46:45 AM, on 10/14/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe
C:\Program Files\WinTV\Ir.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\jlwbv.exe
F2 - REG:system.ini: UserInit=userinit.exe,uhefhbp.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [xload] "C:\WINDOWS\s.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [qbv76fee] RUNDLL32.EXE w185cd5e.dll,n 00476fea00000003185cd5e
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [sys0286595543-1] C:\WINDOWS\sys0286595543-1.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: BlackBerry Desktop Redirector.lnk = C:\Program Files\Research In Motion\BlackBerry\Redirector.exe
O4 - Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.freeemotes.com
O15 - Trusted Zone: http://*.systemdoctor.com
O15 - Trusted IP range:
http://202.67.220.225O15 - Trusted IP range:
http://59.148.220.121O15 - Trusted IP range:
http://62.4.84.53O15 - Trusted IP range:
http://82.98.235.58O15 - Trusted IP range:
http://85.12.25.90O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://appldnld.m7z.net/qtinstall.info.app...meInstaller.exeO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://seasonalife.spaces.msn.com//PhotoUpload/MsnPUpld.cabO16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} -
http://awbeta.net-nucleus.com/FIX/WinATS.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\WINDOWS\lsass.exe (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe