hi everyone,
i have the same problem as post #1 and i want to get rid of this adware here is my logfile for my ad-aware
Ad-Aware SE Build 1.06r1
Logfile Created on:Thursday, 28 September 2006 12:37:36 p.m.
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R124 19.09.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
DSSAgent(TAC index:8):1 total references
MRU List(TAC index:0):42 total references
Other(TAC index:5):1 total references
Tracking Cookie(TAC index:3):48 total references
Win32.Trojandownloader.Zlob(TAC index:10):5 total references
WinAntiVirusPro(TAC index:10):89 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
28-09-2006 12:37:36 p.m. - Scan started. (Full System Scan)
MRU List Object Recognized!
Location: : C:\Documents and Settings\USER\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office
MRU List Object Recognized!
Location: : C:\Documents and Settings\USER\recent
Description : list of recently opened documents
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\adobe\acrobat reader\5.0\avgeneral\crecentfiles
Description : list of recently used files in adobe reader
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\frontpage\explorer\frontpage explorer\recent file list
Description : list of recently used files in microsoft frontpage
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\frontpage\explorer\frontpage explorer\recent web list
Description : list of recently used webs in microsoft frontpage
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\mediaplayer\medialibraryui
Description : last selected node in the microsoft windows media player media library
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\mediaplayer\player\recentfilelist
Description : list of recently used files in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\mediaplayer\player\settings
Description : last save as directory used in jasc paint shop pro
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\mediaplayer\player\settings
Description : last open directory used in jasc paint shop pro
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\mediaplayer\preferences
Description : last cd record path used in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\mediaplayer\preferences
Description : last playlist index loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\microsoft management console\recent file list
Description : list of recent snap-ins used in the microsoft management console
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\office\10.0\clip organizer\search\last query
Description : last query in microsoft clip organizer
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\office\10.0\common\general
Description : list of recently used symbols in microsoft office
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\office\10.0\common\open find\microsoft powerpoint\settings\save as\file name mru
Description : list of recent documents saved by microsoft powerpoint
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\office\10.0\common\open find\microsoft word\settings\open\file name mru
Description : list of recent documents opened by microsoft word
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\office\10.0\common\open find\microsoft word\settings\save as\file name mru
Description : list of recent documents saved by microsoft word
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\office\10.0\common\search\last query
Description : last query in microsoft office
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\office\10.0\excel\recent files
Description : list of recent files used by microsoft excel
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\office\10.0\powerpoint\recent file list
Description : list of recent files used by microsoft powerpoint
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\office\10.0\powerpoint\recent templates
Description : list of recent templates used by microsoft powerpoint
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\office\10.0\powerpoint\recent typeface list
Description : list of recently used typefaces in microsoft powerpoint
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\office\10.0\powerpoint\recenttemplatelist
Description : list of recent templates used by microsoft powerpoint
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\office\10.0\publisher\recent file list
Description : list of recent files used by microsoft publisher
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\search assistant\acmru
Description : list of recent search terms used with the search assistant
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\windows\currentversion\applets\paint\recent file list
Description : list of files recently opened using microsoft paint
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\windows\currentversion\applets\regedit
Description : last key accessed using the microsoft registry editor
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\windows\currentversion\explorer\runmru
Description : mru list for items opened in start | run
MRU List Object Recognized!
Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
MRU List Object Recognized!
Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
MRU List Object Recognized!
Location: : S-1-5-21-160225841-1163644386-2469798093-1006\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 552
ThreadCreationTime : 27-09-2006 11:59:42 p.m.
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 628
ThreadCreationTime : 27-09-2006 11:59:44 p.m.
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 652
ThreadCreationTime : 27-09-2006 11:59:45 p.m.
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 696
ThreadCreationTime : 27-09-2006 11:59:45 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 708
ThreadCreationTime : 27-09-2006 11:59:45 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 848
ThreadCreationTime : 27-09-2006 11:59:46 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 928
ThreadCreationTime : 27-09-2006 11:59:47 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 968
ThreadCreationTime : 27-09-2006 11:59:47 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1064
ThreadCreationTime : 27-09-2006 11:59:48 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1164
ThreadCreationTime : 27-09-2006 11:59:48 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:11 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1324
ThreadCreationTime : 27-09-2006 11:59:50 p.m.
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:12 [avgamsvr.exe]
FilePath : C:\PROGRA~1\Grisoft\AVGFRE~1\
ProcessID : 1484
ThreadCreationTime : 27-09-2006 11:59:51 p.m.
BasePriority : Normal
FileVersion : 7,1,0,307
ProductVersion : 7.1.0.307
ProductName : AVG Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Alert Manager
InternalName : avgamsvr
LegalCopyright : Copyright © 2005, GRISOFT, s.r.o.
OriginalFilename : avgamsvr.EXE
#:13 [avgupsvc.exe]
FilePath : C:\PROGRA~1\Grisoft\AVGFRE~1\
ProcessID : 1500
ThreadCreationTime : 27-09-2006 11:59:52 p.m.
BasePriority : Normal
FileVersion : 7,1,0,285
ProductVersion : 7.1.0.285
ProductName : AVG 7.0 Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Update Service
InternalName : avgupsvc
LegalCopyright : Copyright © 2004, GRISOFT, s.r.o.
OriginalFilename : avgupdsvc.EXE
#:14 [rrpcsb.exe]
FilePath : C:\Program Files\IBM\IBM Rapid Restore Ultra\
ProcessID : 1560
ThreadCreationTime : 27-09-2006 11:59:52 p.m.
BasePriority : Normal
FileVersion : 4,0,0,4026
ProductVersion : 4,0,0,4026
ProductName : rrpcsb Module
FileDescription : rrpcsb Module
InternalName : rrpcsb
LegalCopyright : Copyright 2002
OriginalFilename : rrpcsb.EXE
#:15 [mdm.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7Debug\
ProcessID : 1596
ThreadCreationTime : 27-09-2006 11:59:52 p.m.
BasePriority : Normal
FileVersion : 7.00.9064.9150
ProductVersion : 7.00.9064.9150
ProductName : Microsoft Development Environment
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : Copyright © Microsoft Corp. 1997-2000
OriginalFilename : mdm.exe
#:16 [smagent.exe]
FilePath : C:\Program Files\Analog Devices\SoundMAX\
ProcessID : 1704
ThreadCreationTime : 27-09-2006 11:59:52 p.m.
BasePriority : Normal
FileVersion : 3, 2, 6, 0
ProductVersion : 3, 2, 6, 0
ProductName : SoundMAX service agent
CompanyName : Analog Devices, Inc.
FileDescription : SoundMAX service agent component
InternalName : SMAgent
LegalCopyright : Copyright © 2002
OriginalFilename : SMAgent.exe
#:17 [wdfmgr.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1760
ThreadCreationTime : 27-09-2006 11:59:53 p.m.
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe
#:18 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 1872
ThreadCreationTime : 27-09-2006 11:59:54 p.m.
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
WinAntiVirusPro Object Recognized!
Type : Process
Data : winpgi.dll
TAC Rating : 10
Category : Malware
Comment :
Object : C:\Program Files\WinAntiVirus Pro 2006\
FileVersion : 1, 1, 2, 0
ProductVersion : 2, 0, 149, 0
ProductName : WinAntiVirus 2006 Pro
CompanyName : WinSoftware, Inc.
FileDescription : WinAntiVirus 2006 Pro Intermediate Layer
InternalName : winpgi.dll
LegalCopyright : © 2006 WinSoftware, Inc. All rights reserved.
OriginalFilename : winpgi.dll
#:19 [isamonitor.exe]
FilePath : C:\Program Files\WinMediaCodec\
ProcessID : 204
ThreadCreationTime : 27-09-2006 11:59:57 p.m.
BasePriority : Normal
#:20 [pmsngr.exe]
FilePath : C:\Program Files\WinMediaCodec\
ProcessID : 212
ThreadCreationTime : 27-09-2006 11:59:57 p.m.
BasePriority : Normal
Win32.Trojandownloader.Zlob Object Recognized!
Type : Process
Data : pmsngr.exe
TAC Rating : 10
Category : Malware
Comment : pmsngr.exe.dmp
Object : C:\Program Files\WinMediaCodec\
Warning! Win32.Trojandownloader.Zlob Object found in memory(C:\Program Files\WinMediaCodec\pmsngr.exe)
"C:\Program Files\WinMediaCodec\pmsngr.exe"Process terminated successfully
"C:\Program Files\WinMediaCodec\pmsngr.exe"Process terminated successfully
#:21 [pptd40nt.exe]
FilePath : C:\Program Files\ScanSoft\PaperPort\
ProcessID : 228
ThreadCreationTime : 27-09-2006 11:59:57 p.m.
BasePriority : Normal
FileVersion : 9.0
ProductVersion : 9.0
ProductName : PaperPort
CompanyName : ScanSoft, Inc.
FileDescription : PaperPort Print to Desktop for NT
InternalName : PPTD40NT
LegalCopyright : Copyright © 1993-2004 ScanSoft, Inc.
OriginalFilename : PPTD40NT.EXE
#:22 [jusched.exe]
FilePath : C:\Program Files\Java\jre1.5.0_06\bin\
ProcessID : 324
ThreadCreationTime : 27-09-2006 11:59:58 p.m.
BasePriority : Normal
#:23 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ProcessID : 348
ThreadCreationTime : 27-09-2006 11:59:58 p.m.
BasePriority : Normal
FileVersion : 7.0.4
ProductVersion : QuickTime 7.0.4
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
FileDescription : QuickTime Task
InternalName : QuickTime Task
LegalCopyright : Copyright Apple Computer, Inc. 1989-2006
OriginalFilename : QTTask.exe
#:24 [pmmon.exe]
FilePath : C:\Program Files\WinMediaCodec\
ProcessID : 356
ThreadCreationTime : 27-09-2006 11:59:58 p.m.
BasePriority : Normal
#:25 [isamini.exe]
FilePath : C:\Program Files\WinMediaCodec\
ProcessID : 364
ThreadCreationTime : 27-09-2006 11:59:58 p.m.
BasePriority : Normal
#:26 [ituneshelper.exe]
FilePath : C:\Program Files\iTunes\
ProcessID : 368
ThreadCreationTime : 27-09-2006 11:59:58 p.m.
BasePriority : Normal
FileVersion : 6.0.4.2
ProductVersion : 6.0.4.2
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2006 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe
#:27 [winav.exe]
FilePath : C:\Program Files\WinAntiVirus Pro 2006\
ProcessID : 392
ThreadCreationTime : 27-09-2006 11:59:58 p.m.
BasePriority : Normal
FileVersion : 2,1,237,0
ProductVersion : 2,1,237,0
ProductName : WinAntiVirus Pro 2006
CompanyName : WinSoftware, Inc.
FileDescription : WinAntiVirus Pro 2006
InternalName : WinAntiVirusPro2006.exe
LegalCopyright : © 2006 WinSoftware Inc. All rights reserved.
OriginalFilename : WinAntiVirusPro2006.exe
WinAntiVirusPro Object Recognized!
Type : Process
Data : WinAV.exe
TAC Rating : 10
Category : Malware
Comment : winav.exe.dmp
Object : C:\Program Files\WinAntiVirus Pro 2006\
FileVersion : 2,1,237,0
ProductVersion : 2,1,237,0
ProductName : WinAntiVirus Pro 2006
CompanyName : WinSoftware, Inc.
FileDescription : WinAntiVirus Pro 2006
InternalName : WinAntiVirusPro2006.exe
LegalCopyright : © 2006 WinSoftware Inc. All rights reserved.
OriginalFilename : WinAntiVirusPro2006.exe
Warning! WinAntiVirusPro Object found in memory(C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe)
Warning! "C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe"Process could not be terminated!
WinAntiVirusPro Object Recognized!
Type : Process
Data : avkernel.dll
TAC Rating : 10
Category : Malware
Comment :
Object : C:\Program Files\WinAntiVirus Pro 2006\
FileVersion : 2, 0, 20, 1
ProductVersion : 2, 0, 143, 0
ProductName : WinAntiVirus Pro 2006
CompanyName : WinSoftware, Ltd.
FileDescription : avkernel.dll
InternalName : avkernel
LegalCopyright : © 2005 WinSoftware. All rights reserved.
OriginalFilename : avkernel.dll
WinAntiVirusPro Object Recognized!
Type : Process
Data : asmngr.dll
TAC Rating : 10
Category : Malware
Comment :
Object : C:\Program Files\WinAntiVirus Pro 2006\
FileVersion : 1, 0, 0, 0
ProductVersion : 2, 0, 147, 0
ProductName : WinAntiVirus 2006 Pro
CompanyName : WinSoftware, Inc.
FileDescription : WinAntiVirus 2006 Pro Assistant
InternalName : AVAssistant
LegalCopyright : © 2006 WinSoftware, Inc. All rights reserved.
OriginalFilename : ASMngr.dll
WinAntiVirusPro Object Recognized!
Type : Process
Data : rpt.dll
TAC Rating : 10
Category : Malware
Comment :
Object : C:\Program Files\WinAntiVirus Pro 2006\
#:28 [memoptimizer.exe]
FilePath : C:\Program Files\TuneUp Utilities 2004\
ProcessID : 400
ThreadCreationTime : 27-09-2006 11:59:58 p.m.
BasePriority : Normal
FileVersion : 1.0.0.193
ProductVersion : 4.0.0.0
ProductName : TuneUp Utilities
CompanyName : TuneUp Software GmbH
FileDescription : TuneUp MemOptimizer
LegalCopyright : © 1996-2003 TuneUp Software GmbH
LegalTrademarks : TuneUp Utilities
#:29 [ipodservice.exe]
FilePath : C:\Program Files\iPod\bin\
ProcessID : 432
ThreadCreationTime : 28-09-2006
BasePriority : Normal
FileVersion : 6.0.4.2
ProductVersion : 6.0.4.2
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2006 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iPodService.exe
#:30 [ctfmon.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 440
ThreadCreationTime : 28-09-2006
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE
#:31 [pareto_as.exe]
FilePath : C:\Program Files\ParetoLogic\Anti-Spyware\
ProcessID : 448
ThreadCreationTime : 28-09-2006
BasePriority : Normal
FileVersion : 5, 0, 35, 2571
ProductVersion : 5.0.1.1
ProductName : Paretologic Anti-Spyware Module
CompanyName : ParetoLogic Inc.
#:32 [fwsvc.exe]
FilePath : C:\Program Files\WinAntiVirus Pro 2006\
ProcessID : 1000
ThreadCreationTime : 28-09-2006 12:00:07 a.m.
BasePriority : Normal
FileVersion : 1, 0, 12, 0
ProductVersion : 1, 0, 12, 0
ProductName : WinAntivirus Pro 2006
CompanyName : WinSoftware, Ltd.
FileDescription : WinAntiVirus Pro 2006 Firewall service
InternalName : WFSvc.exe
LegalCopyright : © 2005 WinSoftware. All rights reserved.
OriginalFilename : WFSvc.exe
WinAntiVirusPro Object Recognized!
Type : Process
Data : FWSvc.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\Program Files\WinAntiVirus Pro 2006\
FileVersion : 1, 0, 12, 0
ProductVersion : 1, 0, 12, 0
ProductName : WinAntivirus Pro 2006
CompanyName : WinSoftware, Ltd.
FileDescription : WinAntiVirus Pro 2006 Firewall service
InternalName : WFSvc.exe
LegalCopyright : © 2005 WinSoftware. All rights reserved.
OriginalFilename : WFSvc.exe
Warning! "C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe"Process could not be terminated!
WinAntiVirusPro Object Recognized!
Type : Process
Data : RulSrv.dll
TAC Rating : 10
Category : Malware
Comment :
Object : C:\Program Files\WinAntiVirus Pro 2006\
FileVersion : 1, 0, 12, 0
ProductVersion : 1, 0, 12, 0
ProductName : WinAntiVirus Pro 2006
CompanyName : WinSoftware, Ltd.
FileDescription : WinAntiVirus Pro 2006 Firewall service
InternalName : RulSrv.dll
LegalCopyright : © 2005 WinSoftware. All rights reserved.
OriginalFilename : RulSrv.dll
Warning! "C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe"Process could not be terminated!
#:33 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 3044
ThreadCreationTime : 28-09-2006 12:06:03 a.m.
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : IEXPLORE.EXE
Win32.Trojandownloader.Zlob Object Recognized!
Type : Process
Data : isaddon.dll
TAC Rating : 10
Category : Malware
Comment : isaddon.dll.dmp
Object : C:\Program Files\WinMediaCodec\
Warning! Win32.Trojandownloader.Zlob Object found in memory(C:\Program Files\WinMediaCodec\isaddon.dll)
#:34 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 1744
ThreadCreationTime : 28-09-2006 12:32:04 a.m.
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 3
Objects found so far: 51
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Win32.Trojandownloader.Zlob Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{202a961f-23ae-42b1-9505-ffe3c818d717}
WinAntiVirusPro Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : appid\{367a86a5-d048-4785-86be-4e2706aafdd9}
WinAntiVirusPro Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{1ac5c88a-dea7-462b-a232-04af5ca42e7e}
WinAntiVirusPro Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{1ac5c88a-dea7-462b-a232-04af5ca42e7e}
Value : AppID
WinAntiVirusPro Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{2178f3fb-2560-458f-bdee-631e2fe0dfe4}
WinAntiVirusPro Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{2178f3fb-2560-458f-bdee-631e2fe0dfe4}
Value : AppID
WinAntiVirusPro Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{723d54c7-7483-4eb8-8eed-ce5b2aea534d}
WinAntiVirusPro Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{b2a3156e-3332-4b47-af5a-5b121503514f}
WinAntiVirusPro Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{b5141620-c2b2-4d95-9f0f-134d99c87ab0}
WinAntiVirusPro Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{b5141620-c2b2-4d95-9f0f-134d99c87ab0}
Value : AppID
WinAntiVirusPro Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{0b9a27eb-125f-4f3e-a35c-2769c47a1442}
WinAntiVirusPro Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{e18b69d0-7e9e-4c6e-bdd8-879a1fff7123}
WinAntiVirusPro Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{1234890a-5e6e-4867-8136-ca6f1456b235}
WinAntiVirusPro Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{2bc32ef8-bb73-4099-bb2e-0f2951b3e276}
WinAntiVirusPro Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{367a86a5-d048-4785-86be-4e2706aafdd9}
WinAntiVirusPro Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{732b6533-7f78-4c47-9c01-2979ba0829b9}
DSSAgent Object Recognized!
Type : Regkey
Data :
TAC Rating : 8
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\broderbund software\dss
Win32.Trojandownloader.Zlob Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\explorer\browser helper objects\{202a961f-23ae-42b1-9505-ffe3c818d717}
WinAntiVirusPro Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\explorer\browser helper objects\{2178f3fb-2560-458f-bdee-631e2fe0dfe4}
WinAntiVirusPro Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\explorer\browser helper objects\{b5141620-c2b2-4d95-9f0f-134d99c87ab0}
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 20
Objects found so far: 71
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 71
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@statcounter[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:163
Value : Cookie:user@statcounter.com/
Expires : 27-09-2011 9:58:00 a.m.
LastSync : Hits:163
UseCount : 0
Hits : 163
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@serving-sys[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:176
Value : Cookie:user@serving-sys.com/
Expires : 1-01-2038 10:00:00 a.m.
LastSync : Hits:176
UseCount : 0
Hits : 176
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@ads.rampidads[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:user@ads.rampidads.com/
Expires : 9-06-2006 9:57:32 p.m.
LastSync : Hits:2
UseCount : 0
Hits : 2
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@estat[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:user@estat.com/
Expires : 31-05-2016 9:29:46 p.m.
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@trafficmp[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:22
Value : Cookie:user@trafficmp.com/
Expires : 2-06-2007 10:12:16 p.m.
LastSync : Hits:22
UseCount : 0
Hits : 22
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@qsrch[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:user@qsrch.com/
Expires : 4-07-2006 9:27:00 a.m.
LastSync : Hits:4
UseCount : 0
Hits : 4
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@2o7[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:163
Value : Cookie:user@2o7.net/
Expires : 13-08-2011 7:58:30 p.m.
LastSync : Hits:163
UseCount : 0
Hits : 163
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@adserver[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:user@ads.revsci.net/adserver
Expires : 26-08-2038 10:10:38 a.m.
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@adtech[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:user@adtech.de/
Expires : 31-05-2016 5:17:34 p.m.
LastSync : Hits:4
UseCount : 0
Hits : 4
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@trafic[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:user@trafic.ro/
Expires : 12-01-2037 2:00:00 a.m.
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@apmebf[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:user@apmebf.com/
Expires : 2-06-2011 8:42:08 p.m.
LastSync : Hits:2
UseCount : 0
Hits : 2
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@revenue[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:16
Value : Cookie:user@revenue.net/
Expires : 10-06-2022 5:05:42 p.m.
LastSync : Hits:16
UseCount : 0
Hits : 16
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@weborama[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:user@weborama.fr/
Expires : 2-06-2008 9:29:46 p.m.
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@perf.overture[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:user@perf.overture.com/
Expires : 1-06-2010 9:08:04 p.m.
LastSync : Hits:4
UseCount : 0
Hits : 4
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@tribalfusion[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:73
Value : Cookie:user@tribalfusion.com/
Expires : 1-01-2038 12:00:00 p.m.
LastSync : Hits:73
UseCount : 0
Hits : 73
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@tripod[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:9
Value : Cookie:user@tripod.com/
Expires : 2-06-2007 10:02:52 p.m.
LastSync : Hits:9
UseCount : 0
Hits : 9
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@questionmarket[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:161
Value : Cookie:user@questionmarket.com/
Expires : 18-11-2007 2:12:44 a.m.
LastSync : Hits:161
UseCount : 0
Hits : 161
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : user@ads.tripod.lycos[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:user@ads.tripod.lycos.de/
Expires : 12-06-2006 12:00:40 p.m.
LastSync : Hits:4
UseCount : 0
Hits : 4
i will continue on my next post