Hi,
I have also been getting uskyonline popups. I do have the latest release of AdAware, and also have done the WebUpdate for the newest database. I have read where you desire the log file, and shall post in here. unfortunately, it will take more than one post to do so...
Ad-Aware SE Build 1.06r1
Logfile Created on:Tuesday, November 07, 2006 1:23:55 AM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R130 06.11.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Adware.AdMedia(TAC index:10):4 total references
Adware.SystemProcess(TAC index:10):35 total references
AdvertBar(TAC index:5):1 total references
eUniverse(TAC index:10):2 total references
MRU List(TAC index:0):42 total references
Possible Browser Hijack attempt(TAC index:3):3 total references
Tracking Cookie(TAC index:3):42 total references
WebHancer(TAC index:9):1 total references
WinAntiVirusPro(TAC index:10):1 total references
WindUpdates(TAC index:8):3 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
11-7-2006 1:23:55 AM - Scan started. (Full System Scan)
MRU List Object Recognized!
Location: : C:\Documents and Settings\Thomas R. France\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office
MRU List Object Recognized!
Location: : C:\Documents and Settings\Thomas R. France\recent
Description : list of recently opened documents
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\adobe\adobe acrobat\5.0\avgeneral\crecentfiles
Description : list of recently used files in adobe acrobat
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\jasc\animation shop 2\fileopendialog
Description : list of recently opened files in jasc animation shop
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\jasc\animation shop 2\recent file list
Description : list of recently used files in jasc animation shop
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\jasc\animation shop 2\saveasdialog
Description : list of recently saved files in jasc animation shop
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\jasc\paint shop pro 6\recent file list
Description : list of recently used files in jasc paint shop pro
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\macromedia\flash 7\recent file list
Description : list of recently used files in macromedia flash
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\frontpage\explorer\frontpage explorer\recent file list
Description : list of recently used files in microsoft frontpage
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\frontpage\explorer\frontpage explorer\recent page list
Description : list of recently used pages in microsoft frontpage
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\frontpage\explorer\frontpage explorer\recent publish list
Description : list of recently published webs in microsoft frontpage
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\frontpage\explorer\frontpage explorer\recent web list
Description : list of recently used webs in microsoft frontpage
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\frontpage\explorer\frontpage explorer\recently created servers
Description : list of recently created servers in microsoft frontpage
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\frontpage\webs\opened
Description : list of recently opened webs in microsoft frontpage
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\internet explorer\main
Description : last save directory used in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\mediaplayer\player\recentfilelist
Description : list of recently used files in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\mediaplayer\player\recenturllist
Description : list of recently used web addresses in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\mediaplayer\player\settings
Description : last open directory used in jasc paint shop pro
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\mediaplayer\preferences
Description : last playlist index loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\microsoft management console\recent file list
Description : list of recent snap-ins used in the microsoft management console
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\office\9.0\common\open find\microsoft word\settings\open\file name mru
Description : list of recent documents opened by microsoft word
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\office\9.0\common\open find\microsoft word\settings\save as\file name mru
Description : list of recent documents saved by microsoft word
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\windows\currentversion\applets\paint\recent file list
Description : list of files recently opened using microsoft paint
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\windows\currentversion\applets\regedit
Description : last key accessed using the microsoft registry editor
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\windows\currentversion\applets\wordpad\recent file list
Description : list of recent files opened using wordpad
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\windows\currentversion\explorer\runmru
Description : mru list for items opened in start | run
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\nico mak computing\winzip\filemenu
Description : winzip recently used archives
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\realnetworks\realplayer\6.0\preferences
Description : list of recent skins in realplayer
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\realnetworks\realplayer\6.0\preferences
Description : list of recent clips in realplayer
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\realnetworks\realplayer\6.0\preferences
Description : last login time in realplayer
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 160
ThreadCreationTime : 11-7-2006 1:23:57 AM
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINNT\system32\
ProcessID : 184
ThreadCreationTime : 11-7-2006 1:24:07 AM
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINNT\system32\
ProcessID : 180
ThreadCreationTime : 11-7-2006 1:24:09 AM
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINNT\system32\
ProcessID : 232
ThreadCreationTime : 11-7-2006 1:24:13 AM
BasePriority : Normal
FileVersion : 5.00.2195.7035
ProductVersion : 5.00.2195.7035
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINNT\system32\
ProcessID : 244
ThreadCreationTime : 11-7-2006 1:24:13 AM
BasePriority : Normal
FileVersion : 5.00.2195.7011
ProductVersion : 5.00.2195.7011
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Executable and Server DLL (Export Version)
InternalName : lsasrv.dll and lsass.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : lsasrv.dll and lsass.exe
#:6 [smc.exe]
FilePath : C:\Program Files\Sygate\SPF\
ProcessID : 384
ThreadCreationTime : 11-7-2006 1:24:21 AM
BasePriority : Normal
FileVersion : 5.6.00.2808
ProductVersion : 5.6.00.2808
ProductName : Sygate® Security Agent and Personal Firewall
CompanyName : Sygate Technologies, Inc.
FileDescription : Sygate Agent Firewall
InternalName : Smc
LegalCopyright : Copyright © 1999 - 2004 Sygate Technologies, Inc. All rights reserved.
OriginalFilename : Smc.EXE
#:7 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 436
ThreadCreationTime : 11-7-2006 1:24:29 AM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:8 [lexbces.exe]
FilePath : C:\WINNT\system32\
ProcessID : 472
ThreadCreationTime : 11-7-2006 1:24:31 AM
BasePriority : Normal
FileVersion : 5,13,00,00
ProductVersion : 5,13,00,00
ProductName : MarkVision for Windows (32 bit)
CompanyName : Lexmark International, Inc.
FileDescription : LexBce Service
InternalName : LexBce Service
LegalCopyright : © 1993 - 2000 Lexmark International, Inc.
OriginalFilename : LexBceS.exe
#:9 [spoolsv.exe]
FilePath : C:\WINNT\system32\
ProcessID : 512
ThreadCreationTime : 11-7-2006 1:24:32 AM
BasePriority : Normal
FileVersion : 5.00.2195.7059
ProductVersion : 5.00.2195.7059
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolss.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : spoolss.exe
#:10 [avgamsvr.exe]
FilePath : C:\PROGRA~1\Grisoft\AVGFRE~1\
ProcessID : 548
ThreadCreationTime : 11-7-2006 1:24:35 AM
BasePriority : Normal
FileVersion : 7,1,0,365
ProductVersion : 7.1.0.365
ProductName : AVG Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Alert Manager
InternalName : avgamsvr
LegalCopyright : Copyright © 2005, GRISOFT, s.r.o.
OriginalFilename : avgamsvr.EXE
#:11 [avgupsvc.exe]
FilePath : C:\PROGRA~1\Grisoft\AVGFRE~1\
ProcessID : 592
ThreadCreationTime : 11-7-2006 1:24:38 AM
BasePriority : Normal
FileVersion : 7,1,0,349
ProductVersion : 7.1.0.349
ProductName : AVG 7.0 Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Update Service
InternalName : avgupsvc
LegalCopyright : Copyright © 2005, GRISOFT, s.r.o.
OriginalFilename : avgupdsvc.EXE
#:12 [svchost.exe]
FilePath : C:\WINNT\System32\
ProcessID : 616
ThreadCreationTime : 11-7-2006 1:24:38 AM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:13 [mdm.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\
ProcessID : 652
ThreadCreationTime : 11-7-2006 1:24:42 AM
BasePriority : Normal
FileVersion : 7.00.9466
ProductVersion : 7.00.9466
ProductName : Microsoft® Visual Studio .NET
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : mdm.exe
#:14 [regsvc.exe]
FilePath : C:\WINNT\system32\
ProcessID : 764
ThreadCreationTime : 11-7-2006 1:24:47 AM
BasePriority : Normal
FileVersion : 5.00.2195.6701
ProductVersion : 5.00.2195.6701
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Remote Registry Service
InternalName : regsvc
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : REGSVC.EXE
#:15 [mstask.exe]
FilePath : C:\WINNT\system32\
ProcessID : 736
ThreadCreationTime : 11-7-2006 1:24:48 AM
BasePriority : Normal
FileVersion : 4.71.2195.6972
ProductVersion : 4.71.2195.6972
ProductName : Microsoft® Windows® Task Scheduler
CompanyName : Microsoft Corporation
FileDescription : Task Scheduler Engine
InternalName : TaskScheduler
LegalCopyright : Copyright © Microsoft Corp. 1997
OriginalFilename : mstask.exe
#:16 [stisvc.exe]
FilePath : C:\WINNT\system32\
ProcessID : 836
ThreadCreationTime : 11-7-2006 1:24:49 AM
BasePriority : Normal
FileVersion : 5.00.2195.6656
ProductVersion : 5.00.2195.6656
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Still Image Devices Monitor
InternalName : STIMON
LegalCopyright : Copyright © Microsoft Corp. 1996-1997
OriginalFilename : STIMON.EXE
#:17 [winmgmt.exe]
FilePath : C:\WINNT\System32\WBEM\
ProcessID : 880
ThreadCreationTime : 11-7-2006 1:24:51 AM
BasePriority : Normal
FileVersion : 1.50.1085.0100
ProductVersion : 1.50.1085.0100
ProductName : Windows Management Instrumentation
CompanyName : Microsoft Corporation
FileDescription : Windows Management Instrumentation
InternalName : WINMGMT
LegalCopyright : Copyright © Microsoft Corp. 1995-1999
#:18 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 888
ThreadCreationTime : 11-7-2006 1:24:51 AM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:19 [explorer.exe]
FilePath : C:\WINNT\
ProcessID : 1092
ThreadCreationTime : 11-7-2006 1:37:12 AM
BasePriority : Normal
FileVersion : 5.00.3700.6690
ProductVersion : 5.00.3700.6690
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : EXPLORER.EXE
#:20 [xiwin32.exe]
FilePath : F:\Xitami\
ProcessID : 1032
ThreadCreationTime : 11-7-2006 1:37:23 AM
BasePriority : Idle
#:21 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 1028
ThreadCreationTime : 11-7-2006 1:37:24 AM
BasePriority : Normal
FileVersion : 0.1.0.3208
ProductVersion : 0.1.0.3208
ProductName : RealPlayer (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
LegalTrademarks : RealAudio is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe
#:22 [amoumain.exe]
FilePath : C:\PROGRA~1\AOpen\Mouse\
ProcessID : 696
ThreadCreationTime : 11-7-2006 1:37:24 AM
BasePriority : Normal
#:23 [wuauclt.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1116
ThreadCreationTime : 11-7-2006 1:37:26 AM
BasePriority : Normal
FileVersion : 5.8.0.2469 built by: lab01_n(wmbla)
ProductVersion : 5.8.0.2469
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Automatic Updates
InternalName : wuauclt.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : wuauclt.exe
#:24 [avgcc.exe]
FilePath : C:\PROGRA~1\Grisoft\AVGFRE~1\
ProcessID : 1316
ThreadCreationTime : 11-7-2006 1:37:30 AM
BasePriority : Normal
FileVersion : 7,1,0,406
ProductVersion : 7.1.0.406
ProductName : AVG Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Control Center
InternalName : AvgCC
LegalCopyright : Copyright © 2006, GRISOFT, s.r.o.
OriginalFilename : AvgCC.EXE
#:25 [avgemc.exe]
FilePath : C:\PROGRA~1\Grisoft\AVGFRE~1\
ProcessID : 1324
ThreadCreationTime : 11-7-2006 1:37:33 AM
BasePriority : Normal
FileVersion : 7,1,0,400
ProductVersion : 7.1.0.400
ProductName : AVG Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG E-Mail Scanner
InternalName : avgemc
LegalCopyright : Copyright © 2006, GRISOFT, s.r.o.
OriginalFilename : avgemc.exe
#:26 [block-checker.exe]
FilePath : C:\Program Files\Block Checker\
ProcessID : 1288
ThreadCreationTime : 11-7-2006 1:37:34 AM
BasePriority : Normal
FileVersion : 1.00.0026
ProductVersion : 1.00.0026
ProductName : block-checker
InternalName : block-checker
OriginalFilename : block-checker.exe
Adware.SystemProcess Object Recognized!
Type : Process
Data : block-checker.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\Program Files\Block Checker\
FileVersion : 1.00.0026
ProductVersion : 1.00.0026
ProductName : block-checker
InternalName : block-checker
OriginalFilename : block-checker.exe
Warning! "C:\Program Files\Block Checker\block-checker.exe"Process could not be terminated!
"C:\Program Files\Block Checker\block-checker.exe"Process terminated successfully
#:27 [hpgs2wnd.exe]
FilePath : C:\Program Files\Hewlett-Packard\HP Share-to-Web\
ProcessID : 1340
ThreadCreationTime : 11-7-2006 1:37:35 AM
BasePriority : Normal
FileVersion : 2,3,0,0\ 162
ProductVersion : 2,3,0,0\ 162
ProductName : Hewlett-Packard hpgs2wnd
CompanyName : Hewlett-Packard
FileDescription : hpgs2wnd
InternalName : hpgs2wnd
LegalCopyright : Copyright © 2001
OriginalFilename : hpgs2wnd.exe
#:28 [hpgs2wnf.exe]
FilePath : c:\Program Files\Hewlett-Packard\HP Share-to-Web\
ProcessID : 1380
ThreadCreationTime : 11-7-2006 1:37:39 AM
BasePriority : Normal
FileVersion : 2, 6, 0, 162
ProductVersion : 2, 6, 0, 162
ProductName : hpgs2wnf Module
FileDescription : hpgs2wnf Module
InternalName : hpgs2wnf
LegalCopyright : Copyright 2001
OriginalFilename : hpgs2wnf.EXE
#:29 [octeltpop.exe]
FilePath : C:\WINNT\
ProcessID : 1436
ThreadCreationTime : 11-7-2006 1:37:41 AM
BasePriority : Normal
FileVersion : 1.00
ProductVersion : 1.00
ProductName : popprog
InternalName : octeltpop
OriginalFilename : octeltpop.exe
#:30 [dwdsregt.exe]
FilePath : C:\winnt\system32\
ProcessID : 272
ThreadCreationTime : 11-7-2006 1:37:44 AM
BasePriority : Normal
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
LegalCopyright : © 2004
#:31 [ctfmon.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1468
ThreadCreationTime : 11-7-2006 1:37:46 AM
BasePriority : Normal
FileVersion : 1.00.2409.7 built by: Lab06_N
ProductVersion : 1.00.2409.7
ProductName : Microsoft® Windows NT® Operating System
CompanyName : Microsoft Corporation
FileDescription : Cicero Loader
InternalName : CICLOAD
LegalCopyright : Copyright © Microsoft Corporation. 1981-2001
OriginalFilename : CICLOAD.EXE
#:32 [acrotray.exe]
FilePath : C:\Program Files\Adobe\Acrobat 5.0\Distillr\
ProcessID : 1504
ThreadCreationTime : 11-7-2006 1:37:51 AM
BasePriority : Normal
FileVersion : 5, 0, 0, 0
ProductVersion : 5, 0, 0, 0
ProductName : AcroTray - Adobe Acrobat Distiller helper application.
CompanyName : Adobe Systems Inc.
FileDescription : AcroTray
InternalName : AcroTray
LegalCopyright : Copyright © 2001
OriginalFilename : AcroTray.exe
#:33 [webshotstray.exe]
FilePath : C:\Program Files\Webshots\
ProcessID : 1564
ThreadCreationTime : 11-7-2006 1:38:00 AM
BasePriority : Normal
FileVersion : 1.3.0.3826
ProductVersion : 1.3.0.3826
ProductName : Webshots Tray Application
CompanyName : The Webshots Corporation
FileDescription : Webshots Desktop Tray Application
InternalName : WEBSHOTSTRAY
LegalCopyright : Copyright © 1998
OriginalFilename : WEBSHOTSTRAY.EXE
#:34 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 1816
ThreadCreationTime : 11-7-2006 3:41:53 AM
BasePriority : Normal
FileVersion : 6.00.2800.1106
ProductVersion : 6.00.2800.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : IEXPLORE.EXE
#:35 [smartsync.exe]
FilePath : C:\PROGRA~1\PDODES~1\
ProcessID : 2148
ThreadCreationTime : 11-7-2006 6:49:41 AM
BasePriority : Normal
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
ProductName : DVSync
FileDescription : DVSync MFC Application
InternalName : DVSync
LegalCopyright : Copyright © 2000
OriginalFilename : DVSync.EXE
#:36 [tprowler.exe]
FilePath : C:\Program Files\Tomcat Web Services\Tomcat Prowler\
ProcessID : 1924
ThreadCreationTime : 11-7-2006 6:57:56 AM
BasePriority : Normal
FileVersion : 1.11.0052
ProductVersion : 1.11.0052
ProductName : Tomcat Prowler
CompanyName : Tomcat Web Services
InternalName : tprowler
OriginalFilename : tprowler.exe
#:37 [ad-aware.exe]
FilePath : C:\PROGRA~1\Lavasoft\AD-AWA~2\
ProcessID : 2068
ThreadCreationTime : 11-7-2006 7:09:44 AM
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 43
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Adware.AdMedia Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{0d3f3cf0-4060-4257-bf18-77ce00454146}
Adware.AdMedia Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{49217364-e570-4f9d-9cd2-62eb4780b2ee}
Adware.SystemProcess Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{c2eeb4fa-b6d6-41b9-9cfa-aba87f862bcb}
AdvertBar Object Recognized!
Type : Regkey
Data :
TAC Rating : 5
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-2000478354-920026266-1957994488-1000\software\adtools, inc.
Adware.SystemProcess Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\explorer\browser helper objects\{c2eeb4fa-b6d6-41b9-9cfa-aba87f862bcb}
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 5
Objects found so far: 48
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Possible Browser Hijack attempt : {E0CE16CB-741C-4B24-8D04-A817856E07F4} (http://cabs.media-motor.net/cabs/jenky.cab)
Possible Browser Hijack attempt Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Vulnerability
Comment : Possible Browser Hijack attempt : http://cabs.media-motor.net/cabs/jenky.cab
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E0CE16CB-741C-4B24-8D04-A817856E07F4}
Possible Browser Hijack attempt Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Vulnerability
Comment : Possible Browser Hijack attempt : http://cabs.media-motor.net/cabs/jenky.cab
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E0CE16CB-741C-4B24-8D04-A817856E07F4}
Value : Installer
Adware.SystemProcess Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment : "BlockChecker"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Run
Value : BlockChecker
Adware.SystemProcess Object Recognized!
Type : File
Data : block-checker.exe
TAC Rating : 10
Category : Malware
Comment :
Object : c:\program files\block checker\
FileVersion : 1.00.0026
ProductVersion : 1.00.0026
ProductName : block-checker
InternalName : block-checker
OriginalFilename : block-checker.exe
Adware.SystemProcess Object Recognized!
Type : RegValue
Data : C:\Program Files\Block Checker\block-checker.exe
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\Program Files\Block Checker\block-checker.exe
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 4
Objects found so far: 53
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@realmedia[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:41
Value : Cookie:thomas r. france@realmedia.com/
Expires : 12-31-2020 6:00:00 PM
LastSync : Hits:41
UseCount : 0
Hits : 41
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@hc2.humanclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:thomas r. france@hc2.humanclick.com/
Expires : 11-4-2007 2:49:22 AM
LastSync : Hits:3
UseCount : 0
Hits : 3
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@server.iad.liveperson[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:8
Value : Cookie:thomas r. france@server.iad.liveperson.net/
Expires : 10-31-2007 4:34:40 PM
LastSync : Hits:8
UseCount : 0
Hits : 8
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@clickbank[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:thomas r. france@clickbank.net/
Expires : 5-2-2007 12:14:38 AM
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@questionmarket[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:16
Value : Cookie:thomas r. france@questionmarket.com/
Expires : 12-26-2007 11:29:24 AM
LastSync : Hits:16
UseCount : 0
Hits : 16
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@adserve.webtoolcafe[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:thomas r. france@adserve.webtoolcafe.com/
Expires : 10-31-2007 3:44:16 PM
LastSync : Hits:2
UseCount : 0
Hits : 2
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@adrevolver[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:thomas r. france@adrevolver.com/
Expires : 11-2-2007 5:14:30 PM
LastSync : Hits:3
UseCount : 0
Hits : 3
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@overture[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:6
Value : Cookie:thomas r. france@overture.com/
Expires : 11-1-2016 2:54:34 AM
LastSync : Hits:6
UseCount : 0
Hits : 6
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@ads.pointroll[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:7
Value : Cookie:thomas r. france@ads.pointroll.com/
Expires : 12-31-2009 6:00:00 PM
LastSync : Hits:7
UseCount : 0
Hits : 7
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@tribalfusion[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:33
Value : Cookie:thomas r. france@tribalfusion.com/
Expires : 12-31-2037 6:00:00 PM
LastSync : Hits:33
UseCount : 0
Hits : 33
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@z1.adserver[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:10
Value : Cookie:thomas r. france@z1.adserver.com/
Expires : 11-6-2007 7:57:34 PM
LastSync : Hits:10
UseCount : 0
Hits : 10
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@as-us.falkag[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:67
Value : Cookie:thomas r. france@as-us.falkag.net/
Expires : 11-3-2007 12:21:40 AM
LastSync : Hits:67
UseCount : 0
Hits : 67
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@ads.addynamix[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:7
Value : Cookie:thomas r. france@ads.addynamix.com/
Expires : 11-5-2006 1:27:08 PM
LastSync : Hits:7
UseCount : 0
Hits : 7
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@bluestreak[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:thomas r. france@bluestreak.com/
Expires : 11-1-2016 8:27:08 AM
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@perf.overture[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:thomas r. france@perf.overture.com/
Expires : 10-30-2010 5:11:32 PM
LastSync : Hits:4
UseCount : 0
Hits : 4
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@2o7[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:20
Value : Cookie:thomas r. france@2o7.net/
Expires : 10-31-2011 11:09:10 PM
LastSync : Hits:20
UseCount : 0
Hits : 20
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@revenue[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:thomas r. france@revenue.net/
Expires : 6-9-2022 11:05:42 PM
LastSync : Hits:4
UseCount : 0
Hits : 4
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@zedo[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:43
Value : Cookie:thomas r. france@zedo.com/
Expires : 10-28-2016 5:34:32 PM
LastSync : Hits:43
UseCount : 0
Hits : 43
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@a.as-us.falkag[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:thomas r. france@a.as-us.falkag.net/
Expires : 11-16-2006 11:09:50 PM
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@qksrv[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:12
Value : Cookie:thomas r. france@qksrv.net/
Expires : 10-30-2011 5:11:32 PM
LastSync : Hits:12
UseCount : 0
Hits : 12
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@spylog[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:thomas r. france@spylog.com/
Expires : 5-2-2007 2:31:02 PM
LastSync : Hits:4
UseCount : 0
Hits : 4
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 21
Objects found so far: 74
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@2o7[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Thomas R. France\Local Settings\Temp\Cookies\thomas r. france@2o7[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : thomas r. france@adrevolver[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\Thomas R. France\Local Settings\Temp\Cookies\thomas r. france@adrevolver[1].txt
(Continued on next post)
Hi,
I have also been getting uskyonline popups. I do have the latest release of AdAware, and also have done the WebUpdate for the newest database. I have read where you desire the log file, and shall post in here. unfortunately, it will take more than one post to do so...
Ad-Aware SE Build 1.06r1
Logfile Created on:Tuesday, November 07, 2006 1:23:55 AM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R130 06.11.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Adware.AdMedia(TAC index:10):4 total references
Adware.SystemProcess(TAC index:10):35 total references
AdvertBar(TAC index:5):1 total references
eUniverse(TAC index:10):2 total references
MRU List(TAC index:0):42 total references
Possible Browser Hijack attempt(TAC index:3):3 total references
Tracking Cookie(TAC index:3):42 total references
WebHancer(TAC index:9):1 total references
WinAntiVirusPro(TAC index:10):1 total references
WindUpdates(TAC index:8):3 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
11-7-2006 1:23:55 AM - Scan started. (Full System Scan)
MRU List Object Recognized!
Location: : C:\Documents and Settings\Thomas R. France\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office
MRU List Object Recognized!
Location: : C:\Documents and Settings\Thomas R. France\recent
Description : list of recently opened documents
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\adobe\adobe acrobat\5.0\avgeneral\crecentfiles
Description : list of recently used files in adobe acrobat
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\jasc\animation shop 2\fileopendialog
Description : list of recently opened files in jasc animation shop
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\jasc\animation shop 2\recent file list
Description : list of recently used files in jasc animation shop
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\jasc\animation shop 2\saveasdialog
Description : list of recently saved files in jasc animation shop
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\jasc\paint shop pro 6\recent file list
Description : list of recently used files in jasc paint shop pro
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\macromedia\flash 7\recent file list
Description : list of recently used files in macromedia flash
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\frontpage\explorer\frontpage explorer\recent file list
Description : list of recently used files in microsoft frontpage
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\frontpage\explorer\frontpage explorer\recent page list
Description : list of recently used pages in microsoft frontpage
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\frontpage\explorer\frontpage explorer\recent publish list
Description : list of recently published webs in microsoft frontpage
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\frontpage\explorer\frontpage explorer\recent web list
Description : list of recently used webs in microsoft frontpage
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\frontpage\explorer\frontpage explorer\recently created servers
Description : list of recently created servers in microsoft frontpage
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\frontpage\webs\opened
Description : list of recently opened webs in microsoft frontpage
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\internet explorer\main
Description : last save directory used in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\mediaplayer\player\recentfilelist
Description : list of recently used files in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\mediaplayer\player\recenturllist
Description : list of recently used web addresses in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\mediaplayer\player\settings
Description : last open directory used in jasc paint shop pro
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\mediaplayer\preferences
Description : last playlist index loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\microsoft management console\recent file list
Description : list of recent snap-ins used in the microsoft management console
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\office\9.0\common\open find\microsoft word\settings\open\file name mru
Description : list of recent documents opened by microsoft word
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\office\9.0\common\open find\microsoft word\settings\save as\file name mru
Description : list of recent documents saved by microsoft word
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\windows\currentversion\applets\paint\recent file list
Description : list of files recently opened using microsoft paint
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\windows\currentversion\applets\regedit
Description : last key accessed using the microsoft registry editor
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\windows\currentversion\applets\wordpad\recent file list
Description : list of recent files opened using wordpad
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension
MRU List Object Recognized!
Location: : S-1-5-21-2000478354-920026266-1957994488-1000\software\microsoft\windows
