|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
Auestioner
Guest IP: 12.240.*.*
|
Posted: Tue Nov 04, 2003 11:18 pm Post subject: Pop-ups and other things please help! (hi-jack and Spyware) |
|
|
Hi, I'm a newbie and I could really use some help. My computer has been going crazy recently. It is totally swarmed by pop-ups all the time. Way more pop-ups are coming up than ever before, and they're poping up even when I'm not going to any web pages and even when internet explorer is not open. Also when going to websites, a little window often pops up that is titled "matched in url". These windows just have a word or two and an "OK" button. How do I get rid of all this crap? Thanks.
|
|
| Back to top |
|
 |
phoenix22
Welcome back our old Site Admin Premium Member
 Joined: Mar 08, 2002 Posts: 4661 Location: APO SF96383
|
Posted: Wed Nov 05, 2003 12:01 am Post subject: |
|
|
first you need to download and run Hi jack this then post the log back here before you delete anything...... _________________ 101st Abn Div. (AirAssault) "Rendezvous With Destiny!" "Night Stalkers/Phoenix Flight" For Buddy...who lived it! Whiskey for my men and beer for my horses! H.A.L.O!, 5th Grp., MACV-SOG, 160th AVN Grp., VFW
|
|
| Back to top |
|
 |
CalamityJane
Security Expert Microsoft MVP
 Joined: Oct 05, 2002 Posts: 4004
|
Posted: Wed Nov 05, 2003 12:37 am Post subject: |
|
|
HiJackThis is a good tool, but it sure is a lot easier to help you if you have first downloaded and run one of the two following (free) Programs to eliminate any know spyware/adware issues which is usually the cause of these problems:
First Download get the updates (If you don't know how, ask back here...but these programs must be updated to be effective). Then run a scan and let them fix what they find.
And the best advice after that....download the HijackThis Phoenix22 has posted above to see if there is anything left to clean up (there usually is).
If you are a novice with Antispyware programs, Adaware is the most user friendly and I would recommend you start there
Adaware
http://www.lavasoft.de/software/adaware/
Adaware settings tips:
http://www.lavasoftsupport.com/index.php?showtopic=9240
Spybot Search and Destroy
http://www.safer-networking.org/
If you have then run an Antispyware scan then the HJT tool is next:
Download *Hijack This!* http://www.tomcoyote.org/hjt/
Unzip, doubleclick HijackThis.exe, and hit "Scan".
When the scan is finished, the "Scan" button will change into a "Save Log" button. Press that and copy & paste its contents here. Most of what it lists will be harmless or even essential, don't fix anything yet. Someone will be along to tell you what steps to take after you post the content of the scan results.
|
|
| Back to top |
|
 |
Auestioner
Guest IP: 12.240.*.*
|
Posted: Wed Nov 05, 2003 2:14 am Post subject: |
|
|
Thanks for all the advice, I'm going to d/l those programs. What is "get the updates"? How do I d/l that?
|
|
| Back to top |
|
 |
Auestioner
Guest IP: 12.240.*.*
|
Posted: Wed Nov 05, 2003 3:26 am Post subject: |
|
|
OK, I got the Ad-aware program and ran a scan. I'm sorry but I'm really new at this - what do I do once I've scanned it? It gives me the scanning results with this huge list of things with the option to quarantine them. What do I do? Thanks again for the help.
|
|
| Back to top |
|
 |
Jamming
Colonel
 Premium Member
Joined: Jun 22, 2002 Posts: 1874
|
Posted: Wed Nov 05, 2003 10:45 am Post subject: |
|
|
Well post the log file here and we can give you some advice on what to remove/quarantine.
|
|
| Back to top |
|
 |
!Mariner
Colonel
 Premium Member
Joined: Aug 25, 2003 Posts: 1914
|
Posted: Wed Nov 05, 2003 5:58 pm Post subject: |
|
|
Get updates simply means bringing the program right up to date so that it is most effective.
With Ad-aware, open the program. In the bottom right hand corner, you will see "Check for update now". Click on this after first connecting to the net.
If there are any updates you will be told and they will download and install automatically.
Once updated, run Ad-aware again and follow the instructions given above.
|
|
| Back to top |
|
 |
phoenix22
Welcome back our old Site Admin Premium Member
 Joined: Mar 08, 2002 Posts: 4661 Location: APO SF96383
|
Posted: Wed Nov 05, 2003 6:06 pm Post subject: |
|
|
| CalamityJane wrote: | HiJackThis is a good tool, but it sure is a lot easier to help you if you have first downloaded and run one of the two following (free) Programs to eliminate any know spyware/adware issues which is usually the cause of these problems:
First Download get the updates (If you don't know how, ask back here...but these programs must be updated to be effective). Then run a scan and let them fix what they find.
And the best advice after that....download the HijackThis Phoenix22 has posted above to see if there is anything left to clean up (there usually is).
If you are a novice with Antispyware programs, Adaware is the most user friendly and I would recommend you start there
Adaware
http://www.lavasoft.de/software/adaware/
Adaware settings tips:
http://www.lavasoftsupport.com/index.php?showtopic=9240
Spybot Search and Destroy
http://www.safer-networking.org/
If you have then run an Antispyware scan then the HJT tool is next:
Download *Hijack This!* http://www.tomcoyote.org/hjt/
Unzip, doubleclick HijackThis.exe, and hit "Scan".
When the scan is finished, the "Scan" button will change into a "Save Log" button. Press that and copy & paste its contents here. Most of what it lists will be harmless or even essential, don't fix anything yet. Someone will be along to tell you what steps to take after you post the content of the scan results. |
see what I mean Jane??
thanks......i meant to add all those in the first place......but I got so swamped..I forgot to comeback an edit this........
Oh btw, Mariner .........thanks for all the help......you can have the nightshift....as long as you pay yer toll  _________________ 101st Abn Div. (AirAssault) "Rendezvous With Destiny!" "Night Stalkers/Phoenix Flight" For Buddy...who lived it! Whiskey for my men and beer for my horses! H.A.L.O!, 5th Grp., MACV-SOG, 160th AVN Grp., VFW
|
|
| Back to top |
|
 |
!Mariner
Colonel
 Premium Member
Joined: Aug 25, 2003 Posts: 1914
|
Posted: Wed Nov 05, 2003 6:24 pm Post subject: |
|
|
OT..........thought you and the Highway Hogger had hopped the Huey out of here.......ain't payin' no toll, no way. no how, no sirreee......
|
|
| Back to top |
|
 |
CalamityJane
Security Expert Microsoft MVP
 Joined: Oct 05, 2002 Posts: 4004
|
|
| Back to top |
|
 |
Auestioner
Guest IP: 12.240.*.*
|
Posted: Wed Nov 05, 2003 11:29 pm Post subject: |
|
|
OK, thanks for writing the tutorial, it was very helpful. Here's my logfile, what do I quarantine?
Lavasoft Ad-aware Personal Build 6.181
Logfile created on :Wednesday, November 05, 2003 3:10:58 PM
Created with Ad-aware Personal, free for private use.
Using reference-file :01R217 08.09.2003
______________________________________________________
Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
11-5-2003 3:10:58 PM - Scan started. (Custom mode)
Listing running processes
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 11-5-2003 10:56:53 PM
BasePriority : Normal
#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ThreadCreationTime : 11-5-2003 10:56:55 PM
BasePriority : High
#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 11-5-2003 10:56:56 PM
BasePriority : Normal
FileSize : 99 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Microsoft
Created on : 8/18/2001 12:00:00 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 8/18/2001 12:00:00 PM
#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 11-5-2003 10:56:56 PM
BasePriority : Normal
FileSize : 11 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
OriginalFilename : lsass.exe
ProductName : Microsoft
Created on : 8/18/2001 12:00:00 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 8/29/2002 10:41:26 AM
#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 11-5-2003 10:56:56 PM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 8/18/2001 12:00:00 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 8/18/2001 12:00:00 PM
#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-5-2003 10:56:56 PM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 8/18/2001 12:00:00 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 8/18/2001 12:00:00 PM
#:7 [explorer.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 11-5-2003 10:56:58 PM
BasePriority : Normal
FileSize : 980 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft
Created on : 9/15/2002 1:37:22 AM
Last accessed : 11/5/2003 10:58:08 PM
Last modified : 8/29/2002 10:41:24 AM
#:8 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 11-5-2003 10:56:59 PM
BasePriority : Normal
FileSize : 50 KB
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
OriginalFilename : spoolsv.exe
ProductName : Microsoft
Created on : 8/18/2001 12:00:00 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 8/18/2001 12:00:00 PM
#:9 [wkufind.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\Works Shared\
ThreadCreationTime : 11-5-2003 10:57:01 PM
BasePriority : Normal
FileSize : 28 KB
FileVersion : 6.00.3215.0
ProductVersion : 6.00.3215.0
Copyright : Copyright
CompanyName : Microsoft
FileDescription : Microsoft
InternalName : WkUFind
OriginalFilename : WkUFind.exe
ProductName : Microsoft
Created on : 8/17/2001 4:41:58 AM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 8/17/2001 4:41:58 AM
#:10 [dellmmkb.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 11-5-2003 10:57:01 PM
BasePriority : Normal
FileSize : 160 KB
FileVersion : 2.0.0
ProductVersion : 2.0.0
Copyright : Copyright
CompanyName : Netropa Corp.
FileDescription : Netropa(tm) Hot Key
InternalName : Netropa Hot Key
OriginalFilename : nhk.exe
ProductName : Netropa Hot Key
Created on : 2/1/2002 4:00:33 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 9/23/2001 1:14:48 PM
#:11 [directcd.exe]
FilePath : C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\
ThreadCreationTime : 11-5-2003 10:57:01 PM
BasePriority : Normal
FileSize : 640 KB
FileVersion : 5.10 (105)
ProductVersion : 5.10 (105)
Copyright : Copyright
CompanyName : Roxio
FileDescription : DirectCD Application
InternalName : DirectCD
OriginalFilename : Directcd.exe
ProductName : DirectCD
Created on : 9/4/2001 9:31:50 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 9/4/2001 9:31:50 PM
#:12 [navapw32.exe]
FilePath : C:\PROGRA~1\NORTON~1\
ThreadCreationTime : 11-5-2003 10:57:01 PM
BasePriority : Normal
FileSize : 73 KB
FileVersion : 8.07.17
ProductVersion : 8.07.17
Copyright : Copyright (c) 2000-2002 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Agent
InternalName : NAVAPW32
OriginalFilename : NAVAPW32.EXE
ProductName : Norton AntiVirus
Created on : 2/1/2003 9:47:12 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 2/27/2002 7:27:58 PM
#:13 [hpztsb04.exe]
FilePath : C:\WINDOWS\System32\spool\drivers\w32x86\3\
ThreadCreationTime : 11-5-2003 10:57:01 PM
BasePriority : Normal
FileSize : 192 KB
FileVersion : 2,76,0,0
ProductVersion : 2,76,0,0
Copyright : Copyright (c) Hewlett-Packard Company 1999-2001
CompanyName : HP
ProductName : HP DeskJet
Created on : 4/9/2002 2:18:17 AM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 9/12/2001 2:00:56 PM
#:14 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ThreadCreationTime : 11-5-2003 10:57:01 PM
BasePriority : Normal
FileSize : 76 KB
FileVersion : 6.0.2
ProductVersion : QuickTime 6.0.2
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
OriginalFilename : QTTask.exe
ProductName : QuickTime
Created on : 8/27/2002 6:55:12 AM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 12/23/2002 7:43:20 AM
#:15 [save.exe]
FilePath : C:\PROGRA~1\Save\
ThreadCreationTime : 11-5-2003 10:57:01 PM
BasePriority : Normal
FileSize : 274 KB
FileVersion : 2, 5, 3, 1
ProductVersion : 2, 5, 3, 1
Copyright : Copyright 2001
CompanyName : WhenU.com, Inc.
FileDescription : Save!
InternalName : WhenUSave
OriginalFilename : Save.exe
ProductName : Save!
Created on : 8/24/2003 10:24:56 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 8/6/2003 1:16:32 AM
#:16 [bpc.exe]
FilePath : C:\Program Files\RVP\
ThreadCreationTime : 11-5-2003 10:57:02 PM
BasePriority : Normal
FileSize : 65 KB
Created on : 10/28/2003 8:06:15 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 10/28/2003 8:06:15 PM
BroadCastPC Object recognized!
Type : Process
Data : bpc.exe
Object : C:\Program Files\RVP\
FileSize : 65 KB
Created on : 10/28/2003 8:06:15 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 10/28/2003 8:06:15 PM
Warning! BroadCastPC object found in memory(bpc.exe)
"bpc.exe"Process terminated successfully.
#:17 [prmt.exe]
FilePath : C:\PROGRA~1\NETRAT~1\Premeter\
ThreadCreationTime : 11-5-2003 10:57:02 PM
BasePriority : Normal
FileSize : 228 KB
FileVersion : 1.0.5.0r
ProductVersion : 1.0.5.0r
Copyright : Copyright (c) 2002 NetRatings.
CompanyName : NetRatings
FileDescription : Premeter
OriginalFilename : prmt.exe
ProductName : Premeter
Created on : 5/28/2003 3:46:33 AM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 6/3/2003 6:56:38 PM
#:18 [whagent.exe]
FilePath : C:\Program Files\webHancer\Programs\
ThreadCreationTime : 11-5-2003 10:57:02 PM
BasePriority : Normal
FileSize : 168 KB
FileVersion : 3.1.0
ProductVersion : 3.1.0
Copyright : Copyright
CompanyName : webHancer Corporation
FileDescription : webHancer Customer Companion
InternalName : whAgent
OriginalFilename : whAgent.exe
ProductName : webHancer Customer Companion
Created on : 7/24/2003 5:58:14 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 7/24/2003 5:58:14 PM
#:19 [rundll32.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-5-2003 10:57:02 PM
BasePriority : Normal
FileSize : 31 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
OriginalFilename : RUNDLL.EXE
ProductName : Microsoft
Created on : 8/18/2001 12:00:00 PM
Last accessed : 11/5/2003 10:57:23 PM
Last modified : 8/18/2001 12:00:00 PM
#:20 [msmsgs.exe]
FilePath : C:\Program Files\Messenger\
ThreadCreationTime : 11-5-2003 10:57:02 PM
BasePriority : Normal
FileSize : 1456 KB
FileVersion : 4.7.2009
ProductVersion : Version 4.7
Copyright : Copyright (c) Microsoft Corporation 1997-2003
CompanyName : Microsoft Corporation
FileDescription : Messenger
InternalName : msmsgs
OriginalFilename : msmsgs.exe
ProductName : Messenger
Created on : 4/15/2003 2:30:14 AM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 4/15/2003 2:30:14 AM
#:21 [weather.exe]
FilePath : C:\Program Files\AWS\WeatherBug\
ThreadCreationTime : 11-5-2003 10:57:02 PM
BasePriority : Normal
FileSize : 816 KB
FileVersion : 5, 0, 0, 4
ProductVersion : 5, 0, 0, 4
Copyright : Copyright
CompanyName : AWS Convergence Technologies, Inc.
FileDescription : WeatherBug
InternalName : Desktop Weather
OriginalFilename : WeatherBug.exe
ProductName : AWS, Inc.WeatherBug
Created on : 2/22/2003 11:09:24 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 1/22/2003 7:10:36 PM
#:22 [winservn.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-5-2003 10:57:02 PM
BasePriority : Normal
FileSize : 22 KB
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
Copyright : Copyright (C) 2002
FileDescription : sear1 MFC Application
InternalName : sear1
OriginalFilename : sear1.EXE
ProductName : sear1 Application
Created on : 5/17/2003 9:15:14 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 5/17/2003 9:15:14 PM
Warning! PurityScan object found in memory(C:\WINDOWS\System32\winservn.exe)
PurityScan Object recognized!
Type : Process
Data : winservn.exe
Object : C:\WINDOWS\System32\
FileSize : 22 KB
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
Copyright : Copyright (C) 2002
FileDescription : sear1 MFC Application
InternalName : sear1
OriginalFilename : sear1.EXE
ProductName : sear1 Application
Created on : 5/17/2003 9:15:14 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 5/17/2003 9:15:14 PM
"winservn.exe"Process terminated successfully.
#:23 [aim.exe]
FilePath : C:\Program Files\AIM\
ThreadCreationTime : 11-5-2003 10:57:02 PM
BasePriority : Normal
FileSize : 60 KB
FileVersion : 5.2.3292
ProductVersion : 5.2.3292
Copyright : Copyright
CompanyName : America Online, Inc.
FileDescription : AOL Instant Messenger
InternalName : AIM
OriginalFilename : AIM.EXE
ProductName : AOL Instant Messenger
Created on : 8/20/2003 4:10:49 AM
Last accessed : 11/5/2003 10:57:21 PM
Last modified : 8/1/2003 3:31:06 PM
#:24 [omgtray.exe]
FilePath : C:\Program Files\Sony\OpenMG Jukebox\
ThreadCreationTime : 11-5-2003 10:57:10 PM
BasePriority : Normal
FileSize : 64 KB
FileVersion : 2.2.00.09190
ProductVersion : 2.2.00
Copyright : Copyright 1999,2000,2001 Sony Corp.
CompanyName : Sony Corporation
FileDescription : OpenMG Jukebox Startup
InternalName : Omgtray
OriginalFilename : Omgtray.EXE
ProductName : OpenMG Jukebox Startup
Created on : 12/25/2002 8:34:38 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 4/20/2002 1:12:18 AM
#:25 [nhksrv.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 11-5-2003 10:57:21 PM
BasePriority : Normal
FileSize : 28 KB
Created on : 1/1/1980 6:00:00 AM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 8/6/2001 7:41:48 PM
#:26 [packethsvc.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-5-2003 10:57:21 PM
BasePriority : Normal
FileSize : 63 KB
FileVersion : 6, 0, 0, 6
ProductVersion : 6, 0, 0, 6
Copyright : Copyright (C) America Online, Inc. 1999 - 2001
CompanyName : America Online, Inc.
FileDescription : Virtual Adapter Service
InternalName : Virtual Adapter Service
OriginalFilename : PackethSvc.exe
ProductName : America Online
Created on : 2/1/2002 4:01:05 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 8/10/2001 12:18:30 AM
#:27 [svchost.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 11-5-2003 10:57:22 PM
BasePriority : Normal
FileSize : 128 KB
Created on : 10/23/2003 3:07:07 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 10/23/2003 3:07:07 PM
#:28 [navapsvc.exe]
FilePath : C:\Program Files\Norton AntiVirus\
ThreadCreationTime : 11-5-2003 10:57:22 PM
BasePriority : Normal
FileSize : 113 KB
FileVersion : 8.07.17
ProductVersion : 8.07.17
Copyright : Copyright (c) 2000-2002 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
OriginalFilename : NAVAPSVC.EXE
ProductName : Norton AntiVirus
Created on : 2/1/2003 9:47:12 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 2/27/2002 7:29:26 PM
#:29 [nvsvc32.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-5-2003 10:57:22 PM
BasePriority : Normal
FileSize : 56 KB
FileVersion : 5.13.01.1520
ProductVersion : 5.13.01.1520
Copyright : Copyright
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA Driver Helper Service, Version 15.20
InternalName : NVSVC
OriginalFilename : nvsvc32.exe
ProductName : NVIDIA Driver Helper Service, Version 15.20
Created on : 1/1/1980 6:00:00 AM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 8/31/2001 5:56:00 AM
#:30 [osd.exe]
FilePath : C:\Program Files\Netropa\
ThreadCreationTime : 11-5-2003 10:57:25 PM
BasePriority : Normal
FileSize : 88 KB
FileVersion : 2.02
ProductVersion : 2.02
Copyright : Copyright
CompanyName : Netropa Corp.
FileDescription : Netropa(r) Onscreen Display
InternalName : OSD
OriginalFilename : osd.exe
ProductName : Onscreen Display
Created on : 2/1/2002 4:00:33 PM
Last accessed : 11/5/2003 10:56:53 PM
Last modified : 9/22/2001 8:28:38 PM
#:31 [sptisrv.exe]
FilePath : C:\Program Files\Common Files\Sony Shared\AVLib\
ThreadCreationTime : 11-5-2003 10:57:47 PM
BasePriority : Normal
FileSize : 64 KB
FileVersion : 3.0.03.03111
ProductVersion : 3.0.03.03110
Copyright : Copyright 1999,2000,2001 Sony Corp.
CompanyName : Sony Corporation
FileDescription : SPTISRV Module
InternalName : SPTISRV
OriginalFilename : SPTISRV.EXE
ProductName : SPTISRV Module
Created on : 12/25/2002 8:33:17 PM
Last accessed : 11/5/2003 10:57:47 PM
Last modified : 3/13/2002 6:59:02 PM
#:32 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ThreadCreationTime : 11-5-2003 10:58:22 PM
BasePriority : Normal
FileSize : 89 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
OriginalFilename : IEXPLORE.EXE
ProductName : Microsoft
Created on : 9/15/2002 1:41:30 AM
Last accessed : 11/5/2003 10:58:26 PM
Last modified : 8/29/2002 10:41:26 AM
#:33 [msnmsgr.exe]
FilePath : C:\Program Files\MSN Messenger\
ThreadCreationTime : 11-5-2003 10:58:54 PM
BasePriority : Normal
FileSize : 2130 KB
FileVersion : 5.0.0543
ProductVersion : Version 5.0
Copyright : Copyright (c) Microsoft Corporation 1997-2002
CompanyName : Microsoft Corporation
FileDescription : Messenger
InternalName : msnmsgr
OriginalFilename : msnmsgr.exe
ProductName : Messenger
Created on : 12/6/2002 1:24:54 AM
Last accessed : 11/5/2003 10:58:54 PM
Last modified : 12/6/2002 1:24:54 AM
#:34 [omgjbox.exe]
FilePath : C:\Program Files\Sony\OpenMG Jukebox\
ThreadCreationTime : 11-5-2003 11:01:37 PM
BasePriority : Normal
FileSize : 2268 KB
FileVersion : 2.2.09.04100
ProductVersion : 2.2.09
Copyright : Copyright 1999,2000,2001,2002 Sony Corp.
CompanyName : Sony Corporation
FileDescription : OpenMG Jukebox Application
InternalName : Omgjbox
OriginalFilename : Omgjbox.exe
ProductName : OpenMG Jukebox
Created on : 12/25/2002 8:34:37 PM
Last accessed : 11/5/2003 11:01:37 PM
Last modified : 7/3/2002 9:30:36 PM
#:35 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-aware 6\
ThreadCreationTime : 11-5-2003 11:07:22 PM
BasePriority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 11/5/2003 2:21:43 AM
Last accessed : 11/5/2003 11:07:22 PM
Last modified : 7/13/2003 6:00:20 AM
Memory scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 2
Objects found so far: 2
Started registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
FlashTrack Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : BRedObj.BRedObj
FlashTrack Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : BRedObj.BRedObj.1
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{014DA6C1-189F-421a-88CD-07CFE51CFF10}
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{014DA6C2-189F-421a-88CD-07CFE51CFF10}
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{014DA6C3-189F-421a-88CD-07CFE51CFF10}
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{014DA6C5-189F-421a-88CD-07CFE51CFF10}
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{014DA6C7-189F-421a-88CD-07CFE51CFF10}
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10}
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{014DA6CB-189F-421a-88CD-07CFE51CFF10}
SideStep Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{0837121A-6472-43BD-8A40-D9221FF1C4CE}
ShopNav Hijacker Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{14b3d246-6274-40b5-8d50-6c2ade2ab29b}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{2119776A-F1AD-4FCD-9548-F1E1C615350C}
Gator Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{21FFB6C0-0DA1-11D5-A9D5-00500413153C}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{41EC560D-9371-4923-B0AD-F6A9504D3AA0}
New.Net Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}
FlashTrack Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{665ACD90-4541-4836-9FE4-062386BB8F05}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{6ACD11BD-4CA0-4283-A8D8-872B9BA289B6}
WebHancer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{c900b400-cdfe-11d3-976a-00e02913a9e0}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{EA9AC01F-FA16-4C68-8F59-08C6D864DF0C}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{F63C5B10-B709-4DF5-BA27-B90102AD313B}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Defender.ScanCore
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Defender.ScanGUi
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Directory\shellex\ContextMenuHandlers\EAC_VirusScanner
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{014DA6C4-189F-421A-88CD-07CFE51CFF10}
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{014DA6C6-189F-421A-88CD-07CFE51CFF10}
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{014DA6CA-189F-421A-88CD-07CFE51CFF10}
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{014DA6CC-189F-421A-88CD-07CFE51CFF10}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{615AD67A-25F6-4E0C-AD06-E29F4A90DABA}
FlashTrack Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{6E83AE1C-F69C-4AED-AF98-D23C24C6FA4B}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{BB80B457-F3F6-4992-A0C3-A128D58C7FB2}
WebHancer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{C89435B0-CDFE-11D3-976A-00E02913A9E0}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{D951B1F4-7399-426A-A925-D2C41FCF2002}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{E6A8EE26-1FAD-431C-99D6-8DBA1E25CD72}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{EA8A2B2C-1E59-4038-B9E0-669B32C51D2D}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{F073D8A5-C4AC-4DDC-9204-B1C032B4BD72}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : MSEaid.Gd\GLSID
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : MySearchToolBar.NetscapeShutdown
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : MySearchToolBar.NetscapeShutdown.1
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : MySearchToolBar.NetscapeStartup
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : MySearchToolBar.NetscapeStartup.1
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : MySearchToolBar.SettingsPlugin
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : MySearchToolBar.SettingsPlugin.1
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Oodlzx.AxOOdlz
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Oodlzx.AxOOdlz.1
ShopNav Hijacker Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : SNHlprObj.SNHlprObj
ShopNav Hijacker Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : SNHlprObj.SNHlprObj.1
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Acceleration Software International Corporation
Other Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : SOFTWARE\Acceleration Software International Corporation
Cydoor Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : software\cydoor
Cydoor Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Cydoor
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\eAnthology
FlashTrack Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Flt
Gator Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Gator.com
Gator Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\GatorTest
SideStep Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Extensions\{3E230861-5C87-11D3-A1C6-00105A1B41B8}
Ebates MoneyMaker Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Extensions\{7F241C00-DAB6-11d5-AAA8-0001028DF1BC}
Alexa Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Ebates MoneyMaker Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\MenuExt\Ebates
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{014DA6C1-189F-421a-88CD-07CFE51CFF10}
ShopNav Hijacker Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{14b3d246-6274-40b5-8d50-6c2ade2ab29b}
New.Net Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}
FlashTrack Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{665ACD90-4541-4836-9FE4-062386BB8F05}
WebHancer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{c900b400-cdfe-11d3-976a-00e02913a9e0}
Ebates MoneyMaker Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ebatesver2.xml
Other Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ETraffic
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\My Search Uninstall
New.Net Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\New.net
NetRatings Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Premeter
BroadCastPC Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RVP
SaveNow Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Uninstall\SaveNow
SideStep Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SideStep
WebHancer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Uninstall\webHancer Agent
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\MySearch
My-Way Speedbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\MyWay
NetRatings Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\NetRatings
New.Net Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\New.net
PurityScan Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\PurityScan
BroadCastPC Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\RVP
SideStep Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\SideStep
ShopNav Hijacker Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Srng
SahAgent Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\VGroup
WebHancer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\webHancer
SaveNow Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\WhenU
SaveNow Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\WhenUSave
New.Net Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Tldctl2.URLLink
New.Net Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Tldctl2.URLLink.1
MySearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : TypeLib\{014DA6C0-189F-421A-88CD-07CFE51CFF10}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : TypeLib\{3E072AB7-3CDA-4536-8AFD-56B0FE6846B4}
FlashTrack Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : TypeLib\{7955EA20-E0D6-4A77-88B6-120674D979EA}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : TypeLib\{963DD0FF-4836-4DE4-9590-D7EFE8F62F8D}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Typelib\{B897BE6A-0729-4D3B-BBDA-377A296AE446}
WebHancer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : TypeLib\{C8CB3870-CDFE-11D3-976A-00E02913A9E0}
eAcceleration Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Webcelerator.WebcBrowserHelper
WebHancer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : WhIeHelperObj.WhIeHelperObj
WebHancer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : WhIeHelperObj.WhIeHelperObj.1
SaveNow Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : WUSN.1
Ebates MoneyMaker Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Extensions\CmdMapping
Value : {7F241C00-DAB6-11d5-AAA8-0001028DF1BC}
MySearch Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Internet Explorer\Toolbar
Value : {014DA6C9-189F-421a-88CD-07CFE51CFF10}
BroadCastPC Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\RUN
Value : RVP
Ebates MoneyMaker Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value : EbatesMoeMoneyMaker
NetRatings Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value : Premeter
New.Net Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value : New.net Startup
PurityScan Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Windows\CurrentVersion\Run
Value : ContentService
SaveNow Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Run
Value : WhenUSave
ShopNav Hijacker Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value : srng
WebHancer Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Run
Value : webHancer Agent
eAcceleration Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Value : {46D570D9-71C8-44E5-A76C-AADFE94442CA}
eAcceleration Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Value : {BB83FD23-AC96-472D-8AA2-7D8560A61D1A}
MySearch Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\Netscape\Netscape Navigator\Automation Shutdown
Value : MySearchToolBar.NetscapeShutdown.1
MySearch Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\Netscape\Netscape Navigator\Automation Startup
Value : MySearchToolBar.NetscapeStartup.1
Registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 110
Objects found so far: 112
Started deep registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Page.2020search.com
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://search.2020search.com/9885/search/redir.php?cid=shnv9885PCID=00000000000000490138&s="
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "http://search.2020search.com/9885/search/redir.php?cid=shnv9885PCID=00000000000000490138&s="
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Page.2020search.com
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://search.2020search.com/9885/search/redir.php?cid=shnv9885PCID=00000000000000490138&s="
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "http://search.2020search.com/9885/search/redir.php?cid=shnv9885PCID=00000000000000490138&s="
Possible Browser Hijack attempt Object recognized!
Type : RegKey
Data : PrevDefaultSearchURL="http://search.2020search.com/9885/search/redir.php?cid=shnv9885PCID=00000000000000490138&s="
Rootkey : HKEY_CURRENT_USER
Object : Software\Srng
Deep registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 3
Objects found so far: 115
Deep scanning and examining files (C
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
SahAgent Object recognized!
Type : File
Data : sahagent.log
Object : C:\
FileSize : 3 KB
Created on : 5/17/2003 9:15:27 PM
Last accessed : 11/5/2003 11:12:37 PM
Last modified : 10/18/2003 6:56:49 AM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@advertising[1].txt
Object : C:\Documents and Settings\Alex Enscoe\Cookies\
Created on : 11/5/2003 10:59:09 PM
Last accessed : 11/5/2003 11:05:14 PM
Last modified : 11/5/2003 11:05:14 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@atdmt[2].txt
Object : C:\Documents and Settings\Alex Enscoe\Cookies\
Created on : 11/5/2003 10:58:52 PM
Last accessed : 11/5/2003 10:58:52 PM
Last modified : 11/5/2003 10:58:52 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@clickagents[1].txt
Object : C:\Documents and Settings\Alex Enscoe\Cookies\
Created on : 11/5/2003 7:16:55 AM
Last accessed : 11/5/2003 11:12:41 PM
Last modified : 11/5/2003 7:16:55 AM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@doubleclick[1].txt
Object : C:\Documents and Settings\Alex Enscoe\Cookies\
Created on : 11/5/2003 7:19:35 AM
Last accessed : 11/5/2003 11:12:41 PM
Last modified : 11/5/2003 7:19:35 AM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@fastclick[2].txt
Object : C:\Documents and Settings\Alex Enscoe\Cookies\
Created on : 11/5/2003 7:16:51 AM
Last accessed : 11/5/2003 11:02:08 PM
Last modified : 11/5/2003 11:02:08 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@internetfuel[1].txt
Object : C:\Documents and Settings\Alex Enscoe\Cookies\
Created on : 11/5/2003 11:07:19 PM
Last accessed : 11/5/2003 11:07:19 PM
Last modified : 11/5/2003 11:07:19 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@mediaplex[1].txt
Object : C:\Documents and Settings\Alex Enscoe\Cookies\
Created on : 11/5/2003 10:58:38 PM
Last accessed : 11/5/2003 10:58:38 PM
Last modified : 11/5/2003 10:58:38 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@mediatrack.revenue[1].txt
Object : C:\Documents and Settings\Alex Enscoe\Cookies\
Created on : 11/5/2003 11:05:13 PM
Last accessed : 11/5/2003 11:05:13 PM
Last modified : 11/5/2003 11:05:13 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@servedby.advertising[2].txt
Object : C:\Documents and Settings\Alex Enscoe\Cookies\
Created on : 11/5/2003 11:05:14 PM
Last accessed : 11/5/2003 11:05:14 PM
Last modified : 11/5/2003 11:05:14 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@z1.adserver[1].txt
Object : C:\Documents and Settings\Alex Enscoe\Cookies\
Created on : 11/5/2003 11:07:07 PM
Last accessed : 11/5/2003 11:07:07 PM
Last modified : 11/5/2003 11:07:07 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@zedo[1].txt
Object : C:\Documents and Settings\Alex Enscoe\Cookies\
Created on : 11/5/2003 3:40:20 AM
Last accessed : 11/5/2003 11:12:42 PM
Last modified : 11/5/2003 3:41:34 AM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@advertising[1].txt
Object : C:\Documents and Settings\Alex Enscoe\Local Settings\Temp\Cookies\
Created on : 8/28/2003 11:01:25 PM
Last accessed : 11/5/2003 11:12:46 PM
Last modified : 8/28/2003 11:01:25 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@atdmt[2].txt
Object : C:\Documents and Settings\Alex Enscoe\Local Settings\Temp\Cookies\
Created on : 8/28/2003 11:01:25 PM
Last accessed : 11/5/2003 11:12:46 PM
Last modified : 8/28/2003 11:01:25 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@doubleclick[1].txt
Object : C:\Documents and Settings\Alex Enscoe\Local Settings\Temp\Cookies\
Created on : 8/28/2003 11:02:49 PM
Last accessed : 11/5/2003 11:12:46 PM
Last modified : 8/28/2003 11:03:45 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@fastclick[1].txt
Object : C:\Documents and Settings\Alex Enscoe\Local Settings\Temp\Cookies\
Created on : 8/28/2003 11:02:37 PM
Last accessed : 11/5/2003 11:12:46 PM
Last modified : 8/28/2003 11:05:37 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@mediaplex[2].txt
Object : C:\Documents and Settings\Alex Enscoe\Local Settings\Temp\Cookies\
Created on : 8/28/2003 11:01:35 PM
Last accessed : 11/5/2003 11:12:46 PM
Last modified : 8/28/2003 11:02:11 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@servedby.advertising[2].txt
Object : C:\Documents and Settings\Alex Enscoe\Local Settings\Temp\Cookies\
Created on : 8/28/2003 11:01:33 PM
Last accessed : 11/5/2003 11:12:46 PM
Last modified : 8/28/2003 11:01:33 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@tribalfusion[1].txt
Object : C:\Documents and Settings\Alex Enscoe\Local Settings\Temp\Cookies\
Created on : 8/28/2003 11:02:49 PM
Last accessed : 11/5/2003 11:12:46 PM
Last modified : 8/28/2003 11:02:49 PM
Tracking Cookie Object recognized!
Type : File
Data : alex enscoe@z1.adserver[1].txt
Object : C:\Documents and Settings\Alex Enscoe\Local Settings\Temp\Cookies\
Created on : 8/28/2003 11:02:12 PM
Last accessed : 11/5/2003 11:12:46 PM
Last modified : 8/28/2003 11:02:13 PM
eAcceleration Object recognized!
Type : File
Data : rav_temp.exe
Object : C:\Documents and Settings\Alex Enscoe\Local Settings\Temp\EACDownload\
FileSize : 36 KB
FileVersion : 1,0,1,107
ProductVersion : 1,0,1,107
CompanyName : eAcceleration Corp.
FileDescription : eAnthology Download module
InternalName : bird
ProductName : eAnthology
Created on : 5/17/2003 9:15:37 PM
Last accessed : 11/5/2003 11:12:47 PM
Last modified : 5/17/2003 9:15:39 PM
NetRatings Object recognized!
Type : File
Data : nrpr.exe
Object : C:\Documents and Settings\Alex Enscoe\Local Settings\Temp\WZS105.tmp\
FileSize : 224 KB
FileVersion : 1.0.0.9r
ProductVersion : 1.0.0.9r
Copyright : Copyright (c) 2002 NetRatings.
CompanyName : NetRatings
FileDescription : Premeter
OriginalFilename : whpr.exe
ProductName : Premeter
Created on : 2/28/2003 10:00:52 PM
Last accessed : 11/5/2003 11:12:52 PM
Last modified : 2/28/2003 10:00:52 PM
WebHancer Object recognized!
Type : File
Data : wbhshare.dll
Object : C:\Documents and Settings\Alex Enscoe\Local Settings\Temp\WZS105.tmp\
FileSize : 28 KB
FileVersion : 3.0.0
ProductVersion : 3.0.0
Copyright : Copyright
CompanyName : webHancer Corporation
FileDescription : webHancer Winsock2 Shared Memory Module
InternalName : wbhshare
OriginalFilename : whwsshm.dll
ProductName : webHancer Customer Companion
Created on : 3/3/2003 10:07:40 PM
Last accessed : 11/5/2003 11:12:52 PM
Last modified : 3/3/2003 10:07:40 PM
WebHancer Object recognized!
Type : File
Data : webhdll.dll
Object : C:\Documents and Settings\Alex Enscoe\Local Settings\Temp\WZS105.tmp\
FileSize : 36 KB
FileVersion : 3.0.0
ProductVersion : 3.0.0
Copyright : Copyright
CompanyName : webHancer Corporation
FileDescription : webHancer Winsock2 SPI
InternalName : webhdll
OriginalFilename : webhdll.dll
ProductName : webHancer Customer Companion
Created on : 3/3/2003 10:07:42 PM
Last accessed : 11/5/2003 11:12:52 PM
Last modified : 3/3/2003 10:07:42 PM
WebHancer Object recognized!
Type : File
Data : whagent.exe
Object : C:\Documents and Settings\Alex Enscoe\Local Settings\Temp\WZS105.tmp\
FileSize : 160 KB
FileVersion : 3.0.0
ProductVersion : 3.0.0
Copyright : Copyright
CompanyName : webHancer Corporation
FileDescription : webHancer Customer Companion
| | |