I'm having some problems here !
I've all these connections going on, so I ran Spybot-s&d and found a few things but nothing more than usual, so I downloaded Ad-Ware and that found a few more (97).
Problem is every time after I visit a site if I run Ad-ware it finds a tracking cookie. I'm not sure if that has anything to do with just finding a programme in my root directory called bi.exe and a folder called My Way.
A dear friend (or was) downloaded a programme and installed it called Direct Connect which if I go: start/settings/panel control/add remove programmes doesn't remove it so I just put it in the trash for now.
I dont know what all the connections are in task manager so I'll just post everything from Ad-Ware and hope some-one can help from there. Please if you can help, make your instructions simple, I have never worked with my registry or Regedit.
Thanks in advance
Lavasoft Ad-aware Personal Build 6.181
Logfile created on :Sunday, 18 April 2004 10:36:34 p.m.
Created with Ad-aware Personal, free for private use.
Using reference-file :01R296 16.04.2004
______________________________________________________
Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
18-04-2004 10:36:35 p.m. - Scan started. (Custom mode)
Listing running processes
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 17-04-2004 9:50:24 p.m.
BasePriority : Normal
#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ThreadCreationTime : 17-04-2004 9:50:25 p.m.
BasePriority : High
#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 17-04-2004 9:50:25 p.m.
BasePriority : Normal
FileSize : 99 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Microsoft
Created on : 18/08/2001
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 18/08/2001
#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 17-04-2004 9:50:25 p.m.
BasePriority : Normal
FileSize : 11 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
OriginalFilename : lsass.exe
ProductName : Microsoft
Created on : 18/08/2001
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 29/08/2002 11:41:26 a.m.
#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 17-04-2004 9:50:26 p.m.
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 18/08/2001
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 18/08/2001
#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 17-04-2004 9:50:26 p.m.
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 18/08/2001
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 18/08/2001
#:7 [explorer.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 17-04-2004 9:50:27 p.m.
BasePriority : Normal
FileSize : 980 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft
Created on : 27/12/2002 9:46:48 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 29/08/2002 11:41:24 a.m.
#:8 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 17-04-2004 9:50:28 p.m.
BasePriority : Normal
FileSize : 50 KB
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
OriginalFilename : spoolsv.exe
ProductName : Microsoft
Created on : 18/08/2001
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 18/08/2001
#:9 [avgcc32.exe]
FilePath : C:\PROGRA~1\Grisoft\AVG6\
ThreadCreationTime : 17-04-2004 9:50:29 p.m.
BasePriority : Normal
FileSize : 396 KB
FileVersion : 6, 0, 0, 427
ProductVersion : 6, 0, 0, 0
Copyright : Copyright
CompanyName : GRISOFT s.r.o.
FileDescription : AVG Control Center
InternalName : AvgCC32
OriginalFilename : AvgCC32.EXE
ProductName : AVG Anti-Virus System
Created on : 25/12/2002 11:09:16 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 12/02/2003 9:55:34 p.m.
#:10 [msmsgs.exe]
FilePath : C:\Program Files\Messenger\
ThreadCreationTime : 17-04-2004 9:50:29 p.m.
BasePriority : Normal
FileSize : 1476 KB
FileVersion : 4.7.0041
ProductVersion : Version 4.7
Copyright : Copyright (c) Microsoft Corporation 1997-2001
CompanyName : Microsoft Corporation
FileDescription : Messenger
InternalName : msmsgs
OriginalFilename : msmsgs.exe
ProductName : Messenger
Created on : 27/12/2002 10:14:46 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 29/08/2002 11:41:26 a.m.
#:11 [wzqkpick.exe]
FilePath : C:\Program Files\WinZip\
ThreadCreationTime : 17-04-2004 9:50:29 p.m.
BasePriority : Normal
FileSize : 104 KB
FileVersion : 1.0 (32-bit)
ProductVersion : 8.1 (4319)
Copyright : Copyright (c) WinZip Computing, Inc. 1991-2001 - All Rights Reserved
CompanyName : WinZip Computing, Inc.
FileDescription : WinZip Executable
InternalName : WZQKPICK.EXE
OriginalFilename : WZQKPICK.EXE
ProductName : WinZip
Created on : 26/12/2002 4:19:28 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 21/11/2002 8:10:00 p.m.
#:12 [apache.exe]
FilePath : C:\Program Files\Apache Group\Apache\
ThreadCreationTime : 17-04-2004 9:50:34 p.m.
BasePriority : Normal
FileSize : 20 KB
Created on : 17/06/2002 11:44:42 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 17/06/2002 11:44:42 p.m.
#:13 [avgserv.exe]
FilePath : C:\PROGRA~1\Grisoft\AVG6\
ThreadCreationTime : 17-04-2004 9:50:34 p.m.
BasePriority : Normal
FileSize : 20 KB
FileVersion : 6.0.1.9
ProductVersion : 6.0.1.9
Copyright : Copyright (c) GRISOFT(c) SOFTWARE 1998-2001
CompanyName : GRISOFT(c) SOFTWARE s.r.o
FileDescription : AvgServ - displays notification message
InternalName : AvgServ
OriginalFilename : AvgServ
ProductName : AVG6
Created on : 25/12/2002 11:09:16 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 16/12/2002 6:00:00 p.m.
#:14 [mysqld-nt.exe]
FilePath : C:\mysql\bin\
ThreadCreationTime : 17-04-2004 9:50:34 p.m.
BasePriority : Normal
FileSize : 1836 KB
Created on : 31/12/2002 6:17:19 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 11/12/2002 12:04:34 a.m.
#:15 [apache.exe]
FilePath : C:\Program Files\Apache Group\Apache\
ThreadCreationTime : 17-04-2004 9:50:35 p.m.
BasePriority : Normal
FileSize : 20 KB
Created on : 17/06/2002 11:44:42 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 17/06/2002 11:44:42 p.m.
#:16 [nvsvc32.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 17-04-2004 9:50:35 p.m.
BasePriority : Normal
FileSize : 60 KB
FileVersion : 6.13.10.3100
ProductVersion : 6.13.10.3100
Copyright : (c) NVIDIA Corporation. All rights reserved.
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA Driver Helper Service, Version 31.00
InternalName : NVSVC
OriginalFilename : nvsvc32.exe
ProductName : NVIDIA Driver Helper Service, Version 31.00
Created on : 23/12/2002 11:59:11 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 30/07/2002 11:50:00 a.m.
#:17 [outpost.exe]
FilePath : C:\PROGRA~1\AGNITUM\OUTPOS~1.0\
ThreadCreationTime : 17-04-2004 9:50:35 p.m.
BasePriority : Normal
FileSize : 77 KB
FileVersion : 1.0.228
ProductVersion : 1.0
Copyright : (C) Agnitum, 1999-2001
CompanyName : Agnitum
FileDescription : Outpost Firewall main module
InternalName : Outpost Firewall
OriginalFilename : outpost.exe
ProductName : Outpost Firewall
Created on : 25/12/2002 11:24:07 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 20/02/2002 1:50:46 a.m.
#:18 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 17-04-2004 9:50:39 p.m.
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 18/08/2001
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 18/08/2001
#:19 [mailwasher.exe]
FilePath : C:\Program Files\MailWasher\
ThreadCreationTime : 18-04-2004 8:39:08 a.m.
BasePriority : Normal
FileSize : 1956 KB
FileVersion : 1.32.8.1231
ProductVersion : 1.0.0.0
Copyright : 2001
CompanyName : eCOSM
FileDescription : MailWasher
InternalName : MailWasher
OriginalFilename : MailWasher.exe
ProductName : MailWasher
Created on : 26/12/2002 1:33:44 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 3/04/2002 2:31:26 a.m.
#:20 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ThreadCreationTime : 18-04-2004 8:41:25 a.m.
BasePriority : Normal
FileSize : 89 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
OriginalFilename : IEXPLORE.EXE
ProductName : Microsoft
Created on : 27/12/2002 9:50:20 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 29/08/2002 11:41:26 a.m.
#:21 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-aware 6\
ThreadCreationTime : 18-04-2004 10:28:51 a.m.
BasePriority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 17/04/2004 11:18:45 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 12/07/2003 10:00:20 a.m.
Memory scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Started registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Started deep registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Deep registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Deep scanning and examining files (C
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New.Net Object recognized!
Type : File
Data : ndnuninstall4_88.exe
Object : C:\WINDOWS\
FileSize : 43 KB
Created on : 2/06/2003 4:37:34 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 2/06/2003 4:37:36 p.m.
Tracking Cookie Object recognized!
Type : File
Data : [email protected][1].txt
Object : C:\Documents and Settings\jas\Local Settings\Temp\Cookies\
Created on : 15/04/2004 7:19:00 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 15/04/2004 7:19:02 p.m.
Tracking Cookie Object recognized!
Type : File
Data : [email protected][1].txt
Object : C:\Documents and Settings\jas\Local Settings\Temp\Cookies\
Created on : 15/04/2004 9:03:43 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 15/04/2004 9:03:46 p.m.
Cydoor Object recognized!
Type : File
Data : cd_clint.dll
Object : C:\Documents and Settings\jas\Local Settings\Temp\
FileSize : 151 KB
FileVersion : 3, 2, 1, 0
ProductVersion : 3, 2, 1, 0
Copyright : Copyright (C) Cydoor Technologies, Inc. 1999-2001
CompanyName : Cydoor Technologies, Inc.
FileDescription : Cydoor Technologies ad-system
InternalName : CD_Clint.dll
OriginalFilename : CD_Clint.dll
ProductName : Cydoor Technologies ad-system
Created on : 7/06/2003 6:57:30 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 14/01/2002 1:57:00 a.m.
Tracking Cookie Object recognized!
Type : File
Data : [email protected][1].txt
Object : C:\Documents and Settings\jas\Cookies\
Created on : 18/04/2004 8:41:36 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 18/04/2004 8:41:38 a.m.
Disk scan result for C:\
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 5
Deep scanning and examining files (D
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Disk scan result for D:\
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 5
Possible Browser Hijack attempt Object recognized!
Type : File
Data : heritage.url
Object : C:\Documents and Settings\jas\Favorites\Jas\
FileSize : 1 KB
Created on : 5/03/2004 6:24:03 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 5/03/2004 6:24:08 a.m.
Scanning Hosts file(C:\WINDOWS\System32\drivers\etc\hosts)
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Hosts file scan result:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
1 entries scanned.
New objects :0
Objects found so far: 6
Performing conditional scans..
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Conditional scan result:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 6
10:44:53 p.m. Scan complete
Summary of this scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Total scanning time :00:08:18:126
Objects scanned :180012
Objects identified :6
Objects ignored :0
New objects :6
I've all these connections going on, so I ran Spybot-s&d and found a few things but nothing more than usual, so I downloaded Ad-Ware and that found a few more (97).
Problem is every time after I visit a site if I run Ad-ware it finds a tracking cookie. I'm not sure if that has anything to do with just finding a programme in my root directory called bi.exe and a folder called My Way.
A dear friend (or was) downloaded a programme and installed it called Direct Connect which if I go: start/settings/panel control/add remove programmes doesn't remove it so I just put it in the trash for now.
I dont know what all the connections are in task manager so I'll just post everything from Ad-Ware and hope some-one can help from there. Please if you can help, make your instructions simple, I have never worked with my registry or Regedit.
Thanks in advance
Lavasoft Ad-aware Personal Build 6.181
Logfile created on :Sunday, 18 April 2004 10:36:34 p.m.
Created with Ad-aware Personal, free for private use.
Using reference-file :01R296 16.04.2004
______________________________________________________
Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
18-04-2004 10:36:35 p.m. - Scan started. (Custom mode)
Listing running processes
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 17-04-2004 9:50:24 p.m.
BasePriority : Normal
#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ThreadCreationTime : 17-04-2004 9:50:25 p.m.
BasePriority : High
#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 17-04-2004 9:50:25 p.m.
BasePriority : Normal
FileSize : 99 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Microsoft
Created on : 18/08/2001
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 18/08/2001
#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 17-04-2004 9:50:25 p.m.
BasePriority : Normal
FileSize : 11 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
OriginalFilename : lsass.exe
ProductName : Microsoft
Created on : 18/08/2001
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 29/08/2002 11:41:26 a.m.
#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 17-04-2004 9:50:26 p.m.
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 18/08/2001
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 18/08/2001
#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 17-04-2004 9:50:26 p.m.
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 18/08/2001
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 18/08/2001
#:7 [explorer.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 17-04-2004 9:50:27 p.m.
BasePriority : Normal
FileSize : 980 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft
Created on : 27/12/2002 9:46:48 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 29/08/2002 11:41:24 a.m.
#:8 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 17-04-2004 9:50:28 p.m.
BasePriority : Normal
FileSize : 50 KB
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
OriginalFilename : spoolsv.exe
ProductName : Microsoft
Created on : 18/08/2001
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 18/08/2001
#:9 [avgcc32.exe]
FilePath : C:\PROGRA~1\Grisoft\AVG6\
ThreadCreationTime : 17-04-2004 9:50:29 p.m.
BasePriority : Normal
FileSize : 396 KB
FileVersion : 6, 0, 0, 427
ProductVersion : 6, 0, 0, 0
Copyright : Copyright
CompanyName : GRISOFT s.r.o.
FileDescription : AVG Control Center
InternalName : AvgCC32
OriginalFilename : AvgCC32.EXE
ProductName : AVG Anti-Virus System
Created on : 25/12/2002 11:09:16 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 12/02/2003 9:55:34 p.m.
#:10 [msmsgs.exe]
FilePath : C:\Program Files\Messenger\
ThreadCreationTime : 17-04-2004 9:50:29 p.m.
BasePriority : Normal
FileSize : 1476 KB
FileVersion : 4.7.0041
ProductVersion : Version 4.7
Copyright : Copyright (c) Microsoft Corporation 1997-2001
CompanyName : Microsoft Corporation
FileDescription : Messenger
InternalName : msmsgs
OriginalFilename : msmsgs.exe
ProductName : Messenger
Created on : 27/12/2002 10:14:46 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 29/08/2002 11:41:26 a.m.
#:11 [wzqkpick.exe]
FilePath : C:\Program Files\WinZip\
ThreadCreationTime : 17-04-2004 9:50:29 p.m.
BasePriority : Normal
FileSize : 104 KB
FileVersion : 1.0 (32-bit)
ProductVersion : 8.1 (4319)
Copyright : Copyright (c) WinZip Computing, Inc. 1991-2001 - All Rights Reserved
CompanyName : WinZip Computing, Inc.
FileDescription : WinZip Executable
InternalName : WZQKPICK.EXE
OriginalFilename : WZQKPICK.EXE
ProductName : WinZip
Created on : 26/12/2002 4:19:28 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 21/11/2002 8:10:00 p.m.
#:12 [apache.exe]
FilePath : C:\Program Files\Apache Group\Apache\
ThreadCreationTime : 17-04-2004 9:50:34 p.m.
BasePriority : Normal
FileSize : 20 KB
Created on : 17/06/2002 11:44:42 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 17/06/2002 11:44:42 p.m.
#:13 [avgserv.exe]
FilePath : C:\PROGRA~1\Grisoft\AVG6\
ThreadCreationTime : 17-04-2004 9:50:34 p.m.
BasePriority : Normal
FileSize : 20 KB
FileVersion : 6.0.1.9
ProductVersion : 6.0.1.9
Copyright : Copyright (c) GRISOFT(c) SOFTWARE 1998-2001
CompanyName : GRISOFT(c) SOFTWARE s.r.o
FileDescription : AvgServ - displays notification message
InternalName : AvgServ
OriginalFilename : AvgServ
ProductName : AVG6
Created on : 25/12/2002 11:09:16 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 16/12/2002 6:00:00 p.m.
#:14 [mysqld-nt.exe]
FilePath : C:\mysql\bin\
ThreadCreationTime : 17-04-2004 9:50:34 p.m.
BasePriority : Normal
FileSize : 1836 KB
Created on : 31/12/2002 6:17:19 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 11/12/2002 12:04:34 a.m.
#:15 [apache.exe]
FilePath : C:\Program Files\Apache Group\Apache\
ThreadCreationTime : 17-04-2004 9:50:35 p.m.
BasePriority : Normal
FileSize : 20 KB
Created on : 17/06/2002 11:44:42 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 17/06/2002 11:44:42 p.m.
#:16 [nvsvc32.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 17-04-2004 9:50:35 p.m.
BasePriority : Normal
FileSize : 60 KB
FileVersion : 6.13.10.3100
ProductVersion : 6.13.10.3100
Copyright : (c) NVIDIA Corporation. All rights reserved.
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA Driver Helper Service, Version 31.00
InternalName : NVSVC
OriginalFilename : nvsvc32.exe
ProductName : NVIDIA Driver Helper Service, Version 31.00
Created on : 23/12/2002 11:59:11 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 30/07/2002 11:50:00 a.m.
#:17 [outpost.exe]
FilePath : C:\PROGRA~1\AGNITUM\OUTPOS~1.0\
ThreadCreationTime : 17-04-2004 9:50:35 p.m.
BasePriority : Normal
FileSize : 77 KB
FileVersion : 1.0.228
ProductVersion : 1.0
Copyright : (C) Agnitum, 1999-2001
CompanyName : Agnitum
FileDescription : Outpost Firewall main module
InternalName : Outpost Firewall
OriginalFilename : outpost.exe
ProductName : Outpost Firewall
Created on : 25/12/2002 11:24:07 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 20/02/2002 1:50:46 a.m.
#:18 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 17-04-2004 9:50:39 p.m.
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 18/08/2001
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 18/08/2001
#:19 [mailwasher.exe]
FilePath : C:\Program Files\MailWasher\
ThreadCreationTime : 18-04-2004 8:39:08 a.m.
BasePriority : Normal
FileSize : 1956 KB
FileVersion : 1.32.8.1231
ProductVersion : 1.0.0.0
Copyright : 2001
CompanyName : eCOSM
FileDescription : MailWasher
InternalName : MailWasher
OriginalFilename : MailWasher.exe
ProductName : MailWasher
Created on : 26/12/2002 1:33:44 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 3/04/2002 2:31:26 a.m.
#:20 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ThreadCreationTime : 18-04-2004 8:41:25 a.m.
BasePriority : Normal
FileSize : 89 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
OriginalFilename : IEXPLORE.EXE
ProductName : Microsoft
Created on : 27/12/2002 9:50:20 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 29/08/2002 11:41:26 a.m.
#:21 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-aware 6\
ThreadCreationTime : 18-04-2004 10:28:51 a.m.
BasePriority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 17/04/2004 11:18:45 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 12/07/2003 10:00:20 a.m.
Memory scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Started registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Started deep registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Deep registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Deep scanning and examining files (C
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New.Net Object recognized!
Type : File
Data : ndnuninstall4_88.exe
Object : C:\WINDOWS\
FileSize : 43 KB
Created on : 2/06/2003 4:37:34 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 2/06/2003 4:37:36 p.m.
Tracking Cookie Object recognized!
Type : File
Data : [email protected][1].txt
Object : C:\Documents and Settings\jas\Local Settings\Temp\Cookies\
Created on : 15/04/2004 7:19:00 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 15/04/2004 7:19:02 p.m.
Tracking Cookie Object recognized!
Type : File
Data : [email protected][1].txt
Object : C:\Documents and Settings\jas\Local Settings\Temp\Cookies\
Created on : 15/04/2004 9:03:43 p.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 15/04/2004 9:03:46 p.m.
Cydoor Object recognized!
Type : File
Data : cd_clint.dll
Object : C:\Documents and Settings\jas\Local Settings\Temp\
FileSize : 151 KB
FileVersion : 3, 2, 1, 0
ProductVersion : 3, 2, 1, 0
Copyright : Copyright (C) Cydoor Technologies, Inc. 1999-2001
CompanyName : Cydoor Technologies, Inc.
FileDescription : Cydoor Technologies ad-system
InternalName : CD_Clint.dll
OriginalFilename : CD_Clint.dll
ProductName : Cydoor Technologies ad-system
Created on : 7/06/2003 6:57:30 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 14/01/2002 1:57:00 a.m.
Tracking Cookie Object recognized!
Type : File
Data : [email protected][1].txt
Object : C:\Documents and Settings\jas\Cookies\
Created on : 18/04/2004 8:41:36 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 18/04/2004 8:41:38 a.m.
Disk scan result for C:\
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 5
Deep scanning and examining files (D
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Disk scan result for D:\
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 5
Possible Browser Hijack attempt Object recognized!
Type : File
Data : heritage.url
Object : C:\Documents and Settings\jas\Favorites\Jas\
FileSize : 1 KB
Created on : 5/03/2004 6:24:03 a.m.
Last accessed : 17/04/2004 12:00:00 p.m.
Last modified : 5/03/2004 6:24:08 a.m.
Scanning Hosts file(C:\WINDOWS\System32\drivers\etc\hosts)
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Hosts file scan result:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
1 entries scanned.
New objects :0
Objects found so far: 6
Performing conditional scans..
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Conditional scan result:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 6
10:44:53 p.m. Scan complete
Summary of this scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Total scanning time :00:08:18:126
Objects scanned :180012
Objects identified :6
Objects ignored :0
New objects :6