i've done everything else I was supposed to do thus far, and so far, so good. Ran Adaware and following the directions it says to post the log and wait until I make sure I know what I"m getting rid of. Thanks again and I'll check this in the afternoon!
Lavasoft Ad-aware Personal Build 6.181
Logfile created on :Monday, March 29, 2004 2:20:23 AM
Created with Ad-aware Personal, free for private use.
Using reference-file :01R276 27.03.2004
______________________________________________________
Reffile status:
=========================
Reference file loaded:
Reference Number : 01R276 27.03.2004
Internal build : 203
File location : C:\PROGRAM FILES\LAVASOFT\AD-AWARE 6\reflist.ref
Total size : 988898 Bytes
Signature data size : 971553 Bytes
Reference data size : 17281 Bytes
Signatures total : 21874
Target categories : 10
Target families : 468
Memory + processor status:
==========================
Number of processors : 1
Processor architecture : Intel Pentium III
Memory available:58 %
Total physical memory:392700 kb
Available physical memory:170000 kb
Total page file size:1704448 kb
Available on page file:1555000 kb
Total virtual memory:2093056 kb
Available virtual memory:2042944 kb
OS:Windows (ME)
Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
Extended Ad-aware Settings
=========================
Set : Unload recognized processes during scanning
Set : Include basic Ad-aware settings in logfile
Set : Include additional Ad-aware settings in logfile
Set : Automatically try to unregister objects prior to deletion
Set : Let windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Always back up reference file, before updating
Set : Play sound if scan produced a result
3-29-2004 2:20:23 AM - Scan started. (Custom mode)
Listing running processes
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
#:1 [kernel32.dll]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4287606451
Threads : 9
Priority : High
FileSize : 524 KB
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
Copyright : Copyright (C) Microsoft Corp. 1991-2000
CompanyName : Microsoft Corporation
FileDescription : Win32 Kernel core component
InternalName : KERNEL32
OriginalFilename : KERNEL32.DLL
ProductName : Microsoft(R) Windows(R) Millennium Operating System
Created on : 12/27/2000 12:25:17 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:2 [msgsrv32.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294966103
Threads : 1
Priority : Normal
FileSize : 11 KB
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
Copyright : Copyright (C) Microsoft Corp. 1992-1998
CompanyName : Microsoft Corporation
FileDescription : Windows 32-bit VxD Message Server
InternalName : MSGSRV32
OriginalFilename : MSGSRV32.EXE
ProductName : Microsoft(R) Windows(R) Millennium Operating System
Created on : 12/27/2000 12:25:55 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:3 [msgloop.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294843203
Threads : 1
Priority : Normal
FileSize : 5 KB
FileVersion : 4.05.00.2112
ProductVersion : 4.05.00.2112
Copyright : Copyright (c) Rockwell Corporation 1996-1998.
CompanyName : Rockwell Corporation
FileDescription : Rockwell WaveStream Message Server
InternalName : MSGLOOP.EXE
OriginalFilename : MSGLOOP.EXE
ProductName : WaveStream\Endless Wave
Created on : 1/1/1601
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 5/24/1999 11:35:36 PM
#:4 [msg32.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294864135
Threads : 1
Priority : Realtime
FileSize : 16 KB
FileVersion : 4.05.00.2112
ProductVersion : 4.05.00.2112
Copyright : Copyright
CompanyName : Rockwell Corporation
FileDescription : Rockwell WaveStream Message Server
InternalName : MSGLOOP.EXE
OriginalFilename : MSGLOOP.EXE
ProductName : WaveStream\Endless Wave
Created on : 1/1/1601
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 5/24/1999 11:39:04 PM
#:5 [mmtask.tsk]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294864395
Threads : 1
Priority : Normal
FileSize : 1 KB
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
Copyright : Copyright
CompanyName : Microsoft Corporation
FileDescription : Multimedia background task support module
InternalName : mmtask.tsk
OriginalFilename : mmtask.tsk
ProductName : Microsoft Windows
Created on : 12/27/2000 12:26:21 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:6 [mprexe.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294868607
Threads : 1
Priority : Normal
FileSize : 28 KB
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
Copyright : Copyright (C) Microsoft Corp. 1993-2000
CompanyName : Microsoft Corporation
FileDescription : WIN32 Network Interface Service Process
InternalName : MPREXE
OriginalFilename : MPREXE.EXE
ProductName : Microsoft(R) Windows(R) Millennium Operating System
Created on : 12/27/2000 12:25:55 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:7 [aolfix.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294873887
Threads : 1
Priority : Normal
FileSize : 28 KB
FileVersion : 1, 0, 0, 0
ProductVersion : 1, 0, 0, 0
Copyright : Copyright
CompanyName : Hewlett-Packard Co.
FileDescription : Repairs power management configuration
InternalName : Jvprjsxfcs
OriginalFilename : AolFix.exe
ProductName : Hewlett-Packard AolFix Application
Created on : 1/11/2000 1:24:34 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 1/11/2000 1:24:34 AM
#:8 [mstask.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294898051
Threads : 3
Priority : Normal
FileSize : 124 KB
FileVersion : 4.71.2721.1
ProductVersion : 4.71.2721.1
Copyright : Copyright (C) Microsoft Corp. 2000
CompanyName : Microsoft Corporation
FileDescription : Task Scheduler Engine
InternalName : TaskScheduler
OriginalFilename : mstask.exe
ProductName : Microsoft
Created on : 12/27/2000 12:25:55 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:9 [avsynmgr.exe]
FilePath : C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\
ProcessID : 4294881159
Threads : 4
Priority : Normal
FileSize : 152 KB
Copyright : gin
Created on : 11/26/2001 9:51:00 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 11/26/2001 9:51:00 PM
#:10 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 4294784999
Threads : 18
Priority : Normal
FileSize : 220 KB
FileVersion : 5.50.4134.100
ProductVersion : 5.50.4134.100
Copyright : Copyright (C) Microsoft Corp. 1981-2000
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft(R) Windows (R) 2000 Operating System
Created on : 12/27/2000 12:23:42 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:11 [hidserv.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294800495
Threads : 1
Priority : Normal
FileSize : 25 KB
FileVersion : 4.90.3000.1
ProductVersion : 4.90.3000.1
Copyright : Copyright (C) Microsoft Corp. 1981-2000
CompanyName : Microsoft Corporation
FileDescription : HID Audio Service
InternalName : hidserv
OriginalFilename : HIDSERV.EXE
ProductName : Microsoft(R) Windows(R) Millennium Operating System
Created on : 12/27/2000 12:22:30 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:12 [realsched.exe]
FilePath : C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\
ProcessID : 4294894095
Threads : 2
Priority : Normal
FileSize : 148 KB
FileVersion : 0.1.0.1622
ProductVersion : 0.1.0.1622
Copyright : Copyright
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
OriginalFilename : realsched.exe
ProductName : RealOne Player (32-bit)
Created on : 12/12/2003 3:19:49 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 12/12/2003 3:19:50 AM
#:13 [vsstat.exe]
FilePath : C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\
ProcessID : 4294724079
Threads : 2
Priority : Normal
FileSize : 96 KB
Copyright : Cop
Created on : 11/26/2001 9:51:00 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 11/26/2001 9:51:00 PM
#:14 [loadqm.exe]
FilePath : C:\WINDOWS\
ProcessID : 4294752567
Threads : 3
Priority : Normal
FileSize : 7 KB
FileVersion : 5.4.1103.3
ProductVersion : 5.4.1103.3
Copyright : Copyright (C) Microsoft Corp. 1981-1999
CompanyName : Microsoft Corporation
FileDescription : Microsoft QMgr
InternalName : LOADQM.EXE
OriginalFilename : LOADQM.EXE
ProductName : QMgr Loader
Created on : 3/19/2004 1:47:54 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 5/3/2000 10:23:10 PM
#:15 [taskmon.exe]
FilePath : C:\WINDOWS\
ProcessID : 4294745367
Threads : 1
Priority : Normal
FileSize : 28 KB
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
Copyright : Copyright (C) Microsoft Corp. 1998
CompanyName : Microsoft Corporation
FileDescription : Task Monitor
InternalName : TaskMon
OriginalFilename : TASKMON.EXE
ProductName : Microsoft(R) Windows(R) Millennium Operating System
Created on : 12/27/2000 12:25:58 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:16 [stmgr.exe]
FilePath : C:\WINDOWS\SYSTEM\RESTORE\
ProcessID : 4294766283
Threads : 4
Priority : Normal
FileSize : 60 KB
FileVersion : 4.90.0.2533
ProductVersion : 4.90.0.2533
Copyright : Copyright (C) Microsoft Corp. 1981-2000
CompanyName : Microsoft Corporation
FileDescription : Microsoft (R) PC State Manager
InternalName : StateMgr.exe
OriginalFilename : StateMgr.exe
ProductName : Microsoft (r) PCHealth
Created on : 12/27/2000 12:25:58 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:17 [systray.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294885987
Threads : 2
Priority : Normal
FileSize : 36 KB
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
Copyright : Copyright (C) Microsoft Corp. 1993-2000
CompanyName : Microsoft Corporation
FileDescription : System Tray Applet
InternalName : SYSTRAY
OriginalFilename : SYSTRAY.EXE
ProductName : Microsoft(R) Windows(R) Millennium Operating System
Created on : 12/27/2000 12:25:58 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:18 [hpsysdrv.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294758943
Threads : 1
Priority : Normal
FileSize : 51 KB
FileVersion : 1, 7, 0, 0
ProductVersion : 1, 7, 0, 0
Copyright : Copyright
CompanyName : Hewlett-Packard Company
FileDescription : hpsysdrv
InternalName : hpsysdrv
OriginalFilename : hpsysdrv.exe
ProductName : hpsysdrv
Created on : 3/9/2000 1:53:18 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 5/7/1998 2:04:38 PM
#:19 [ddhelp.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294679687
Threads : 25
Priority : Realtime
FileSize : 31 KB
FileVersion : 4.08.01.0881
ProductVersion : 4.08.01.0881
Copyright : Copyright
CompanyName : Microsoft Corporation
FileDescription : Microsoft DirectX Helper
InternalName : DDHelp.exe
OriginalFilename : DDHelp.exe
ProductName : Microsoft
Created on : 1/17/2002 5:20:28 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 1/17/2002 5:20:28 AM
#:20 [wmiexe.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294660431
Threads : 3
Priority : Normal
FileSize : 16 KB
FileVersion : 4.90.2452.1
ProductVersion : 4.90.2452.1
Copyright : Copyright (C) Microsoft Corp. 1981-1999
CompanyName : Microsoft Corporation
FileDescription : WMI service exe housing
InternalName : wmiexe
OriginalFilename : wmiexe.exe
ProductName : Microsoft(R) Windows(R) Millennium Operating System
Created on : 12/27/2000 12:26:00 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:21 [rundll32.exe]
FilePath : C:\WINDOWS\
ProcessID : 4294582783
Threads : 2
Priority : Normal
FileSize : 24 KB
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
Copyright : Copyright (C) Microsoft Corp. 1991-1998
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
OriginalFilename : RUNDLL.EXE
ProductName : Microsoft(R) Windows(R) Millennium Operating System
Created on : 12/27/2000 12:25:57 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:22 [avconsol.exe]
FilePath : C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\
ProcessID : 4294678319
Threads : 2
Priority : Normal
FileSize : 160 KB
Copyright : <?1
Created on : 11/26/2001 9:51:00 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 11/26/2001 9:51:00 PM
#:23 [vshwin32.exe]
FilePath : C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\
ProcessID : 4294646683
Threads : 6
Priority : Normal
FileSize : 116 KB
Copyright : ¼>1
Created on : 11/26/2001 9:51:00 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 11/26/2001 9:51:00 PM
#:24 [winmgmt.exe]
FilePath : C:\WINDOWS\SYSTEM\WBEM\
ProcessID : 4294463371
Threads : 3
Priority : Normal
FileSize : 192 KB
FileVersion : 1.50.1164.0000
ProductVersion : 1.50.1164.0000
Copyright : Copyright (C) Microsoft Corp. 1995-1999
CompanyName : Microsoft Corporation
FileDescription : Windows Management Instrumentation
InternalName : WINMGMT
ProductName : Windows Management Instrumentation
Created on : 12/27/2000 12:26:00 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:25 [spool32.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294710955
Threads : 2
Priority : Normal
FileSize : 44 KB
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
Copyright : Copyright (C) Microsoft Corp. 1994 - 1998
CompanyName : Microsoft Corporation
FileDescription : Spooler Sub System Process
InternalName : spool32
OriginalFilename : spool32.exe
ProductName : Microsoft(R) Windows(R) Millennium Operating System
Created on : 12/27/2000 12:25:58 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:26 [rnaapp.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294456695
Threads : 3
Priority : Normal
FileSize : 56 KB
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
Copyright : Copyright (C) Microsoft Corp. 1992-1996
CompanyName : Microsoft Corporation
FileDescription : Dial-Up Networking Application
InternalName : RNAAPP
OriginalFilename : RNAAPP.EXE
ProductName : Microsoft(R) Windows(R) Millennium Operating System
Created on : 12/27/2000 12:25:57 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:27 [tapisrv.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294456935
Threads : 5
Priority : Normal
FileSize : 120 KB
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
Copyright : Copyright (C) Microsoft Corp. 1994-1998
CompanyName : Microsoft Corporation
FileDescription : Microsoft
InternalName : Telephony Service
OriginalFilename : TAPISRV.EXE
ProductName : Microsoft(R) Windows(R) Millennium Operating System
Created on : 12/27/2000 12:25:58 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
#:28 [ad-aware.exe]
FilePath : C:\PROGRAM FILES\LAVASOFT\AD-AWARE 6\
ProcessID : 4294422851
Threads : 2
Priority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 3/29/2004 12:21:38 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 7/13/2003 3:00:20 AM
#:29 [stimon.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294482027
Threads : 5
Priority : Normal
FileSize : 27 KB
FileVersion : 4.90.3000.1
ProductVersion : 4.90.3000.1
Copyright : Copyright (C) Microsoft Corp. 1981-2000
CompanyName : Microsoft Corporation
FileDescription : Still Image Devices Monitor
InternalName : STIMON
OriginalFilename : STIMON.EXE
ProductName : Microsoft(R) Windows(R) Millennium Operating System
Created on : 12/27/2000 12:25:58 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 6/8/2000 10:00:00 PM
Memory scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Started registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Started deep registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Possible browser hijack attempt : Software\Microsoft\Windows\CurrentVersion\Internet SettingsAutoConfigUrlmarketscore.com
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://proxycfg.marketscore.com/gencfg.asp?id1=MNxxtm7GNh6&id2=U1d0btwUq5f&lp=1&nsv=5.1.0.4"
Category : Data Miner
Comment : Possible browser hijack attempt
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Windows\CurrentVersion\Internet Settings
Value : AutoConfigUrl
Data : "http://proxycfg.marketscore.com/gencfg.asp?id1=MNxxtm7GNh6&id2=U1d0btwUq5f&lp=1&nsv=5.1.0.4"
Deep registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 1
Objects found so far: 1
Deep scanning and examining files (C

¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
TPS108 Object recognized!
Type : File
Data : tps108.html
Category : Data Miner
Comment :
Object : C:\
Dialer Object recognized!
Type : File
Data : nsupd9x.inf
Category : Malware
Comment : Proclaim Telcom
Object : C:\WINDOWS\INF\
Created on : 8/22/2000 5:18:22 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 8/22/2000 5:18:22 PM
TPS108 Object recognized!
Type : File
Data : tps108.inf
Category : Data Miner
Comment :
Object : C:\WINDOWS\INF\
Created on : 2/22/2002 8:34:40 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 2/22/2002 8:34:40 PM
ToolbarCC Object recognized!
Type : File
Data : winpkpk.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\TEMP\
FileSize : 9 KB
Created on : 7/18/2003 3:33:43 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 7/18/2003 3:33:44 PM
ToolbarCC Object recognized!
Type : File
Data : winlobe.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\TEMP\
FileSize : 10 KB
Created on : 7/21/2003 4:03:54 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 7/21/2003 4:03:56 PM
VX2.BetterInternet Object recognized!
Type : File
Data : belt.exe
Category : Data Miner
Comment :
Object : C:\WINDOWS\TEMP\
FileSize : 80 KB
FileVersion : 0, 1, 1, 3
ProductVersion : 0, 1, 1, 3
Copyright : Copyright
CompanyName : Better Internet Inc.
FileDescription :
www.abetterinternet.com
Created on : 2/16/2004 4:02:32 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 8/15/2003 9:18:20 PM
Tracking Cookie Object recognized!
Type : File
Data : randy
[email protected][1].txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\Cookies\
Created on : 3/29/2004 12:54:05 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 3/29/2004 12:54:06 AM
Tracking Cookie Object recognized!
Type : File
Data : randy
[email protected][2].txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\Cookies\
Created on : 3/29/2004 12:50:22 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 3/29/2004 12:50:24 AM
Tracking Cookie Object recognized!
Type : File
Data : randy
[email protected][2].txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\Cookies\
Created on : 3/29/2004 5:03:48 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 3/29/2004 5:03:50 AM
Tracking Cookie Object recognized!
Type : File
Data : randy
[email protected][1].txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\Cookies\
Created on : 3/29/2004 5:03:47 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 3/29/2004 5:03:48 AM
Tracking Cookie Object recognized!
Type : File
Data : randy
[email protected]ox[2].txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\Cookies\
FileSize : 2 KB
Created on : 3/29/2004 5:17:04 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 3/29/2004 5:17:06 AM
Tracking Cookie Object recognized!
Type : File
Data : randy
[email protected][1].txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\Cookies\
Created on : 3/29/2004 5:14:37 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 3/29/2004 5:14:38 AM
Tracking Cookie Object recognized!
Type : File
Data : randy
[email protected][1].txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\Cookies\
Created on : 3/29/2004 5:17:04 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 3/29/2004 5:17:06 AM
Tracking Cookie Object recognized!
Type : File
Data : randy
[email protected][1].txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\Cookies\
Created on : 3/29/2004 5:17:02 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 3/29/2004 5:17:04 AM
WildTangent Object recognized!
Type : File
Data : wtcpl.cpl
Category : Data Miner
Comment :
Object : C:\WINDOWS\SYSTEM\
FileSize : 44 KB
FileVersion : 1.6.1.2
ProductVersion : 1.6.1.2
Copyright : Copyright
CompanyName : WildTangent, Inc.
FileDescription : wtcpl
InternalName : wtcpl
OriginalFilename : wtcpl.cpl
ProductName : Wild Tangent wtcpl
Created on : 12/1/2003 6:28:14 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 9/23/2003 11:48:48 PM
Dialer Object recognized!
Type : File
Data : nsupd9x.inf
Category : Malware
Comment : Proclaim Telcom
Object : C:\WINDOWS\Downloaded Program Files\
Created on : 8/22/2000 5:18:22 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 8/22/2000 5:18:22 PM
NiteLine Media Object recognized!
Type : File
Data : dialer.inf
Category : Vulnerability
Comment :
Object : C:\WINDOWS\Downloaded Program Files\
Created on : 11/15/2001 2:26:20 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 11/15/2001 2:26:20 PM
EGroup Dialer Object recognized!
Type : File
Data : ieaccess2.inf
Category : Malware
Comment : IEAccess (eGroup)
Object : C:\WINDOWS\Downloaded Program Files\
Created on : 10/8/2002 3:07:36 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 10/8/2002 3:07:36 PM
Lop.com Object recognized!
Type : File
Data : mp3.exe
Category : Malware
Comment :
Object : C:\WINDOWS\Downloaded Program Files\
FileSize : 73 KB
Created on : 9/16/2002 4:13:34 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 9/16/2002 4:13:48 AM
Dialer Object recognized!
Type : File
Data : installer.inf
Category : Malware
Comment :
Object : C:\WINDOWS\Downloaded Program Files\
Created on : 1/20/2003 8:52:38 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 1/20/2003 8:52:38 PM
TPS108 Object recognized!
Type : File
Data : preinsttps108.exe
Category : Malware
Comment :
Object : C:\WINDOWS\
FileSize : 32 KB
Created on : 2/22/2002 8:34:38 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 2/22/2002 8:34:38 PM
New.Net Object recognized!
Type : File
Data : ndnuninstall4_80.exe
Category : Misc
Comment :
Object : C:\WINDOWS\
FileSize : 51 KB
Created on : 2/14/2003 12:25:55 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 2/14/2003 12:25:56 AM
New.Net Object recognized!
Type : File
Data : ndnuninstall4_88.exe
Category : Misc
Comment :
Object : C:\WINDOWS\
FileSize : 43 KB
Created on : 5/25/2003 10:27:24 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 5/25/2003 10:27:26 PM
New.Net Object recognized!
Type : File
Data : ndnuninstall5_40.exe
Category : Misc
Comment :
Object : C:\WINDOWS\
FileSize : 48 KB
Created on : 9/18/2003 4:12:15 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 9/18/2003 4:12:16 AM
New.Net Object recognized!
Type : File
Data : ndnuninstall5_20.exe
Category : Misc
Comment :
Object : C:\WINDOWS\
FileSize : 44 KB
Created on : 8/4/2003 6:41:22 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 8/4/2003 6:41:24 PM
New.Net Object recognized!
Type : File
Data : ndnuninstall5_48.exe
Category : Misc
Comment :
Object : C:\WINDOWS\
FileSize : 48 KB
Created on : 11/15/2003 10:34:07 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 11/15/2003 10:34:08 PM
PromulGate Object recognized!
Type : File
Data : dpi.exe
Category : Data Miner
Comment :
Object : C:\Program Files\Common Files\Dpi\
FileSize : 92 KB
Created on : 11/6/2003 9:53:44 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 11/6/2003 9:50:04 PM
SecretCrush Object recognized!
Type : File
Data : restart.exe
Category : Malware
Comment :
Object : C:\Program Files\Logitech\Desktop Messenger\8876480\6.1.0.155-8876480L\Program\
FileSize : 16 KB
Created on : 4/24/2002 11:31:30 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 4/24/2002 11:31:32 PM
New.Net Object recognized!
Type : Folder
Category : Misc
Comment :
Object : C:\Program Files\FirstLook
eUniverse Object recognized!
Type : File
Data : incfindbho.dll
Category : Data Miner
Comment :
Object : C:\Program Files\IncrediFind\BHO\
FileSize : 40 KB
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
Copyright : Copyright 2003
FileDescription : BHO Module
InternalName : BHO
OriginalFilename : BHO.DLL
ProductName : BHO Module
Created on : 10/16/2003 5:49:20 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 10/16/2003 5:49:20 PM
Cydoor Object recognized!
Type : File
Data : cd_install_336.exe
Category : Data Miner
Comment :
Object : C:\Program Files\Blubster\
FileSize : 281 KB
ProductVersion : Morpheus
ProductName : Morpheus
Created on : 2/23/2004 6:07:40 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 5/21/2003 8:37:58 AM
TopMoxie Object recognized!
Type : File
Data : blubstersupport.exe
Category : Data Miner
Comment :
Object : C:\Program Files\BlubsterSupport\
FileSize : 44 KB
Created on : 9/15/2003 10:38:30 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 9/15/2003 10:38:30 PM
TopMoxie Object recognized!
Type : File
Data : blubstersupport1.exe
Category : Data Miner
Comment :
Object : C:\Program Files\BlubsterSupport\
FileSize : 24 KB
Created on : 1/25/2004 12:30:40 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 1/25/2004 12:30:42 AM
Disk scan result for C:\
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 34
Possible Browser Hijack attempt Object recognized!
Type : File
Data : billboard.url
Category : Misc
Comment : Item referrs to blacklisted Site:
http://billboard.com/bb/charts/hot100.jsp
Object : C:\WINDOWS\Favorites\
Created on : 7/12/2003 5:18:45 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 7/12/2003 5:18:44 PM
Possible Browser Hijack attempt Object recognized!
Type : File
Data : search the web.url
Category : Misc
Comment : Item referrs to blacklisted Site:
http://www.sureseeker.com/
Object : C:\WINDOWS\Favorites\Links\
Created on : 7/31/2001 4:22:22 AM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 7/31/2001 4:22:24 AM
Possible Browser Hijack attempt Object recognized!
Type : File
Data : search.url
Category : Misc
Comment : Item referrs to blacklisted Site:
http://www.searchalot.com/
Object : C:\WINDOWS\Favorites\Links\
Created on : 11/19/2002 10:18:24 PM
Last accessed : 3/29/2004 5:00:00 AM
Last modified : 11/19/2002 10:18:26 PM
Scanning Hosts file(C:\WINDOWS\hosts)
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Hosts file scan result:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
0 entries scanned.
New objects :0
Objects found so far: 37
Performing conditional scans..
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
ToolbarCC Object recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : .default\SOFTWARE\Microsoft\Internet Explorer\Registration
Value : Delta
ToolbarCC Object recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Internet Explorer\Registration
Value : Delta
PromulGate Object recognized!
Type : RegKey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Dpi
Conditional scan result:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 3
Objects found so far: 40
2:35:42 AM Scan complete
Summary of this scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Total scanning time :00:15:19:10
Objects scanned :177526
Objects identified :40
Objects ignored :0
New objects :40