This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack This log

56 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please down,load Kazaabegone and use uit to remove all kazaa file.

NEXT


Step #1

Please download and run Spybot 1.4 & AdAware SE Then follow the instructions in the link below to run.

Spybot & Adaware Tutorial

Step # 2

Then do a virus scan here >>> Trend Micro


Reboot and post a new HiJackThis log.
Ad-Aware SE Build 1.06r1 Logfile Created on:Monday, August 15, 2005 10:34:58 AM Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R61 10.08.2005 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Definition File: ========================= Definitions File Loaded: Reference Number : SE1R60 04.08.2005 Internal build : 70 File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref File size : 506981 Bytes Total size : 1528563 Bytes Signature data size : 1495861 Bytes Reference data size : 32190 Bytes Signatures total : 42593 CSI Fingerprints total : 1001 CSI data size : 35296 Bytes Target categories : 15 Target families : 728 8-15-2005 10:31:08 AM Performing WebUpdate… Installing Update… Definitions File Loaded: Reference Number : SE1R61 10.08.2005 Internal build : 71 File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref File size : 508229 Bytes Total size : 1531791 Bytes Signature data size : 1498915 Bytes Reference data size : 32364 Bytes Signatures total : 42681 CSI Fingerprints total : 1003 CSI data size : 35408 Bytes Target categories : 15 Target families : 729 8-15-2005 10:31:15 AM Success Update successfully downloaded and installed. Memory + processor status: ========================== Number of processors : 1 Processor architecture : Intel Pentium IV Memory available:46 % Total physical memory:523568 kb Available physical memory:240488 kb Total page file size:1279452 kb Available on page file:1020904 kb Total virtual memory:2097024 kb Available virtual memory:2042500 kb OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600) Ad-Aware SE Settings =========================== Set : Search for low-risk threats Set : Move deleted files to Recycle Bin Set : Safe mode (always request confirmation) Set : Don't log streams smaller than 0 Bytes Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan within archives Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Scan registry for all users instead of current user only Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Play sound at scan completion if scan locates critical objects 8-15-2005 10:34:58 AM - Scan started. (Full System Scan) Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] FilePath : \SystemRoot\System32\ ProcessID : 652 ThreadCreationTime : 8-15-2005 3:19:10 PM BasePriority : Normal #:2 [csrss.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 756 ThreadCreationTime : 8-15-2005 3:19:14 PM BasePriority : Normal #:3 [winlogon.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 780 ThreadCreationTime : 8-15-2005 3:19:15 PM BasePriority : High #:4 [services.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 828 ThreadCreationTime : 8-15-2005 3:19:15 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : services.exe #:5 [lsass.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 840 ThreadCreationTime : 8-15-2005 3:19:15 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:6 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1000 ThreadCreationTime : 8-15-2005 3:19:16 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:7 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1068 ThreadCreationTime : 8-15-2005 3:19:16 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1164 ThreadCreationTime : 8-15-2005 3:19:16 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:9 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1228 ThreadCreationTime : 8-15-2005 3:19:16 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:10 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1364 ThreadCreationTime : 8-15-2005 3:19:17 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:11 [ccproxy.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1476 ThreadCreationTime : 8-15-2005 3:19:17 PM BasePriority : Normal FileVersion : 103.0.4.3 ProductVersion : 103.0.4.3 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Network Proxy Service InternalName : ccProxy LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccProxy.exe #:12 [ccsetmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1492 ThreadCreationTime : 8-15-2005 3:19:17 PM BasePriority : Normal FileVersion : 103.0.4.3 ProductVersion : 103.0.4.3 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Settings Manager Service InternalName : ccSetMgr LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccSetMgr.exe #:13 [issvc.exe] FilePath : C:\Program Files\Norton Internet Security\ ProcessID : 1504 ThreadCreationTime : 8-15-2005 3:19:17 PM BasePriority : Normal FileVersion : 8.0.2.5 ProductVersion : 8.0 ProductName : Norton Internet Security CompanyName : Symantec Corporation FileDescription : IS Service InternalName : ISSVC.exe LegalCopyright : Copyright © 2004 Symantec Corporation OriginalFilename : ISSVC.exe #:14 [sndsrvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1516 ThreadCreationTime : 8-15-2005 3:19:18 PM BasePriority : Normal FileVersion : 5.5.1.6 ProductVersion : 5.5 ProductName : Symantec Security Drivers CompanyName : Symantec Corporation FileDescription : Network Driver Service InternalName : SndSrvc LegalCopyright : Copyright 2002, 2003, 2004 Symantec Corporation OriginalFilename : SndSrvc.exe #:15 [spbbcsvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\SPBBC\ ProcessID : 1548 ThreadCreationTime : 8-15-2005 3:19:18 PM BasePriority : Normal FileVersion : 1,0,1,47 ProductVersion : 1,0,1,47 ProductName : SPBBC CompanyName : Symantec Corporation FileDescription : SPBBC Service InternalName : SPBBCSvc LegalCopyright : Copyright © 2004 Symantec Corporation. All rights reserved. OriginalFilename : SPBBCSvc.exe #:16 [ccevtmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1828 ThreadCreationTime : 8-15-2005 3:19:28 PM BasePriority : Normal FileVersion : 103.0.4.3 ProductVersion : 103.0.4.3 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Event Manager Service InternalName : ccEvtMgr LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccEvtMgr.exe #:17 [spoolsv.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 200 ThreadCreationTime : 8-15-2005 3:19:30 PM BasePriority : Normal FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) ProductVersion : 5.1.2600.2696 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : spoolsv.exe #:18 [ewidoctrl.exe] FilePath : C:\Program Files\ewido\security suite\ ProcessID : 472 ThreadCreationTime : 8-15-2005 3:19:36 PM BasePriority : Normal FileVersion : 3, 0, 0, 1 ProductVersion : 3, 0, 0, 1 ProductName : ewido control CompanyName : ewido networks FileDescription : ewido control InternalName : ewido control LegalCopyright : Copyright © 2004 OriginalFilename : ewidoctrl.exe #:19 [ewidoguard.exe] FilePath : C:\Program Files\ewido\security suite\ ProcessID : 484 ThreadCreationTime : 8-15-2005 3:19:36 PM BasePriority : Normal FileVersion : 3, 0, 0, 1 ProductVersion : 3, 0, 0, 1 ProductName : guard CompanyName : ewido networks FileDescription : guard InternalName : guard LegalCopyright : Copyright © 2004 OriginalFilename : guard.exe #:20 [appservices.exe] FilePath : C:\PROGRA~1\Iomega\System32\ ProcessID : 512 ThreadCreationTime : 8-15-2005 3:19:36 PM BasePriority : Normal FileVersion : 2, 0, 4, 2 ProductVersion : 2, 0, 4, 2 ProductName : Iomega App Services CompanyName : Iomega Corporation FileDescription : AppServices InternalName : AppServices LegalCopyright : Copyright © 2003 OriginalFilename : AppService.exe Comments : Iomega App Services For Windows NT/2000/XP #:21 [navapsvc.exe] FilePath : C:\Program Files\Norton Internet Security\Norton AntiVirus\ ProcessID : 568 ThreadCreationTime : 8-15-2005 3:19:36 PM BasePriority : Normal FileVersion : 11.0.9.16 ProductVersion : 11.0.9 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Auto-Protect Service InternalName : NAVAPSVC LegalCopyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright © 2004 Symantec Corporation. All rights reserved. OriginalFilename : NAVAPSVC.EXE #:22 [nvsvc32.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 600 ThreadCreationTime : 8-15-2005 3:19:36 PM BasePriority : Normal FileVersion : 6.14.10.4523 ProductVersion : 6.14.10.4523 ProductName : NVIDIA Driver Helper Service, Version 45.23 CompanyName : NVIDIA Corporation FileDescription : NVIDIA Driver Helper Service, Version 45.23 InternalName : NVSVC LegalCopyright : © NVIDIA Corporation. All rights reserved. OriginalFilename : nvsvc32.exe #:23 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1028 ThreadCreationTime : 8-15-2005 3:19:40 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:24 [symlcsvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\ ProcessID : 1132 ThreadCreationTime : 8-15-2005 3:19:41 PM BasePriority : Normal FileVersion : 1, 8, 54, 478 ProductVersion : 1, 8, 54, 478 ProductName : Symantec Core Component CompanyName : Symantec Corporation FileDescription : Symantec Core Component InternalName : symlcsvc LegalCopyright : Copyright © 2003 OriginalFilename : symlcsvc.exe #:25 [wdfmgr.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1220 ThreadCreationTime : 8-15-2005 3:19:41 PM BasePriority : Normal FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act) ProductVersion : 5.2.3790.1230 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows User Mode Driver Manager InternalName : WdfMgr LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : WdfMgr.exe #:26 [alg.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 108 ThreadCreationTime : 8-15-2005 3:19:56 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Application Layer Gateway Service InternalName : ALG.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ALG.exe #:27 [explorer.exe] FilePath : C:\WINDOWS\ ProcessID : 3968 ThreadCreationTime : 8-15-2005 3:29:27 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE #:28 [cthelper.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 4036 ThreadCreationTime : 8-15-2005 3:29:31 PM BasePriority : Normal FileVersion : 1, 0, 0, 1 ProductVersion : 1, 0, 0, 1 ProductName : cthelper CompanyName : Creative Technology Ltd FileDescription : cthelper InternalName : cthelper LegalCopyright : Copyright © 2002 OriginalFilename : cthelper.exe #:29 [sk9910dm.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 4064 ThreadCreationTime : 8-15-2005 3:29:33 PM BasePriority : Normal FileVersion : 1, 0, 9, 0 CompanyName : Silitek Corporation FileDescription : Daemon LegalCopyright : Copyright © Silitek Corp. 1999, 2000 #:30 [ccapp.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 124 ThreadCreationTime : 8-15-2005 3:29:34 PM BasePriority : Normal FileVersion : 103.0.4.3 ProductVersion : 103.0.4.3 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec User Session InternalName : ccApp LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccApp.exe #:31 [gcasdtserv.exe] FilePath : C:\Program Files\Microsoft AntiSpyware\ ProcessID : 1456 ThreadCreationTime : 8-15-2005 3:29:41 PM BasePriority : Normal FileVersion : 1.00.0501 ProductVersion : 1.00.0501 ProductName : Microsoft AntiSpyware (Beta 1) CompanyName : Microsoft Corporation FileDescription : Microsoft AntiSpyware Data Service InternalName : gcasDtServ LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved. LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet™ is a trademark of Microsoft Corporation. OriginalFilename : gcasDtServ.exe #:32 [acctmgr.exe] FilePath : C:\Program Files\Norton Password Manager\ ProcessID : 1396 ThreadCreationTime : 8-15-2005 3:29:42 PM BasePriority : Normal FileVersion : 2004.1.406 ProductVersion : 2004.1.406 ProductName : Norton Password Manager CompanyName : Symantec Corporation FileDescription : Password Manager Controller InternalName : AcctMgr LegalCopyright : Copyright © 2003-2004 Symantec Corporation OriginalFilename : AcctMgr.EXE #:33 [qttask.exe] FilePath : C:\Program Files\QuickTime\ ProcessID : 2684 ThreadCreationTime : 8-15-2005 3:30:05 PM BasePriority : Normal FileVersion : 6.5.1 ProductVersion : QuickTime 6.5.1 ProductName : QuickTime CompanyName : Apple Computer, Inc. InternalName : QuickTime Task LegalCopyright : © Apple Computer, Inc. 2001-2004 OriginalFilename : QTTask.exe #:34 [msmsgs.exe] FilePath : C:\Program Files\Messenger\ ProcessID : 3288 ThreadCreationTime : 8-15-2005 3:30:20 PM BasePriority : Normal FileVersion : 4.7.3001 ProductVersion : Version 4.7.3001 ProductName : Messenger CompanyName : Microsoft Corporation FileDescription : Windows Messenger InternalName : msmsgs LegalCopyright : Copyright © Microsoft Corporation 2004 LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries. OriginalFilename : msmsgs.exe #:35 [autolaunch.exe] FilePath : C:\Program Files\Iomega HotBurn Pro\ ProcessID : 3836 ThreadCreationTime : 8-15-2005 3:30:29 PM BasePriority : Normal FileVersion : 1.8 ProductVersion : 1.8 ProductName : Iomega HotBurn CompanyName : Iomega Corporation FileDescription : Iomega HotBurn Auto Launch Program InternalName : AutoLaunch LegalCopyright : Copyright © 2001-2002 Iomega Corporation LegalTrademarks : HOTBURN OriginalFilename : Autolaunch.exe Comments : HotBurn AutoLaunch Program #:36 [ezdmontr.exe] FilePath : C:\Program Files\Quik Touch\ ProcessID : 3848 ThreadCreationTime : 8-15-2005 3:30:29 PM BasePriority : Normal FileVersion : 0.9.9.0 ProductVersion : 0.9.9.0 ProductName : Emuzed Record Monitor CompanyName : Emuzed, Inc. FileDescription : EzdMontr manages QuikTouch launch of DVD Capture/Burn Software InternalName : EzdMontr.exe LegalCopyright : Copyright © 2003 Emuzed, Inc. All rights reserved. OriginalFilename : EzdMontr.exe #:37 [drgtodsc.exe] FilePath : C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\ ProcessID : 3924 ThreadCreationTime : 8-15-2005 3:30:33 PM BasePriority : Normal FileVersion : 7.5.0.47 ProductVersion : 7.5.0.47 ProductName : Drag-to-Disc CompanyName : Sonic Solutions FileDescription : Drag To Disc Application InternalName : D2D LegalCopyright : Copyright © 1994-2005 Sonic Solutions LegalTrademarks : Copyright © 1994-2005 Sonic Solutions OriginalFilename : BurnCtrl.EXE #:38 [sm1bg.exe] FilePath : C:\WINDOWS\ ProcessID : 3872 ThreadCreationTime : 8-15-2005 3:30:34 PM BasePriority : Normal FileVersion : 6.01.1000.0 ProductVersion : 6.01.1000.0 ProductName : Cypress USB Mass Storage Adapter CompanyName : Cypress Semiconductor FileDescription : Cypress USB Mass Storage Driver Background Application InternalName : SM1BG.EXE LegalCopyright : Copyright © 1998-2003 Cypress Semiconductor OriginalFilename : SM1BG.EXE #:39 [realsched.exe] FilePath : C:\Program Files\Common Files\Real\Update_OB\ ProcessID : 316 ThreadCreationTime : 8-15-2005 3:30:36 PM BasePriority : Normal FileVersion : 0.1.0.3275 ProductVersion : 0.1.0.3275 ProductName : RealPlayer (32-bit) CompanyName : RealNetworks, Inc. FileDescription : RealNetworks Scheduler InternalName : schedapp LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004 LegalTrademarks : RealAudio™ is a trademark of RealNetworks, Inc. OriginalFilename : realsched.exe #:40 [issch.exe] FilePath : C:\Program Files\Common Files\InstallShield\UpdateService\ ProcessID : 1812 ThreadCreationTime : 8-15-2005 3:30:38 PM BasePriority : Normal FileVersion : 3, 10, 100, 1155 ProductVersion : 3, 10 ProductName : InstallShield Update Service CompanyName : InstallShield Software Corporation FileDescription : InstallShield Update Service Scheduler InternalName : Scheduler LegalCopyright : Copyright © 1990-2004 InstallShield Software Corporation OriginalFilename : issch.exe #:41 [ituneshelper.exe] FilePath : C:\Program Files\iTunes\ ProcessID : 192 ThreadCreationTime : 8-15-2005 3:30:40 PM BasePriority : Normal FileVersion : 4.9.0.17 ProductVersion : 4.9.0.17 ProductName : iTunes CompanyName : Apple Computer, Inc. FileDescription : iTunesHelper Module InternalName : iTunesHelper LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved. OriginalFilename : iTunesHelper.exe #:42 [ipodservice.exe] FilePath : C:\Program Files\iPod\bin\ ProcessID : 1292 ThreadCreationTime : 8-15-2005 3:30:42 PM BasePriority : Normal FileVersion : 4.9.0.17 ProductVersion : 4.9.0.17 ProductName : iTunes CompanyName : Apple Computer, Inc. FileDescription : iPodService Module InternalName : iPodService LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved. OriginalFilename : iPodService.exe #:43 [wzqkpick.exe] FilePath : C:\Program Files\WinZip\ ProcessID : 624 ThreadCreationTime : 8-15-2005 3:30:45 PM BasePriority : Normal FileVersion : 1.0 (32-bit) ProductVersion : 9.0 (6028) ProductName : WinZip CompanyName : WinZip Computing, Inc. FileDescription : WinZip Executable InternalName : WZQKPICK.EXE LegalCopyright : Copyright © WinZip Computing, Inc. 1991-2004 - All Rights Reserved LegalTrademarks : WinZip is a registered trademark of WinZip Computing, Inc OriginalFilename : WZQKPICK.EXE Comments : StringFileInfo: U.S. English #:44 [ad-aware.exe] FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\ ProcessID : 2576 ThreadCreationTime : 8-15-2005 3:30:52 PM BasePriority : Normal FileVersion : 6.2.0.236 ProductVersion : SE 106 ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft AB Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 8-14-2006 4:09:14 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : juli@2o7[1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:70 Value : Cookie:[removed]/ Expires : 8-14-2010 8:00:34 AM LastSync : Hits:70 UseCount : 0 Hits : 70 Tracking Cookie Object Recognized! Type : IECache Entry Data : juli@statcounter[2].txt TAC Rating : 3 Category : Data Miner Comment : Hits:5 Value : Cookie:[removed]/ Expires : 8-13-2010 1:18:42 PM LastSync : Hits:5 UseCount : 0 Hits : 5 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 8-19-2005 6:21:42 AM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : juli@apmebf[1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:2 Value : Cookie:[removed]/ Expires : 8-12-2010 8:38:44 AM LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking Cookie Object Recognized! Type : IECache Entry Data : juli@realmedia[2].txt TAC Rating : 3 Category : Data Miner Comment : Hits:5 Value : Cookie:[removed]/ Expires : 12-31-2020 7:00:00 PM LastSync : Hits:5 UseCount : 0 Hits : 5 Tracking Cookie Object Recognized! Type : IECache Entry Data : juli@live365[1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 8-18-2010 10:54:42 AM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:2 Value : Cookie:[removed]/ Expires : 12-30-2037 11:00:00 AM LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 8 Objects found so far: 8 Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 8 Deep scanning and examining files (D:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for D:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 8 Scanning Hosts file…… Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 1 entries scanned. New critical objects:0 Objects found so far: 8 Performing conditional scans… »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 8 10:49:48 AM Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:14:49.657 Objects scanned:181938 Objects identified:8 Objects ignored:0 New critical objects:8 Here you go. thanks again.
Ad-Aware SE Build 1.06r1 Logfile Created on:Wednesday, August 17, 2005 6:56:22 PM Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R62 17.08.2005 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Definition File: ========================= Definitions File Loaded: Reference Number : SE1R62 17.08.2005 Internal build : 72 File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref File size : 509965 Bytes Total size : 1536749 Bytes Signature data size : 1503983 Bytes Reference data size : 32254 Bytes Signatures total : 42805 CSI Fingerprints total : 1012 CSI data size : 35821 Bytes Target categories : 15 Target families : 731 Memory + processor status: ========================== Number of processors : 1 Processor architecture : Intel Pentium IV Memory available:46 % Total physical memory:523568 kb Available physical memory:238664 kb Total page file size:1279452 kb Available on page file:1014168 kb Total virtual memory:2097024 kb Available virtual memory:2042680 kb OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600) Ad-Aware SE Settings =========================== Set : Search for low-risk threats Set : Move deleted files to Recycle Bin Set : Safe mode (always request confirmation) Set : Don't log streams smaller than 0 Bytes Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan within archives Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Scan registry for all users instead of current user only Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Play sound at scan completion if scan locates critical objects 8-17-2005 6:56:22 PM - Scan started. (Full System Scan) Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] FilePath : \SystemRoot\System32\ ProcessID : 648 ThreadCreationTime : 8-17-2005 11:51:43 PM BasePriority : Normal #:2 [csrss.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 736 ThreadCreationTime : 8-17-2005 11:51:47 PM BasePriority : Normal #:3 [winlogon.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 760 ThreadCreationTime : 8-17-2005 11:51:48 PM BasePriority : High #:4 [services.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 808 ThreadCreationTime : 8-17-2005 11:51:48 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : services.exe #:5 [lsass.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 820 ThreadCreationTime : 8-17-2005 11:51:48 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:6 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 980 ThreadCreationTime : 8-17-2005 11:51:49 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:7 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1048 ThreadCreationTime : 8-17-2005 11:51:49 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1144 ThreadCreationTime : 8-17-2005 11:51:49 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:9 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1224 ThreadCreationTime : 8-17-2005 11:51:50 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:10 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1364 ThreadCreationTime : 8-17-2005 11:51:50 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:11 [ccproxy.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1456 ThreadCreationTime : 8-17-2005 11:51:50 PM BasePriority : Normal FileVersion : 103.0.4.3 ProductVersion : 103.0.4.3 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Network Proxy Service InternalName : ccProxy LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccProxy.exe #:12 [ccsetmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1472 ThreadCreationTime : 8-17-2005 11:51:50 PM BasePriority : Normal FileVersion : 103.0.4.3 ProductVersion : 103.0.4.3 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Settings Manager Service InternalName : ccSetMgr LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccSetMgr.exe #:13 [issvc.exe] FilePath : C:\Program Files\Norton Internet Security\ ProcessID : 1484 ThreadCreationTime : 8-17-2005 11:51:51 PM BasePriority : Normal FileVersion : 8.0.2.5 ProductVersion : 8.0 ProductName : Norton Internet Security CompanyName : Symantec Corporation FileDescription : IS Service InternalName : ISSVC.exe LegalCopyright : Copyright © 2004 Symantec Corporation OriginalFilename : ISSVC.exe #:14 [sndsrvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1496 ThreadCreationTime : 8-17-2005 11:51:51 PM BasePriority : Normal FileVersion : 5.5.1.6 ProductVersion : 5.5 ProductName : Symantec Security Drivers CompanyName : Symantec Corporation FileDescription : Network Driver Service InternalName : SndSrvc LegalCopyright : Copyright 2002, 2003, 2004 Symantec Corporation OriginalFilename : SndSrvc.exe #:15 [spbbcsvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\SPBBC\ ProcessID : 1532 ThreadCreationTime : 8-17-2005 11:51:51 PM BasePriority : Normal FileVersion : 1,0,1,47 ProductVersion : 1,0,1,47 ProductName : SPBBC CompanyName : Symantec Corporation FileDescription : SPBBC Service InternalName : SPBBCSvc LegalCopyright : Copyright © 2004 Symantec Corporation. All rights reserved. OriginalFilename : SPBBCSvc.exe #:16 [explorer.exe] FilePath : C:\WINDOWS\ ProcessID : 1900 ThreadCreationTime : 8-17-2005 11:51:55 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE #:17 [ccevtmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 2036 ThreadCreationTime : 8-17-2005 11:52:06 PM BasePriority : Normal FileVersion : 103.0.4.3 ProductVersion : 103.0.4.3 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Event Manager Service InternalName : ccEvtMgr LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccEvtMgr.exe #:18 [spoolsv.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 484 ThreadCreationTime : 8-17-2005 11:52:08 PM BasePriority : Normal FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) ProductVersion : 5.1.2600.2696 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : spoolsv.exe #:19 [ewidoctrl.exe] FilePath : C:\Program Files\ewido\security suite\ ProcessID : 1176 ThreadCreationTime : 8-17-2005 11:52:14 PM BasePriority : Normal FileVersion : 3, 0, 0, 1 ProductVersion : 3, 0, 0, 1 ProductName : ewido control CompanyName : ewido networks FileDescription : ewido control InternalName : ewido control LegalCopyright : Copyright © 2004 OriginalFilename : ewidoctrl.exe #:20 [ewidoguard.exe] FilePath : C:\Program Files\ewido\security suite\ ProcessID : 1244 ThreadCreationTime : 8-17-2005 11:52:14 PM BasePriority : Normal FileVersion : 3, 0, 0, 1 ProductVersion : 3, 0, 0, 1 ProductName : guard CompanyName : ewido networks FileDescription : guard InternalName : guard LegalCopyright : Copyright © 2004 OriginalFilename : guard.exe #:21 [appservices.exe] FilePath : C:\PROGRA~1\Iomega\System32\ ProcessID : 1292 ThreadCreationTime : 8-17-2005 11:52:14 PM BasePriority : Normal FileVersion : 2, 0, 4, 2 ProductVersion : 2, 0, 4, 2 ProductName : Iomega App Services CompanyName : Iomega Corporation FileDescription : AppServices InternalName : AppServices LegalCopyright : Copyright © 2003 OriginalFilename : AppService.exe Comments : Iomega App Services For Windows NT/2000/XP #:22 [navapsvc.exe] FilePath : C:\Program Files\Norton Internet Security\Norton AntiVirus\ ProcessID : 1332 ThreadCreationTime : 8-17-2005 11:52:14 PM BasePriority : Normal FileVersion : 11.0.9.16 ProductVersion : 11.0.9 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Auto-Protect Service InternalName : NAVAPSVC LegalCopyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright © 2004 Symantec Corporation. All rights reserved. OriginalFilename : NAVAPSVC.EXE #:23 [nvsvc32.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1524 ThreadCreationTime : 8-17-2005 11:52:18 PM BasePriority : Normal FileVersion : 6.14.10.4523 ProductVersion : 6.14.10.4523 ProductName : NVIDIA Driver Helper Service, Version 45.23 CompanyName : NVIDIA Corporation FileDescription : NVIDIA Driver Helper Service, Version 45.23 InternalName : NVSVC LegalCopyright : © NVIDIA Corporation. All rights reserved. OriginalFilename : nvsvc32.exe #:24 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1704 ThreadCreationTime : 8-17-2005 11:52:19 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:25 [symlcsvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\ ProcessID : 1752 ThreadCreationTime : 8-17-2005 11:52:19 PM BasePriority : Normal FileVersion : 1, 8, 54, 478 ProductVersion : 1, 8, 54, 478 ProductName : Symantec Core Component CompanyName : Symantec Corporation FileDescription : Symantec Core Component InternalName : symlcsvc LegalCopyright : Copyright © 2003 OriginalFilename : symlcsvc.exe #:26 [wdfmgr.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1780 ThreadCreationTime : 8-17-2005 11:52:19 PM BasePriority : Normal FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act) ProductVersion : 5.2.3790.1230 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows User Mode Driver Manager InternalName : WdfMgr LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : WdfMgr.exe #:27 [alg.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 2132 ThreadCreationTime : 8-17-2005 11:52:42 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Application Layer Gateway Service InternalName : ALG.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ALG.exe #:28 [cthelper.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 2148 ThreadCreationTime : 8-17-2005 11:52:43 PM BasePriority : Normal FileVersion : 1, 0, 0, 1 ProductVersion : 1, 0, 0, 1 ProductName : cthelper CompanyName : Creative Technology Ltd FileDescription : cthelper InternalName : cthelper LegalCopyright : Copyright © 2002 OriginalFilename : cthelper.exe #:29 [sk9910dm.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 2280 ThreadCreationTime : 8-17-2005 11:52:47 PM BasePriority : Normal FileVersion : 1, 0, 9, 0 CompanyName : Silitek Corporation FileDescription : Daemon LegalCopyright : Copyright © Silitek Corp. 1999, 2000 #:30 [ccapp.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 2684 ThreadCreationTime : 8-17-2005 11:52:52 PM BasePriority : Normal FileVersion : 103.0.4.3 ProductVersion : 103.0.4.3 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec User Session InternalName : ccApp LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccApp.exe #:31 [acctmgr.exe] FilePath : C:\Program Files\Norton Password Manager\ ProcessID : 2776 ThreadCreationTime : 8-17-2005 11:52:54 PM BasePriority : Normal FileVersion : 2004.1.406 ProductVersion : 2004.1.406 ProductName : Norton Password Manager CompanyName : Symantec Corporation FileDescription : Password Manager Controller InternalName : AcctMgr LegalCopyright : Copyright © 2003-2004 Symantec Corporation OriginalFilename : AcctMgr.EXE #:32 [gcasdtserv.exe] FilePath : C:\Program Files\Microsoft AntiSpyware\ ProcessID : 2792 ThreadCreationTime : 8-17-2005 11:52:54 PM BasePriority : Normal FileVersion : 1.00.0501 ProductVersion : 1.00.0501 ProductName : Microsoft AntiSpyware (Beta 1) CompanyName : Microsoft Corporation FileDescription : Microsoft AntiSpyware Data Service InternalName : gcasDtServ LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved. LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet™ is a trademark of Microsoft Corporation. OriginalFilename : gcasDtServ.exe #:33 [qttask.exe] FilePath : C:\Program Files\QuickTime\ ProcessID : 2880 ThreadCreationTime : 8-17-2005 11:52:56 PM BasePriority : Normal FileVersion : 6.5.1 ProductVersion : QuickTime 6.5.1 ProductName : QuickTime CompanyName : Apple Computer, Inc. InternalName : QuickTime Task LegalCopyright : © Apple Computer, Inc. 2001-2004 OriginalFilename : QTTask.exe #:34 [wuauclt.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 3640 ThreadCreationTime : 8-17-2005 11:53:19 PM BasePriority : Normal FileVersion : 5.8.0.2469 built by: lab01_n(wmbla) ProductVersion : 5.8.0.2469 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Automatic Updates InternalName : wuauclt.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : wuauclt.exe #:35 [msmsgs.exe] FilePath : C:\Program Files\Messenger\ ProcessID : 4036 ThreadCreationTime : 8-17-2005 11:53:28 PM BasePriority : Normal FileVersion : 4.7.3001 ProductVersion : Version 4.7.3001 ProductName : Messenger CompanyName : Microsoft Corporation FileDescription : Windows Messenger InternalName : msmsgs LegalCopyright : Copyright © Microsoft Corporation 2004 LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries. OriginalFilename : msmsgs.exe #:36 [autolaunch.exe] FilePath : C:\Program Files\Iomega HotBurn Pro\ ProcessID : 2468 ThreadCreationTime : 8-17-2005 11:53:45 PM BasePriority : Normal FileVersion : 1.8 ProductVersion : 1.8 ProductName : Iomega HotBurn CompanyName : Iomega Corporation FileDescription : Iomega HotBurn Auto Launch Program InternalName : AutoLaunch LegalCopyright : Copyright © 2001-2002 Iomega Corporation LegalTrademarks : HOTBURN OriginalFilename : Autolaunch.exe Comments : HotBurn AutoLaunch Program #:37 [ezdmontr.exe] FilePath : C:\Program Files\Quik Touch\ ProcessID : 2484 ThreadCreationTime : 8-17-2005 11:53:46 PM BasePriority : Normal FileVersion : 0.9.9.0 ProductVersion : 0.9.9.0 ProductName : Emuzed Record Monitor CompanyName : Emuzed, Inc. FileDescription : EzdMontr manages QuikTouch launch of DVD Capture/Burn Software InternalName : EzdMontr.exe LegalCopyright : Copyright © 2003 Emuzed, Inc. All rights reserved. OriginalFilename : EzdMontr.exe #:38 [drgtodsc.exe] FilePath : C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\ ProcessID : 1620 ThreadCreationTime : 8-17-2005 11:53:46 PM BasePriority : Normal FileVersion : 7.5.0.47 ProductVersion : 7.5.0.47 ProductName : Drag-to-Disc CompanyName : Sonic Solutions FileDescription : Drag To Disc Application InternalName : D2D LegalCopyright : Copyright © 1994-2005 Sonic Solutions LegalTrademarks : Copyright © 1994-2005 Sonic Solutions OriginalFilename : BurnCtrl.EXE #:39 [sm1bg.exe] FilePath : C:\WINDOWS\ ProcessID : 2560 ThreadCreationTime : 8-17-2005 11:53:47 PM BasePriority : Normal FileVersion : 6.01.1000.0 ProductVersion : 6.01.1000.0 ProductName : Cypress USB Mass Storage Adapter CompanyName : Cypress Semiconductor FileDescription : Cypress USB Mass Storage Driver Background Application InternalName : SM1BG.EXE LegalCopyright : Copyright © 1998-2003 Cypress Semiconductor OriginalFilename : SM1BG.EXE #:40 [realsched.exe] FilePath : C:\Program Files\Common Files\Real\Update_OB\ ProcessID : 2660 ThreadCreationTime : 8-17-2005 11:53:49 PM BasePriority : Normal FileVersion : 0.1.0.3275 ProductVersion : 0.1.0.3275 ProductName : RealPlayer (32-bit) CompanyName : RealNetworks, Inc. FileDescription : RealNetworks Scheduler InternalName : schedapp LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004 LegalTrademarks : RealAudio™ is a trademark of RealNetworks, Inc. OriginalFilename : realsched.exe #:41 [issch.exe] FilePath : C:\Program Files\Common Files\InstallShield\UpdateService\ ProcessID : 2860 ThreadCreationTime : 8-17-2005 11:53:52 PM BasePriority : Normal FileVersion : 3, 10, 100, 1155 ProductVersion : 3, 10 ProductName : InstallShield Update Service CompanyName : InstallShield Software Corporation FileDescription : InstallShield Update Service Scheduler InternalName : Scheduler LegalCopyright : Copyright © 1990-2004 InstallShield Software Corporation OriginalFilename : issch.exe #:42 [ituneshelper.exe] FilePath : C:\Program Files\iTunes\ ProcessID : 2924 ThreadCreationTime : 8-17-2005 11:53:54 PM BasePriority : Normal FileVersion : 4.9.0.17 ProductVersion : 4.9.0.17 ProductName : iTunes CompanyName : Apple Computer, Inc. FileDescription : iTunesHelper Module InternalName : iTunesHelper LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved. OriginalFilename : iTunesHelper.exe #:43 [ipodservice.exe] FilePath : C:\Program Files\iPod\bin\ ProcessID : 3128 ThreadCreationTime : 8-17-2005 11:53:57 PM BasePriority : Normal FileVersion : 4.9.0.17 ProductVersion : 4.9.0.17 ProductName : iTunes CompanyName : Apple Computer, Inc. FileDescription : iPodService Module InternalName : iPodService LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved. OriginalFilename : iPodService.exe #:44 [wzqkpick.exe] FilePath : C:\Program Files\WinZip\ ProcessID : 3312 ThreadCreationTime : 8-17-2005 11:54:00 PM BasePriority : Normal FileVersion : 1.0 (32-bit) ProductVersion : 9.0 (6028) ProductName : WinZip CompanyName : WinZip Computing, Inc. FileDescription : WinZip Executable InternalName : WZQKPICK.EXE LegalCopyright : Copyright © WinZip Computing, Inc. 1991-2004 - All Rights Reserved LegalTrademarks : WinZip is a registered trademark of WinZip Computing, Inc OriginalFilename : WZQKPICK.EXE Comments : StringFileInfo: U.S. English #:45 [ad-aware.exe] FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\ ProcessID : 3500 ThreadCreationTime : 8-17-2005 11:54:07 PM BasePriority : Normal FileVersion : 6.2.0.236 ProductVersion : SE 106 ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft AB Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie Object Recognized! Type : IECache Entry Data : juli@2o7[2].txt TAC Rating : 3 Category : Data Miner Comment : Hits:4 Value : Cookie:[removed]/ Tracking Cookie Object Recognized! Type : IECache Entry Data : juli@statcounter[1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 2 Objects found so far: 2 Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 2 Deep scanning and examining files (D:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for D:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 2 Scanning Hosts file…… Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 1 entries scanned. New critical objects:0 Objects found so far: 2 Performing conditional scans… »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 2 7:11:26 PM Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:15:03.953 Objects scanned:185699 Objects identified:2 Objects ignored:0 New critical objects:2 Sorry, I thought it changed automatically.
Logfile of HijackThis v1.99.1
Scan saved at 8:28:24 PM, on 8/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\SK9910DM.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Norton Password Manager\AcctMgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Iomega HotBurn Pro\Autolaunch.exe
C:\Program Files\Quik Touch\EzdMontr.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\PROGRA~1\MICROS~3\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\OPScan.exe
C:\Documents and Settings\Juli\Desktop\highjackthis\HijackThis.exe

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Juli\Application Data\Mozilla\Profiles\default\b7flcck4.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [EzdMontr] C:\Program Files\Quik Touch\EzdMontr.exe install
O4 - HKLM\..\Run: [Drag'n'Drop_Autolaunch] "C:\Program Files\Iomega HotBurn Pro\Autolaunch.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .xml: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O16 - DPF: {3299935F-2C5A-499A-9908-95CFFF6EF8C1} (Quicksilver Class) - http://scpwob.ops.placeware.com/etc/place/…quicksilver.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120150319530
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.walgreensphotocenter.com/upload…ploadClient.cab
O16 - DPF: {E6EB803E-DD89-11D3-80C4-0050DA2E09D0} (LightSurfUploadCtl Class) - http://prints.picturecenter.kodak.com/acti…loadControl.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe



OK, how's this?
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI