Hello, I have a very big problem. When I try to download a software from internet or access some web pages my computer restarts automatically. I even try to create a new post and it just shutdowns and restart (I am using another computer to send this SOS) Please help!!!!!!!!!!!! :scratch: I tried to download an updated version of Ad Aware or Hijack this but when I try it simply restarts. thanks in advance for your help…. The Ad Aware log is: Ad-Aware SE Build 1.06r1 Logfile Created on:Sábado, 25 de Agosto de 2007 06:05:36 p.m. Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R47 24.05.2005 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» MRU List(TAC index:0):25 total references Tracking Cookie(TAC index:3):2 total references Windows(TAC index:3):2 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Ad-Aware SE Settings =========================== Set : Search for negligible risk entries Set : Search for low-risk threats Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects 08-25-2007 06:05:36 p.m. - Scan started. (Smart mode) Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] FilePath : \SystemRoot\System32\ ProcessID : 628 ThreadCreationTime : 08-25-2007 11:03:14 p.m. BasePriority : Normal #:2 [csrss.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 676 ThreadCreationTime : 08-25-2007 11:03:15 p.m. BasePriority : Normal #:3 [winlogon.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 700 ThreadCreationTime : 08-25-2007 11:03:18 p.m. BasePriority : High #:4 [services.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 744 ThreadCreationTime : 08-25-2007 11:03:18 p.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Sistema operativo Microsoft® Windows® CompanyName : Microsoft Corporation FileDescription : Aplicación de servicios y controlador InternalName : services.exe LegalCopyright : Copyright © Microsoft Corporation. Reservados todos los derechos. OriginalFilename : services.exe #:5 [lsass.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 756 ThreadCreationTime : 08-25-2007 11:03:18 p.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:6 [ati2evxx.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 932 ThreadCreationTime : 08-25-2007 11:03:19 p.m. BasePriority : Normal #:7 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 948 ThreadCreationTime : 08-25-2007 11:03:19 p.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1032 ThreadCreationTime : 08-25-2007 11:03:19 p.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:9 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1128 ThreadCreationTime : 08-25-2007 11:03:20 p.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:10 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1184 ThreadCreationTime : 08-25-2007 11:03:20 p.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:11 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1328 ThreadCreationTime : 08-25-2007 11:03:20 p.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:12 [ccsetmgr.exe] FilePath : C:\Archivos de programa\Archivos comunes\Symantec Shared\ ProcessID : 1388 ThreadCreationTime : 08-25-2007 11:03:20 p.m. BasePriority : Normal FileVersion : 2.1.6.3 ProductVersion : 2.1.6.3 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client Settings Manager Service InternalName : ccSetMgr LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccSetMgr.exe #:13 [sndsrvc.exe] FilePath : C:\Archivos de programa\Archivos comunes\Symantec Shared\ ProcessID : 1400 ThreadCreationTime : 08-25-2007 11:03:21 p.m. BasePriority : Normal FileVersion : 5.5.1.6 ProductVersion : 5.5 ProductName : Symantec Security Drivers CompanyName : Symantec Corporation FileDescription : Network Driver Service InternalName : SndSrvc LegalCopyright : Copyright 2002, 2003, 2004 Symantec Corporation OriginalFilename : SndSrvc.exe #:14 [ccevtmgr.exe] FilePath : C:\Archivos de programa\Archivos comunes\Symantec Shared\ ProcessID : 1504 ThreadCreationTime : 08-25-2007 11:03:21 p.m. BasePriority : Normal FileVersion : 2.1.6.3 ProductVersion : 2.1.6.3 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client Event Manager Service InternalName : ccEvtMgr LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccEvtMgr.exe #:15 [spoolsv.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1796 ThreadCreationTime : 08-25-2007 11:03:22 p.m. BasePriority : Normal FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) ProductVersion : 5.1.2600.2696 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : spoolsv.exe #:16 [mainserv.exe] FilePath : C:\Archivos de programa\APC\APC PowerChute Personal Edition\ ProcessID : 1908 ThreadCreationTime : 08-25-2007 11:03:28 p.m. BasePriority : Normal FileVersion : 1, 4, 0, 0 ProductVersion : 1, 4, 0, 0 ProductName : APC PowerChute Personal Edition CompanyName : American Power Conversion Corporation FileDescription : Battery backup management service InternalName : PowerChute LegalCopyright : Copyright © 2003 OriginalFilename : PowerChute Comments : Battery backup management service #:17 [ccproxy.exe] FilePath : C:\Archivos de programa\Archivos comunes\Symantec Shared\ ProcessID : 1924 ThreadCreationTime : 08-25-2007 11:03:29 p.m. BasePriority : Normal FileVersion : 2.1.6.3 ProductVersion : 2.1.6.3 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client Network Proxy Service InternalName : ccProxy LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccProxy.exe #:18 [iaantmon.exe] FilePath : C:\Archivos de programa\Intel\Intel Application Accelerator\ ProcessID : 1968 ThreadCreationTime : 08-25-2007 11:03:29 p.m. BasePriority : Normal FileVersion : 4.5.0.6515 ProductVersion : 4.5.0.6515 ProductName : Intel IAANTmon CompanyName : Intel Corporation FileDescription : Intel Application Accelerator RAID Monitor InternalName : IAANTmon LegalCopyright : Copyright© Intel Corporation 2003-04 OriginalFilename : IAANTmon.exe #:19 [mdm.exe] FilePath : C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\ ProcessID : 2004 ThreadCreationTime : 08-25-2007 11:03:29 p.m. BasePriority : Normal FileVersion : 7.00.9466 ProductVersion : 7.00.9466 ProductName : Microsoft® Visual Studio .NET CompanyName : Microsoft Corporation FileDescription : Machine Debug Manager InternalName : mdm.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : mdm.exe #:20 [sqlservr.exe] FilePath : C:\ARCHIV~1\MI6841~1\MSSQL\binn\ ProcessID : 2044 ThreadCreationTime : 08-25-2007 11:03:29 p.m. BasePriority : Normal FileVersion : 2000.080.0194.00 ProductVersion : 8.00.194 ProductName : Microsoft SQL Server CompanyName : Microsoft Corporation FileDescription : SQL Server Windows NT InternalName : SQLSERVR LegalCopyright : © 1988-2000 Microsoft Corp. All rights reserved. LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation. Windows™ is a trademark of Microsoft Corporation OriginalFilename : SQLSERVR.EXE Comments : NT INTEL X86 #:21 [navapsvc.exe] FilePath : C:\Archivos de programa\Norton Internet Security\Norton AntiVirus\ ProcessID : 284 ThreadCreationTime : 08-25-2007 11:03:32 p.m. BasePriority : Normal FileVersion : 10.00.2 ProductVersion : 10.00.2 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Auto-Protect Service InternalName : NAVAPSVC LegalCopyright : Norton AntiVirus 2004 for Windows 98/ME/2000/XP Copyright © 2003 Symantec Corporation. All rights reserved. OriginalFilename : NAVAPSVC.EXE #:22 [savscan.exe] FilePath : C:\Archivos de programa\Norton Internet Security\Norton AntiVirus\ ProcessID : 504 ThreadCreationTime : 08-25-2007 11:03:32 p.m. BasePriority : Normal ProductVersion : 9.2 ProductName : Symantec AntiVirus AutoProtect CompanyName : Symantec Corporation FileDescription : Symantec AntiVirus Scanner InternalName : SAVSCAN LegalCopyright : Copyright © 2004 Symantec Corporation OriginalFilename : SAVSCAN.EXE #:23 [explorer.exe] FilePath : C:\WINDOWS\ ProcessID : 668 ThreadCreationTime : 08-25-2007 11:03:33 p.m. BasePriority : Normal FileVersion : 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234) ProductVersion : 6.00.2900.3156 ProductName : Sistema operativo Microsoft® Windows® CompanyName : Microsoft Corporation FileDescription : Explorador de Windows InternalName : explorer LegalCopyright : © Microsoft Corporation. Reservados todos los derechos. OriginalFilename : EXPLORER.EXE #:24 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 760 ThreadCreationTime : 08-25-2007 11:03:33 p.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:25 [wdfmgr.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1168 ThreadCreationTime : 08-25-2007 11:03:34 p.m. BasePriority : Normal FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act) ProductVersion : 5.2.3790.1230 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows User Mode Driver Manager InternalName : WdfMgr LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : WdfMgr.exe #:26 [symwsc.exe] FilePath : C:\Archivos de programa\Archivos comunes\Symantec Shared\Security Center\ ProcessID : 1492 ThreadCreationTime : 08-25-2007 11:03:34 p.m. BasePriority : Normal FileVersion : 2005.1.2.20 ProductVersion : 2005.1 ProductName : Norton Security Center CompanyName : Symantec Corporation FileDescription : Norton Security Center Service InternalName : SymWSC.exe LegalCopyright : Copyright © 1997-2004 Symantec Corporation OriginalFilename : SymWSC.exe #:27 [smax4pnp.exe] FilePath : C:\Archivos de programa\Analog Devices\Core\ ProcessID : 1936 ThreadCreationTime : 08-25-2007 11:03:35 p.m. BasePriority : Normal FileVersion : 5, 2, 0, 5 ProductVersion : 5, 2, 0, 5 ProductName : SMax4PNP Application CompanyName : Analog Devices, Inc. FileDescription : SMax4PNP MFC Application InternalName : SMax4PNP LegalCopyright : Copyright © 2002-2004 Analog Devices OriginalFilename : SMax4PNP.EXE #:28 [jusched.exe] FilePath : C:\Archivos de programa\Java\j2re1.4.2_03\bin\ ProcessID : 2068 ThreadCreationTime : 08-25-2007 11:03:36 p.m. BasePriority : Normal #:29 [iaanotif.exe] FilePath : C:\Archivos de programa\Intel\Intel Application Accelerator\ ProcessID : 2076 ThreadCreationTime : 08-25-2007 11:03:36 p.m. BasePriority : Normal FileVersion : 4.5.0.6515 ProductVersion : 4.5.0.6515 ProductName : IAA RAID Event Monitor CompanyName : Intel Corporation FileDescription : IAA Event Monitor User Notification Tool InternalName : IAAnotif LegalCopyright : Copyright© Intel Corporation 2003-04 OriginalFilename : IAAnotif.exe #:30 [intelmem.exe] FilePath : C:\Archivos de programa\Intel\Modem Event Monitor\ ProcessID : 2092 ThreadCreationTime : 08-25-2007 11:03:36 p.m. BasePriority : Normal FileVersion : 0, 1, 0, 10 ProductVersion : 0, 1, 0, 10 ProductName : Intel Modem Event Monitor Application CompanyName : Intel Corporation FileDescription : Modem Event Monitor Application InternalName : Modem Event Monitor LegalCopyright : Copyright © 2003 OriginalFilename : IntelMEM.exe #:31 [dvdlauncher.exe] FilePath : C:\Archivos de programa\CyberLink\PowerDVD\ ProcessID : 2100 ThreadCreationTime : 08-25-2007 11:03:36 p.m. BasePriority : Normal FileVersion : 3.00.0000 ProductVersion : 3.00.0000 ProductName : Cyberlink PowerCinema 3.0 CompanyName : CyberLink Corp. FileDescription : CyberLink PowerCinema Resident Program InternalName : CyberLink PowerCinema Resident Program LegalCopyright : Copyright © 2003 CyberLink Corp. OriginalFilename : DVDLauncher.EXE #:32 [sgtray.exe] FilePath : C:\Archivos de programa\Archivos comunes\Sonic\Update Manager\ ProcessID : 2112 ThreadCreationTime : 08-25-2007 11:03:36 p.m. BasePriority : Normal FileVersion : 1.01.33b CompanyName : Sonic Solutions FileDescription : Sonic Update Manager LegalCopyright : Copyright © 2002 Sonic Solutions #:33 [tfswctrl.exe] FilePath : C:\WINDOWS\system32\dla\ ProcessID : 2128 ThreadCreationTime : 08-25-2007 11:03:36 p.m. BasePriority : Normal FileVersion : 1.04.08a CompanyName : Sonic Solutions FileDescription : Drive Letter Access Component LegalCopyright : Copyright © 2004 Sonic Solutions #:34 [ccapp.exe] FilePath : C:\Archivos de programa\Archivos comunes\Symantec Shared\ ProcessID : 2212 ThreadCreationTime : 08-25-2007 11:03:37 p.m. BasePriority : Normal FileVersion : 2.1.6.3 ProductVersion : 2.1.6.3 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client User Session InternalName : ccApp LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccApp.exe #:35 [hpwuschd.exe] FilePath : C:\Archivos de programa\HP\HP Software Update\ ProcessID : 2232 ThreadCreationTime : 08-25-2007 11:03:37 p.m. BasePriority : Normal FileVersion : 1, 0, 0, 3 ProductVersion : 1, 0, 0, 3 ProductName : Hewlett-Packard hpwuSchd CompanyName : Hewlett-Packard FileDescription : hpwuSchd InternalName : hpwuSchd LegalCopyright : Copyright © 2003 OriginalFilename : hpwuSchd.exe #:36 [hpcmpmgr.exe] FilePath : C:\Archivos de programa\HP\hpcoretech\ ProcessID : 2260 ThreadCreationTime : 08-25-2007 11:03:37 p.m. BasePriority : Normal FileVersion : 2.1.1.0 ProductVersion : 2.1.4 ProductName : hp coretech (COmponent REuse TECHnology) CompanyName : Hewlett-Packard Company FileDescription : HP Framework Component Manager Service InternalName : HPComponentManagerService module LegalCopyright : Copyright © Hewlett-Packard. 2002-2003 OriginalFilename : HpCmpMgr.exe #:37 [qttask.exe] FilePath : C:\Archivos de programa\QuickTime\ ProcessID : 2304 ThreadCreationTime : 08-25-2007 11:03:38 p.m. BasePriority : Normal FileVersion : 6.5.1 ProductVersion : QuickTime 6.5.1 ProductName : QuickTime CompanyName : Apple Computer, Inc. InternalName : QuickTime Task LegalCopyright : © Apple Computer, Inc. 2001-2004 OriginalFilename : QTTask.exe #:38 [ituneshelper.exe] FilePath : C:\Archivos de programa\iTunes\ ProcessID : 2344 ThreadCreationTime : 08-25-2007 11:03:38 p.m. BasePriority : Normal FileVersion : 4.7.1.30 ProductVersion : 4.7.1.30 ProductName : iTunes CompanyName : Apple Computer, Inc. FileDescription : iTunesHelper Module InternalName : iTunesHelper LegalCopyright : © 2003-2004 Apple Computer, Inc. All Rights Reserved. OriginalFilename : iTunesHelper.exe #:39 [ctfmon.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 2448 ThreadCreationTime : 08-25-2007 11:03:39 p.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : CTF Loader InternalName : CTFMON LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : CTFMON.EXE #:40 [msmsgs.exe] FilePath : C:\Archivos de programa\Messenger\ ProcessID : 2520 ThreadCreationTime : 08-25-2007 11:03:39 p.m. BasePriority : Normal FileVersion : 4.7.3001 ProductVersion : Version 4.7.3001 ProductName : Messenger CompanyName : Microsoft Corporation FileDescription : Windows Messenger InternalName : msmsgs LegalCopyright : Copyright © Microsoft Corporation 2004 LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries. OriginalFilename : msmsgs.exe #:41 [hpqtra08.exe] FilePath : C:\Archivos de programa\HP\Digital Imaging\bin\ ProcessID : 2768 ThreadCreationTime : 08-25-2007 11:03:40 p.m. BasePriority : Normal FileVersion : 5.35.0.035 ProductVersion : 005.035.000.035 ProductName : hp digital imaging - hp all-in-one series CompanyName : Hewlett-Packard Co. FileDescription : HP Digital Imaging Monitor (CUE) InternalName : HPQTRA00 LegalCopyright : Copyright © Hewlett-Packard Co. 1995-2001 OriginalFilename : HPQTRA00.EXE Comments : HP Digital Imaging Monitor (CUE) #:42 [sqlmangr.exe] FilePath : C:\Archivos de programa\Microsoft SQL Server\80\Tools\Binn\ ProcessID : 2844 ThreadCreationTime : 08-25-2007 11:03:41 p.m. BasePriority : Normal FileVersion : 2000.080.0194.00 ProductVersion : 8.00.194 ProductName : Microsoft SQL Server CompanyName : Microsoft Corporation FileDescription : SQL Server Service Manager InternalName : SQLMANGR LegalCopyright : © 1988-2000 Microsoft Corp. All rights reserved. LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation. Windows™ is a trademark of Microsoft Corporation OriginalFilename : SQLMANGR.exe Comments : NT INTEL X86 #:43 [winlogon.exe] FilePath : C:\Documents and Settings\Nidia McCarthy\Configuración local\Datos de programa\ ProcessID : 2864 ThreadCreationTime : 08-25-2007 11:03:41 p.m. BasePriority : Normal #:44 [wmiprvse.exe] FilePath : C:\WINDOWS\system32\wbem\ ProcessID : 3128 ThreadCreationTime : 08-25-2007 11:03:43 p.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : WMI InternalName : Wmiprvse.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : Wmiprvse.exe #:45 [ipodservice.exe] FilePath : C:\Archivos de programa\iPod\bin\ ProcessID : 3240 ThreadCreationTime : 08-25-2007 11:03:44 p.m. BasePriority : Normal FileVersion : 4.7.1.30 ProductVersion : 4.7.1.30 ProductName : iTunes CompanyName : Apple Computer, Inc. FileDescription : iPodService Module InternalName : iPodService LegalCopyright : © 2003-2004 Apple Computer, Inc. All Rights Reserved. OriginalFilename : iPodService.exe #:46 [alg.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 3360 ThreadCreationTime : 08-25-2007 11:03:45 p.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Application Layer Gateway Service InternalName : ALG.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ALG.exe #:47 [apcsystray.exe] FilePath : C:\Archivos de programa\APC\APC PowerChute Personal Edition\ ProcessID : 3384 ThreadCreationTime : 08-25-2007 11:03:45 p.m. BasePriority : Normal FileVersion : 1, 4, 0, 0 ProductVersion : 1, 4, 0, 0 ProductName : APC PowerChute Personal Edition CompanyName : American Power Conversion Corporation FileDescription : PowerChute system tray power icon InternalName : PowerChute LegalCopyright : Copyright © 2003 OriginalFilename : PowerChute Comments : PowerChute system tray power icon #:48 [services.exe] FilePath : C:\Documents and Settings\Nidia McCarthy\Configuración local\Datos de programa\ ProcessID : 3440 ThreadCreationTime : 08-25-2007 11:03:45 p.m. BasePriority : Normal #:49 [lsass.exe] FilePath : C:\Documents and Settings\Nidia McCarthy\Configuración local\Datos de programa\ ProcessID : 3844 ThreadCreationTime : 08-25-2007 11:03:48 p.m. BasePriority : Normal #:50 [msimn.exe] FilePath : C:\Archivos de programa\Outlook Express\ ProcessID : 4084 ThreadCreationTime : 08-25-2007 11:03:53 p.m. BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Sistema operativo Microsoft® Windows® CompanyName : Microsoft Corporation FileDescription : Outlook Express InternalName : MSIMN LegalCopyright : © 2004 Microsoft Corporation. Reservados todos los derechos. OriginalFilename : MSIMN.EXE #:51 [notepad.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 2284 ThreadCreationTime : 08-25-2007 11:04:09 p.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Sistema operativo Microsoft® Windows® CompanyName : Microsoft Corporation FileDescription : Bloc de notas InternalName : Notepad LegalCopyright : © Microsoft Corporation. Reservados todos los derechos. OriginalFilename : NOTEPAD.EXE #:52 [wuauclt.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 2856 ThreadCreationTime : 08-25-2007 11:04:20 p.m. BasePriority : Normal #:53 [ad-aware.exe] FilePath : C:\Archivos de programa\Lavasoft\Ad-Aware SE Personal\ ProcessID : 3340 ThreadCreationTime : 08-25-2007 11:05:06 p.m. BasePriority : Normal FileVersion : 6.2.0.236 ProductVersion : SE 106 ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft AB Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Windows Object Recognized! Type : RegData Data : TAC Rating : 3 Category : Vulnerability Comment : Possible unintended lockout from Registry Editor (Regedit access disabled) Rootkey : HKEY_USERS Object : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\windows\currentversion\policies\system Value : DisableRegistryTools Data : Windows Object Recognized! Type : RegData Data : explorer.exe "c:\windows\eksplorasi.exe" TAC Rating : 3 Category : Vulnerability Comment : Shell Possibly Compromised Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\windows nt\currentversion\winlogon Value : Shell Data : explorer.exe "c:\windows\eksplorasi.exe" Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 2 Objects found so far: 2 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 2 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie Object Recognized! Type : IECache Entry Data : nidia mccarthy@tribalfusion[1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:1 Value : Cookie:nidia [removed]/ Expires : 08-24-2008 04:41:56 p.m. LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : nidia [removed][1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:1 Value : Cookie:nidia [removed]/ Expires : 08-24-2011 05:40:38 p.m. LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 2 Objects found so far: 4 Deep scanning and examining files… »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 4 Disk Scan Result for C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 4 Disk Scan Result for C:\DOCUME~1\NIDIAM~1\CONFIG~1\Temp\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 4 Scanning Hosts file…… Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 1 entries scanned. New critical objects:0 Objects found so far: 4 MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\adobe\acrobat reader\6.0\avgeneral\crecentfiles Description : list of recently used files in adobe reader MRU List Object Recognized! Location: : software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct3d MRU List Object Recognized! Location: : software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct X MRU List Object Recognized! Location: : software\microsoft\directdraw\mostrecentapplication Description : most recent application to use microsoft directdraw MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\internet explorer Description : last download directory used in microsoft internet explorer MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\internet explorer\main Description : last save directory used in microsoft internet explorer MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\internet explorer\typedurls Description : list of recently entered addresses in microsoft internet explorer MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\mediaplayer\player\recentfilelist Description : list of recently used files in microsoft windows media player MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\mediaplayer\preferences Description : last playlist index loaded in microsoft windows media player MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\mediaplayer\preferences Description : last playlist loaded in microsoft windows media player MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\office\11.0\access\settings Description : list of recently opened documents in microsoft access MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\office\11.0\common\general Description : list of recently used symbols in microsoft office MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\office\11.0\powerpoint\recent file list Description : list of recent files used by microsoft powerpoint MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\office\11.0\powerpoint\recent typeface list Description : list of recently used typefaces in microsoft powerpoint MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\office\9.0\excel\recent files Description : list of recent files used by microsoft excel MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\office\9.0\powerpoint\recent file list Description : list of recent files used by microsoft powerpoint MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\office\9.0\powerpoint\recent typeface list Description : list of recently used typefaces in microsoft powerpoint MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\office\9.0\powerpoint\recentfolderlist Description : list of recent folders used by microsoft powerpoint MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\search assistant\acmru Description : list of recent search terms used with the search assistant MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\windows\currentversion\applets\regedit Description : last key accessed using the microsoft registry editor MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru Description : list of recent programs opened MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru Description : list of recently saved files, stored according to file extension MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\windows\currentversion\explorer\recentdocs Description : list of recent documents opened MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\windows\currentversion\explorer\runmru Description : mru list for items opened in start | run MRU List Object Recognized! Location: : S-1-5-21-4252116425-4008737654-514938775-1006\software\microsoft\windows media\wmsdk\general Description : windows media sdk Performing conditional scans… »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 29 06:07:10 p.m. Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:01:33.235 Objects scanned:73028 Objects identified:4 Objects ignored:0 New critical objects:4