this a lof from adware se 1.04 ok can u guys tell me what to do!!!!
Ad-Aware SE Build 1.04
Logfile Created on:Wednesday, September 08, 2004 3:25:28 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R7 06.09.2004
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
CoolWebSearch(TAC index:10):105 total references
Other(TAC index:5):4 total references
Possible Browser Hijack attempt(TAC index:3):3 total references
Tracking Cookie(TAC index:3):1 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
9-8-2004 3:25:28 PM - Scan started. (Full System Scan)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 520
ThreadCreationTime : 9-8-2004 9:34:32 PM
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 584
ThreadCreationTime : 9-8-2004 9:34:34 PM
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 608
ThreadCreationTime : 9-8-2004 9:34:34 PM
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 652
ThreadCreationTime : 9-8-2004 9:34:35 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 680
ThreadCreationTime : 9-8-2004 9:34:35 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 820
ThreadCreationTime : 9-8-2004 9:34:36 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 864
ThreadCreationTime : 9-8-2004 9:34:36 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1024
ThreadCreationTime : 9-8-2004 9:34:37 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1064
ThreadCreationTime : 9-8-2004 9:34:37 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1160
ThreadCreationTime : 9-8-2004 9:34:37 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:11 [navapsvc.exe]
FilePath : c:\Program Files\Norton AntiVirus\
ProcessID : 1276
ThreadCreationTime : 9-8-2004 9:34:37 PM
BasePriority : Normal
FileVersion : 8.07.17
ProductVersion : 8.07.17
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
LegalCopyright : Copyright (c) 2000-2002 Symantec Corporation. All rights reserved.
OriginalFilename : NAVAPSVC.EXE
#:12 [nprotect.exe]
FilePath : C:\Program Files\Norton Utilities\
ProcessID : 1288
ThreadCreationTime : 9-8-2004 9:34:37 PM
BasePriority : Normal
FileVersion : 15.0.0.20
ProductVersion : 15.0.0.20
ProductName : Norton Utilities
CompanyName : Symantec Corporation
FileDescription : Norton Protection Status
InternalName : NPROTECT
LegalCopyright : Copyright (C) 2001 Symantec Corporation
LegalTrademarks : Norton Utilities
OriginalFilename : NPROTECT.EXE
#:13 [nvsvc32.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1308
ThreadCreationTime : 9-8-2004 9:34:37 PM
BasePriority : Normal
FileVersion : 6.13.10.2880
ProductVersion : 6.13.10.2880
ProductName : NVIDIA Driver Helper Service, Version 28.80
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA Driver Helper Service, Version 28.80
InternalName : NVSVC
LegalCopyright : (c) NVIDIA Corporation. All rights reserved.
OriginalFilename : nvsvc32.exe
#:14 [ipka32.exe]
FilePath : C:\WINDOWS\
ProcessID : 1356
ThreadCreationTime : 9-8-2004 9:34:38 PM
BasePriority : Normal
CoolWebSearch Object Recognized!
Type : Process
Data : ipka32.exe
Category : Data Miner
Comment : (CSI MATCH)
Object : C:\WINDOWS\
Warning! CoolWebSearch Object found in memory(C:\WINDOWS\ipka32.exe)
"C:\WINDOWS\ipka32.exe"Process terminated successfully
"C:\WINDOWS\ipka32.exe"Process terminated successfully
#:15 [tcpsvcs.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1436
ThreadCreationTime : 9-8-2004 9:34:43 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : TCP/IP Services Application
InternalName : TCPSVCS.EXE
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : TCPSVCS.EXE
#:16 [snmp.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1448
ThreadCreationTime : 9-8-2004 9:34:43 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : SNMP Service
InternalName : snmp.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : snmp.exe
#:17 [nopdb.exe]
FilePath : C:\Program Files\Speed Disk\
ProcessID : 1460
ThreadCreationTime : 9-8-2004 9:34:43 PM
BasePriority : Normal
FileVersion : 6.0.0.20
ProductVersion : 6.0.0.20
ProductName : Norton Speed Disk
CompanyName : Symantec Corporation
FileDescription : NOPDB
InternalName : NOPDB
LegalCopyright : Copyright (C) 2001
OriginalFilename : NOPDB.dll
#:18 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1512
ThreadCreationTime : 9-8-2004 9:34:43 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:19 [uphclean.exe]
FilePath : C:\Program Files\UPHClean\
ProcessID : 1532
ThreadCreationTime : 9-8-2004 9:34:43 PM
BasePriority : Normal
FileVersion : 1.5.5.21
ProductVersion : 1.5e
ProductName : User Profile Hive Cleanup Service
CompanyName : Microsoft Corporation
FileDescription : User Profile Hive Cleanup Service
InternalName : UPHClean
LegalCopyright : Copyright © 2003, 2004
OriginalFilename : uphclean.exe
Comments : Written by Robin Caron (rcaron@microsoft.com)
#:20 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 132
ThreadCreationTime : 9-8-2004 9:35:02 PM
BasePriority : Normal
FileVersion : 6.00.2600.0000 (xpclient.010817-1148)
ProductVersion : 6.00.2600.0000
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
#:21 [kbd.exe]
FilePath : C:\HP\KBD\
ProcessID : 108
ThreadCreationTime : 9-8-2004 9:35:53 PM
BasePriority : High
#:22 [hpsysdrv.exe]
FilePath : C:\windows\system\
ProcessID : 772
ThreadCreationTime : 9-8-2004 9:35:54 PM
BasePriority : Normal
FileVersion : 1, 7, 0, 0
ProductVersion : 1, 7, 0, 0
ProductName : hpsysdrv
CompanyName : Hewlett-Packard Company
FileDescription : hpsysdrv
InternalName : hpsysdrv
LegalCopyright : Copyright © 1998
OriginalFilename : hpsysdrv.exe
#:23 [rundll32.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 976
ThreadCreationTime : 9-8-2004 9:35:56 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : RUNDLL.EXE
#:24 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 1008
ThreadCreationTime : 9-8-2004 9:35:57 PM
BasePriority : Normal
FileVersion : 0.1.0.1622
ProductVersion : 0.1.0.1622
ProductName : RealOne Player (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2002
LegalTrademarks : RealAudio(tm) is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe
#:25 [s3apphk.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1032
ThreadCreationTime : 9-8-2004 9:35:57 PM
BasePriority : Normal
#:26 [rnathchk.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 1252
ThreadCreationTime : 9-8-2004 9:35:58 PM
BasePriority : Normal
FileVersion : 7.0.0.1176
ProductVersion : 7.0.0.1176
ProductName : RealOne Player (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks ATH Check App
InternalName : rnathchk
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2002
LegalTrademarks : RealAudio(tm) is a trademark of RealNetworks, Inc.
OriginalFilename : rnathchk.EXE
#:27 [navapw32.exe]
FilePath : C:\PROGRA~1\NORTON~1\
ProcessID : 1184
ThreadCreationTime : 9-8-2004 9:35:59 PM
BasePriority : Normal
FileVersion : 8.07.17
ProductVersion : 8.07.17
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Agent
InternalName : NAVAPW32
LegalCopyright : Copyright (c) 2000-2002 Symantec Corporation. All rights reserved.
OriginalFilename : NAVAPW32.EXE
#:28 [ieqp32.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1784
ThreadCreationTime : 9-8-2004 9:36:00 PM
BasePriority : Normal
CoolWebSearch Object Recognized!
Type : Process
Data : ieqp32.exe
Category : Malware
Comment : (CSI MATCH)
Object : C:\WINDOWS\system32\
Warning! CoolWebSearch Object found in memory(C:\WINDOWS\system32\ieqp32.exe)
"C:\WINDOWS\system32\ieqp32.exe"Process terminated successfully
"C:\WINDOWS\system32\ieqp32.exe"Process terminated successfully
#:29 [ypager.exe]
FilePath : C:\Program Files\Yahoo!\Messenger\
ProcessID : 1860
ThreadCreationTime : 9-8-2004 9:36:05 PM
BasePriority : Normal
FileVersion : 6,0,0,1750
ProductVersion : 6,0,0,1750
ProductName : Yahoo! Messenger
CompanyName : Yahoo! Inc.
FileDescription : Yahoo! Messenger
InternalName : Yahoo! Messengerr
LegalCopyright : Copyright 1998-2004
OriginalFilename : YPager.exe
#:30 [weather.exe]
FilePath : C:\PROGRA~1\AWS\WEATHE~1\
ProcessID : 1900
ThreadCreationTime : 9-8-2004 9:36:09 PM
BasePriority : Normal
FileVersion : 6, 3, 0, 1
ProductVersion : 6, 3, 0, 1
ProductName : WeatherBug
CompanyName : AWS Convergence Technologies, Inc.
FileDescription : WeatherBug
InternalName : Desktop Weather
LegalCopyright : Copyright © 2001-2004
LegalTrademarks : WeatherBug
OriginalFilename : Weather.exe
Comments : World Largest Weather Network
#:31 [exec.exe]
FilePath : C:\Program Files\Netzero\
ProcessID : 1904
ThreadCreationTime : 9-8-2004 9:36:11 PM
BasePriority : Normal
FileVersion : 4, 3, 0, 0
ProductVersion : 4, 3, 0, 0
CompanyName : NetZero
FileDescription : ZCast
InternalName : ZCOM_exec
LegalCopyright : Copyright © 2002 United Online, Inc.
#:32 [msnmsgr.exe]
FilePath : C:\Program Files\MSN Messenger\
ProcessID : 120
ThreadCreationTime : 9-8-2004 9:36:19 PM
BasePriority : Normal
FileVersion : 6.2.0137
ProductVersion : Version 6.2
ProductName : MSN Messenger
CompanyName : Microsoft Corporation
FileDescription : MSN Messenger
InternalName : msnmsgr
LegalCopyright : Copyright (c) Microsoft Corporation 1997-2004
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msnmsgr.exe
#:33 [sgmain.exe]
FilePath : C:\Program Files\SpywareGuard\
ProcessID : 380
ThreadCreationTime : 9-8-2004 9:36:26 PM
BasePriority : Normal
FileVersion : 2.02.0001
ProductVersion : 2.02.0001
ProductName : SpywareGuard
FileDescription : SpywareGuard
InternalName : sgmain
LegalCopyright : Copyright (C) 2002-2003 Javacool Software LLC
OriginalFilename : sgmain.exe
Comments : SpywareGuard
#:34 [sgbhp.exe]
FilePath : C:\Program Files\SpywareGuard\
ProcessID : 492
ThreadCreationTime : 9-8-2004 9:36:36 PM
BasePriority : Normal
FileVersion : 2.02.0001
ProductVersion : 2.02.0001
ProductName : SG Browser Hijacking Protection
FileDescription : SG Browser Hijacking Protection
InternalName : sgbhp
LegalCopyright : Copyright (C) 2002-2003 Javacool Software LLC.
OriginalFilename : sgbhp.exe
Comments : SG Browser Hijacking Protection
#:35 [exec.exe]
FilePath : C:\Program Files\Netzero\
ProcessID : 2648
ThreadCreationTime : 9-8-2004 9:38:46 PM
BasePriority : Normal
FileVersion : 4, 3, 0, 0
ProductVersion : 4, 3, 0, 0
CompanyName : NetZero
FileDescription : ZCast
InternalName : ZCOM_exec
LegalCopyright : Copyright © 2002 United Online, Inc.
#:36 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 3576
ThreadCreationTime : 9-8-2004 9:41:17 PM
BasePriority : Normal
FileVersion : 6.00.2600.0000 (xpclient.010817-1148)
ProductVersion : 6.00.2600.0000
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : IEXPLORE.EXE
#:37 [ad-aware.exe]
FilePath : C:\PROGRA~1\Lavasoft\AD-AWA~2\
ProcessID : 2900
ThreadCreationTime : 9-8-2004 10:24:25 PM
BasePriority : Normal
FileVersion : 6.2.0.200
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 2
Objects found so far: 2
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : CWS.FullSearch
Rootkey : HKEY_LOCAL_MACHINE
Object : system\currentcontrolset\services\o?’ŽrtñåȲ$Ó
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : CWS.FullSearch
Rootkey : HKEY_LOCAL_MACHINE
Object : system\controlset001\services\o?’ŽrtñåȲ$Ó
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment : CWS.FullSearch
Rootkey : HKEY_LOCAL_MACHINE
Object : system\controlset001\enum\root\legacy_o?*001e*2019*017drt*00f1*00e5*00c8*00b2$*000e*00d3
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\currentcontrolset\enum\root\legacy_o?*001e*2019*017drt*00f1*00e5*00c8*00b2$*000e*00d3\0000
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\currentcontrolset\enum\root\legacy_o?*001e*2019*017drt*00f1*00e5*00c8*00b2$*000e*00d3\0000\control
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\currentcontrolset\enum\root\legacy_o?*001e*2019*017drt*00f1*00e5*00c8*00b2$*000e*00d3
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 6
Objects found so far: 8
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Possible Browser Hijack attempt : Software\Microsoft\Internet Explorer\MainStart Page.dll/index.html
Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "res://xfjwt.dll/index.html#37049"
Category : Malware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "res://xfjwt.dll/index.html#37049"
Possible Browser Hijack attempt : Software\Microsoft\Internet Explorer\MainDefault_Page_URL.dll/index.html
Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "res://xfjwt.dll/index.html#37049"
Category : Malware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Default_Page_URL
Data : "res://xfjwt.dll/index.html#37049"
Possible Browser Hijack attempt : S-1-5-21-270800707-1206608168-381150471-1003\Software\Microsoft\Internet Explorer\MainStart Page.dll/index.html
Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "res://xfjwt.dll/index.html#37049"
Category : Malware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_USERS
Object : S-1-5-21-270800707-1206608168-381150471-1003\Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "res://xfjwt.dll/index.html#37049"
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 3
Objects found so far: 11
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [email]owner@realmedia[1].txt[/email]
Category : Data Miner
Comment : 9-8-2004 3:13:26 PM
Value : Cookie:owner@realmedia.com/
Expires : 12-31-2010 5:00:00 PM
LastSync : 9-8-2004 3:13:26 PM
UseCount : 0
Hits : 12
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 12
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
CoolWebSearch Object Recognized!
Type : File
Data : addij32.exe
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : bpplf.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : cxlsl.txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : d3oe.exe
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : dgnyj.log
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : dmcnh.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : dqvbm.log
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : exgar.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : gfvpx.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : gldtt.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : hyzit.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : kckym.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : kepxe.dat
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : ltgmi.dat
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : mvgax.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : ngaiz.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : nvmrr.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : nxian.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : ohvdg.dat
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : pjixx.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : qcfrw.txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : qgfmg.dat
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : rcuet.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : sgghl.log
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : stsqh.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : adduv32.exe
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : amjck.dat
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : apixf.exe
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : bdbox.txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : cfrwm.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : cpnuy.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : dboxz.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : dcsne.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : enlfv.log
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : envmr.log
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : epxem.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : ercue.dat
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : fqnvi.txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : fxwuk.txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : gexga.log
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : gfmgq.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : gghls.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : glrie.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : gnyjo.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : hfbbj.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : hqigj.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : hvdga.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : ihdtu.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : jfsvq.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : jrdhs.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : jstsq.txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : jtfqn.txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : kgldt.log
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : lfoan.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : lqjhb.dat
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : lxirg.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : lyyje.log
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : mjckb.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : mnvgp.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : nbdyl.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : nffes.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : nlfvx.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : oalhx.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : pdvke.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : plfoa.dat
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : qbppl.dat
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : qnvib.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : rkepg.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : rnxia.dat
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : smyhq.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : sumax.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : tgmio.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : xbqpx.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : xfjwt.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : xodvs.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : xwukj.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : xzrrg.txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : zoalh.txt
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
CoolWebSearch Object Recognized!
Type : File
Data : szsrm.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : tfqnp.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : tkcky.dat
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : tnzfb.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : tszsr.dat
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : vxnpv.dat
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : wpsge.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : xlsle.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : xnpvg.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : yrxfs.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : yyjeb.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : zihdt.dat
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : zrrgv.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
CoolWebSearch Object Recognized!
Type : File
Data : zsgvi.dll
Category : Data Miner
Comment :
Object : C:\WINDOWS\
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 104
Deep scanning and examining files (D:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for D:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 104
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\sw
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\se
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\hsa
CoolWebSearch Object Recognized!
Type : Folder
Category : Malware
Comment :
Object : C:\Documents and Settings\Owner\local settings\temporary internet files\msft\images-sprem
CoolWebSearch Object Recognized!
Type : File
Data : up.gif
Category : Malware
Comment :
Object : C:\Documents and Settings\Owner\local settings\temporary internet files\msft\images-sprem\
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 9
Objects found so far: 113
3:43:21 PM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:17:53.204
Objects scanned:162123
Objects identified:113
Objects ignored:0
New critical objects:113