Så er der slettet efter ovenstående... Og her er så en log fra ad-aware:
Ad-Aware SE Build 1.05
Logfile Created on:14. april 2005 12:00:51
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R38 11.04.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Alexa(TAC index:5):11 total references
AltnetBDE(TAC index:4):28 total references
Claria(TAC index:7):16 total references
Cydoor(TAC index:7):325 total references
eUniverse(TAC index:10):25 total references
MicroGaming(TAC index:4):1 total references
Other(TAC index:5):1 total references
Possible Browser Hijack attempt(TAC index:3):1 total references
Tracking Cookie(TAC index:3):7 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
14-04-2005 12:00:51 - Scan started. (Full System Scan)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 580
ThreadCreationTime : 14-04-2005 09:52:13
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 628
ThreadCreationTime : 14-04-2005 09:52:16
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 652
ThreadCreationTime : 14-04-2005 09:52:16
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 696
ThreadCreationTime : 14-04-2005 09:52:18
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operativsystem
CompanyName : Microsoft Corporation
FileDescription : Tjenester og controllerprogrammer
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. Alle rettigheder forbeholdes.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 708
ThreadCreationTime : 14-04-2005 09:52:18
BasePriority : Normal
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 876
ThreadCreationTime : 14-04-2005 09:52:19
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 996
ThreadCreationTime : 14-04-2005 09:52:19
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1112
ThreadCreationTime : 14-04-2005 09:52:20
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1144
ThreadCreationTime : 14-04-2005 09:52:20
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [ccsetmgr.exe]
FilePath : C:\Programmer\Fælles filer\Symantec Shared\
ProcessID : 1380
ThreadCreationTime : 14-04-2005 09:52:23
BasePriority : Normal
FileVersion : 2.1.6.3
ProductVersion : 2.1.6.3
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client Settings Manager Service
InternalName : ccSetMgr
LegalCopyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
OriginalFilename : ccSetMgr.exe
#:11 [ccevtmgr.exe]
FilePath : C:\Programmer\Fælles filer\Symantec Shared\
ProcessID : 1696
ThreadCreationTime : 14-04-2005 09:52:23
BasePriority : Normal
FileVersion : 2.1.6.3
ProductVersion : 2.1.6.3
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client Event Manager Service
InternalName : ccEvtMgr
LegalCopyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
OriginalFilename : ccEvtMgr.exe
#:12 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1976
ThreadCreationTime : 14-04-2005 09:52:24
BasePriority : Normal
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:13 [btwdins.exe]
FilePath : C:\Programmer\WIDCOMM\Bluetooth Software\bin\
ProcessID : 204
ThreadCreationTime : 14-04-2005 09:52:30
BasePriority : Normal
FileVersion : 1.4.2 Build 10
ProductVersion : 1.4.2 Build 10
ProductName : Bluetooth Software 1.4.2 Build 10
CompanyName : WIDCOMM, Inc.
FileDescription : Bluetooth Support Server
InternalName : BTWDIns
LegalCopyright : Copyright WIDCOMM, Inc. 2000-2003.
OriginalFilename : BTWDIns.EXE
#:14 [navapsvc.exe]
FilePath : C:\Programmer\Norton AntiVirus\
ProcessID : 244
ThreadCreationTime : 14-04-2005 09:52:30
BasePriority : Normal
FileVersion : 10.00.2
ProductVersion : 10.00.2
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
LegalCopyright : Norton AntiVirus 2004 for Windows 98/ME/2000/XP Copyright (c) 2003 Symantec Corporation. All rights reserved.
OriginalFilename : NAVAPSVC.EXE
#:15 [nprotect.exe]
FilePath : C:\Programmer\Norton AntiVirus\AdvTools\
ProcessID : 284
ThreadCreationTime : 14-04-2005 09:52:31
BasePriority : Normal
FileVersion : 16.00.0.22
ProductVersion : 16.00.0.22
ProductName : Norton Utilities
CompanyName : Symantec Corporation
FileDescription : Norton Protection Status
InternalName : NPROTECT
LegalCopyright : Copyright (C) 2003 Symantec Corporation
LegalTrademarks : Norton Utilities
OriginalFilename : NPROTECT.EXE
#:16 [savscan.exe]
FilePath : C:\Programmer\Norton AntiVirus\
ProcessID : 440
ThreadCreationTime : 14-04-2005 09:52:31
BasePriority : Normal
ProductVersion : 9.2
ProductName : Symantec AntiVirus AutoProtect
CompanyName : Symantec Corporation
FileDescription : Symantec AntiVirus Scanner
InternalName : SAVSCAN
LegalCopyright : Copyright (c) 2004 Symantec Corporation
OriginalFilename : SAVSCAN.EXE
#:17 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 1088
ThreadCreationTime : 14-04-2005 09:52:35
BasePriority : Normal
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
ProductName : Microsoft® Windows® Operativsystem
CompanyName : Microsoft Corporation
FileDescription : Windows Stifinder
InternalName : explorer
LegalCopyright : © Microsoft Corporation. Alle rettigheder forbeholdes.
OriginalFilename : EXPLORER.EXE
#:18 [symlcsvc.exe]
FilePath : C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\
ProcessID : 1176
ThreadCreationTime : 14-04-2005 09:52:35
BasePriority : Normal
FileVersion : 1, 8, 48, 77
ProductVersion : 1, 8, 48, 77
ProductName : Symantec Core Component
CompanyName : Symantec Corporation
FileDescription : Symantec Core Component
InternalName : symlcsvc
LegalCopyright : Copyright (C) 2003
OriginalFilename : symlcsvc.exe
#:19 [wdfmgr.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1224
ThreadCreationTime : 14-04-2005 09:52:36
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe
#:20 [mspmspsv.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1396
ThreadCreationTime : 14-04-2005 09:52:37
BasePriority : Normal
FileVersion : 7.01.00.3055
ProductVersion : 7.01.00.3055
ProductName : Microsoft (R) DRM
CompanyName : Microsoft Corporation
FileDescription : WMDM PMSP Service
InternalName : MSPMSPSV.EXE
LegalCopyright : Copyright (C) Microsoft Corp. 1981-2000
OriginalFilename : MSPMSPSV.EXE
#:21 [hpi_monitor.exe]
FilePath : C:\Programmer\Hewlett-Packard\PhotoSmart\Photo Imaging\
ProcessID : 1660
ThreadCreationTime : 14-04-2005 09:52:41
BasePriority : Normal
FileVersion : 3.7.0.3
ProductVersion : 3.7.0.3
ProductName : HP PhotoSmart Software
CompanyName : Hewlett-Packard Company
FileDescription : Device Monitor Application
InternalName : HPI_MONITOR
LegalCopyright : Copyright © 1997-98 Hewlett-Packard Company
OriginalFilename : HPI_Monitor.EXE
#:22 [qttask.exe]
FilePath : C:\Programmer\QuickTime\
ProcessID : 1680
ThreadCreationTime : 14-04-2005 09:52:41
BasePriority : Normal
FileVersion : 6.4
ProductVersion : QuickTime 6.4
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2003
OriginalFilename : QTTask.exe
#:23 [ccapp.exe]
FilePath : C:\Programmer\Fælles filer\Symantec Shared\
ProcessID : 1712
ThreadCreationTime : 14-04-2005 09:52:41
BasePriority : Normal
FileVersion : 2.1.6.3
ProductVersion : 2.1.6.3
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client User Session
InternalName : ccApp
LegalCopyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
OriginalFilename : ccApp.exe
#:24 [hpwuschd2.exe]
FilePath : C:\Programmer\HP\HP Software Update\
ProcessID : 1752
ThreadCreationTime : 14-04-2005 09:52:42
BasePriority : Normal
FileVersion : 2, 0, 39, 0
ProductVersion : 2, 0, 39, 0
ProductName : Hewlett-Packard hpwuSchd
CompanyName : Hewlett-Packard Company
FileDescription : hpwuSchd
InternalName : hpwuSchd
LegalCopyright : Copyright © 2003
OriginalFilename : hpwuSchd2.exe
#:25 [hpcmpmgr.exe]
FilePath : C:\Programmer\HP\hpcoretech\
ProcessID : 1792
ThreadCreationTime : 14-04-2005 09:52:42
BasePriority : Normal
FileVersion : 2.1.1.0
ProductVersion : 2.1.5
ProductName : hp coretech (COmponent REuse TECHnology)
CompanyName : Hewlett-Packard Company
FileDescription : HP Framework Component Manager Service
InternalName : HPComponentManagerService module
LegalCopyright : Copyright (C) Hewlett-Packard. 2002-2004
OriginalFilename : HpCmpMgr.exe
#:26 [datala~1.exe]
FilePath : C:\PROGRA~1\FLLESF~1\PCSuite\DATALA~1\
ProcessID : 1804
ThreadCreationTime : 14-04-2005 09:52:42
BasePriority : Normal
FileVersion : 6, 3, 72, 2
ProductVersion : 5, 0
ProductName : Nokia PC Suite
CompanyName : Nokia Mobile Phones Ltd.
FileDescription : DataLayer 2.0 Module
InternalName : DataLayer 2.0
LegalCopyright : Copyright (c) 2004. Nokia. All rights reserved.
OriginalFilename : DataLayer.exe
#:27 [trayap~1.exe]
FilePath : C:\PROGRA~1\Nokia\NOKIAP~1\
ProcessID : 1824
ThreadCreationTime : 14-04-2005 09:52:43
BasePriority : Normal
FileVersion : 6, 3, 26, 0
ProductVersion : 6, 0, 26, 0
ProductName : Nokia Tray Application
FileDescription : Nokia Tray Application
InternalName : Nokia Tray Application
LegalCopyright : Copyright © 2001 - 2004 Nokia. All Rights Reserved.
OriginalFilename : TrayApplication.EXE
#:28 [ctfmon.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2004
ThreadCreationTime : 14-04-2005 09:52:43
BasePriority : Normal
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE
#:29 [msnmsgr.exe]
FilePath : C:\Programmer\MSN Messenger\
ProcessID : 176
ThreadCreationTime : 14-04-2005 09:52:43
BasePriority : Normal
FileVersion : 6.2.0205
ProductVersion : Version 6.2
ProductName : MSN Messenger
CompanyName : Microsoft Corporation
FileDescription : MSN Messenger
InternalName : msnmsgr
LegalCopyright : Copyright (c) Microsoft Corporation 1997-2004
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msnmsgr.exe
#:30 [skype.exe]
FilePath : C:\Programmer\Skype\Phone\
ProcessID : 412
ThreadCreationTime : 14-04-2005 09:52:44
BasePriority : Normal
#:31 [devldr32.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 756
ThreadCreationTime : 14-04-2005 09:52:45
BasePriority : Normal
FileVersion : 1, 0, 0, 17
ProductVersion : 1, 0, 0, 17
ProductName : Creative Ring3 NT Inteface
CompanyName : Creative Technology Ltd.
FileDescription : DevLdr32
InternalName : DevLdr
LegalCopyright : Copyright (C) Creative Technology Ltd. 1998-2001
OriginalFilename : DevLdr32.exe
#:32 [acrotray.exe]
FilePath : C:\Programmer\Adobe\Acrobat 5.0\Distillr\
ProcessID : 540
ThreadCreationTime : 14-04-2005 09:52:45
BasePriority : Normal
FileVersion : 5, 0, 0, 0
ProductVersion : 5, 0, 0, 0
ProductName : AcroTray - Adobe Acrobat Distiller helper application.
CompanyName : Adobe Systems Inc.
FileDescription : AcroTray
InternalName : AcroTray
LegalCopyright : Copyright © 2001
OriginalFilename : AcroTray.exe
#:33 [bttray.exe]
FilePath : C:\Programmer\WIDCOMM\Bluetooth Software\
ProcessID : 868
ThreadCreationTime : 14-04-2005 09:52:46
BasePriority : Normal
FileVersion : 1.4.2 Build 10
ProductVersion : 1.4.2 Build 10
ProductName : Bluetooth Software 1.4.2 Build 10
CompanyName : WIDCOMM, Inc.
FileDescription : Bluetooth Tray Application
InternalName : BTTray
LegalCopyright : Copyright WIDCOMM, Inc. 2000-2003.
OriginalFilename : BTTray.exe
#:34 [hpqtra08.exe]
FilePath : C:\Programmer\HP\Digital Imaging\bin\
ProcessID : 568
ThreadCreationTime : 14-04-2005 09:52:46
BasePriority : Normal
FileVersion : 43.1.5.000
ProductVersion : 043.001.005.000
ProductName : hp digital imaging - hp all-in-one series
CompanyName : Hewlett-Packard Co.
FileDescription : HP Digital Imaging Monitor (CUE)
InternalName : HPQTRA00
LegalCopyright : Copyright (C) Hewlett-Packard Co. 1995-2004
OriginalFilename : HPQTRA00.EXE
Comments : HP Digital Imaging Monitor (CUE)
#:35 [kem.exe]
FilePath : C:\Programmer\Logitech\SetPoint\
ProcessID : 952
ThreadCreationTime : 14-04-2005 09:52:47
BasePriority : Normal
FileVersion : 2.00.171
ProductVersion : 2.00.171
ProductName : SetPoint Files
CompanyName : Logitech Inc.
FileDescription : Logitech SetPoint
InternalName : SetPoint
LegalCopyright : (C) 2003 Logitech. All rights reserved.
LegalTrademarks : Logitech®, is a registered trademark of Logitech Inc.
OriginalFilename : KEM.exe
Comments : Created by the Productivity Software team
#:36 [hotsync.exe]
FilePath : C:\Programmer\Palm\
ProcessID : 924
ThreadCreationTime : 14-04-2005 09:52:49
BasePriority : Normal
FileVersion : 4.0.4
ProductVersion : 4.1.0
ProductName : HotSync® Manager, Palm Desktop
CompanyName : Palm, Inc.
FileDescription : HotSync® Manager Application
InternalName : HotSync®
LegalCopyright : Copyright © 1995-2001 Palm, Inc.
LegalTrademarks : HotSync® is a registered trademark of Palm, Inc.
OriginalFilename : Hotsync.exe
#:37 [servic~1.exe]
FilePath : C:\PROGRA~1\FLLESF~1\PCSuite\Services\
ProcessID : 1164
ThreadCreationTime : 14-04-2005 09:52:50
BasePriority : Normal
FileVersion : 6, 3, 15, 0
ProductVersion : 6.0
ProductName : Nokia Connectivity Library
CompanyName : Nokia.
FileDescription : ServiceLayer Module
InternalName : ServiceLayer
LegalCopyright : Copyright © 2002-2004 Nokia. All Rights Reserved.
OriginalFilename : ServiceLayer.exe
#:38 [khalmnpr.exe]
FilePath : C:\Programmer\Logitech\SetPoint\
ProcessID : 1140
ThreadCreationTime : 14-04-2005 09:52:51
BasePriority : Normal
FileVersion : 2.00.171
ProductVersion : 2.00.171
ProductName : Productivity Software Common Files
CompanyName : Logitech Inc.
FileDescription : Logitech Hardware Abstraction Layer
InternalName : SetPoint
LegalCopyright : (C) 2003 Logitech. All rights reserved.
LegalTrademarks : Logitech®, MouseWare® and iTouch® are registered trademarks of Logitech Inc.
OriginalFilename : KHALMNPR.Exe
Comments : Created by the Productivity Software team
#:39 [hpqgalry.exe]
FilePath : C:\Programmer\HP\Digital Imaging\bin\
ProcessID : 2120
ThreadCreationTime : 14-04-2005 09:52:56
BasePriority : Normal
#:40 [msmsgs.exe]
FilePath : C:\Programmer\Messenger\
ProcessID : 2260
ThreadCreationTime : 14-04-2005 09:53:00
BasePriority : Normal
FileVersion : 4.7.2009
ProductVersion : Version 4.7
ProductName : Messenger
CompanyName : Microsoft Corporation
FileDescription : Messenger
InternalName : msmsgs
LegalCopyright : Copyright (c) Microsoft Corporation 1997-2003
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msmsgs.exe
#:41 [wuauclt.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2744
ThreadCreationTime : 14-04-2005 09:53:45
BasePriority : Normal
FileVersion : 5.4.3790.2182 built by: srv03_rtm(ntvbl04)
ProductVersion : 5.4.3790.2182
ProductName : Microsoft® Windows® Operativsystem
CompanyName : Microsoft Corporation
FileDescription : Automatiske opdateringer
InternalName : wuauclt.exe
LegalCopyright : © Microsoft Corporation. Alle rettigheder forbeholdes.
OriginalFilename : wuauclt.exe
#:42 [iexplore.exe]
FilePath : C:\Programmer\Internet Explorer\
ProcessID : 2776
ThreadCreationTime : 14-04-2005 09:53:55
BasePriority : Normal
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
ProductName : Microsoft® Windows® Operativsystem
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. Alle rettigheder forbeholdes.
OriginalFilename : IEXPLORE.EXE
#:43 [hpzipm12.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2960
ThreadCreationTime : 14-04-2005 09:54:12
BasePriority : Normal
FileVersion : 8, 0, 0, 0
ProductVersion : 8, 0, 0, 0
ProductName : HP PML
CompanyName : HP
FileDescription : PML Driver
InternalName : PmlDrv
LegalCopyright : Copyright © 1998, 1999 Hewlett-Packard Company
OriginalFilename : PmlDrv.exe
#:44 [ad-aware.exe]
FilePath : C:\PROGRA~1\Lavasoft\AD-AWA~1\
ProcessID : 2392
ThreadCreationTime : 14-04-2005 10:00:32
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
eUniverse Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : bho.perfectnavbho
eUniverse Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : bho.perfectnavbho
Value :
eUniverse Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : bho.perfectnavbho.1
eUniverse Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : bho.perfectnavbho.1
Value :
eUniverse Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{8b8f6968-2f24-41e3-b653-e9613226f14d}
eUniverse Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{8b8f6968-2f24-41e3-b653-e9613226f14d}
Value :
eUniverse Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{de289bfa-737b-4abb-a4ec-f8753551b875}
eUniverse Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{00d6a7e7-4a97-456f-848a-3b75bf7554d7}
eUniverse Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{00d6a7e7-4a97-456f-848a-3b75bf7554d7}
Value :
eUniverse Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{00d6a7e7-4a97-456f-848a-3b75bf7554d7}\progid
eUniverse Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{00d6a7e7-4a97-456f-848a-3b75bf7554d7}\progid
Value :
eUniverse Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{00d6a7e7-4a97-456f-848a-3b75bf7554d7}\typelib
eUniverse Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{00d6a7e7-4a97-456f-848a-3b75bf7554d7}\typelib
Value :
eUniverse Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{00d6a7e7-4a97-456f-848a-3b75bf7554d7}\programmable
Cydoor Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-220523388-688789844-854245398-1003\software\cydoor
Cydoor Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-220523388-688789844-854245398-1003\software\cydoor
Value : Vers
Cydoor Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-220523388-688789844-854245398-1003\software\cydoor
Value : Desc2
Cydoor Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-220523388-688789844-854245398-1003\software\cydoor
Value : ConnType
Alexa Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Value : MenuText
Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Value : MenuStatusBar
Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Value : Script
Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Value : clsid
Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Value : Icon
Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Value : HotIcon
Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Value : ButtonText
AltnetBDE Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\classes\adm4.adm4
AltnetBDE Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\classes\adm4.adm4
Value :
AltnetBDE Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\classes\adm25.adm25
AltnetBDE Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\classes\adm25.adm25
Value :
AltnetBDE Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\classes\adm4.adm4.1
AltnetBDE Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\classes\adm4.adm4.1
Value :
AltnetBDE Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\classes\adm25.adm25.1
AltnetBDE Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\classes\adm25.adm25.1
Value :
AltnetBDE Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\classes\appid\adm.exe
AltnetBDE Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\classes\appid\adm.exe
Value : AppID
AltnetBDE Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\classes\appid\altnet signing module.exe
AltnetBDE Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\classes\appid\altnet signing module.exe
Value : AppID
Cydoor Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\cydoor
Cydoor Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\cydoor
Value : C:\Programmer\Kazaa\Kazaa.exe
Cydoor Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\cydoor
Value : AdwrCnt
MicroGaming Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-220523388-688789844-854245398-1003\software\microgaming
Cydoor Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-220523388-688789844-854245398-1003\\software\cydoor
Cydoor Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-220523388-688789844-854245398-1003\\software\cydoor
Value : Vers
Cydoor Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-220523388-688789844-854245398-1003\\software\cydoor
Value : Desc2
Cydoor Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-220523388-688789844-854245398-1003\\software\cydoor
Value : ConnType
Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment : "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
Rootkey : HKEY_USERS
Object : .DEFAULT\software\microsoft\internet explorer\extensions\cmdmapping
Value : {c95fe080-8f5d-11d2-a20b-00aa003c157a}
Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment : "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
Rootkey : HKEY_USERS
Object : S-1-5-18\software\microsoft\internet explorer\extensions\cmdmapping
Value : {c95fe080-8f5d-11d2-a20b-00aa003c157a}
Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment : "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
Rootkey : HKEY_USERS
Object : S-1-5-21-220523388-688789844-854245398-1003\software\microsoft\internet explorer\extensions\cmdmapping
Value : {c95fe080-8f5d-11d2-a20b-00aa003c157a}
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 49
Objects found so far: 49
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 49
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : xx@instadia[1].txt
Category : Data Miner
Comment : Hits:2
Value : Cookie:xx@instadia.net/
Expires : 04-07-2029 02:00:00
LastSync : Hits:2
UseCount : 0
Hits : 2
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : xx@doubleclick[1].txt
Category : Data Miner
Comment : Hits:5
Value : Cookie:xx@doubleclick.net/
Expires : 12-04-2008 16:17:44
LastSync : Hits:5
UseCount : 0
Hits : 5
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : xx@cgi-bin[1].txt
Category : Data Miner
Comment : Hits:5
Value : Cookie:xx@imrworldwide.com/cgi-bin
Expires : 19-01-2009 01:00:00
LastSync : Hits:5
UseCount : 0
Hits : 5
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : xx@advertising[1].txt
Category : Data Miner
Comment : Hits:18
Value : Cookie:xx@advertising.com/
Expires : 12-04-2010 18:01:12
LastSync : Hits:18
UseCount : 0
Hits : 18
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : xx@mediaplex[1].txt
Category : Data Miner
Comment : Hits:7
Value : Cookie:xx@mediaplex.com/
Expires : 22-06-2009 02:00:00
LastSync : Hits:7
UseCount : 0
Hits : 7
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : xx@servedby.advertising[1].txt
Category : Data Miner
Comment : Hits:18
Value : Cookie:xx@servedby.advertising.com/
Expires : 13-05-2005 18:01:12
LastSync : Hits:18
UseCount : 0
Hits : 18
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : xx@adtech[1].txt
Category : Data Miner
Comment : Hits:12
Value : Cookie:xx@adtech.de/
Expires : 11-04-2015 14:49:56
LastSync : Hits:12
UseCount : 0
Hits : 12
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 7
Objects found so far: 56
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Claria Object Recognized!
Type : File
Data : Dc11.dll
Category : Data Miner
Comment :
Object : C:\RECYCLER\S-1-5-21-220523388-688789844-854245398-1003\
FileVersion : 5.1.1.5
ProductVersion : 5.1.1.5
ProductName : CME
CompanyName : GAIN Publishing, Inc.
FileDescription : CME II Client Application
InternalName : GController.dll
LegalCopyright : Copyright © 1999-2003 GAIN Publishing, Inc.
OriginalFilename : GController.dll
Claria Object Recognized!
Type : File
Data : Dc12.dll
Category : Data Miner
Comment :
Object : C:\RECYCLER\S-1-5-21-220523388-688789844-854245398-1003\
FileVersion : 5.1.1.5
ProductVersion : 5.1.1.5
ProductName : CME
CompanyName : GAIN Publishing, Inc.
FileDescription : CME II Client Application
InternalName : GDlwdEng.dll
LegalCopyright : Copyright © 1999-2003 GAIN Publishing, Inc.
OriginalFilename : GDlwdEng.dll
Claria Object Recognized!
Type : File
Data : Dc13.dll
Category : Data Miner
Comment :
Object : C:\RECYCLER\S-1-5-21-220523388-688789844-854245398-1003\
FileVersion : 5.1.1.5
ProductVersion : 5.1.1.5
ProductName : CME
CompanyName : GAIN Publishing, Inc.
FileDescription : CME II Client Application
InternalName : GObjs.dll
LegalCopyright : Copyright © 1999-2003 GAIN Publishing, Inc.
OriginalFilename : GObjs.dll
Claria Object Recognized!
Type : File
Data : Dc14.dll
Category : Data Miner
Comment :
Object : C:\RECYCLER\S-1-5-21-220523388-688789844-854245398-1003\
FileVersion : 5.1.1.5
ProductVersion : 5.1.1.5
ProductName : CME
CompanyName : GAIN Publishing, Inc.
FileDescription : CME II Client Application
InternalName : GStore.dll
LegalCopyright : Copyright © 1999-2003 GAIN Publishing, Inc.
OriginalFilename : GStore.dll
Claria Object Recognized!
Type : File
Data : Dc15.dll
Category : Data Miner
Comment :
Object : C:\RECYCLER\S-1-5-21-220523388-688789844-854245398-1003\
FileVersion : 5.1.1.5
ProductVersion : 5.1.1.5
ProductName : CME
CompanyName : GAIN Publishing, Inc.
FileDescription : CME II Client Application
InternalName : GStoreServer.dll
LegalCopyright : Copyright © 1999-2003 GAIN Publishing, Inc.
OriginalFilename : GStoreServer.dll
Claria Object Recognized!
Type : File
Data : Dc16.dll
Category : Data Miner
Comment :
Object : C:\RECYCLER\S-1-5-21-220523388-688789844-854245398-1003\
FileVersion : 5.1.1.5
ProductVersion : 5.1.1.5
ProductName : CME
CompanyName : GAIN Publishing, Inc.
FileDescription : CME II Client Application
InternalName : GTools.dll
LegalCopyright : Copyright © 1999-2003 GAIN Publishing, Inc.
OriginalFilename : GTools.dll
Claria Object Recognized!
Type : File
Data : EGGCEngine.dll
Category : Data Miner
Comment :
Object : C:\RECYCLER\S-1-5-21-220523388-688789844-854245398-1003\Dc2\
FileVersion : 5.1.1.5
ProductVersion : 5.1.1.5
ProductName : GAIN Publishing
CompanyName : GAIN Publishing, Inc
FileDescription : EGGCEngine Dynamic Link Library
InternalName : EGGCEngine dll
LegalCopyright : Copyright © 1999-2003 GAIN Publishing, Inc
OriginalFilename : EGGCEngine dll
Claria Object Recognized!
Type : File
Data : EGIEProcess.dll
Category : Data Miner
Comment :
Object : C:\RECYCLER\S-1-5-21-220523388-688789844-854245398-1003\Dc2\
FileVersion : 5.1.1.5
ProductVersion : 5.1.1.5
ProductName : GAIN Publishing
CompanyName : GAIN Publishing, Inc
FileDescription : EGIEProcess Dynamic Link Library
InternalName : EGIEProcess dll
LegalCopyright : Copyright © 1999-2003 GAIN Publishing, Inc
OriginalFilename : EGIEProcess dll
Claria Object Recognized!
Type : File
Data : EGNSEngine.dll
Category : Data Miner
Comment :
Object : C:\RECYCLER\S-1-5-21-220523388-688789844-854245398-1003\Dc2\
FileVersion : 5.1.1.5
ProductVersion : 5.1.1.5
ProductName : GAIN Publishing
CompanyName : GAIN Publishing, Inc
FileDescription : EGNSEngine Dynamic Link Library
InternalName : EGNSEngine dll
LegalCopyright : Copyright © 1999-2003 GAIN Publishing, Inc
OriginalFilename : EGNSEngine dll
Claria Object Recognized!
Type : File
Data : GatorRes.dll
Category : Data Miner
Comment :
Object : C:\RECYCLER\S-1-5-21-220523388-688789844-854245398-1003\Dc2\
FileVersion : 5.1.1.5
ProductVersion : 5.1.1.5
ProductName : GAIN Publishing
CompanyName : GAIN Publishing, Inc
FileDescription : GatorRes Dynamic Link Library
InternalName : GatorRes DLL
LegalCopyright : Copyright © 1999-2003 GAIN Publishing, Inc
OriginalFilename : GatorRes DLL
Claria Object Recognized!
Type : File
Data : Dc8.dll
Category : Data Miner
Comment :
Object : C:\RECYCLER\S-1-5-21-220523388-688789844-854245398-1003\
FileVersion : 5.1.1.5
ProductVersion : 5.1.1.5
ProductName : CME
CompanyName : GAIN Publishing, Inc.
FileDescription : CME II Client Application
InternalName : CMEIIAPI.DLL
LegalCopyright : Copyright © 1999-2003 GAIN Publishing, Inc.
OriginalFilename : CMEIIAPI.DLL
Claria Object Recognized!
Type : File
Data : Dc9.dll
Category : Data Miner
Comment :
Object : C:\RECYCLER\S-1-5-21-220523388-688789844-854245398-1003\
FileVersion : 5.1.1.5
ProductVersion : 5.1.1.5
ProductName : CME
CompanyName : GAIN Publishing, Inc.
FileDescription : CME II Client Application
InternalName : GAppMgr.dll
LegalCopyright : Copyright © 1999-2003 GAIN Publishing, Inc.
OriginalFilename : GAppMgr.dll
Cydoor Object Recognized!
Type : File
Data : cd_clint.dll.mwt
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
FileVersion : 3, 2, 1, 6
ProductVersion : 3, 2, 1, 6
ProductName : cd_clint
FileDescription : cd_clint
InternalName : cd_clint
LegalCopyright : Copyright © 2003
OriginalFilename : cd_clint.dll
Object "asmend.exe" found in this archive.
AltnetBDE Object Recognized!
Type : File
Data : dmfiles.cab
Category : Data Miner
Comment : Object "asmend.exe" found in this archive.
Object : C:\WINDOWS\Temp\Altnet\
AltnetBDE Object Recognized!
Type : File
Data : dmfiles.cab
Category : Data Miner
Comment :
Object : C:\WINDOWS\Temp\Altnet\
AltnetBDE Object Recognized!
Type : File
Data : DMinfo3.cab
Category : Data Miner
Comment :
Object : C:\WINDOWS\Temp\Altnet\
AltnetBDE Object Recognized!
Type : File
Data : pmexe.cab
Category : Data Miner
Comment :
Object : C:\WINDOWS\Temp\Altnet\
Object "sysdetect.dll" found in this archive.
AltnetBDE Object Recognized!
Type : File
Data : pmfiles.cab
Category : Data Miner
Comment : Object "sysdetect.dll" found in this archive.
Object : C:\WINDOWS\Temp\Altnet\
AltnetBDE Object Recognized!
Type : File
Data : Setup.exe
Category : Data Miner
Comment :
Object : C:\WINDOWS\Temp\Altnet\
FileVersion : 1, 0, 4, 13
ProductVersion : 1, 0, 0, 0
ProductName : AltnetInstaller
CompanyName : Altnet
FileDescription : AltnetInstaller
InternalName : AltnetInstaller
LegalCopyright : Copyright © 2003
OriginalFilename : AltnetInstaller.exe
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 75
Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
2 entries scanned.
New critical objects:0
Objects found so far: 75
Possible Browser Hijack attempt Object Recognized!
Type : File
Data : Bounce Out!.url
Category : Misc
Comment : Problematic URL discovered:
http://www.gamehouse.com/bounceout/ Object : C:\Documents and Settings\xx\Foretrukne\
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
eUniverse Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\updmgr
eUniverse Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\updmgr
Value : installDate
eUniverse Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\updmgr
Value : cid
eUniverse Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\updmgr
Value : puid
eUniverse Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\updmgr
Value : Install_Dir
eUniverse Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\updmgr
Value : EXEname
eUniverse Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\updmgr
Value : VersionNumber
eUniverse Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\updmgr
Value : LastUpdateAttempt
eUniverse Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\Programmer\common files\updmgr
eUniverse Object Recognized!
Type : File
Data : data1.dat
Category : Data Miner
Comment :
Object : C:\Programmer\common files\updmgr\
eUniverse Object Recognized!
Type : File
Data : data2.dat
Category : Data Miner
Comment :
Object : C:\Programmer\common files\updmgr\
Cydoor Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\AdCache
Cydoor Object Recognized!
Type : File
Data : B_169700.htm
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_179100.htm
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_209200.htm
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_211100.htm
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_213700.htm
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_226100.htm
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_251200.htm
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_251300.htm
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_311500.htm
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_0_171400.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_0_209000.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_0_232800.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_0_250300.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_0_250400.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_0_266600.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_0_266700.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_0_266800.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_171400.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_209000.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_266500.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_501000.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_502300.htm
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_502300.swf
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_504300.htm
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_504300.swf
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_512200.htm
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_512200.swf
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_525200.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_535600.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_564400.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_573700.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_661100.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_661500.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_755300.htm
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_755300.swf
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : File
Data : B_329_0_1_778300.gif
Category : Data Miner
Comment :
Object : C:\WINDOWS\System32\adcache\
Cydoor Object Recognized!
Type : F