G
Guest
Hi experts,
I have recently downloaded ad aware 6.0 and it detected a registry value with an attempt to hijack my browser .It redirects to a blacklisted site it says.I have tried to delete it so many times and each time i do another search it again shows attempted browser hijack.I m sending my log file for your analysis
Lavasoft Ad-aware Personal Build 6.181
Logfile created on :11 July 2004 17:00:41
Created with Ad-aware Personal, free for private use.
Using reference-file :01R331 08.07.2004
______________________________________________________
Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry
11-07-2004 17:00:41 - Scan started. (Smart mode)
Listing running processes
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 11-07-2004 15:56:23
BasePriority : Normal
#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ThreadCreationTime : 11-07-2004 15:56:26
BasePriority : High
#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 11-07-2004 15:56:27
BasePriority : Normal
FileSize : 99 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Microsoft
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 18/08/2001 19:00:00
#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 11-07-2004 15:56:27
BasePriority : Normal
FileSize : 11 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
OriginalFilename : lsass.exe
ProductName : Microsoft
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 29/08/2002 02:41:26
#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 11-07-2004 15:56:28
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 18/08/2001 19:00:00
#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-07-2004 15:56:28
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 18/08/2001 19:00:00
#:7 [ccsetmgr.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ThreadCreationTime : 11-07-2004 15:56:31
BasePriority : Normal
FileSize : 229 KB
FileVersion : 2.1.1.700
ProductVersion : 2.1.1.700
Copyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Common Client Settings Manager Service
InternalName : ccSetMgr
OriginalFilename : ccSetMgr.exe
ProductName : Common Client
Created on : 08/12/2003 16:18:44
Last accessed : 10/07/2004 23:00:00
Last modified : 08/12/2003 16:18:44
#:8 [ccevtmgr.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ThreadCreationTime : 11-07-2004 15:56:31
BasePriority : Normal
FileSize : 249 KB
FileVersion : 2.1.1.700
ProductVersion : 2.1.1.700
Copyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Common Client Event Manager Service
InternalName : ccEvtMgr
OriginalFilename : ccEvtMgr.exe
ProductName : Common Client
Created on : 08/12/2003 16:18:36
Last accessed : 10/07/2004 23:00:00
Last modified : 08/12/2003 16:18:36
#:9 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 11-07-2004 15:56:32
BasePriority : Normal
FileSize : 50 KB
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
OriginalFilename : spoolsv.exe
ProductName : Microsoft
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 18/08/2001 19:00:00
#:10 [explorer.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 11-07-2004 15:56:35
BasePriority : Normal
FileSize : 973 KB
FileVersion : 6.00.2800.1221 (xpsp2.030511-1403)
ProductVersion : 6.00.2800.1221
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft
Created on : 11/05/2003 20:12:10
Last accessed : 10/07/2004 23:00:00
Last modified : 11/05/2003 20:12:10
#:11 [ccproxy.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ThreadCreationTime : 11-07-2004 15:56:35
BasePriority : Normal
FileSize : 213 KB
FileVersion : 2.1.2.800
ProductVersion : 2.1.2.800
Copyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Common Client Network Proxy Service
InternalName : ccProxy
OriginalFilename : ccProxy.exe
ProductName : Common Client
Created on : 30/06/2004 12:28:10
Last accessed : 10/07/2004 23:00:00
Last modified : 27/01/2004 18:06:54
#:12 [mdm.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\
ThreadCreationTime : 11-07-2004 15:56:35
BasePriority : Normal
FileSize : 314 KB
FileVersion : 7.00.9466
ProductVersion : 7.00.9466
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
OriginalFilename : mdm.exe
ProductName : Microsoft
Created on : 19/06/2003 22:25:00
Last accessed : 10/07/2004 23:00:00
Last modified : 19/06/2003 22:25:00
#:13 [navapsvc.exe]
FilePath : C:\Program Files\Norton Internet Security\Norton AntiVirus\
ThreadCreationTime : 11-07-2004 15:56:36
BasePriority : Normal
FileSize : 155 KB
FileVersion : 10.00.2
ProductVersion : 10.00.2
Copyright : Norton AntiVirus 2004 for Windows 98/ME/2000/XP Copyright (c) 2003 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
OriginalFilename : NAVAPSVC.EXE
ProductName : Norton AntiVirus
Created on : 30/06/2004 12:28:09
Last accessed : 10/07/2004 23:00:00
Last modified : 23/04/2004 10:04:18
#:14 [savscan.exe]
FilePath : C:\Program Files\Norton Internet Security\Norton AntiVirus\
ThreadCreationTime : 11-07-2004 15:56:36
BasePriority : Normal
FileSize : 189 KB
FileVersion : 9.2.1.14
ProductVersion : 9.2
Copyright : Copyright (c) 2003 Symantec Corporation
CompanyName : Symantec Corporation
FileDescription : Symantec AntiVirus Scanner
InternalName : SAVSCAN
OriginalFilename : SAVSCAN.EXE
ProductName : Symantec AntiVirus AutoProtect
Created on : 07/11/2003 17:46:58
Last accessed : 10/07/2004 23:00:00
Last modified : 07/11/2003 17:46:58
#:15 [sndsrvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ThreadCreationTime : 11-07-2004 15:56:37
BasePriority : Normal
FileSize : 189 KB
FileVersion : 5.3.2.67
ProductVersion : 5.3
Copyright : Copyright 2002, 2003 Symantec Corporation
CompanyName : Symantec Corporation
FileDescription : Network Driver Service
InternalName : SndSrvc
OriginalFilename : SndSrvc.exe
ProductName : Symantec Security Drivers
Created on : 29/06/2004 15:14:38
Last accessed : 10/07/2004 23:00:00
Last modified : 29/06/2004 15:14:38
#:16 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-07-2004 15:56:38
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 18/08/2001 19:00:00
#:17 [symlcsvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\
ThreadCreationTime : 11-07-2004 15:56:38
BasePriority : Normal
FileSize : 572 KB
FileVersion : 1, 8, 48, 79
ProductVersion : 1, 8, 48, 79
Copyright : Copyright (C) 2003
CompanyName : Symantec Corporation
FileDescription : Symantec Core Component
InternalName : symlcsvc
OriginalFilename : symlcsvc.exe
ProductName : Symantec Core Component
Created on : 30/06/2004 11:44:40
Last accessed : 10/07/2004 23:00:00
Last modified : 30/06/2004 11:44:42
#:18 [igfxtray.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-07-2004 15:56:39
BasePriority : Normal
FileSize : 152 KB
FileVersion : 3,0,0,2104
ProductVersion : 7,0,0,2104
Copyright : Copyright 1999-2003, Intel Corporation
CompanyName : Intel Corporation
FileDescription : igfxTray Module
InternalName : IGFXTRAY
OriginalFilename : IGFXTRAY.EXE
ProductName : Intel(R) Common User Interface
Created on : 19/05/2003 22:52:39
Last accessed : 10/07/2004 23:00:00
Last modified : 06/04/2003 23:19:52
#:19 [hkcmd.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-07-2004 15:56:39
BasePriority : Normal
FileSize : 112 KB
FileVersion : 3,0,0,2104
ProductVersion : 7,0,0,2104
Copyright : Copyright 1999-2003, Intel Corporation
CompanyName : Intel Corporation
FileDescription : hkcmd Module
InternalName : HKCMD
OriginalFilename : HKCMD.EXE
ProductName : Intel(R) Common User Interface
Created on : 19/05/2003 22:52:38
Last accessed : 10/07/2004 23:00:00
Last modified : 06/04/2003 23:07:38
#:20 [almxptray.exe]
FilePath : C:\Program Files\Acer\Notebook Manager\
ThreadCreationTime : 11-07-2004 15:56:39
BasePriority : Normal
FileSize : 498 KB
FileVersion : 2.0.10.3
ProductVersion : 2.0.10
CompanyName : Acer
Created on : 16/05/2003 16:09:34
Last accessed : 10/07/2004 23:00:00
Last modified : 16/05/2003 16:09:34
#:21 [syntplpr.exe]
FilePath : C:\Program Files\Synaptics\SynTP\
ThreadCreationTime : 11-07-2004 15:56:39
BasePriority : Normal
FileSize : 108 KB
FileVersion : 7.5.5 24Apr03
ProductVersion : 7.5.5 24Apr03
Copyright : Copyright (C) Synaptics, Inc. 1996-2003
CompanyName : Synaptics, Inc.
FileDescription : TouchPad Driver Helper Application
InternalName : SynTPLpr
OriginalFilename : SynTPLpr.exe
ProductName : Progressive Touch
Created on : 26/05/2003 14:30:15
Last accessed : 10/07/2004 23:00:00
Last modified : 24/04/2003 15:51:36
#:22 [syntpenh.exe]
FilePath : C:\Program Files\Synaptics\SynTP\
ThreadCreationTime : 11-07-2004 15:56:40
BasePriority : Normal
FileSize : 596 KB
FileVersion : 7.5.5 24Apr03
ProductVersion : 7.5.5 24Apr03
Copyright : Copyright (C) Synaptics, Inc. 1996-2003
CompanyName : Synaptics, Inc.
FileDescription : Synaptics TouchPad Enhancements
InternalName : Scrolleroo
OriginalFilename : SynTPEnh.exe
ProductName : Progressive Touch
Created on : 26/05/2003 14:30:15
Last accessed : 10/07/2004 23:00:00
Last modified : 24/04/2003 15:44:56
#:23 [launchap.exe]
FilePath : C:\Program Files\Launch Manager\
ThreadCreationTime : 11-07-2004 15:56:40
BasePriority : Normal
FileSize : 32 KB
FileVersion : 1, 0, 0, 3
ProductVersion : 1, 0, 0, 3
Copyright : Copyright (C) 2001
FileDescription : LaunchAp MFC Application
InternalName : LaunchAp
OriginalFilename : LaunchAp.EXE
ProductName : LaunchAp Application
Created on : 19/05/2003 22:58:00
Last accessed : 10/07/2004 23:00:00
Last modified : 12/05/2003 13:28:50
#:24 [powerkey.exe]
FilePath : C:\Program Files\Launch Manager\
ThreadCreationTime : 11-07-2004 15:56:40
BasePriority : Normal
FileSize : 92 KB
FileVersion : 1, 4, 4, 0
ProductVersion : 1, 4, 4, 0
Copyright : Copyright
FileDescription : Powerkey
InternalName : Powerkey
OriginalFilename : Powerkey.exe
Created on : 02/06/2003 10:45:26
Last accessed : 10/07/2004 23:00:00
Last modified : 30/08/2002 14:02:48
#:25 [hotkeyapp.exe]
FilePath : C:\Program Files\Launch Manager\
ThreadCreationTime : 11-07-2004 15:56:40
BasePriority : Normal
FileSize : 44 KB
FileVersion : 1, 0, 4, 7
ProductVersion : 1, 0, 4, 7
Copyright : Copyright c 2002
CompanyName : Wistron
FileDescription : HotkeyApp
InternalName : HotkeyApp
OriginalFilename : HotkeyApp.exe
ProductName : Wistron HotkeyApp
Created on : 02/06/2003 10:45:25
Last accessed : 10/07/2004 23:00:00
Last modified : 19/05/2003 10:51:32
#:26 [ctrlvol.exe]
FilePath : C:\Program Files\Launch Manager\
ThreadCreationTime : 11-07-2004 15:56:41
BasePriority : Normal
FileSize : 164 KB
FileVersion : 1, 0, 0, 2
ProductVersion : 1, 0, 0, 2
Copyright : Copyright c 2003
CompanyName : Wistron
FileDescription : ctrlvol
InternalName : ctrlvol
OriginalFilename : ctrlvol.exe
ProductName : Wistron ctrlvol
Created on : 02/06/2003 10:45:25
Last accessed : 10/07/2004 23:00:00
Last modified : 12/05/2003 14:05:16
#:27 [wbutton.exe]
FilePath : C:\Program Files\Launch Manager\
ThreadCreationTime : 11-07-2004 15:56:41
BasePriority : Normal
FileSize : 52 KB
FileVersion : 1, 0, 2, 4
ProductVersion : 1, 0, 2, 4
Copyright : Copyright (C) 2001
FileDescription : WButton MFC Application
InternalName : WButton
OriginalFilename : WButton.EXE
ProductName : WButton Application
Created on : 02/06/2003 10:45:25
Last accessed : 10/07/2004 23:00:00
Last modified : 28/05/2003 09:02:34
#:28 [agrsmmsg.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 11-07-2004 15:56:41
BasePriority : Normal
FileSize : 86 KB
FileVersion : 2.1.25 2.1.25 02/14/2003 11:58:58
ProductVersion : 2.1.25 2.1.25 02/14/2003 11:58:58
Copyright : Copyright
CompanyName : Agere Systems
FileDescription : SoftModem Messaging Applet
InternalName : smdmstat.exe
OriginalFilename : smdmstat.exe
ProductName : Agere SoftModem Messaging Applet
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 14/02/2003 10:59:00
#:29 [ltmoh.exe]
FilePath : C:\Program Files\ltmoh\
ThreadCreationTime : 11-07-2004 15:56:41
BasePriority : Normal
FileSize : 168 KB
FileVersion : 1.68
ProductVersion : 1.68
Copyright : Agere Copyright
CompanyName : Agere Systems
FileDescription : LtMoh MFC Application
InternalName : LtMoh
OriginalFilename : LtMoh.EXE
ProductName : LtMoh Application
Created on : 29/06/2004 20:22:24
Last accessed : 10/07/2004 23:00:00
Last modified : 25/11/2002 09:23:20
#:30 [ccapp.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ThreadCreationTime : 11-07-2004 15:56:41
BasePriority : Normal
FileSize : 69 KB
FileVersion : 2.1.1.700
ProductVersion : 2.1.1.700
Copyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Common Client User Session
InternalName : ccApp
OriginalFilename : ccApp.exe
ProductName : Common Client
Created on : 08/12/2003 16:18:34
Last accessed : 10/07/2004 23:00:00
Last modified : 08/12/2003 16:18:34
#:31 [realplay.exe]
FilePath : C:\Program Files\Real\RealPlayer\
ThreadCreationTime : 11-07-2004 15:56:42
BasePriority : Normal
FileSize : 20 KB
FileVersion : 6.0.8.122
ProductVersion : 6.0.8.122
Copyright : Copyright
CompanyName : RealNetworks, Inc.
FileDescription : RealPlayer
InternalName : REALPLAY
OriginalFilename : REALPLAY.EXE
ProductName : RealPlayer (32-bit)
Created on : 02/07/2004 10:02:07
Last accessed : 10/07/2004 23:00:00
Last modified : 02/07/2004 10:02:08
#:32 [lvcoms.exe]
FilePath : C:\Program Files\Common Files\Logitech\QCDriver3\
ThreadCreationTime : 11-07-2004 15:56:42
BasePriority : Normal
FileSize : 124 KB
FileVersion : 7.3.0.1113
ProductVersion : 7.3.0.1113
Copyright : (c) 1996-2002 Logitech. All rights reserved.
CompanyName : Logitech Inc.
FileDescription : LVCom Server
InternalName : LVComS.exe
OriginalFilename : LVComS.exe
ProductName : Logitech ImageStudio
Created on : 02/07/2004 10:05:06
Last accessed : 10/07/2004 23:00:00
Last modified : 10/12/2002 16:54:04
#:33 [logitray.exe]
FilePath : C:\Program Files\Logitech\ImageStudio\
ThreadCreationTime : 11-07-2004 15:56:42
BasePriority : Normal
FileSize : 60 KB
FileVersion : 7.3.0.1113
ProductVersion : 7.3.0.1113
Copyright : (c) 1996-2002 Logitech. All rights reserved.
CompanyName : Logitech Inc.
FileDescription : ImageStudio Tray Application
InternalName : LogiTray.exe
OriginalFilename : LogiTray.exe
ProductName : Logitech ImageStudio
Created on : 10/12/2002 17:31:34
Last accessed : 10/07/2004 23:00:00
Last modified : 10/12/2002 17:31:34
#:34 [backweb-8876480.exe]
FilePath : C:\Program Files\Logitech\Desktop Messenger\8876480\Program\
ThreadCreationTime : 11-07-2004 15:56:42
BasePriority : Normal
FileSize : 16 KB
Created on : 02/07/2004 10:00:27
Last accessed : 10/07/2004 23:00:00
Last modified : 02/07/2004 10:00:26
#:35 [ctfmon.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-07-2004 15:56:42
BasePriority : Normal
FileSize : 13 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
OriginalFilename : CTFMON.EXE
ProductName : Microsoft
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 29/08/2002 02:41:22
#:36 [hpotdd01.exe]
FilePath : C:\Program Files\Hewlett-Packard\Digital Imaging\bin\
ThreadCreationTime : 11-07-2004 15:56:43
BasePriority : Normal
FileSize : 28 KB
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
Copyright : Copyright
CompanyName : Hewlett-Packard
FileDescription : hpotdd01
InternalName : hpotdd01
OriginalFilename : hpotdd01.exe
ProductName : Hewlett-Packard hpotdd01
Created on : 06/04/2003 00:06:58
Last accessed : 10/07/2004 23:00:00
Last modified : 06/04/2003 00:06:58
#:37 [hpobnz08.exe]
FilePath : C:\Program Files\Hewlett-Packard\Digital Imaging\bin\
ThreadCreationTime : 11-07-2004 15:56:43
BasePriority : Normal
FileSize : 316 KB
FileVersion : 4.2.0.020
ProductVersion : 2.4.1.020
Copyright : Copyright (C) Hewlett-Packard Co. 1995-2001
CompanyName : Hewlett-Packard Co.
FileDescription : HP OfficeJet COM Device Objects
InternalName : HPOBNZ08
OriginalFilename : HPOBNZ08.EXE
ProductName : hp digital imaging - hp all-in-one series
Created on : 05/04/2003 23:37:10
Last accessed : 10/07/2004 23:00:00
Last modified : 05/04/2003 23:37:10
#:38 [msmsgs.exe]
FilePath : C:\Program Files\Messenger\
ThreadCreationTime : 11-07-2004 15:56:50
BasePriority : Normal
FileSize : 1456 KB
FileVersion : 4.7.2009
ProductVersion : Version 4.7
Copyright : Copyright (c) Microsoft Corporation 1997-2003
CompanyName : Microsoft Corporation
FileDescription : Messenger
InternalName : msmsgs
OriginalFilename : msmsgs.exe
ProductName : Messenger
Created on : 14/04/2003 18:30:14
Last accessed : 10/07/2004 23:00:00
Last modified : 14/04/2003 18:30:14
#:39 [hpoevm08.exe]
FilePath : C:\Program Files\Hewlett-Packard\Digital Imaging\bin\
ThreadCreationTime : 11-07-2004 15:56:52
BasePriority : Normal
FileSize : 280 KB
FileVersion : 4.2.0.020
ProductVersion : 2.4.1.020
Copyright : Copyright (C) Hewlett-Packard Co. 1995-2001
CompanyName : Hewlett-Packard Co.
FileDescription : HP OfficeJet COM Event Manager
InternalName : HPOEVM08
OriginalFilename : HPOEVM08.EXE
ProductName : hp digital imaging - hp all-in-one series
Created on : 05/04/2003 23:45:10
Last accessed : 10/07/2004 23:00:00
Last modified : 05/04/2003 23:45:10
#:40 [tesconet.exe]
FilePath : C:\Program Files\Tesconet\
ThreadCreationTime : 11-07-2004 15:56:53
BasePriority : Normal
FileSize : 120 KB
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
Copyright : Copyright (C) Rytec Consultants Ltd 2001.
CompanyName : Rytec Consultants Ltd.
FileDescription : RyDial MFC Application
InternalName : RyDial
OriginalFilename : RyDial.EXE
ProductName : RyDial Application
Created on : 01/08/2002 16:58:42
Last accessed : 10/07/2004 23:00:00
Last modified : 01/08/2002 16:58:42
#:41 [hposts08.exe]
FilePath : C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\
ThreadCreationTime : 11-07-2004 15:56:57
BasePriority : Normal
FileSize : 304 KB
FileVersion : 4.2.0.020
ProductVersion : 2.4.1.020
Copyright : Copyright (C) Hewlett-Packard Co. 1995-2001
CompanyName : Hewlett-Packard Co.
FileDescription : HP OfficeJet Status
InternalName : HPOSTS08
OriginalFilename : HPOSTS08.EXE
ProductName : hp digital imaging - hp all-in-one series
Created on : 05/04/2003 23:55:04
Last accessed : 10/07/2004 23:00:00
Last modified : 05/04/2003 23:55:04
#:42 [ad-aware.exe]
FilePath : C:\PROGRA~1\LAVASOFT\AD-AWA~1\
ThreadCreationTime : 11-07-2004 16:00:24
BasePriority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 10/07/2004 22:56:32
Last accessed : 10/07/2004 23:00:00
Last modified : 12/07/2003 20:00:20
Memory scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Started registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Started deep registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pageabout:blank
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "about:blank"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "about:blank"
Deep registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 1
Objects found so far: 1
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Deep scanning and examining files (C
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Performing conditional scans..
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Conditional scan result:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 1
17:03:18 Scan complete
Summary of this scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Total scanning time :00:02:36:445
Objects scanned :48661
Objects identified :1
Objects ignored :0
New objects :1
Thanks in advance
I have recently downloaded ad aware 6.0 and it detected a registry value with an attempt to hijack my browser .It redirects to a blacklisted site it says.I have tried to delete it so many times and each time i do another search it again shows attempted browser hijack.I m sending my log file for your analysis
Lavasoft Ad-aware Personal Build 6.181
Logfile created on :11 July 2004 17:00:41
Created with Ad-aware Personal, free for private use.
Using reference-file :01R331 08.07.2004
______________________________________________________
Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry
11-07-2004 17:00:41 - Scan started. (Smart mode)
Listing running processes
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 11-07-2004 15:56:23
BasePriority : Normal
#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ThreadCreationTime : 11-07-2004 15:56:26
BasePriority : High
#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 11-07-2004 15:56:27
BasePriority : Normal
FileSize : 99 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Microsoft
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 18/08/2001 19:00:00
#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 11-07-2004 15:56:27
BasePriority : Normal
FileSize : 11 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
OriginalFilename : lsass.exe
ProductName : Microsoft
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 29/08/2002 02:41:26
#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 11-07-2004 15:56:28
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 18/08/2001 19:00:00
#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-07-2004 15:56:28
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 18/08/2001 19:00:00
#:7 [ccsetmgr.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ThreadCreationTime : 11-07-2004 15:56:31
BasePriority : Normal
FileSize : 229 KB
FileVersion : 2.1.1.700
ProductVersion : 2.1.1.700
Copyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Common Client Settings Manager Service
InternalName : ccSetMgr
OriginalFilename : ccSetMgr.exe
ProductName : Common Client
Created on : 08/12/2003 16:18:44
Last accessed : 10/07/2004 23:00:00
Last modified : 08/12/2003 16:18:44
#:8 [ccevtmgr.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ThreadCreationTime : 11-07-2004 15:56:31
BasePriority : Normal
FileSize : 249 KB
FileVersion : 2.1.1.700
ProductVersion : 2.1.1.700
Copyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Common Client Event Manager Service
InternalName : ccEvtMgr
OriginalFilename : ccEvtMgr.exe
ProductName : Common Client
Created on : 08/12/2003 16:18:36
Last accessed : 10/07/2004 23:00:00
Last modified : 08/12/2003 16:18:36
#:9 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 11-07-2004 15:56:32
BasePriority : Normal
FileSize : 50 KB
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
OriginalFilename : spoolsv.exe
ProductName : Microsoft
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 18/08/2001 19:00:00
#:10 [explorer.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 11-07-2004 15:56:35
BasePriority : Normal
FileSize : 973 KB
FileVersion : 6.00.2800.1221 (xpsp2.030511-1403)
ProductVersion : 6.00.2800.1221
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft
Created on : 11/05/2003 20:12:10
Last accessed : 10/07/2004 23:00:00
Last modified : 11/05/2003 20:12:10
#:11 [ccproxy.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ThreadCreationTime : 11-07-2004 15:56:35
BasePriority : Normal
FileSize : 213 KB
FileVersion : 2.1.2.800
ProductVersion : 2.1.2.800
Copyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Common Client Network Proxy Service
InternalName : ccProxy
OriginalFilename : ccProxy.exe
ProductName : Common Client
Created on : 30/06/2004 12:28:10
Last accessed : 10/07/2004 23:00:00
Last modified : 27/01/2004 18:06:54
#:12 [mdm.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\
ThreadCreationTime : 11-07-2004 15:56:35
BasePriority : Normal
FileSize : 314 KB
FileVersion : 7.00.9466
ProductVersion : 7.00.9466
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
OriginalFilename : mdm.exe
ProductName : Microsoft
Created on : 19/06/2003 22:25:00
Last accessed : 10/07/2004 23:00:00
Last modified : 19/06/2003 22:25:00
#:13 [navapsvc.exe]
FilePath : C:\Program Files\Norton Internet Security\Norton AntiVirus\
ThreadCreationTime : 11-07-2004 15:56:36
BasePriority : Normal
FileSize : 155 KB
FileVersion : 10.00.2
ProductVersion : 10.00.2
Copyright : Norton AntiVirus 2004 for Windows 98/ME/2000/XP Copyright (c) 2003 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
OriginalFilename : NAVAPSVC.EXE
ProductName : Norton AntiVirus
Created on : 30/06/2004 12:28:09
Last accessed : 10/07/2004 23:00:00
Last modified : 23/04/2004 10:04:18
#:14 [savscan.exe]
FilePath : C:\Program Files\Norton Internet Security\Norton AntiVirus\
ThreadCreationTime : 11-07-2004 15:56:36
BasePriority : Normal
FileSize : 189 KB
FileVersion : 9.2.1.14
ProductVersion : 9.2
Copyright : Copyright (c) 2003 Symantec Corporation
CompanyName : Symantec Corporation
FileDescription : Symantec AntiVirus Scanner
InternalName : SAVSCAN
OriginalFilename : SAVSCAN.EXE
ProductName : Symantec AntiVirus AutoProtect
Created on : 07/11/2003 17:46:58
Last accessed : 10/07/2004 23:00:00
Last modified : 07/11/2003 17:46:58
#:15 [sndsrvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ThreadCreationTime : 11-07-2004 15:56:37
BasePriority : Normal
FileSize : 189 KB
FileVersion : 5.3.2.67
ProductVersion : 5.3
Copyright : Copyright 2002, 2003 Symantec Corporation
CompanyName : Symantec Corporation
FileDescription : Network Driver Service
InternalName : SndSrvc
OriginalFilename : SndSrvc.exe
ProductName : Symantec Security Drivers
Created on : 29/06/2004 15:14:38
Last accessed : 10/07/2004 23:00:00
Last modified : 29/06/2004 15:14:38
#:16 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-07-2004 15:56:38
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 18/08/2001 19:00:00
#:17 [symlcsvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\
ThreadCreationTime : 11-07-2004 15:56:38
BasePriority : Normal
FileSize : 572 KB
FileVersion : 1, 8, 48, 79
ProductVersion : 1, 8, 48, 79
Copyright : Copyright (C) 2003
CompanyName : Symantec Corporation
FileDescription : Symantec Core Component
InternalName : symlcsvc
OriginalFilename : symlcsvc.exe
ProductName : Symantec Core Component
Created on : 30/06/2004 11:44:40
Last accessed : 10/07/2004 23:00:00
Last modified : 30/06/2004 11:44:42
#:18 [igfxtray.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-07-2004 15:56:39
BasePriority : Normal
FileSize : 152 KB
FileVersion : 3,0,0,2104
ProductVersion : 7,0,0,2104
Copyright : Copyright 1999-2003, Intel Corporation
CompanyName : Intel Corporation
FileDescription : igfxTray Module
InternalName : IGFXTRAY
OriginalFilename : IGFXTRAY.EXE
ProductName : Intel(R) Common User Interface
Created on : 19/05/2003 22:52:39
Last accessed : 10/07/2004 23:00:00
Last modified : 06/04/2003 23:19:52
#:19 [hkcmd.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-07-2004 15:56:39
BasePriority : Normal
FileSize : 112 KB
FileVersion : 3,0,0,2104
ProductVersion : 7,0,0,2104
Copyright : Copyright 1999-2003, Intel Corporation
CompanyName : Intel Corporation
FileDescription : hkcmd Module
InternalName : HKCMD
OriginalFilename : HKCMD.EXE
ProductName : Intel(R) Common User Interface
Created on : 19/05/2003 22:52:38
Last accessed : 10/07/2004 23:00:00
Last modified : 06/04/2003 23:07:38
#:20 [almxptray.exe]
FilePath : C:\Program Files\Acer\Notebook Manager\
ThreadCreationTime : 11-07-2004 15:56:39
BasePriority : Normal
FileSize : 498 KB
FileVersion : 2.0.10.3
ProductVersion : 2.0.10
CompanyName : Acer
Created on : 16/05/2003 16:09:34
Last accessed : 10/07/2004 23:00:00
Last modified : 16/05/2003 16:09:34
#:21 [syntplpr.exe]
FilePath : C:\Program Files\Synaptics\SynTP\
ThreadCreationTime : 11-07-2004 15:56:39
BasePriority : Normal
FileSize : 108 KB
FileVersion : 7.5.5 24Apr03
ProductVersion : 7.5.5 24Apr03
Copyright : Copyright (C) Synaptics, Inc. 1996-2003
CompanyName : Synaptics, Inc.
FileDescription : TouchPad Driver Helper Application
InternalName : SynTPLpr
OriginalFilename : SynTPLpr.exe
ProductName : Progressive Touch
Created on : 26/05/2003 14:30:15
Last accessed : 10/07/2004 23:00:00
Last modified : 24/04/2003 15:51:36
#:22 [syntpenh.exe]
FilePath : C:\Program Files\Synaptics\SynTP\
ThreadCreationTime : 11-07-2004 15:56:40
BasePriority : Normal
FileSize : 596 KB
FileVersion : 7.5.5 24Apr03
ProductVersion : 7.5.5 24Apr03
Copyright : Copyright (C) Synaptics, Inc. 1996-2003
CompanyName : Synaptics, Inc.
FileDescription : Synaptics TouchPad Enhancements
InternalName : Scrolleroo
OriginalFilename : SynTPEnh.exe
ProductName : Progressive Touch
Created on : 26/05/2003 14:30:15
Last accessed : 10/07/2004 23:00:00
Last modified : 24/04/2003 15:44:56
#:23 [launchap.exe]
FilePath : C:\Program Files\Launch Manager\
ThreadCreationTime : 11-07-2004 15:56:40
BasePriority : Normal
FileSize : 32 KB
FileVersion : 1, 0, 0, 3
ProductVersion : 1, 0, 0, 3
Copyright : Copyright (C) 2001
FileDescription : LaunchAp MFC Application
InternalName : LaunchAp
OriginalFilename : LaunchAp.EXE
ProductName : LaunchAp Application
Created on : 19/05/2003 22:58:00
Last accessed : 10/07/2004 23:00:00
Last modified : 12/05/2003 13:28:50
#:24 [powerkey.exe]
FilePath : C:\Program Files\Launch Manager\
ThreadCreationTime : 11-07-2004 15:56:40
BasePriority : Normal
FileSize : 92 KB
FileVersion : 1, 4, 4, 0
ProductVersion : 1, 4, 4, 0
Copyright : Copyright
FileDescription : Powerkey
InternalName : Powerkey
OriginalFilename : Powerkey.exe
Created on : 02/06/2003 10:45:26
Last accessed : 10/07/2004 23:00:00
Last modified : 30/08/2002 14:02:48
#:25 [hotkeyapp.exe]
FilePath : C:\Program Files\Launch Manager\
ThreadCreationTime : 11-07-2004 15:56:40
BasePriority : Normal
FileSize : 44 KB
FileVersion : 1, 0, 4, 7
ProductVersion : 1, 0, 4, 7
Copyright : Copyright c 2002
CompanyName : Wistron
FileDescription : HotkeyApp
InternalName : HotkeyApp
OriginalFilename : HotkeyApp.exe
ProductName : Wistron HotkeyApp
Created on : 02/06/2003 10:45:25
Last accessed : 10/07/2004 23:00:00
Last modified : 19/05/2003 10:51:32
#:26 [ctrlvol.exe]
FilePath : C:\Program Files\Launch Manager\
ThreadCreationTime : 11-07-2004 15:56:41
BasePriority : Normal
FileSize : 164 KB
FileVersion : 1, 0, 0, 2
ProductVersion : 1, 0, 0, 2
Copyright : Copyright c 2003
CompanyName : Wistron
FileDescription : ctrlvol
InternalName : ctrlvol
OriginalFilename : ctrlvol.exe
ProductName : Wistron ctrlvol
Created on : 02/06/2003 10:45:25
Last accessed : 10/07/2004 23:00:00
Last modified : 12/05/2003 14:05:16
#:27 [wbutton.exe]
FilePath : C:\Program Files\Launch Manager\
ThreadCreationTime : 11-07-2004 15:56:41
BasePriority : Normal
FileSize : 52 KB
FileVersion : 1, 0, 2, 4
ProductVersion : 1, 0, 2, 4
Copyright : Copyright (C) 2001
FileDescription : WButton MFC Application
InternalName : WButton
OriginalFilename : WButton.EXE
ProductName : WButton Application
Created on : 02/06/2003 10:45:25
Last accessed : 10/07/2004 23:00:00
Last modified : 28/05/2003 09:02:34
#:28 [agrsmmsg.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 11-07-2004 15:56:41
BasePriority : Normal
FileSize : 86 KB
FileVersion : 2.1.25 2.1.25 02/14/2003 11:58:58
ProductVersion : 2.1.25 2.1.25 02/14/2003 11:58:58
Copyright : Copyright
CompanyName : Agere Systems
FileDescription : SoftModem Messaging Applet
InternalName : smdmstat.exe
OriginalFilename : smdmstat.exe
ProductName : Agere SoftModem Messaging Applet
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 14/02/2003 10:59:00
#:29 [ltmoh.exe]
FilePath : C:\Program Files\ltmoh\
ThreadCreationTime : 11-07-2004 15:56:41
BasePriority : Normal
FileSize : 168 KB
FileVersion : 1.68
ProductVersion : 1.68
Copyright : Agere Copyright
CompanyName : Agere Systems
FileDescription : LtMoh MFC Application
InternalName : LtMoh
OriginalFilename : LtMoh.EXE
ProductName : LtMoh Application
Created on : 29/06/2004 20:22:24
Last accessed : 10/07/2004 23:00:00
Last modified : 25/11/2002 09:23:20
#:30 [ccapp.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ThreadCreationTime : 11-07-2004 15:56:41
BasePriority : Normal
FileSize : 69 KB
FileVersion : 2.1.1.700
ProductVersion : 2.1.1.700
Copyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Common Client User Session
InternalName : ccApp
OriginalFilename : ccApp.exe
ProductName : Common Client
Created on : 08/12/2003 16:18:34
Last accessed : 10/07/2004 23:00:00
Last modified : 08/12/2003 16:18:34
#:31 [realplay.exe]
FilePath : C:\Program Files\Real\RealPlayer\
ThreadCreationTime : 11-07-2004 15:56:42
BasePriority : Normal
FileSize : 20 KB
FileVersion : 6.0.8.122
ProductVersion : 6.0.8.122
Copyright : Copyright
CompanyName : RealNetworks, Inc.
FileDescription : RealPlayer
InternalName : REALPLAY
OriginalFilename : REALPLAY.EXE
ProductName : RealPlayer (32-bit)
Created on : 02/07/2004 10:02:07
Last accessed : 10/07/2004 23:00:00
Last modified : 02/07/2004 10:02:08
#:32 [lvcoms.exe]
FilePath : C:\Program Files\Common Files\Logitech\QCDriver3\
ThreadCreationTime : 11-07-2004 15:56:42
BasePriority : Normal
FileSize : 124 KB
FileVersion : 7.3.0.1113
ProductVersion : 7.3.0.1113
Copyright : (c) 1996-2002 Logitech. All rights reserved.
CompanyName : Logitech Inc.
FileDescription : LVCom Server
InternalName : LVComS.exe
OriginalFilename : LVComS.exe
ProductName : Logitech ImageStudio
Created on : 02/07/2004 10:05:06
Last accessed : 10/07/2004 23:00:00
Last modified : 10/12/2002 16:54:04
#:33 [logitray.exe]
FilePath : C:\Program Files\Logitech\ImageStudio\
ThreadCreationTime : 11-07-2004 15:56:42
BasePriority : Normal
FileSize : 60 KB
FileVersion : 7.3.0.1113
ProductVersion : 7.3.0.1113
Copyright : (c) 1996-2002 Logitech. All rights reserved.
CompanyName : Logitech Inc.
FileDescription : ImageStudio Tray Application
InternalName : LogiTray.exe
OriginalFilename : LogiTray.exe
ProductName : Logitech ImageStudio
Created on : 10/12/2002 17:31:34
Last accessed : 10/07/2004 23:00:00
Last modified : 10/12/2002 17:31:34
#:34 [backweb-8876480.exe]
FilePath : C:\Program Files\Logitech\Desktop Messenger\8876480\Program\
ThreadCreationTime : 11-07-2004 15:56:42
BasePriority : Normal
FileSize : 16 KB
Created on : 02/07/2004 10:00:27
Last accessed : 10/07/2004 23:00:00
Last modified : 02/07/2004 10:00:26
#:35 [ctfmon.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 11-07-2004 15:56:42
BasePriority : Normal
FileSize : 13 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
OriginalFilename : CTFMON.EXE
ProductName : Microsoft
Created on : 31/12/1979 23:00:00
Last accessed : 10/07/2004 23:00:00
Last modified : 29/08/2002 02:41:22
#:36 [hpotdd01.exe]
FilePath : C:\Program Files\Hewlett-Packard\Digital Imaging\bin\
ThreadCreationTime : 11-07-2004 15:56:43
BasePriority : Normal
FileSize : 28 KB
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
Copyright : Copyright
CompanyName : Hewlett-Packard
FileDescription : hpotdd01
InternalName : hpotdd01
OriginalFilename : hpotdd01.exe
ProductName : Hewlett-Packard hpotdd01
Created on : 06/04/2003 00:06:58
Last accessed : 10/07/2004 23:00:00
Last modified : 06/04/2003 00:06:58
#:37 [hpobnz08.exe]
FilePath : C:\Program Files\Hewlett-Packard\Digital Imaging\bin\
ThreadCreationTime : 11-07-2004 15:56:43
BasePriority : Normal
FileSize : 316 KB
FileVersion : 4.2.0.020
ProductVersion : 2.4.1.020
Copyright : Copyright (C) Hewlett-Packard Co. 1995-2001
CompanyName : Hewlett-Packard Co.
FileDescription : HP OfficeJet COM Device Objects
InternalName : HPOBNZ08
OriginalFilename : HPOBNZ08.EXE
ProductName : hp digital imaging - hp all-in-one series
Created on : 05/04/2003 23:37:10
Last accessed : 10/07/2004 23:00:00
Last modified : 05/04/2003 23:37:10
#:38 [msmsgs.exe]
FilePath : C:\Program Files\Messenger\
ThreadCreationTime : 11-07-2004 15:56:50
BasePriority : Normal
FileSize : 1456 KB
FileVersion : 4.7.2009
ProductVersion : Version 4.7
Copyright : Copyright (c) Microsoft Corporation 1997-2003
CompanyName : Microsoft Corporation
FileDescription : Messenger
InternalName : msmsgs
OriginalFilename : msmsgs.exe
ProductName : Messenger
Created on : 14/04/2003 18:30:14
Last accessed : 10/07/2004 23:00:00
Last modified : 14/04/2003 18:30:14
#:39 [hpoevm08.exe]
FilePath : C:\Program Files\Hewlett-Packard\Digital Imaging\bin\
ThreadCreationTime : 11-07-2004 15:56:52
BasePriority : Normal
FileSize : 280 KB
FileVersion : 4.2.0.020
ProductVersion : 2.4.1.020
Copyright : Copyright (C) Hewlett-Packard Co. 1995-2001
CompanyName : Hewlett-Packard Co.
FileDescription : HP OfficeJet COM Event Manager
InternalName : HPOEVM08
OriginalFilename : HPOEVM08.EXE
ProductName : hp digital imaging - hp all-in-one series
Created on : 05/04/2003 23:45:10
Last accessed : 10/07/2004 23:00:00
Last modified : 05/04/2003 23:45:10
#:40 [tesconet.exe]
FilePath : C:\Program Files\Tesconet\
ThreadCreationTime : 11-07-2004 15:56:53
BasePriority : Normal
FileSize : 120 KB
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
Copyright : Copyright (C) Rytec Consultants Ltd 2001.
CompanyName : Rytec Consultants Ltd.
FileDescription : RyDial MFC Application
InternalName : RyDial
OriginalFilename : RyDial.EXE
ProductName : RyDial Application
Created on : 01/08/2002 16:58:42
Last accessed : 10/07/2004 23:00:00
Last modified : 01/08/2002 16:58:42
#:41 [hposts08.exe]
FilePath : C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\
ThreadCreationTime : 11-07-2004 15:56:57
BasePriority : Normal
FileSize : 304 KB
FileVersion : 4.2.0.020
ProductVersion : 2.4.1.020
Copyright : Copyright (C) Hewlett-Packard Co. 1995-2001
CompanyName : Hewlett-Packard Co.
FileDescription : HP OfficeJet Status
InternalName : HPOSTS08
OriginalFilename : HPOSTS08.EXE
ProductName : hp digital imaging - hp all-in-one series
Created on : 05/04/2003 23:55:04
Last accessed : 10/07/2004 23:00:00
Last modified : 05/04/2003 23:55:04
#:42 [ad-aware.exe]
FilePath : C:\PROGRA~1\LAVASOFT\AD-AWA~1\
ThreadCreationTime : 11-07-2004 16:00:24
BasePriority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 10/07/2004 22:56:32
Last accessed : 10/07/2004 23:00:00
Last modified : 12/07/2003 20:00:20
Memory scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Started registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Started deep registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pageabout:blank
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "about:blank"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "about:blank"
Deep registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 1
Objects found so far: 1
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Deep scanning and examining files (C

¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Performing conditional scans..
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Conditional scan result:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 1
17:03:18 Scan complete
Summary of this scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Total scanning time :00:02:36:445
Objects scanned :48661
Objects identified :1
Objects ignored :0
New objects :1
Thanks in advance