Precast
10 May 2007, 3:45am
Greetings all!
I made the mistake of trying to get some stuff on astalavista. I knew better but I did it anyway and ended up with a sick computer.
I'm running Vista and I realized I had an issue when IE opened on its own (I usually use Firefox) and it tried to visit a web page that only contained a couple lines of text. IE now opens and tries to access different similar pages of that same site every couple minutes. I could post the link but I'm guessing you wouldn't like me much after that.
Here is a summery of what I've done thus far. When you guys get a chance, could you take a look at it?
Thanks.
Precast
Summary of what I've done thus far:
1) I have run ATF Cleaner.
2) I have run Ad Aware SE (1 critical object in registry scan - Log below).
3) I ran Spybot Search & Destroy (which found "no immediate threats")
4) I ran Spyware Doctor (which found Trojan.Downloader.Small.CML - 9 infectons - log below)
5) I HAVE NOT run Online scans - Apparently IE 7.0.6 doesn't like online scans. I fooled with all the IE security settings and still couldn't get any of them past the Terms of Usage.
6) (Hijack log in next post.)
//////////////////////////////////
AD AWARE SE LOG FILE
Ad-Aware SE Build 1.06r1
Logfile Created on:Tuesday, May 08, 2007 9:32:30 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R169 07.05.2007
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Windows(TAC index:3):1 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
5-8-2007 9:32:30 PM - Scan started. (Full System Scan)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 464
ThreadCreationTime : 5-9-2007 12:46:05 AM
BasePriority : Normal
#:2 [csrss.exe]
FilePath : C:\Windows\system32\
ProcessID : 540
ThreadCreationTime : 5-9-2007 12:46:07 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Client Server Runtime Process
InternalName : CSRSS.Exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CSRSS.Exe.MUI
#:3 [wininit.exe]
FilePath : C:\Windows\system32\
ProcessID : 584
ThreadCreationTime : 5-9-2007 12:46:09 AM
BasePriority : High
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Start-Up Application
InternalName : WinInit
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WinInit.exe.mui
#:4 [csrss.exe]
FilePath : C:\Windows\system32\
ProcessID : 596
ThreadCreationTime : 5-9-2007 12:46:09 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Client Server Runtime Process
InternalName : CSRSS.Exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CSRSS.Exe.MUI
#:5 [services.exe]
FilePath : C:\Windows\system32\
ProcessID : 628
ThreadCreationTime : 5-9-2007 12:46:09 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe.mui
#:6 [lsass.exe]
FilePath : C:\Windows\system32\
ProcessID : 644
ThreadCreationTime : 5-9-2007 12:46:09 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Local Security Authority Process
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe.mui
#:7 [lsm.exe]
FilePath : C:\Windows\system32\
ProcessID : 652
ThreadCreationTime : 5-9-2007 12:46:09 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Local Session Manager Service
InternalName : lsm.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsm.exe.mui
#:8 [winlogon.exe]
FilePath : C:\Windows\system32\
ProcessID : 732
ThreadCreationTime : 5-9-2007 12:46:09 AM
BasePriority : High
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Logon Application
InternalName : winlogon
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WINLOGON.EXE.MUI
#:9 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 836
ThreadCreationTime : 5-9-2007 12:46:10 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:10 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 924
ThreadCreationTime : 5-9-2007 12:46:10 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:11 [svchost.exe]
FilePath : C:\Windows\System32\
ProcessID : 980
ThreadCreationTime : 5-9-2007 12:46:10 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:12 [svchost.exe]
FilePath : C:\Windows\System32\
ProcessID : 1064
ThreadCreationTime : 5-9-2007 12:46:11 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:13 [svchost.exe]
FilePath : C:\Windows\System32\
ProcessID : 1156
ThreadCreationTime : 5-9-2007 12:46:12 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:14 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 1184
ThreadCreationTime : 5-9-2007 12:46:12 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:15 [slsvc.exe]
FilePath : C:\Windows\system32\
ProcessID : 1288
ThreadCreationTime : 5-9-2007 12:46:14 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Microsoft Software Licensing Service
InternalName : SLService
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : SLService
#:16 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 1328
ThreadCreationTime : 5-9-2007 12:46:15 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:17 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 1496
ThreadCreationTime : 5-9-2007 12:46:16 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:18 [dwm.exe]
FilePath : C:\Windows\system32\
ProcessID : 1700
ThreadCreationTime : 5-9-2007 12:46:18 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Desktop Window Manager
InternalName : dwm.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : dwm.exe.mui
#:19 [explorer.exe]
FilePath : C:\Windows\
ProcessID : 1728
ThreadCreationTime : 5-9-2007 12:46:18 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE.MUI
#:20 [spoolsv.exe]
FilePath : C:\Windows\System32\
ProcessID : 1784
ThreadCreationTime : 5-9-2007 12:46:18 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe.mui
#:21 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 1808
ThreadCreationTime : 5-9-2007 12:46:18 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:22 [taskeng.exe]
FilePath : C:\Windows\system32\
ProcessID : 1848
ThreadCreationTime : 5-9-2007 12:46:19 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Task Scheduler Engine
InternalName : TaskEng
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : taskeng.exe.mui
#:23 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 1996
ThreadCreationTime : 5-9-2007 12:46:21 AM
BasePriority : Normal
FileVersion : 0.1.0.3760
ProductVersion : 0.1.0.3760
ProductName : RealPlayer (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
LegalTrademarks : RealAudio(tm) is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe
#:24 [ituneshelper.exe]
FilePath : C:\Program Files\iTunes\
ProcessID : 2016
ThreadCreationTime : 5-9-2007 12:46:21 AM
BasePriority : Normal
FileVersion : 7.1.1.5
ProductVersion : 7.1.1.5
ProductName : iTunes
CompanyName : Apple Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2007 Apple Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe
#:25 [smanager.7.exe]
FilePath : C:\Windows\
ProcessID : 2028
ThreadCreationTime : 5-9-2007 12:46:21 AM
BasePriority : Normal
#:26 [sdtrayapp.exe]
FilePath : C:\Program Files\Spyware Doctor\
ProcessID : 316
ThreadCreationTime : 5-9-2007 12:46:21 AM
BasePriority : Normal
FileVersion : 5.0.0.37
ProductVersion : 5.0
CompanyName : PC Tools
FileDescription : Spyware Doctor Tray
LegalCopyright : Copyright ? 2007 PC Tools. All rights reserved.
#:27 [sidebar.exe]
FilePath : C:\Program Files\Windows Sidebar\
ProcessID : 384
ThreadCreationTime : 5-9-2007 12:46:22 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 1.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Sidebar
InternalName : Windows Sidebar
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : sidebar.EXE.MUI
#:28 [ehtray.exe]
FilePath : C:\Windows\ehome\
ProcessID : 472
ThreadCreationTime : 5-9-2007 12:46:22 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Media Center Tray Applet
InternalName : ehtray.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ehtray.exe
#:29 [pnagent.exe]
FilePath : C:\Program Files\Citrix\ICA Client\
ProcessID : 844
ThreadCreationTime : 5-9-2007 12:46:22 AM
BasePriority : Normal
FileVersion : 10.00.52110
ProductVersion : 10.00
ProductName : Citrix ICA Client
CompanyName : Citrix Systems, Inc.
FileDescription : Citrix ICA Client PNAgent (Win32)
InternalName : PNAGENT
LegalCopyright : Copyright (c) 1990-2006 Citrix Systems, Inc.
OriginalFilename : PNAGENT.EXE
#:30 [ehmsas.exe]
FilePath : C:\Windows\ehome\
ProcessID : 920
ThreadCreationTime : 5-9-2007 12:46:24 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Media Center Media Status Aggregator Service
InternalName : eHMSAS.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ehMSAS.exe.mui
#:31 [sidebar.exe]
FilePath : C:\Program Files\Windows Sidebar\
ProcessID : 1384
ThreadCreationTime : 5-9-2007 12:46:27 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 1.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Sidebar
InternalName : Windows Sidebar
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : sidebar.EXE.MUI
#:32 [guard.exe]
FilePath : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\
ProcessID : 2732
ThreadCreationTime : 5-9-2007 12:47:02 AM
BasePriority : Normal
FileVersion : 7, 5, 0, 47
ProductVersion : 7, 5, 0, 47
ProductName : AVG Anti-Spyware
CompanyName : Anti-Malware Development a.s.
FileDescription : AVG Anti-Spyware guard
InternalName : AVG Anti-Spyware guard
LegalCopyright : Copyright © 2006 Anti-Malware Development a.s.
OriginalFilename : guard.exe
#:33 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 2748
ThreadCreationTime : 5-9-2007 12:47:05 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:34 [clcapsvc.exe]
FilePath : C:\Program Files\HP\QuickPlay\Kernel\TV\
ProcessID : 2764
ThreadCreationTime : 5-9-2007 12:47:06 AM
BasePriority : Normal
FileVersion : 5.00.3517
ProductVersion : 5.00.3517
ProductName : CLCapSvc Module
FileDescription : CLCapSvc Module
InternalName : CLCapSvc
LegalCopyright : Copyright 2004
OriginalFilename : CLCapSvc.EXE
#:35 [hphc_service.exe]
FilePath : C:\Program Files\Hewlett-Packard\HP Health Check\
ProcessID : 2800
ThreadCreationTime : 5-9-2007 12:47:06 AM
BasePriority : Normal
#:36 [lssrvc.exe]
FilePath : C:\Program Files\Common Files\LightScribe\
ProcessID : 2992
ThreadCreationTime : 5-9-2007 12:47:07 AM
BasePriority : Normal
FileVersion : 1.4.124.1
ProductName : LightScribe
CompanyName : Hewlett-Packard Company
LegalCopyright : © Copyright 2003-2006 Hewlett-Packard Development Company, LP
OriginalFilename : LSSrvc.exe
#:37 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 3024
ThreadCreationTime : 5-9-2007 12:47:07 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:38 [svcntaux.exe]
FilePath : C:\Program Files\Spyware Doctor\
ProcessID : 3096
ThreadCreationTime : 5-9-2007 12:47:07 AM
BasePriority : Normal
FileVersion : 5.0.0.21
ProductVersion : 5.0
CompanyName : PC Tools
LegalCopyright : Copyright ? 2006 PC Tools. All rights reserved.
#:39 [swdsvc.exe]
FilePath : C:\Program Files\Spyware Doctor\
ProcessID : 3168
ThreadCreationTime : 5-9-2007 12:47:08 AM
BasePriority : Normal
FileVersion : 5.0.0.57
ProductVersion : 5.0
CompanyName : PC Tools
FileDescription : Spyware Doctor Service
LegalCopyright : Copyright © 2006 PC Tools. All rights reserved.
#:40 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 3224
ThreadCreationTime : 5-9-2007 12:47:10 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:41 [tavsvc.exe]
FilePath : C:\Program Files\Trend Micro\AntiVirus 2007\
ProcessID : 3240
ThreadCreationTime : 5-9-2007 12:47:10 AM
BasePriority : Normal
FileVersion : 15.1.0.1206
ProductVersion : 15.1.0
ProductName : Trend Micro AntiVirus 2007
CompanyName : Trend Micro Inc.
FileDescription : Trend Micro AntiVirus Service Manager
InternalName : tavsvc
LegalCopyright : Copyright (C) 1995-2007 Trend Micro Incorporated. All rights reserved.
LegalTrademarks : Copyright (C) 1995-2007 Trend Micro Incorporated.
OriginalFilename : tavsvc.exe
#:42 [tmproxy.exe]
FilePath : C:\Program Files\Trend Micro\AntiVirus 2007\Components\
ProcessID : 3276
ThreadCreationTime : 5-9-2007 12:47:11 AM
BasePriority : Normal
FileVersion : 3.1.0.1013
ProductVersion : 3.1.0
ProductName : Trend Micro Network Security Components 3.1
CompanyName : Trend Micro Inc.
FileDescription : Trend Micro Proxy Service Controller
InternalName : TmProxy.exe
LegalCopyright : Copyright (C) 2001-2006 Trend Micro Inc. All rights reserved.
LegalTrademarks : Copyright (C) Trend Micro Inc.
OriginalFilename : TmProxy.exe
#:43 [spysweeper.exe]
FilePath : C:\Program Files\Webroot\Spy Sweeper\
ProcessID : 3308
ThreadCreationTime : 5-9-2007 12:47:11 AM
BasePriority : Normal
FileVersion : 3,3,1,2592
ProductVersion : 3, 3
ProductName : Spy Sweeper SDK
CompanyName : Webroot Software, Inc.
FileDescription : Spy Sweeper Engine
LegalCopyright : Copyright (C) 2002 - 2007, All Rights Reserved.
LegalTrademarks : Spy Sweeper is a trademark of Webroot Software, Inc.
OriginalFilename : SpySweeper.exe
#:44 [svchost.exe]
FilePath : C:\Windows\System32\
ProcessID : 3492
ThreadCreationTime : 5-9-2007 12:47:13 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:45 [searchindexer.exe]
FilePath : C:\Windows\system32\
ProcessID : 3516
ThreadCreationTime : 5-9-2007 12:47:13 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Microsoft Windows Search Indexer
InternalName : SearchIndexer.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : SearchIndexer.exe.mui
#:46 [xaudio.exe]
FilePath : C:\Windows\system32\DRIVERS\
ProcessID : 3556
ThreadCreationTime : 5-9-2007 12:47:13 AM
BasePriority : Normal
#:47 [clsched.exe]
FilePath : C:\Program Files\HP\QuickPlay\Kernel\TV\
ProcessID : 3568
ThreadCreationTime : 5-9-2007 12:47:13 AM
BasePriority : Normal
FileVersion : 5.00.3517
ProductVersion : 5.00.3517
ProductName : CLSched Module
FileDescription : CLSched Module
InternalName : CLSched
LegalCopyright : Copyright 2004
OriginalFilename : CLSched.EXE
#:48 [hpqwmiex.exe]
FilePath : C:\Program Files\Hewlett-Packard\Shared\
ProcessID : 3588
ThreadCreationTime : 5-9-2007 12:47:13 AM
BasePriority : Normal
FileVersion : 2, 0, 1, 9
ProductVersion : 2, 0, 1, 9
ProductName : hpqwmiex Module
CompanyName : Hewlett-Packard Development Company, L.P.
FileDescription : hpqwmiex Module
InternalName : hpqwmiex
LegalCopyright : © Copyright 2003-2006 Hewlett-Packard Development Company, L.P.
OriginalFilename : hpqwmiex.EXE
#:49 [taskeng.exe]
FilePath : C:\Windows\system32\
ProcessID : 2532
ThreadCreationTime : 5-9-2007 12:47:55 AM
BasePriority : Below Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Task Scheduler Engine
InternalName : TaskEng
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : taskeng.exe.mui
#:50 [ipodservice.exe]
FilePath : C:\Program Files\iPod\bin\
ProcessID : 2608
ThreadCreationTime : 5-9-2007 12:47:58 AM
BasePriority : Normal
FileVersion : 7.1.1.5
ProductVersion : 7.1.1.5
ProductName : iTunes
CompanyName : Apple Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2007 Apple Inc. All Rights Reserved.
OriginalFilename : iPodService.exe
#:51 [notepad.exe]
FilePath : C:\Windows\system32\
ProcessID : 1912
ThreadCreationTime : 5-9-2007 12:49:18 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Notepad
InternalName : Notepad
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : NOTEPAD.EXE.MUI
#:52 [unsecapp.exe]
FilePath : C:\Windows\system32\wbem\
ProcessID : 3544
ThreadCreationTime : 5-9-2007 12:50:09 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Sink to receive asynchronous callbacks for WMI client application
InternalName : unsecapp.dll
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : unsecapp.dll
#:53 [wmiprvse.exe]
FilePath : C:\Windows\system32\wbem\
ProcessID : 1924
ThreadCreationTime : 5-9-2007 12:50:10 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : WMI Provider Host
InternalName : Wmiprvse.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : Wmiprvse.exe
#:54 [swdoctor.exe]
FilePath : C:\Program Files\Spyware Doctor\
ProcessID : 2956
ThreadCreationTime : 5-9-2007 12:52:18 AM
BasePriority : Normal
FileVersion : 5.0.0.184
ProductVersion : 5.0
CompanyName : PC Tools
FileDescription : Spyware Doctor
LegalCopyright : Copyright ? 2006 PC Tools. All rights reserved.
#:55 [spybotsd.exe]
FilePath : C:\Program Files\Spybot - Search & Destroy\
ProcessID : 5988
ThreadCreationTime : 5-9-2007 1:06:38 AM
BasePriority : Normal
FileVersion : 1.4.0.3
ProductVersion : 1, 4, 0, 3
ProductName : SpyBot-S&D
CompanyName : Safer Networking Limited
FileDescription : Spybot - Search & Destroy
InternalName : SpybotSD
LegalCopyright : © 2000-2005 Patrick M. Kolla / Safer Networking Limited. Alle Rechte vorbehalten.
LegalTrademarks : "Spybot" und "Spybot - Search & Destroy" sind registrierte Warenzeichen.
OriginalFilename : SpyBotSD.exe
Comments : Software zum Entfernen von Spyware und ähnlichen Bedrohungen.
#:56 [firefox.exe]
FilePath : C:\Program Files\Mozilla Firefox\
ProcessID : 4332
ThreadCreationTime : 5-9-2007 1:12:35 AM
BasePriority : Normal
#:57 [ad-aware.exe]
FilePath : C:\PROGRA~1\Lavasoft\AD-AWA~1\
ProcessID : 4136
ThreadCreationTime : 5-9-2007 1:27:29 AM
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
#:58 [ieuser.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 5128
ThreadCreationTime : 5-9-2007 1:30:46 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : ieuser.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ieuser.exe.mui
#:59 [searchprotocolhost.exe]
FilePath : C:\Windows\system32\
ProcessID : 5308
ThreadCreationTime : 5-9-2007 1:31:57 AM
BasePriority : Idle
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Microsoft Windows Search Protocol Host
InternalName : SearchProtocolHost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : SearchProtocolHost.exe
#:60 [searchfilterhost.exe]
FilePath : C:\Windows\system32\
ProcessID : 5344
ThreadCreationTime : 5-9-2007 1:31:58 AM
BasePriority : Idle
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Microsoft Windows Search Filter Host
InternalName : SearchFilterHost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : SearchFilterHost.exe
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Windows Object Recognized!
Type : RegData
Data :
TAC Rating : 3
Category : Vulnerability
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-110746431-3671446382-3770039454-1000\software\policies\microsoft\internet explorer\control panel
Value : Homepage
Data :
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 1
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Deep scanning and examining files (D:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for D:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Scanning Hosts file......
Hosts file location:"C:\Windows\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
2 entries scanned.
New critical objects:0
Objects found so far: 1
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
10:24:03 PM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:51:33.166
Objects scanned:481254
Objects identified:1
Objects ignored:0
New critical objects:1
/////////////////////////////////////////////////
////////////////////////////////////////////////
PC TOOLS SPYWARE DOCTOR - LOG FILE (from a .htm)
PC Tools Spyware Doctor
DATE STATUS
5/9/2007 7:57:40 PM:24 Service Started
Spyware Doctor Service Application started
5/9/2007 7:57:40 PM:217 OnGuards status
All OnGuards were Enabled
5/9/2007 7:57:43 PM:156 Immunizer Results
ActiveX section has been immunized, Processed 4 items.
5/9/2007 8:10:41 PM:922 Scan Started
Scan Type - Full Scan
5/9/2007 8:37:52 PM:986 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - File
Risk Level - High
Infection - C:\Windows\System32\wincis32.dll
5/9/2007 8:42:51 PM:486 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - Registry Value
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wincis32, Asynchronous
5/9/2007 8:42:51 PM:496 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - Registry Value
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wincis32, DllName
5/9/2007 8:42:51 PM:506 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - Registry Value
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wincis32, Impersonate
5/9/2007 8:42:51 PM:516 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - Registry Value
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wincis32, Startup
5/9/2007 8:42:51 PM:525 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - Registry Value
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wincis32, Shutdown
5/9/2007 8:42:51 PM:526 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - Registry Key
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wincis32
5/9/2007 8:43:37 PM:223 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - File
Risk Level - High
Infection - wincis32.dll
5/9/2007 8:43:37 PM:262 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - Startup
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\wincis32 wincis32.dll
5/9/2007 8:44:29 PM:524 Scan Finished
Scan Type - Full Scan
Items Processed - 200300
Threats Detected - 1
Infections Detected - 9
Infections Ignored - 0
I made the mistake of trying to get some stuff on astalavista. I knew better but I did it anyway and ended up with a sick computer.
I'm running Vista and I realized I had an issue when IE opened on its own (I usually use Firefox) and it tried to visit a web page that only contained a couple lines of text. IE now opens and tries to access different similar pages of that same site every couple minutes. I could post the link but I'm guessing you wouldn't like me much after that.
Here is a summery of what I've done thus far. When you guys get a chance, could you take a look at it?
Thanks.
Precast
Summary of what I've done thus far:
1) I have run ATF Cleaner.
2) I have run Ad Aware SE (1 critical object in registry scan - Log below).
3) I ran Spybot Search & Destroy (which found "no immediate threats")
4) I ran Spyware Doctor (which found Trojan.Downloader.Small.CML - 9 infectons - log below)
5) I HAVE NOT run Online scans - Apparently IE 7.0.6 doesn't like online scans. I fooled with all the IE security settings and still couldn't get any of them past the Terms of Usage.
6) (Hijack log in next post.)
//////////////////////////////////
AD AWARE SE LOG FILE
Ad-Aware SE Build 1.06r1
Logfile Created on:Tuesday, May 08, 2007 9:32:30 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R169 07.05.2007
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Windows(TAC index:3):1 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
5-8-2007 9:32:30 PM - Scan started. (Full System Scan)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 464
ThreadCreationTime : 5-9-2007 12:46:05 AM
BasePriority : Normal
#:2 [csrss.exe]
FilePath : C:\Windows\system32\
ProcessID : 540
ThreadCreationTime : 5-9-2007 12:46:07 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Client Server Runtime Process
InternalName : CSRSS.Exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CSRSS.Exe.MUI
#:3 [wininit.exe]
FilePath : C:\Windows\system32\
ProcessID : 584
ThreadCreationTime : 5-9-2007 12:46:09 AM
BasePriority : High
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Start-Up Application
InternalName : WinInit
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WinInit.exe.mui
#:4 [csrss.exe]
FilePath : C:\Windows\system32\
ProcessID : 596
ThreadCreationTime : 5-9-2007 12:46:09 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Client Server Runtime Process
InternalName : CSRSS.Exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CSRSS.Exe.MUI
#:5 [services.exe]
FilePath : C:\Windows\system32\
ProcessID : 628
ThreadCreationTime : 5-9-2007 12:46:09 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe.mui
#:6 [lsass.exe]
FilePath : C:\Windows\system32\
ProcessID : 644
ThreadCreationTime : 5-9-2007 12:46:09 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Local Security Authority Process
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe.mui
#:7 [lsm.exe]
FilePath : C:\Windows\system32\
ProcessID : 652
ThreadCreationTime : 5-9-2007 12:46:09 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Local Session Manager Service
InternalName : lsm.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsm.exe.mui
#:8 [winlogon.exe]
FilePath : C:\Windows\system32\
ProcessID : 732
ThreadCreationTime : 5-9-2007 12:46:09 AM
BasePriority : High
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Logon Application
InternalName : winlogon
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WINLOGON.EXE.MUI
#:9 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 836
ThreadCreationTime : 5-9-2007 12:46:10 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:10 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 924
ThreadCreationTime : 5-9-2007 12:46:10 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:11 [svchost.exe]
FilePath : C:\Windows\System32\
ProcessID : 980
ThreadCreationTime : 5-9-2007 12:46:10 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:12 [svchost.exe]
FilePath : C:\Windows\System32\
ProcessID : 1064
ThreadCreationTime : 5-9-2007 12:46:11 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:13 [svchost.exe]
FilePath : C:\Windows\System32\
ProcessID : 1156
ThreadCreationTime : 5-9-2007 12:46:12 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:14 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 1184
ThreadCreationTime : 5-9-2007 12:46:12 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:15 [slsvc.exe]
FilePath : C:\Windows\system32\
ProcessID : 1288
ThreadCreationTime : 5-9-2007 12:46:14 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Microsoft Software Licensing Service
InternalName : SLService
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : SLService
#:16 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 1328
ThreadCreationTime : 5-9-2007 12:46:15 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:17 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 1496
ThreadCreationTime : 5-9-2007 12:46:16 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:18 [dwm.exe]
FilePath : C:\Windows\system32\
ProcessID : 1700
ThreadCreationTime : 5-9-2007 12:46:18 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Desktop Window Manager
InternalName : dwm.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : dwm.exe.mui
#:19 [explorer.exe]
FilePath : C:\Windows\
ProcessID : 1728
ThreadCreationTime : 5-9-2007 12:46:18 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE.MUI
#:20 [spoolsv.exe]
FilePath : C:\Windows\System32\
ProcessID : 1784
ThreadCreationTime : 5-9-2007 12:46:18 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe.mui
#:21 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 1808
ThreadCreationTime : 5-9-2007 12:46:18 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:22 [taskeng.exe]
FilePath : C:\Windows\system32\
ProcessID : 1848
ThreadCreationTime : 5-9-2007 12:46:19 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Task Scheduler Engine
InternalName : TaskEng
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : taskeng.exe.mui
#:23 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 1996
ThreadCreationTime : 5-9-2007 12:46:21 AM
BasePriority : Normal
FileVersion : 0.1.0.3760
ProductVersion : 0.1.0.3760
ProductName : RealPlayer (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
LegalTrademarks : RealAudio(tm) is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe
#:24 [ituneshelper.exe]
FilePath : C:\Program Files\iTunes\
ProcessID : 2016
ThreadCreationTime : 5-9-2007 12:46:21 AM
BasePriority : Normal
FileVersion : 7.1.1.5
ProductVersion : 7.1.1.5
ProductName : iTunes
CompanyName : Apple Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2007 Apple Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe
#:25 [smanager.7.exe]
FilePath : C:\Windows\
ProcessID : 2028
ThreadCreationTime : 5-9-2007 12:46:21 AM
BasePriority : Normal
#:26 [sdtrayapp.exe]
FilePath : C:\Program Files\Spyware Doctor\
ProcessID : 316
ThreadCreationTime : 5-9-2007 12:46:21 AM
BasePriority : Normal
FileVersion : 5.0.0.37
ProductVersion : 5.0
CompanyName : PC Tools
FileDescription : Spyware Doctor Tray
LegalCopyright : Copyright ? 2007 PC Tools. All rights reserved.
#:27 [sidebar.exe]
FilePath : C:\Program Files\Windows Sidebar\
ProcessID : 384
ThreadCreationTime : 5-9-2007 12:46:22 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 1.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Sidebar
InternalName : Windows Sidebar
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : sidebar.EXE.MUI
#:28 [ehtray.exe]
FilePath : C:\Windows\ehome\
ProcessID : 472
ThreadCreationTime : 5-9-2007 12:46:22 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Media Center Tray Applet
InternalName : ehtray.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ehtray.exe
#:29 [pnagent.exe]
FilePath : C:\Program Files\Citrix\ICA Client\
ProcessID : 844
ThreadCreationTime : 5-9-2007 12:46:22 AM
BasePriority : Normal
FileVersion : 10.00.52110
ProductVersion : 10.00
ProductName : Citrix ICA Client
CompanyName : Citrix Systems, Inc.
FileDescription : Citrix ICA Client PNAgent (Win32)
InternalName : PNAGENT
LegalCopyright : Copyright (c) 1990-2006 Citrix Systems, Inc.
OriginalFilename : PNAGENT.EXE
#:30 [ehmsas.exe]
FilePath : C:\Windows\ehome\
ProcessID : 920
ThreadCreationTime : 5-9-2007 12:46:24 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Media Center Media Status Aggregator Service
InternalName : eHMSAS.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ehMSAS.exe.mui
#:31 [sidebar.exe]
FilePath : C:\Program Files\Windows Sidebar\
ProcessID : 1384
ThreadCreationTime : 5-9-2007 12:46:27 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 1.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Sidebar
InternalName : Windows Sidebar
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : sidebar.EXE.MUI
#:32 [guard.exe]
FilePath : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\
ProcessID : 2732
ThreadCreationTime : 5-9-2007 12:47:02 AM
BasePriority : Normal
FileVersion : 7, 5, 0, 47
ProductVersion : 7, 5, 0, 47
ProductName : AVG Anti-Spyware
CompanyName : Anti-Malware Development a.s.
FileDescription : AVG Anti-Spyware guard
InternalName : AVG Anti-Spyware guard
LegalCopyright : Copyright © 2006 Anti-Malware Development a.s.
OriginalFilename : guard.exe
#:33 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 2748
ThreadCreationTime : 5-9-2007 12:47:05 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:34 [clcapsvc.exe]
FilePath : C:\Program Files\HP\QuickPlay\Kernel\TV\
ProcessID : 2764
ThreadCreationTime : 5-9-2007 12:47:06 AM
BasePriority : Normal
FileVersion : 5.00.3517
ProductVersion : 5.00.3517
ProductName : CLCapSvc Module
FileDescription : CLCapSvc Module
InternalName : CLCapSvc
LegalCopyright : Copyright 2004
OriginalFilename : CLCapSvc.EXE
#:35 [hphc_service.exe]
FilePath : C:\Program Files\Hewlett-Packard\HP Health Check\
ProcessID : 2800
ThreadCreationTime : 5-9-2007 12:47:06 AM
BasePriority : Normal
#:36 [lssrvc.exe]
FilePath : C:\Program Files\Common Files\LightScribe\
ProcessID : 2992
ThreadCreationTime : 5-9-2007 12:47:07 AM
BasePriority : Normal
FileVersion : 1.4.124.1
ProductName : LightScribe
CompanyName : Hewlett-Packard Company
LegalCopyright : © Copyright 2003-2006 Hewlett-Packard Development Company, LP
OriginalFilename : LSSrvc.exe
#:37 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 3024
ThreadCreationTime : 5-9-2007 12:47:07 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:38 [svcntaux.exe]
FilePath : C:\Program Files\Spyware Doctor\
ProcessID : 3096
ThreadCreationTime : 5-9-2007 12:47:07 AM
BasePriority : Normal
FileVersion : 5.0.0.21
ProductVersion : 5.0
CompanyName : PC Tools
LegalCopyright : Copyright ? 2006 PC Tools. All rights reserved.
#:39 [swdsvc.exe]
FilePath : C:\Program Files\Spyware Doctor\
ProcessID : 3168
ThreadCreationTime : 5-9-2007 12:47:08 AM
BasePriority : Normal
FileVersion : 5.0.0.57
ProductVersion : 5.0
CompanyName : PC Tools
FileDescription : Spyware Doctor Service
LegalCopyright : Copyright © 2006 PC Tools. All rights reserved.
#:40 [svchost.exe]
FilePath : C:\Windows\system32\
ProcessID : 3224
ThreadCreationTime : 5-9-2007 12:47:10 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:41 [tavsvc.exe]
FilePath : C:\Program Files\Trend Micro\AntiVirus 2007\
ProcessID : 3240
ThreadCreationTime : 5-9-2007 12:47:10 AM
BasePriority : Normal
FileVersion : 15.1.0.1206
ProductVersion : 15.1.0
ProductName : Trend Micro AntiVirus 2007
CompanyName : Trend Micro Inc.
FileDescription : Trend Micro AntiVirus Service Manager
InternalName : tavsvc
LegalCopyright : Copyright (C) 1995-2007 Trend Micro Incorporated. All rights reserved.
LegalTrademarks : Copyright (C) 1995-2007 Trend Micro Incorporated.
OriginalFilename : tavsvc.exe
#:42 [tmproxy.exe]
FilePath : C:\Program Files\Trend Micro\AntiVirus 2007\Components\
ProcessID : 3276
ThreadCreationTime : 5-9-2007 12:47:11 AM
BasePriority : Normal
FileVersion : 3.1.0.1013
ProductVersion : 3.1.0
ProductName : Trend Micro Network Security Components 3.1
CompanyName : Trend Micro Inc.
FileDescription : Trend Micro Proxy Service Controller
InternalName : TmProxy.exe
LegalCopyright : Copyright (C) 2001-2006 Trend Micro Inc. All rights reserved.
LegalTrademarks : Copyright (C) Trend Micro Inc.
OriginalFilename : TmProxy.exe
#:43 [spysweeper.exe]
FilePath : C:\Program Files\Webroot\Spy Sweeper\
ProcessID : 3308
ThreadCreationTime : 5-9-2007 12:47:11 AM
BasePriority : Normal
FileVersion : 3,3,1,2592
ProductVersion : 3, 3
ProductName : Spy Sweeper SDK
CompanyName : Webroot Software, Inc.
FileDescription : Spy Sweeper Engine
LegalCopyright : Copyright (C) 2002 - 2007, All Rights Reserved.
LegalTrademarks : Spy Sweeper is a trademark of Webroot Software, Inc.
OriginalFilename : SpySweeper.exe
#:44 [svchost.exe]
FilePath : C:\Windows\System32\
ProcessID : 3492
ThreadCreationTime : 5-9-2007 12:47:13 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Host Process for Windows Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe.mui
#:45 [searchindexer.exe]
FilePath : C:\Windows\system32\
ProcessID : 3516
ThreadCreationTime : 5-9-2007 12:47:13 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Microsoft Windows Search Indexer
InternalName : SearchIndexer.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : SearchIndexer.exe.mui
#:46 [xaudio.exe]
FilePath : C:\Windows\system32\DRIVERS\
ProcessID : 3556
ThreadCreationTime : 5-9-2007 12:47:13 AM
BasePriority : Normal
#:47 [clsched.exe]
FilePath : C:\Program Files\HP\QuickPlay\Kernel\TV\
ProcessID : 3568
ThreadCreationTime : 5-9-2007 12:47:13 AM
BasePriority : Normal
FileVersion : 5.00.3517
ProductVersion : 5.00.3517
ProductName : CLSched Module
FileDescription : CLSched Module
InternalName : CLSched
LegalCopyright : Copyright 2004
OriginalFilename : CLSched.EXE
#:48 [hpqwmiex.exe]
FilePath : C:\Program Files\Hewlett-Packard\Shared\
ProcessID : 3588
ThreadCreationTime : 5-9-2007 12:47:13 AM
BasePriority : Normal
FileVersion : 2, 0, 1, 9
ProductVersion : 2, 0, 1, 9
ProductName : hpqwmiex Module
CompanyName : Hewlett-Packard Development Company, L.P.
FileDescription : hpqwmiex Module
InternalName : hpqwmiex
LegalCopyright : © Copyright 2003-2006 Hewlett-Packard Development Company, L.P.
OriginalFilename : hpqwmiex.EXE
#:49 [taskeng.exe]
FilePath : C:\Windows\system32\
ProcessID : 2532
ThreadCreationTime : 5-9-2007 12:47:55 AM
BasePriority : Below Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Task Scheduler Engine
InternalName : TaskEng
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : taskeng.exe.mui
#:50 [ipodservice.exe]
FilePath : C:\Program Files\iPod\bin\
ProcessID : 2608
ThreadCreationTime : 5-9-2007 12:47:58 AM
BasePriority : Normal
FileVersion : 7.1.1.5
ProductVersion : 7.1.1.5
ProductName : iTunes
CompanyName : Apple Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2007 Apple Inc. All Rights Reserved.
OriginalFilename : iPodService.exe
#:51 [notepad.exe]
FilePath : C:\Windows\system32\
ProcessID : 1912
ThreadCreationTime : 5-9-2007 12:49:18 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Notepad
InternalName : Notepad
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : NOTEPAD.EXE.MUI
#:52 [unsecapp.exe]
FilePath : C:\Windows\system32\wbem\
ProcessID : 3544
ThreadCreationTime : 5-9-2007 12:50:09 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Sink to receive asynchronous callbacks for WMI client application
InternalName : unsecapp.dll
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : unsecapp.dll
#:53 [wmiprvse.exe]
FilePath : C:\Windows\system32\wbem\
ProcessID : 1924
ThreadCreationTime : 5-9-2007 12:50:10 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : WMI Provider Host
InternalName : Wmiprvse.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : Wmiprvse.exe
#:54 [swdoctor.exe]
FilePath : C:\Program Files\Spyware Doctor\
ProcessID : 2956
ThreadCreationTime : 5-9-2007 12:52:18 AM
BasePriority : Normal
FileVersion : 5.0.0.184
ProductVersion : 5.0
CompanyName : PC Tools
FileDescription : Spyware Doctor
LegalCopyright : Copyright ? 2006 PC Tools. All rights reserved.
#:55 [spybotsd.exe]
FilePath : C:\Program Files\Spybot - Search & Destroy\
ProcessID : 5988
ThreadCreationTime : 5-9-2007 1:06:38 AM
BasePriority : Normal
FileVersion : 1.4.0.3
ProductVersion : 1, 4, 0, 3
ProductName : SpyBot-S&D
CompanyName : Safer Networking Limited
FileDescription : Spybot - Search & Destroy
InternalName : SpybotSD
LegalCopyright : © 2000-2005 Patrick M. Kolla / Safer Networking Limited. Alle Rechte vorbehalten.
LegalTrademarks : "Spybot" und "Spybot - Search & Destroy" sind registrierte Warenzeichen.
OriginalFilename : SpyBotSD.exe
Comments : Software zum Entfernen von Spyware und ähnlichen Bedrohungen.
#:56 [firefox.exe]
FilePath : C:\Program Files\Mozilla Firefox\
ProcessID : 4332
ThreadCreationTime : 5-9-2007 1:12:35 AM
BasePriority : Normal
#:57 [ad-aware.exe]
FilePath : C:\PROGRA~1\Lavasoft\AD-AWA~1\
ProcessID : 4136
ThreadCreationTime : 5-9-2007 1:27:29 AM
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
#:58 [ieuser.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 5128
ThreadCreationTime : 5-9-2007 1:30:46 AM
BasePriority : Normal
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : ieuser.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ieuser.exe.mui
#:59 [searchprotocolhost.exe]
FilePath : C:\Windows\system32\
ProcessID : 5308
ThreadCreationTime : 5-9-2007 1:31:57 AM
BasePriority : Idle
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Microsoft Windows Search Protocol Host
InternalName : SearchProtocolHost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : SearchProtocolHost.exe
#:60 [searchfilterhost.exe]
FilePath : C:\Windows\system32\
ProcessID : 5344
ThreadCreationTime : 5-9-2007 1:31:58 AM
BasePriority : Idle
FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205)
ProductVersion : 6.0.6000.16386
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Microsoft Windows Search Filter Host
InternalName : SearchFilterHost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : SearchFilterHost.exe
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Windows Object Recognized!
Type : RegData
Data :
TAC Rating : 3
Category : Vulnerability
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-110746431-3671446382-3770039454-1000\software\policies\microsoft\internet explorer\control panel
Value : Homepage
Data :
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 1
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Deep scanning and examining files (D:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for D:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Scanning Hosts file......
Hosts file location:"C:\Windows\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
2 entries scanned.
New critical objects:0
Objects found so far: 1
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
10:24:03 PM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:51:33.166
Objects scanned:481254
Objects identified:1
Objects ignored:0
New critical objects:1
/////////////////////////////////////////////////
////////////////////////////////////////////////
PC TOOLS SPYWARE DOCTOR - LOG FILE (from a .htm)
PC Tools Spyware Doctor
DATE STATUS
5/9/2007 7:57:40 PM:24 Service Started
Spyware Doctor Service Application started
5/9/2007 7:57:40 PM:217 OnGuards status
All OnGuards were Enabled
5/9/2007 7:57:43 PM:156 Immunizer Results
ActiveX section has been immunized, Processed 4 items.
5/9/2007 8:10:41 PM:922 Scan Started
Scan Type - Full Scan
5/9/2007 8:37:52 PM:986 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - File
Risk Level - High
Infection - C:\Windows\System32\wincis32.dll
5/9/2007 8:42:51 PM:486 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - Registry Value
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wincis32, Asynchronous
5/9/2007 8:42:51 PM:496 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - Registry Value
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wincis32, DllName
5/9/2007 8:42:51 PM:506 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - Registry Value
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wincis32, Impersonate
5/9/2007 8:42:51 PM:516 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - Registry Value
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wincis32, Startup
5/9/2007 8:42:51 PM:525 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - Registry Value
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wincis32, Shutdown
5/9/2007 8:42:51 PM:526 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - Registry Key
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wincis32
5/9/2007 8:43:37 PM:223 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - File
Risk Level - High
Infection - wincis32.dll
5/9/2007 8:43:37 PM:262 Infection was detected on this computer
Threat Name - Trojan.Downloader.Small.CML
Type - Startup
Risk Level - High
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\wincis32 wincis32.dll
5/9/2007 8:44:29 PM:524 Scan Finished
Scan Type - Full Scan
Items Processed - 200300
Threats Detected - 1
Infections Detected - 9
Infections Ignored - 0