home

Forum HomeMain  SearchSearch  please registerplease register  Log inLog in  FAQFAQ  RULESRULES  
Problem after using Adaware 6.0
Goto page 1, 2  Next
 
Post new topic   Reply to topic    Forum Index -> PC Protection
View previous topic :: View next topic  
Author Message
Hbardsparky


 
Joined: 28 Jun 2004
Posts: 107

PostPosted: Mon Jun 28, 2004 17:13 pm    Post subject: Problem after using Adaware 6.0 Reply with quote

Recently I used Adaware 6.0 to try and get rid of a CWS Hijacker/Trojan whatever its called but I had a problem after deleting specific CWS files or what not. For some reason after using Adaware my notepad file has been deleted and I have to open up programs using the Microsoft Word. Also, my system restore files have been removed not allowing me to restart to a previous state.

I'm at a friends house and I dont have a log since im not on my computer, but I do have a log in which I was removing files but my notepad was now not currently there. I doubt that it is the log from when it was removed along with my system restore files but im 100% sure that all of this occured around the same date of the hunt for removal of the CWS. I did get rid of the CWS but my notepad and system restore files are gone once again, does any one know what I can do about this?
Back to top
View user's profile Send private message
Corrine

Administrator
 
Joined: 18 Jan 2001
Posts: 12721
Location: Upstate, NY

PostPosted: Mon Jun 28, 2004 17:18 pm    Post subject: Reply with quote

Ad-Aware didn't remove your notepad -- its part of the CWS garbage!!! Hold on, I'll get the fix for you. And, since those files are still on your machine, it is likely CWS is still on your machine.
_________________
Freedomlist.com (2000 - 2010)



Take a walk through my Security Garden
Back to top
View user's profile Send private message
Corrine

Administrator
 
Joined: 18 Jan 2001
Posts: 12721
Location: Upstate, NY

PostPosted: Mon Jun 28, 2004 17:39 pm    Post subject: Reply with quote

Here's the information from Option^Explicit (a highly respected LavaXpert and the creator of the winsock fix as well as several other excellent programs) on notepad:
Quote:
There is one notepad.exe in the C:\WINDOWS\notepad.exe and one in C:\WINDOWS\System32\notepad.exe.

both are the same file and can be copied over to the missing or corrupted location
Notepad in the system32 folder is what windows will try to run from the shortcut.

*If in doubt, physically go to the file and click on notepad to see if it starts.
although I would verify file sizes of notepad in case it a phoney and unloads more crap onto the system

have the user open a command prompt and type in:
dir %systemroot%\system32\notepad.exe
and
dir %systemroot%\notepad.exe

both files should be identical.

Quote:
Directory of C:\WINDOWS\system32

08/23/2001 07:00 AM 66,048 notepad.exe
1 File(s) 66,048 bytes
0 Dir(s) 19,026,784,256 bytes free

_________________
Freedomlist.com (2000 - 2010)



Take a walk through my Security Garden
Back to top
View user's profile Send private message
Hbardsparky


 
Joined: 28 Jun 2004
Posts: 107

PostPosted: Tue Jun 29, 2004 3:54 am    Post subject: Hi Reply with quote

Thanx for your help. Since im not going to be at my computer for about 2 days I cant directly go through the steps, but I presume I need to go to the right notepad and then find out where the phony note pad is and copy over it? Oh and if I futher get rid of CWS will my system restore files be back? I tried using that CWS cruncher that destroyed every varient of CWS but do I still need to run spybot and what not? Is there alot more I need to do?
Back to top
View user's profile Send private message
Corrine

Administrator
 
Joined: 18 Jan 2001
Posts: 12721
Location: Upstate, NY

PostPosted: Tue Jun 29, 2004 8:36 am    Post subject: Reply with quote

Hi, Hbardsparky. That is correct as I understand O^E's instructions.
_________________
Freedomlist.com (2000 - 2010)



Take a walk through my Security Garden
Back to top
View user's profile Send private message
Hbardsparky


 
Joined: 28 Jun 2004
Posts: 107

PostPosted: Wed Jun 30, 2004 15:40 pm    Post subject: hmmm Reply with quote

Does this missing system restore files have anything to do with the problem or where they caused by something else? Im pretty sure I can still restore using a restore disk but I dont have a burner and theres alot of hours worth of files on my computer that would take along time to get back especially on dial up.
Back to top
View user's profile Send private message
Hbardsparky


 
Joined: 28 Jun 2004
Posts: 107

PostPosted: Wed Jun 30, 2004 20:58 pm    Post subject: Last Resort Reply with quote

exclaim Ive tried using adaware and spybot to get rid of the cws trojin but its not working. Also, im unable to use SpywareBlaster because of a, "Corrupted sector of the hardrive or a virus" But im sure its a virus from something like cws or something. Ill need to scan for viruses when I have more time but as my last resort, im going to use Hijackthis. I heard I shouldnt go fixing things without a professionals help so, here I am lol. Here is my log for hijackthis. It would mean a great deal if you could bold text the entrys that should be deleted to remove CWS and perhaps other bold entrys that should be removed as well.

Logfile of HijackThis v1.97.7
Scan saved at 6:40:55 PM, on 6/30/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

:! HiJackThis Log Removed:!
Ad-aware Logfile Required
Please see  Freedomlist Support for Ad-aware  

Im sure the pcpitstop thing isnt bad though since I use it to scan for viruses. Once again thanx for your support with the process of my problems.
Back to top
View user's profile Send private message
Hbardsparky


 
Joined: 28 Jun 2004
Posts: 107

PostPosted: Thu Jul 01, 2004 1:33 am    Post subject: To finally add... Reply with quote

For my last post tonight, CWS Shredder recommends also getting rid of MS Java or what not. Will getting rid of java be bad in any way for my computer if I didn't go and get the new Java that Microsoft supports or would it not do anything because its no longer supported in Windows XP?
Back to top
View user's profile Send private message
Corrine

Administrator
 
Joined: 18 Jan 2001
Posts: 12721
Location: Upstate, NY

PostPosted: Thu Jul 01, 2004 6:15 am    Post subject: Reply with quote

CWShredder is no longer updated -- I would not recommend using it!!! In addition, please allow at least a shutdown/restart between usage of different antitrackware programs.

Please post an Ad-Aware logfile for review and assistance and then we will move on the HJT if/as needed. (There is also a new release of HJT that we will have you use.)
_________________
Freedomlist.com (2000 - 2010)



Take a walk through my Security Garden
Back to top
View user's profile Send private message
plodr

Administrator
 
Joined: 12 Apr 2001
Posts: 6778

PostPosted: Thu Jul 01, 2004 9:42 am    Post subject: Reply with quote

Quote:
CWS Shredder recommends also getting rid of MS Java or what not. Will getting rid of java be bad in any way for my computer ...

I cleaned up CoolWWWshredder in April using the shredder and removed MSVM (they have to call it virtual machine instead of Java - lawsuit with Sun). I discovered that my HP camera software no longer works because it needed MSVM. I am using Sun Java and don't notice any difference except for the camera software. (I've since ordered a newer version of the camera software on CD but haven't installed it yet). The bottom line, once you remove MSVM you can't put it back on - I know I tried everything for 2 weeks. Soooo if any software used it, it may not function.
I can get the pictures from my camera by dragging and dropping in Explorer but the software was a lot handier.[/quote]
Back to top
View user's profile Send private message Visit poster's website
Corrine

Administrator
 
Joined: 18 Jan 2001
Posts: 12721
Location: Upstate, NY

PostPosted: Thu Jul 01, 2004 13:41 pm    Post subject: Reply with quote

Hbardsparky, we'll assist with Ad-Aware if you wish to post a logfile. See  Freedomlist Support for Ad-aware  . There were 5 more CWS variants added to the update today.
_________________
Freedomlist.com (2000 - 2010)



Take a walk through my Security Garden
Back to top
View user's profile Send private message
Hbardsparky


 
Joined: 28 Jun 2004
Posts: 107

PostPosted: Sat Jul 03, 2004 0:01 am    Post subject: hmmm Reply with quote

It appears that ive gotten rid of it and recently ive made some updates for windows so maybe that helped. Maybe it might come back but who knows. I've been able to sucessfully change my homepage and restart and the homepage is still normal. Recently ive manually deleted the OldHomesp registry out of my reg and it didnt come back but I havent rebooted yet so it may but ill keep note on that and check it out before I shut my computer off for today. I did scanning before I realised that you said there was 5 new updates for Adaware and not for the CWS virus
*mis read it* and here is the log from pre-update just incase, but none of the files have been redetected. For some reason it didnt come up with the OldHomesp Registry but ive hopefully manually deleted it and its hopefully gone for good *re-checked registry*

Heres the log. As I said before also, nothing new came up when I rescanned it so there is no new update log yet.
Lavasoft Ad-aware Personal Build 6.181
Logfile created on :Friday, July 02, 2004 8:25:33 PM
Created with Ad-aware Personal, free for private use.
Using reference-file :01R325 27.06.2004
______________________________________________________

Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry


7-2-2004 8:25:33 PM - Scan started. (Custom mode)

Listing running processes
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 7-2-2004 4:54:58 PM
BasePriority : Normal


#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ThreadCreationTime : 7-2-2004 4:55:00 PM
BasePriority : High


#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-2-2004 4:55:00 PM
BasePriority : Normal
FileSize : 99 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Microsoft
Created on : 10/21/2001 5:39:34 PM
Last accessed : 7/3/2004 3:20:09 AM
Last modified : 8/18/2001 12:00:00 PM

#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-2-2004 4:55:00 PM
BasePriority : Normal
FileSize : 11 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
OriginalFilename : lsass.exe
ProductName : Microsoft
Created on : 10/6/2002 7:24:40 PM
Last accessed : 7/3/2004 3:20:09 AM
Last modified : 8/29/2002 10:41:26 AM

#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-2-2004 4:55:02 PM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 10/21/2001 5:39:40 PM
Last accessed : 7/3/2004 3:20:09 AM
Last modified : 8/18/2001 12:00:00 PM

#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7-2-2004 4:55:02 PM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 10/21/2001 5:39:40 PM
Last accessed : 7/3/2004 3:20:09 AM
Last modified : 8/18/2001 12:00:00 PM

#:7 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-2-2004 4:55:06 PM
BasePriority : Normal
FileSize : 50 KB
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
OriginalFilename : spoolsv.exe
ProductName : Microsoft
Created on : 10/21/2001 5:39:38 PM
Last accessed : 7/3/2004 3:20:09 AM
Last modified : 8/18/2001 12:00:00 PM

#:8 [explorer.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 7-2-2004 4:55:17 PM
BasePriority : Normal
FileSize : 980 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft
Created on : 10/18/2003 7:39:47 PM
Last accessed : 7/3/2004 3:20:09 AM
Last modified : 8/29/2002 10:41:24 AM

#:9 [backweb-8876480.exe]
FilePath : C:\Program Files\Logitech\Desktop Messenger\8876480\Program\
ThreadCreationTime : 7-2-2004 4:55:27 PM
BasePriority : Normal
FileSize : 16 KB
Created on : 9/26/2003 3:59:32 AM
Last accessed : 7/3/2004 3:20:09 AM
Last modified : 9/26/2003 3:59:32 AM

#:10 [realplay.exe]
FilePath : C:\Program Files\Real\RealPlayer\
ThreadCreationTime : 7-2-2004 4:55:27 PM
BasePriority : Normal
FileSize : 25 KB
FileVersion : 6.0.9.584
ProductVersion : 6.0.9.584
Copyright : Copyright
CompanyName : RealNetworks, Inc.
FileDescription : RealPlayer
InternalName : REALPLAY
OriginalFilename : REALPLAY.EXE
ProductName : RealPlayer (32-bit)
Created on : 9/25/2003 2:51:18 AM
Last accessed : 7/3/2004 3:20:09 AM
Last modified : 9/26/2003 3:50:25 AM

#:11 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ThreadCreationTime : 7-2-2004 4:55:28 PM
BasePriority : Normal
FileSize : 76 KB
FileVersion : 6.4
ProductVersion : QuickTime 6.4
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
OriginalFilename : QTTask.exe
ProductName : QuickTime
Created on : 10/23/2003 1:12:30 AM
Last accessed : 7/3/2004 3:20:09 AM
Last modified : 10/23/2003 1:12:30 AM

#:12 [mcagent.exe]
FilePath : C:\PROGRA~1\mcafee.com\agent\
ThreadCreationTime : 7-2-2004 4:55:28 PM
BasePriority : Normal
FileSize : 240 KB
FileVersion : 4, 3, 0, 27
ProductVersion : 4, 3, 0, 0
Copyright : Copyright
CompanyName : Networks Associates Technology, Inc
FileDescription : McAfee SecurityCenter Agent
InternalName : mcagent
OriginalFilename : mcagent.exe
ProductName : McAfee SecurityCenter
Created on : 5/11/2004 2:41:41 AM
Last accessed : 7/3/2004 2:49:42 AM
Last modified : 12/8/2003 10:38:52 PM

#:13 [packethsvc.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7-2-2004 4:56:19 PM
BasePriority : Normal
FileSize : 63 KB
FileVersion : 6, 0, 0, 6
ProductVersion : 6, 0, 0, 6
Copyright : Copyright (C) America Online, Inc. 1999 - 2001
CompanyName : America Online, Inc.
FileDescription : Virtual Adapter Service
InternalName : Virtual Adapter Service
OriginalFilename : PackethSvc.exe
ProductName : America Online
Created on : 1/22/2002 11:14:33 PM
Last accessed : 7/3/2004 3:20:10 AM
Last modified : 8/10/2001 1:18:30 AM

#:14 [gearsec.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7-2-2004 4:56:21 PM
BasePriority : Normal
FileSize : 48 KB
FileVersion : 1, 0, 0, 3
ProductVersion : 1, 0, 0, 3
Copyright : Copyright
CompanyName : GEAR Software
FileDescription : gearsec
InternalName : gearsec
OriginalFilename : gearsec.exe
ProductName : gearsec
Created on : 9/11/2003 1:11:46 AM
Last accessed : 7/3/2004 3:20:10 AM
Last modified : 9/11/2003 1:11:46 AM

#:15 [pctspk.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-2-2004 4:56:22 PM
BasePriority : Normal
FileSize : 84 KB
FileVersion : 4.00
ProductVersion : 4.00
Copyright : Copyright (C)PCtel,Inc. 1999-2000
CompanyName : PCtel, Inc.
FileDescription : PCTSPK.EXE
InternalName : PCTSPK.EXE
OriginalFilename : PCTSPK.EXE
ProductName : PCTSPK.EXE
Created on : 10/21/2001 10:48:53 AM
Last accessed : 7/3/2004 3:20:10 AM
Last modified : 8/17/2001 10:36:54 PM

#:16 [wanmpsvc.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 7-2-2004 4:56:25 PM
BasePriority : Normal
FileSize : 64 KB
FileVersion : 7, 0, 0, 2
ProductVersion : 7, 0, 0, 2
Copyright : Copyright
CompanyName : America Online, Inc.
FileDescription : Wan Miniport (ATW) Service
InternalName : WanMPSvc
OriginalFilename : WanMPSvc.exe
ProductName : America Online
Created on : 9/25/2003 2:54:11 AM
Last accessed : 7/3/2004 3:20:10 AM
Last modified : 11/27/2001 2:54:02 AM

#:17 [waol.exe]
FilePath : C:\Program Files\America Online 6.0\
ThreadCreationTime : 7-2-2004 4:58:20 PM
BasePriority : Normal
FileSize : 168 KB
FileVersion : 6.02.000
ProductVersion : 6.02.000
Copyright : Copyright (C) America Online, Inc. 1999 - 2001
CompanyName : America Online, Inc.
FileDescription : AOL
InternalName : WAOL
ProductName : America Online
Created on : 10/21/2001 6:08:41 PM
Last accessed : 7/3/2004 3:20:10 AM
Last modified : 9/24/2003 1:34:22 AM

#:18 [wuauclt.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7-2-2004 5:21:03 PM
BasePriority : Normal
FileSize : 145 KB
FileVersion : 5.4.3790.20 built by: lab04_n
ProductVersion : 5.4.3790.20
CompanyName : Microsoft Corporation
FileDescription : Windows Update AutoUpdate Client
InternalName : wuauclt.exe
OriginalFilename : wuauclt.exe
ProductName : Microsoft
Created on : 10/6/2002 7:24:52 PM
Last accessed : 7/3/2004 3:20:10 AM
Last modified : 1/31/2004 8:40:14 AM

#:19 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-aware 6\
ThreadCreationTime : 7-3-2004 3:19:52 AM
BasePriority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 9/26/2003 4:01:01 AM
Last accessed : 7/3/2004 3:19:52 AM
Last modified : 7/13/2003 6:00:20 AM

Memory scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 0


Started registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

Registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 0


Started deep registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pageabout:blank

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "about:blank"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "about:blank"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pageabout:blank

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "about:blank"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "about:blank"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Pagetemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Bartemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\SearchSearchAssistanttemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Search
Value : SearchAssistant
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Pagetemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Bartemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\SearchSearchAssistanttemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Search
Value : SearchAssistant
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"


CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{BBA3B46E-7632-4D69-AA37-968767D39E20}


CoolWebSearch Object recognized!
Type : File
Data : nobhad.dll
Object : c:\windows\system32\
FileSize : 30 KB
Created on : 7/2/2004 10:27:18 PM
Last accessed : 7/3/2004 2:54:39 AM
Last modified : 7/2/2004 10:27:18 PM



CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{DEA39AA0-F940-4AC4-8E2D-73C77332A8B7}


CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : PROTOCOLS\Filter\text/html


CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : PROTOCOLS\Filter\text/plain


CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DEA39AA0-F940-4AC4-8E2D-73C77332A8B7}


Deep registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 13
Objects found so far: 14


Deep scanning and examining files (C:)
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

Tracking Cookie Object recognized!
Type : File
Data : hbard@2o7[1].txt
Object : C:\Documents and Settings\hbard\Cookies\

Created on : 7/3/2004 3:17:49 AM
Last accessed : 7/3/2004 3:17:52 AM
Last modified : 7/3/2004 3:17:52 AM



Tracking Cookie Object recognized!
Type : File
Data : hbard@web4.realtracker[1].txt
Object : C:\Documents and Settings\hbard\Cookies\

Created on : 7/2/2004 1:03:27 PM
Last accessed : 7/3/2004 3:22:59 AM
Last modified : 7/2/2004 1:03:27 PM



Disk scan result for C:\
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 16


Performing conditional scans..
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

CoolWebSearch Object recognized!
Type : File
Data : sp.html
Object : c:\docume~1\hbard\locals~1\temp\
FileSize : 7 KB
Created on : 7/2/2004 10:27:21 PM
Last accessed : 7/3/2004 3:17:41 AM
Last modified : 7/3/2004 3:17:41 AM



Conditional scan result:
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 1
Objects found so far: 17


8:50:16 PM Scan complete

Summary of this scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Total scanning time :00:24:42:641
Objects scanned :218447
Objects identified :17
Objects ignored :0
New objects :17
Back to top
View user's profile Send private message
Corrine

Administrator
 
Joined: 18 Jan 2001
Posts: 12721
Location: Upstate, NY

PostPosted: Sat Jul 03, 2004 6:43 am    Post subject: Reply with quote

Hi, Hbardsparky. Sorry, but you have not gotten rid of it -- CWS is still on your computer. Please do a Webupdate to get the latest reference file and a do a full custom scan. To adjust the scan, please launch Ad-Aware and click on the Gear at the top of the start screen to access the preferences/setting window.

Under the Scanning button:
-- Scan within archives
-- Under Memory & Registry, Check EVERYTHING
-- In Check Drives & Folders, make sure all of your hard drives are selected

After doing so, it may take 2-3 posts to get the entire log posted. Just continue copy/pasting where the reply left off until the Summary appears.

Thanks! Rose
_________________
Freedomlist.com (2000 - 2010)



Take a walk through my Security Garden
Back to top
View user's profile Send private message
Hbardsparky


 
Joined: 28 Jun 2004
Posts: 107

PostPosted: Sun Jul 04, 2004 16:22 pm    Post subject: hi Reply with quote

K I will resume scanning later today but I want to make sure of something. If I come up with alot of registry keys should I throw them into the quarintine area and post the log and wait for you to tell me what to delete or should I just delete everything that comes up? Will the log be that big most likely because of everything being scanned or is it because of all the infections?
Back to top
View user's profile Send private message
Corrine

Administrator
 
Joined: 18 Jan 2001
Posts: 12721
Location: Upstate, NY

PostPosted: Sun Jul 04, 2004 17:34 pm    Post subject: Reply with quote

You can remove any tracking cookies, but leave the rest so we can see what is there. After posting the new logfile, we'll give you cleanup instructions.

Rose
_________________
Freedomlist.com (2000 - 2010)



Take a walk through my Security Garden
Back to top
View user's profile Send private message
Hbardsparky


 
Joined: 28 Jun 2004
Posts: 107

PostPosted: Wed Jul 07, 2004 3:44 am    Post subject: My Log Reply with quote

Lavasoft Ad-aware Personal Build 6.181
Logfile created on :Wednesday, July 07, 2004 12:50:22 AM
Created with Ad-aware Personal, free for private use.
Using reference-file :01R326 01.07.2004
______________________________________________________

Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file


7-7-2004 12:50:22 AM - Scan started. (Custom mode)

Listing running processes
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 7-6-2004 4:50:32 PM
BasePriority : Normal


#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ThreadCreationTime : 7-6-2004 4:50:34 PM
BasePriority : High


#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-6-2004 4:50:34 PM
BasePriority : Normal
FileSize : 99 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Microsoft
Created on : 10/21/2001 5:39:34 PM
Last accessed : 7/7/2004 7:50:23 AM
Last modified : 8/18/2001 12:00:00 PM

#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-6-2004 4:50:35 PM
BasePriority : Normal
FileSize : 11 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
OriginalFilename : lsass.exe
ProductName : Microsoft
Created on : 10/6/2002 7:24:40 PM
Last accessed : 7/7/2004 7:50:23 AM
Last modified : 8/29/2002 10:41:26 AM

#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-6-2004 4:50:36 PM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 10/21/2001 5:39:40 PM
Last accessed : 7/7/2004 7:50:23 AM
Last modified : 8/18/2001 12:00:00 PM

#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7-6-2004 4:50:36 PM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 10/21/2001 5:39:40 PM
Last accessed : 7/7/2004 7:50:23 AM
Last modified : 8/18/2001 12:00:00 PM

#:7 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-6-2004 4:50:41 PM
BasePriority : Normal
FileSize : 50 KB
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
OriginalFilename : spoolsv.exe
ProductName : Microsoft
Created on : 10/21/2001 5:39:38 PM
Last accessed : 7/7/2004 7:50:23 AM
Last modified : 8/18/2001 12:00:00 PM

#:8 [explorer.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 7-6-2004 4:51:06 PM
BasePriority : Normal
FileSize : 980 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft
Created on : 10/18/2003 7:39:47 PM
Last accessed : 7/7/2004 7:50:23 AM
Last modified : 8/29/2002 10:41:24 AM

#:9 [realplay.exe]
FilePath : C:\Program Files\Real\RealPlayer\
ThreadCreationTime : 7-6-2004 4:51:16 PM
BasePriority : Normal
FileSize : 25 KB
FileVersion : 6.0.9.584
ProductVersion : 6.0.9.584
Copyright : Copyright
CompanyName : RealNetworks, Inc.
FileDescription : RealPlayer
InternalName : REALPLAY
OriginalFilename : REALPLAY.EXE
ProductName : RealPlayer (32-bit)
Created on : 9/25/2003 2:51:18 AM
Last accessed : 7/7/2004 7:50:23 AM
Last modified : 9/26/2003 3:50:25 AM

#:10 [ituneshelper.exe]
FilePath : C:\Program Files\iTunes\
ThreadCreationTime : 7-6-2004 4:51:16 PM
BasePriority : Normal
FileSize : 224 KB
FileVersion : 4.1.1.54
ProductVersion : 4.1.1.54
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
OriginalFilename : iTunesHelper.exe
ProductName : iTunes
Created on : 10/22/2003 12:07:50 AM
Last accessed : 7/7/2004 7:50:23 AM
Last modified : 10/22/2003 12:07:50 AM

#:11 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ThreadCreationTime : 7-6-2004 4:51:17 PM
BasePriority : Normal
FileSize : 76 KB
FileVersion : 6.4
ProductVersion : QuickTime 6.4
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
OriginalFilename : QTTask.exe
ProductName : QuickTime
Created on : 10/23/2003 1:12:30 AM
Last accessed : 7/7/2004 7:50:23 AM
Last modified : 10/23/2003 1:12:30 AM

#:12 [mcagent.exe]
FilePath : C:\PROGRA~1\mcafee.com\agent\
ThreadCreationTime : 7-6-2004 4:51:17 PM
BasePriority : Normal
FileSize : 240 KB
FileVersion : 4, 3, 0, 27
ProductVersion : 4, 3, 0, 0
Copyright : Copyright
CompanyName : Networks Associates Technology, Inc
FileDescription : McAfee SecurityCenter Agent
InternalName : mcagent
OriginalFilename : mcagent.exe
ProductName : McAfee SecurityCenter
Created on : 5/11/2004 2:41:41 AM
Last accessed : 7/7/2004 7:36:17 AM
Last modified : 12/8/2003 10:38:52 PM

#:13 [backweb-8876480.exe]
FilePath : C:\Program Files\Logitech\Desktop Messenger\8876480\Program\
ThreadCreationTime : 7-6-2004 4:51:18 PM
BasePriority : Normal
FileSize : 16 KB
Created on : 9/26/2003 3:59:32 AM
Last accessed : 7/7/2004 7:50:24 AM
Last modified : 9/26/2003 3:59:32 AM

#:14 [packethsvc.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7-6-2004 4:51:54 PM
BasePriority : Normal
FileSize : 63 KB
FileVersion : 6, 0, 0, 6
ProductVersion : 6, 0, 0, 6
Copyright : Copyright (C) America Online, Inc. 1999 - 2001
CompanyName : America Online, Inc.
FileDescription : Virtual Adapter Service
InternalName : Virtual Adapter Service
OriginalFilename : PackethSvc.exe
ProductName : America Online
Created on : 1/22/2002 11:14:33 PM
Last accessed : 7/7/2004 7:50:24 AM
Last modified : 8/10/2001 1:18:30 AM

#:15 [gearsec.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7-6-2004 4:51:58 PM
BasePriority : Normal
FileSize : 48 KB
FileVersion : 1, 0, 0, 3
ProductVersion : 1, 0, 0, 3
Copyright : Copyright
CompanyName : GEAR Software
FileDescription : gearsec
InternalName : gearsec
OriginalFilename : gearsec.exe
ProductName : gearsec
Created on : 9/11/2003 1:11:46 AM
Last accessed : 7/7/2004 7:50:24 AM
Last modified : 9/11/2003 1:11:46 AM

#:16 [pctspk.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-6-2004 4:51:59 PM
BasePriority : Normal
FileSize : 84 KB
FileVersion : 4.00
ProductVersion : 4.00
Copyright : Copyright (C)PCtel,Inc. 1999-2000
CompanyName : PCtel, Inc.
FileDescription : PCTSPK.EXE
InternalName : PCTSPK.EXE
OriginalFilename : PCTSPK.EXE
ProductName : PCTSPK.EXE
Created on : 10/21/2001 10:48:53 AM
Last accessed : 7/7/2004 7:50:24 AM
Last modified : 8/17/2001 10:36:54 PM

#:17 [wanmpsvc.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 7-6-2004 4:52:04 PM
BasePriority : Normal
FileSize : 64 KB
FileVersion : 7, 0, 0, 2
ProductVersion : 7, 0, 0, 2
Copyright : Copyright
CompanyName : America Online, Inc.
FileDescription : Wan Miniport (ATW) Service
InternalName : WanMPSvc
OriginalFilename : WanMPSvc.exe
ProductName : America Online
Created on : 9/25/2003 2:54:11 AM
Last accessed : 7/7/2004 7:50:25 AM
Last modified : 11/27/2001 2:54:02 AM

#:18 [ipodservice.exe]
FilePath : C:\Program Files\iPod\bin\
ThreadCreationTime : 7-6-2004 4:52:27 PM
BasePriority : Normal
FileSize : 408 KB
FileVersion : 4.1.1.54
ProductVersion : 4.1.1.54
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
OriginalFilename : iPodService.exe
ProductName : iTunes
Created on : 10/22/2003 12:07:40 AM
Last accessed : 7/7/2004 7:50:25 AM
Last modified : 10/22/2003 12:07:40 AM

#:19 [kazaa.exe]
FilePath : C:\Abandon\abadon\
ThreadCreationTime : 7-7-2004 4:24:29 AM
BasePriority : Normal
FileSize : 2384 KB
FileVersion : 2, 6, 0, 0
ProductVersion : 2, 6, 0, 0
Copyright : Copyright (C) 1997-2003
CompanyName : Sharman Networks
FileDescription : Kazaa Media Desktop
InternalName : kazaa
OriginalFilename : Kazaa.exe
ProductName : Kazaa Media Desktop
Created on : 11/17/2003 11:29:14 PM
Last accessed : 7/7/2004 7:50:25 AM
Last modified : 11/17/2003 11:29:14 PM

#:20 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-aware 6\
ThreadCreationTime : 7-7-2004 7:49:52 AM
BasePriority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 9/26/2003 4:01:01 AM
Last accessed : 7/7/2004 7:49:52 AM
Last modified : 7/13/2003 6:00:20 AM

Memory scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 0


Started registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

Registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 0


Started deep registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pageabout:blank

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "about:blank"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "about:blank"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pageabout:blank

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "about:blank"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "about:blank"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Pagetemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Bartemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\SearchSearchAssistanttemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Search
Value : SearchAssistant
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Pagetemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Bartemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\SearchSearchAssistanttemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Search
Value : SearchAssistant
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"


CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{65D6E0CC-2B17-4373-8443-AB0BDC678BC3}


CoolWebSearch Object recognized!
Type : File
Data : mdnjijc.dll
Object : c:\windows\system32\
FileSize : 30 KB
Created on : 7/5/2004 2:15:09 AM
Last accessed : 7/7/2004 7:51:35 AM
Last modified : 7/5/2004 2:15:09 AM



CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{F3C584A1-310D-4A84-9CE3-210E32EDEC36}


CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : PROTOCOLS\Filter\text/html


CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : PROTOCOLS\Filter\text/plain


CoolWebSearch Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{65D6E0CC-2B17-4373-8443-AB0BDC678BC3}


Deep registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 13
Objects found so far: 14


Deep scanning and examining files (A:)
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

Disk scan result for A:\
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 14


Deep scanning and examining files (C:)
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ



Disk scan result for C:\
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 54


Deep scanning and examining files (D:)
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

Disk scan result for D:\
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 54

Possible Browser Hijack attempt Object recognized!
Type : File
Data : extreme sex.url
Object : C:\Documents and Settings\hbard\Favorites\

Created on : 6/10/2004 9:01:14 PM
Last accessed : 7/7/2004 8:28:24 AM
Last modified : 6/10/2004 9:01:14 PM



Possible Browser Hijack attempt Object recognized!
Type : File
Data : only sex website.url
Object : C:\Documents and Settings\hbard\Favorites\

Created on : 6/10/2004 9:01:14 PM
Last accessed : 7/7/2004 8:28:24 AM
Last modified : 6/10/2004 9:01:14 PM



Possible Browser Hijack attempt Object recognized!
Type : File
Data : seven days of free porn.url
Object : C:\Documents and Settings\hbard\Favorites\

Created on : 6/10/2004 9:01:14 PM
Last accessed : 7/7/2004 8:28:24 AM
Last modified : 6/10/2004 9:01:14 PM




Performing conditional scans..
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

CoolWebSearch Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
Value : ITBarLayout


CoolWebSearch Object recognized!
Type : File
Data : sp.html
Object : c:\docume~1\hbard\locals~1\temp\
FileSize : 7 KB
Created on : 7/5/2004 2:15:12 AM
Last accessed : 7/7/2004 8:28:26 AM
Last modified : 7/7/2004 4:33:29 AM



Conditional scan result:
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 2
Objects found so far: 59


1:28:27 AM Scan complete

Summary of this scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Total scanning time :00:38:03:391
Objects scanned :239311
Objects identified :59
Objects ignored :0
New objects :59

There where like 40 tracking cookies so I removed them from the posted log though its in the original. K finally got the post in :D
Back to top
View user's profile Send private message
Corrine

Administrator
 
Joined: 18 Jan 2001
Posts: 12721
Location: Upstate, NY

PostPosted: Wed Jul 07, 2004 6:28 am    Post subject: Reply with quote

Hi, Hbardsparky. There has been several Reference File updates -- each including additional variants of CWS. So you will definitely need to do a WebUpdate before cleaning your machine.

First, however, please note that there are some "clean " alternatives to your P2P that you are using at the moment. You may wish to have a look at,

 WinMx 
 Shareaza 
 Gnucleus 
 Piolet  (music only)

If you want to keep your P2P, and do not wish to use an alternate, then please do the following:
Uninstall it, go to the Add/Remove Programs & remove it
Scan with Ad-aware to make sure your system is clean then re-install it
Run another scan with Ad-aware and then place all the found components in your ignore list.
This will ensure your P2P will function without problems.
The Elements will still be there just ignored.

To clean your machine, please make sure that you have these options checked:

Under Ad-aware 6 > Configurations > Tweaks > Cleaning Engine:
"Let Windows remove files in use after reboot."

Also, please check to see if you have the option "quarantine all objects prior to removal" checked. Open Ad-aware > General Options, there is an option "Automatically Quarantine objects prior to removal

1) Please check for Reference File updates
2) Disconnect from the Internet
3) Clear your Temporary Internet Files, cookies, temp folders and recycle bin
4) Shutdown and restart in safemode (See  http://service1.symantec.com/SUPPORT/tsgen...ec_doc_nam  for safemode instructions.)
5) Run a full custom scan, using the In-Depth scanning mode and in the results screen, right click and select the objects for removal.
6) Shutdown/Restart
7) Rescan and post the logfile

Please Note:

After removing a Browser Hijacker Ad-aware 6 will set your Start Page to "Blank". So you may need to set the Start and Search pages in your Browser manually back to your prefered one. The reason is, the Hijack has changed the page, since Ad-aware 6 does not know what it was set to before, it resets it to a blank page. If you do not see any differences, then disregard this.

If you have any further questions, please don't hesitate to ask. Would you please post a new logfile after your clean your PC.

Thanks Rose
_________________
Freedomlist.com (2000 - 2010)



Take a walk through my Security Garden
Back to top
View user's profile Send private message
Hbardsparky


 
Joined: 28 Jun 2004
Posts: 107

PostPosted: Wed Jul 07, 2004 13:49 pm    Post subject: One question before I start Reply with quote

Oh first before I begin ive had ipod and itunes on my machine for awhile and have been wanting to get rid of it but on ipod it says its in use when I try to delete it and on itunes it says its write protected. What should I do?

Ok further to the business, I also got rid of kazaa and stuff but I have a question about the removal of the temporary internet files and the temp files. When you go into control panel/network-settings/internet options does the delete files button do this all for you? I know it kills your cookies and kills temporary internet files but does it also get rid of temp internet files?
Back to top
View user's profile Send private message
Hbardsparky


 
Joined: 28 Jun 2004
Posts: 107

PostPosted: Thu Jul 08, 2004 12:41 pm    Post subject: ok Reply with quote

I did the scan in safe and the reference files where up to date. Also, I scanned it after I restarted the computer out of safe mode and then one more time in the morning when another family member used the internet to go to a union worker website. Here is the safe mode log. I dont use kazaa anymore and I deleted everything kazaa related through the search bar because when I installed it it wasnt a programs related install, it was in a specific folder of a C: Drive. Im not sure if it made a difference that I was using kazaa light but the uninstall program wouldnt work so I manually got rid of the files.

Whoops I posted my log file of the safe boot lol ill keep the log in my files incase but I edited the post so it wasnt so large.


Last edited by Hbardsparky on Thu Jul 08, 2004 12:45 pm; edited 1 time in total
Back to top
View user's profile Send private message
Hbardsparky


 
Joined: 28 Jun 2004
Posts: 107

PostPosted: Thu Jul 08, 2004 12:42 pm    Post subject: my non safe log afterwords Reply with quote

Lavasoft Ad-aware Personal Build 6.181
Logfile created on :Thursday, July 08, 2004 1:33:02 AM
Created with Ad-aware Personal, free for private use.
Using reference-file :01R326 01.07.2004
______________________________________________________

Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file


7-8-2004 1:33:02 AM - Scan started. (Custom mode)

Listing running processes
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 7-8-2004 8:28:14 AM
BasePriority : Normal


#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ThreadCreationTime : 7-8-2004 8:28:17 AM
BasePriority : High


#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-8-2004 8:28:17 AM
BasePriority : Normal
FileSize : 99 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Microsoft
Created on : 10/21/2001 5:39:34 PM
Last accessed : 7/8/2004 7:54:47 AM
Last modified : 8/18/2001 12:00:00 PM

#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-8-2004 8:28:17 AM
BasePriority : Normal
FileSize : 11 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
OriginalFilename : lsass.exe
ProductName : Microsoft
Created on : 10/6/2002 7:24:40 PM
Last accessed : 7/8/2004 7:54:47 AM
Last modified : 8/29/2002 10:41:26 AM

#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-8-2004 8:28:19 AM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 10/21/2001 5:39:40 PM
Last accessed : 7/8/2004 7:54:46 AM
Last modified : 8/18/2001 12:00:00 PM

#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7-8-2004 8:28:19 AM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 10/21/2001 5:39:40 PM
Last accessed : 7/8/2004 7:54:46 AM
Last modified : 8/18/2001 12:00:00 PM

#:7 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-8-2004 8:28:23 AM
BasePriority : Normal
FileSize : 50 KB
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
OriginalFilename : spoolsv.exe
ProductName : Microsoft
Created on : 10/21/2001 5:39:38 PM
Last accessed : 7/8/2004 7:54:48 AM
Last modified : 8/18/2001 12:00:00 PM

#:8 [explorer.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 7-8-2004 8:28:33 AM
BasePriority : Normal
FileSize : 980 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft
Created on : 10/18/2003 7:39:47 PM
Last accessed : 7/8/2004 8:28:35 AM
Last modified : 8/29/2002 10:41:24 AM

#:9 [realplay.exe]
FilePath : C:\Program Files\Real\RealPlayer\
ThreadCreationTime : 7-8-2004 8:28:47 AM
BasePriority : Normal
FileSize : 25 KB
FileVersion : 6.0.9.584
ProductVersion : 6.0.9.584
Copyright : Copyright
CompanyName : RealNetworks, Inc.
FileDescription : RealPlayer
InternalName : REALPLAY
OriginalFilename : REALPLAY.EXE
ProductName : RealPlayer (32-bit)
Created on : 9/25/2003 2:51:18 AM
Last accessed : 7/8/2004 8:28:14 AM
Last modified : 9/26/2003 3:50:25 AM

#:10 [ituneshelper.exe]
FilePath : C:\Program Files\iTunes\
ThreadCreationTime : 7-8-2004 8:28:47 AM
BasePriority : Normal
FileSize : 224 KB
FileVersion : 4.1.1.54
ProductVersion : 4.1.1.54
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
OriginalFilename : iTunesHelper.exe
ProductName : iTunes
Created on : 10/22/2003 12:07:50 AM
Last accessed : 7/8/2004 8:28:14 AM
Last modified : 10/22/2003 12:07:50 AM

#:11 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ThreadCreationTime : 7-8-2004 8:28:48 AM
BasePriority : Normal
FileSize : 76 KB
FileVersion : 6.4
ProductVersion : QuickTime 6.4
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
OriginalFilename : QTTask.exe
ProductName : QuickTime
Created on : 10/23/2003 1:12:30 AM
Last accessed : 7/8/2004 8:28:14 AM
Last modified : 10/23/2003 1:12:30 AM

#:12 [mcagent.exe]
FilePath : C:\PROGRA~1\mcafee.com\agent\
ThreadCreationTime : 7-8-2004 8:28:48 AM
BasePriority : Normal
FileSize : 240 KB
FileVersion : 4, 3, 0, 27
ProductVersion : 4, 3, 0, 0
Copyright : Copyright
CompanyName : Networks Associates Technology, Inc
FileDescription : McAfee SecurityCenter Agent
InternalName : mcagent
OriginalFilename : mcagent.exe
ProductName : McAfee SecurityCenter
Created on : 5/11/2004 2:41:41 AM
Last accessed : 7/8/2004 8:28:14 AM
Last modified : 12/8/2003 10:38:52 PM

#:13 [backweb-8876480.exe]
FilePath : C:\Program Files\Logitech\Desktop Messenger\8876480\Program\
ThreadCreationTime : 7-8-2004 8:28:50 AM
BasePriority : Normal
FileSize : 16 KB
Created on : 9/26/2003 3:59:32 AM
Last accessed : 7/8/2004 8:28:47 AM
Last modified : 9/26/2003 3:59:32 AM

#:14 [packethsvc.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7-8-2004 8:29:41 AM
BasePriority : Normal
FileSize : 63 KB
FileVersion : 6, 0, 0, 6
ProductVersion : 6, 0, 0, 6
Copyright : Copyright (C) America Online, Inc. 1999 - 2001
CompanyName : America Online, Inc.
FileDescription : Virtual Adapter Service
InternalName : Virtual Adapter Service
OriginalFilename : PackethSvc.exe
ProductName : America Online
Created on : 1/22/2002 11:14:33 PM
Last accessed : 7/8/2004 7:54:47 AM
Last modified : 8/10/2001 1:18:30 AM

#:15 [gearsec.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7-8-2004 8:29:44 AM
BasePriority : Normal
FileSize : 48 KB
FileVersion : 1, 0, 0, 3
ProductVersion : 1, 0, 0, 3
Copyright : Copyright
CompanyName : GEAR Software
FileDescription : gearsec
InternalName : gearsec
OriginalFilename : gearsec.exe
ProductName : gearsec
Created on : 9/11/2003 1:11:46 AM
Last accessed : 7/8/2004 7:54:47 AM
Last modified : 9/11/2003 1:11:46 AM

#:16 [pctspk.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-8-2004 8:29:45 AM
BasePriority : Normal
FileSize : 84 KB
FileVersion : 4.00
ProductVersion : 4.00
Copyright : Copyright (C)PCtel,Inc. 1999-2000
CompanyName : PCtel, Inc.
FileDescription : PCTSPK.EXE
InternalName : PCTSPK.EXE
OriginalFilename : PCTSPK.EXE
ProductName : PCTSPK.EXE
Created on : 10/21/2001 10:48:53 AM
Last accessed : 7/8/2004 7:54:48 AM
Last modified : 8/17/2001 10:36:54 PM

#:17 [wanmpsvc.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 7-8-2004 8:29:48 AM
BasePriority : Normal
FileSize : 64 KB
FileVersion : 7, 0, 0, 2
ProductVersion : 7, 0, 0, 2
Copyright : Copyright
CompanyName : America Online, Inc.
FileDescription : Wan Miniport (ATW) Service
InternalName : WanMPSvc
OriginalFilename : WanMPSvc.exe
ProductName : America Online
Created on : 9/25/2003 2:54:11 AM
Last accessed : 7/8/2004 8:23:04 AM
Last modified : 11/27/2001 2:54:02 AM

#:18 [ipodservice.exe]
FilePath : C:\Program Files\iPod\bin\
ThreadCreationTime : 7-8-2004 8:30:14 AM
BasePriority : Normal
FileSize : 408 KB
FileVersion : 4.1.1.54
ProductVersion : 4.1.1.54
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
OriginalFilename : iPodService.exe
ProductName : iTunes
Created on : 10/22/2003 12:07:40 AM
Last accessed : 7/8/2004 7:54:47 AM
Last modified : 10/22/2003 12:07:40 AM

#:19 [urlmap.exe]
FilePath : C:\Program Files\Microsoft Money\System\
ThreadCreationTime : 7-8-2004 8:31:56 AM
BasePriority : Normal
FileSize : 48 KB
FileVersion : 10.00.0809
ProductVersion : 10.00.0809
Copyright : Copyright (C) Microsoft Corp. 1990-2001. All rights reserved.
CompanyName : Microsoft Corporation
FileDescription : Money URL Map
InternalName : URLMAP
OriginalFilename : urlmap.exe
ProductName : Microsoft Money
Created on : 9/26/2003 3:41:16 AM
Last accessed : 7/8/2004 8:31:56 AM
Last modified : 9/26/2003 3:41:16 AM

#:20 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-aware 6\
ThreadCreationTime : 7-8-2004 8:32:37 AM
BasePriority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 9/26/2003 4:01:01 AM
Last accessed : 7/8/2004 8:32:37 AM
Last modified : 7/13/2003 6:00:20 AM

Memory scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 0


Started registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

Registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 0


Started deep registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pageabout:blank

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "about:blank"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "about:blank"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Pagetemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Bartemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\SearchSearchAssistanttemp\sp.html

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Search
Value : SearchAssistant
Data : "file://C:\DOCUME~1\hbard\LOCALS~1\Temp\sp.html"


Deep registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 4
Objects found so far: 4


Deep scanning and examining files (A:)
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

Disk scan result for A:\
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 4


Deep scanning and examining files (C:)
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

Disk scan result for C:\
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 4


Deep scanning and examining files (D:)
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

Disk scan result for D:\
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 4


Performing conditional scans..
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ

Conditional scan result:
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 4


1:58:00 AM Scan complete

Summary of this scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Total scanning time :00:24:55:782
Objects scanned :206092
Objects identified :4
Objects ignored :0
New objects :4
Back to top
View user's profile Send private message
Post new topic  Reply to topic     Forum Index -> PC Protection   All times are GMT - 5 Hours
Goto page 1, 2  Next
Powered by phpBB İ    
*freedomlist.com assumes no responsibility for any postings
spacer