Log file from ad-ware. i cleared all 3 of them
Lavasoft Ad-aware Personal Build 6.181
Logfile created on

unday, July 18, 2004 2:04:40 PM
Created with Ad-aware Personal, free for private use.
Using reference-file :01R333 18.07.2004
______________________________________________________
Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry
7/18/2004 2:04:40 PM - Scan started. (Smart mode)
Listing running processes
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 7/18/2004 5:09:44 AM
BasePriority : Normal
#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ThreadCreationTime : 7/18/2004 5:09:49 AM
BasePriority : High
#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7/18/2004 5:09:49 AM
BasePriority : Normal
FileSize : 99 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Microsoft
Created on : 8/23/2001 1:30:00 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 8/23/2001 1:30:00 AM
#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7/18/2004 5:09:49 AM
BasePriority : Normal
FileSize : 11 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
OriginalFilename : lsass.exe
ProductName : Microsoft
Created on : 8/23/2001 1:30:00 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 8/23/2001 1:30:00 AM
#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7/18/2004 5:09:50 AM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 8/23/2001 1:30:00 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 8/23/2001 1:30:00 AM
#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7/18/2004 5:09:51 AM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 8/23/2001 1:30:00 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 8/23/2001 1:30:00 AM
#:7 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7/18/2004 5:09:53 AM
BasePriority : Normal
FileSize : 50 KB
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
OriginalFilename : spoolsv.exe
ProductName : Microsoft
Created on : 8/23/2001 1:30:00 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 8/23/2001 1:30:00 AM
#:8 [explorer.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 7/18/2004 5:09:56 AM
BasePriority : Normal
FileSize : 977 KB
FileVersion : 6.00.2600.0000 (xpclient.010817-1148)
ProductVersion : 6.00.2600.0000
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft
Created on : 8/23/2001 1:30:00 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 8/23/2001 1:30:00 AM
#:9 [inetinfo.exe]
FilePath : C:\WINDOWS\System32\inetsrv\
ThreadCreationTime : 7/18/2004 5:10:01 AM
BasePriority : Normal
FileSize : 13 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Internet Information Services
InternalName : INETINFO.EXE
OriginalFilename : INETINFO.EXE
ProductName : Internet Information Services
Created on : 10/22/2003 6:39:03 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 8/23/2001 7:00:00 AM
#:10 [mdm.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7Debug\
ThreadCreationTime : 7/18/2004 5:10:02 AM
BasePriority : Normal
FileSize : 264 KB
FileVersion : 7.00.9064.9150
ProductVersion : 7.00.9064.9150
Copyright : Copyright (C) Microsoft Corp. 1997-2000
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
OriginalFilename : mdm.exe
ProductName : Microsoft Development Environment
Created on : 2/23/2001 4:37:30 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 2/23/2001 4:37:30 AM
#:11 [navapsvc.exe]
FilePath : C:\Program Files\Norton AntiVirus\
ThreadCreationTime : 7/18/2004 5:10:03 AM
BasePriority : Normal
FileSize : 113 KB
FileVersion : 8.07.17
ProductVersion : 8.07.17
Copyright : Copyright (c) 2000-2002 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
OriginalFilename : NAVAPSVC.EXE
ProductName : Norton AntiVirus
Created on : 10/18/2003 7:11:05 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 2/27/2002 5:59:26 AM
#:12 [navapw32.exe]
FilePath : C:\PROGRA~1\NORTON~1\
ThreadCreationTime : 7/18/2004 5:10:04 AM
BasePriority : Normal
FileSize : 73 KB
FileVersion : 8.07.17
ProductVersion : 8.07.17
Copyright : Copyright (c) 2000-2002 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Agent
InternalName : NAVAPW32
OriginalFilename : NAVAPW32.EXE
ProductName : Norton AntiVirus
Created on : 10/18/2003 7:11:05 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 2/27/2002 5:57:58 AM
#:13 [jusched.exe]
FilePath : C:\Program Files\Java\j2re1.4.2_04\bin\
ThreadCreationTime : 7/18/2004 5:10:04 AM
BasePriority : Normal
FileSize : 32 KB
Created on : 2/22/2068 6:14:46 PM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 2/22/2004 6:14:44 PM
#:14 [ctfmon.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7/18/2004 5:10:05 AM
BasePriority : Normal
FileSize : 13 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
OriginalFilename : CTFMON.EXE
ProductName : Microsoft
Created on : 8/23/2001 1:30:00 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 8/23/2001 1:30:00 AM
#:15 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7/18/2004 5:10:05 AM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 8/23/2001 1:30:00 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 8/23/2001 1:30:00 AM
#:16 [nkvmon.exe]
FilePath : C:\Program Files\Nikon\NkView6\
ThreadCreationTime : 7/18/2004 5:10:07 AM
BasePriority : Normal
FileSize : 232 KB
FileVersion : 6, 0, 0, 3000
ProductVersion : 6, 0
Copyright : Copyright (C) Nikon Corporation. 1998 - 2003
CompanyName : Nikon Corporation
FileDescription : Nikon Monitor
InternalName : NkvMon
OriginalFilename : NkvMon.exe
ProductName : Nikon Monitor
Created on : 11/20/2003 1:24:03 PM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 12/4/2002 5:22:48 AM
#:17 [acrotray.exe]
FilePath : C:\Program Files\Adobe\Acrobat 5.0\Distillr\
ThreadCreationTime : 7/18/2004 5:10:08 AM
BasePriority : Normal
FileSize : 48 KB
FileVersion : 5, 0, 0, 0
ProductVersion : 5, 0, 0, 0
Copyright : Copyright
CompanyName : Adobe Systems Inc.
FileDescription : AcroTray
InternalName : AcroTray
OriginalFilename : AcroTray.exe
ProductName : AcroTray - Adobe Acrobat Distiller helper application.
Created on : 1/9/2004 5:53:37 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 3/14/2001 11:48:18 PM
#:18 [psnlite.exe]
FilePath : C:\Program Files\3M\PSNLite\
ThreadCreationTime : 7/18/2004 5:10:08 AM
BasePriority : Normal
FileSize : 1584 KB
FileVersion : 3, 0, 1, 1069
ProductVersion : 3, 0, 1, 1069
CompanyName : 3M
FileDescription : Post-it(R) Software Notes: System
InternalName : PSN
OriginalFilename : PSN2VIEW.EXE
ProductName : Post-it(R) Software Notes Lite
Created on : 10/9/2003 8:38:32 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 10/9/2003 8:38:32 AM
#:19 [hpotdd01.exe]
FilePath : C:\Program Files\Hewlett-Packard\Digital Imaging\bin\
ThreadCreationTime : 7/18/2004 5:10:10 AM
BasePriority : Normal
FileSize : 40 KB
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
Copyright : Copyright
CompanyName : Hewlett-Packard
FileDescription : hpotdd01
InternalName : hpotdd01
OriginalFilename : hpotdd01.exe
ProductName : Hewlett-Packard hpotdd01
Created on : 12/2/2002 3:26:10 PM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 12/2/2002 3:26:10 PM
#:20 [hpohmr08.exe]
FilePath : C:\Program Files\Hewlett-Packard\Digital Imaging\bin\
ThreadCreationTime : 7/18/2004 5:10:10 AM
BasePriority : Normal
FileSize : 144 KB
FileVersion : 4.2.0.170
ProductVersion : 002.000.000.170
Copyright : Copyright (C) Hewlett-Packard Co. 1995-2001
CompanyName : Hewlett-Packard Co.
FileDescription : HP OfficeJet COM Device Objects
InternalName : HPOHMR08
OriginalFilename : HPOHMR08.EXE
ProductName : hp digital imaging - hp all-in-one series
Created on : 12/2/2002 3:38:34 PM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 12/2/2002 3:38:34 PM
#:21 [psngive.exe]
FilePath : C:\PROGRA~1\3M\PSNLite\
ThreadCreationTime : 7/18/2004 5:10:17 AM
BasePriority : Normal
FileSize : 64 KB
FileVersion : 3, 0, 2, 2069
ProductVersion : 3, 0, 2, 2069
CompanyName : 3M
FileDescription : Post-it(R) Software Notes: GiveNote
InternalName : PSN
OriginalFilename : PSN.EXE
ProductName : Post-it(R) Software Notes
Created on : 10/9/2003 8:37:36 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 10/9/2003 8:37:36 AM
#:22 [hpoevm08.exe]
FilePath : C:\Program Files\Hewlett-Packard\Digital Imaging\bin\
ThreadCreationTime : 7/18/2004 5:10:20 AM
BasePriority : Normal
FileSize : 276 KB
FileVersion : 4.2.0.170
ProductVersion : 002.000.000.170
Copyright : Copyright (C) Hewlett-Packard Co. 1995-2001
CompanyName : Hewlett-Packard Co.
FileDescription : HP OfficeJet COM Event Manager
InternalName : HPOEVM08
OriginalFilename : HPOEVM08.EXE
ProductName : hp digital imaging - hp all-in-one series
Created on : 12/2/2002 3:00:02 PM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 12/2/2002 3:00:02 PM
#:23 [hposts08.exe]
FilePath : C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\
ThreadCreationTime : 7/18/2004 5:10:28 AM
BasePriority : Normal
FileSize : 300 KB
FileVersion : 4.2.0.170
ProductVersion : 002.000.000.170
Copyright : Copyright (C) Hewlett-Packard Co. 1995-2001
CompanyName : Hewlett-Packard Co.
FileDescription : HP OfficeJet Status
InternalName : HPOSTS08
OriginalFilename : HPOSTS08.EXE
ProductName : hp digital imaging - hp all-in-one series
Created on : 12/2/2002 3:11:48 PM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 12/2/2002 3:11:48 PM
#:24 [msnmsgr.exe]
FilePath : C:\Program Files\MSN Messenger\
ThreadCreationTime : 7/18/2004 5:15:23 AM
BasePriority : Normal
FileSize : 4768 KB
FileVersion : 6.2.0137
ProductVersion : Version 6.2
Copyright : Copyright (c) Microsoft Corporation 1997-2004
CompanyName : Microsoft Corporation
FileDescription : MSN Messenger
InternalName : msnmsgr
OriginalFilename : msnmsgr.exe
ProductName : MSN Messenger
Created on : 5/28/2004 9:52:04 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 5/28/2004 9:52:04 AM
#:25 [ymsgr_tray.exe]
FilePath : C:\Program Files\Yahoo!\Messenger\
ThreadCreationTime : 7/18/2004 7:54:29 AM
BasePriority : Normal
FileSize : 64 KB
Created on : 10/16/2003 8:53:56 PM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 2/4/2002 12:45:00 PM
#:26 [ad-aware.exe]
FilePath : C:\PROGRA~1\LAVASOFT\AD-AWA~1\
ThreadCreationTime : 7/18/2004 8:28:04 AM
BasePriority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 7/15/2004 4:16:54 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 7/12/2003 3:30:20 PM
Memory scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Started registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0
Started deep registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pageabout
:blank
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "about
:blank"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "about
:blank"
Deep registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 1
Objects found so far: 1
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Tracking Cookie Object recognized!
Type : File
Data : dad@bravenet[2].txt
Object : C:\Documents and Settings\Dad\Cookies\
Created on : 7/18/2004 5:18:04 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 7/18/2004 5:18:06 AM
Tracking Cookie Object recognized!
Type : File
Data : dad@maxserving[1].txt
Object : C:\Documents and Settings\Dad\Cookies\
Created on : 7/18/2004 8:09:46 AM
Last accessed : 7/17/2004 6:30:00 PM
Last modified : 7/18/2004 8:09:48 AM
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Deep scanning and examining files (C

¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Performing conditional scans..
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Conditional scan result:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 3
2:10:40 PM Scan complete
Summary of this scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Total scanning time :00:05:59:897
Objects scanned :48319
Objects identified :3
Objects ignored :0
New objects :3