ad-aware after uninstalling spybot
Ad-Aware Build
Log File Created on: 2008-09-14 23:04:09
Using Definitions File: C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\core.aawdef
Computer name: DDXPK121
Name of user performing scan: SYSTEM
System information
===========================
Number of processors: 1
Processor type: Intel(R) Pentium(R) 4 CPU 2.53GHz
Memory Available: 57%
Total Physical Memory: 1072697344 Bytes
Available Physical Memory: 600801280 Bytes
Total Page File Size: 1373216768 Bytes
Available On Page File: 942837760 Bytes
Total Virtual Memory: 2147352576 Bytes
Available Virtual Memory: 1753845760 Bytes
OS: Microsoft Windows XP Service Pack 2 (Build 2600)
Ad-Aware Settings
===========================
Skipping files larger than 1048576 kB
Ignoring infections with lower TAI than: 1
Extended Ad-Aware Settings
===========================
Unloading known modules during scan
Ignoring spanned files when scanning cab archives
Reanalyzing results after scanning before displaying results
Trying to unload modules prior to removal
Let Windows remove files currently in use at next reboot
Removing quarantined objects after restore
Deactivating Ad-Watch during scans
Writeprotecting system files after repairs
Include info about ignored objects in log file
Including basic settings in log file
Including advanced settings in log file
Including user and computer name in log file
Create and save WebUpdate log file
Databaseinfo
===========================
Version number: 120
Build Number: 0
Build Date and Time: 2008/09/11 01:37:19
Scan Statistics
===========================
Method: Full
Scan tracking cookies.............................: On
Scan ADS filestreams..............................: Off
Item Scanned: 366947
Infections Detected: 89
Infections Ignored: 0
Scan detailed statistics
===========================
Type Critical Total
Process Scan....: 0 0
Registry Scan...: 9 9
Registry PE Scan: 0 0
Hosts File Scan.: 0 0
File Scan.......: 1 1
Folder Scan.....: 0 0
LSP Scan........: 0 0
ADS Scan........: 0 0
Cookie Scan.....: 63 63
File Hash Scan..: 13 13
Infections Found
===========================
Family Id: 731 Name: Trojan Category: Vulnerability TAI:5
Item Id: 300015600 Value: Root: HKLM Path: system\currentcontrolset\services\psexesvc
Family Id: 1022 Name: Win32.TrojanDownloader.NewMedia Category: Malware TAI:10
Item Id: 300051526 Value: Root: HKCR Path: interface\{6a4a71b0-36d2-4674-87af-288f60e3ec71}
Item Id: 300051527 Value: Root: HKCR Path: interface\{8adabfcc-2174-46c8-8dc8-161780adeac5}
Item Id: 300051528 Value: Root: HKCR Path: interface\{a74cd9a1-9348-4b3f-87a4-4852c2ce802e}
Item Id: 300051531 Value: Root: HKCR Path: typelib\{88a6bf68-b9b6-429b-a8b0-3cc5c6db948c}
Item Id: 300051532 Value: Root: HKCR Path: typelib\{8c6aacdd-4862-496c-ba20-d712ad679760}
Item Id: 203574 Value: File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP974\A0141625.dll
Item Id: 203576 Value: File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP974\A0141642.exe
Item Id: 203578 Value: File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP974\A0141797.exe
Item Id: 300051529 Value: Root: HKCR Path: qndsfmao.bvqe
Item Id: 300051530 Value: Root: HKCR Path: qndsfmao.toolbar.1
Item Id: 300051537 Value: Root: HKU Path: S-1-5-21-769079328-2221179514-3766738458-1011\software\microsoft\windows\currentversion\policies\explorer Value: nodrives
Item Id: 700005547 Value: File: C:\Documents and Settings\Julian Richards\Desktop\Privacy Protector.url
Family Id: 725 Name: Tracking Cookie Category: DataMiner TAI:3
Item Id: 600000101 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat overture.com SessionData /
Item Id: 600000101 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat overture.com ConvData /
Item Id: 600000101 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat overture.com UserData /
Item Id: 600000171 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat bs.serving-sys.com eyeblaster /
Item Id: 600000085 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat questionmarket.com CS1 /
Item Id: 600000085 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat questionmarket.com ES /
Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat serving-sys.com A2 /
Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat serving-sys.com B2 /
Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat serving-sys.com C3 /
Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat serving-sys.com D3 /
Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat serving-sys.com E2 /
Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat serving-sys.com U /
Item Id: 600000578 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat unicast.com VWCUK200 /
Item Id: 600000415 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat revsci.net NETID01 /
Item Id: 600000415 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat revsci.net NETSEGS_K05540 /
Item Id: 600000415 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat revsci.net rsi_cls_1000000 /
Item Id: 600000415 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Julian Richards\Cookies\index.dat revsci.net rsi_segs_1000000 /
Item Id: 600000449 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat adultfriendfinder.com ffadult_tr /
Item Id: 600000449 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat adultfriendfinder.com HISTORY /
Item Id: 600000449 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat adultfriendfinder.com REFERRAL_URL /
Item Id: 600000449 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat adultfriendfinder.com __utma /
Item Id: 600000449 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat adultfriendfinder.com __utmb /
Item Id: 600000449 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat adultfriendfinder.com __utmz /
Item Id: 600000085 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat questionmarket.com LP /
Item Id: 600000212 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat 2o7.net s_vi_dzzkjyx7Bfm /
Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat realmedia.com RMID /
Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat realmedia.com RMFD /
Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat realmedia.com NXCLICK2 /
Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat realmedia.com RMFL /
Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat adopt.euroclick.com LO /
Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat adopt.euroclick.com UI /
Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat adopt.euroclick.com NSC_mc-bepqu.fvspdmjdl.dpn-iuuq /
Item Id: 600000415 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat ads.revsci.net rsi_us_1000000 /adserver
Item Id: 600000400 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat tacoda.net TID /
Item Id: 600000400 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat tacoda.net CMP /
Item Id: 600000050 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat tribalfusion.com ANON_ID /
Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat 247realmedia.com OAX /
Item Id: 600000073 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat adopt.specificclick.net LO /
Item Id: 600000073 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Administrator\Cookies\index.dat adopt.specificclick.net UI /
Item Id: 600000415 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Cheryl Richards\Cookies\index.dat ads.revsci.net rsi_us_1000000 /adserver
Item Id: 600000661 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Cheryl Richards\Cookies\index.dat te100.kontera.com ai /
Item Id: 600000661 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Cheryl Richards\Cookies\index.dat te100.kontera.com ki /
Item Id: 600000661 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Cheryl Richards\Cookies\index.dat te100.kontera.com cn /
Item Id: 600000661 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Cheryl Richards\Cookies\index.dat te100.kontera.com rf /
Item Id: 600000661 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Cheryl Richards\Cookies\index.dat te100.kontera.com agi /
Item Id: 600000661 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Cheryl Richards\Cookies\index.dat te100.kontera.com ci /
Item Id: 600000409 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Cheryl Richards\Cookies\index.dat server.iad.liveperson.net HumanClickID /hc/67419622
Item Id: 600000421 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Cheryl Richards\Cookies\index.dat kefta.overstock.com KWSID-OSTK.1.1000.client /
Item Id: 600000421 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Cheryl Richards\Cookies\index.dat
www.overstock.com SSLB /
Item Id: 600000421 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Cheryl Richards\Cookies\index.dat
www.overstock.com gpv_p13 /
Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Cheryl Richards\Cookies\index.dat oasis.realbeer.com OASISID /
Item Id: 600000190 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Cheryl Richards\Cookies\index.dat
www.googleadservices.com Conversion /pagead/conversion/1070694555/
Item Id: 600000073 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\ian\Cookies\index.dat adopt.specificclick.net DMEXP /
Item Id: 600000073 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\ian\Cookies\index.dat adopt.specificclick.net UI /
Item Id: 600000409 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\ian\Cookies\index.dat server.iad.liveperson.net HumanClickKEY /hc/51889961
Item Id: 600000409 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\ian\Cookies\index.dat server.iad.liveperson.net HumanClickID /hc/51889961
Item Id: 600000119 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\ian\Cookies\index.dat kelkoo.co.uk kelkooCountry /
Item Id: 600000119 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\ian\Cookies\index.dat kelkoo.co.uk kelkooSession /
Item Id: 600000119 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\ian\Cookies\index.dat kelkoo.co.uk kelkooID /
Item Id: 600000409 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\ian\Cookies\index.dat server.iad.liveperson.net HumanClickKEY /hc/46369213
Item Id: 600000579 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\ian\Cookies\index.dat creativeby.viewpoint.com VWCUK180 /
Item Id: 600000268 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\ian\Cookies\index.dat hc2.humanclick.com HumanClickKEY /hc/10286206
Item Id: 600000119 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\ian\Cookies\index.dat
www.kelkoo.co.uk kelkooID /
Family Id: 3262 Name: Win32.Trojan.Monder Category: Malware TAI:10
Item Id: 205314 Value: File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP974\A0141626.dll
Item Id: 224052 Value: File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP974\A0141629.dll
Item Id: 205314 Value: File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP974\A0141630.dll
Item Id: 205314 Value: File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP974\A0141631.dll
Item Id: 205314 Value: File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP974\A0141632.dll
Family Id: 1455 Name: Adware.SuperJuan Category: Adware TAI:3
Item Id: 223950 Value: File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP974\A0141627.dll
Item Id: 223950 Value: File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP974\A0141628.dll
Family Id: 5004 Name: VirusRemover2008 Category: Misc TAI:3
Item Id: 203867 Value: File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP974\A0143851.exe
Item Id: 203867 Value: File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP974\A0143852.exe
Item Id: 203867 Value: File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP974\A0143853.exe
Family Id: 9999 Name: MRU Object Category: MRU Object TAI:0
Item Id: 1 Value: MRU Path: C:\Documents and Settings\Julian Richards\Recent Count: 60
Item Id: 2 Value: MRU Registry Key: S-1-5-21-769079328-2221179514-3766738458-1011\Software\Microsoft\Search Assistant\ACMru\5603 Count: 18
Item Id: 3 Value: MRU Registry Key: S-1-5-21-769079328-2221179514-3766738458-1011\Software\Microsoft\Internet Explorer\TypedURLs Count: 1
Items Ignored During Scan
===========================
second half below (too long for ine post)