Ad-Aware SE Build 1.06r1
Logfile Created on:Saturday, 14 June 2008 9:30:57 PM
Using definitions file:SE1R259 12.06.2008
Computer name:BENT
User name:bent
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):1 total references
Win32.Trojandownloader.Zlob(TAC index:10):1 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Obtain command line of scanned processes
Set : Ignore spanned files when scanning cab archives
Set : Scan registry for all users instead of current user only
Set : Use permanent archive caching
Set : Automatically check all objects in results lists
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Deactivate Ad-Watch during Ad-Aware scans
Set : Log Ad-Aware events
Set : Block pop-ups aggressively
Set : Load Ad-Watch minimized
Set : Hide Ad-Watch tray icon
Set : Automatically select problematic objects in results lists
Set : Reanalyze results after scanning before displaying results lists
Set : Write-protect system files after repair (Hosts file, etc.)
Set : Include info about ignored objects in log file, if detected in scan
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include used command line parameters in log file
Set : Include computer and username in log file
Set : Include reference summary in log file
Set : Create log file for removal operations
Set : Include module list in log file
Set : Include alternate data stream details in log file
Set : Show splash screen
Set : Remember window positions
Set : Limit drive selection to fixed drives
Set : Use gridlines in results lists
Set : Show detail tooltips in results lists
Set : Suppress WebUpdate confirmation dialogs
Set : Backup current definitions file before updating
Set : Play sound at scan completion if scan locates critical objects
14-06-2008 9:30:57 PM - Scan started. (Smart mode)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
ModuleName : \SystemRoot\System32\smss.exe
Command Line : n/a
ProcessID : 732
ThreadCreationTime : 14-06-2008 6:32:11 AM
BasePriority : Normal
Scanning Module:\SystemRoot\System32\smss.exe...
Scanning Module:C:\WINDOWS\system32\ntdll.dll...
#:2 [csrss.exe]
ModuleName : \??\C:\WINDOWS\system32\csrss.exe
Command Line : C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestTh
ProcessID : 788
ThreadCreationTime : 14-06-2008 6:32:13 AM
BasePriority : Normal
Scanning Module:\??\C:\WINDOWS\system32\csrss.exe...
Scanning Module:C:\WINDOWS\system32\CSRSRV.dll...
Scanning Module:C:\WINDOWS\system32\basesrv.dll...
Scanning Module:C:\WINDOWS\system32\winsrv.dll...
Scanning Module:C:\WINDOWS\system32\GDI32.dll...
Scanning Module:C:\WINDOWS\system32\KERNEL32.dll...
Scanning Module:C:\WINDOWS\system32\USER32.dll...
Scanning Module:C:\WINDOWS\system32\sxs.dll...
Scanning Module:C:\WINDOWS\system32\ADVAPI32.dll...
Scanning Module:C:\WINDOWS\system32\RPCRT4.dll...
Scanning Module:C:\WINDOWS\system32\Secur32.dll...
Scanning Module:C:\WINDOWS\system32\Apphelp.dll...
Scanning Module:C:\WINDOWS\system32\VERSION.dll...
#:3 [winlogon.exe]
ModuleName : \??\C:\WINDOWS\system32\winlogon.exe
Command Line : winlogon.exe
ProcessID : 812
ThreadCreationTime : 14-06-2008 6:32:14 AM
BasePriority : High
Scanning Module:\??\C:\WINDOWS\system32\winlogon.exe...
Scanning Module:C:\WINDOWS\system32\AUTHZ.dll...
Scanning Module:C:\WINDOWS\system32\msvcrt.dll...
Scanning Module:C:\WINDOWS\system32\CRYPT32.dll...
Scanning Module:C:\WINDOWS\system32\MSASN1.dll...
Scanning Module:C:\WINDOWS\system32\NDdeApi.dll...
Scanning Module:C:\WINDOWS\system32\PROFMAP.dll...
Scanning Module:C:\WINDOWS\system32\NETAPI32.dll...
Scanning Module:C:\WINDOWS\system32\USERENV.dll...
Scanning Module:C:\WINDOWS\system32\PSAPI.DLL...
Scanning Module:C:\WINDOWS\system32\REGAPI.dll...
Scanning Module:C:\WINDOWS\system32\SETUPAPI.dll...
Scanning Module:C:\WINDOWS\system32\WINSTA.dll...
Scanning Module:C:\WINDOWS\system32\WINTRUST.dll...
Scanning Module:C:\WINDOWS\system32\IMAGEHLP.dll...
Scanning Module:C:\WINDOWS\system32\WS2_32.dll...
Scanning Module:C:\WINDOWS\system32\WS2HELP.dll...
Scanning Module:C:\WINDOWS\system32\IMM32.DLL...
Scanning Module:C:\WINDOWS\system32\MSGINA.dll...
Scanning Module:C:\WINDOWS\system32\COMCTL32.dll...
Scanning Module:C:\WINDOWS\system32\ODBC32.dll...
Scanning Module:C:\WINDOWS\system32\comdlg32.dll...
Scanning Module:C:\WINDOWS\system32\SHELL32.dll...
Scanning Module:C:\WINDOWS\system32\SHLWAPI.dll...
Scanning Module:C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll...
Scanning Module:C:\WINDOWS\system32\odbcint.dll...
Scanning Module:C:\WINDOWS\system32\SHSVCS.dll...
Scanning Module:C:\WINDOWS\system32\sfc.dll...
Scanning Module:C:\WINDOWS\system32\sfc_os.dll...
Scanning Module:C:\WINDOWS\system32\ole32.dll...
Scanning Module:C:\WINDOWS\system32\msctfime.ime...
Scanning Module:C:\WINDOWS\system32\WINSCARD.DLL...
Scanning Module:C:\WINDOWS\system32\WTSAPI32.dll...
Scanning Module:C:\WINDOWS\system32\uxtheme.dll...
Scanning Module:C:\WINDOWS\system32\WINMM.dll...
Scanning Module:C:\WINDOWS\system32\cscdll.dll...
Scanning Module:C:\WINDOWS\System32\dimsntfy.dll...
Scanning Module:C:\WINDOWS\system32\WlNotify.dll...
Scanning Module:C:\WINDOWS\system32\MPR.dll...
Scanning Module:C:\WINDOWS\system32\WINSPOOL.DRV...
Scanning Module:C:\WINDOWS\system32\WgaLogon.dll...
Scanning Module:C:\WINDOWS\system32\OLEAUT32.dll...
Scanning Module:C:\WINDOWS\system32\rsaenh.dll...
Scanning Module:C:\WINDOWS\system32\NTMARTA.DLL...
Scanning Module:C:\WINDOWS\system32\SAMLIB.dll...
Scanning Module:C:\WINDOWS\system32\WLDAP32.dll...
Scanning Module:C:\WINDOWS\system32\CLBCATQ.DLL...
Scanning Module:C:\WINDOWS\system32\COMRes.dll...
Scanning Module:C:\WINDOWS\system32\msv1_0.dll...
Scanning Module:C:\WINDOWS\system32\iphlpapi.dll...
Scanning Module:C:\WINDOWS\system32\cscui.dll...
Scanning Module:C:\WINDOWS\system32\xpsp2res.dll...
Scanning Module:C:\WINDOWS\system32\wdmaud.drv...
Scanning Module:C:\WINDOWS\system32\msacm32.drv...
Scanning Module:C:\WINDOWS\system32\MSACM32.dll...
Scanning Module:C:\WINDOWS\system32\midimap.dll...
Scanning Module:C:\Program Files\ThreatFire\TFNI.dll...
Scanning Module:C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCP80.dll...
Scanning Module:C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll...
Scanning Module:C:\WINDOWS\system32\wbem\wbemprox.dll...
Scanning Module:C:\WINDOWS\system32\wbem\wbemcomn.dll...
Scanning Module:C:\WINDOWS\system32\wbem\wbemsvc.dll...
Scanning Module:C:\WINDOWS\system32\wbem\fastprox.dll...
Scanning Module:C:\WINDOWS\system32\MSVCP60.dll...
Scanning Module:C:\WINDOWS\system32\NTDSAPI.dll...
Scanning Module:C:\WINDOWS\system32\DNSAPI.dll...
#:4 [services.exe]
ModuleName : C:\WINDOWS\system32\services.exe
Command Line : C:\WINDOWS\system32\services.exe
ProcessID : 856
ThreadCreationTime : 14-06-2008 6:32:14 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-2111)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
Scanning Module:C:\WINDOWS\system32\services.exe...
Scanning Module:C:\WINDOWS\system32\NCObjAPI.DLL...
Scanning Module:C:\WINDOWS\system32\SCESRV.dll...
Scanning Module:C:\WINDOWS\system32\umpnpmgr.dll...
Scanning Module:C:\WINDOWS\system32\ShimEng.dll...
Scanning Module:C:\WINDOWS\AppPatch\AcAdProc.dll...
Scanning Module:C:\WINDOWS\system32\eventlog.dll...
Scanning Module:C:\Program Files\ThreatFire\TFWAH.dll...
#:5 [lsass.exe]
ModuleName : C:\WINDOWS\system32\lsass.exe
Command Line : C:\WINDOWS\system32\lsass.exe
ProcessID : 868
ThreadCreationTime : 14-06-2008 6:32:14 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-2113)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
Scanning Module:C:\WINDOWS\system32\lsass.exe...
Scanning Module:C:\WINDOWS\system32\LSASRV.dll...
Scanning Module:C:\WINDOWS\system32\SAMSRV.dll...
Scanning Module:C:\WINDOWS\system32\cryptdll.dll...
Scanning Module:C:\WINDOWS\AppPatch\AcGenral.DLL...
Scanning Module:C:\WINDOWS\system32\msprivs.dll...
Scanning Module:C:\WINDOWS\system32\kerberos.dll...
Scanning Module:C:\WINDOWS\system32\netlogon.dll...
Scanning Module:C:\WINDOWS\system32\w32time.dll...
Scanning Module:C:\WINDOWS\system32\schannel.dll...
Scanning Module:C:\WINDOWS\system32\wdigest.dll...
Scanning Module:C:\WINDOWS\system32\scecli.dll...
Scanning Module:C:\WINDOWS\system32\ipsecsvc.dll...
Scanning Module:C:\WINDOWS\system32\oakley.DLL...
Scanning Module:C:\WINDOWS\system32\WINIPSEC.DLL...
Scanning Module:C:\WINDOWS\system32\pstorsvc.dll...
Scanning Module:C:\WINDOWS\system32\imon.dll...
Scanning Module:C:\WINDOWS\system32\WSOCK32.dll...
Scanning Module:C:\WINDOWS\system32\psbase.dll...
Scanning Module:C:\WINDOWS\system32\mswsock.dll...
Scanning Module:C:\WINDOWS\system32\hnetcfg.dll...
Scanning Module:C:\WINDOWS\System32\wshtcpip.dll...
Scanning Module:C:\WINDOWS\system32\dssenh.dll...
#:6 [svchost.exe]
ModuleName : C:\WINDOWS\system32\svchost.exe
Command Line : C:\WINDOWS\system32\svchost -k DcomLaunch
ProcessID : 1036
ThreadCreationTime : 14-06-2008 6:32:15 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-2111)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
Scanning Module:C:\WINDOWS\system32\svchost.exe...
Scanning Module:c:\windows\system32\rpcss.dll...
Scanning Module:c:\windows\system32\termsrv.dll...
Scanning Module:c:\windows\system32\ICAAPI.dll...
Scanning Module:c:\windows\system32\mstlsapi.dll...
Scanning Module:c:\windows\system32\ACTIVEDS.dll...
Scanning Module:c:\windows\system32\adsldpc.dll...
Scanning Module:c:\windows\system32\ATL.DLL...
#:7 [svchost.exe]
ModuleName : C:\WINDOWS\system32\svchost.exe
Command Line : C:\WINDOWS\system32\svchost -k rpcss
ProcessID : 1104
ThreadCreationTime : 14-06-2008 6:32:15 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-2111)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
Scanning Module:C:\WINDOWS\System32\wship6.dll...
Scanning Module:C:\WINDOWS\system32\pnrpnsp.dll...
Scanning Module:C:\WINDOWS\System32\winrnr.dll...
Scanning Module:C:\WINDOWS\system32\rasadhlp.dll...
#:8 [msmpeng.exe]
ModuleName : C:\Program Files\Windows Defender\MsMpEng.exe
Command Line : "C:\Program Files\Windows Defender\MsMpEng.exe"
ProcessID : 1216
ThreadCreationTime : 14-06-2008 6:32:15 AM
BasePriority : Normal
FileVersion : 1.1.1593.0
ProductVersion : 1.1.1593.0
ProductName : Windows Defender
CompanyName : Microsoft Corporation
FileDescription : Service Executable
InternalName : MsMpEng.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : MsMpEng.exe
Scanning Module:C:\Program Files\Windows Defender\MsMpEng.exe...
Scanning Module:C:\Program Files\Windows Defender\MpSvc.dll...
Scanning Module:C:\Program Files\Windows Defender\MpClient.dll...
Scanning Module:C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{36453B81-3159-460D-B200-C483FE3B65F0}\mpengine.dll...
Scanning Module:C:\WINDOWS\system32\DBGHELP.DLL...
Scanning Module:C:\WINDOWS\system32\WININET.DLL...
Scanning Module:C:\WINDOWS\system32\Normaliz.dll...
Scanning Module:C:\WINDOWS\system32\iertutil.dll...
Scanning Module:C:\Program Files\Windows Defender\mprtplug.dll...
Scanning Module:C:\Program Files\Windows Defender\MpAsDesc.dll...
#:9 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k netsvcs
ProcessID : 1256
ThreadCreationTime : 14-06-2008 6:32:15 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-2111)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
Scanning Module:c:\windows\system32\dhcpcsvc.dll...
Scanning Module:c:\windows\system32\wzcsvc.dll...
Scanning Module:c:\windows\system32\rtutils.dll...
Scanning Module:c:\windows\system32\WMI.dll...
Scanning Module:c:\windows\system32\EapolQec.dll...
Scanning Module:c:\windows\system32\QUtil.dll...
Scanning Module:c:\windows\system32\dot3api.dll...
Scanning Module:c:\windows\system32\ESENT.dll...
Scanning Module:C:\WINDOWS\System32\rastls.dll...
Scanning Module:C:\WINDOWS\system32\CRYPTUI.dll...
Scanning Module:C:\WINDOWS\System32\MPRAPI.dll...
Scanning Module:C:\WINDOWS\System32\RASAPI32.dll...
Scanning Module:C:\WINDOWS\System32\rasman.dll...
Scanning Module:C:\WINDOWS\System32\TAPI32.dll...
Scanning Module:C:\WINDOWS\System32\raschap.dll...
Scanning Module:c:\windows\system32\schedsvc.dll...
Scanning Module:C:\WINDOWS\System32\MSIDLE.DLL...
Scanning Module:c:\windows\system32\audiosrv.dll...
Scanning Module:c:\windows\system32\wkssvc.dll...
Scanning Module:c:\windows\system32\qmgr.dll...
Scanning Module:c:\windows\system32\SHFOLDER.dll...
Scanning Module:c:\windows\system32\WINHTTP.dll...
Scanning Module:C:\WINDOWS\System32\netman.dll...
Scanning Module:C:\WINDOWS\System32\netshell.dll...
Scanning Module:C:\WINDOWS\System32\credui.dll...
Scanning Module:C:\WINDOWS\System32\dot3dlg.dll...
Scanning Module:C:\WINDOWS\System32\OneX.DLL...
Scanning Module:C:\WINDOWS\System32\eappcfg.dll...
Scanning Module:C:\WINDOWS\System32\eappprxy.dll...
Scanning Module:C:\WINDOWS\System32\WZCSAPI.DLL...
Scanning Module:c:\windows\system32\cryptsvc.dll...
Scanning Module:c:\windows\system32\certcli.dll...
Scanning Module:c:\windows\pchealth\helpctr\binaries\pchsvc.dll...
Scanning Module:c:\windows\system32\ersvc.dll...
Scanning Module:c:\windows\system32\es.dll...
Scanning Module:c:\windows\system32\dmserver.dll...
Scanning Module:c:\windows\system32\iprip.dll...
Scanning Module:c:\windows\system32\srvsvc.dll...
Scanning Module:c:\windows\system32\seclogon.dll...
Scanning Module:c:\windows\system32\sens.dll...
Scanning Module:c:\windows\system32\srsvc.dll...
Scanning Module:c:\windows\system32\POWRPROF.dll...
Scanning Module:c:\windows\system32\tapisrv.dll...
Scanning Module:c:\windows\system32\trkwks.dll...
Scanning Module:c:\windows\system32\wbem\wmisvc.dll...
Scanning Module:C:\WINDOWS\system32\VSSAPI.DLL...
Scanning Module:c:\windows\system32\wuauserv.dll...
Scanning Module:C:\WINDOWS\system32\wuaueng.dll...
Scanning Module:C:\WINDOWS\System32\Cabinet.dll...
Scanning Module:C:\WINDOWS\System32\mspatcha.dll...
Scanning Module:C:\WINDOWS\system32\comsvcs.dll...
Scanning Module:C:\WINDOWS\system32\colbact.DLL...
Scanning Module:C:\WINDOWS\system32\MTXCLU.DLL...
Scanning Module:C:\WINDOWS\System32\CLUSAPI.DLL...
Scanning Module:C:\WINDOWS\System32\RESUTILS.DLL...
Scanning Module:c:\windows\system32\ipnathlp.dll...
Scanning Module:c:\windows\system32\wscsvc.dll...
Scanning Module:c:\windows\system32\msi.dll...
Scanning Module:C:\WINDOWS\system32\WBEM\wbemcore.dll...
Scanning Module:C:\WINDOWS\system32\WBEM\esscli.dll...
Scanning Module:C:\WINDOWS\system32\wbem\wmiutils.dll...
Scanning Module:C:\WINDOWS\system32\wbem\repdrvfs.dll...
Scanning Module:C:\WINDOWS\system32\wbem\wmiprvsd.dll...
Scanning Module:C:\WINDOWS\system32\wbem\wbemess.dll...
Scanning Module:C:\WINDOWS\system32\wbem\ncprov.dll...
Scanning Module:c:\windows\system32\browser.dll...
Scanning Module:C:\WINDOWS\system32\upnp.dll...
Scanning Module:C:\WINDOWS\system32\SSDPAPI.dll...
Scanning Module:C:\WINDOWS\system32\netcfgx.dll...
Scanning Module:C:\WINDOWS\System32\rasmans.dll...
Scanning Module:C:\WINDOWS\System32\rastapi.dll...
Scanning Module:C:\WINDOWS\System32\unimdm.tsp...
Scanning Module:C:\WINDOWS\System32\uniplat.dll...
Scanning Module:C:\WINDOWS\System32\kmddsp.tsp...
Scanning Module:C:\WINDOWS\System32\ndptsp.tsp...
Scanning Module:C:\WINDOWS\System32\ipconf.tsp...
Scanning Module:C:\WINDOWS\System32\h323.tsp...
Scanning Module:C:\WINDOWS\System32\hidphone.tsp...
Scanning Module:C:\WINDOWS\System32\HID.DLL...
Scanning Module:C:\WINDOWS\System32\rasppp.dll...
Scanning Module:C:\WINDOWS\System32\ntlsapi.dll...
Scanning Module:C:\WINDOWS\System32\RASQEC.DLL...
Scanning Module:C:\WINDOWS\System32\RASDLG.dll...
Scanning Module:C:\WINDOWS\system32\urlmon.dll...
Scanning Module:C:\WINDOWS\system32\advpack.dll...
Scanning Module:C:\WINDOWS\system32\wups.dll...
Scanning Module:C:\WINDOWS\system32\msxml3.dll...
Scanning Module:C:\WINDOWS\system32\wups2.dll...
Scanning Module:C:\WINDOWS\system32\wuapi.dll...
Scanning Module:C:\WINDOWS\system32\rsvpsp.dll...
#:10 [svchost.exe]
ModuleName : C:\WINDOWS\system32\svchost.exe
Command Line : C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
ProcessID : 1288
ThreadCreationTime : 14-06-2008 6:32:15 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-2111)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
Scanning Module:c:\windows\system32\wudfsvc.dll...
Scanning Module:c:\windows\system32\WUDFPlatform.dll...
#:11 [svchost.exe]
ModuleName : C:\WINDOWS\system32\svchost.exe
Command Line : C:\WINDOWS\system32\svchost.exe -k NetworkService
ProcessID : 1352
ThreadCreationTime : 14-06-2008 6:32:15 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-2111)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
Scanning Module:c:\windows\system32\dnsrslvr.dll...
#:12 [svchost.exe]
ModuleName : C:\WINDOWS\system32\svchost.exe
Command Line : C:\WINDOWS\system32\svchost.exe -k LocalService
ProcessID : 1504
ThreadCreationTime : 14-06-2008 6:32:15 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-2111)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
Scanning Module:c:\windows\system32\lmhsvc.dll...
Scanning Module:c:\windows\system32\webclnt.dll...
Scanning Module:c:\windows\system32\regsvc.dll...
Scanning Module:c:\windows\system32\ssdpsrv.dll...
Scanning Module:C:\WINDOWS\system32\httpapi.dll...
#:13 [spoolsv.exe]
ModuleName : C:\WINDOWS\system32\spoolsv.exe
Command Line : C:\WINDOWS\system32\spoolsv.exe
ProcessID : 1728
ThreadCreationTime : 14-06-2008 6:32:16 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-0852)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
Scanning Module:C:\WINDOWS\system32\spoolsv.exe...
Scanning Module:C:\WINDOWS\system32\SPOOLSS.DLL...
Scanning Module:C:\WINDOWS\system32\localspl.dll...
Scanning Module:C:\WINDOWS\system32\cnbjmon.dll...
Scanning Module:C:\WINDOWS\system32\CNMLM5y.DLL...
Scanning Module:C:\WINDOWS\system32\lprmon.dll...
Scanning Module:C:\WINDOWS\system32\LPRHELP.dll...
Scanning Module:C:\WINDOWS\system32\FXSMON.DLL...
Scanning Module:C:\WINDOWS\system32\FXSEVENT.dll...
Scanning Module:C:\WINDOWS\system32\pjlmon.dll...
Scanning Module:C:\WINDOWS\system32\msonpmon.dll...
Scanning Module:C:\WINDOWS\system32\tcpmon.dll...
Scanning Module:C:\WINDOWS\system32\usbmon.dll...
Scanning Module:C:\WINDOWS\System32\spool\PRTPROCS\W32X86\CNMPD5y.DLL...
Scanning Module:C:\WINDOWS\System32\spool\PRTPROCS\W32X86\msonpppr.dll...
Scanning Module:C:\WINDOWS\system32\win32spl.dll...
Scanning Module:C:\WINDOWS\system32\NETRAP.dll...
Scanning Module:C:\WINDOWS\system32\inetpp.dll...
#:14 [explorer.exe]
ModuleName : C:\WINDOWS\Explorer.EXE
Command Line : C:\WINDOWS\Explorer.EXE
ProcessID : 1984
ThreadCreationTime : 14-06-2008 6:32:17 AM
BasePriority : Normal
FileVersion : 6.00.2900.5512 (xpsp.080413-2105)
ProductVersion : 6.00.2900.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
Scanning Module:C:\WINDOWS\Explorer.EXE...
Scanning Module:C:\WINDOWS\system32\BROWSEUI.dll...
Scanning Module:C:\WINDOWS\system32\SHDOCVW.dll...
Scanning Module:C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll...
Scanning Module:C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL...
Scanning Module:C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL...
Scanning Module:C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.DLL...
Scanning Module:C:\WINDOWS\system32\MSImg32.dll...
Scanning Module:C:\WINDOWS\system32\themeui.dll...
Scanning Module:C:\WINDOWS\system32\LINKINFO.dll...
Scanning Module:C:\WINDOWS\system32\ntshrui.dll...
Scanning Module:C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll...
Scanning Module:C:\WINDOWS\system32\MSCTF.dll...
Scanning Module:C:\WINDOWS\system32\shdoclc.dll...
Scanning Module:C:\WINDOWS\system32\webcheck.dll...
Scanning Module:C:\WINDOWS\system32\IEFRAME.dll...
Scanning Module:C:\WINDOWS\system32\stobject.dll...
Scanning Module:C:\WINDOWS\system32\BatMeter.dll...
Scanning Module:C:\WINDOWS\system32\upnpui.dll...
Scanning Module:C:\WINDOWS\system32\WPDShServiceObj.dll...
Scanning Module:C:\WINDOWS\system32\PortableDeviceTypes.dll...
Scanning Module:C:\WINDOWS\system32\PortableDeviceApi.dll...
Scanning Module:C:\WINDOWS\system32\fxsst.dll...
Scanning Module:C:\WINDOWS\system32\FXSAPI.dll...
Scanning Module:C:\WINDOWS\System32\drprov.dll...
Scanning Module:C:\WINDOWS\System32\ntlanman.dll...
Scanning Module:C:\WINDOWS\System32\NETUI0.dll...
Scanning Module:C:\WINDOWS\System32\NETUI1.dll...
Scanning Module:C:\WINDOWS\System32\davclnt.dll...
Scanning Module:C:\Program Files\Microsoft Office\Office12\GrooveMisc.dll...
Scanning Module:C:\WINDOWS\system32\wzcdlg.dll...
Scanning Module:C:\PROGRA~1\WIFD1F~1\MpShHook.dll...
Scanning Module:C:\WINDOWS\system32\MSISIP.DLL...
Scanning Module:C:\WINDOWS\system32\wshext.dll...
#:15 [nod32kui.exe]
ModuleName : C:\Program Files\Eset\nod32kui.exe
Command Line : "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
ProcessID : 208
ThreadCreationTime : 14-06-2008 6:32:19 AM
BasePriority : Normal
FileVersion : 2, 70, 39
ProductVersion : 2, 70, 39
ProductName : NOD32 Antivirus System
CompanyName : Eset
FileDescription : NOD32 Control Center GUI
InternalName : NOD32 Control Center GUI
LegalCopyright : Copyright (c) 1992-2005 Eset
LegalTrademarks : NOD, NOD32, AMON, ESET are registered trademarks of Eset
OriginalFilename : nod32kui.exe
Scanning Module:C:\Program Files\Eset\nod32kui.exe...
Scanning Module:C:\WINDOWS\system32\MFC42u.DLL...
Scanning Module:C:\Program Files\Eset\pu_amon.dll...
Scanning Module:C:\Program Files\Eset\pu_dmon.dll...
Scanning Module:C:\Program Files\Eset\pu_emon.dll...
Scanning Module:C:\Program Files\Eset\pu_imon.dll...
Scanning Module:C:\Program Files\Eset\pu_nod32.dll...
Scanning Module:C:\Program Files\Eset\pu_upd.dll...
#:16 [issch.exe]
ModuleName : C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
Command Line : "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
ProcessID : 236
ThreadCreationTime : 14-06-2008 6:32:19 AM
BasePriority : Normal
FileVersion : 4, 10, 100, 25539
ProductVersion : 4, 10
ProductName : InstallShield Update Service
CompanyName : InstallShield Software Corporation
FileDescription : InstallShield Update Service Scheduler
InternalName : Scheduler
LegalCopyright : Copyright (C) 1990-2004 InstallShield Software Corporation
OriginalFilename : issch.exe
Scanning Module:C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe...
#:17 [jusched.exe]
ModuleName : C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
Command Line : "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
ProcessID : 244
ThreadCreationTime : 14-06-2008 6:32:19 AM
BasePriority : Normal
Scanning Module:C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe...
#:18 [tftray.exe]
ModuleName : C:\Program Files\ThreatFire\TFTray.exe
Command Line : n/a
ProcessID : 272
ThreadCreationTime : 14-06-2008 6:32:19 AM
BasePriority : Normal
FileVersion : 3.8.4.24
ProductVersion : 3.5.0.21
ProductName : ThreatFire
CompanyName : PC Tools
FileDescription : PC Tools ThreatFire Tray App
InternalName : TrayApp
LegalCopyright : Copyright © 2005-2008 PC Tools. All Rights Reserved.
LegalTrademarks : ThreatFire(tm) is a trademark of PC Tools
OriginalFilename : TrayApp.exe
Scanning Module:C:\Program Files\ThreatFire\TFTray.exe...
Scanning Module:C:\Program Files\ThreatFire\TFAPI.dll...
Scanning Module:C:\Program Files\ThreatFire\TFRes-en.dll...
#:19 [msascui.exe]
ModuleName : C:\Program Files\Windows Defender\MSASCui.exe
Command Line : "C:\Program Files\Windows Defender\MSASCui.exe" -hide
ProcessID : 368
ThreadCreationTime : 14-06-2008 6:32:19 AM
BasePriority : Normal
FileVersion : 1.1.1593.0
ProductVersion : 1.1.1593.0
ProductName : Windows Defender
CompanyName : Microsoft Corporation
FileDescription : Windows Defender User Interface
InternalName : MSASCUI
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : MSASCUI.exe
Scanning Module:C:\Program Files\Windows Defender\MSASCui.exe...
Scanning Module:C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\gdiplus.dll...
Scanning Module:C:\WINDOWS\system32\OLEACC.dll...
Scanning Module:C:\Program Files\Windows Defender\MsMpRes.dll...
Scanning Module:C:\Program Files\Windows Defender\MpRtMon.DLL...
Scanning Module:C:\WINDOWS\system32\MSFTEDIT.DLL...
Scanning Module:C:\WINDOWS\system32\WshRm.dll...
#:20 [rthdcpl.exe]
ModuleName : C:\WINDOWS\RTHDCPL.EXE
Command Line : "C:\WINDOWS\RTHDCPL.EXE"
ProcessID : 376
ThreadCreationTime : 14-06-2008 6:32:19 AM
BasePriority : Normal
FileVersion : 2.1.1.1
ProductVersion : 2.1.1.1
ProductName : Realtek HD Audio Sound Effect Manager
CompanyName : Realtek Semiconductor Corp.
FileDescription : Realtek HD Audio Control Panel
LegalCopyright : Copyright (c) 2004 Realtek Semiconductor Corp.
OriginalFilename : RTHDCPL.EXE
Scanning Module:C:\WINDOWS\RTHDCPL.EXE...
Scanning Module:C:\WINDOWS\system32\DSOUND.DLL...
Scanning Module:C:\WINDOWS\system32\HHCTRL.OCX...
Scanning Module:C:\WINDOWS\system32\KsUser.dll...
#:21 [igfxtray.exe]
ModuleName : C:\WINDOWS\system32\igfxtray.exe
Command Line : "C:\WINDOWS\system32\igfxtray.exe"
ProcessID : 424
ThreadCreationTime : 14-06-2008 6:32:19 AM
BasePriority : Normal
FileVersion : 6.14.10.4764
ProductVersion : 6.14.10.4764
ProductName : Intel(R) Common User Interface
CompanyName : Intel Corporation
FileDescription : igfxTray Module
InternalName : IGFXTRAY
LegalCopyright : Copyright 1999-2006, Intel Corporation
OriginalFilename : IGFXTRAY.EXE
Scanning Module:C:\WINDOWS\system32\igfxtray.exe...
Scanning Module:C:\WINDOWS\system32\hccutils.DLL...
Scanning Module:C:\WINDOWS\system32\igfxsrvc.dll...
Scanning Module:C:\WINDOWS\system32\igfxres.dll...
Scanning Module:C:\WINDOWS\system32\igfxress.dll...
#:22 [hkcmd.exe]
ModuleName : C:\WINDOWS\system32\hkcmd.exe
Command Line : "C:\WINDOWS\system32\hkcmd.exe"
ProcessID : 444
ThreadCreationTime : 14-06-2008 6:32:19 AM
BasePriority : Normal
FileVersion : 6.14.10.4764
ProductVersion : 6.14.10.4764
ProductName : Intel(R) Common User Interface
CompanyName : Intel Corporation
FileDescription : hkcmd Module
InternalName : HKCMD
LegalCopyright : Copyright 1999-2006, Intel Corporation
OriginalFilename : HKCMD.EXE
Scanning Module:C:\WINDOWS\system32\hkcmd.exe...
#:23 [igfxpers.exe]
ModuleName : C:\WINDOWS\system32\igfxpers.exe
Command Line : "C:\WINDOWS\system32\igfxpers.exe"
ProcessID : 456
ThreadCreationTime : 14-06-2008 6:32:19 AM
BasePriority : Normal
FileVersion : 6.14.10.4764
ProductVersion : 6.14.10.4764
ProductName : Intel(R) Common User Interface
CompanyName : Intel Corporation
FileDescription : persistence Module
InternalName : PERSISTENCE
LegalCopyright : Copyright 1999-2006, Intel Corporation
OriginalFilename : IGFXPERS.EXE
Scanning Module:C:\WINDOWS\system32\igfxpers.exe...
#:24 [groovemonitor.exe]
ModuleName : C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
Command Line : "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
ProcessID : 572
ThreadCreationTime : 14-06-2008 6:32:19 AM
BasePriority : Normal
Scanning Module:C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe...
#:25 [spyeraser.exe]
ModuleName : C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
Command Line : "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
ProcessID : 608
ThreadCreationTime : 14-06-2008 6:32:19 AM
BasePriority : Normal
FileVersion : 2.0.1.1531
ProductVersion : 2.0.1.1531
ProductName : SpyEraser
CompanyName : Uniblue Software
FileDescription : SpyEraser
InternalName : SpyEraser
LegalCopyright : Copyright (C) 2003-2006 Uniblue Software. All rights reserved.
LegalTrademarks : Uniblue Software
OriginalFilename : SpyEraser
Comments :
http://www.Uniblue.com
Scanning Module:C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe...
Scanning Module:C:\Program Files\Uniblue\SpyEraser\SEEng.dll...
Scanning Module:C:\Program Files\Uniblue\SpyEraser\zlibwapi.dll...
Scanning Module:C:\Program Files\Uniblue\SpyEraser\XceedZip.dll...
Scanning Module:C:\Program Files\Uniblue\SpyEraser\spyeraser.dll...
Scanning Module:C:\Program Files\Uniblue\SpyEraser\ubvarse.dll...
Scanning Module:C:\WINDOWS\system32\inetmib1.dll...
Scanning Module:C:\WINDOWS\system32\snmpapi.dll...
Scanning Module:C:\WINDOWS\system32\mstask.dll...
Scanning Module:C:\WINDOWS\system32\RICHED20.DLL...
Scanning Module:C:\WINDOWS\system32\mshtml.dll...
Scanning Module:C:\WINDOWS\system32\msls31.dll...
#:26 [ad-watch.exe]
ModuleName : C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe
Command Line : "C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe"
ProcessID : 616
ThreadCreationTime : 14-06-2008 6:32:19 AM
BasePriority : High
FileVersion : 3.1.2.17
ProductVersion : 3.2
ProductName : Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Watch System Protector
InternalName : Ad-Watch.exe
LegalCopyright : 1999-2004 Team Lavasoft
OriginalFilename : Ad-Watch.exe
Scanning Module:C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe...
Scanning Module:C:\WINDOWS\system32\olepro32.dll...
Scanning Module:C:\WINDOWS\system32\RICHED32.DLL...
#:27 [ctfmon.exe]
ModuleName : C:\WINDOWS\system32\ctfmon.exe
Command Line : "C:\WINDOWS\system32\ctfmon.exe"
ProcessID : 632
ThreadCreationTime : 14-06-2008 6:32:20 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-2105)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE
Scanning Module:C:\WINDOWS\system32\ctfmon.exe...
Scanning Module:C:\WINDOWS\system32\MSUTB.dll...
#:28 [msdtc.exe]
ModuleName : C:\WINDOWS\system32\msdtc.exe
Command Line : C:\WINDOWS\system32\msdtc.exe
ProcessID : 1276
ThreadCreationTime : 14-06-2008 6:32:25 AM
BasePriority : Normal
FileVersion : 2001.12.4414.700
ProductVersion : 03.01.00.4414
ProductName : Microsoft Distributed Transaction Coordinator
CompanyName : Microsoft Corporation
FileDescription : MS DTC console program
InternalName : MSDTC.EXE
LegalCopyright : Copyright (C) Microsoft Corp. 1995-1998
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation. Windows(TM) is a trademark of Microsoft Corporation
Scanning Module:C:\WINDOWS\system32\msdtc.exe...
Scanning Module:C:\WINDOWS\system32\MSDTCTM.dll...
Scanning Module:C:\WINDOWS\system32\MSDTCLOG.dll...
Scanning Module:C:\WINDOWS\system32\MSDTCPRX.dll...
Scanning Module:C:\WINDOWS\system32\XOLEHLP.dll...
Scanning Module:C:\WINDOWS\system32\MTxOCI.Dll...
#:29 [a2service.exe]
ModuleName : C:\Program Files\a-squared Free\a2service.exe
Command Line : "C:\Program Files\a-squared Free\a2service.exe"
ProcessID : 1432
ThreadCreationTime : 14-06-2008 6:32:27 AM
BasePriority : Normal
FileVersion : 3.0.0.448
ProductVersion : 3.0.0.0
ProductName : a-squared
CompanyName : Emsi Software GmbH
FileDescription : a-squared Service
InternalName : a2service
LegalCopyright : (C) 2003-2008 Emsi Software GmbH
OriginalFilename : a2service.exe
Scanning Module:C:\Program Files\a-squared Free\a2service.exe...
#:30 [cisvc.exe]
ModuleName : C:\WINDOWS\system32\cisvc.exe
Command Line : C:\WINDOWS\system32\cisvc.exe
ProcessID : 1528
ThreadCreationTime : 14-06-2008 6:32:28 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-0852)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Content Index service
InternalName : cisvc.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : cisvc.exe
Scanning Module:C:\WINDOWS\system32\cisvc.exe...
Scanning Module:C:\WINDOWS\system32\query.dll...
Scanning Module:C:\WINDOWS\system32\ADMWPROX.DLL...
#:31 [inetinfo.exe]
ModuleName : C:\WINDOWS\system32\inetsrv\inetinfo.exe
Command Line : C:\WINDOWS\system32\inetsrv\inetinfo.exe
ProcessID : 1872
ThreadCreationTime : 14-06-2008 6:32:29 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-0852)
ProductVersion : 5.1.2600.5512
ProductName : Internet Information Services
CompanyName : Microsoft Corporation
FileDescription : Internet Information Services
InternalName : INETINFO.EXE
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : INETINFO.EXE
Scanning Module:C:\WINDOWS\system32\inetsrv\inetinfo.exe...
Scanning Module:C:\WINDOWS\system32\IisRTL.DLL...
Scanning Module:C:\WINDOWS\system32\inetsrv\rpcref.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\iisadmin.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\COADMIN.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\metadata.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\nsepm.dll...
Scanning Module:C:\WINDOWS\system32\IISMAP.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\wamreg.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\admexs.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\svcext.dll...
Scanning Module:C:\WINDOWS\system32\Security.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\w3svc.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\INFOCOMM.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\ISATQ.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\IISFECNV.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\lonsint.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\ftpsvc2.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\SMTPSVC.dll...
Scanning Module:C:\WINDOWS\system32\FCACHDLL.dll...
Scanning Module:C:\WINDOWS\system32\RWNH.dll...
Scanning Module:C:\WINDOWS\system32\exstrace.dll...
Scanning Module:C:\WINDOWS\system32\STAXMEM.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\iscomlog.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\sspifilt.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\compfilt.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\seo.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\gzip.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\pwsdata.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\md5filt.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\aqueue.dll...
Scanning Module:C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\40\bin\fpexedll.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\iislog.dll...
Scanning Module:C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\ntfsdrv.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\httpext.dll...
#:32 [nod32krn.exe]
ModuleName : C:\Program Files\Eset\nod32krn.exe
Command Line : "C:\Program Files\Eset\nod32krn.exe"
ProcessID : 1952
ThreadCreationTime : 14-06-2008 6:32:29 AM
BasePriority : Normal
FileVersion : 2, 70, 39
ProductVersion : 2, 70, 39
ProductName : NOD32 Antivirus System
CompanyName : Eset
FileDescription : NOD32 Kernel Service
InternalName : NOD32 Kernel
LegalCopyright : Copyright (c) 1992-2005 Eset
LegalTrademarks : NOD, NOD32, AMON, ESET are registered trademarks of Eset
OriginalFilename : nod32krn.exe
Scanning Module:C:\Program Files\Eset\nod32krn.exe...
Scanning Module:C:\Program Files\Eset\ps_amon.dll...
Scanning Module:C:\Program Files\Eset\ps_dmon.dll...
Scanning Module:C:\Program Files\Eset\ps_emon.dll...
Scanning Module:C:\Program Files\Eset\ps_nod32.dll...
Scanning Module:C:\Program Files\Eset\ps_upd.dll...
#:33 [tcpsvcs.exe]
ModuleName : C:\WINDOWS\system32\tcpsvcs.exe
Command Line : C:\WINDOWS\system32\tcpsvcs.exe
ProcessID : 2220
ThreadCreationTime : 14-06-2008 6:32:30 AM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : TCP/IP Services Application
InternalName : TCPSVCS.EXE
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : TCPSVCS.EXE
Scanning Module:C:\WINDOWS\system32\tcpsvcs.exe...
Scanning Module:C:\WINDOWS\system32\simptcp.dll...
#:34 [snmp.exe]
ModuleName : C:\WINDOWS\System32\snmp.exe
Command Line : C:\WINDOWS\System32\snmp.exe
ProcessID : 2272
ThreadCreationTime : 14-06-2008 6:32:30 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-0852)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : SNMP Service
InternalName : snmp.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : snmp.exe
Scanning Module:C:\WINDOWS\System32\snmp.exe...
Scanning Module:C:\WINDOWS\System32\lmmib2.dll...
Scanning Module:C:\WINDOWS\System32\hostmib.dll...
Scanning Module:C:\WINDOWS\System32\snmpmib.dll...
Scanning Module:C:\WINDOWS\System32\evntagnt.dll...
Scanning Module:C:\WINDOWS\System32\igmpagnt.dll...
Scanning Module:C:\WINDOWS\System32\mcastmib.dll...
Scanning Module:C:\WINDOWS\System32\rtipxmib.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\httpmib.dll...
Scanning Module:C:\WINDOWS\system32\INFOADMN.dll...
Scanning Module:C:\WINDOWS\system32\inetsrv\ftpmib.dll...
Scanning Module:C:\WINDOWS\System32\perfos.dll...
#:35 [svchost.exe]
ModuleName : C:\WINDOWS\system32\svchost.exe
Command Line : C:\WINDOWS\system32\svchost.exe -k imgsvc
ProcessID : 2376
ThreadCreationTime : 14-06-2008 6:32:31 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-2111)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
Scanning Module:c:\windows\system32\wiaservc.dll...
Scanning Module:c:\windows\system32\CFGMGR32.dll...
Scanning Module:c:\windows\system32\mscms.dll...
Scanning Module:C:\WINDOWS\system32\ACTXPRXY.DLL...
#:36 [tfservice.exe]
ModuleName : C:\Program Files\ThreatFire\TFService.exe
Command Line : n/a
ProcessID : 2448
ThreadCreationTime : 14-06-2008 6:32:31 AM
BasePriority : Normal
FileVersion : 3.8.4.24
ProductVersion : 3.5.0.21
ProductName : ThreatFire
CompanyName : PC Tools
FileDescription : PC Tools ThreatFire Service
InternalName : OCService
LegalCopyright : Copyright © 2005-2008 PC Tools. All Rights Reserved.
LegalTrademarks : ThreatFire(tm) is a trademark of PC Tools
OriginalFilename : OCService.dll
Scanning Module:C:\Program Files\ThreatFire\TFService.exe...
Scanning Module:C:\Program Files\ThreatFire\TFServer.dll...
Scanning Module:C:\Program Files\ThreatFire\TFE.dll...
Scanning Module:C:\Program Files\ThreatFire\TFMisc.dll...
Scanning Module:C:\Program Files\ThreatFire\TFLog.dll...
Scanning Module:C:\Program Files\ThreatFire\TFMon.dll...
Scanning Module:C:\Program Files\ThreatFire\TFUndo.dll...
Scanning Module:C:\Program Files\ThreatFire\TFSF.dll...
Scanning Module:C:\Program Files\ThreatFire\TFRK.dll...
Scanning Module:C:\Program Files\ThreatFire\TFQT.dll...
Scanning Module:C:\Program Files\ThreatFire\TFScan.dll...
Scanning Module:C:\Program Files\ThreatFire\TFAVE.dll...
Scanning Module:C:\Program Files\ThreatFire\TFDBM.dll...
Scanning Module:C:\Program Files\ThreatFire\TFTM.dll...
Scanning Module:C:\Program Files\ThreatFire\TFO.dll...
Scanning Module:C:\Program Files\ThreatFire\TFCR.dll...
Scanning Module:C:\Program Files\ThreatFire\TFWS.dll...
Scanning Module:C:\WINDOWS\system32\cryptnet.dll...
Scanning Module:C:\WINDOWS\system32\SensApi.dll...
#:37 [mqsvc.exe]
ModuleName : C:\WINDOWS\system32\mqsvc.exe
Command Line : C:\WINDOWS\system32\mqsvc.exe
ProcessID : 3008
ThreadCreationTime : 14-06-2008 6:32:35 AM
BasePriority : Normal
FileVersion : 5.01.1110
ProductVersion : 5.01.1110
ProductName : Microsoft Message Queue
CompanyName : Microsoft Corporation
FileDescription : Message Queuing Service
LegalCopyright : Copyright (C) Microsoft Corporation. 1981-2000
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation. Windows NT(TM) is a trademark of Microsoft Corporation
OriginalFilename : MQSVC.EXE
Scanning Module:C:\WINDOWS\system32\mqsvc.exe...
Scanning Module:C:\WINDOWS\system32\MQQM.dll...
Scanning Module:C:\WINDOWS\system32\mqutil.dll...
Scanning Module:C:\WINDOWS\system32\mqsec.dll...
Scanning Module:C:\WINDOWS\system32\MqLogMgr.dll...
#:38 [mqtgsvc.exe]
ModuleName : C:\WINDOWS\system32\mqtgsvc.exe
Command Line : C:\WINDOWS\system32\mqtgsvc.exe
ProcessID : 3464
ThreadCreationTime : 14-06-2008 6:32:39 AM
BasePriority : Normal
FileVersion : 5.01.1110
ProductVersion : 5.01.1110
ProductName : Microsoft Message Queue
CompanyName : Microsoft Corporation
FileDescription : Windows NT MSMQ Trigger Service
LegalCopyright : Copyright (C) Microsoft Corporation. 1981-2000
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation. Windows NT(TM) is a trademark of Microsoft Corporation
OriginalFilename : QMTGSVC.EXE
Scanning Module:C:\WINDOWS\system32\mqtgsvc.exe...
Scanning Module:C:\WINDOWS\system32\mqrt.dll...
Scanning Module:C:\WINDOWS\system32\MQTRIG.DLL...
#:39 [imapi.exe]
ModuleName : C:\WINDOWS\system32\imapi.exe
Command Line : C:\WINDOWS\system32\imapi.exe
ProcessID : 3532
ThreadCreationTime : 14-06-2008 6:32:41 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-2105)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Image Mastering API
InternalName : imapi
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : imapi.exe
Scanning Module:C:\WINDOWS\system32\imapi.exe...
#:40 [alg.exe]
ModuleName : C:\WINDOWS\System32\alg.exe
Command Line : C:\WINDOWS\System32\alg.exe
ProcessID : 3864
ThreadCreationTime : 14-06-2008 6:32:41 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-0852)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe
Scanning Module:C:\WINDOWS\System32\alg.exe...
#:41 [svchost.exe]
ModuleName : C:\WINDOWS\System32\svchost.exe
Command Line : C:\WINDOWS\System32\svchost.exe -k HTTPFilter
ProcessID : 3840
ThreadCreationTime : 14-06-2008 6:32:51 AM
BasePriority : Normal
FileVersion : 5.1.2600.5512 (xpsp.080413-2111)
ProductVersion : 5.1.2600.5512
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
Scanning Module:c:\windows\system32\w3ssl.dll...
Scanning Module:C:\WINDOWS\System32\strmfilt.dll...
#:42 [cidaemon.exe]
ModuleName : C:\WINDOWS\system32\cidaemon.exe
Command Line : "cidaemon.exe" DownLevelDaemon "c:\system volume information\catalog.wci" 196672l 1528l
ProcessID : 2752
ThreadCreationTime : 14-06-2008 6:40:05 AM
BasePriority : Idle
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Indexing Service filter daemon
InternalName : cidaemon.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : cidaemon.exe
Scanning Module:C:\WINDOWS\system32\cidaemon.exe...
#:43 [firefox.exe]
ModuleName : C:\Program Files\Mozilla Firefox\firefox.exe
Command Line : "C:\Program Files\Mozilla Firefox\firefox.exe"
ProcessID : 780
ThreadCreationTime : 14-06-2008 11:29:09 AM
BasePriority : Normal
Scanning Module:C:\Program Files\Mozilla Firefox\firefox.exe...
Scanning Module:C:\Program Files\Mozilla Firefox\js3250.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\nspr4.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\xpcom_core.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\plc4.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\plds4.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\smime3.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\nss3.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\softokn3.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\ssl3.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\xpcom_compat.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\components\myspell.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\components\jar50.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org\components\FULLSOFT.DLL...
Scanning Module:C:\WINDOWS\system32\msimtf.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\freebl3.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\nssckbi.dll...
Scanning Module:C:\Documents and Settings\bent\Application Data\Mozilla\Firefox\Profiles\fjiorepz.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayAccessService.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\xpcom.dll...
Scanning Module:C:\Program Files\Mozilla Firefox\components\spellchk.dll...
#:44 [ad-aware.exe]
ModuleName : C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe
Command Line : "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe"
ProcessID : 2800
ThreadCreationTime : 14-06-2008 11:30:38 AM
BasePriority : Normal
FileVersion : 6.2.0.238
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Scanning Module:C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe...
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Win32.Trojandownloader.Zlob Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-725345543-1454471165-682003330-1003\software\microsoft\internet explorer\toolbar\Webbrowser
Value : {51d81dd5-55b7-497f-95db-d356429bb54e}
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Deep scanning and examining files...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Disk Scan Result for C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Disk Scan Result for C:\DOCUME~1\bent\LOCALS~1\Temp\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
8750 entries scanned.
New critical objects:0
Objects found so far: 1
MRU List Object Recognized!
Location: : C:\Documents and Settings\bent\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 2
9:32:22 PM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:01:25.140
Objects scanned:151835
Objects identified:1
Objects ignored:0
New critical objects:1
Reanalyzing scan result
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
No objects have been removed from the result list.