El Ad-Aware SE Build 1.05 esto:
Logfile Created on:Martes, 19 de Abril de 2005 12:10:46 a.m.
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R39 15.04.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Alexa(TAC index:5):1 total references
Other(TAC index:5):2 total references
Possible Browser Hijack attempt(TAC index:3):2 total references
ShowBehind(TAC index:5):1 total references
Tracking Cookie(TAC index:3):14 total references
WebHancer(TAC index:9):4 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
19/04/05 12:10:46 a.m. - Scan started. (Full System Scan)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [KERNEL32.DLL]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4279186427
Threads : 4
Priority : High
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
ProductName : Sistema operativo Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Componente del núcleo del kernel Win32
InternalName : KERNEL32
LegalCopyright : Copyright © Microsoft Corp. 1991-1999
OriginalFilename : KERNEL32.DLL
#:2 [MSGSRV32.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294960995
Threads : 1
Priority : Normal
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
ProductName : Sistema operativo Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Servidor de mensajes VxD de 32 bits de Windows
InternalName : MSGSRV32
LegalCopyright : Copyright © Microsoft Corp. 1992-1998
OriginalFilename : MSGSRV32.EXE
#:3 [SPOOL32.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294963067
Threads : 2
Priority : Normal
FileVersion : 4.10.1998
ProductVersion : 4.10.1998
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler Sub System Process
InternalName : spool32
LegalCopyright : Copyright © Microsoft Corp. 1994 - 1998
OriginalFilename : spool32.exe
#:4 [MPREXE.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294952931
Threads : 1
Priority : Normal
FileVersion : 4.10.1998
ProductVersion : 4.10.1998
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : WIN32 Network Interface Service Process
InternalName : MPREXE
LegalCopyright : Copyright © Microsoft Corp. 1993-1998
OriginalFilename : MPREXE.EXE
#:5 [MSTASK.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294865895
Threads : 3
Priority : Normal
FileVersion : 4.71.1972.1
ProductVersion : 4.71.1972.1
ProductName : Programador de tareas de Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Motor de Programador de tareas
InternalName : TaskScheduler
LegalCopyright : Copyright © Microsoft Corp. 2000
OriginalFilename : mstask.exe
#:6 [SYMTRAY.EXE]
FilePath : C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\SYMANTEC SHARED\
ProcessID : 4294868295
Threads : 1
Priority : Normal
FileVersion : 2004.7.81
ProductVersion : 2004.7.81
ProductName : Norton SystemWorks
CompanyName : Symantec Corporation
FileDescription : Norton SystemWorks SymTray
InternalName : SymTray.exe
LegalCopyright : Copyright © 1997-2003 Symantec Corporation
OriginalFilename : SymTray.exe
#:7 [CCSETMGR.EXE]
FilePath : C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\SYMANTEC SHARED\
ProcessID : 4294859991
Threads : 5
Priority : Normal
FileVersion : 2.1.6.3
ProductVersion : 2.1.6.3
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client Settings Manager Service
InternalName : ccSetMgr
LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved.
OriginalFilename : ccSetMgr.exe
#:8 [CCEVTMGR.EXE]
FilePath : C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\SYMANTEC SHARED\
ProcessID : 4294850123
Threads : 21
Priority : Normal
FileVersion : 2.1.6.3
ProductVersion : 2.1.6.3
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client Event Manager Service
InternalName : ccEvtMgr
LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved.
OriginalFilename : ccEvtMgr.exe
#:9 [mmtask.tsk]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294835695
Threads : 1
Priority : Normal
FileVersion : 4.03.1998
ProductVersion : 4.03.1998
ProductName : Microsoft Windows
CompanyName : Microsoft Corporation
FileDescription : Multimedia background task support module
InternalName : mmtask.tsk
LegalCopyright : Copyright © Microsoft Corp. 1991-1998
OriginalFilename : mmtask.tsk
#:10 [EXPLORER.EXE]
FilePath : C:\WINDOWS\
ProcessID : 4294812579
Threads : 4
Priority : Normal
FileVersion : 4.72.3110.1
ProductVersion : 4.72.3110.1
ProductName : Sistema operativo Microsoft® Windows NT®
CompanyName : Microsoft Corporation
FileDescription : Explorador de Windows
InternalName : explorer
LegalCopyright : © Microsoft Corporation 1981-1997
OriginalFilename : EXPLORER.EXE
#:11 [ptsnoop.exe]
FilePath : C:\WINDOWS\
ProcessID : 4294884611
Threads : 1
Priority : Normal
#:12 [SYSTRAY.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294884363
Threads : 2
Priority : Normal
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
ProductName : Sistema operativo Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Subprograma Bandeja de sistema
InternalName : SYSTRAY
LegalCopyright : Copyright © Microsoft Corp. 1993-1998
OriginalFilename : SYSTRAY.EXE
#:13 [CCAPP.EXE]
FilePath : C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\SYMANTEC SHARED\
ProcessID : 4294807111
Threads : 27
Priority : Normal
FileVersion : 2.1.6.3
ProductVersion : 2.1.6.3
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client User Session
InternalName : ccApp
LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved.
OriginalFilename : ccApp.exe
#:14 [KODAKCCS.EXE]
FilePath : C:\WINDOWS\SYSTEM32\DRIVERS\
ProcessID : 4294731843
Threads : 2
Priority : Normal
FileVersion : 1.1.5100.4
ProductVersion : 4.4.0.0
ProductName : Kodak DC File System Driver (Win32)
CompanyName : Eastman Kodak Company
FileDescription : Kodak DC Ring 3 Conduit (Win32)
InternalName : KodakCCS.exe
LegalCopyright : Copyright © Eastman Kodak Co. 2000-2004
OriginalFilename : DcFsSvc.exe
#:15 [QTTASK.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294732731
Threads : 5
Priority : Normal
FileVersion : 6.4
ProductVersion : QuickTime 6.4
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2003
OriginalFilename : QTTask.exe
#:16 [STIMON.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294718083
Threads : 3
Priority : Normal
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
ProductName : Sistema operativo Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Monitor de dispositivos de imagen estática
InternalName : STIMON
LegalCopyright : Copyright © Microsoft Corp. 1996-1998
OriginalFilename : STIMON.EXE
#:17 [WINCINEMAMGR.EXE]
FilePath : C:\ARCHIVOS DE PROGRAMA\INTERVIDEO\COMMON\BIN\
ProcessID : 4294746891
Threads : 1
Priority : Normal
FileVersion : 1.8.0
ProductVersion : 1, 8, 0, 0
ProductName : WinCinema Manager for InterVideo WinCinema products
CompanyName : InterVideo Inc.
FileDescription : WinCinema Manager
InternalName : WinCinema Manager
LegalCopyright : Copyright 1999-2003 InterVideo, Inc. All rights reserved.
OriginalFilename : WinCinemaMgr.EXE
#:18 [EASYSHARE.EXE]
FilePath : C:\ARCHIVOS DE PROGRAMA\KODAK\KODAK EASYSHARE SOFTWARE\BIN\
ProcessID : 4294738339
Threads : 4
Priority : Normal
FileVersion : 5, 0, 4, 128
ProductVersion : 4, 0, 2, 134
ProductName : Kodak EasyShare software
CompanyName : Eastman Kodak Company
FileDescription : Kodak EasyShare software
InternalName : EasyShare
LegalCopyright : Copyright © Eastman Kodak Company 2002
LegalTrademarks : EasyShare
OriginalFilename : EasyShare.exe
#:19 [KODAK SOFTWARE UPDATER.EXE]
FilePath : C:\ARCHIVOS DE PROGRAMA\KODAK\KODAK SOFTWARE UPDATER\7288971\PROGRAM\
ProcessID : 4278437899
Threads : 6
Priority : Normal
#:20 [DDHELP.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4278445159
Threads : 5
Priority : Realtime
FileVersion : 4.08.01.0881
ProductVersion : 4.08.01.0881
ProductName : Microsoft® DirectX for Windows® 95 and 98
CompanyName : Microsoft Corporation
FileDescription : Microsoft DirectX Helper
InternalName : DDHelp.exe
LegalCopyright : Copyright © Microsoft Corp. 1994-2001
OriginalFilename : DDHelp.exe
#:21 [WMIEXE.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4278344295
Threads : 3
Priority : Normal
FileVersion : 5.00.1755.1
ProductVersion : 5.00.1755.1
ProductName : Microsoft® Windows NT® Operating System
CompanyName : Microsoft Corporation
FileDescription : WMI service exe housing
InternalName : wmiexe
LegalCopyright : Copyright © Microsoft Corp. 1981-1998
OriginalFilename : wmiexe.exe
#:22 [TAPISRV.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4278528139
Threads : 8
Priority : Normal
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
ProductName : Sistema operativo Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Servidor de telefonía de Microsoft® Windows
InternalName : Servicio de telefonía
LegalCopyright : Copyright © Microsoft Corp. 1994-1998
OriginalFilename : TAPISRV.EXE
#:23 [RNAAPP.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4278582371
Threads : 3
Priority : Normal
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
ProductName : Sistema operativo Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Aplicación Acceso telefónico a redes
InternalName : RNAAPP
LegalCopyright : Copyright © Microsoft Corp. 1992-1996
OriginalFilename : RNAAPP.EXE
#:24 [PSTORES.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4278797163
Threads : 3
Priority : Normal
FileVersion : 5.00.1877.3
ProductVersion : 5.00.1877.3
ProductName : Microsoft® Windows NT® Operating System
CompanyName : Microsoft Corporation
FileDescription : Protected storage server
InternalName : Protected storage server
LegalCopyright : Copyright © Microsoft Corp. 1981-1998
OriginalFilename : Protected storage server
#:25 [AD-AWARE.EXE]
FilePath : C:\ARCHIVOS DE PROGRAMA\LAVASOFT\AD-AWARE SE PERSONAL\
ProcessID : 4278496727
Threads : 2
Priority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
#:26 [HH.EXE]
FilePath : C:\WINDOWS\
ProcessID : 4278499755
Threads : 4
Priority : Normal
FileVersion : 5.2.3644.0
ProductVersion : 5.2.3644.0
ProductName : HTML Help
CompanyName : Microsoft Corporation
FileDescription : Microsoft® HTML Help Executable
InternalName : HH 1.4
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : HH.exe
#:27 [WAOL.EXE]
FilePath : C:\ARCHIVOS DE PROGRAMA\AMERICA ONLINE 7.0\
ProcessID : 4278858379
Threads : 8
Priority : Normal
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Other Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : zapspot.zml.1
Other Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : zapspot.zml.1
Value :
Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment : "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
Rootkey : HKEY_USERS
Object : .DEFAULT\software\microsoft\internet explorer\extensions\cmdmapping
Value : {c95fe080-8f5d-11d2-a20b-00aa003c157a}
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 3
Objects found so far: 3
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 3
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@targetnet[2].txt
Category : Data Miner
Comment : Hits:2
Value : Cookie:anyuser@targetnet.com/
Expires : 18/05/33 12:33:20 a.m.
LastSync : Hits:2
UseCount : 0
Hits : 2
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@servedby.advertising[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:anyuser@servedby.advertising.com/
Expires : 18/05/05 11:37:36 p.m.
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@tribalfusion[1].txt
Category : Data Miner
Comment : Hits:2
Value : Cookie:anyuser@tribalfusion.com/
Expires : 31/12/37 09:00:00 p.m.
LastSync : Hits:2
UseCount : 0
Hits : 2
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@advertising[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:anyuser@advertising.com/
Expires : 17/04/10 11:37:36 p.m.
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@atdmt[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:anyuser@atdmt.com/
Expires : 17/04/10 09:00:00 p.m.
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@fastclick[1].txt
Category : Data Miner
Comment : Hits:8
Value : Cookie:anyuser@fastclick.net/
Expires : 08/04/07 09:27:08 p.m.
LastSync : Hits:8
UseCount : 0
Hits : 8
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@zedo[1].txt
Category : Data Miner
Comment : Hits:35
Value : Cookie:anyuser@zedo.com/
Expires : 16/04/15 09:19:54 p.m.
LastSync : Hits:35
UseCount : 0
Hits : 35
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 7
Objects found so far: 10
Deep scanning and examining files (c:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@zedo[1].txt
Category : Data Miner
Comment :
Value : c:\WINDOWS\Cookies\anyuser@zedo[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@tribalfusion[1].txt
Category : Data Miner
Comment :
Value : c:\WINDOWS\Cookies\anyuser@tribalfusion[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@atdmt[1].txt
Category : Data Miner
Comment :
Value : c:\WINDOWS\Cookies\anyuser@atdmt[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@servedby.advertising[1].txt
Category : Data Miner
Comment :
Value : c:\WINDOWS\Cookies\anyuser@servedby.advertising[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@advertising[1].txt
Category : Data Miner
Comment :
Value : c:\WINDOWS\Cookies\anyuser@advertising[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@fastclick[1].txt
Category : Data Miner
Comment :
Value : c:\WINDOWS\Cookies\anyuser@fastclick[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@targetnet[2].txt
Category : Data Miner
Comment :
Value : c:\WINDOWS\Cookies\anyuser@targetnet[2].txt
WebHancer Object Recognized!
Type : File
Data : DC57.DLL
Category : Data Miner
Comment :
Object : c:\RECYCLED\
FileVersion : 1.6
ProductVersion : 1.6
ProductName : webHancer Customer Companion
CompanyName : webHancer Corporation
FileDescription : webHancer IE Performance Collector
InternalName : WhIePerfCollector
LegalCopyright : Copyright © 1999-2000 webHancer Corporation
OriginalFilename : whiedc.dll
WebHancer Object Recognized!
Type : File
Data : WBHSHARE.DLL
Category : Data Miner
Comment :
Object : c:\Master 2003\Programas rescatados\webHancer\Programs\
FileVersion : 2.9.0
ProductVersion : 2.9.0
ProductName : webHancer Customer Companion
CompanyName : webHancer Corporation
FileDescription : webHancer Winsock2 Shared Memory Module
InternalName : wbhshare
LegalCopyright : Copyright © 1999-2002 webHancer Corporation
OriginalFilename : whwsshm.dll
WebHancer Object Recognized!
Type : File
Data : WHIEHLPR.DLL
Category : Data Miner
Comment :
Object : c:\Master 2003\Programas rescatados\webHancer\Programs\
FileVersion : 2.9.0
ProductVersion : 2.9.0
ProductName : webHancer Customer Companion
CompanyName : webHancer Corporation
FileDescription : webHancer IE Helper Module
InternalName : WhIeHelper
LegalCopyright : Copyright © 1999-2002 webHancer Corporation
OriginalFilename : whiehlpr.dll
WebHancer Object Recognized!
Type : File
Data : WHIESHM.DLL
Category : Data Miner
Comment :
Object : c:\Master 2003\Programas rescatados\webHancer\Programs\
FileVersion : 2.9.0
ProductVersion : 2.9.0
ProductName : webHancer Customer Companion
CompanyName : webHancer Corporation
FileDescription : webHancer IE Shared Memory Module
InternalName : WhIeShmem
LegalCopyright : Copyright © 1999-2002 webHancer Corporation
OriginalFilename : whieshm.dll
ShowBehind Object Recognized!
Type : File
Data : thank.exe
Category : Data Miner
Comment :
Object : c:\spm2\
Disk Scan Result for c:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 22
Possible Browser Hijack attempt Object Recognized!
Type : File
Data : News.url
Category : Misc
Comment : Problematic URL discovered:
http://www.sfux.com/go/news Object : C:\WINDOWS\Favoritos\
Possible Browser Hijack attempt Object Recognized!
Type : File
Data : Games.url
Category : Misc
Comment : Problematic URL discovered:
http://www.sfux.com/go/games Object : C:\WINDOWS\Favoritos\
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 24
12:35:40 a.m. Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:24:54.420
Objects scanned:93273
Objects identified:24
Objects ignored:0
New critical objects:24