Ad-Aware SE Build 1.06r1
Logfile Created on:08 January 2006 13:58:04
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R85 04.01.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):34 total references
Tracking Cookie(TAC index:3):2 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
08-01-2006 13:58:04 - Scan started. (Full System Scan)
MRU List Object Recognized!
Location: : C:\Documents and Settings\D.T-4SAGYGA8ENF5V\recent
Description : list of recently opened documents
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\adobe\acrobat reader\6.0\avgeneral\crecentfiles
Description : list of recently used files in adobe reader
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\clipart gallery\2.0\mrudescription
Description : most recently used description in microsoft clipart gallery
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\direct3d\mostrecentapplica tion
Description : most recent application to use microsoft direct3d
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\direct3d\mostrecentapplica tion
Description : most recent application to use microsoft direct X
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplicatio n
Description : most recent application to use microsoft directdraw
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\directinput\mostrecentappl ication
Description : most recent application to use microsoft directinput
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\directinput\mostrecentappl ication
Description : most recent application to use microsoft directinput
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\internet explorer\main
Description : last save directory used in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\mediaplayer\medialibraryui
Description : last selected node in the microsoft windows media player media library
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\mediaplayer\player\recentf ilelist
Description : list of recently used files in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\mediaplayer\player\setting s
Description : last save as directory used in jasc paint shop pro
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\mediaplayer\player\setting s
Description : last open directory used in jasc paint shop pro
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\mediaplayer\preferences
Description : last cd record path used in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\mediaplayer\preferences
Description : last playlist index loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\mediaplayer\preferences
Description : last search path used in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\microsoft management console\recent file list
Description : list of recent snap-ins used in the microsoft management console
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\office\8.0\common\open find\microsoft word\settings\open\file name mru
Description : list of recent documents opened by microsoft word
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\office\8.0\common\open find\microsoft word\settings\save as\file name mru
Description : list of recent documents saved by microsoft word
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\office\8.0\excel\recent file list
Description : list of recent files used by microsoft excel
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\office\8.0\powerpoint\rece nt file list
Description : list of recent files used by microsoft powerpoint
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\search assistant\acmru
Description : list of recent search terms used with the search assistant
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\windows\currentversion\app lets\paint\recent file list
Description : list of files recently opened using microsoft paint
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\windows\currentversion\app lets\wordpad\recent file list
Description : list of recent files opened using wordpad
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\windows\currentversion\exp lorer\comdlg32\lastvisitedmru
Description : list of recent programs opened
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\windows\currentversion\exp lorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\windows\currentversion\exp lorer\recentdocs
Description : list of recent documents opened
MRU List Object Recognized!
Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
MRU List Object Recognized!
Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1482476501-725345543-1004\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 36
14:09:09 Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:11:05.203
Objects scanned:105870
Objects identified:2
Objects ignored:0
New critical objects:2
+ Created on: 15:02:02, 08/01/2006
+ Report-Checksum: CEB51CD4
+ Scan result:
C:\Documents and Settings\D.T-4SAGYGA8ENF5V\Cookies\d@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\D.T-4SAGYGA8ENF5V\Cookies\d@data2.perf.overture[2].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\dba2044.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\dba2044.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\dba2044.exe -> Dialer.Generic : Cleaned with backup
::Report End
Thanks again for the help. P.s, is she clean now! lol Cheers, Dave
don't run the tool just yet please.
Install it. The windows tab should be opened in the upper left of the program. Click analyze and then click run cleaner. Just use the windows tab that is up front by default.
1.Uncheck "Cookies" under "Internet Explorer".
2.If you are running Firefox: ,then click on the "Applications" tab and uncheck "Cookies" under "Firefox".
Now reboot into safe mode by tapping your F8 key upon restart and safe mode screen appears, select safe mode and press enter.
Neal, i owe you one for all your help. My pc seems a lot faster and i can't believe how many bugs you've helped me find
That CCleaner on its own found 140mb of junk...just doing nowt!
"Go here to learn how to show hidden files/folders:"
don't run the tool just yet please.
Install it. The windows tab should be opened in the upper left of the program. Click analyze and then click run cleaner. Just use the windows tab that is up front by default.
1.Uncheck "Cookies" under "Internet Explorer". Done that.
Now reboot into safe mode by tapping your F8 key upon restart and safe mode screen appears, select safe mode and press enter.
Hunt for and delete if found:
C:\WINDOWS\SYSTEM32\adupdmanager.xml < file Found + deleted that.
C:\WINDOWS\SYSTEM32\wppp.html < file Not found.
C:\WINDOWS\DOWNLOADED PROGRAM FILES\f3initialsetup1.0.0.15.inf < file Not found.
Now while in safe mode run CCleaner useing the windows tab only please. Found 0.45mb.
How's she looking now?
Logfile of HijackThis v1.99.1
Scan saved at 00:01:18, on 09/01/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Quick questions. While running CCleaner i noticed the 'issues' tab - so i scanned and it found loads of issues/shared files etc.Stuff like McAfee,which i don't use anymore. Can i scan + delete these files, or will it have a knock on effect on other programs ( if they're shared etc )
Also, ( sorry to be a pain ), but i now have these programs on my desktop:
AVG 7 Anti-virus
Spybot S&D
Ad-Aware SE personal
CCleaner
Ewido
+ Smitrem,Panda and CWshredder - somewhere on my pc!
My Q is, do they run automatically / in the background, like McAfee,(which alerted me to possible bugs), or do i have to run them manually,from time to time?
Many thanks again. Dave.
I would keep CCleaner and use it about once a month, windows tab only, as far as the issue tab is concerned if you remove anything with that be sure to back up the registry first. CCleaner has been known to find things it shouldn't when useing the issues tab which deals with the registry. I personally would not do it, anything in there that is old stuff is harmless clutter and doesn't take up hardly any space on your computer.
keep spybot and adaware check for updates often at least once a week and run the scans and they are scanners and removers.
I also would keep Ewido even if the trial runs out it will update and scan and remove but will not run in the back ground.
Uninstall smitrem, unless you put a shortcut on your desktop panda will not need to be removed as it is an online scanner but would scan with it once a month for safetys sake.
Remove CWShredder it does nothing but remove stuff after infection.
Are you satisfied with your computer if you are i will have some free programs for your consideration that will keep your computer a lot safer then it is now.
Never use more than one anti-virus program at a time and the same goes for firealls.
If you are no longer having any more trouble here is some preventative measures for you.
Here are some preventive measures you can take to keep your computer from getting infected again. also keep all these and Ad-awareSE and SpybotS&D updated.
To reduce the re-infection potential for malware and protect yourself against spyware, here are a few helpful suggestions:
1. Keep Windows and Internet Explorer current with the latest critical security updates from Microsoft. This will patch many of the security holes through which attackers can gain access to your computer. You CANNOT complete this update using an alternate browser. http://v5.windowsupdate.microsoft.co....aspx?ln=en-us
2. Run your antivirus software regularly, and to keep its definitions up-to-date. If you are thinking about switching, there are a some good free Antivirus programs that are decent, including AVG and Avast!. AVG:http://free.grisoft.com/doc/1
5. Consider using an alternate free browser for general web surfing but you must use IE for windows update. Mozilla Firefox: www.mozilla.org/products/firefox/
6. Consider increasing your browser security by using these programs: SpywareGuard will protect your homepage from being hijacked: http://www.javacoolsoftware.com/spywareguard.html SpywareBlaster will increase browser protection by blocking Thousands of known malware sites by adding them to IE's restricted sites zone. Download it here:
If you use SpywareBlaster, you can also use a customblocklist to add even more entries into IE restricted sites zone. Go to this site for the current list and how to use instructions: http://customblockinglist.cjb.net/
*Remember just like your primary anti-virus software, it is important to keep all of these programs up-to-date and use them on a regular basis. It's Free