Ran Ad-aware 6 . Here is the log file. Lavasoft Ad-aware Personal Build 6.181 Logfile created on :Thursday, 13 May 2004 10:36:08 PM Created with Ad-aware Personal, free for private use. Using reference-file :01R303 08.05.2004 ______________________________________________________ Reffile status: ========================= Reference file loaded: Reference Number : 01R303 08.05.2004 Internal build : 235 File location : C:\Utility\Ad-aware 6\reflist.ref Total size : 1096786 Bytes Signature data size : 1078166 Bytes Reference data size : 18556 Bytes Signatures total : 24182 Target categories : 10 Target families : 463 Memory + processor status: ========================== Number of processors : 1 Processor architecture : Non Intel Memory available:71 % Total physical memory:1048048 kb Available physical memory:743344 kb Total page file size:2521612 kb Available on page file:2337776 kb Total virtual memory:2097024 kb Available virtual memory:2056712 kb OS: Ad-aware Settings ========================= Set : Activate in-depth scan (Recommended) Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep scan registry Set : Scan my IE Favorites for banned URLs Set : Scan within archives Set : Scan my Hosts file Extended Ad-aware Settings ========================= Set : Unload recognized processes during scanning Set : Include basic Ad-aware settings in logfile Set : Include additional Ad-aware settings in logfile Set : Let windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Always back up reference file, before updating Set : Play sound if scan produced a result 13-05-2004 10:36:08 PM - Scan started. (Custom mode) Listing running processes ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ #:1 [smss.exe] FilePath : \SystemRoot\System32\ ThreadCreationTime : 13-05-2004 11:01:52 AM BasePriority : Normal #:2 [winlogon.exe] FilePath : \??\C:\WINDOWS\system32\ ThreadCreationTime : 13-05-2004 11:01:55 AM BasePriority : High #:3 [services.exe] FilePath : C:\WINDOWS\system32\ ThreadCreationTime : 13-05-2004 11:01:55 AM BasePriority : Normal FileSize : 99 KB FileVersion : 5.1.2600.0 (xpclient.010817-1148) ProductVersion : 5.1.2600.0 CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe OriginalFilename : services.exe ProductName : Microsoft Created on : 31/03/2003 12:00:00 PM Last accessed : 13/05/2004 12:36:08 PM Last modified : 31/03/2003 12:00:00 PM #:4 [lsass.exe] FilePath : C:\WINDOWS\system32\ ThreadCreationTime : 13-05-2004 11:01:55 AM BasePriority : Normal FileSize : 11 KB FileVersion : 5.1.2600.1106 (xpsp1.020828-1920) ProductVersion : 5.1.2600.1106 CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe OriginalFilename : lsass.exe ProductName : Microsoft Created on : 31/03/2003 12:00:00 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 31/03/2003 12:00:00 PM #:5 [svchost.exe] FilePath : C:\WINDOWS\system32\ ThreadCreationTime : 13-05-2004 11:01:55 AM BasePriority : Normal FileSize : 12 KB FileVersion : 5.1.2600.0 (xpclient.010817-1148) ProductVersion : 5.1.2600.0 CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe OriginalFilename : svchost.exe ProductName : Microsoft Created on : 31/03/2003 12:00:00 PM Last accessed : 13/05/2004 12:33:57 PM Last modified : 31/03/2003 12:00:00 PM #:6 [svchost.exe] FilePath : C:\WINDOWS\System32\ ThreadCreationTime : 13-05-2004 11:01:55 AM BasePriority : Normal FileSize : 12 KB FileVersion : 5.1.2600.0 (xpclient.010817-1148) ProductVersion : 5.1.2600.0 CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe OriginalFilename : svchost.exe ProductName : Microsoft Created on : 31/03/2003 12:00:00 PM Last accessed : 13/05/2004 12:33:57 PM Last modified : 31/03/2003 12:00:00 PM #:7 [explorer.exe] FilePath : C:\WINDOWS\ ThreadCreationTime : 13-05-2004 11:01:57 AM BasePriority : Normal FileSize : 980 KB FileVersion : 6.00.2800.1106 (xpsp1.020828-1920) ProductVersion : 6.00.2800.1106 CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer OriginalFilename : EXPLORER.EXE ProductName : Microsoft Created on : 31/03/2003 12:00:00 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 31/03/2003 12:00:00 PM #:8 [spoolsv.exe] FilePath : C:\WINDOWS\system32\ ThreadCreationTime : 13-05-2004 11:01:58 AM BasePriority : Normal FileSize : 50 KB FileVersion : 5.1.2600.0 (XPClient.010817-1148) ProductVersion : 5.1.2600.0 CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe OriginalFilename : spoolsv.exe ProductName : Microsoft Created on : 31/03/2003 12:00:00 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 31/03/2003 12:00:00 PM #:9 [ccsetmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ThreadCreationTime : 13-05-2004 11:01:58 AM BasePriority : Normal FileSize : 229 KB FileVersion : 2.1.0.610 ProductVersion : 2.1.0.610 Copyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. CompanyName : Symantec Corporation FileDescription : Common Client Settings Manager Service InternalName : ccSetMgr OriginalFilename : ccSetMgr.exe ProductName : Common Client Created on : 26/03/2004 11:12:34 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 10/11/2003 2:30:12 AM #:10 [ctsvccda.exe] FilePath : C:\WINDOWS\System32\ ThreadCreationTime : 13-05-2004 11:01:58 AM BasePriority : Normal FileSize : 43 KB FileVersion : 1.0.1.0 ProductVersion : 1.0.0.0 Copyright : Copyright © Creative Technology Ltd., 1999. All rights reserved. CompanyName : Creative Technology Ltd FileDescription : Creative Service for CDROM Access InternalName : CTsvcCDAEXE OriginalFilename : CTsvcCDA.EXE ProductName : Creative Service for CDROM Access Created on : 26/03/2004 10:09:13 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 12/12/1999 2:01:00 PM #:11 [mdm.exe] FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\ ThreadCreationTime : 13-05-2004 11:01:58 AM BasePriority : Normal FileSize : 314 KB FileVersion : 7.00.9466 ProductVersion : 7.00.9466 CompanyName : Microsoft Corporation FileDescription : Machine Debug Manager InternalName : mdm.exe OriginalFilename : mdm.exe ProductName : Microsoft Created on : 19/06/2003 12:25:00 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 19/06/2003 12:25:00 PM #:12 [navapsvc.exe] FilePath : C:\Program Files\Norton SystemWorks\Norton Antivirus\ ThreadCreationTime : 13-05-2004 11:01:58 AM BasePriority : Normal FileSize : 154 KB FileVersion : 10.00.13 ProductVersion : 10.00.13 Copyright : Norton AntiVirus 2004 for Windows 98/ME/2000/XP Copyright © 2003 Symantec Corporation. All rights reserved. CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Auto-Protect Service InternalName : NAVAPSVC OriginalFilename : NAVAPSVC.EXE ProductName : Norton AntiVirus Created on : 26/03/2004 11:00:21 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 4/12/2003 7:22:28 AM #:13 [nprotect.exe] FilePath : C:\PROGRA~1\NORTON~1\NORTON~2\ ThreadCreationTime : 13-05-2004 11:01:58 AM BasePriority : Normal FileSize : 80 KB FileVersion : 17.0.0.82 ProductVersion : 17.0.0.82 Copyright : Copyright © 1997-2003 Symantec Corporation CompanyName : Symantec Corporation FileDescription : Norton Protection Status InternalName : NPROTECT OriginalFilename : NPROTECT.EXE ProductName : Norton Utilities Created on : 9/09/2003 6:26:58 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 9/09/2003 6:26:58 PM #:14 [nopdb.exe] FilePath : C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\ ThreadCreationTime : 13-05-2004 11:01:58 AM BasePriority : Normal FileSize : 172 KB FileVersion : 7.00.0.24 ProductVersion : 7.00.0.24 Copyright : Copyright © 1997-2003 Symantec Corporation CompanyName : Symantec Corporation FileDescription : NOPDB InternalName : NOPDB OriginalFilename : NOPDB.dll ProductName : Norton Speed Disk Created on : 9/09/2003 5:59:32 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 9/09/2003 5:59:32 PM #:15 [symlcsvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\ ThreadCreationTime : 13-05-2004 11:01:58 AM BasePriority : Normal FileSize : 572 KB FileVersion : 1, 8, 48, 79 ProductVersion : 1, 8, 48, 79 Copyright : Copyright © 2003 CompanyName : Symantec Corporation FileDescription : Symantec Core Component InternalName : symlcsvc OriginalFilename : symlcsvc.exe ProductName : Symantec Core Component Created on : 26/03/2004 9:04:28 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 26/03/2004 9:04:27 PM #:16 [ccevtmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ThreadCreationTime : 13-05-2004 11:01:58 AM BasePriority : Normal FileSize : 249 KB FileVersion : 2.1.0.610 ProductVersion : 2.1.0.610 Copyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. CompanyName : Symantec Corporation FileDescription : Common Client Event Manager Service InternalName : ccEvtMgr OriginalFilename : ccEvtMgr.exe ProductName : Common Client Created on : 26/03/2004 11:12:34 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 10/11/2003 2:30:04 AM #:17 [ctnotify.exe] FilePath : C:\Program Files\Creative\ShareDLL\ ThreadCreationTime : 13-05-2004 11:02:00 AM BasePriority : Normal FileSize : 185 KB FileVersion : 1.55.0.0 ProductVersion : 1.55 Copyright : Copyright © 1999 Creative Technology Ltd. CompanyName : Creative Technology Ltd. FileDescription : Disc Detector InternalName : CtNotify OriginalFilename : CtNotify.exe ProductName : Creative Disc Detector Created on : 26/03/2004 10:09:14 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 29/08/1999 2:55:00 PM #:18 [mediadet.exe] FilePath : C:\Program Files\Creative\ShareDLL\ ThreadCreationTime : 13-05-2004 11:02:00 AM BasePriority : Normal FileSize : 161 KB FileVersion : 1.55.2.0 ProductVersion : 1.55 Copyright : Copyright © 1998 Creative Technology Ltd. CompanyName : Creative Technology Ltd. FileDescription : Disc Detector InternalName : MediaDet OriginalFilename : MediaDet.exe ProductName : Creative Disc Detector Created on : 26/03/2004 10:09:14 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 26/03/2000 2:55:00 PM #:19 [ccapp.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ThreadCreationTime : 13-05-2004 11:02:04 AM BasePriority : Normal FileSize : 69 KB FileVersion : 2.1.0.610 ProductVersion : 2.1.0.610 Copyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. CompanyName : Symantec Corporation FileDescription : Common Client User Session InternalName : ccApp OriginalFilename : ccApp.exe ProductName : Common Client Created on : 26/03/2004 11:12:33 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 10/11/2003 2:30:02 AM #:20 [ctfmon.exe] FilePath : C:\WINDOWS\System32\ ThreadCreationTime : 13-05-2004 11:02:08 AM BasePriority : Normal FileSize : 13 KB FileVersion : 5.1.2600.1106 (xpsp1.020828-1920) ProductVersion : 5.1.2600.1106 CompanyName : Microsoft Corporation FileDescription : CTF Loader InternalName : CTFMON OriginalFilename : CTFMON.EXE ProductName : Microsoft Created on : 31/03/2003 12:00:00 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 31/03/2003 12:00:00 PM #:21 [savscan.exe] FilePath : C:\Program Files\Norton SystemWorks\Norton Antivirus\ ThreadCreationTime : 13-05-2004 11:02:10 AM BasePriority : Normal FileSize : 189 KB FileVersion : 9.2.1.14 ProductVersion : 9.2 Copyright : Copyright © 2003 Symantec Corporation CompanyName : Symantec Corporation FileDescription : Symantec AntiVirus Scanner InternalName : SAVSCAN OriginalFilename : SAVSCAN.EXE ProductName : Symantec AntiVirus AutoProtect Created on : 26/03/2004 11:00:22 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 4/12/2003 7:22:30 AM #:22 [csinsmnt.exe] FilePath : C:\Program Files\Norton SystemWorks\Norton CleanSweep\ ThreadCreationTime : 13-05-2004 11:02:15 AM BasePriority : Normal FileSize : 212 KB FileVersion : 8.0.00.79 ProductVersion : 8.0 Copyright : Copyright © 1992-2002 Symantec Corporation CompanyName : Symantec Corporation FileDescription : Norton CleanSweep Install Monitor InternalName : CSINSM OriginalFilename : CSINSM*.EXE ProductName : Norton CleanSweep Created on : 7/09/2003 7:17:32 AM Last accessed : 13/05/2004 12:36:09 PM Last modified : 7/09/2003 7:17:32 AM #:23 [kpalive.exe] FilePath : C:\Utility\Keep It Alive\ ThreadCreationTime : 13-05-2004 11:02:17 AM BasePriority : Normal FileSize : 416 KB Created on : 24/04/2004 1:30:31 PM Last accessed : 13/05/2004 12:34:50 PM Last modified : 1/01/2001 9:00:20 PM #:24 [ntvdm.exe] FilePath : C:\WINDOWS\system32\ ThreadCreationTime : 13-05-2004 11:02:18 AM BasePriority : Normal FileSize : 386 KB FileVersion : 5.1.2600.1106 (xpsp1.020828-1920) ProductVersion : 5.1.2600.1106 CompanyName : Microsoft Corporation FileDescription : NTVDM.EXE InternalName : NTVDM.EXE OriginalFilename : NTVDM.EXE ProductName : Microsoft Created on : 31/03/2003 12:00:00 PM Last accessed : 13/05/2004 12:36:09 PM Last modified : 31/03/2003 12:00:00 PM #:25 [iexplore.exe] FilePath : C:\Program Files\Internet Explorer\ ThreadCreationTime : 13-05-2004 12:34:05 PM BasePriority : Normal FileSize : 89 KB FileVersion : 6.00.2800.1106 (xpsp1.020828-1920) ProductVersion : 6.00.2800.1106 CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore OriginalFilename : IEXPLORE.EXE ProductName : Microsoft Created on : 26/03/2004 8:16:08 PM Last accessed : 13/05/2004 12:34:06 PM Last modified : 31/03/2003 12:00:00 PM #:26 [ad-aware.exe] FilePath : C:\Utility\Ad-aware 6\ ThreadCreationTime : 13-05-2004 12:35:59 PM BasePriority : Normal FileSize : 668 KB FileVersion : 6.0.1.181 ProductVersion : 6.0.0.0 Copyright : Copyright CompanyName : Lavasoft Sweden FileDescription : Ad-aware 6 core application InternalName : Ad-aware.exe OriginalFilename : Ad-aware.exe ProductName : Lavasoft Ad-aware Plus Created on : 30/04/2004 12:17:15 PM Last accessed : 13/05/2004 12:35:59 PM Last modified : 12/07/2003 11:00:20 AM Memory scan result : ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ New objects : 0 Objects found so far: 0 Started registry scan ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ Registry scan result : ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ New objects : 0 Objects found so far: 0 Started deep registry scan ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ Deep registry scan result : ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ New objects : 0 Objects found so far: 0 Deep scanning and examining files (C:) ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ Disk scan result for C:\Documents and Settings\Meng\Local Settings\Temporary Internet Files\Content.IE5\ ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ New objects : 0 Objects found so far: 0 Deep scanning and examining files (F:) ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ Disk scan result for F:\ ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ New objects : 0 Objects found so far: 0 Deep scanning and examining files (G:) ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ Disk scan result for G:\ ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ New objects : 0 Objects found so far: 0 Scanning Hosts file(C:\WINDOWS\System32\drivers\etc\hosts) ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ Hosts file scan result: ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ 1 entries scanned. New objects :0 Objects found so far: 0 10:38:47 PM Scan complete Summary of this scan ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ Total scanning time :00:02:38:985 Objects scanned :68077 Objects identified :0 Objects ignored :0 New objects :0