Good morning everyone.
Here's the sum up: I have Shopping Wizard and Home Search Assistent (sic) in my Add/Remove Programs list, but I get errors when I try to remove them.
I have 3 bookmarks that keep coming back no matter what I do.
Ad-Aware finds CoolWWWSearch and says it successfully removes it. SpyBot S&D also finds CoolWWWSearch.Aff.Winshow and successfully removes it. Neither CWS Shredder nor Killer finds anything. After I reboot, Ad-Aware finds the exact same entries in the registry.
IE redirects to about:blank, and I get about:blank pop-ups.
Thank you all very much for your tremendous help.
Ad-Aware log and HiJackThis log follows:
Ad-Aware SE Build 1.06r1
Logfile Created on:Wednesday, June 01, 2005 11:45:06 AM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R49 31.05.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
CoolWebSearch(TAC index:10):19 total references
MRU List(TAC index:0):3 total references
Possible Browser Hijack attempt(TAC index:3):3 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
6-1-2005 11:45:06 AM - Scan started. (Custom mode)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 152
ThreadCreationTime : 6-1-2005 3:39:26 PM
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINNT\system32\
ProcessID : 176
ThreadCreationTime : 6-1-2005 3:40:46 PM
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINNT\system32\
ProcessID : 196
ThreadCreationTime : 6-1-2005 3:40:49 PM
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINNT\system32\
ProcessID : 224
ThreadCreationTime : 6-1-2005 3:40:50 PM
BasePriority : Normal
FileVersion : 5.00.2195.6700
ProductVersion : 5.00.2195.6700
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINNT\system32\
ProcessID : 236
ThreadCreationTime : 6-1-2005 3:40:50 PM
BasePriority : Normal
FileVersion : 5.00.2195.6902
ProductVersion : 5.00.2195.6902
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Executable and Server DLL (Export Version)
InternalName : lsasrv.dll and lsass.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : lsasrv.dll and lsass.exe
#:6 [ibmpmsvc.exe]
FilePath : C:\WINNT\system32\
ProcessID : 348
ThreadCreationTime : 6-1-2005 3:40:52 PM
BasePriority : Normal
#:7 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 420
ThreadCreationTime : 6-1-2005 3:40:53 PM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINNT\System32\
ProcessID : 468
ThreadCreationTime : 6-1-2005 3:40:53 PM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:9 [spoolsv.exe]
FilePath : C:\WINNT\system32\
ProcessID : 524
ThreadCreationTime : 6-1-2005 3:40:53 PM
BasePriority : Normal
FileVersion : 5.00.2195.6659
ProductVersion : 5.00.2195.6659
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolss.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : spoolss.exe
#:10 [ati2evxx.exe]
FilePath : C:\WINNT\System32\
ProcessID : 600
ThreadCreationTime : 6-1-2005 3:41:04 PM
BasePriority : Normal
#:11 [avsynmgr.exe]
FilePath : C:\Program Files\Network Associates\VirusScan\
ProcessID : 616
ThreadCreationTime : 6-1-2005 3:41:05 PM
BasePriority : Normal
#:12 [residentagent.exe]
FilePath : C:\Program Files\LANDesk\Shared Files\
ProcessID : 640
ThreadCreationTime : 6-1-2005 3:41:05 PM
BasePriority : Normal
FileVersion : 8.5.0.19
ProductVersion : 8.5.0.19
ProductName : LANDesk® Management Agent
CompanyName : LANDesk® Development, Ltd
FileDescription : Resident Agent Application
InternalName : Resident Agent
LegalCopyright : Copyright © 2003-2004, LANDesk Software, Ltd.
OriginalFilename : resident.exe
#:13 [cvpnd.exe]
FilePath : C:\Program Files\Cisco Systems\VPN Client\
ProcessID : 660
ThreadCreationTime : 6-1-2005 3:41:05 PM
BasePriority : Normal
FileVersion : 4.0.3 (Rel)
ProductVersion : 4.0.3 (Rel)
ProductName : Cisco Systems VPN Client
CompanyName : Cisco Systems, Inc.
FileDescription : Cisco Systems VPN Client
InternalName : cvpnd
LegalCopyright : Copyright © 1998-2003 Cisco Systems, Inc.
OriginalFilename : CVPND.EXE
#:14 [localsch.exe]
FilePath : C:\Program Files\LANDesk\LDClient\
ProcessID : 352
ThreadCreationTime : 6-1-2005 3:41:08 PM
BasePriority : Normal
FileVersion : 8.5.0.164
ProductVersion : 8.5.0.164
ProductName : LANDesk® Management Suite
CompanyName : LANDesk Software Ltd.
FileDescription : LocalSch
InternalName : Local Scheduler Service
LegalCopyright : Copyright© 2004 LANDesk Software Ltd.
OriginalFilename : LocalSch.exe
#:15 [pds.exe]
FilePath : C:\WINNT\system32\cba\
ProcessID : 744
ThreadCreationTime : 6-1-2005 3:41:09 PM
BasePriority : Normal
FileVersion : 6.12.0.133 E
ProductVersion : 6.12.0.133
ProductName : Intel Common Base Agent
CompanyName : Intel® Corporation
FileDescription : CBA -- Ping Discovery Service
InternalName : PDS
LegalCopyright : Copyright © 1997-2001 Intel® Corporation
LegalTrademarks : LANDesk® is a registered trademark of Intel Corporation
OriginalFilename : PDS.EXE
#:16 [qipclnt.exe]
FilePath : C:\Program Files\LANDesk\LDClient\
ProcessID : 788
ThreadCreationTime : 6-1-2005 3:41:09 PM
BasePriority : Normal
FileVersion : 8.5.0.164
ProductVersion : 8.5.0.164
ProductName : LANDesk® Management Suite
CompanyName : LANDesk Software Ltd.
FileDescription : QIP Client
InternalName : QIPClnt
LegalCopyright : Copyright© 2004 LANDesk Software Ltd.
OriginalFilename : qipclnt.exe
#:17 [tmcsvc.exe]
FilePath : C:\Program Files\LANDesk\LDClient\
ProcessID : 800
ThreadCreationTime : 6-1-2005 3:41:10 PM
BasePriority : Normal
FileVersion : 8.5.0.164
ProductVersion : 8.5.0.164
ProductName : LANDesk® Management Suite
CompanyName : LANDesk Software Ltd.
FileDescription : Targeted Multicast Client Service Executable
InternalName : sdmsvc
LegalCopyright : Copyright© 2004 LANDesk Software Ltd.
OriginalFilename : sdmsvc.exe
#:18 [issuser.exe]
FilePath : C:\PROGRA~1\LANDesk\LDClient\
ProcessID : 840
ThreadCreationTime : 6-1-2005 3:41:11 PM
BasePriority : Normal
FileVersion : 8.5.0.164
ProductVersion : 8.5.0.164
ProductName : LANDesk® Management Suite
CompanyName : LANDesk Software, Ltd.
FileDescription : Remote Control Client
LegalCopyright : Copyright© 2003 LANDesk Software, Ltd.
#:19 [frameworkservice.exe]
FilePath : C:\Program Files\Network Associates\Common Framework\
ProcessID : 808
ThreadCreationTime : 6-1-2005 3:41:11 PM
BasePriority : Normal
FileVersion : 3.1.1.184
ProductName : McAfee Common Framework
CompanyName : Network Associates, Inc.
FileDescription : Framework Service
InternalName : Framework
LegalCopyright : Copyright© 2000-2003 Networks Associates Technology, Inc. All Rights Reserved.
OriginalFilename : Framework.exe
#:20 [qconsvc.exe]
FilePath : C:\WINNT\System32\
ProcessID : 996
ThreadCreationTime : 6-1-2005 3:41:15 PM
BasePriority : Normal
#:21 [regsvc.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1012
ThreadCreationTime : 6-1-2005 3:41:16 PM
BasePriority : Normal
FileVersion : 5.00.2195.6701
ProductVersion : 5.00.2195.6701
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Remote Registry Service
InternalName : regsvc
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : REGSVC.EXE
#:22 [vsstat.exe]
FilePath : C:\Program Files\Network Associates\VirusScan\
ProcessID : 1020
ThreadCreationTime : 6-1-2005 3:41:16 PM
BasePriority : Normal
#:23 [mstask.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1036
ThreadCreationTime : 6-1-2005 3:41:16 PM
BasePriority : Normal
FileVersion : 4.71.2195.6920
ProductVersion : 4.71.2195.6920
ProductName : Microsoft® Windows® Task Scheduler
CompanyName : Microsoft Corporation
FileDescription : Task Scheduler Engine
InternalName : TaskScheduler
LegalCopyright : Copyright © Microsoft Corp. 1997
OriginalFilename : mstask.exe
#:24 [vshwin32.exe]
FilePath : C:\Program Files\Network Associates\VirusScan\
ProcessID : 1108
ThreadCreationTime : 6-1-2005 3:41:17 PM
BasePriority : Normal
#:25 [winmgmt.exe]
FilePath : C:\WINNT\System32\WBEM\
ProcessID : 1124
ThreadCreationTime : 6-1-2005 3:41:17 PM
BasePriority : Normal
FileVersion : 1.50.1085.0100
ProductVersion : 1.50.1085.0100
ProductName : Windows Management Instrumentation
CompanyName : Microsoft Corporation
FileDescription : Windows Management Instrumentation
InternalName : WINMGMT
LegalCopyright : Copyright © Microsoft Corp. 1995-1999
#:26 [mspmspsv.exe]
FilePath : C:\WINNT\System32\
ProcessID : 1140
ThreadCreationTime : 6-1-2005 3:41:18 PM
BasePriority : Normal
FileVersion : 7.10.00.3068
ProductVersion : 7.10.00.3068
ProductName : Microsoft ® DRM
CompanyName : Microsoft Corporation
FileDescription : WMDM PMSP Service
InternalName : MSPMSPSV.EXE
LegalCopyright : Copyright © Microsoft Corp. 1981-2000
OriginalFilename : MSPMSPSV.EXE
#:27 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1152
ThreadCreationTime : 6-1-2005 3:41:18 PM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:28 [softmon.exe]
FilePath : C:\Program Files\LANDesk\LDClient\
ProcessID : 1196
ThreadCreationTime : 6-1-2005 3:41:19 PM
BasePriority : Normal
FileVersion : 8.5.0.164
ProductVersion : 8.5.0.164
ProductName : LANDesk® Management Suite
CompanyName : LANDesk Software Ltd.
FileDescription : LANDesk Software Monitor
InternalName : LANDesk Software Monitor
LegalCopyright : Copyright© 2004 LANDesk Software Ltd.
OriginalFilename : softmon.exe
#:29 [explorer.exe]
FilePath : C:\WINNT\
ProcessID : 128
ThreadCreationTime : 6-1-2005 3:41:19 PM
BasePriority : Normal
FileVersion : 5.00.3700.6690
ProductVersion : 5.00.3700.6690
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : EXPLORER.EXE
#:30 [webscanx.exe]
FilePath : C:\Program Files\Network Associates\VirusScan\
ProcessID : 1276
ThreadCreationTime : 6-1-2005 3:41:22 PM
BasePriority : Normal
#:31 [naprdmgr.exe]
FilePath : C:\PROGRA~1\NETWOR~1\COMMON~1\
ProcessID : 1300
ThreadCreationTime : 6-1-2005 3:41:23 PM
BasePriority : Normal
FileVersion : 3.1.1.184
ProductName : McAfee Common Framework
CompanyName : Network Associates, Inc.
FileDescription : NAI Product Manager
InternalName : Product Manager
LegalCopyright : Copyright© 2000-2003 Networks Associates Technology, Inc. All Rights Reserved.
OriginalFilename : naPrdMgr.exe
#:32 [syntplpr.exe]
FilePath : C:\Program Files\Synaptics\SynTP\
ProcessID : 1332
ThreadCreationTime : 6-1-2005 3:41:23 PM
BasePriority : Normal
FileVersion : 7.2.3.10 24Jun03
ProductVersion : 7.2.3.10 24Jun03
ProductName : Progressive Touch
CompanyName : Synaptics, Inc.
FileDescription : TouchPad Driver Helper Application
InternalName : SynTPLpr
LegalCopyright : Copyright © Synaptics, Inc. 1996-2002
OriginalFilename : SynTPLpr.exe
#:33 [syntpenh.exe]
FilePath : C:\Program Files\Synaptics\SynTP\
ProcessID : 1340
ThreadCreationTime : 6-1-2005 3:41:24 PM
BasePriority : Normal
FileVersion : 7.2.3.10 24Jun03
ProductVersion : 7.2.3.10 24Jun03
ProductName : Progressive Touch
CompanyName : Synaptics, Inc.
FileDescription : Synaptics TouchPad Enhancements
InternalName : Scrolleroo
LegalCopyright : Copyright © Synaptics, Inc. 1996-2002
OriginalFilename : SynTPEnh.exe
#:34 [agrsmmsg.exe]
FilePath : C:\WINNT\
ProcessID : 1356
ThreadCreationTime : 6-1-2005 3:41:24 PM
BasePriority : Normal
FileVersion : 2.1.7 2.1.7 02/22/2002 15:37:42
ProductVersion : 2.1.7 2.1.7 02/22/2002 15:37:42
ProductName : Agere SoftModem Messaging Applet
CompanyName : Agere Systems
FileDescription : SoftModem Messaging Applet
InternalName : smdmstat.exe
LegalCopyright : Copyright © Agere Systems 1998-2000
OriginalFilename : smdmstat.exe
#:35 [prpcui.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1388
ThreadCreationTime : 6-1-2005 3:41:24 PM
BasePriority : Normal
FileVersion : 2.2.0.0
ProductVersion : 2.2.0.0
ProductName : Intel® SpeedStep technology applet
CompanyName : Intel Corporation
FileDescription : Intel® SpeedStep technology User Interface
InternalName : prpcui.exe
LegalCopyright : Copyright© Intel Corporation 1998-2001
LegalTrademarks : Intel® SpeedStep technology
OriginalFilename : prpcui.exe
Comments : Intel SpeedStep technology Applet v2.2
#:36 [tphkmgr.exe]
FilePath : C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\
ProcessID : 1396
ThreadCreationTime : 6-1-2005 3:41:25 PM
BasePriority : Normal
#:37 [rundll32.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1424
ThreadCreationTime : 6-1-2005 3:41:25 PM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : RUNDLL.EXE
#:38 [updaterui.exe]
FilePath : C:\Program Files\Network Associates\Common Framework\
ProcessID : 1452
ThreadCreationTime : 6-1-2005 3:41:26 PM
BasePriority : Normal
FileVersion : 3.1.1.184
ProductName : McAfee Common Framework
CompanyName : Network Associates, Inc.
FileDescription : Common User Interface
InternalName : UpdaterUI
LegalCopyright : Copyright© 2000-2003 Networks Associates Technology, Inc. All Rights Reserved.
OriginalFilename : UpdaterUI.exe
#:39 [sdclientmonitor.exe]
FilePath : C:\Program Files\LANDesk\LDClient\webportal\
ProcessID : 1464
ThreadCreationTime : 6-1-2005 3:41:27 PM
BasePriority : Normal
FileVersion : 8.5.0.164
ProductVersion : 8.5.0.164
ProductName : LANDesk® Management Suite
CompanyName : LANDesk Software Ltd.
FileDescription : TODO: <File description>
InternalName : SDClientMonitor.exe
LegalCopyright : Copyright© 2004 LANDesk Software Ltd.
OriginalFilename : SDClientMonitor.exe
#:40 [sdkyi.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1492
ThreadCreationTime : 6-1-2005 3:41:27 PM
BasePriority : Normal
#:41 [wzqkpick.exe]
FilePath : C:\Program Files\WinZip\
ProcessID : 1600
ThreadCreationTime : 6-1-2005 3:41:32 PM
BasePriority : Normal
FileVersion : 1.0 (32-bit)
ProductVersion : 9.0 (6028)
ProductName : WinZip
CompanyName : WinZip Computing, Inc.
FileDescription : WinZip Executable
InternalName : WZQKPICK.EXE
LegalCopyright : Copyright © WinZip Computing, Inc. 1991-2004 - All Rights Reserved
LegalTrademarks : WinZip is a registered trademark of WinZip Computing, Inc
OriginalFilename : WZQKPICK.EXE
Comments : StringFileInfo: U.S. English
#:42 [rimdevicemanager.exe]
FilePath : C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\
ProcessID : 1660
ThreadCreationTime : 6-1-2005 3:41:34 PM
BasePriority : Normal
FileVersion : 3.6.2.9 (Release build by unknown)
ProductVersion : 3.6.2.9 (Release build by unknown)
ProductName : Desktop Tools for RIM Handheld Devices
CompanyName : Research In Motion Limited
FileDescription : Handheld Tools RimDeviceManager
InternalName : RimDeviceManager
LegalCopyright : © 1997-2003 Research In Motion Limited.
OriginalFilename : RimDeviceManager.exe
#:43 [msoffice.exe]
FilePath : C:\Program Files\Microsoft Office\Office\1033\
ProcessID : 1668
ThreadCreationTime : 6-1-2005 3:41:35 PM
BasePriority : Normal
FileVersion : 9.0.2601
ProductVersion : 9.0.2601
ProductName : Microsoft Office 2000
CompanyName : Microsoft Corporation
FileDescription : Microsoft Office 2000 component
InternalName : MSOFFICE
LegalCopyright : Copyright© Microsoft Corporation 1994-1999. All rights reserved.
OriginalFilename : MSOFFICE.EXE
#:44 [bbdevmgr.exe]
FilePath : C:\Program Files\Common Files\Research In Motion\USB Drivers\
ProcessID : 1708
ThreadCreationTime : 6-1-2005 3:41:36 PM
BasePriority : Normal
FileVersion : 1.1.0.12
ProductVersion : 1.1.0.12
ProductName : RIM handheld driver
CompanyName : Research In Motion Limited
FileDescription : RIM handheld device manager
InternalName : BbDevMgr
LegalCopyright : Copyright 2004 Research In Motion Limited
OriginalFilename : BbDevMgr.EXE
#:45 [mcshield.exe]
FilePath : C:\Program Files\Common Files\Network Associates\McShield\
ProcessID : 1604
ThreadCreationTime : 6-1-2005 3:42:46 PM
BasePriority : High
#:46 [msiexec.exe]
FilePath : C:\WINNT\System32\
ProcessID : 1756
ThreadCreationTime : 6-1-2005 3:42:46 PM
BasePriority : Normal
#:47 [svchost.exe]
FilePath : C:\WINNT\System32\
ProcessID : 1952
ThreadCreationTime : 6-1-2005 3:42:49 PM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:48 [sdkak.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1980
ThreadCreationTime : 6-1-2005 3:42:49 PM
BasePriority : Normal
#:49 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 1468
ThreadCreationTime : 6-1-2005 3:44:48 PM
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
CoolWebSearch Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\currentcontrolset\services\ 11fßä#·ºÄÖ`i
CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\currentcontrolset\services\ 11fßä#·ºÄÖ`i
Value : Start
CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\currentcontrolset\services\ 11fßä#·ºÄÖ`i
Value : ErrorControl
CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\currentcontrolset\services\ 11fßä#·ºÄÖ`i
Value : ImagePath
CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\currentcontrolset\services\ 11fßä#·ºÄÖ`i
Value : DisplayName
CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\currentcontrolset\services\ 11fßä#·ºÄÖ`i
Value : ObjectName
CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : system\currentcontrolset\services\ 11fßä#·ºÄÖ`i
Value : FailureActions
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 7
Objects found so far: 7
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 7
MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Object Recognized!
Location: : S-1-5-21-287920652-361002115-1528318997-500\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-287920652-361002115-1528318997-500\software\microsoft\windows\currentversion\explorer\runmru
Description : mru list for items opened in start | run
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 10
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 10
Possible Browser Hijack attempt Object Recognized!
Type : File
Data : Search the web.url
TAC Rating : 10
Category : Misc
Comment : Problematic URL discovered: http://www.lookfor.cc/
Object : C:\Documents and Settings\Administrator\Favorites\
Possible Browser Hijack attempt Object Recognized!
Type : File
Data : Only -- The nicest hobby on Earth ;) -- website.url
TAC Rating : 10
Category : Misc
Comment : Problematic URL discovered: http://www.only-- The nicest hobby on Earth ;) --.ws/
Object : C:\Documents and Settings\Administrator\Favorites\
Possible Browser Hijack attempt Object Recognized!
Type : File
Data : Seven days of free porn.url
TAC Rating : 10
Category : Misc
Comment : Problematic URL discovered: http://www.7days.ws/
Object : C:\Documents and Settings\Administrator\Favorites\
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
CoolWebSearch Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\urlsearchhooks
CoolWebSearch Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\hsa
CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\hsa
Value : UninstallString
CoolWebSearch Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\se
CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\se
Value : UninstallString
CoolWebSearch Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\sw
CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\sw
Value : UninstallString
CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Search Bar
CoolWebSearch Object Recognized!
Type : RegData
Data : no
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Use Search Asst
Data : no
CoolWebSearch Object Recognized!
Type : RegData
Data : about:blank
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Start Page
Data : about:blank
CoolWebSearch Object Recognized!
Type : RegData
Data : no
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\main
Value : Use Search Asst
Data : no
CoolWebSearch Object Recognized!
Type : RegData
Data : about:blank
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\main
Value : Start Page
Data : about:blank
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 12
Objects found so far: 25
11:53:11 AM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:08:04.437
Objects scanned:78839
Objects identified:22
Objects ignored:0
New critical objects:22
-----------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 12:03:33 PM, on 6/1/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\ibmpmsvc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\Program Files\LANDesk\Shared Files\residentagent.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\LANDesk\LDClient\LocalSch.EXE
C:\WINNT\system32\cba\pds.exe
C:\Program Files\LANDesk\LDClient\qipclnt.exe
C:\Program Files\LANDesk\LDClient\tmcsvc.exe
C:\PROGRA~1\LANDesk\LDClient\issuser.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\WINNT\System32\QCONSVC.EXE
C:\WINNT\system32\regsvc.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\LANDesk\LDClient\softmon.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\AGRSMMSG.exe
C:\WINNT\system32\PRPCUI.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINNT\system32\RunDll32.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\LANDesk\LDClient\webportal\sdclientmonitor.exe
C:\WINNT\system32\sdkyi.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\sdkak.exe
E:\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\udsga.dll/sp.html#55135
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\udsga.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\udsga.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\system32\udsga.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\udsga.dll/sp.html#55135
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\system32\udsga.dll/sp.html#55135
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = www-relay:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 172.16.*.*;<local>
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,,C:\Program Files\LANDesk\LDClient\softmon.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Class - {C712592C-C0E3-647D-3991-4EF25619B7DF} - C:\WINNT\system32\mfcrx.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [Tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe /server"
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [IntelAPMClient] "C:\Program Files\LANDesk\LDClient\amclient.exe" /apm /s /ro
O4 - HKLM\..\Run: [SDClientMonitor] "C:\Program Files\LANDesk\LDClient\webportal\sdclientmonitor.exe"
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [sdkyi.exe] C:\WINNT\system32\sdkyi.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Legal55 4.0.lnk = C:\Program Files\Legal55 4.0\Legal55_3.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.holycross.edu/departments/publi...sCamControl.ocx
O16 - DPF: {CA34C280-5156-4E04-857A-BB69604B2F09} (EditXCon Class) - http://prvwestkm1/km/controls/aleph.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ealaw.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ealaw.com
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: LANDesk® Management Agent (CBA8) - LANDesk® Development, Ltd - C:\Program Files\LANDesk\Shared Files\residentagent.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINNT\system32\ibmpmsvc.exe
O23 - Service: Intel Local Scheduler Service - LANDesk Software Ltd. - C:\Program Files\LANDesk\LDClient\LocalSch.EXE
O23 - Service: Intel PDS - Intel® Corporation - C:\WINNT\system32\cba\pds.exe
O23 - Service: Intel QIP Client Service - LANDesk Software Ltd. - C:\Program Files\LANDesk\LDClient\qipclnt.exe
O23 - Service: LANDesk Targeted Multicast (Intel Targeted Multicast) - LANDesk Software Ltd. - C:\Program Files\LANDesk\LDClient\tmcsvc.exe
O23 - Service: LANDesk Remote Control Service (ISSUSER) - LANDesk Software, Ltd. - C:\PROGRA~1\LANDesk\LDClient\issuser.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINNT\System32\QCONSVC.EXE
Again, thank very much.