You are on page 1of 9

Logfile created: 9/26/2011 21:17:00 Ad-Aware version: 9.0.7 Extended engine: 3 Extended engine version: 3.1.

2770 User performing scan: Warren Cohen *********************** Definitions database information *********************** Lavasoft definition file: 150.581 Genotype definition file version: 2011/09/21 13:56:01 Extended engine definition file: 10591.0 ******************************** Scan results: ********************************* Scan profile name: Full Scan (ID: full) Objects scanned: 590062 Objects detected: 8 Type Detected ========================== Processes.......: 0 Registry entries: 0 Hostfile entries: 0 Files...........: 0 Folders.........: 0 LSPs............: 0 Cookies.........: 8 Browser hijacks.: 0 MRU objects.....: 0

Removed items: Description: *doubleclick* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408875 Family ID: 0 Description: *serving-sys* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 409130 Family ID: 0 Description: *atdmt* Family Name: Cookies Engine: 1 Clean status: Success Item I D: 408910 Family ID: 0 Description: *serving-sys* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 409130 Family ID: 0 Description: *doubleclick* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408875 Family ID: 0 Description: *2o7* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408943 Family ID: 0 Description: *doubleclick* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 408875 Family ID: 0 Description: *serving-sys* Family Name: Cookies Engine: 1 Clean status: Success Item ID: 409130 Family ID: 0 Scan and cleaning complete: Finished correctly after 10313 seconds *********************************** Settings *********************************** Scan profile: ID: full, enabled:1, value: Full Scan ID: folderstoscan, enabled:1, value: C:\,D:\,F:\,G:\,H:\ ID: useantivirus, enabled:1, value: true ID: sections, enabled:1 ID: scancriticalareas, enabled:1, value: true ID: scanrunningapps, enabled:1, value: true

ID: scanregistry, enabled:1, value: true ID: scanlsp, enabled:1, value: true ID: scanads, enabled:1, value: true ID: scanhostsfile, enabled:1, value: true ID: scanmru, enabled:1, value: true ID: scanbrowserhijacks, enabled:1, value: true ID: scantrackingcookies, enabled:1, value: true ID: closebrowsers, enabled:1, value: false ID: filescanningoptions, enabled:1 ID: archives, enabled:1, value: true ID: onlyexecutables, enabled:1, value: false ID: skiplargerthan, enabled:1, value: 20480 ID: scanrootkits, enabled:1, value: true ID: rootkitlevel, enabled:1, value: mild, domain: medium,mild,strict ID: usespywareheuristics, enabled:1, value: true Scan global: ID: global, enabled:1 ID: addtocontextmenu, enabled:1, value: true ID: playsoundoninfection, enabled:1, value: false ID: soundfile, enabled:0, value: N/A Scheduled scan settings: <Empty> Update settings: ID: updates, enabled:1 ID: launchthreatworksafterscan, enabled:1, value: off, domain: normal,off,sile ntly ID: deffiles, enabled:1, value: downloadandinstall, domain: dontcheck,download andinstall ID: licenseandinfo, enabled:1, value: downloadandinstall, domain: dontcheck,do wnloadandinstall ID: schedules, enabled:1, value: true ID: updatedaily1, enabled:1, value: Daily 1 ID: time, enabled:1, value: Mon Jun 13 20:37:00 2011 ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systems tart,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: false ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: false ID: thursday, enabled:1, value: false ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: false ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false ID: updatedaily2, enabled:1, value: Daily 2 ID: time, enabled:1, value: Mon Jun 13 02:37:00 2011 ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systems tart,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: false ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: false ID: thursday, enabled:1, value: false ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: false

ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false ID: updatedaily3, enabled:1, value: Daily 3 ID: time, enabled:1, value: Mon Jun 13 08:37:00 2011 ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systems tart,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: false ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: false ID: thursday, enabled:1, value: false ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: false ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false ID: updatedaily4, enabled:1, value: Daily 4 ID: time, enabled:1, value: Mon Jun 13 14:37:00 2011 ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systems tart,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: false ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: false ID: thursday, enabled:1, value: false ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: false ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false ID: updateweekly1, enabled:1, value: Weekly ID: time, enabled:1, value: Mon Jun 13 20:37:00 2011 ID: frequency, enabled:1, value: weekly, domain: daily,monthly,once,system start,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: true ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: false ID: thursday, enabled:1, value: true ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: false ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false Appearance settings: ID: appearance, enabled:1 ID: skin, enabled:1, value: default.egl, reglocation: HKEY_LOCAL_MACHINE\SOFTW ARE\Lavasoft\Ad-Aware\Resource ID: showtrayicon, enabled:1, value: true ID: autoentertainmentmode, enabled:1, value: true ID: guimode, enabled:1, value: mode_simple, domain: mode_advanced,mode_simple ID: language, enabled:1, value: en, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\L avasoft\Ad-Aware\Language

Realtime protection settings: ID: realtime, enabled:1 ID: infomessages, enabled:1, value: onlyimportant, domain: display,dontnotify, onlyimportant ID: layers, enabled:1 ID: useantivirus, enabled:1, value: true ID: usespywareheuristics, enabled:1, value: true ID: maintainbackup, enabled:1, value: true ID: modules, enabled:1 ID: processprotection, enabled:1, value: true ID: onaccessprotection, enabled:1, value: true ID: registryprotection, enabled:1, value: true ID: networkprotection, enabled:1, value: true ****************************** System information ****************************** Computer name: WARRENCOHEN-HP Processor name: AMD Athlon(tm) II X4 630 Processor Processor identifier: AMD64 Family 16 Model 5 Stepping 2 Processor speed: ~2793MHZ Raw info: processorarchitecture 9, processortype 8664, processorlevel 16, proces sor revision 1282, number of processors 4, processor features: [MMX,SSE,SSE2,SSE 3,3DNow] Physical memory available: 2598719488 bytes Physical memory total: 4018032640 bytes Virtual memory available: 1891127296 bytes Virtual memory total: 2147352576 bytes Memory load: 35% Microsoft (build 7600) Windows startup mode: Running processes: PID: 276 name: C:\Windows\System32\smss.exe owner: SYSTEM domain: NT AUTHORITY PID: 456 name: C:\Windows\System32\csrss.exe owner: SYSTEM domain: NT AUTHORITY PID: 508 name: C:\Windows\System32\wininit.exe owner: SYSTEM domain: NT AUTHORIT Y PID: 544 name: C:\Windows\System32\csrss.exe owner: SYSTEM domain: NT AUTHORITY PID: 568 name: C:\Windows\System32\services.exe owner: SYSTEM domain: NT AUTHORI TY PID: 588 name: C:\Windows\System32\lsass.exe owner: SYSTEM domain: NT AUTHORITY PID: 596 name: C:\Windows\System32\lsm.exe owner: SYSTEM domain: NT AUTHORITY PID: 700 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORIT Y PID: 764 name: C:\Windows\System32\winlogon.exe owner: SYSTEM domain: NT AUTHORI TY PID: 820 name: C:\Windows\System32\svchost.exe owner: NETWORK SERVICE domain: NT AUTHORITY PID: 884 name: C:\Windows\System32\atiesrxx.exe owner: SYSTEM domain: NT AUTHORI TY PID: 948 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT A UTHORITY PID: 988 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORIT Y PID: 124 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORIT Y PID: 524 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT A UTHORITY PID: 1064 name: C:\Windows\System32\atieclxx.exe owner: SYSTEM domain: NT AUTHOR ITY PID: 1104 name: C:\Windows\System32\svchost.exe owner: NETWORK SERVICE domain: N

T AUTHORITY PID: 1308 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe owner: S YSTEM domain: NT AUTHORITY PID: 1416 name: C:\Windows\System32\spoolsv.exe owner: SYSTEM domain: NT AUTHORI TY PID: 1444 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY PID: 1528 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY PID: 1576 name: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe own er: SYSTEM domain: NT AUTHORITY PID: 1600 name: C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe ow ner: SYSTEM domain: NT AUTHORITY PID: 1624 name: C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe owner: SY STEM domain: NT AUTHORITY PID: 1632 name: C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\ AppleMobileDeviceService.exe owner: SYSTEM domain: NT AUTHORITY PID: 1640 name: C:\Windows\System32\conhost.exe owner: SYSTEM domain: NT AUTHORI TY PID: 1692 name: C:\Program Files (x86)\Bonjour\mDNSResponder.exe owner: SYSTEM d omain: NT AUTHORITY PID: 1760 name: C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe owner: SYSTEM domain: NT AUTHORITY PID: 1832 name: C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe owner : SYSTEM domain: NT AUTHORITY PID: 1884 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY PID: 1928 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY PID: 2016 name: C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLID SVC.EXE owner: SYSTEM domain: NT AUTHORITY PID: 2072 name: C:\Windows\System32\wbem\unsecapp.exe owner: SYSTEM domain: NT A UTHORITY PID: 2200 name: C:\Windows\System32\wbem\WmiPrvSE.exe owner: NETWORK SERVICE dom ain: NT AUTHORITY PID: 2208 name: C:\Windows\System32\wbem\WmiPrvSE.exe owner: SYSTEM domain: NT A UTHORITY PID: 2584 name: C:\Windows\System32\WUDFHost.exe owner: LOCAL SERVICE domain: NT AUTHORITY PID: 2724 name: C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLID SVCM.EXE owner: SYSTEM domain: NT AUTHORITY PID: 2984 name: C:\Windows\SysWOW64\WinMsgBalloonServer.exe owner: SYSTEM domain : NT AUTHORITY PID: 2124 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORI TY PID: 516 name: C:\Windows\SysWOW64\WinMsgBalloonClient.exe owner: SYSTEM domain: NT AUTHORITY PID: 1168 name: C:\Program Files\Windows Media Player\wmpnetwk.exe owner: NETWOR K SERVICE domain: NT AUTHORITY PID: 2836 name: C:\Windows\System32\dwm.exe owner: Warren Cohen domain: WarrenCo hen-HP PID: 924 name: C:\Windows\explorer.exe owner: Warren Cohen domain: WarrenCohen-H P PID: 2392 name: C:\Windows\System32\taskhost.exe owner: Warren Cohen domain: War renCohen-HP PID: 3208 name: C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe owner: Warren Cohen domain: WarrenCohen-HP PID: 3220 name: C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe own er: Warren Cohen domain: WarrenCohen-HP PID: 3232 name: C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisor

Dock.exe owner: Warren Cohen domain: WarrenCohen-HP PID: 3344 name: C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe owne r: Warren Cohen domain: WarrenCohen-HP PID: 3428 name: C:\Program Files (x86)\iTunes\iTunesHelper.exe owner: Warren Coh en domain: WarrenCohen-HP PID: 3500 name: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe owner: Warren Cohen domain: WarrenCohen-HP PID: 3592 name: C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin owne r: Warren Cohen domain: WarrenCohen-HP PID: 3712 name: C:\Program Files\iPod\bin\iPodService.exe owner: SYSTEM domain: NT AUTHORITY PID: 4080 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY PID: 3972 name: C:\Windows\System32\dllhost.exe owner: SYSTEM domain: NT AUTHORI TY PID: 3416 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe owner: Warr en Cohen domain: WarrenCohen-HP PID: 3004 name: C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM. exe owner: Warren Cohen domain: WarrenCohen-HP PID: 2788 name: C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC. exe owner: Warren Cohen domain: WarrenCohen-HP PID: 4504 name: C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe owner: Warren Cohen domain: WarrenCohen-HP PID: 4556 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe owner: War ren Cohen domain: WarrenCohen-HP Startup items: Name: StartCCC imagepath: "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Stati c\CLIStart.exe" MSRun Name: QuickTime Task imagepath: "G:\Program Files (x86)\QTTask.exe" -atboottime Name: iTunesHelper imagepath: "C:\Program Files (x86)\iTunes\iTunesHelper.exe" Name: Adobe ARM imagepath: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM .exe" Name: SunJavaUpdateSched imagepath: "C:\Program Files (x86)\Common Files\Java\Java Update\jusch ed.exe" Name: WebCheck imagepath: {E6FB5E20-DE35-11CF-9C87-00AA005127ED} Name: imagepath: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startu p\desktop.ini Bootexecute items: Name: imagepath: autocheck autochk * Name: imagepath: lsdelete Running services: Name: AdobeARMservice displayname: Adobe Acrobat Update Service Name: AeLookupSvc displayname: Application Experience Name: AMD External Events Utility displayname: AMD External Events Utility Name: AMD_RAIDXpert

displayname: AMD RAIDXpert Name: Appinfo displayname: Application Information Name: Apple Mobile Device displayname: Apple Mobile Device Name: AudioEndpointBuilder displayname: Windows Audio Endpoint Builder Name: AudioSrv displayname: Windows Audio Name: BFE displayname: Base Filtering Engine Name: BITS displayname: Background Intelligent Transfer Service Name: Bonjour Service displayname: Bonjour Service Name: Browser displayname: Computer Browser Name: CryptSvc displayname: Cryptographic Services Name: DcomLaunch displayname: DCOM Server Process Launcher Name: Dhcp displayname: DHCP Client Name: Dnscache displayname: DNS Client Name: DPS displayname: Diagnostic Policy Service Name: EapHost displayname: Extensible Authentication Protocol Name: eventlog displayname: Windows Event Log Name: EventSystem displayname: COM+ Event System Name: fdPHost displayname: Function Discovery Provider Host Name: FDResPub displayname: Function Discovery Resource Publication Name: FlipShare Service displayname: FlipShare Service Name: FontCache displayname: Windows Font Cache Service Name: gpsvc displayname: Group Policy Client Name: hidserv displayname: Human Interface Device Access Name: HomeGroupListener displayname: HomeGroup Listener Name: HomeGroupProvider displayname: HomeGroup Provider Name: iphlpsvc displayname: IP Helper Name: iPod Service displayname: iPod Service Name: KeyIso displayname: CNG Key Isolation Name: LanmanServer displayname: Server Name: LanmanWorkstation displayname: Workstation Name: Lavasoft Ad-Aware Service

displayname: Lavasoft Ad-Aware Service Name: LightScribeService displayname: LightScribeService Direct Disc Labeling Service Name: lmhosts displayname: TCP/IP NetBIOS Helper Name: MpsSvc displayname: Windows Firewall Name: Net Driver HPZ12 displayname: Net Driver HPZ12 Name: Netman displayname: Network Connections Name: netprofm displayname: Network List Service Name: NlaSvc displayname: Network Location Awareness Name: nsi displayname: Network Store Interface Service Name: p2pimsvc displayname: Peer Networking Identity Manager Name: p2psvc displayname: Peer Networking Grouping Name: PcaSvc displayname: Program Compatibility Assistant Service Name: PlugPlay displayname: Plug and Play Name: Pml Driver HPZ12 displayname: Pml Driver HPZ12 Name: PNRPsvc displayname: Peer Name Resolution Protocol Name: Power displayname: Power Name: ProfSvc displayname: User Profile Service Name: RpcEptMapper displayname: RPC Endpoint Mapper Name: RpcSs displayname: Remote Procedure Call (RPC) Name: SamSs displayname: Security Accounts Manager Name: Schedule displayname: Task Scheduler Name: SENS displayname: System Event Notification Service Name: ShellHWDetection displayname: Shell Hardware Detection Name: Spooler displayname: Print Spooler Name: SSDPSRV displayname: SSDP Discovery Name: SysMain displayname: Superfetch Name: Themes displayname: Themes Name: TrkWks displayname: Distributed Link Tracking Client Name: upnphost displayname: UPnP Device Host Name: UxSms displayname: Desktop Window Manager Session Manager Name: WdiServiceHost

displayname: Diagnostic Service Host Name: WdiSystemHost displayname: Diagnostic System Host Name: WinDefend displayname: Windows Defender Name: WinHttpAutoProxySvc displayname: WinHTTP Web Proxy Auto-Discovery Service Name: Winmgmt displayname: Windows Management Instrumentation Name: Wlansvc displayname: WLAN AutoConfig Name: wlidsvc displayname: Windows Live ID Sign-in Assistant Name: WMPNetworkSvc displayname: Windows Media Player Network Sharing Service Name: WPDBusEnum displayname: Portable Device Enumerator Service Name: wscsvc displayname: Security Center Name: wuauserv displayname: Windows Update Name: wudfsvc displayname: Windows Driver Foundation - User-mode Driver Framework

You might also like