Man i need soem help the stupid Softomate toolbar wont go, and on regedit the files i am supposed to move arent there! can anybody please give me some tips onto how to remove this unwanted spyware form my system???
Download HijackThis. Run the program. Click the Do a System Scan and save a Logfile button. Copy/paste the contents of the log in a reply to this topic please.
First of all please loose the slang talk, this is a public forum not MSN. Second go to add or remove programms ( i belive u no were that is on XP) and look for the softomate toolbar. after you've removed it run Ccleaner (if you do not already have it, google is your friend) and clean your registery out. If all else fails please post hijackthis log.
i cant run a full hijackthis scan i get two error messages http://img365.imageshack.us/img365/5538/untitled1bs6.jpg and http://img353.imageshack.us/img353/5120/untitled2rs9.jpg wat should i do?
well the first one it tells u what to do and for the second just press ok and paste what ever it scans here.
yh im running windows vista home premium, does this make a difference with hijackthis? and this is the log hijackthis gave me after i pressed ok after those two error messages, although i dont think its a full hijackthis log Logfile of HijackThis v1.99.1 Scan saved at 22:44:20, on 10/04/2007 Platform: Unknown Windows (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16386) Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\autoclk.exe C:\Program Files\Grisoft\AVG7\avgcc.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\PIXELA\ImageMixer for HDD Camcorder\IMx3Launcher.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe C:\Users\Ali\Desktop\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: (no name) - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [autoclk] autoclk.exe O4 - HKLM\..\Run: [adiras] adiras.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe O4 - Global Startup: ImageMixer for HDD Camcorder.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll O11 - Options group: [INTERNATIONAL] International* O13 - Gopher Prefix: O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by112fd.bay112.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{688D9973-210F-430A-8AD3-B568E5C69A92}: NameServer = 212.139.132.24 212.139.132.25 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: dlcx_device - - C:\Windows\system32\dlcxcoms.exe O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
well u see in your hijackthis log there doesnt look like any traces of that toolbar but u do have some stuff u don't need. O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe So basicaly i don't think u need them two listed. also regarding hijackthis on vista. it should work as i havent heard of any one elses on vista not working.
To be sure we are getting the full log... right click on HijackThis.exe and choose Run as Administrator. Do another scan and post the new log please.
ok i ran as administrator and this is wat i got i think its the same Logfile of HijackThis v1.99.1 Scan saved at 18:42:05, on 11/04/2007 Platform: Unknown Windows (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16386) Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\autoclk.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\Grisoft\AVG7\avgcc.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe C:\Program Files\PIXELA\ImageMixer for HDD Camcorder\IMx3Launcher.exe C:\Windows\ehome\ehmsas.exe C:\Windows\System32\mobsync.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Ali\Desktop\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: (no name) - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [autoclk] autoclk.exe O4 - HKLM\..\Run: [adiras] adiras.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe O4 - Global Startup: ImageMixer for HDD Camcorder.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll O11 - Options group: [INTERNATIONAL] International* O13 - Gopher Prefix: O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by112fd.bay112.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{688D9973-210F-430A-8AD3-B568E5C69A92}: NameServer = 212.139.132.24 212.139.132.25 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: dlcx_device - - C:\Windows\system32\dlcxcoms.exe O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing) and also i searched up on the internet how to remove the softomate toolbar, i need to remove some files on registry, but wen i check the files arent there wat should i do?
well i didnt run a spybot scan coz ad aware always finds the softomate toolbar threat so this is the adaware log Ad-Aware SE Build 1.06r1 Logfile Created on:11 April 2007 19:11:27 Using definitions file:SE1R164 02.04.2007 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» MRU List(TAC index:0):18 total references Softomate Toolbar(TAC index:9):1 total references Tracking Cookie(TAC index:3):12 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Ad-Aware SE Settings =========================== Set : Search for negligible risk entries Set : Search for low-risk threats Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Ignore spanned files when scanning cab archives Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Block pop-ups aggressively Set : Automatically select problematic objects in results lists Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Show splash screen Set : Backup current definitions file before updating Set : Play sound at scan completion if scan locates critical objects 11-04-2007 19:11:27 - Scan started. (Full System Scan) MRU List Object Recognized! Location: : C:\Users\Ali\AppData\Roaming\microsoft\office\recent Description : list of recently opened documents using microsoft office MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct3d MRU List Object Recognized! Location: : S-1-5-18\software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct3d MRU List Object Recognized! Location: : S-1-5-21-228332201-3050579902-260128071-1000\software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct3d MRU List Object Recognized! Location: : software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct3d MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct X MRU List Object Recognized! Location: : S-1-5-18\software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct X MRU List Object Recognized! Location: : S-1-5-21-228332201-3050579902-260128071-1000\software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct X MRU List Object Recognized! Location: : software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct X MRU List Object Recognized! Location: : software\microsoft\directdraw\mostrecentapplication Description : most recent application to use microsoft directdraw MRU List Object Recognized! Location: : S-1-5-21-228332201-3050579902-260128071-1000\software\microsoft\internet explorer\typedurls Description : list of recently entered addresses in microsoft internet explorer MRU List Object Recognized! Location: : S-1-5-21-228332201-3050579902-260128071-1000\software\microsoft\mediaplayer\player\recentfilelist Description : list of recently used files in microsoft windows media player MRU List Object Recognized! Location: : S-1-5-21-228332201-3050579902-260128071-1000\software\microsoft\office\11.0\common\open find\microsoft office word\settings\open\file name mru Description : list of recent documents opened by microsoft word MRU List Object Recognized! Location: : S-1-5-21-228332201-3050579902-260128071-1000\software\microsoft\office\11.0\common\open find\microsoft office word\settings\save as\file name mru Description : list of recent documents saved by microsoft word MRU List Object Recognized! Location: : S-1-5-21-228332201-3050579902-260128071-1000\software\microsoft\windows\currentversion\explorer\recentdocs Description : list of recent documents opened MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general Description : windows media sdk MRU List Object Recognized! Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general Description : windows media sdk MRU List Object Recognized! Location: : S-1-5-21-228332201-3050579902-260128071-1000\software\microsoft\windows media\wmsdk\general Description : windows media sdk Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [dwm.exe] FilePath : C:\Windows\system32\ ProcessID : 1616 ThreadCreationTime : 11-04-2007 05:14:06 BasePriority : High FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205) ProductVersion : 6.0.6000.16386 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Desktop Window Manager InternalName : dwm.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : dwm.exe.mui #:2 [taskeng.exe] FilePath : C:\Windows\system32\ ProcessID : 1716 ThreadCreationTime : 11-04-2007 05:14:06 BasePriority : Normal FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205) ProductVersion : 6.0.6000.16386 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Task Scheduler Engine InternalName : TaskEng LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : taskeng.exe.mui #:3 [explorer.exe] FilePath : C:\Windows\ ProcessID : 1752 ThreadCreationTime : 11-04-2007 05:14:06 BasePriority : Normal FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205) ProductVersion : 6.0.6000.16386 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE.MUI #:4 [msascui.exe] FilePath : C:\Program Files\Windows Defender\ ProcessID : 324 ThreadCreationTime : 11-04-2007 05:14:08 BasePriority : Normal FileVersion : 1.1.1505.0 ProductVersion : 1.1.1505.0 ProductName : Windows Defender CompanyName : Microsoft Corporation FileDescription : Windows Defender User Interface InternalName : MSASCUI LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : MSASCUI.exe #:5 [autoclk.exe] FilePath : C:\Windows\ ProcessID : 372 ThreadCreationTime : 11-04-2007 05:14:08 BasePriority : Normal FileVersion : 1, 0, 0, 1 ProductVersion : 1, 0, 0, 1 ProductName : autoclk Application FileDescription : autoclk MFC Application InternalName : autoclk LegalCopyright : Copyright (C) 2002 OriginalFilename : autoclk.EXE #:6 [pwrisovm.exe] FilePath : C:\Program Files\PowerISO\ ProcessID : 512 ThreadCreationTime : 11-04-2007 05:14:08 BasePriority : Normal FileVersion : 3, 6, 0, 0 ProductVersion : 3, 6, 0, 0 ProductName : PowerISO Virtual Drive Manager CompanyName : PowerISO Computing, Inc. FileDescription : PowerISO Virtual Drive Manager InternalName : PowerISO Virtual Drive Manager LegalCopyright : Copyright (C) 2004-2007 OriginalFilename : PWRISOVM.EXE Comments : http://www.poweriso.com #:7 [avgcc.exe] FilePath : C:\Program Files\Grisoft\AVG7\ ProcessID : 824 ThreadCreationTime : 11-04-2007 05:14:08 BasePriority : Normal FileVersion : 7.5.0.438 ProductVersion : 7.5.0.438 ProductName : AVG Anti-Virus system CompanyName : GRISOFT, s.r.o. FileDescription : AVG Control Center InternalName : AvgCC LegalCopyright : Copyright © 2007 GRISOFT, s.r.o. OriginalFilename : AvgCC.EXE #:8 [qttask.exe] FilePath : C:\Program Files\QuickTime\ ProcessID : 1008 ThreadCreationTime : 11-04-2007 05:14:08 BasePriority : Normal FileVersion : 7.1.5 ProductVersion : QuickTime 7.1.5 ProductName : QuickTime CompanyName : Apple Computer, Inc. FileDescription : QuickTime Task InternalName : QuickTime Task LegalCopyright : Copyright Apple Computer, Inc. 1989-2007 OriginalFilename : QTTask.exe #:9 [ituneshelper.exe] FilePath : C:\Program Files\iTunes\ ProcessID : 1116 ThreadCreationTime : 11-04-2007 05:14:08 BasePriority : Normal FileVersion : 7.1.1.5 ProductVersion : 7.1.1.5 ProductName : iTunes CompanyName : Apple Inc. FileDescription : iTunesHelper Module InternalName : iTunesHelper LegalCopyright : © 2003-2007 Apple Inc. All Rights Reserved. OriginalFilename : iTunesHelper.exe #:10 [sidebar.exe] FilePath : C:\Program Files\Windows Sidebar\ ProcessID : 1340 ThreadCreationTime : 11-04-2007 05:14:08 BasePriority : Normal FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205) ProductVersion : 1.0.6000.16386 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Sidebar InternalName : Windows Sidebar LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : sidebar.EXE.MUI #:11 [msnmsgr.exe] FilePath : C:\Program Files\MSN Messenger\ ProcessID : 1592 ThreadCreationTime : 11-04-2007 05:14:08 BasePriority : Normal FileVersion : 8.1.0178.00 ProductVersion : 8.1.0178 ProductName : Messenger CompanyName : Microsoft Corporation FileDescription : Messenger InternalName : msnmsgr.exe LegalCopyright : Copyright (c) Microsoft Corporation. All rights reserved. OriginalFilename : msnmsgr.exe #:12 [nmbgmonitor.exe] FilePath : C:\Program Files\Common Files\Ahead\Lib\ ProcessID : 2228 ThreadCreationTime : 11-04-2007 05:14:11 BasePriority : Normal #:13 [ehtray.exe] FilePath : C:\Windows\ehome\ ProcessID : 2272 ThreadCreationTime : 11-04-2007 05:14:11 BasePriority : Normal FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205) ProductVersion : 6.0.6000.16386 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Media Center Tray Applet InternalName : ehtray.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ehtray.exe #:14 [googletoolbarnotifier.exe] FilePath : C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\ ProcessID : 2300 ThreadCreationTime : 11-04-2007 05:14:11 BasePriority : Normal FileVersion : 1, 2, 1128, 5462 ProductVersion : 1, 2, 1128, 5462 ProductName : GoogleToolbarNotifier CompanyName : Google Inc. FileDescription : GoogleToolbarNotifier LegalCopyright : Copyright © 2005-2006 OriginalFilename : GoogleToolbarNotifier.exe #:15 [dslmon.exe] FilePath : C:\Program Files\SAGEM\SAGEM F@st 800-840\ ProcessID : 2312 ThreadCreationTime : 11-04-2007 05:14:12 BasePriority : Normal FileVersion : 1, 0, 0, 1 ProductVersion : 1, 0, 0, 1 ProductName : DSLMON Application FileDescription : ADIMON MFC Application InternalName : DSLMON LegalCopyright : Copyright (C) 2000 OriginalFilename : ADIMON.EXE #:16 [imx3launcher.exe] FilePath : C:\Program Files\PIXELA\ImageMixer for HDD Camcorder\ ProcessID : 2320 ThreadCreationTime : 11-04-2007 05:14:12 BasePriority : Normal FileVersion : 1.1.0.2 ProductVersion : 1.1.0.2 ProductName : ImageMixer Menu CompanyName : PIXELA CORPORATION FileDescription : ImageMixer Menu InternalName : ImxHDDLauncher.exe LegalCopyright : Copyright(c) 2005-2006 PIXELA CORPORATION OriginalFilename : ImxHDDLauncher.exe #:17 [ehmsas.exe] FilePath : C:\Windows\ehome\ ProcessID : 2348 ThreadCreationTime : 11-04-2007 05:14:12 BasePriority : Normal FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205) ProductVersion : 6.0.6000.16386 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Media Center Media Status Aggregator Service InternalName : eHMSAS.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ehMSAS.exe.mui #:18 [mobsync.exe] FilePath : C:\Windows\System32\ ProcessID : 3024 ThreadCreationTime : 11-04-2007 05:14:17 BasePriority : Normal FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205) ProductVersion : 6.0.6000.16386 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Microsoft Sync Center InternalName : mobsync.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : mobsync.exe #:19 [nmindexstoresvr.exe] FilePath : C:\Program Files\Common Files\Ahead\Lib\ ProcessID : 3332 ThreadCreationTime : 11-04-2007 05:14:19 BasePriority : Normal #:20 [sidebar.exe] FilePath : C:\Program Files\Windows Sidebar\ ProcessID : 3408 ThreadCreationTime : 11-04-2007 05:14:19 BasePriority : Normal FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205) ProductVersion : 1.0.6000.16386 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Sidebar InternalName : Windows Sidebar LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : sidebar.EXE.MUI #:21 [wuauclt.exe] FilePath : C:\Windows\system32\ ProcessID : 1992 ThreadCreationTime : 11-04-2007 05:17:36 BasePriority : Normal #:22 [ieuser.exe] FilePath : C:\Program Files\Internet Explorer\ ProcessID : 4780 ThreadCreationTime : 11-04-2007 11:06:05 BasePriority : Normal FileVersion : 6.0.6000.16386 (vista_rtm.061101-2205) ProductVersion : 6.0.6000.16386 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : ieuser.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ieuser.exe.mui #:23 [iexplore.exe] FilePath : C:\Program Files\Internet Explorer\ ProcessID : 7740 ThreadCreationTime : 11-04-2007 11:06:05 BasePriority : Normal FileVersion : 7.00.6000.16386 (vista_rtm.061101-2205) ProductVersion : 7.00.6000.16386 ProductName : Windows® Internet Explorer CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE.MUI #:24 [flashutil9b.exe] FilePath : C:\Windows\system32\Macromed\Flash\ ProcessID : 8940 ThreadCreationTime : 11-04-2007 13:13:59 BasePriority : Normal FileVersion : 9,0,28,0 ProductVersion : 9,0,28,0 ProductName : Flash Player Helper CompanyName : Adobe Systems, Inc. FileDescription : Adobe Flash Player Helper 9.0 r28 InternalName : Adobe Flash Player Helper 9.0 LegalCopyright : Copyright © 1996-2006 Adobe, Inc. LegalTrademarks : Adobe Flash Player OriginalFilename : FlashBroker.exe #:25 [iexplore.exe] FilePath : C:\Program Files\Internet Explorer\ ProcessID : 3512 ThreadCreationTime : 11-04-2007 14:41:02 BasePriority : Normal FileVersion : 7.00.6000.16386 (vista_rtm.061101-2205) ProductVersion : 7.00.6000.16386 ProductName : Windows® Internet Explorer CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE.MUI #:26 [ad-aware.exe] FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Professional\ ProcessID : 15156 ThreadCreationTime : 11-04-2007 18:11:19 BasePriority : Normal FileVersion : 6.2.0.238 ProductVersion : SE 106 ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft AB Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 18 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 18 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 18 Softomate Toolbar Object Recognized! Type : RegValue Data : TAC Rating : 9 Category : Data Miner Comment : Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\internet explorer\toolbar Value : {c1b4dec2-2623-438e-9ca2-c9043ab28508} Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie Object Recognized! Type : IECache Entry Data : ali@ad.uk.tangozebra[1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:1 Value : Cookie:ali@ad.uk.tangozebra.com/a Expires : 01-01-2035 01:00:00 LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 1 Objects found so far: 20 Deep scanning and examining files (C »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie Object Recognized! Type : IECache Entry Data : ali@ad.uk.tangozebra[1].txt TAC Rating : 3 Category : Data Miner Comment : Value : C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Cookies\Low\ali@ad.uk.tangozebra[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : ali@adbrite[2].txt TAC Rating : 3 Category : Data Miner Comment : Value : C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Cookies\Low\ali@adbrite[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : ali@adtech[2].txt TAC Rating : 3 Category : Data Miner Comment : Value : C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Cookies\Low\ali@adtech[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : ali@as-us.falkag[2].txt TAC Rating : 3 Category : Data Miner Comment : Value : C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Cookies\Low\ali@as-us.falkag[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : ali@bs.serving-sys[2].txt TAC Rating : 3 Category : Data Miner Comment : Value : C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Cookies\Low\ali@bs.serving-sys[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : ali@e-2dj6wbkoaiazoho.stats.esomniture[2].txt TAC Rating : 3 Category : Data Miner Comment : Value : C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Cookies\Low\ali@e-2dj6wbkoaiazoho.stats.esomniture[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : ali@msnaccountservices.112.2o7[1].txt TAC Rating : 3 Category : Data Miner Comment : Value : C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Cookies\Low\ali@msnaccountservices.112.2o7[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : ali@questionmarket[1].txt TAC Rating : 3 Category : Data Miner Comment : Value : C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Cookies\Low\ali@questionmarket[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : ali@serving-sys[2].txt TAC Rating : 3 Category : Data Miner Comment : Value : C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Cookies\Low\ali@serving-sys[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : ali@specificclick[2].txt TAC Rating : 3 Category : Data Miner Comment : Value : C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Cookies\Low\ali@specificclick[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : ali@tribalfusion[1].txt TAC Rating : 3 Category : Data Miner Comment : Value : C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Cookies\Low\ali@tribalfusion[1].txt Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 31 Performing conditional scans... »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 31 19:25:36 Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:14:08.939 Objects scanned:240346 Objects identified:13 Objects ignored:0 New critical objects:13
I got that stuff right after I installed AOL software and it only comes up on my Adaware Scans...nothing else...but watever it is is is messing my PC all up