Ad-Aware SE Build 1.06r1
Logfile Created on:4 stycznia 2006 21:46:06
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R47 24.05.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
CrackSpider(TAC index:4):8 total references
DyFuCA(TAC index:3):25 total references
istbar(TAC index:7):6 total references
Possible Browser Hijack attempt(TAC index:3):5 total references
Powerscan(TAC index:5):5 total references
SideFind(TAC index:5):7 total references
Tracking Cookie(TAC index:3):13 total references
ZyncosMark(TAC index:3):1 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
2006-01-04 21:46:06 - Scan started. (Full System Scan)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
    FilePath           : \SystemRoot\System32\
    ProcessID          : 540
    ThreadCreationTime : 2006-01-04 19:47:57
    BasePriority       : Normal
#:2 [csrss.exe]
    FilePath           : \??\D:\WINDOWS\system32\
    ProcessID          : 604
    ThreadCreationTime : 2006-01-04 19:47:59
    BasePriority       : Normal
#:3 [winlogon.exe]
    FilePath           : \??\D:\WINDOWS\system32\
    ProcessID          : 632
    ThreadCreationTime : 2006-01-04 19:48:00
    BasePriority       : High
#:4 [services.exe]
    FilePath           : D:\WINDOWS\system32\
    ProcessID          : 676
    ThreadCreationTime : 2006-01-04 19:48:01
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : System operacyjny Microsoft® Windows®
    CompanyName        : Microsoft Corporation
    FileDescription    : Usługi i aplikacja Kontroler
    InternalName       : services.exe
    LegalCopyright     : © Microsoft Corporation. Wszelkie prawa zastrzeżone.
    OriginalFilename   : services.exe
#:5 [lsass.exe]
    FilePath           : D:\WINDOWS\system32\
    ProcessID          : 688
    ThreadCreationTime : 2006-01-04 19:48:01
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : LSA Shell (Export Version)
    InternalName       : lsass.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : lsass.exe
#:6 [ati2evxx.exe]
    FilePath           : D:\WINDOWS\System32\
    ProcessID          : 844
    ThreadCreationTime : 2006-01-04 19:48:01
    BasePriority       : Normal
    FileVersion        : 6.14.10.4121
    ProductVersion     : 6.14.10.4121
    ProductName        : ATI External Event Utility for WindowsNT and Windows9X
    CompanyName        : ATI Technologies Inc.
    FileDescription    : ATI External Event Utility EXE Module
    InternalName       : ATI2EVXX.EXE
    LegalCopyright     : Copyright © 1999-2004 ATI Technologies Inc.
    OriginalFilename   : ATI2EVXX.EXE
#:7 [svchost.exe]
    FilePath           : D:\WINDOWS\system32\
    ProcessID          : 856
    ThreadCreationTime : 2006-01-04 19:48:01
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe
#:8 [svchost.exe]
    FilePath           : D:\WINDOWS\system32\
    ProcessID          : 948
    ThreadCreationTime : 2006-01-04 19:48:02
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe
#:9 [svchost.exe]
    FilePath           : D:\WINDOWS\System32\
    ProcessID          : 1044
    ThreadCreationTime : 2006-01-04 19:48:02
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe
#:10 [svchost.exe]
    FilePath           : D:\WINDOWS\System32\
    ProcessID          : 1088
    ThreadCreationTime : 2006-01-04 19:48:02
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe
#:11 [svchost.exe]
    FilePath           : D:\WINDOWS\System32\
    ProcessID          : 1148
    ThreadCreationTime : 2006-01-04 19:48:02
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe
#:12 [spoolsv.exe]
    FilePath           : D:\WINDOWS\system32\
    ProcessID          : 1524
    ThreadCreationTime : 2006-01-04 19:48:03
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
    ProductVersion     : 5.1.2600.2696
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Spooler SubSystem App
    InternalName       : spoolsv.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : spoolsv.exe
#:13 [ati2evxx.exe]
    FilePath           : D:\WINDOWS\system32\
    ProcessID          : 1544
    ThreadCreationTime : 2006-01-04 19:48:03
    BasePriority       : Normal
    FileVersion        : 6.14.10.4121
    ProductVersion     : 6.14.10.4121
    ProductName        : ATI External Event Utility for WindowsNT and Windows9X
    CompanyName        : ATI Technologies Inc.
    FileDescription    : ATI External Event Utility EXE Module
    InternalName       : ATI2EVXX.EXE
    LegalCopyright     : Copyright © 1999-2004 ATI Technologies Inc.
    OriginalFilename   : ATI2EVXX.EXE
#:14 [explorer.exe]
    FilePath           : D:\WINDOWS\
    ProcessID          : 1644
    ThreadCreationTime : 2006-01-04 19:48:03
    BasePriority       : Normal
    FileVersion        : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 6.00.2900.2180
    ProductName        : System operacyjny Microsoft® Windows®
    CompanyName        : Microsoft Corporation
    FileDescription    : Eksplorator Windows
    InternalName       : explorer
    LegalCopyright     : © Microsoft Corporation. Wszelkie prawa zastrzeżone.
    OriginalFilename   : EXPLORER.EXE
#:15 [atiptaxx.exe]
    FilePath           : D:\Program Files\ATI Technologies\ATI Control Panel\
    ProcessID          : 1720
    ThreadCreationTime : 2006-01-04 19:48:05
    BasePriority       : Normal
    FileVersion        : 6.14.10.5006
    ProductVersion     : 6.14.10.5006
    ProductName        : ATI Desktop Component
    CompanyName        : ATI Technologies, Inc.
    FileDescription    : ATI Desktop Control Panel
    InternalName       : Atiptaxx.exe
    LegalCopyright     : Copyright (C) 1998-2002 ATI Technologies Inc.
    OriginalFilename   : Atiptaxx.exe
#:16 [abmenu.exe]
    FilePath           : D:\Program Files\ArcaVir\Bin\
    ProcessID          : 1728
    ThreadCreationTime : 2006-01-04 19:48:05
    BasePriority       : Normal
    FileVersion        : 1, 0, 0, 1
    ProductVersion     : 1, 0, 0, 1
    ProductName        : ArcaVir Tray
    CompanyName        : ArcaBit
    FileDescription    : ArcaVir Tray
    InternalName       : ABMenu
    LegalCopyright     : Copyright (C) 1997
    OriginalFilename   : ABMenu.exe
#:17 [abregmon.exe]
    FilePath           : D:\Program Files\ArcaVir\Bin\
    ProcessID          : 1736
    ThreadCreationTime : 2006-01-04 19:48:05
    BasePriority       : Normal
    FileVersion        : 1, 0, 0, 1
    ProductVersion     : 1, 0, 0, 1
    ProductName        : Registry Monitor
    CompanyName        : ArcaBit
    FileDescription    : Registry Monitor
    InternalName       : Registry Monitor
    LegalCopyright     : Copyright (C) 2005
    OriginalFilename   : Registry Monitor
#:18 [skype.exe]
    FilePath           : D:\Program Files\Skype\Phone\
    ProcessID          : 1832
    ThreadCreationTime : 2006-01-04 19:48:05
    BasePriority       : Normal
#:19 [tlen.exe]
    FilePath           : D:\Program Files\Tlen.pl\
    ProcessID          : 1868
    ThreadCreationTime : 2006-01-04 19:48:06
    BasePriority       : High
#:20 [gg.exe]
    FilePath           : D:\Program Files\Gadu-Gadu\
    ProcessID          : 1876
    ThreadCreationTime : 2006-01-04 19:48:06
    BasePriority       : Normal
#:21 [netmonsv.exe]
    FilePath           : D:\Program Files\ArcaVir\Bin\
    ProcessID          : 1992
    ThreadCreationTime : 2006-01-04 19:48:12
    BasePriority       : Normal
    FileVersion        : 1, 2, 0, 1
    ProductVersion     : 1, 2, 0, 1
    ProductName        : ArcaBit Net Monitor
    CompanyName        : ArcaBit sp. z o.o.
    FileDescription    : NetMonSV
    InternalName       : NetMonSV
    LegalCopyright     : Copyright © 2004
    OriginalFilename   : NetMonSV.exe
    Comments           : Kontroluje dane przesyłane przez TCP/IP.
#:22 [imapp.exe]
    FilePath           : D:\PROGRA~1\INCRED~1\bin\
    ProcessID          : 2000
    ThreadCreationTime : 2006-01-04 19:48:12
    BasePriority       : Normal
    FileVersion        : 4, 5, 0, 2068
    ProductVersion     : 4, 5, 0, 2068
    ProductName        : IncrediMail
    CompanyName        : IncrediMail, Ltd.
    FileDescription    : IncrediMail Application
    InternalName       : IncrediApp
    LegalCopyright     : Copyright © 2002 IncrediMail, Ltd.
    OriginalFilename   : IMAPP.EXE
#:23 [avmonsv.exe]
    FilePath           : D:\Program Files\ArcaVir\Bin\
    ProcessID          : 2040
    ThreadCreationTime : 2006-01-04 19:48:12
    BasePriority       : Normal
    FileVersion        : 1, 0, 0, 1
    ProductVersion     : 1, 0, 0, 1
    ProductName        : ArcaVir
    CompanyName        : ArcaBit
    FileDescription    : ArcaVir Antivirus Monitor
    InternalName       : ArcaVir Monitor Service
    LegalCopyright     : Copyright (C) 2005
    OriginalFilename   : ArcaVir Monitor Service
#:24 [mdm.exe]
    FilePath           : D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\
    ProcessID          : 332
    ThreadCreationTime : 2006-01-04 19:48:13
    BasePriority       : Normal
    FileVersion        : 7.00.9466
    ProductVersion     : 7.00.9466
    ProductName        : Microsoft® Visual Studio .NET
    CompanyName        : Microsoft Corporation
    FileDescription    : Machine Debug Manager
    InternalName       : mdm.exe
    LegalCopyright     : © Microsoft Corporation.  All rights reserved.
    OriginalFilename   : mdm.exe
#:25 [sqlservr.exe]
    FilePath           : D:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\
    ProcessID          : 436
    ThreadCreationTime : 2006-01-04 19:48:15
    BasePriority       : Normal
    FileVersion        : 2000.080.0760.00
    ProductVersion     : 8.00.760
    ProductName        : Microsoft SQL Server
    CompanyName        : Microsoft Corporation
    FileDescription    : SQL Server Windows NT
    InternalName       : SQLSERVR
    LegalCopyright     : © 1988-2003 Microsoft Corp. All rights reserved.
    LegalTrademarks    : Microsoft® is a registered trademark of Microsoft Corporation. Windows(TM) is a trademark of Microsoft Corporation
    OriginalFilename   : SQLSERVR.EXE
    Comments           : NT INTEL X86
#:26 [svchost.exe]
    FilePath           : D:\WINDOWS\System32\
    ProcessID          : 988
    ThreadCreationTime : 2006-01-04 19:48:20
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe
#:27 [alg.exe]
    FilePath           : D:\WINDOWS\System32\
    ProcessID          : 1100
    ThreadCreationTime : 2006-01-04 19:49:48
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Application Layer Gateway Service
    InternalName       : ALG.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : ALG.exe
#:28 [arcascan.exe]
    FilePath           : D:\Program Files\ArcaVir\Bin\
    ProcessID          : 2172
    ThreadCreationTime : 2006-01-04 19:49:52
    BasePriority       : Normal
    FileVersion        : 1, 0, 0, 1
    ProductVersion     : 1, 0, 0, 1
    ProductName        : ArcaBit Scanner Component
    CompanyName        : ArcaBit
    FileDescription    : ArcaBit Scanner Component
    InternalName       : ArcaScan
    LegalCopyright     : Copyright 2004
    OriginalFilename   : ArcaScan.exe
#:29 [iexplore.exe]
    FilePath           : D:\Program Files\Internet Explorer\
    ProcessID          : 2764
    ThreadCreationTime : 2006-01-04 19:51:13
    BasePriority       : Normal
    FileVersion        : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 6.00.2900.2180
    ProductName        : System operacyjny Microsoft® Windows®
    CompanyName        : Microsoft Corporation
    FileDescription    : Internet Explorer
    InternalName       : iexplore
    LegalCopyright     : © Microsoft Corporation. Wszelkie prawa zastrzeżone.
    OriginalFilename   : IEXPLORE.EXE
#:30 [iexplore.exe]
    FilePath           : D:\Program Files\Internet Explorer\
    ProcessID          : 3052
    ThreadCreationTime : 2006-01-04 19:54:11
    BasePriority       : Normal
    FileVersion        : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 6.00.2900.2180
    ProductName        : System operacyjny Microsoft® Windows®
    CompanyName        : Microsoft Corporation
    FileDescription    : Internet Explorer
    InternalName       : iexplore
    LegalCopyright     : © Microsoft Corporation. Wszelkie prawa zastrzeżone.
    OriginalFilename   : IEXPLORE.EXE
#:31 [dap.exe]
    FilePath           : D:\PROGRA~1\DAP\
    ProcessID          : 3664
    ThreadCreationTime : 2006-01-04 19:59:17
    BasePriority       : Normal
    FileVersion        : 7, 4, 0, 1
    ProductVersion     : 7, 4, 0, 1
    ProductName        : Download Accelerator Plus 
    CompanyName        : Speedbit Ltd.
    FileDescription    : Download Accelerator Plus
    InternalName       : DAP
    LegalCopyright     : Copyright (C) 1999 - 2005 Speedbit Ltd.
    OriginalFilename   : DAP.EXE
    Comments           : 59
#:32 [ad-aware.exe]
    FilePath           : D:\PROGRA~1\Lavasoft\AD-AWA~1\
    ProcessID          : 2100
    ThreadCreationTime : 2006-01-04 20:44:45
    BasePriority       : Normal
    FileVersion        : 6.2.0.236
    ProductVersion     : SE 106
    ProductName        : Lavasoft Ad-Aware SE
    CompanyName        : Lavasoft Sweden
    FileDescription    : Ad-Aware SE Core application
    InternalName       : Ad-Aware.exe
    LegalCopyright     : Copyright © Lavasoft AB Sweden
    OriginalFilename   : Ad-Aware.exe
    Comments           : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
 CrackSpider Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 4
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_CLASSES_ROOT
    Object             : addressbar.loader
 CrackSpider Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 4
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_CLASSES_ROOT
    Object             : addressbar.loader.1
 CrackSpider Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 4
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_CLASSES_ROOT
    Object             : clsid\{f65b197f-8260-4d52-909a-f70118e646eb}
 CrackSpider Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 4
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_CLASSES_ROOT
    Object             : interface\{38252777-2500-456e-8b3d-a55850306da2}
 CrackSpider Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 4
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_CLASSES_ROOT
    Object             : typelib\{dea43ce3-d57b-45f6-a4d1-110e652ced11}
 istbar Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 7
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_CLASSES_ROOT
    Object             : typelib\{67907b3c-a6ef-4a01-99ad-3fcd5f526429}
 istbar Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 7
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_CLASSES_ROOT
    Object             : interface\{0985c112-2562-46f2-8da6-92648ba4630f}
 SideFind Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 5
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_CLASSES_ROOT
    Object             : clsid\{8cba1b49-8144-4721-a7b1-64c578c9eed7}
 SideFind Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 5
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_CLASSES_ROOT
    Object             : typelib\{58634367-d62b-4c2c-86be-5aac45cdb671}
 SideFind Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 5
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_CLASSES_ROOT
    Object             : typelib\{d0288a41-9855-4a9b-8316-babe243648da}
 ZyncosMark Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : 
    Rootkey            : HKEY_CLASSES_ROOT
    Object             : clsid\{dc341f1b-ec77-47be-8f58-96e83861cc5a}
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-21-583907252-926492609-725345543-1003\software\policies\avenue media
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-21-583907252-926492609-725345543-1003\software\ist
 DyFuCA Object Recognized!
    Type               : RegValue
    Data               : 
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-21-583907252-926492609-725345543-1003\software\ist
    Value              : account_id
 DyFuCA Object Recognized!
    Type               : RegValue
    Data               : 
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-21-583907252-926492609-725345543-1003\software\ist
    Value              : config
 DyFuCA Object Recognized!
    Type               : RegValue
    Data               : 
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-21-583907252-926492609-725345543-1003\software\ist
    Value              : referer
 DyFuCA Object Recognized!
    Type               : RegValue
    Data               : 
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-21-583907252-926492609-725345543-1003\software\ist
    Value              : NeverISTsvc
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-21-583907252-926492609-725345543-1003\software\avenue media
 CrackSpider Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 4
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\azesearchco
 CrackSpider Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 4
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\loaderco
 CrackSpider Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 4
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\microsoft\windows\currentversion\explorer\browser helper objects\{f65b197f-8260-4d52-909a-f70118e646eb}
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\policies\avenue media
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\microsoft\windows\currentversion\uninstall\dyfuca
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : DyFuCA
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : .DEFAULT\software\microsoft\windows\currentversion\uninstall\DyFuCA
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : DyFuCA
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-18\software\microsoft\windows\currentversion\uninstall\DyFuCA
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : DyFuCA
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-19\software\microsoft\windows\currentversion\uninstall\DyFuCA
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : DyFuCA
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-20\software\microsoft\windows\currentversion\uninstall\DyFuCA
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : DyFuCA
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-21-583907252-926492609-725345543-1003\software\microsoft\windows\currentversion\uninstall\DyFuCA
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : Internet Optimizer
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : .DEFAULT\software\microsoft\windows\currentversion\uninstall\Internet Optimizer
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : Internet Optimizer
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-18\software\microsoft\windows\currentversion\uninstall\Internet Optimizer
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : Internet Optimizer
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-19\software\microsoft\windows\currentversion\uninstall\Internet Optimizer
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : Internet Optimizer
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-20\software\microsoft\windows\currentversion\uninstall\Internet Optimizer
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : Internet Optimizer
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_USERS
    Object             : S-1-5-21-583907252-926492609-725345543-1003\software\microsoft\windows\currentversion\uninstall\Internet Optimizer
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : Internet Optimizer
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\microsoft\windows\currentversion\uninstall\Internet Optimizer
 DyFuCA Object Recognized!
    Type               : RegValue
    Data               : Internet Optimizer
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\microsoft\windows\currentversion\uninstall\Internet Optimizer
    Value              : UninstallString
 DyFuCA Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 3
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\avenue media
 SideFind Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 5
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\microsoft\sidefind
 SideFind Object Recognized!
    Type               : RegValue
    Data               : 
    TAC Rating         : 5
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\microsoft\sidefind
    Value              : shoppingautosearch
 Powerscan Object Recognized!
    Type               : RegValue
    Data               : 
    TAC Rating         : 5
    Category           : Malware
    Comment            : "account_id"
    Rootkey            : HKEY_USERS
    Object             : S-1-5-21-583907252-926492609-725345543-1003\software\powerscan
    Value              : account_id
 Powerscan Object Recognized!
    Type               : RegValue
    Data               : 
    TAC Rating         : 5
    Category           : Malware
    Comment            : "LoadNum"
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\powerscan
    Value              : LoadNum
 Powerscan Object Recognized!
    Type               : RegValue
    Data               : 
    TAC Rating         : 5
    Category           : Malware
    Comment            : "account_id"
    Rootkey            : HKEY_USERS
    Object             : S-1-5-21-583907252-926492609-725345543-1003\\software\powerscan
    Value              : account_id
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 41
Objects found so far: 41
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Possible Browser Hijack attempt : S-1-5-21-583907252-926492609-725345543-1003\Software\Microsoft\Internet Explorer\MainStart Pageonet.pl
 Possible Browser Hijack attempt Object Recognized!
    Type               : RegData
    Data               : "http://www.onet.pl/"
    TAC Rating         : 5
    Category           : Malware
    Comment            : Possible Browser Hijack attempt
    Rootkey            : HKEY_USERS
    Object             : S-1-5-21-583907252-926492609-725345543-1003\Software\Microsoft\Internet Explorer\Main
    Value              : Start Page
    Data               : "http://www.onet.pl/"
Trusted zone presumably compromised : searchmeup.com
 Possible Browser Hijack attempt Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 5
    Category           : Vulnerability
    Comment            : Trusted zone presumably compromised : searchmeup.com
    Rootkey            : HKEY_CURRENT_USER
    Object             : Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmeup.com
Trusted zone presumably compromised : searchmeup.com
Trusted zone presumably compromised : contentmatch.net
 Possible Browser Hijack attempt Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 5
    Category           : Vulnerability
    Comment            : Trusted zone presumably compromised : contentmatch.net\ny
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\contentmatch.net\ny
 Possible Browser Hijack attempt Object Recognized!
    Type               : RegValue
    Data               : 
    TAC Rating         : 5
    Category           : Vulnerability
    Comment            : Trusted zone presumably compromised : contentmatch.net\ny
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\contentmatch.net\ny
    Value              : https
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 4
Objects found so far: 45
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : a@tribalfusion[1].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : Hits:1
    Value              : Cookie:a@tribalfusion.com/
    Expires            : 2038-01-01 01:00:00
    LastSync           : Hits:1
    UseCount           : 0
    Hits               : 1
 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : a@tradedoubler[2].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : Hits:8
    Value              : Cookie:a@tradedoubler.com/
    Expires            : 2025-12-30 20:31:38
    LastSync           : Hits:8
    UseCount           : 0
    Hits               : 8
 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : a@casalemedia[1].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : Hits:19
    Value              : Cookie:a@casalemedia.com/
    Expires            : 2006-12-26 15:32:14
    LastSync           : Hits:19
    UseCount           : 0
    Hits               : 19
 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : a@mediaplex[1].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : Hits:1
    Value              : Cookie:a@mediaplex.com/
    Expires            : 2009-06-22 01:00:00
    LastSync           : Hits:1
    UseCount           : 0
    Hits               : 1
 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : a@trafic[1].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : Hits:1
    Value              : Cookie:a@trafic.ro/
    Expires            : 2037-01-11 15:00:00
    LastSync           : Hits:1
    UseCount           : 0
    Hits               : 1
 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : a@please[1].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : Hits:1
    Value              : Cookie:a@ad2.pl.mediainter.net/please/
    Expires            : 2006-12-03 20:32:16
    LastSync           : Hits:1
    UseCount           : 0
    Hits               : 1
 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : 
a@servedby.netshelter[1].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : Hits:1
    Value              : Cookie:a@servedby.netshelter.net/
    Expires            : 2006-01-12 01:20:38
    LastSync           : Hits:1
    UseCount           : 0
    Hits               : 1
 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : 
a@adserver.o2[1].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : Hits:16
    Value              : Cookie:a@adserver.o2.pl/
    Expires            : 2008-09-02 03:37:52
    LastSync           : Hits:16
    UseCount           : 0
    Hits               : 16
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 8
Objects found so far: 53
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : ktos@doubleclick[2].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : 
    Value              : C:\WINDOWS\Cookies\ktos@doubleclick[2].txt
 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : ktos@hitbox[2].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : 
    Value              : C:\WINDOWS\Cookies\ktos@hitbox[2].txt
 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : 
ktos@ehg-ati.hitbox[2].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : 
    Value              : C:\WINDOWS\Cookies\ktos@ehg-ati.hitbox[2].txt
 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : ktos@please[1].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : 
    Value              : C:\WINDOWS\Cookies\ktos@please[1].txt
 Tracking Cookie Object Recognized!
    Type               : IECache Entry
    Data               : ktos@please[2].txt
    TAC Rating         : 3
    Category           : Data Miner
    Comment            : 
    Value              : C:\WINDOWS\Cookies\ktos@please[2].txt
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 58
Deep scanning and examining files (D:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for D:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 58
Deep scanning and examining files (E:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for E:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 58
Scanning Hosts file......
Hosts file location:"D:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 58
 Possible Browser Hijack attempt Object Recognized!
    Type               : File
    Data               : CRACKS.AM - Page A.url
    TAC Rating         : 3
    Category           : Misc
    Comment            : Problematic URL discovered: http://www.cracks.am/cracks/a.html
    Object             : D:\Documents and Settings\A\Ulubione\
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
 istbar Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 7
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_CLASSES_ROOT
    Object             : aspfile\persistenthandler
 istbar Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 7
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\microsoft\downloadmanager
 istbar Object Recognized!
    Type               : RegData
    Data               : Never
    TAC Rating         : 7
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_CURRENT_USER
    Object             : software\microsoft\internet explorer\main
    Value              : BandRest
    Data               : Never
 istbar Object Recognized!
    Type               : RegData
    Data               : Never
    TAC Rating         : 7
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_LOCAL_MACHINE
    Object             : software\microsoft\internet explorer\main
    Value              : BandRest
    Data               : Never
 SideFind Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 5
    Category           : Malware
    Comment            : 
    Rootkey            : HKEY_CLASSES_ROOT
    Object             : interface\{339d8aff-0b42-4260-ad82-78ce605a9543}
 SideFind Object Recognized!
    Type               : Regkey
    Data               : 
    TAC Rating         : 5
    Category           : Malware
    Comment            : 
    Rootkey