ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 3:26:42 PM, 7/5/2005
+ Report-Checksum: 7896E4A5
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{38D4D5D0-423E-4220-B6F9-30918C2AE4A4} -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BEB133E5-FD72-43b7-8AFF-681831CC72D9} -> Spyware.Hijacker.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{8EA362BD-39CB-40F5-9226-73CD40999095} -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BEB133E5-FD72-43b7-8AFF-681831CC72D9} -> Spyware.Hijacker.Generic : Cleaned with backup
HKU\S-1-5-21-1229272821-842925246-854245398-1004\Software\intexp -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1229272821-842925246-854245398-1004\Software\intexp\Config -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1229272821-842925246-854245398-1004\Software\intexp\MyFileSystem2 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1229272821-842925246-854245398-1004\Software\WareOut -> TrojanDownloader.Wareout : Cleaned with backup
HKU\S-1-5-21-1229272821-842925246-854245398-1004\Software\WareOut\FirstRun -> TrojanDownloader.Wareout : Cleaned with backup
HKU\S-1-5-21-1229272821-842925246-854245398-1004\Software\WareOut\Options -> TrojanDownloader.Wareout : Cleaned with backup
HKU\S-1-5-21-1229272821-842925246-854245398-1004\Software\WareOut\Registration -> TrojanDownloader.Wareout : Cleaned with backup
[3656] VM_02C70000 -> Adware.BetterInternet : Error during cleaning
C:\WINDOWS\system32\nnjdsxw.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\drv2cltr.dll -> TrojanSpy.Agent.am : Cleaned with backup
C:\WINDOWS\system32\rdsndin.exe -> Spyware.FindSpy : Cleaned with backup
C:\WINDOWS\system32\DrPMon.dll -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\DrPMon.dll_tobedeleted -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\uixazw.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\wupdt.exe -> TrojanDownloader.Intexp.c : Cleaned with backup
C:\WINDOWS\zhdnmnwnb.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\tdtb.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\systb.dll -> Spyware.ImiBar : Cleaned with backup
C:\WINDOWS\sasetup.dll -> Heuristic.Win32.Hijacker1 : Cleaned with backup
C:\WINDOWS\svcproc.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\Nail.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\ISTSVC.EXE -> TrojanDownloader.IstBar.k : Cleaned with backup
:mozilla.6:C:\Documents and Settings\mcdolej\Application Data\Mozilla\Profiles\default\f2lbz20b.slt\cookies.txt -> Spyware.Cookie.Specificpop : Cleaned with backup
:mozilla.7:C:\Documents and Settings\mcdolej\Application Data\Mozilla\Profiles\default\f2lbz20b.slt\cookies.txt -> Spyware.Cookie.Specificpop : Cleaned with backup
C:\Program Files\Common Files\aolback\Comps\coach\aolcinst.exe/data\player\aolnysev.exe -> Heuristic.Win32.Hijacker1 : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP310\A0054175.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP310\A0054216.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP310\A0054218.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP310\A0054228.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP310\A0054234.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP310\A0055223.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP310\A0055228.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP310\A0056223.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP310\A0056228.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP310\A0057223.exe -> TrojanDropper.Vidro.p : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP310\A0058227.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP310\A0058229.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP310\A0058237.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP316\A0060593.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP316\A0060625.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP316\A0060629.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP312\A0058334.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP312\A0058335.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP312\A0058374.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP312\A0058376.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP312\A0059346.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP312\A0059348.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP312\A0059352.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP312\A0059363.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP312\A0059370.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP312\A0059372.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP312\A0059402.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP312\A0059404.exe -> TrojanDownloader.Small.ajn : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP313\A0059414.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP313\A0059441.exe -> Heuristic.Win32.Hijacker1 : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP313\A0060370.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP313\A0060372.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP313\A0060394.exe -> TrojanDownloader.Intexp.c : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060750.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060796.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060798.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060808.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060816.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060819.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060823.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060824.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060825.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060826.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060849.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060851.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060869.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060871.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060875.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060910.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060914.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060918.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060919.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060920.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060921.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060928.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060930.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP319\A0060933.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP320\A0060950.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP320\A0060953.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP320\A0060959.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP320\A0060960.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP320\A0060964.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP320\A0060971.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP320\A0060974.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP320\A0060976.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP320\A0060983.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP320\A0060984.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP320\A0060991.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP320\A0060993.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0061460.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0061462.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0061497.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0061499.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0061505.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0062498.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0062502.dll -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0062510.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0062667.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0062692.exe -> Trojan.Starter : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0062693.exe -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0062694.dll -> Spyware.SBSoft : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0062695.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0063009.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0063010.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0063011.dll -> Heuristic.Win32.Hijacker1 : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0063012.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\System Volume Information\_restore{8E3B3A85-BE7E-444C-8C23-C2B5AC40B31E}\RP322\A0063013.exe -> TrojanDownloader.IstBar.l : Cleaned with backup
Logfile of HijackThis v1.99.1
Scan saved at 4:46:17 PM, on 7/5/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Atievxx.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\hijackthis\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - {0578DB05-D81E-B608-36C0-0D3959E4D1A9} - forces_elite.dll (file missing)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O3 - Toolbar: (no name) - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [msag] browsebar.exe
O4 - HKLM\..\Run: [control64] runload32.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [nwphdd] c:\windows\system32\vchbkah.exe r
O4 - HKLM\..\Run: [tvxtcf] c:\windows\system32\qhzuji.exe r
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy1\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [WareOut] "C:\Program Files\WareOut\WareOut.exe"
O4 - HKCU\..\Run: [SYSTRAV] bhoserv.exe
O4 - HKCU\..\Run: [driver32] 34763.exe
O4 - HKCU\..\Run: [JAguAr] keybdll.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: KeyAccess.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .csm: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .csml: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cub: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cube: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .dx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .emb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .embl: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .gau: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .jdx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mol: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mop: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .pdb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .rxn: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .scr: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .skc: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .spt: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .tgf: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .xyz: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = berea.edu
O17 - HKLM\Software\..\Telephony: DomainName = berea.edu
O17 - HKLM\System\CCS\Services\Tcpip\..\{A0B1B47D-AEFB-4858-92AB-D5869E116233}: NameServer = 69.50.176.196,195.225.176.110
O18 - Protocol: ncbi8 - {2B576DD3-0B3E-4718-BCBF-B15E4FB8009D} - C:\Program Files\Informax\Vector NTI Suite 9\Ncbi.dll
O20 - AppInit_DLLs: KATRACK.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O21 - SSODL: systemp - {F19F8B11-98A1-4D7C-9032-AAF5B32245D6} - systemp.dll (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe