Quick description of the problem:
! was getting an uncontrollable number of pop-ups. A Mirbar toolbar or something along that name installed itself every time I restarted. Some how my windows firewall was disabled and I got error messages when I tried to go through control panel to enable it.
Overview of what I have tried:
-Update and scan w/Symantec Anti-Virus version 9
- Ran Ad-Ware
- Ran Spybot Search and Destroy
- Used Symantec's FixWebHancer tool
- Deleted suspicious entries found using Hijack This based on previous posts on geekstogo
- Installed BitDefender Client Standard
- Installed ewido anti-malware
(I ran all of the above in normal mode as well as safemode)
The above helped solve a lot of the problems, and at least makes the system usable, but its still not back to normal, and I'm worried about making purchases online as well as filling out my taxes!
Here are the details I think will help get to the root of the problem:
-usbdrivr098.exe appears in C: and BitDefender 'blocks' it every time I open my computer. The msg says it is Trojan.LowZones.G I cannot delete the file mannualy as it is in use.
-No matter how many times I run SpyBot the following always appear: Command Service, FastClick, and MediaPlex
Below is my HiJack This Log and a spybot log. If someone can guide me along the steps to fix this they way I tried to follow in other people's post, it would be greatly appreciated. I've spent HOURS trying to clean my PC of all this Malware, but can't seem to get past the last few issues.
Thanks in advance!
HiJack This Log:
Logfile of HijackThis v1.99.1
Scan saved at 1:41:16 AM, on 2/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Symantec AntiVirus CE 9.0.1\DefWatch.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\MSREMO~1\NetCfgSv.EXE
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\Program Files\Symantec AntiVirus CE 9.0.1\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1.1\VPTray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\program files\softwin\bitdefender8\bdnagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\Banshee Screamer Alarm\alarm.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender8\vsserv.exe
c:\program files\softwin\bitdefender8\bdmcon.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Trecker Class - {39C78B50-7E98-4aa0-B007-D83114EA6E0F} - C:\PROGRA~1\Jalmp\jalmp.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1.1\VPTray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [HydraVisionViewport] C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraMD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Microsoft System Support] spool.exe
O4 - HKLM\..\Run: [winsysupd] C:\windows\winsysupd5.exe
O4 - HKLM\..\Run: [winsysban] C:\\winsysban5.exe
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender8\bdmcon.exe"
O4 - HKLM\..\Run: [BDNewsAgent] "c:\program files\softwin\bitdefender8\bdnagent.exe"
O4 - HKLM\..\RunServices: [Microsoft System Support] spool.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.EXE
O4 - HKCU\..\Run: [ATI Launchpad] C:\Program Files\ATI Multimedia\main\launchpd.exe
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [ATI Scheduler] C:\Program Files\ATI Multimedia\main\ATISched.EXE
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Microsoft System Support] spool.exe
O4 - Startup: Banshee Screamer Alarm.lnk = C:\Program Files\Banshee Screamer Alarm\alarm.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {13AE2BC6-2F8A-4AFC-8116-2946938A4CE4} (ActiveWyncs Control) - http://www.newjerseydevils.com/2005/html/f...ActiveWyncs.cab
O16 - DPF: {3BA494B1-D507-4C11-9BDA-D47E1A65DFCF} (Confidence Online Enterprise Edition) - https://portal.morganstanley.com/llclient/p...ms.com,CT=java+
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://portal.morganstanley.com/dana-cache...oterisSetup.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.del...t/TLIEFlash.CAB
O18 - Filter: text/html - {2F6E85DC-8D2D-4896-8A4F-7DF8A7B1749D} - C:\PROGRA~1\Jalmp\jalmp.dll
O20 - AppInit_DLLs: sockspy.dll
O20 - Winlogon Notify: MCD - C:\WINDOWS\system32\VLAR332.DLL (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus CE 9.0.1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\MSREMO~1\NetCfgSv.EXE
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus CE 9.0.1\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus CE 9.0.1\Rtvscan.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender8\vsserv.exe" /service (file missing)
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
Spybot Log:
--- Search result list ---
Command Service: System Service (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService
Command Service: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService
Command Service: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService
FastClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
FastClick: Tracking cookie (Firefox: default) (Cookie, nothing done)
MediaPlex: Tracking cookie (Firefox: default) (Cookie, nothing done)
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2006-02-05 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2005-05-31 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2005-05-31 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-02-03 Includes\Cookies.sbi (*)
2006-02-03 Includes\Dialer.sbi (*)
2006-02-03 Includes\Hijackers.sbi (*)
2006-02-03 Includes\Keyloggers.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2006-02-03 Includes\Malware.sbi (*)
2006-02-03 Includes\PUPS.sbi (*)
2006-02-03 Includes\Revision.sbi (*)
2006-02-03 Includes\Security.sbi (*)
2006-02-03 Includes\Spybots.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-02-03 Includes\Trojans.sbi (*)
--- System information ---
Windows XP (Build: 2600) Service Pack 2
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB886903)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
/ Windows XP / SP3: Windows XP Hotfix - KB867282
/ Windows XP / SP3: Windows XP Hotfix - KB873333
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885250
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB887472
/ Windows XP / SP3: Windows XP Hotfix - KB887742
/ Windows XP / SP3: Windows XP Hotfix - KB887797
/ Windows XP / SP3: Windows XP Hotfix - KB888113
/ Windows XP / SP3: Windows XP Hotfix - KB888302
/ Windows XP / SP3: Security Update for Windows XP (KB890046)
/ Windows XP / SP3: Windows XP Hotfix - KB890047
/ Windows XP / SP3: Windows XP Hotfix - KB890175
/ Windows XP / SP3: Windows XP Hotfix - KB890859
/ Windows XP / SP3: Windows XP Hotfix - KB890923
/ Windows XP / SP3: Windows XP Hotfix - KB891781
/ Windows XP / SP3: Security Update for Windows XP (KB893066)
/ Windows XP / SP3: Windows XP Hotfix - KB893086
/ Windows XP / SP3: Security Update for Windows XP (KB893756)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Update for Windows XP (KB894391)
/ Windows XP / SP3: Hotfix for Windows XP (KB896344)
/ Windows XP / SP3: Security Update for Windows XP (KB896358)
/ Windows XP / SP3: Security Update for Windows XP (KB896422)
/ Windows XP / SP3: Security Update for Windows XP (KB896423)
/ Windows XP / SP3: Security Update for Windows XP (KB896424)
/ Windows XP / SP3: Security Update for Windows XP (KB896428)
/ Windows XP / SP3: Security Update for Windows XP (KB896688)
/ Windows XP / SP3: Update for Windows XP (KB896727)
/ Windows XP / SP3: Update for Windows XP (KB898461)
/ Windows XP / SP3: Security Update for Windows XP (KB899587)
/ Windows XP / SP3: Security Update for Windows XP (KB899588)
/ Windows XP / SP3: Security Update for Windows XP (KB899589)
/ Windows XP / SP3: Security Update for Windows XP (KB899591)
/ Windows XP / SP3: Security Update for Windows XP (KB900725)
/ Windows XP / SP3: Update for Windows XP (KB900930)
/ Windows XP / SP3: Security Update for Windows XP (KB901017)
/ Windows XP / SP3: Security Update for Windows XP (KB901214)
/ Windows XP / SP3: Security Update for Windows XP (KB902400)
/ Windows XP / SP3: Security Update for Windows XP (KB904706)
/ Windows XP / SP3: Security Update for Windows XP (KB905414)
/ Windows XP / SP3: Security Update for Windows XP (KB905749)
/ Windows XP / SP3: Security Update for Windows XP (KB905915)
/ Windows XP / SP3: Security Update for Windows XP (KB908519)
/ Windows XP / SP3: Update for Windows XP (KB910437)
/ Windows XP / SP3: Security Update for Windows XP (KB912919)
--- Startup entries list ---
Located: HK_LM:Run, ATICCC
command: "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
file: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
size: 32768
MD5: 2d510eaa846689443882367c37abc65e
Located: HK_LM:Run, BDMCon
command: "C:\Program Files\Softwin\BitDefender8\bdmcon.exe"
file: C:\Program Files\Softwin\BitDefender8\bdmcon.exe
size: 417792
MD5: 4aeccdb404437848325f045973e23e3c
Located: HK_LM:Run, BDNewsAgent
command: "c:\program files\softwin\bitdefender8\bdnagent.exe"
file: c:\program files\softwin\bitdefender8\bdnagent.exe
size: 8192
MD5: 641e3f9e3bd0856eb6c8f88f318df4d4
Located: HK_LM:Run, ccApp
command: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
file: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 66680
MD5: 05a76d9dd303def4dcc8ee18ee8c58b9
Located: HK_LM:Run, HP Component Manager
command: "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
file: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
size: 241664
MD5: b75b654ee1da99876461b24597ae3ff3
Located: HK_LM:Run, HP Software Update
command: C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
file: C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
size: 49152
MD5: 821f73b833c4daebc33c1a9a4b16bb5a
Located: HK_LM:Run, HPDJ Taskbar Utility
command: C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
file: C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
size: 176128
MD5: 31c21d0a32e06d7a5dddfce78414b2a0
Located: HK_LM:Run, HPHmon05
command: C:\WINDOWS\system32\hphmon05.exe
file: C:\WINDOWS\system32\hphmon05.exe
size: 491520
MD5: 78bee8060718100187484871b404b08a
Located: HK_LM:Run, HPHUPD05
command: c:\Program Files\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
file: c:\Program Files\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
size: 49152
MD5: b86ea852c1401e4aa744e2755b5b9903
Located: HK_LM:Run, HydraVisionDesktopManager
command: C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
file: C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
size: 270336
MD5: 44cd1a04bb7cebd3845eef2a7761e61d
Located: HK_LM:Run, HydraVisionViewport
command: C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraMD.exe
file: C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraMD.exe
size: 364544
MD5: bb4c82a0d561d7a415a59f55d6bee537
Located: HK_LM:Run, iTunesHelper
command: "C:\Program Files\iTunes\iTunesHelper.exe"
file: C:\Program Files\iTunes\iTunesHelper.exe
size: 274432
MD5: 1c2b9fcd48112b0297b83e7fc43d1b42
Located: HK_LM:Run, Logitech Utility
command: Logi_MwX.Exe
file: C:\WINDOWS\Logi_MwX.Exe
size: 19968
MD5: 34a14cd6b6e9c8bfbabeaf6eed5149bb
Located: HK_LM:Run, Microsoft System Support
command: spool.exe
file:
Located: HK_LM:Run, NeroFilterCheck
command: C:\WINDOWS\system32\NeroCheck.exe
file: C:\WINDOWS\system32\NeroCheck.exe
size: 155648
MD5: 3e4c03cefad8de135263236b61a49c90
Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 155648
MD5: 3e7d91f24d28c968b92c85c7e2882eed
Located: HK_LM:Run, RemoteControl
command: "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
file: C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
size: 32768
MD5: 8fb740d758b14b1bc950cc347c21e461
Located: HK_LM:Run, SoundMan
command: SOUNDMAN.EXE
file: C:\WINDOWS\SOUNDMAN.EXE
size: 69632
MD5: 16fded08c873555859d2c83c82f0348d
Located: HK_LM:Run, SunJavaUpdateSched
command: C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
file: C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
size: 36975
MD5: 61a3a9d5d98bf0331df5b716144a8100
Located: HK_LM:Run, vptray
command: C:\PROGRA~1\SYMANT~1.1\VPTray.exe
file: C:\PROGRA~1\SYMANT~1.1\VPTray.exe
size: 124232
MD5: 6aab4074f9899f2e89aa2fb37998a7d6
Located: HK_LM:Run, winsysban
command: C:\\winsysban5.exe
file:
Located: HK_LM:Run, winsysupd
command: C:\windows\winsysupd5.exe
file:
Located: HK_LM:Run, zBrowser Launcher
command: C:\Program Files\Logitech\iTouch\iTouch.exe
file: C:\Program Files\Logitech\iTouch\iTouch.exe
size: 892928
MD5: 9aee9bcb32d82bcc36474eb921f3bb49
Located: HK_LM:RunServices, Microsoft System Support
command: spool.exe
file:
Located: HK_CU:Run,
command:
file:
Located: HK_CU:Run, ATI DeviceDetect
command: C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
file: C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
size: 53248
MD5: d1ac47f905f555b5ed791520e62823ad
Located: HK_CU:Run, ATI Launchpad
command: C:\Program Files\ATI Multimedia\main\launchpd.exe
file: C:\Program Files\ATI Multimedia\main\launchpd.exe
size: 102400
MD5: d842933eb271be30d4337320c036ebed
Located: HK_CU:Run, ATI Remote Control
command: C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.EXE
file: C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.EXE
size: 1482752
MD5: 69945b73e53c579287b1c5c8c03b23cf
Located: HK_CU:Run, ATI Scheduler
command: C:\Program Files\ATI Multimedia\main\ATISched.EXE
file: C:\Program Files\ATI Multimedia\main\ATISched.EXE
size: 45131
MD5: a01a0912c985ea0e429dd7b140bb2bbe
Located: HK_CU:Run, ctfmon.exe
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996a38c0b0cf151c2140ae29fc8
Located: HK_CU:Run, H/PC Connection Agent
command: "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
file: C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
size: 413775
MD5: e729abbad56fe6a7142abbe1743c80bb
Located: HK_CU:Run, Microsoft System Support
command: spool.exe
file:
Located: Startup (common), ATI CATALYST System Tray.lnk
command: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
file: C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
size: 32768
MD5: 2d510eaa846689443882367c37abc65e
Located: Startup (user), Banshee Screamer Alarm.lnk
command: C:\Program Files\Banshee Screamer Alarm\alarm.exe
file: C:\Program Files\Banshee Screamer Alarm\alarm.exe
size: 282624
MD5: ffbeb91ee9b829994501adae9ca8e284
Located: System.ini, AtiExtEvent
command: Ati2evxx.dll
file: Ati2evxx.dll
Located: System.ini, crypt32chain
command: crypt32.dll
file: crypt32.dll
Located: System.ini, cryptnet
command: cryptnet.dll
file: cryptnet.dll
Located: System.ini, cscdll
command: cscdll.dll
file: cscdll.dll
Located: System.ini, MCD
command: C:\WINDOWS\system32\VLAR332.DLL
file: C:\WINDOWS\system32\VLAR332.DLL
Located: System.ini, NavLogon
command: C:\WINDOWS\system32\NavLogon.dll
file: C:\WINDOWS\system32\NavLogon.dll
size: 83272
MD5: 123bd287cff65cef573c731f97e8dda3
Located: System.ini, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
Located: System.ini, Schedule
command: wlnotify.dll
file: wlnotify.dll
Located: System.ini, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
Located: System.ini, SensLogn
command: WlNotify.dll
file: WlNotify.dll
Located: System.ini, termsrv
command: wlnotify.dll
file: wlnotify.dll
Located: System.ini, wlballoon
command: wlnotify.dll
file: wlnotify.dll
--- Browser helper object list ---
{39C78B50-7E98-4aa0-B007-D83114EA6E0F} (Trecker Class)
BHO name:
CLSID name: Trecker Class
Path: C:\PROGRA~1\Jalmp\
Long name: jalmp.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
BHO name:
CLSID name: SSVHelper Class
Path: C:\Program Files\Java\jre1.5.0_06\bin\
Long name: ssv.dll
Short name:
Date (created): 11/10/2005 1:03:56 PM
Date (last access): 2/9/2006 1:39:42 AM
Date (last write): 11/10/2005 1:22:10 PM
Filesize: 184423
Attributes: archive
MD5: F01726F7CA8538FDD4663C9DB8FEAEDC
CRC32: 0111B892
Version: 5.0.60.5
{AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
BHO name:
CLSID name: Google Toolbar Helper
description: Google toolbar
classification: Open for discussion
known filename: googletoolbar.dll<br>googletoolbar*.dll<br>(* = number)<br>googletoolbar_en_*.**-big.dll<br>Googletoolbar_en_*.*.**-deleon.dll
info link: http://toolbar.google.com/
info source: TonyKlein
Path: c:\program files\google\
Long name: GoogleToolbar1.dll
Short name: GOOGLE~1.DLL
Date (created): 12/15/2005 2:17:10 AM
Date (last access): 2/9/2006 1:20:56 AM
Date (last write): 11/8/2005 6:43:56 PM
Filesize: 1164800
Attributes: readonly archive
MD5: 238E278572C5CF68BA02FCE1CC26E10E
CRC32: 0FDA8451
Version: 3.0.128.1
--- ActiveX list ---
{13AE2BC6-2F8A-4AFC-8116-2946938A4CE4} (ActiveWyncs Control)
DPF name:
CLSID name: ActiveWyncs Control
Installer: C:\WINDOWS\Downloaded Program Files\ActiveWyncs.inf
Codebase: http://www.newjerseydevils.com/2005/html/f...ActiveWyncs.cab
Path: C:\WINDOWS\DOWNLO~1\
Long name: ActiveWyncs.ocx
Short name: ACTIVE~1.OCX
Date (created): 10/11/2002 2:49:00 PM
Date (last access): 2/9/2006 2:01:52 AM
Date (last write): 10/11/2002 2:49:00 PM
Filesize: 409600
Attributes: archive
MD5: FAD0B50F856D7BAFB3ADA2BDCFCA4F9B
CRC32: 9C6E938C
Version: 2.1.0.0
{3BA494B1-D507-4C11-9BDA-D47E1A65DFCF} (Confidence Online Enterprise Edition)
DPF name:
CLSID name: Confidence Online Enterprise Edition
Installer:
Codebase: https://portal.morganstanley.com/llclient/p...ms.com,CT=java+
Path: C:\WINDOWS\Downloaded Program Files\
Long name: AXXPEE.dll,DanaInfo=hasas142.ms.com,CT=java+
Short name: AXXPEE~1.COM
Date (created): 10/14/2005 12:10:40 AM
Date (last access): 2/9/2006 2:01:52 AM
Date (last write): 10/14/2005 12:10:42 AM
Filesize: 380520
Attributes: archive
MD5: C30C1F60D8E5065D1D3A1EF1C948E27E
CRC32: D88DB135
Version: 4.2.0.45
{4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control)
DPF name:
CLSID name: NeoterisSetup Control
Installer: C:\WINDOWS\Downloaded Program Files\NeoterisSetup.INF
Codebase: https://portal.morganstanley.com/dana-cache...oterisSetup.cab
description:
classification: Open for discussion
known filename: NeoterisSetup.ocx
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\DOWNLO~1\
Long name: NeoterisSetup.ocx
Short name: NEOTER~1.OCX
Date (created): 12/10/2004 2:53:12 PM
Date (last access): 2/9/2006 2:01:52 AM
Date (last write): 12/10/2004 2:53:12 PM
Filesize: 61440
Attributes: archive
MD5: 09D21CE63B98DB675DA068D947A40559
CRC32: 609582EB
Version: 4.2.0.5
{94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class)
DPF name:
CLSID name: TLIEFlashObj Class
Installer:
Codebase: https://echat.us.del...t/TLIEFlash.CAB
description:
classification: Open for discussion
known filename: TLFlsCtl.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\
Long name: TLIEFlashCtrlU.dll
Short name: TLIEFL~1.DLL
Date (created): 6/19/2001 3:10:00 PM
Date (last access): 2/9/2006 1:44:14 AM
Date (last write): 6/19/2001 3:10:00 PM
Filesize: 122880
Attributes: archive
MD5: A08CA47F8F832B942EED05AC1B5814FA
CRC32: ADF15001
Version: 1.0.0.1
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
DPF name: Java Runtime Environment 1.5.0
CLSID name: Java Plug-in 1.5.0_06
Installer:
Codebase: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab
Path: C:\Program Files\Java\jre1.5.0_06\bin\
Long name: NPJPI150_06.dll
Short name: NPJPI1~1.DLL
Date (created): 11/10/2005 1:03:56 PM
Date (last access): 2/9/2006 2:01:54 AM
Date (last write): 11/10/2005 1:22:10 PM
Filesize: 69746
Attributes: archive
MD5: D2CF6BB5E9020E6707B62575F8083954
CRC32: 7F39DC54
Version: 5.0.60.5
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
DPF name: Java Runtime Environment 1.5.0
CLSID name: Java Plug-in 1.5.0_06
Installer:
Codebase: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab
Path: C:\Program Files\Java\jre1.5.0_06\bin\
Long name: NPJPI150_06.dll
Short name: NPJPI1~1.DLL
Date (created): 11/10/2005 1:03:56 PM
Date (last access): 2/9/2006 2:01:54 AM
Date (last write): 11/10/2005 1:22:10 PM
Filesize: 69746
Attributes: archive
MD5: D2CF6BB5E9020E6707B62575F8083954
CRC32: 7F39DC54
Version: 5.0.60.5
--- Process list ---
PID: 0 ( 0) [System]
PID: 1036 ( 4) \SystemRoot\System32\smss.exe
PID: 1124 (1036) \??\C:\WINDOWS\system32\csrss.exe
PID: 1152 (1036) \??\C:\WINDOWS\system32\winlogon.exe
PID: 1196 (1152) C:\WINDOWS\system32\services.exe
size: 108032
MD5: C6CE6EEC82F187615D1002BB3BB50ED4
PID: 1208 (1152) C:\WINDOWS\system32\lsass.exe
size: 13312
MD5: 84885F9B82F4D55C6146EBF6065D75D2
PID: 1384 (1196) C:\WINDOWS\system32\Ati2evxx.exe
size: 352256
MD5: D6C058E35B19F2999966E85433AFD760
PID: 1400 (1196) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1476 (1196) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1776 (1196) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1972 (1196) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 208 (1196) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 448 (1196) C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
size: 242808
MD5: C5AF6EC3DDE5F349E4F55A088297C871
PID: 520 (1196) C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
size: 255096
MD5: AE5858E655396D8EFA3008B83B7F739A
PID: 684 (1196) C:\WINDOWS\system32\spoolsv.exe
size: 57856
MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
PID: 436 (1196) C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
size: 98304
MD5: E42F7B36B4D8866184E8DF9776CA4226
PID: 772 (1196) C:\Program Files\Symantec AntiVirus CE 9.0.1\DefWatch.exe
size: 30024
MD5: 8C313CE948922D0801212AD8D0FA60CC
PID: 816 (1196) C:\Program Files\ewido anti-malware\ewidoctrl.exe
size: 13888
MD5: 26830B750372AB1BF29C95DEEBEB802F
PID: 828 (1196) C:\Program Files\ewido anti-malware\ewidoguard.exe
size: 151616
MD5: 34A50717AD686900F078F5208F8E908E
PID: 896 (1196) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
size: 322120
MD5: 11F714F85530A2BD134074DC30E99FCA
PID: 912 (1196) C:\PROGRA~1\MSREMO~1\NetCfgSv.EXE
size: 126976
MD5: C4A07342F661EE293A0DEE96B25D87AA
PID: 952 (1196) C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
size: 118784
MD5: D0F9F362023BF94CF58A1C3CDBBEBE06
PID: 1288 (1196) C:\Program Files\Symantec AntiVirus CE 9.0.1\Rtvscan.exe
size: 1267024
MD5: C246AF73D4C08B5799A25222A8BE827D
PID: 1436 (1196) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
size: 49152
MD5: CA90D2C55EB3BB90687677BEA3DB0B59
PID: 1512 (1196) C:\WINDOWS\system32\wdfmgr.exe
size: 38912
MD5: C81B8635DEE0D3EF5F64B3DD643023A5
PID: 1576 (1196) C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
size: 69632
MD5: FE5C052FC82645F87139F6655B3C21E6
PID: 1016 (1196) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1696 (1196) C:\WINDOWS\System32\alg.exe
size: 44544
MD5: F1958FBF86D5C004CF19A5951A9514B7
PID: 3112 (1152) C:\WINDOWS\system32\Ati2evxx.exe
size: 352256
MD5: D6C058E35B19F2999966E85433AFD760
PID: 3416 (3288) C:\WINDOWS\Explorer.EXE
size: 1032192
MD5: A0732187050030AE399B241436565E64
PID: 3872 (3416) C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
size: 32768
MD5: 2D510EAA846689443882367C37ABC65E
PID: 3888 (3416) C:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 66680
MD5: 05A76D9DD303DEF4DCC8EE18EE8C58B9
PID: 3896 (3416) C:\PROGRA~1\SYMANT~1.1\VPTray.exe
size: 124232
MD5: 6AAB4074F9899F2E89AA2FB37998A7D6
PID: 3984 (3416) C:\WINDOWS\SOUNDMAN.EXE
size: 69632
MD5: 16FDED08C873555859D2C83C82F0348D
PID: 3996 (3416) C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
size: 176128
MD5: 31C21D0A32E06D7A5DDDFCE78414B2A0
PID: 4012 (3416) C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
size: 241664
MD5: B75B654EE1DA99876461B24597AE3FF3
PID: 4028 (3416) C:\WINDOWS\system32\hphmon05.exe
size: 491520
MD5: 78BEE8060718100187484871B404B08A
PID: 4040 (3416) C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
size: 49152
MD5: 821F73B833C4DAEBC33C1A9A4B16BB5A
PID: 4068 (3416) C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
size: 36975
MD5: 61A3A9D5D98BF0331DF5B716144A8100
PID: 2144 (3416) C:\Program Files\iTunes\iTunesHelper.exe
size: 274432
MD5: 1C2B9FCD48112B0297B83E7FC43D1B42
PID: 2432 (1196) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 3528 (1196) C:\Program Files\iPod\bin\iPodService.exe
size: 323584
MD5: 5590C0E3B40C924C2B94CB5868B8360A
PID: 3552 (2288) C:\Program Files\Logitech\MouseWare\system\em_exec.exe
size: 37888
MD5: 7D325EC9B9B1589DF12D0874700BC59E
PID: 260 (3416) C:\Program Files\Logitech\iTouch\iTouch.exe
size: 892928
MD5: 9AEE9BCB32D82BCC36474EB921F3BB49
PID: 3772 (3416) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
size: 32768
MD5: 8FB740D758B14B1BC950CC347C21E461
PID: 3784 (1196) C:\WINDOWS\system32\HPZipm12.exe
size: 65536
MD5: 901C43516504CBE582E4C4193E00876A
PID: 1584 (3416) C:\program files\softwin\bitdefender8\bdnagent.exe
size: 8192
MD5: 641E3F9E3BD0856EB6C8F88F318DF4D4
PID: 1800 (3416) C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8
PID: 2584 (1400) C:\WINDOWS\system32\rundll32.exe
size: 33280
MD5: DA285490BBD8A1D0CE6623577D5BA1FF
PID: 1188 (3416) C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
size: 413775
MD5: E729ABBAD56FE6A7142ABBE1743C80BB
PID: 2564 (3416) C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
size: 32768
MD5: 2D510EAA846689443882367C37ABC65E
PID: 304 (3416) C:\Program Files\Banshee Screamer Alarm\alarm.exe
size: 282624
MD5: FFBEB91EE9B829994501ADAE9CA8E284
PID: 2740 (3416) C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
size: 6637156
MD5: CA35469F8987EBD2FB779DD915499462
PID: 2612 (3416) C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe
size: 528384
MD5: 3DDD47B8C513EF32DD09C0CF927AD6EF
PID: 3648 (1196) C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
size: 61440
MD5: 17F055B75C66EEE725251767F57BFA6A
PID: 1524 (1196) C:\Program Files\Softwin\BitDefender8\vsserv.exe
size: 90112
MD5: FA3ED6EDB1F3A0F87165ED5A9FADB910
PID: 1080 (2752) c:\program files\softwin\bitdefender8\bdmcon.exe
size: 417792
MD5: 4AECCDB404437848325F045973E23E3C
PID: 3848 (3416) C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
size: 218112
MD5: EE86268E59E4B38961E7C40D16BE5BB4
PID: 2232 (3848) C:\WINDOWS\system32\NOTEPAD.EXE
size: 69120
MD5: 388B8FBC36A8558587AFC90FB23A3B99
PID: 3012 (1080) C:\WINDOWS\notepad.exe
size: 69120
MD5: 388B8FBC36A8558587AFC90FB23A3B99
PID: 3392 (3416) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 4393096
MD5: 09CA174A605B480318731E691DC98539
PID: 2748 (1080) C:\WINDOWS\notepad.exe
size: 69120
MD5: 388B8FBC36A8558587AFC90FB23A3B99
PID: 4 ( 0) System
--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 2/9/2006 2:15:45 AM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://ie.search.msn.com
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.msn.com/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://ie.search.msn.com
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\SearchAssistant Explorer\Main\Default_Search_URL
about:blank
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
http://www.google.com/keyword/%s
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
%SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://ie.search.msn.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.microsoft.com/isapi/redir.dll?p...B_PVER}&ar=home
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft...=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn...st/srchcust.htm
--- Winsock Layered Service Provider list ---
--- Uninstall list ---
Ad-Aware SE Personal 1.06 (Ad-Aware SE Personal)
uninstall cmd: C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
publisher: Lavasoft
help link: http://www.lavasoft.com
(AddressBook)
Adobe Atmosphere Player for Acrobat and Adobe Reader (Adobe Atmosphere Player)
uninstall cmd: C:\WINDOWS\atmoUn.exe
ATI - Software Uninstall Utility 6.14.10.1012 (All ATI Software)
install location: C:\Program Files\ATI Technologies\UninstallAll
uninstall cmd: C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
AOL Instant Messenger (AOL Instant Messenger)
uninstall cmd: C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=
(AT&T Global Network Client)
ATI Display Driver 8.111-050222a-021277C-ATI (ATI Display Driver)
uninstall cmd: rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
(AvantGo Client)
AviSynth 2.5 (AviSynth)
uninstall cmd: "C:\Program Files\DVD Copy\AviSynth 2.5\Uninstall.exe"
Banshee Screamer Alarm 2.54 (Banshee Screamer Alarm 2.54)
uninstall cmd: C:\WINDOWS\UnGins.exe "C:\Program Files\Banshee Screamer Alarm\install.log"
BitComet 0.57 0.57 (BitComet)
uninstall cmd: C:\Program Files\BitComet\uninst.exe
publisher: ~RnySmile~
(Branding)
CCE SP Trial Version (CCE SP Trial Version)
uninstall cmd: C:\PROGRA~1\DVDCOP~1\CCE27~1.02S\uinst.exe
Citrix Web Client (Citrix Web Client)
uninstall cmd: C:\WINDOWS\system32\ctxsetup.exe /uninst C:\PROGRA~1\Citrix\icaweb32\uninst.inf
(Connection Manager)
Codec Pack - All In 1 6.0.2.8 (Cool's_Codec_pack_4.12)
uninstall cmd: C:\WINDOWS\iun6002.exe "C:\Program Files\Codec Pack - All In 1\irunin.ini"
VSO CopyToDVD 3 3.1.2 (CopyToDVD_is1)
install location: C:\Program Files\DVD Copy\CopyToDVD\
uninstall cmd: "C:\Program Files\DVD Copy\CopyToDVD\unins000.exe"
publisher: VSO Software
(DirectAnimation)
(DirectDrawEx)
DVD Decrypter (Remove Only) (DVD Decrypter)
uninstall cmd: "C:\Program Files\DVD Copy\DVD Decrypter\uninstall.exe"
DVD Shrink 3.2 (DVD Shrink_is1)
install location: C:\Program Files\DVD Shrink\
uninstall cmd: "C:\Program Files\DVD Shrink\unins000.exe"
publisher: DVD Shrink
help link: http://www.dvdshrink.org
DVDXCopy Xpress 3.0.2 (DVDXCopyXpress)
uninstall cmd: "C:\Program Files\321Studios\Xpress\uninstall.exe"
(DXM_Runtime)
ewido anti-malware (ewidoantimalware)
install location: C:\Program Files\ewido anti-malware
uninstall cmd: C:\Program Files\ewido anti-malware\Uninstall.exe
publisher: ewido networks
help link: http://www.ewido.net
(Fontcore)
HijackThis 1.99.1 1.99.1 (HijackThis)
uninstall cmd: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.157\HijackThis.exe /uninstall
publisher: Soeperman Enterprises Ltd.
(ICW)
(IE40)
(IE4Data)
(IE5BAKEX)
(IEData)
(InstallShield Uninstall Information)
ATI Multimedia Center 9.06 9.06 (InstallShield_{3CBA0E30-6F54-47EF-910E-1D4D450AFE45})
version: 151388160
version (major): 9
version (minor): 6
estimated size: 51169
install date: 20050323
install source: C:\WINDOWS\Downloaded Installations\{5AB58C0B-7E21-4632-8E78-8D77C8B87ABC}\
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{3CBA0E30-6F54-47EF-910E-1D4D450AFE45}
publisher: ATI Technologies
comments: ATI offers a wide variety of product support including driver downloads, technical and warranty information.
contact: ATI Customer Support Department
help link: http://support.ati.com
help telephone: 1-905-882-2626
readme: Readme.txt
QuickTime 7.0.2 (InstallShield_{4E5E22C2-1386-47AE-8EDE-32DDCDCD6653})
version: 117440514
version (major): 7
estimated size: 151170
install date: 20050911
install location: C:\Program Files\QuickTime\
install source: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_is10D\
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{4E5E22C2-1386-47AE-8EDE-32DDCDCD6653} /l1033
publisher: Apple Computer, Inc.
contact: AppleCare Support
help link: http://www.info.apple.com/
help telephone: 1-800-275-2273
iTunes 5.0.1.4 (InstallShield_{78F4DFCE-1336-4027-BCB2-1A00C24A8653})
version: 83886081
version (major): 5
estimated size: 30982
install date: 20050921
install location: C:\Program Files\iTunes\
install source: C:\WINDOWS\Downloaded Installations\{78F4DFCE-1336-4027-BCB2-1A00C24A8653}\
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{78F4DFCE-1336-4027-BCB2-1A00C24A8653} /l1033
publisher: Apple Computer, Inc.
contact: AppleCare Support
help link: http://www.info.apple.com/
help telephone: 1-800-275-2273
ATI Remote Wonder 3.0 3.0 (InstallShield_{8F36E44A-E6E7-41B7-B6F6-4637BF84EFA5})
version: 50331648
version (major): 3
estimated size: 3780
install date: 20050323
install source: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_isD9\
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{8F36E44A-E6E7-41B7-B6F6-4637BF84EFA5}
publisher: ATI Technologies
comments: Contact ATI Support for any issues with this product
contact: Customer Support Department
help link: http://support.ati.com
help telephone: 905-882-2600
readme: http://support.ati.com
DAO 3.5 (InstallShield_{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74})
version: 50659328
version (major): 3
version (minor): 5
estimated size: 57493
install date: 20050323
install source: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\_isB5\
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}
publisher: ATI
comments: Your Comments
contact: Microsoft
help link: http://www.microsoft.com
help telephone: 1-555-555-4505
Windows XP Hotfix - KB867282 20050127.090417 (KB867282)
uninstall cmd: C:\WINDOWS\$NtUninstallKB867282$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=867282
Windows XP Hotfix - KB873333 20050114.005213 (KB873333)
uninstall cmd: C:\WINDOWS\$NtUninstallKB873333$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=873333
Windows XP Hotfix - KB873339 20041117.092459 (KB873339)
uninstall cmd: C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=873339
(KB884016)
Windows XP Hotfix - KB885250 20050118.202711 (KB885250)
uninstall cmd: C:\WINDOWS\$NtUninstallKB885250$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=885250
Windows XP Hotfix - KB885835 20041027.181713 (KB885835)
uninstall cmd: C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=885835
Windows XP Hotfix - KB885836 20041028.173203 (KB885836)
uninstall cmd: C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=885836
Windows XP Hotfix - KB886185 20041021.090540 (KB886185)
uninstall cmd: C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=886185
Windows XP Hotfix - KB887472 20041014.162858 (KB887472)
uninstall cmd: C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=887472
Windows XP Hotfix - KB887742 20041103.095002 (KB887742)
uninstall cmd: C:\WINDOWS\$NtUninstallKB887742$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=887742
Windows XP Hotfix - KB887797 20041018.133824 (KB887797)
uninstall cmd: C:\WINDOWS\$NtUninstallKB887797$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=887797
Windows XP Hotfix - KB888113 20041116.131036 (KB888113)
uninstall cmd: C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=888113
Windows XP Hotfix - KB888302 20041207.111426 (KB888302)
unins
