Scanned at: 12:23:04 PM on: 11/16/2004
– Scan 1 —————————
About:Buster Version 3.0
Reference List : 15
No ADS found on system
Attempted Clean Of Temp folder.
Pages Reset… Done!
– Scan 2 —————————
About:Buster Version 3.0
Reference List : 15
No ADS found on system
Attempted Clean Of Temp folder.
Pages Reset… Done!
Ad-Aware SE Build 1.05
Logfile Created on:Tuesday, November 16, 2004 12:39:24 AM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R19 14.11.2004
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
ClickSpring(TAC index:6):16 total references
CoolWebSearch(TAC index:10):12 total references
midADdle(TAC index:4):9 total references
MyWay.Speedbar(TAC index:0):1 total references
Other(TAC index:5):2 total references
ShopNav Hijacker(TAC index:8):1 total references
StatBlaster(TAC index:8):9 total references
Tracking Cookie(TAC index:3):19 total references
Win32.Trojan.ByteVerify.A(TAC index:8):1 total references
VX2(TAC index:10):8 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Definition File:
=========================
Definitions File Loaded:
Reference Number : SE1R19 14.11.2004
Internal build : 24
File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
File size : 399688 Bytes
Total size : 1262753 Bytes
Signature data size : 1233509 Bytes
Reference data size : 28732 Bytes
Signatures total : 35069
Fingerprints total : 513
Fingerprints size : 19898 Bytes
Target categories : 15
Target families : 617
Memory + processor status:
==========================
Number of processors : 2
Processor architecture : Intel Pentium IV
Memory available:46 %
Total physical memory:515436 kb
Available physical memory:234332 kb
Total page file size:1260004 kb
Available on page file:1038848 kb
Total virtual memory:2097024 kb
Available virtual memory:2043604 kb
OS:Microsoft Windows XP Professional Service Pack 2 (Build 2600)
Ad-Aware SE Settings
===========================
Set : Safe mode (always request confirmation)
Set : Don't log streams smaller than 0 Bytes
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
11-16-2004 12:39:24 AM - Scan started. (Full System Scan)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 400
ThreadCreationTime : 11-16-2004 5:30:30 AM
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 456
ThreadCreationTime : 11-16-2004 5:30:33 AM
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 480
ThreadCreationTime : 11-16-2004 5:30:33 AM
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 524
ThreadCreationTime : 11-16-2004 5:30:34 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 536
ThreadCreationTime : 11-16-2004 5:30:34 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 692
ThreadCreationTime : 11-16-2004 5:30:34 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 768
ThreadCreationTime : 11-16-2004 5:30:35 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 808
ThreadCreationTime : 11-16-2004 5:30:35 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [stylexpservice.exe]
FilePath : C:\Program Files\TGTSoft\StyleXP\
ProcessID : 836
ThreadCreationTime : 11-16-2004 5:30:35 AM
BasePriority : Normal
FileVersion : 0, 20, 0, 3000
ProductVersion : 0, 20, 0, 3000
ProductName : StyleXPService Module
FileDescription : StyleXPService Module
InternalName : StyleXPService
LegalCopyright : Copyright 2001
OriginalFilename : StyleXPService.EXE
#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 900
ThreadCreationTime : 11-16-2004 5:30:35 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:11 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 952
ThreadCreationTime : 11-16-2004 5:30:35 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:12 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1104
ThreadCreationTime : 11-16-2004 5:30:36 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:13 [ccevtmgr.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 1192
ThreadCreationTime : 11-16-2004 5:30:37 AM
BasePriority : Normal
FileVersion : 1.03.4
ProductVersion : 1.03.4
ProductName : Event Manager
CompanyName : Symantec Corporation
FileDescription : Event Manager Service
InternalName : ccEvtMgr
LegalCopyright : Copyright © 2000-2002 Symantec Corporation. All rights reserved.
OriginalFilename : ccEvtMgr.exe
#:14 [mxtask.exe]
FilePath : C:\PROGRA~1\Ontrack\Fix-It\
ProcessID : 1236
ThreadCreationTime : 11-16-2004 5:30:37 AM
BasePriority : Normal
FileVersion : 4,0,0,11
CompanyName : Ontrack Data International
FileDescription : The background task server
InternalName : MXTask
LegalCopyright : Copyright © 1997-2001 Ontrack Data International
LegalTrademarks : Fix-It Utilities is a trademark of Ontrack Data International
OriginalFilename : MXTask.exe
#:15 [navapsvc.exe]
FilePath : C:\Program Files\Norton AntiVirus\
ProcessID : 1284
ThreadCreationTime : 11-16-2004 5:30:38 AM
BasePriority : Normal
FileVersion : 9.05.1015
ProductVersion : 9.05.1015
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
LegalCopyright : Copyright © 2000-2002 Symantec Corporation. All rights reserved.
OriginalFilename : NAVAPSVC.EXE
#:16 [nisum.exe]
FilePath : C:\Program Files\Norton Internet Security\
ProcessID : 1320
ThreadCreationTime : 11-16-2004 5:30:38 AM
BasePriority : Normal
FileVersion : 6.02.2003
ProductVersion : 6.02.2003
ProductName : Norton Internet Security
CompanyName : Symantec Corporation
FileDescription : Norton Internet Security NISUM
InternalName : NISUM
LegalCopyright : Copyright © 2000-2002 Symantec Corporation. All rights reserved.
OriginalFilename : NISUM.exe
#:17 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1532
ThreadCreationTime : 11-16-2004 5:30:40 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:18 [swnetsup.exe]
FilePath : C:\Program Files\Sophos SWEEP for NT\
ProcessID : 1572
ThreadCreationTime : 11-16-2004 5:30:40 AM
BasePriority : Normal
FileVersion : 1.00.0228
ProductVersion : 3 (Build 0228)
ProductName : Sophos Anti-Virus
CompanyName : Sophos Plc
FileDescription : Sophos Anti-Virus network support service
InternalName : SWNETSUP
LegalCopyright : © 1989-2004 Sophos Plc, www.sophos.com
LegalTrademarks : SWEEP®, InterCheck®, and SAVI®, are trademarks of Sophos® Plc.
OriginalFilename : SWNETSUP.EXE
#:19 [wdfmgr.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1644
ThreadCreationTime : 11-16-2004 5:30:42 AM
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe
#:20 [mspmspsv.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1700
ThreadCreationTime : 11-16-2004 5:30:42 AM
BasePriority : Normal
FileVersion : 7.00.00.1956
ProductVersion : 7.00.00.1956
ProductName : Microsoft ® DRM
CompanyName : Microsoft Corporation
FileDescription : WMDM PMSP Service
InternalName : MSPMSPSV.EXE
LegalCopyright : Copyright © Microsoft Corp. 1981-2000
OriginalFilename : MSPMSPSV.EXE
#:21 [ccpxysvc.exe]
FilePath : C:\Program Files\Norton Internet Security\
ProcessID : 1756
ThreadCreationTime : 11-16-2004 5:30:42 AM
BasePriority : Normal
FileVersion : 6.02.2003
ProductVersion : 6.02.2003
ProductName : Norton Internet Security
CompanyName : Symantec Corporation
FileDescription : Norton Internet Security Proxy Service
InternalName : ccPxySvc
LegalCopyright : Copyright © 2000-2002 Symantec Corporation. All rights reserved.
OriginalFilename : ccPxySvc.exe
#:22 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 212
ThreadCreationTime : 11-16-2004 5:30:44 AM
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
#:23 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 452
ThreadCreationTime : 11-16-2004 5:30:46 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe
#:24 [wscntfy.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 720
ThreadCreationTime : 11-16-2004 5:30:47 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Security Center Notification App
InternalName : wscntfy.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : wscntfy.exe
#:25 [hpsysdrv.exe]
FilePath : C:\windows\system\
ProcessID : 1036
ThreadCreationTime : 11-16-2004 5:30:56 AM
BasePriority : Normal
FileVersion : 1, 7, 0, 0
ProductVersion : 1, 7, 0, 0
ProductName : hpsysdrv
CompanyName : Hewlett-Packard Company
FileDescription : hpsysdrv
InternalName : hpsysdrv
LegalCopyright : Copyright © 1998
OriginalFilename : hpsysdrv.exe
#:26 [hkcmd.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1220
ThreadCreationTime : 11-16-2004 5:30:57 AM
BasePriority : Normal
FileVersion : 3,0,0,2082
ProductVersion : 7,0,0,2082
ProductName : Intel® Common User Interface
CompanyName : Intel Corporation
FileDescription : hkcmd Module
InternalName : HKCMD
LegalCopyright : Copyright 1999-2003, Intel Corporation
OriginalFilename : HKCMD.EXE
#:27 [hpqcmon.exe]
FilePath : C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\
ProcessID : 1264
ThreadCreationTime : 11-16-2004 5:30:58 AM
BasePriority : Normal
FileVersion : 2.0.0.133
ProductVersion : 2.0.0.133
ProductName : HpqCmon Application
FileDescription : HpqCmon MFC Application
InternalName : HpqCmon
LegalCopyright : Copyright © 2001
OriginalFilename : HpqCmon.EXE
#:28 [hpgs2wnd.exe]
FilePath : C:\Program Files\Hewlett-Packard\HP Share-to-Web\
ProcessID : 1476
ThreadCreationTime : 11-16-2004 5:30:59 AM
BasePriority : Normal
FileVersion : 2,3,0,0\ 162
ProductVersion : 2,3,0,0\ 162
ProductName : Hewlett-Packard hpgs2wnd
CompanyName : Hewlett-Packard
FileDescription : hpgs2wnd
InternalName : hpgs2wnd
LegalCopyright : Copyright © 2001
OriginalFilename : hpgs2wnd.exe
#:29 [ps2.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2028
ThreadCreationTime : 11-16-2004 5:31:03 AM
BasePriority : Normal
#:30 [hpgs2wnf.exe]
FilePath : c:\Program Files\Hewlett-Packard\HP Share-to-Web\
ProcessID : 2052
ThreadCreationTime : 11-16-2004 5:31:04 AM
BasePriority : Normal
FileVersion : 2, 6, 0, 162
ProductVersion : 2, 6, 0, 162
ProductName : hpgs2wnf Module
FileDescription : hpgs2wnf Module
InternalName : hpgs2wnf
LegalCopyright : Copyright 2001
OriginalFilename : hpgs2wnf.EXE
#:31 [ccapp.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 2076
ThreadCreationTime : 11-16-2004 5:31:04 AM
BasePriority : Normal
FileVersion : 1.0.10.006
ProductVersion : 1.0.10.006
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client CC App
InternalName : ccApp
LegalCopyright : Copyright © 2000-2002 Symantec Corporation. All rights reserved.
OriginalFilename : ccApp.exe
#:32 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 2136
ThreadCreationTime : 11-16-2004 5:31:06 AM
BasePriority : Normal
FileVersion : 0.1.0.1622
ProductVersion : 0.1.0.1622
ProductName : RealOne Player (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2002
LegalTrademarks : RealAudio™ is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe
#:33 [alcxmntr.exe]
FilePath : C:\WINDOWS\
ProcessID : 2160
ThreadCreationTime : 11-16-2004 5:31:07 AM
BasePriority : Normal
FileVersion : 1.2
ProductVersion : 1.2
ProductName : Realtek AC97 Audio - Event Monitor
CompanyName : Realtek Semiconductor Corp.
FileDescription : Realtek AC97 Audio - Event Monitor
InternalName : Alcxmntr
LegalCopyright : Copyright © 2003 Realtek Semiconductor Corp.
OriginalFilename : Alcxmntr.exe
#:34 [runtimes.exe]
FilePath : C:\Program Files\Internet Explorer\PLUGINS\
ProcessID : 2168
ThreadCreationTime : 11-16-2004 5:31:08 AM
BasePriority : Normal
FileVersion : 1.00
ProductVersion : 1.00
ProductName : Project1
InternalName : folder
OriginalFilename : folder.exe
#:35 [qttask.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2312
ThreadCreationTime : 11-16-2004 5:31:13 AM
BasePriority : Normal
FileVersion : 6.3
ProductVersion : QuickTime 6.3
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2003
OriginalFilename : QTTask.exe
#:36 [hpzeng07.exe]
FilePath : C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\
ProcessID : 2332
ThreadCreationTime : 11-16-2004 5:31:16 AM
BasePriority : ?
FileVersion : 2,140,0,0
ProductVersion : 2,140,0,0
ProductName : HP DeskJet
CompanyName : HP
FileDescription : HPDJ Print Engine
InternalName : HPDJ
LegalCopyright : Copyright © Hewlett-Packard Company 1999-2002
#:37 [93tefngr.exe]
FilePath : C:\documents and settings\soccerplr012\local settings\temp\
ProcessID : 2440
ThreadCreationTime : 11-16-2004 5:31:28 AM
BasePriority : Normal
StatBlaster Object Recognized!
Type : Process
Data : 93tefNGR.exe
Category : Data Miner
Comment : (CSI MATCH)
Object : C:\documents and settings\soccerplr012\local settings\temp\
Warning! StatBlaster Object found in memory(C:\documents and settings\soccerplr012\local settings\temp\93tefNGR.exe)
"C:\documents and settings\soccerplr012\local settings\temp\93tefNGR.exe"Process terminated successfully
"C:\documents and settings\soccerplr012\local settings\temp\93tefNGR.exe"Process terminated successfully
#:38 [qg8.exe]
FilePath : C:\documents and settings\soccerplr012\local settings\temp\
ProcessID : 2540
ThreadCreationTime : 11-16-2004 5:31:33 AM
BasePriority : Normal
midADdle Object Recognized!
Type : Process
Data : Qg8.exe
Category : Malware
Comment : (CSI MATCH)
Object : C:\documents and settings\soccerplr012\local settings\temp\
Warning! midADdle Object found in memory(C:\documents and settings\soccerplr012\local settings\temp\Qg8.exe)
"C:\documents and settings\soccerplr012\local settings\temp\Qg8.exe"Process terminated successfully
"C:\documents and settings\soccerplr012\local settings\temp\Qg8.exe"Process terminated successfully
#:39 [aim.exe]
FilePath : C:\PROGRA~1\AIM\
ProcessID : 2556
ThreadCreationTime : 11-16-2004 5:31:35 AM
BasePriority : Normal
FileVersion : 5.9.3690
ProductVersion : 5.9.3690
ProductName : AOL Instant Messenger
CompanyName : America Online, Inc.
FileDescription : AOL Instant Messenger
InternalName : AIM
LegalCopyright : Copyright © 1996-2004 America Online, Inc.
OriginalFilename : AIM.EXE
#:40 [nhdi.exe]
FilePath : C:\Documents and Settings\Soccerplr012\Application Data\
ProcessID : 2604
ThreadCreationTime : 11-16-2004 5:31:37 AM
BasePriority : Normal
Warning! VX2 Object found in memory(C:\Documents and Settings\Soccerplr012\Application Data\nhdi.exe)
VX2 Object Recognized!
Type : Process
Data : nhdi.exe
Category : Malware
Comment :
Object : C:\Documents and Settings\Soccerplr012\Application Data\
"C:\Documents and Settings\Soccerplr012\Application Data\nhdi.exe"Process terminated successfully
"C:\Documents and Settings\Soccerplr012\Application Data\nhdi.exe"Process terminated successfully
#:41 [w?wexec.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2656
ThreadCreationTime : 11-16-2004 5:31:41 AM
BasePriority : Normal
#:42 [hpotdd01.exe]
FilePath : C:\Program Files\Hewlett-Packard\Digital Imaging\bin\
ProcessID : 2696
ThreadCreationTime : 11-16-2004 5:31:45 AM
BasePriority : Normal
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
ProductName : Hewlett-Packard hpotdd01
CompanyName : Hewlett-Packard
FileDescription : hpotdd01
InternalName : hpotdd01
LegalCopyright : Copyright © 2002
OriginalFilename : hpotdd01.exe
#:43 [msmsgs.exe]
FilePath : C:\Program Files\Messenger\
ProcessID : 3532
ThreadCreationTime : 11-16-2004 5:38:24 AM
BasePriority : Normal
FileVersion : 4.7.3000
ProductVersion : Version 4.7.3000
ProductName : Messenger
CompanyName : Microsoft Corporation
FileDescription : Windows Messenger
InternalName : msmsgs
LegalCopyright : Copyright © Microsoft Corporation 2004
LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msmsgs.exe
#:44 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 3640
ThreadCreationTime : 11-16-2004 5:39:10 AM
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 3
Objects found so far: 3
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
ClickSpring Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{46605c8c-d306-4e2d-b367-9b53690cb867}
ClickSpring Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{46605c8c-d306-4e2d-b367-9b53690cb867}\1.0
ClickSpring Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{46605c8c-d306-4e2d-b367-9b53690cb867}\1.0
Value :
ClickSpring Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : mediaticketsinstaller.mediaticketsinstallerctrl.1
ClickSpring Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : mediaticketsinstaller.mediaticketsinstallerctrl.1
Value :
ClickSpring Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{9eb320ce-be1d-4304-a081-4b4665414bef}
ClickSpring Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{9eb320ce-be1d-4304-a081-4b4665414bef}
Value :
ClickSpring Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{39da2444-065f-47cb-b27c-ccb1a39c06b7}
ClickSpring Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{39da2444-065f-47cb-b27c-ccb1a39c06b7}
Value :
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{ee6f3f6a-ad8e-48da-9b1d-d5204b2d227d}
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{3e43040c-73c1-4898-a4f8-e2c9428b1167}
CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{3e43040c-73c1-4898-a4f8-e2c9428b1167}
Value :
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{20f13844-04bc-4987-9964-2502f0da54d3}
CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{20f13844-04bc-4987-9964-2502f0da54d3}
Value :
midADdle Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\midaddle
midADdle Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\midaddle
Value : Install_Dir
midADdle Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\midaddle
midADdle Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\midaddle
Value : DisplayName
midADdle Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\midaddle
Value : UninstallString
StatBlaster Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wildmedia\licensestores
StatBlaster Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wildmedia\licensestores
Value : 35f05749-e699-45df-a27f-79c05110c180
StatBlaster Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wildmedia\licensestores
Value : temp_overpro
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 22
Objects found so far: 25
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
ClickSpring Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\microsoft\windows\currentversion\moduleusage\C:/WINDOWS/Downloaded Program Files/MediaTicketsInstaller.ocx
ClickSpring Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\microsoft\windows\currentversion\moduleusage\C:/WINDOWS/Downloaded Program Files/MediaTicketsInstaller.ocx
Value : .Owner
ClickSpring Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\microsoft\windows\currentversion\moduleusage\C:/WINDOWS/Downloaded Program Files/MediaTicketsInstaller.ocx
Value : {9EB320CE-BE1D-4304-A081-4B4665414BEF}
ClickSpring Object Recognized!
Type : File
Data : /windows/downloaded program files/mediaticketsinstaller.ocx
Category : Data Miner
Comment :
Object : c:\
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
ProductName : MediaTicketsInstaller ActiveX Control Module
CompanyName : PowerTeam Corporation
FileDescription : MediaTicketsInstaller ActiveX Control Module
InternalName : MediaTicketsInstaller
LegalCopyright : Copyright © 2003
OriginalFilename : MediaTicketsInstaller.OCX
VX2 Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment : "Assw"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Windows\CurrentVersion\Run
Value : Assw
VX2 Object Recognized!
Type : File
Data : nhdi.exe
Category : Malware
Comment :
Object : c:\documents and settings\soccerplr012\application data\
ClickSpring Object Recognized!
Type : RegValue
Data : C:\WINDOWS\Downloaded Program Files\MediaTicketsInstaller.ocx
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\SharedDLLs
Value : C:\WINDOWS\Downloaded Program Files\MediaTicketsInstaller.ocx
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 5
Objects found so far: 32
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@2o7[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][2].txt
Category : Data Miner
Comment : Hits:34
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@questionmarket[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@statcounter[2].txt
Category : Data Miner
Comment : Hits:35
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@0[1].txt
Category : Data Miner
Comment : Hits:12
Value : Cookie:[removed]/HTM/559/0
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][1].txt
Category : Data Miner
Comment : Hits:6
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@bluestreak[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@zedo[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@xxxcounter[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][2].txt
Category : Data Miner
Comment : Hits:4
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@edge.ru4[1].txt
Category : Data Miner
Comment : Hits:37
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@tribalfusion[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@gator[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@revenue[1].txt
Category : Data Miner
Comment : Hits:5
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@cgi-bin[2].txt
Category : Data Miner
Comment : Hits:8
Value : Cookie:[removed]/cgi-bin
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@cgi-bin[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:[removed]/cgi-bin
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@paycounter[2].txt
Category : Data Miner
Comment : Hits:3
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : soccerplr012@centrport[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:[removed]/
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 19
Objects found so far: 51
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
VX2 Object Recognized!
Type : File
Data : !update.exe
Category : Malware
Comment :
Object : C:\Documents and Settings\Soccerplr012\Local Settings\Temp\
StatBlaster Object Recognized!
Type : File
Data : WinWildApp.exe
Category : Data Miner
Comment :
Object : C:\Documents and Settings\Soccerplr012\Local Settings\Temp\
Win32.Trojan.ByteVerify.A Object Recognized!
Type : File
Data : Counter[1].class
Category : Malware
Comment :
Object : C:\Documents and Settings\Soccerplr012\Local Settings\Temporary Internet Files\Content.IE5\WRHBIQ7X\
midADdle Object Recognized!
Type : File
Data : clicks[1].dll
Category : Malware
Comment :
Object : C:\Documents and Settings\Soccerplr012\Local Settings\Temporary Internet Files\Content.IE5\YX8FA5Q5\
FileVersion : 1.0.0.16
ProductVersion : 1.0.0.16
InternalName : clicks.dll
LegalCopyright : All rights reserved.
OriginalFilename : clicks.dll
CoolWebSearch Object Recognized!
Type : File
Data : A0050743.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{1411EB45-DEEF-49B6-A0AA-F85B814604DC}\RP437\
MyWay.Speedbar Object Recognized!
Type : File
Data : A0050929.DLL
Category : Misc
Comment :
Object : C:\System Volume Information\_restore{1411EB45-DEEF-49B6-A0AA-F85B814604DC}\RP443\
FileVersion : 2, 0, 1, 5
ProductVersion : 2, 0, 1, 5
ProductName : My Search Bar for Internet Explorer and Netscape
CompanyName : My Search
FileDescription : My Search Bar
InternalName : s4Bar
LegalCopyright : Copyright © 2002, 2003, 2004
OriginalFilename : s4Bar.DLL
CoolWebSearch Object Recognized!
Type : File
Data : A0056201.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{1411EB45-DEEF-49B6-A0AA-F85B814604DC}\RP468\
ShopNav Hijacker Object Recognized!
Type : File
Data : A0056202.exe
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{1411EB45-DEEF-49B6-A0AA-F85B814604DC}\RP468\
ClickSpring Object Recognized!
Type : File
Data : MediaTicketsInstaller.ocx
Category : Data Miner
Comment :
Object : C:\WINDOWS\Downloaded Program Files\
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
ProductName : MediaTicketsInstaller ActiveX Control Module
CompanyName : PowerTeam Corporation
FileDescription : MediaTicketsInstaller ActiveX Control Module
InternalName : MediaTicketsInstaller
LegalCopyright : Copyright © 2003
OriginalFilename : MediaTicketsInstaller.OCX
ClickSpring Object Recognized!
Type : File
Data : ezPopStub.exe
Category : Data Miner
Comment :
Object : C:\WINDOWS\system32\
FileVersion : 3, 0, 80, 0
ProductVersion : 1, 0, 0, 1
ProductName : eZstub Module
CompanyName : ClickSpringWO
FileDescription : eZstub Module
InternalName : eZstub
LegalCopyright : Copyright 2000
OriginalFilename : eZstub.EXE
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 61
Deep scanning and examining files (D:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for D:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 61
Scanning Hosts file……
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
869 entries scanned.
New critical objects:0
Objects found so far: 61
Performing conditional scans…
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
StatBlaster Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wildmedia
StatBlaster Object Recognized!
Type : File
Data : update_1.exe
Category : Data Miner
Comment :
Object : C:\DOCUME~1\SOCCER~1\LOCALS~1\Temp\
StatBlaster Object Recognized!
Type : File
Data : TempWM_FUINS.bat
Category : Data Miner
Comment :
Object : C:\Documents and Settings\Soccerplr012\local settings\
StatBlaster Object Recognized!
Type : File
Data : WinWildApp.exe
Category : Data Miner
Comment :
Object : C:\DOCUME~1\SOCCER~1\LOCALS~1\Temp\
VX2 Object Recognized!
Type : File
Data : !update.exe
Category : Malware
Comment :
Object : C:\DOCUME~1\SOCCER~1\LOCALS~1\Temp\
midADdle Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Updater
midADdle Object Recognized!
Type : File
Data : clicks.dll
Category : Malware
Comment :
Object : C:\DOCUME~1\SOCCER~1\LOCALS~1\Temp\
FileVersion : 1.0.0.16
ProductVersion : 1.0.0.16
InternalName : clicks.dll
LegalCopyright : All rights reserved.
OriginalFilename : clicks.dll
VX2 Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\toolbar\webbrowser
Value : {0E5CBF21-D15F-11D0-8301-00AA005B4383}
VX2 Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\main\featurecontrol\feature_window_restrictions
Value : iexplore.exe
VX2 Object Recognized!
Type : File
Data : billionaire.bmp
Category : Malware
Comment :
Object : C:\DOCUME~1\SOCCER~1\LOCALS~1\Temp\
CoolWebSearch Object Recognized!
Type : Regkey
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{9d573d0e-663c-435f-bf31-2c4497373c41}
CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{9d573d0e-663c-435f-bf31-2c4497373c41}
Value :
CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Enable Browser Extensions
CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Use Custom Search URL
CoolWebSearch Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\main
Value : Use Search Asst
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 17
Objects found so far: 78
12:54:28 AM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:15:04.172
Objects scanned:183666
Objects identified:78
Objects ignored:0
New critical objects:78
Logfile of HijackThis v1.98.2
Scan saved at 5:09:11 PM, on 11/16/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\Ontrack\Fix-It\mxtask.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sophos SWEEP for NT\SWNETSUP.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\documents and settings\soccerplr012\local settings\temp\93tefNGR.exe
C:\documents and settings\soccerplr012\local settings\temp\Qg8.exe
C:\PROGRA~1\AIM\aim.exe
C:\WINDOWS\system32\w?wexec.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://one.drexel.edu/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {44FA6006-BC4D-5E92-8004-6D557FF0734E} - C:\WINDOWS\system32\fswuodlk.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [runtimes19] C:\Program Files\Internet Explorer\PLUGINS\runtimes.exe
O4 - HKLM\..\Run: [MMTrayLSI] C:\WINDOWS\System32\MMTrayLSI.exe
O4 - HKLM\..\Run: [MMTray2K] C:\WINDOWS\System32\MMTray2k.exe
O4 - HKLM\..\Run: [MMTray] C:\WINDOWS\System32\MMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\System32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [93tefNGR] C:\documents and settings\soccerplr012\local settings\temp\93tefNGR.exe
O4 - HKLM\..\Run: [Qg8] C:\documents and settings\soccerplr012\local settings\temp\Qg8.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Oisgkcz] C:\WINDOWS\system32\w?wexec.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: &AIM; Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} -
http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} -
http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Video Poker -
http://download.games.yahoo.com/games/clients/y/vpt0_x.cab
O16 - DPF: Yahoo! Blackjack -
http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Dominoes -
http://download.games.yahoo.com/games/clients/y/dot8_x.cab
O16 - DPF: Yahoo! Fleet -