This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Adaware, Spybot Does Not Get Rid Of The Spyware

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Multiple problems with virtual bouncer and other spyware. Spybot, ad aware removes them, but they keep coming back. Norton 2005 correctly identifies the various threats, but cannot delete them. Now have issues with error codes at start up, trashcan deletes everything immediately (no, it's not set that way), etc. I am posting the hijack log, Norton, spybot and ad aware. All have the most recent updates. Thank you for any help you can give me.

Logfile of HijackThis v1.99.1
Scan saved at 8:34:57 PM, on 4/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\nrirkp.exe
C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
C:\WINDOWS\system32\picsvr\picsvr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Gary Jr\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…://my.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R3 - URLSearchHook: (no name) - _{9368D063-44BE-49B9-BD14-BB9663FD38FC} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.com/"); (C:\Documents and Settings\Gary Jr\Application Data\Mozilla\Profiles\default\vdsuqq7a.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\Gary Jr\Application Data\Mozilla\Profiles\default\vdsuqq7a.slt\prefs.js)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\nrirkp.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\system32\picsvr\picsvr.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Shorten URL - http://www.cjb.net/menuext.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…s/yinst0401.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_41.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…72/mcinsctl.cab
O16 - DPF: {666DDE35-E955-11D0-A707-000000521958} - http://69.56.176.227/webplugin.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {9FC87BC7-7963-4B70-8485-B1A41034C9A1} (Sony Pictures Game Downloader) - http://www.sonypictures.com/charliesangels…eDownloader.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_In…ller/dwnldr.cab
O16 - DPF: {D03A1C33-1913-4533-A8C1-F2C8D13045DE} - http://www.cjb.net/search.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\mvrul9991.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Norton:
Category: Threat alerts
Date,Feature,Threat Name,Action Taken,Item Type,Target,Suspicious Action,Virus Definition Version,Product Version,User Name,Computer Name,Details
4/17/2005 9:34:26 PM,Virus scanner,Adware.Ezula,No action taken,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\woinstall.exe,Description: The file C:\WINDOWS\woinstall.exe is a Adware threat."
4/17/2005 9:34:26 PM,Virus scanner,Adware.QoolAid,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\unadbeh.exe,Description: The file C:\WINDOWS\unadbeh.exe is a Adware threat."
4/17/2005 9:34:26 PM,Virus scanner,Adware.DelFin,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\Temp\uppicsvr.exe,Description: The file C:\WINDOWS\Temp\uppicsvr.exe is a Adware threat."
4/17/2005 9:34:26 PM,Virus scanner,Adware.DelFin,Delete failed,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: uppicsvr.exe,Description: The compressed file uppicsvr.exe within C:\WINDOWS\Temp\tsvcin.exe is a Adware threat."
4/17/2005 9:34:26 PM,Virus scanner,Adware.DelFin,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: RemoveDisplayUtility.exe,Description: The compressed file RemoveDisplayUtility.exe within C:\WINDOWS\Temp\tsvcin.exe is a Adware threat."
4/17/2005 9:34:26 PM,Virus scanner,Adware.DelFin,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: nsvsvc.exe,Description: The compressed file nsvsvc.exe within C:\WINDOWS\Temp\tsvcin.exe is a Adware threat."
4/17/2005 9:34:26 PM,Virus scanner,Adware.DelFin,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: nsvs.dll,Description: The compressed file nsvs.dll within C:\WINDOWS\Temp\tsvcin.exe is a Adware threat."
4/17/2005 9:34:26 PM,Virus scanner,Adware.DelFin,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\Temp\tsvcin.exe,Description: The file C:\WINDOWS\Temp\tsvcin.exe is a Adware threat."
4/17/2005 9:34:26 PM,Virus scanner,Adware.Ezula,No action taken,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\QIP237E5\eZinstall[1].exe,Description: The file C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\QIP237E5\eZinstall[1].exe is a Adware threat."
4/17/2005 9:34:26 PM,Virus scanner,Adware.Ezula,No action taken,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\OPQ9ABUD\woinstall[1].exe,Description: The file C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\OPQ9ABUD\woinstall[1].exe is a Adware threat."
4/17/2005 9:34:26 PM,Virus scanner,Adware.QoolAid,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\Temp\f26015171.exe,Description: The file C:\WINDOWS\Temp\f26015171.exe is a Adware threat."
4/17/2005 9:34:26 PM,Virus scanner,Adware.QoolAid,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM32\wmconfig.cpl,Description: The file C:\WINDOWS\SYSTEM32\wmconfig.cpl is a Adware threat."
4/17/2005 9:34:26 PM,Virus scanner,Adware.QoolAid,Delete failed,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM32\winup2date.dll,Description: The file C:\WINDOWS\SYSTEM32\winup2date.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.QoolAid,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM32\vqwqk.dat,Description: The file C:\WINDOWS\SYSTEM32\vqwqk.dat is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.DelFin,Delete failed,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM32\picsvr\picsvr.exe,Description: The file C:\WINDOWS\SYSTEM32\picsvr\picsvr.exe is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.QoolAid,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM32\ocdcmno.exe,Description: The file C:\WINDOWS\SYSTEM32\ocdcmno.exe is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.DelFin,Delete failed,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM32\nsvsvc\nsvs.dll,Description: The file C:\WINDOWS\SYSTEM32\nsvsvc\nsvs.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.DelFin,Delete failed,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM32\nsvsvc\nsvsvc.exe,Description: The file C:\WINDOWS\SYSTEM32\nsvsvc\nsvsvc.exe is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.QoolAid,Delete failed,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM32\nrirkp.exe,Description: The file C:\WINDOWS\SYSTEM32\nrirkp.exe is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.Look2Me,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM32\m8280ifue8280.dll,Description: The file C:\WINDOWS\SYSTEM32\m8280ifue8280.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.QoolAid,Delete failed,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM32\gpsprig.dll,Description: The file C:\WINDOWS\SYSTEM32\gpsprig.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.Ezula,No action taken,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM32\ezPopStub.exe,Description: The file C:\WINDOWS\SYSTEM32\ezPopStub.exe is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.QoolAid,Delete failed,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\SYSTEM32\andnu.dll,Description: The file C:\WINDOWS\SYSTEM32\andnu.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Spyware.ISearch,Delete failed,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: SpywareSource: C:\WINDOWS\isrvs\mfiltis.dll,Description: The file C:\WINDOWS\isrvs\mfiltis.dll is a Spyware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.BetterInternet,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\inst\3p_1n.exe,Description: The file C:\WINDOWS\inst\3p_1n.exe is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.Gator,No action taken,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\Downloaded Program Files\CONFLICT.5\HDPlugin1014.dll,Description: The file C:\WINDOWS\Downloaded Program Files\CONFLICT.5\HDPlugin1014.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.Gator,No action taken,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\Downloaded Program Files\CONFLICT.4\HDPlugin1014.dll,Description: The file C:\WINDOWS\Downloaded Program Files\CONFLICT.4\HDPlugin1014.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.Gator,No action taken,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1014.dll,Description: The file C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1014.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.Gator,No action taken,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\Downloaded Program Files\CONFLICT.3\HDPlugin1015.dll,Description: The file C:\WINDOWS\Downloaded Program Files\CONFLICT.3\HDPlugin1015.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.Gator,No action taken,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1015.dll,Description: The file C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1015.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.Gator,No action taken,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\Downloaded Program Files\CONFLICT.3\HDPlugin1014.dll,Description: The file C:\WINDOWS\Downloaded Program Files\CONFLICT.3\HDPlugin1014.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.Gator,No action taken,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1015.dll,Description: The file C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1015.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.Gator,No action taken,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\Downloaded Program Files\CONFLICT.12\HDPlugin1015.dll,Description: The file C:\WINDOWS\Downloaded Program Files\CONFLICT.12\HDPlugin1015.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.Gator,No action taken,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\Downloaded Program Files\CONFLICT.10\HDPlugin1015.dll,Description: The file C:\WINDOWS\Downloaded Program Files\CONFLICT.10\HDPlugin1015.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.BetterInternet,Delete failed,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\WINDOWS\ceres.dll,Description: The file C:\WINDOWS\ceres.dll is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.DelFin,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe,Description: The file C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.VirtuMonde,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\Documents and Settings\Gary Jr\Local Settings\Temporary Internet Files\Content.IE5\SD2NW5YF\AppWrap[2].exe,Description: The file C:\Documents and Settings\Gary Jr\Local Settings\Temporary Internet Files\Content.IE5\SD2NW5YF\AppWrap[2].exe is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.QoolAid,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\Documents and Settings\Gary Jr\Local Settings\Temp\tp7543.exe,Description: The file C:\Documents and Settings\Gary Jr\Local Settings\Temp\tp7543.exe is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.QoolAid,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\Documents and Settings\Gary Jr\Local Settings\Temp\Temporary Internet Files\Content.IE5\8TWBCXG1\i282[1].exe,Description: The file C:\Documents and Settings\Gary Jr\Local Settings\Temp\Temporary Internet Files\Content.IE5\8TWBCXG1\i282[1].exe is a Adware threat."
4/17/2005 9:34:25 PM,Virus scanner,Adware.QoolAid,Manually deleted,File,N/A,N/A,200504160025,11.0.9.16,Gary Jr,D3Q43G31JUNIOR,"Threat category: AdwareSource: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\tdrd.exe,Description: The file C:\Documents and Settings\All Users\Start Menu\Programs\Startup\tdrd.exe is a Adware threat."
Ad Aware

Ad-Aware SE Build 1.05
Logfile Created on:Tuesday, April 19, 2005 9:07:40 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R39 15.04.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
None
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Definition File:
=========================
Definitions File Loaded:
Reference Number : SE1R39 15.04.2005
Internal build : 46
File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
File size : 459480 Bytes
Total size : 1389159 Bytes
Signature data size : 1358772 Bytes
Reference data size : 29875 Bytes
Signatures total : 38701
Fingerprints total : 794
Fingerprints size : 29979 Bytes
Target categories : 15
Target families : 649


Memory + processor status:
==========================
Number of processors : 1
Processor architecture : Intel Pentium IV
Memory available:34 %
Total physical memory:260096 kb
Available physical memory:85912 kb
Total page file size:640204 kb
Available on page file:375552 kb
Total virtual memory:2097024 kb
Available virtual memory:2046792 kb
OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)

Ad-Aware SE Settings
===========================
Set : Safe mode (always request confirmation)
Set : Don't log streams smaller than 0 Bytes
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


4-19-2005 9:07:40 PM - Scan started. (Full System Scan)

Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 580
ThreadCreationTime : 4-20-2005 12:19:51 AM
BasePriority : Normal


#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 652
ThreadCreationTime : 4-20-2005 12:19:52 AM
BasePriority : High


#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 696
ThreadCreationTime : 4-20-2005 12:19:53 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe

#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 708
ThreadCreationTime : 4-20-2005 12:19:53 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe

#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 852
ThreadCreationTime : 4-20-2005 12:19:53 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 944
ThreadCreationTime : 4-20-2005 12:19:53 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:7 [ccsetmgr.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 1296
ThreadCreationTime : 4-20-2005 12:19:55 AM
BasePriority : Normal
FileVersion : 103.0.4.3
ProductVersion : 103.0.4.3
ProductName : Client and Host Security Platform
CompanyName : Symantec Corporation
FileDescription : Symantec Settings Manager Service
InternalName : ccSetMgr
LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved.
OriginalFilename : ccSetMgr.exe

#:8 [rundll32.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1312
ThreadCreationTime : 4-20-2005 12:19:56 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : RUNDLL.EXE

#:9 [sndsrvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 1380
ThreadCreationTime : 4-20-2005 12:19:56 AM
BasePriority : Normal
FileVersion : 5.4.4.17
ProductVersion : 5.4
ProductName : Symantec Security Drivers
CompanyName : Symantec Corporation
FileDescription : Network Driver Service
InternalName : SndSrvc
LegalCopyright : Copyright 2002, 2003, 2004 Symantec Corporation
OriginalFilename : SndSrvc.exe

#:10 [spbbcsvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\SPBBC\
ProcessID : 1396
ThreadCreationTime : 4-20-2005 12:19:56 AM
BasePriority : Normal
FileVersion : 1,0,1,47
ProductVersion : 1,0,1,47
ProductName : SPBBC
CompanyName : Symantec Corporation
FileDescription : SPBBC Service
InternalName : SPBBCSvc
LegalCopyright : Copyright © 2004 Symantec Corporation. All rights reserved.
OriginalFilename : SPBBCSvc.exe

#:11 [ccevtmgr.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 1444
ThreadCreationTime : 4-20-2005 12:19:56 AM
BasePriority : Normal
FileVersion : 103.0.4.3
ProductVersion : 103.0.4.3
ProductName : Client and Host Security Platform
CompanyName : Symantec Corporation
FileDescription : Symantec Event Manager Service
InternalName : ccEvtMgr
LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved.
OriginalFilename : ccEvtMgr.exe

#:12 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1596
ThreadCreationTime : 4-20-2005 12:19:57 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe

#:13 [cisvc.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1696
ThreadCreationTime : 4-20-2005 12:19:57 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Content Index service
InternalName : cisvc.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : cisvc.exe

#:14 [navapsvc.exe]
FilePath : C:\Program Files\Norton AntiVirus\
ProcessID : 1736
ThreadCreationTime : 4-20-2005 12:19:58 AM
BasePriority : Normal
FileVersion : 11.0.9.16
ProductVersion : 11.0.9
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
LegalCopyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright © 2004 Symantec Corporation. All rights reserved.
OriginalFilename : NAVAPSVC.EXE

#:15 [npfmntor.exe]
FilePath : C:\Program Files\Norton AntiVirus\IWP\
ProcessID : 1800
ThreadCreationTime : 4-20-2005 12:19:58 AM
BasePriority : Normal
FileVersion : 11.0.9.16
ProductVersion : 11.0.9
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Firewall Install Monitor
InternalName : NPFMonitor
LegalCopyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright © 2004 Symantec Corporation. All rights reserved.
OriginalFilename : NPFMonitor.EXE

#:16 [symlcsvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\
ProcessID : 1952
ThreadCreationTime : 4-20-2005 12:19:58 AM
BasePriority : Normal
FileVersion : 1, 8, 54, 419
ProductVersion : 1, 8, 54, 419
ProductName : Symantec Core Component
CompanyName : Symantec Corporation
FileDescription : Symantec Core Component
InternalName : symlcsvc
LegalCopyright : Copyright © 2003
OriginalFilename : symlcsvc.exe

#:17 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 200
ThreadCreationTime : 4-20-2005 12:19:58 AM
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE

#:18 [support.exe]
FilePath : C:\Program Files\Common Files\Dell\EUSW\
ProcessID : 2056
ThreadCreationTime : 4-20-2005 12:20:15 AM
BasePriority : Normal
FileVersion : 2, 1, 1, 0
ProductVersion : 1, 0, 0, 1
ProductName : Dell Support
CompanyName : Dell
FileDescription : Support
InternalName : Support
LegalCopyright : Copyright © 2002
OriginalFilename : Support.exe

#:19 [hkcmd.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2124
ThreadCreationTime : 4-20-2005 12:20:21 AM
BasePriority : Normal
FileVersion : 3.0.0.3762
ProductVersion : 7.0.0.3762
ProductName : Intel® Common User Interface
CompanyName : Intel Corporation
FileDescription : hkcmd Module
InternalName : HKCMD
LegalCopyright : Copyright 1999-2002, Intel Corporation
OriginalFilename : HKCMD.EXE

#:20 [dsentry.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2132
ThreadCreationTime : 4-20-2005 12:20:21 AM
BasePriority : Normal
FileVersion : 1, 0, 2, 0
ProductVersion : 1, 0, 2, 0
ProductName : Dell - DVDSentry
CompanyName : Dell - Advanced Desktop Engineering
FileDescription : DVDSentry
InternalName : DVDSentry
LegalCopyright : Copyright © 2002 Dell
OriginalFilename : DSentry.exe
Comments : DVDSentry launches your software DVD player when a DVD is inserted.

#:21 [bcmsmmsg.exe]
FilePath : C:\WINDOWS\
ProcessID : 2140
ThreadCreationTime : 4-20-2005 12:20:22 AM
BasePriority : Normal
FileVersion : 3.5.25 08/27/2003 20:04:35
ProductVersion : 3.5.25 08/27/2003 20:04:35
ProductName : BCM Modem Messaging Applet
CompanyName : Broadcom Corporation
FileDescription : Modem Messaging Applet
InternalName : smdmstat.exe
LegalCopyright : Copyright © Broadcom Corporation 1998-2000
OriginalFilename : smdmstat.exe

#:22 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 2148
ThreadCreationTime : 4-20-2005 12:20:24 AM
BasePriority : Normal
FileVersion : 0.1.0.3208
ProductVersion : 0.1.0.3208
ProductName : RealPlayer (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
LegalTrademarks : RealAudio™ is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe

#:23 [jusched.exe]
FilePath : C:\Program Files\Java\j2re1.4.2_06\bin\
ProcessID : 2156
ThreadCreationTime : 4-20-2005 12:20:24 AM
BasePriority : Normal


#:24 [ccapp.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 2172
ThreadCreationTime : 4-20-2005 12:20:24 AM
BasePriority : Normal
FileVersion : 103.0.4.3
ProductVersion : 103.0.4.3
ProductName : Client and Host Security Platform
CompanyName : Symantec Corporation
FileDescription : Symantec User Session
InternalName : ccApp
LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved.
OriginalFilename : ccApp.exe

#:25 [nrirkp.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2244
ThreadCreationTime : 4-20-2005 12:20:27 AM
BasePriority : Normal


#:26 [nsvsvc.exe]
FilePath : C:\WINDOWS\system32\nsvsvc\
ProcessID : 2280
ThreadCreationTime : 4-20-2005 12:20:28 AM
BasePriority : Normal
FileVersion : 2.17.0000
ProductVersion : 2, 1, 7, 0

#:27 [picsvr.exe]
FilePath : C:\WINDOWS\system32\picsvr\
ProcessID : 2296
ThreadCreationTime : 4-20-2005 12:20:29 AM
BasePriority : Normal


#:28 [msmsgs.exe]
FilePath : C:\Program Files\Messenger\
ProcessID : 2324
ThreadCreationTime : 4-20-2005 12:20:31 AM
BasePriority : Normal
FileVersion : 4.7.3001
ProductVersion : Version 4.7.3001
ProductName : Messenger
CompanyName : Microsoft Corporation
FileDescription : Windows Messenger
InternalName : msmsgs
LegalCopyright : Copyright © Microsoft Corporation 2004
LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msmsgs.exe

#:29 [netscp.exe]
FilePath : C:\Program Files\Netscape\Netscape\
ProcessID : 2368
ThreadCreationTime : 4-20-2005 12:20:32 AM
BasePriority : Normal


#:30 [osa.exe]
FilePath : C:\Program Files\Microsoft Office\Office\
ProcessID : 3016
ThreadCreationTime : 4-20-2005 12:20:45 AM
BasePriority : Normal


#:31 [cidaemon.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2572
ThreadCreationTime : 4-20-2005 12:27:43 AM
BasePriority : Idle
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Indexing Service filter daemon
InternalName : cidaemon.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : cidaemon.exe

#:32 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 1144
ThreadCreationTime : 4-20-2005 1:07:23 AM
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

#:33 [rundll32.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 800
ThreadCreationTime : 4-20-2005 1:07:34 AM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Run a DLL as an App
InternalName : rundll
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : RUNDLL.EXE

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Scanning Hosts file……
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
40 entries scanned.
New critical objects:0
Objects found so far: 0


9:31:10 PM Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:23:30.421
Objects scanned:125765
Objects identified:0
Objects ignored:0
New critical objects:0

Spybot:


— Search result list —
iSearch: Root class (Registry key, fixed)
HKEY_CLASSES_ROOT\CLSID\{950238FB-C706-4791-8674-4D429F85897E}


— Spybot - Search && Destroy version: 1.3 —
2005-03-03 Includes\Cookies.sbi
2005-04-07 Includes\Dialer.sbi
2005-04-07 Includes\Hijackers.sbi
2005-03-22 Includes\Keyloggers.sbi
2004-11-29 Includes\LSP.sbi
2005-04-07 Includes\Malware.sbi
2005-03-17 Includes\PUPS.sbi
2005-03-17 Includes\Revision.sbi
2005-02-09 Includes\Security.sbi
2005-04-07 Includes\Spybots.sbi
2005-02-17 Includes\Tracks.uti
2005-04-07 Includes\Trojans.sbi


— System information —
Windows XP (Build: 2600) Service Pack 2
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB886903)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
/ DataAccess: Microsoft Data Access Components KB870669
/ DataAccess: Security update for Microsoft Data Access Components
/ DataAccess: Security Update for Microsoft Data Access Components
/ DirectX: DirectX Update 819696
/ DirectX / DX9 / SP1: DirectX 9 Hotfix - KB839643
/ Windows Media Player / SP0: Windows Media Player Hotfix [See wm828026 for more information]
/ Windows Media Player: Windows Media Update 817787
/ Windows Media Player: Windows Media Update 828026
/ Windows XP / SP2: Windows XP Service Pack 2
/ Windows XP / SP3: Windows XP Hotfix - KB834707
/ Windows XP / SP3: Windows XP Hotfix - KB867282
/ Windows XP / SP3: Windows XP Hotfix - KB873333
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885250
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB887472
/ Windows XP / SP3: Windows XP Hotfix - KB887742
/ Windows XP / SP3: Windows XP Hotfix - KB888113
/ Windows XP / SP3: Windows XP Hotfix - KB888302
/ Windows XP / SP3: Windows XP Hotfix - KB890047
/ Windows XP / SP3: Windows XP Hotfix - KB890175
/ Windows XP / SP3: Windows XP Hotfix - KB890859
/ Windows XP / SP3: Windows XP Hotfix - KB890923
/ Windows XP / SP3: Windows XP Hotfix - KB891781
/ Windows XP / SP3: Windows XP Hotfix - KB893066
/ Windows XP / SP3: Windows XP Hotfix - KB893086
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)


— Startup entries list —
Located: HK_LM:Run, BCMSMMSG
command: BCMSMMSG.exe
file: C:\WINDOWS\BCMSMMSG.exe
size: 122880
MD5: 2d99607f21ff368c0e335a2d91a052a1

Located: HK_LM:Run, ccApp
command: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
file: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 58992
MD5: e5f9b0314442ea5816518c64b02f10a2

Located: HK_LM:Run, Desktop Search
command: C:\WINDOWS\isrvs\desktop.exe

Located: HK_LM:Run, DVDSentry
command: C:\WINDOWS\System32\DSentry.exe
file: C:\WINDOWS\System32\DSentry.exe
size: 28672
MD5: 3bc0b332cac05c40a0c42122a6c4bfc0

Located: HK_LM:Run, DwlClient
command: C:\Program Files\Common Files\Dell\EUSW\Support.exe
file: C:\Program Files\Common Files\Dell\EUSW\Support.exe
size: 323584
MD5: 27b68f137ed4c85ff92db98231bf11ed

Located: HK_LM:Run, ffis
command: C:\WINDOWS\isrvs\ffisearch.exe
file: C:\WINDOWS\isrvs\ffisearch.exe
size: 34146
MD5: af31054d6a0a336f979ebcbda2f151e8

Located: HK_LM:Run, HotKeysCmds
command: C:\WINDOWS\System32\hkcmd.exe
file: C:\WINDOWS\System32\hkcmd.exe
size: 118784
MD5: 66a5047df0c0cec911b95b5b1e24cebc

Located: HK_LM:Run, IgfxTray
command: C:\WINDOWS\System32\igfxtray.exe
file: C:\WINDOWS\System32\igfxtray.exe
size: 155648
MD5: d24b9b36c06ca0acf7ca2c69d9bb25b5

Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 77824
MD5: 96d2436434d14b99d0edf8a26be76eed

Located: HK_LM:Run, SunJavaUpdateSched
command: C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
file: C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
size: 32881
MD5: b3f49526347a82f8939881804c56aa94

Located: HK_LM:Run, Symantec NetDriver Monitor
command: C:\PROGRA~1\SYMNET~1\SNDMon.exe
file: C:\PROGRA~1\SYMNET~1\SNDMon.exe
size: 95960
MD5: abba14e4513a3eb53194c472d94943d7

Located: HK_LM:Run, TkBellExe
command: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
file: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
size: 180269
MD5: b8e684df9a97497edd2f87444a6307fb

Located: HK_LM:Run, Desktop Search (DISABLED)
command: C:\WINDOWS\isrvs\desktop.exe

Located: HK_LM:Run, ffis (DISABLED)
command: C:\WINDOWS\isrvs\ffisearch.exe
file: C:\WINDOWS\isrvs\ffisearch.exe
size: 34146
MD5: af31054d6a0a336f979ebcbda2f151e8

Located: HK_LM:Run, Nsv (DISABLED)
command: C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
file: C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
size: 57344
MD5: 016645ad95781969367a4500aeea456f

Located: HK_LM:Run, picsvr (DISABLED)
command: C:\WINDOWS\system32\picsvr\picsvr.exe
file: C:\WINDOWS\system32\picsvr\picsvr.exe
size: 94208
MD5: 779a079ba282db68d120d7164c16f981

Located: HK_CU:Run, Mozilla Quick Launch
command: "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
file: C:\Program Files\Netscape\Netscape\Netscp.exe
size: 526224
MD5: 720af523f27e0878b23b6e013249227f

Located: HK_CU:Run, MSMSGS
command: "C:\Program Files\Messenger\msmsgs.exe" /background
file: C:\Program Files\Messenger\msmsgs.exe
size: 1694208
MD5: 74e6e96c6f0e2eca4edbb7f7a468f259

Located: Startup (common), Microsoft Office.lnk
command: C:\Program Files\Microsoft Office\Office\OSA9.EXE
file: C:\Program Files\Microsoft Office\Office\OSA9.EXE
size: 65588
MD5: f51f9e10d937a8edd58d2d456ff49468

Located: Startup (user), Office Startup.lnk
command: C:\Program Files\Microsoft Office\Office\OSA.EXE
file: C:\Program Files\Microsoft Office\Office\OSA.EXE
size: 51984
MD5: d06276d4cad46cdceabefdeb1a0d3c0d



— Browser helper object list —


— ActiveX list —
DirectAnimation Java Classes (DirectAnimation Java Classes)
DPF name: DirectAnimation Java Classes
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\dajava.cab
info link:
info source: Patrick M. Kolla

Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla

{0000000A-0000-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:

{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object)
DPF name:
CLSID name: QuickTime Object
description: Apple Quicktime
classification: Legitimate
known filename: QTPLUGIN.OCX
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\QuickTime\
Long name: QTPlugin.ocx
Short name:
Date (created): 10/17/2003 10:32:46 PM
Date (last access): 4/19/2005 9:24:04 PM
Date (last write): 10/14/2004 5:43:04 PM
Filesize: 327736
Attributes: archive
MD5: 2C7319D66FE0AC7370B8346F55E7AAAE
CRC32: 4AC1F085
Version: 0.6.0.1

{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
DPF name:
CLSID name: Shockwave ActiveX Control
description: Macromedia ShockWave Flash Player 7
classification: Unknown
known filename: SWDIR.DLL
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\SYSTEM32\Macromed\Director\
Long name: SwDir.dll
Short name:
Date (created): 10/10/2003 8:48:26 PM
Date (last access): 4/19/2005 8:55:00 PM
Date (last write): 9/9/2004 3:49:12 PM
Filesize: 54488
Attributes: archive
MD5: 943193399C341AC34E842CB07B5F29A0
CRC32: 12DEB8F4
Version: 0.10.0.1

{2B323CD9-50E3-11D3-9466-00A0C9700498} ()
DPF name:
CLSID name:
description: Yahoo Audio Conferencing
classification: Legitimate
known filename: YACSCOM.DLL
info link:
info source: Patrick M. Kolla

{30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class)
DPF name:
CLSID name: YInstStarter Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: yinsthelper.dll
Short name: YINSTH~1.DLL
Date (created): 1/26/2004 7:40:04 PM
Date (last access): 4/19/2005 9:08:58 PM
Date (last write): 1/26/2004 7:40:04 PM
Filesize: 133120
Attributes: archive
MD5: E1FBF33D995C89583A36F461EC2879FF
CRC32: 1592E04B
Version: 7.212.0.1

{33564D57-0000-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:

{39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class)
DPF name:
CLSID name: FilePlanet Download Control Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: FilePlanetDownloadCtrl.dll
Short name: FILEPL~1.DLL
Date (created): 3/1/2004 12:31:26 PM
Date (last access): 4/19/2005 9:09:00 PM
Date (last write): 3/1/2004 12:31:26 PM
Filesize: 290816
Attributes: archive
MD5: A9D412FDD8F0248E4F210ABB1040BCE4
CRC32: 71C03A79
Version: 0.1.0.0

{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine)
DPF name:
CLSID name: Office Update Installation Engine
Path: C:\WINDOWS\
Long name: opuc.dll
Short name:
Date (created): 8/27/2003 4:10:30 AM
Date (last access): 4/19/2005 8:45:46 PM
Date (last write): 8/27/2003 4:10:30 AM
Filesize: 314368
Attributes: archive
MD5: 1E32EC4A8A17B19926B49EA5F6B79A76
CRC32: E98FC293
Version: 0.11.0.0

{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class)
DPF name:
CLSID name: McAfee.com Operating System Class
Path: C:\WINDOWS\System32\
Long name: mcinsctl.dll
Short name:
Date (created): 8/5/2003 12:01:28 PM
Date (last access): 4/19/2005 8:53:44 PM
Date (last write): 8/5/2003 12:01:28 PM
Filesize: 344064
Attributes: archive
MD5: 6E95B0FB3AAA84367B9D196F3C3811F4
CRC32: 99B321D7
Version: 0.4.0.0

{666DDE35-E955-11D0-A707-000000521958} ()
DPF name:
CLSID name:

{70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class)
DPF name:
CLSID name: GSDACtl Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: gsda.dll
Short name:
Date (created): 8/2/2002 11:26:16 AM
Date (last access): 4/19/2005 9:09:08 PM
Date (last write): 8/2/2002 11:26:16 AM
Filesize: 126976
Attributes: archive
MD5: 5EE65B9EC52620265673154EA2B9E5DD
CRC32: 7A1393C7
Version: 0.1.0.0

{77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control)
DPF name:
CLSID name: Groove Control
Path: C:\WINDOWS\Downloaded Program Files\
Long name: GrooveAX.dll
Short name:
Date (created): 1/5/2004 9:37:48 AM
Date (last access): 4/19/2005 9:39:24 PM
Date (last write): 1/5/2004 9:37:48 AM
Filesize: 468696
Attributes: archive
MD5: ABAD8F14E3F8F73C54FA588C76384685
CRC32: E7E2E448
Version: 0.1.0.0

{7D1E9C49-BD6A-11D3-87A8-009027A35D73} ()
DPF name:
CLSID name:
description: Yahoo audio
classification: Unknown
known filename: yacsui.dll
info link:
info source: Patrick M. Kolla

{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2)
DPF name: Java Runtime Environment 1.4.2
CLSID name: Java Plug-in 1.4.2_06
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\j2re1.4.2_06\bin\
Long name: NPJPI142_06.dll
Short name: NPJPI1~1.DLL
Date (created): 9/28/2004 9:26:10 PM
Date (last access): 4/19/2005 9:58:50 PM
Date (last write): 9/28/2004 9:26:00 PM
Filesize: 65650
Attributes: archive
MD5: 69E5147BA901A9238C4EB08C84E1A85B
CRC32: 6CB34BCC
Version: 0.1.0.4

{9FC87BC7-7963-4B70-8485-B1A41034C9A1} (Sony Pictures Game Downloader)
DPF name:
CLSID name: Sony Pictures Game Downloader
Path: C:\WINDOWS\Downloaded Program Files\
Long name: SonyPicturesGameDownloader.ocx
Short name: SONYPI~1.OCX
Date (created): 6/10/2003 12:27:40 PM
Date (last access): 4/19/2005 9:09:20 PM
Date (last write): 6/10/2003 12:27:40 PM
Filesize: 131072
Attributes: archive
MD5: 3C2EF4B33E144164C208057EAA295537
CRC32: 443EB50B
Version: 0.1.0.0

{AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class)
DPF name:
CLSID name: HeartbeatCtl Class
Path: C:\WINDOWS\DOWNLO~1\
Long name: hrtbeat.ocx
Short name:
Date (created): 9/18/2001 6:37:48 PM
Date (last access): 4/17/2005 8:11:16 PM
Date (last write): 9/18/2001 6:37:48 PM
Filesize: 101451
Attributes: archive
MD5: 06DDD56BB43CB6FDA26C9D65396EDA78
CRC32: 8BFE3040
Version: 0.6.0.2

{BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class)
DPF name:
CLSID name: DwnldGroupMgr Class
Path: C:\WINDOWS\System32\
Long name: McGDMgr.dll
Short name:
Date (created): 8/5/2003 12:04:54 PM
Date (last access): 4/19/2005 8:53:42 PM
Date (last write): 8/5/2003 12:04:54 PM
Filesize: 270336
Attributes: archive
MD5: 3662EFE944EF3D76808C048ACD8C1A0C
CRC32: 2DB3B258
Version: 0.1.0.0

{CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class)
DPF name:
CLSID name: Downloader Class
Path: C:\WINDOWS\DOWNLO~1\
Long name: dwnldr.dll
Short name:
Date (created): 12/15/2002 7:46:04 AM
Date (last access): 4/19/2005 9:09:26 PM
Date (last write): 12/15/2002 7:46:04 AM
Filesize: 102400
Attributes: archive
MD5: 6C85378C0DD243C9C4685EB01DE7CB72
CRC32: 2F4BF700
Version: 0.2.0.0

{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02)
DPF name: Java Runtime Environment 1.4.1_02
CLSID name: Java Plug-in 1.4.1_02
Path: C:\Program Files\Java\j2re1.4.1_02\bin\
Long name: NPJPI141_02.dll
Short name: NPJPI1~1.DLL
Date (created): 9/16/2003 8:15:18 PM
Date (last access): 4/19/2005 9:59:12 PM
Date (last write): 2/20/2003 4:42:34 PM
Filesize: 61553
Attributes: archive
MD5: E4EFF4ADF1367AA79815A9061E64C0D9
CRC32: A0446F8E
Version: 0.1.0.4

{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} (Java Runtime Environment 1.4.2)
DPF name: Java Runtime Environment 1.4.2
CLSID name: Java Plug-in 1.4.2_05
Path: C:\Program Files\Java\j2re1.4.2_05\bin\
Long name: NPJPI142_05.dll
Short name: NPJPI1~1.DLL
Date (created): 6/3/2068 11:05:12 PM
Date (last access): 4/19/2005 9:59:02 PM
Date (last write): 6/3/2004 11:05:06 PM
Filesize: 65650
Attributes: archive
MD5: 174488C8877FA852448D1937C322AABB
CRC32: 62C2460D
Version: 0.1.0.4

{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.4.2)
DPF name: Java Runtime Environment 1.4.2
CLSID name: Java Plug-in 1.4.2_06
Path: C:\Program Files\Java\j2re1.4.2_06\bin\
Long name: NPJPI142_06.dll
Short name: NPJPI1~1.DLL
Date (created): 9/28/2004 9:26:10 PM
Date (last access): 4/19/2005 9:58:50 PM
Date (last write): 9/28/2004 9:26:00 PM
Filesize: 65650
Attributes: archive
MD5: 69E5147BA901A9238C4EB08C84E1A85B
CRC32: 6CB34BCC
Version: 0.1.0.4

{D03A1C33-1913-4533-A8C1-F2C8D13045DE} ()
DPF name:
CLSID name:

{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\system32\Macromed\Flash\
Long name: swflash.ocx
Short name:
Date (created): 4/15/2005 7:28:26 PM
Date (last access): 4/19/2005 8:55:00 PM
Date (last write): 10/8/2004 8:48:58 AM
Filesize: 405504
Attributes: archive
MD5: 438487C9F2C320BC607C67B3A0764934
CRC32: 65E36F54
Version: 0.5.0.0

{E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class)
DPF name:
CLSID name: HeartbeatCtl Class
Path: C:\WINDOWS\DOWNLO~1\CONFLICT.1\
Long name: hrtbeat.ocx
Short name:
Date (created): 7/26/2004 8:36:00 PM
Date (last access): 4/17/2005 8:11:14 PM
Date (last write): 7/26/2004 8:36:00 PM
Filesize: 101464
Attributes: archive
MD5: 4BB1D03DFDFBBC51A7EC5D65D269EF42
CRC32: 5A8F1091
Version: 0.9.0.2



— Process list —
Spybot - Search && Destroy process list report, 4/19/2005 10:16:51 PM

PID: 0 ( 0) [System]
PID: 4 ( 0) System
PID: 200 (2020) C:\WINDOWS\Explorer.EXE
PID: 412 (2900) C:\PROGRA~1\Netscape\Netscape\Netscp.exe
PID: 420 ( 696) wdfmgr.exe
PID: 580 ( 4) \SystemRoot\System32\smss.exe
PID: 628 ( 580) csrss.exe
PID: 652 ( 580) \??\C:\WINDOWS\system32\winlogon.exe
PID: 696 ( 652) C:\WINDOWS\system32\services.exe
PID: 708 ( 652) C:\WINDOWS\system32\lsass.exe
PID: 852 ( 696) C:\WINDOWS\system32\svchost.exe
PID: 896 ( 696) svchost.exe
PID: 944 ( 696) C:\WINDOWS\System32\svchost.exe
PID: 1012 ( 696) svchost.exe
PID: 1108 ( 696) svchost.exe
PID: 1296 ( 696) C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PID: 1312 ( 652) C:\WINDOWS\system32\rundll32.exe
PID: 1380 ( 696) C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
PID: 1396 ( 696) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
PID: 1444 ( 696) C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PID: 1596 ( 696) C:\WINDOWS\system32\spoolsv.exe
PID: 1696 ( 696) C:\WINDOWS\system32\cisvc.exe
PID: 1736 ( 696) C:\Program Files\Norton AntiVirus\navapsvc.exe
PID: 1800 ( 696) C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
PID: 1952 ( 696) C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PID: 2056 ( 200) C:\Program Files\Common Files\Dell\EUSW\Support.exe
PID: 2124 ( 200) C:\WINDOWS\System32\hkcmd.exe
PID: 2132 ( 200) C:\WINDOWS\System32\DSentry.exe
PID: 2140 ( 200) C:\WINDOWS\BCMSMMSG.exe
PID: 2148 ( 200) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PID: 2156 ( 200) C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
PID: 2172 ( 200) C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PID: 2236 ( 696) alg.exe
PID: 2244 ( 200) C:\WINDOWS\system32\nrirkp.exe
PID: 2280 ( 200) C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
PID: 2296 ( 200) C:\WINDOWS\system32\picsvr\picsvr.exe
PID: 2324 ( 200) C:\Program Files\Messenger\msmsgs.exe
PID: 2572 (1696) C:\WINDOWS\system32\cidaemon.exe
PID: 3016 ( 200) C:\Program Files\Microsoft Office\Office\OSA.EXE
PID: 3220 ( 200) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe


— Browser start & search pages list —
Spybot - Search && Destroy browser pages report, 4/19/2005 10:16:51 PM

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL
http://ie.search.msn.com
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\about.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
about:blank
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.microsoft.com/isapi/redir.dll?p…er=6&ar;=msnhome
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
%SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://ie.search.msn.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://red.clientapps.yahoo.com/customize/…://my.yahoo.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.dellnet.com/
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com


— Winsock Layered Service Provider list —
Protocol 0: dolsp over [MSAFD Tcpip [TCP/IP]]
GUID: {BAC16DB4-C832-4752-A3C3-300D26FDD2DF}
Filename: C:\WINDOWS\system32\dolsp.dll

Protocol 1: dolsp over [MSAFD Tcpip [UDP/IP]]
GUID: {BAC16DB4-C832-4752-A3C3-300D26FDD2DF}
Filename: C:\WINDOWS\system32\dolsp.dll

Protocol 2: dolsp over [MSAFD Tcpip [RAW/IP]]
GUID: {BAC16DB4-C832-4752-A3C3-300D26FDD2DF}
Filename: C:\WINDOWS\system32\dolsp.dll

Protocol 3: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 4: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 5: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 6: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 7: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{21752D04-9BA1-417C-BD0E-828826C90C9F}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{21752D04-9BA1-417C-BD0E-828826C90C9F}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{9DA6D3CC-A1FA-429C-A84A-023A77C8AFA1}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{9DA6D3CC-A1FA-429C-A84A-023A77C8AFA1}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{61820C7F-1F2D-4EC6-AC52-4AA4C5CE956B}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{61820C7F-1F2D-4EC6-AC52-4AA4C5CE956B}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E5EC0A67-7EEA-48D6-BF30-90F5C13ABCA3}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E5EC0A67-7EEA-48D6-BF30-90F5C13ABCA3}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 16: dolsp
GUID: {CD395805-A77B-401F-B1AC-A3A409EF16BB}
Filename: C:\WINDOWS\system32\dolsp.dll

Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP

Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS

Namespace Provider 2: Network Location Awareness (NLA) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace
Hi bald eagle. You have quite a few infecrions on this computer.

RED or UNDERLINED words are links that can be clicked.

HOW TO Instructions:

Reboot in safe mode. If you have a keyboard with a "F Lock" key click it so that the "F" light above it is on when you start tapping the "F8" key.
How to print the fix instructions
Click the red links above.

Unzip a downloaded zip file.
Place the zip file in the folder where you want the unzipped program to be.
If you are running Windows XP you simply right click the zip file and select "Extract Files".
For the other versions of Windows you will need a program like 7-Zip . If you decide to use 7-Zip down load the newest version that is not a beta version.
Open 7-Zip. Navigate to to the downloaded zipfile and highlight it. Right click and select "Extract Here"

When asked to post a new HijackThis log please
Close all windows and browsers.
Find the HijackThis folder. Open it and double click "HijackThis.exe". Click "Do a system scan" and save a "logfile". (If Hijack this shows you a "Scan" button it is OK.)
When the "Scan" button changes into a "Save Log" button click it. Click "Ctrl-A" (the "Ctrl" key and the "A" key at the same time) to highlight the whole log. Now click "Ctrl-C" to copy the text. Open this topic and click the "Add Reply" ("Post Reply") button at the bottom of the page. Paste the log into the window that opens up by clicking "Ctrl-V".

DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL INSTRUCTED TO DO SO. SOME OF THE FILES ARE LEGIT AND VITAL TO YOUR COMPUTER'S HEALTH


1. Please copy the instructions to a notepad or preferably print them.

2. Make sure to work through the fixes exactly as given and in the exact order they are mentioned below.

3. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

4. Configure Windows to show all files. Showing hidden files and folders in Windows.

5.
  • Run HijackThis. Click on "Config…", "Misc Tools", "Open process manager". Select the following files and click on "Kill process". Answer Yes to the "Are you sure…" question.
    • desktop.exe
    • edmond.exe
    • ffisearch.exe
  • Launch Notepad, and copy/paste the box below into a new text file. Save it as fixme.reg and save it on your Desktop.

    REGEDIT4

    [-HKEY_CLASSES_ROOT\clsid\{5b4ab8e2-6dc5-477a-b637-bf3c1a2e5993}]

    [-HKEY_CLASSES_ROOT\clsid\{950238fb-c706-4791-8674-4d429f85897e}]

    [-HKEY_CLASSES_ROOT\mfiltis]

    [-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\ext\clsid\{5b4ab8e2-6dc5-477a-b637-bf3c1a2e5993}]

    [-HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_delprot]

    [-HKEY_LOCAL_MACHINE\system\currentcontrolset\services\delprot]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "desktop search"=-

    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "ffis"=-

    Locate fixme.reg on your Desktop and double-click on it.
    You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
    Answer "Yes" and wait for a message to appear similar to "Merged Successfully".
    Restart your computer.
  • Launch Notepad, and copy/paste the box below into a new text file. Save it as Unreg.bat and save it on your Desktop.

    regsvr32 /u C:\Windows\isrvs\msfiltis.dll
    regsvr32 /u C:\Windows\isrvs\msdbhk.dll
    regsvr32 /u C:\Windows\isrvs\sysupd.dll


    Locate Unreg.bat on your Desktop and double-click on it.
  • Delete the following files/folders (if present) in C:\Windows or C:\Windows\System32
    • delprot.ini
    • delprot.log
    • desktop.exe
    • isrvs (delete the entire folder)
  • Delete the following file: C:\Windows\System32\Drivers\Delprot.sys
  • Delete the following files/folder (if present) in C:\Documents and Settings\\Desktop
    • anal exploits.url
    • big dick school for 2.95.url
    • evidence eraser.lnk
    • popup blocker stops popups.lnk
    • spyware avenger.lnk
    • virus hunter security.lnk
    • your platinum visa.lnk
  • Restart your computer
6. You may have the latest version of VX2. Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

7. Run a new Hijack This scan and post the new log together with the log from l2mfix.
I stopped at step 5 because none of those files (desktp, ffi, edmond) were there. Should I continue with the other steps that are shown? I reran the scan, since I had adjustments made by Dell yesterday (logon problems). Also, as I was typing this, Norton popped up a virus that could not be repaired (windows/sys32/drivers/delprot.sys) Here is the log:

Logfile of HijackThis v1.99.1
Scan saved at 11:06:56 PM, on 4/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\nrirkp.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\PROGRA~1\WEBOFF~1\wo.exe
C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
C:\WINDOWS\system32\picsvr\picsvr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…://my.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R3 - URLSearchHook: (no name) - _{9368D063-44BE-49B9-BD14-BB9663FD38FC} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.com/"); (C:\Documents and Settings\Gary Jr\Application Data\Mozilla\Profiles\default\vdsuqq7a.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\Gary Jr\Application Data\Mozilla\Profiles\default\vdsuqq7a.slt\prefs.js)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [tsvcin] C:\WINDOWS\system32\n20050308.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\nrirkp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\system32\picsvr\picsvr.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Shorten URL - http://www.cjb.net/menuext.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…s/yinst0401.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_41.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…72/mcinsctl.cab
O16 - DPF: {666DDE35-E955-11D0-A707-000000521958} - http://69.56.176.227/webplugin.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {9FC87BC7-7963-4B70-8485-B1A41034C9A1} (Sony Pictures Game Downloader) - http://www.sonypictures.com/charliesangels…eDownloader.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_In…ller/dwnldr.cab
O16 - DPF: {D03A1C33-1913-4533-A8C1-F2C8D13045DE} - http://www.cjb.net/search.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\jtjq0715e.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
bald eagle We will have to go after that infection in a different way. It looks as if it is a more difficult form of the infection. :( The trouble is that you have more than one serious infection on your computer and there is no given order in which to remove them. They all download more junk to your computer all the time. Please continue with point 6 as that is a completely different infection. Will be back with you in about 7 hours but it is bed time for me. Good night. :)
See you tomorrow. Here are the logs from step 6.
L2mfix:
L2MFIX find log 1.03
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
@=""
"DLLName"="igfxsrvc.dll"
"Asynchronous"=dword:00000001
"Impersonate"=dword:00000001
"Unlock"="WinlogonUnlockEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Internet Settings]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\m046lahs1d46.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{07F88F15-D52E-D4BE-8AD3-2CC611205DD5}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run…"
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People…"
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{C7A5BCFE-E89F-42D4-9F3F-82B74D95BC4B}"=""
"{2138781D-1948-4F1D-8B33-A10A7B3DC2A6}"=""
"{4EC26602-4807-40FE-A40F-1A41E4D40C78}"="Dell DJ Explorer"
"{5EFA0222-DFCE-42DC-807C-B8D00A108C7F}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{2138781D-1948-4F1D-8B33-A10A7B3DC2A6}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2138781D-1948-4F1D-8B33-A10A7B3DC2A6}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2138781D-1948-4F1D-8B33-A10A7B3DC2A6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2138781D-1948-4F1D-8B33-A10A7B3DC2A6}\InprocServer32]
@="C:\\WINDOWS\\system32\\cpodm.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{5EFA0222-DFCE-42DC-807C-B8D00A108C7F}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5EFA0222-DFCE-42DC-807C-B8D00A108C7F}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5EFA0222-DFCE-42DC-807C-B8D00A108C7F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5EFA0222-DFCE-42DC-807C-B8D00A108C7F}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:
Hijack:
Logfile of HijackThis v1.99.1
Scan saved at 12:42:41 AM, on 4/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\nrirkp.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
C:\WINDOWS\system32\picsvr\picsvr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Web Offer\wo.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…://my.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R3 - URLSearchHook: (no name) - _{9368D063-44BE-49B9-BD14-BB9663FD38FC} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.com/"); (C:\Documents and Settings\Gary Jr\Application Data\Mozilla\Profiles\default\vdsuqq7a.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\Gary Jr\Application Data\Mozilla\Profiles\default\vdsuqq7a.slt\prefs.js)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [tsvcin] C:\WINDOWS\system32\n20050308.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\nrirkp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\system32\picsvr\picsvr.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Shorten URL - http://www.cjb.net/menuext.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…s/yinst0401.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_41.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…72/mcinsctl.cab
O16 - DPF: {666DDE35-E955-11D0-A707-000000521958} - http://69.56.176.227/webplugin.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {9FC87BC7-7963-4B70-8485-B1A41034C9A1} (Sony Pictures Game Downloader) - http://www.sonypictures.com/charliesangels…eDownloader.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_In…ller/dwnldr.cab
O16 - DPF: {D03A1C33-1913-4533-A8C1-F2C8D13045DE} - http://www.cjb.net/search.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: Internet Settings - C:\WINDOWS\system32\m046lahs1d46.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Hi again bald eagle I can see that you have a VX2 L2m Infection but it looks as if you cut a bit of the log from the L2Mfix log :( and it is important for me to see the complete log. Please post the complete log. There should be a list of files there. No need for another HijackThis log. :)
I ran the program again. I do get a message saying something along the lines of "this program is not supported by ms dos". I click ignore and then the log pops up. It is 7:30 AM, I'll be back around 6 PM. Thanks for the help, I would hate to have to wipe this computer and lose an irreplacable DVD burning program. L2MFIX find log 1.03 These are the registry keys present ********************************************************************************** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] @="" "DLLName"="igfxsrvc.dll" "Asynchronous"=dword:00000001 "Impersonate"=dword:00000001 "Unlock"="WinlogonUnlockEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IPConfTSP] "Asynchronous"=dword:00000000 "DllName"="C:\\WINDOWS\\system32\\k2lq0c35ef.dll" "Impersonate"=dword:00000000 "Logon"="WinLogon" "Logoff"="WinLogoff" "Shutdown"="WinShutdown" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 ********************************************************************************** useragent: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{01737325-A6F4-0EB0-4DE4-CED9B13F1921}"="" ********************************************************************************** Shell Extension key: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] "{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet" "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management" "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page" "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page" "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing" "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension" "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension" "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension" "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension" "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page" "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page" "{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler" "{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension" "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects" "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management" "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management" "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression" "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension" "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI" "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu" "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase" "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext" "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts" "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile" "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page" "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing" "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension" "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension" "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension" "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections" "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections" "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras" "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras" "{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras" "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras" "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras" "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension" "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host" "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link" "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler" "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension" "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks" "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu" "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search" "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support" "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support" "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run…" "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet" "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail" "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts" "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools" "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler" "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler" "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler" "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler" "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler" "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor" "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar" "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status" "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder" "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2" "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy" "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand" "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band" "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band" "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search" "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search" "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility" "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address" "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox" "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete" "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor" "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List" "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List" "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible" "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar" "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser" "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List" "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List" "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container" "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu" "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp" "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar" "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite" "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist" "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings" "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band" "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service" "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer" "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture" "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut" "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service" "{FF393560-C2A7-11CF-BFF4-444553540000}"="History" "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files" "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files" "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook" "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen" "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook" "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC" "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC" "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet" "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space" "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band" "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder" "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck" "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr" "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder" "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler" "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent" "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent" "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent" "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent" "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent" "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler" "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager" "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator" "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher" "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs" "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory" "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor" "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)" "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor" "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler" "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard" "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web" "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object" "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard" "{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts" "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler" "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target" "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File" "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut" "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object" "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu" "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties" "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview" "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext" "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control" "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control" "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control" "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control" "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control" "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI" "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object" "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find" "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find" "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI" "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs" "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook" "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target" "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties" "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu" "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options" "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder" "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler" "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell" "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%" "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler" "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer" "{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People…" "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler" "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler" "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler" "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache" "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player" "{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler" "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults" "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension" "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page" "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions" "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder" "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices" "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu" "{C7A5BCFE-E89F-42D4-9F3F-82B74D95BC4B}"="" "{2138781D-1948-4F1D-8B33-A10A7B3DC2A6}"="" "{4EC26602-4807-40FE-A40F-1A41E4D40C78}"="Dell DJ Explorer" "{5EFA0222-DFCE-42DC-807C-B8D00A108C7F}"="" ********************************************************************************** HKEY ROOT CLASSIDS: Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{2138781D-1948-4F1D-8B33-A10A7B3DC2A6}] @="" [HKEY_CLASSES_ROOT\CLSID\{2138781D-1948-4F1D-8B33-A10A7B3DC2A6}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{2138781D-1948-4F1D-8B33-A10A7B3DC2A6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{2138781D-1948-4F1D-8B33-A10A7B3DC2A6}\InprocServer32] @="C:\\WINDOWS\\system32\\CYMSNAP.DLL" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{5EFA0222-DFCE-42DC-807C-B8D00A108C7F}] @="" [HKEY_CLASSES_ROOT\CLSID\{5EFA0222-DFCE-42DC-807C-B8D00A108C7F}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{5EFA0222-DFCE-42DC-807C-B8D00A108C7F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{5EFA0222-DFCE-42DC-807C-B8D00A108C7F}\InprocServer32] @="C:\\WINDOWS\\system32\\guard.tmp" "ThreadingModel"="Apartment" ********************************************************************************** Files Found are not all bad files: Locate .tmp files: Directory Listing of system files: Volume in drive C has no label. Volume Serial Number is FC4A-DDCC Directory of C:\WINDOWS\System32 04/28/2005 07:31 AM 234,962 guard.tmp 04/28/2005 07:24 AM 234,962 CYMSNAP.DLL 04/28/2005 12:36 AM 233,044 gp8sl3l71.dll 04/27/2005 11:15 PM 234,962 k2lq0c35ef.dll 04/25/2005 09:35 PM 233,225 o4480ehueh480.dll 04/24/2005 09:39 AM 233,225 l88m0il1e8q.dll 02/21/2005 08:04 PM DLLCACHE 05/24/2004 06:51 AM 518 Yfk8.bt6 09/05/2003 10:17 PM Microsoft 7 File(s) 1,404,898 bytes 2 Dir(s) 30,081,040,384 bytes free
Thanks bald eagle. :)
Let's see if we can get rid of the first of the major infections.

1. Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!
L2Mfix 1.03

Running From:
C:\Documents and Settings\Gary Jr\Desktop\l2mfix



RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting registry permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry


Registry Permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY –C——- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting up for Reboot


Starting Reboot!

C:\Documents and Settings\Gary Jr\Desktop\l2mfix
System Rebooted!

Running From:
C:\Documents and Settings\Gary Jr\Desktop\l2mfix

killing explorer and rundll32.exe

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 1408 'explorer.exe'
Killing PID 1408 'explorer.exe'
Killing PID 1408 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Error, Cannot find a process with an image name of rundll32.exe

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!
Backing Up: C:\WINDOWS\system32\enr8l19u1.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\guard.tmp
1 file(s) copied.
deleting: C:\WINDOWS\system32\enr8l19u1.dll
Successfully Deleted: C:\WINDOWS\system32\enr8l19u1.dll
deleting: C:\WINDOWS\system32\guard.tmp
Successfully Deleted: C:\WINDOWS\system32\guard.tmp

Desktop.ini sucessfully removed

Zipping up files for submission:
adding: enr8l19u1.dll (164 bytes security) (deflated 5%)
adding: guard.tmp (164 bytes security) (deflated 4%)
adding: clear.reg (164 bytes security) (deflated 46%)
adding: echo.reg (164 bytes security) (deflated 9%)
adding: desktop.ini (164 bytes security) (deflated 14%)
adding: direct.txt (164 bytes security) (stored 0%)
adding: lo2.txt (164 bytes security) (deflated 73%)
adding: readme.txt (164 bytes security) (deflated 49%)
adding: test.txt (164 bytes security) (deflated 30%)
adding: test2.txt (164 bytes security) (deflated 25%)
adding: test3.txt (164 bytes security) (deflated 25%)
adding: test5.txt (164 bytes security) (deflated 25%)
adding: xfind.txt (164 bytes security) (deflated 24%)
adding: backregs/2138781D-1948-4F1D-8B33-A10A7B3DC2A6.reg (164 bytes security) (deflated 70%)
adding: backregs/5EFA0222-DFCE-42DC-807C-B8D00A108C7F.reg (164 bytes security) (deflated 70%)
adding: backregs/shell.reg (164 bytes security) (deflated 73%)

Restoring Registry Permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Revoking access for predefined group "Administrators"
Inherited ACE can not be revoked here!
Inherited ACE can not be revoked here!


Registry permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


Restoring Sedebugprivilege:

Granting SeDebugPrivilege to Administrators … successful

deleting local copy: enr8l19u1.dll
deleting local copy: guard.tmp

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
@=""
"DLLName"="igfxsrvc.dll"
"Asynchronous"=dword:00000001
"Impersonate"=dword:00000001
"Unlock"="WinlogonUnlockEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


The following are the files found:
****************************************************************************
C:\WINDOWS\system32\enr8l19u1.dll
C:\WINDOWS\system32\guard.tmp

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{C7A5BCFE-E89F-42D4-9F3F-82B74D95BC4B}"=-
"{2138781D-1948-4F1D-8B33-A10A7B3DC2A6}"=-
"{5EFA0222-DFCE-42DC-807C-B8D00A108C7F}"=-
[-HKEY_CLASSES_ROOT\CLSID\{C7A5BCFE-E89F-42D4-9F3F-82B74D95BC4B}]
[-HKEY_CLASSES_ROOT\CLSID\{2138781D-1948-4F1D-8B33-A10A7B3DC2A6}]
[-HKEY_CLASSES_ROOT\CLSID\{5EFA0222-DFCE-42DC-807C-B8D00A108C7F}]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
{08759F01-34F8-4657-89E3-15BD97D5C352}
VT09
200
****************************************************************************


Logfile of HijackThis v1.99.1
Scan saved at 12:43:57 AM, on 4/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\nrirkp.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
C:\WINDOWS\system32\picsvr\picsvr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Web Offer\wo.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cidaemon.exe
C:\PROGRA~1\Netscape\Netscape\Netscp.exe
C:\Program Files\Norton AntiVirus\OPScan.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…://my.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R3 - URLSearchHook: (no name) - _{9368D063-44BE-49B9-BD14-BB9663FD38FC} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.com/"); (C:\Documents and Settings\Gary Jr\Application Data\Mozilla\Profiles\default\vdsuqq7a.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\Gary Jr\Application Data\Mozilla\Profiles\default\vdsuqq7a.slt\prefs.js)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\nrirkp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\system32\picsvr\picsvr.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Shorten URL - http://www.cjb.net/menuext.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…s/yinst0401.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_41.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…72/mcinsctl.cab
O16 - DPF: {666DDE35-E955-11D0-A707-000000521958} - http://69.56.176.227/webplugin.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {9FC87BC7-7963-4B70-8485-B1A41034C9A1} (Sony Pictures Game Downloader) - http://www.sonypictures.com/charliesangels…eDownloader.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_In…ller/dwnldr.cab
O16 - DPF: {D03A1C33-1913-4533-A8C1-F2C8D13045DE} - http://www.cjb.net/search.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Hi again Bald eagle

At least it looks as one infection is gone. Let's go for the next one.

However we have to repair your internet connection that has been invaded by malware.

1. One of the fixes that we will be doing can break your internet connection if something would go wrong. In order to be able to correct the situation I want you to download this program http://www.spychecker.com/program/winsockxpfix.html . DO NOT RUN IT Unless instructed to do so.

2. Please download LSPFix from : here.
*Disconnect from the Internet and close all Internet Explorer and Explorer Windows.
*Run the program.
*On the opening screen, click the "I know what I'm doing" checkbox.
*Check all instances of dolsp.dll (and nothing else)
* move them to the "Remove" pane.
*Then click Finish.

3. Now to go after the second of the major infections.
Please go to http://forum.malwareremoval.com/viewtopic.php?p=1072#1072 and follow the instructions. I want you to run both Kasperski and Microsoft AntiSpyware according to the instructions.
To post a log from Microsoft AntiSpyware do as follows:
Open Microsoft AntiSpyware.
Click "Tools" > "Spyware Scan" > View Spyware Scan History.
Highlight the latest scan.
Click "View full details of scan" found in the lower right corner.
Right-click on the window with the details of the scan.
Click "Select All"
Click Ctrl + c to copy the contents
Paste the content into a new post in this topic.

4. Do a new HijackThis scan and post the log together with the information from Kasperski and from Microsoft AntiSpyware.

For your information I will be absent for 48 hours from tonight until Sunday evening New York time. Jewish holiday. I hope that this will not be to inconvenient.

Elrond :)
K program caused a lot of problems, extremely slow after installing. Seems to be getting better though. I have copied the report, but it is not very detailed. Statistics: Task start time: 4/30/2005 12:25:12 AM Task completion time: 4/30/2005 12:26:24 AM Objects scanned: 1563 Viruses detected: 0 Viruses disinfected: 0 Objects deleted: 0 Objects quarantined: 0 Settings: Objects to be scanned: System memory, disks boot sectors, objects executed during the system startup If an infected object is found: Perform recommended action Scan level: Recommended Objects to be excluded from the scan scope: Option not used Report: Elrond, This is all there was
Microsoft:
Spyware Scan Details
Start Date: 4/30/2005 1:02:54 PM
End Date: 4/30/2005 1:09:40 PM
Total Time: 6 mins 46 secs

Detected Threats

ClickAlchemy Adware more information…
Details: ClickAlchemy is adware.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected files detected
c:\windows\inf\polmx.inf


SEP Adware more information…
Details: SEP installs an Internet Explorer browser helper object and toolbar.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected registry keys/values detected
HKEY_CURRENT_USER\Software\sep
HKEY_CURRENT_USER\Software\sep PBPV 0
HKEY_CURRENT_USER\Software\sep Guid {7D37162E-CCF0-4378-A39D-4E808399CCBE}
HKEY_CURRENT_USER\Software\sep SettingsUpdate 38176
HKEY_CURRENT_USER\Software\sep SearchEngineUpdate 38176
HKEY_CURRENT_USER\Software\sep SettingsInterval 48
HKEY_CURRENT_USER\Software\sep SettingsUrl http://www.searchreslt.com/settings/
HKEY_CURRENT_USER\Software\sep SearchEngineInterval 72
HKEY_CURRENT_USER\Software\sep SearchEngineUrl http://www.searchreslt.com/selist/
HKEY_CURRENT_USER\Software\sep AdUrl http://www.searchreslt.com/ad/


CoolWebSearch.StartPage Browser Modifier more information…
Details: CoolWebSearch StartPage changes Internet Explorers start page, however, it does not allow you to change the URL.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected registry keys/values detected
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main Search Bar_bak


Searchwww.com Adware more information…
Details: Searchwww.com is a Visual Basic Script that changes your search page and downloads other adware or spyware.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D03A1C33-1913-4533-A8C1-F2C8D13045DE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D03A1C33-1913-4533-A8C1-F2C8D13045DE}\DownloadInformation CODEBASE http://www.cjb.net/search.cab
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D03A1C33-1913-4533-A8C1-F2C8D13045DE}\DownloadInformation INF C:\WINDOWS\Downloaded Program Files\search.inf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D03A1C33-1913-4533-A8C1-F2C8D13045DE}\InstalledVersion 0,0,0,1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D03A1C33-1913-4533-A8C1-F2C8D13045DE}\InstalledVersion LastModified Thu, 01 Jan 1970 00:00:00 GMT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D03A1C33-1913-4533-A8C1-F2C8D13045DE} SystemComponent 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D03A1C33-1913-4533-A8C1-F2C8D13045DE} Installer MSICD


Unclassified.Spyware.61 Spyware more information…
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected registry keys/values detected
HKEY_CLASSES_ROOT\clsid\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}
HKEY_CLASSES_ROOT\clsid\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}\InProcServer32 C:\WINDOWS\system32\winup2date.dll
HKEY_CLASSES_ROOT\clsid\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}\InProcServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}\ProgId Columns class
HKEY_CLASSES_ROOT\clsid\{6EC11407-5B2E-4E25-8BDF-77445B52AB37} Columns class


AvenueMedia.DyFuCA Browser Plug-in more information…
Details: AvenueMedia DyFuCA Internet Optimizer is adware that changes your browser error page. It periodically displays pop-up advertisements from its remote sites and may update itself.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Internet Optimizer Active Alert
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Internet Optimizer Active Alert
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Internet Optimizer Active Alert Changed 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Internet Optimizer Software Installer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Internet Optimizer Software Installer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Internet Optimizer Software Installer Changed 0


NCase Browser Modifier more information…
Details: NCase is adware that looks for known URLs and keywords in URLs, and displays pop-up advertisements targeted at related Web sites. nCase also periodically opens non-targeted pop-up advertisements while you are using Internet Explorer.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected files detected
c:\program files\ncase\fiz1
c:\program files\ncase\fiz2
c:\program files\ncase\fiz3

Infected folders detected
c:\program files\ncase
c:\program files\ncase\fleok


SearchCentrix Browser Modifier more information…
Details: SearchCentrix changes your search bar and SearchAssistant settings to its remote server.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected registry keys/values detected
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C431BF1E-9E71-4BB6-9C4E-8496D158DB1F}


eZula.WebOffer Adware more information…
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\Program Files\eZula\search.src
c:\program files\web offer\install.log
c:\program files\web offer\paramp.ez
c:\program files\web offer\rwdsp.rst
c:\program files\web offer\sepng.dll
c:\program files\web offer\unwise.exe
c:\program files\web offer\upgradep.vrn
c:\program files\web offer\versionp.vrn
c:\Program Files\web offer\wndbannnp.src
c:\program files\web offer\apev.exe
c:\program files\web offer\basisp.dst
c:\program files\web offer\basisp.kwd
c:\program files\web offer\basisp.pu
c:\program files\web offer\basisp.rst
c:\program files\web offer\eapbh.dll
c:\program files\web offer\gendis.ez

Infected folders detected
c:\program files\web offer

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}
HKEY_CLASSES_ROOT\EZulaFSearchEng.eZulaSearch.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EZulaFSearchEng.eZulaSearch.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}
HKEY_CLASSES_ROOT\EZulaFSearchEng.eZulaHash.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EZulaFSearchEng.eZulaHash.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{78BCF937-45B0-40A7-9391-DCC03420DB35}
HKEY_CLASSES_ROOT\EZulaFSearchEng.SearchHelper.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EZulaFSearchEng.SearchHelper.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}
HKEY_CLASSES_ROOT\eZulaAgent.IEObject.1
HKEY_CLASSES_ROOT\EZulaFSearchEng.PopupDisplay.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EZulaFSearchEng.PopupDisplay.1
HKEY_CLASSES_ROOT\clsid\{25630B47-53C6-4E66-A945-9D7B6B2171FF}
HKEY_CLASSES_ROOT\clsid\{25630B47-53C6-4E66-A945-9D7B6B2171FF}\InprocServer32 C:\PROGRA~1\WEBOFF~1\sepng.dll
HKEY_CLASSES_ROOT\clsid\{25630B47-53C6-4E66-A945-9D7B6B2171FF}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{25630B47-53C6-4E66-A945-9D7B6B2171FF}\ProgID EZulaFSearchEng.eZulaCode.1
HKEY_CLASSES_ROOT\clsid\{25630B47-53C6-4E66-A945-9D7B6B2171FF}\TypeLib {370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}
HKEY_CLASSES_ROOT\clsid\{25630B47-53C6-4E66-A945-9D7B6B2171FF}\VersionIndependentProgID EZulaFSearchEng.eZulaCode
HKEY_CLASSES_ROOT\clsid\{25630B47-53C6-4E66-A945-9D7B6B2171FF} eZulaCode Class
HKEY_CLASSES_ROOT\clsid\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eZulaAgent.IEObject.1
HKEY_CLASSES_ROOT\clsid\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}\InprocServer32 C:\PROGRA~1\WEBOFF~1\sepng.dll
HKEY_CLASSES_ROOT\clsid\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}\ProgID EZulaFSearchEng.eZulaSearch.1
HKEY_CLASSES_ROOT\clsid\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}\TypeLib {370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}
HKEY_CLASSES_ROOT\clsid\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}\VersionIndependentProgID EZulaFSearchEng.eZulaSearch
HKEY_CLASSES_ROOT\clsid\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9} eZulaSearch Class
HKEY_CLASSES_ROOT\clsid\{6DF5E318-6994-4A41-85BD-45CCADA616F8}
HKEY_CLASSES_ROOT\clsid\{6DF5E318-6994-4A41-85BD-45CCADA616F8}\LocalServer32 C:\PROGRA~1\WEBOFF~1\apev.exe
HKEY_CLASSES_ROOT\clsid\{6DF5E318-6994-4A41-85BD-45CCADA616F8}\ProgID AtlBrCon.AtlBrCon.1
HKEY_CLASSES_ROOT\clsid\{6DF5E318-6994-4A41-85BD-45CCADA616F8}\VersionIndependentProgID AtlBrCon.AtlBrCon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2306ABE4-4D42-11D4-8A6D-0050DA2EE1BE}
HKEY_CLASSES_ROOT\clsid\{6DF5E318-6994-4A41-85BD-45CCADA616F8} AtlBrCon Class
HKEY_CLASSES_ROOT\clsid\{6DF5E318-6994-4A41-85BD-45CCADA616F8} AppID {0818D423-6247-11D1-ABEE-00D049C10000}
HKEY_CLASSES_ROOT\clsid\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}
HKEY_CLASSES_ROOT\clsid\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}\InprocServer32 C:\PROGRA~1\WEBOFF~1\sepng.dll
HKEY_CLASSES_ROOT\clsid\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}\ProgID EZulaFSearchEng.eZulaHash.1
HKEY_CLASSES_ROOT\clsid\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}\TypeLib {370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}
HKEY_CLASSES_ROOT\clsid\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}\VersionIndependentProgID EZulaFSearchEng.eZulaHash
HKEY_CLASSES_ROOT\clsid\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4} eZulaHash Class
HKEY_CLASSES_ROOT\clsid\{78BCF937-45B0-40A7-9391-DCC03420DB35}
HKEY_CLASSES_ROOT\EZulaFSearchEng.ResultHelper.1
HKEY_CLASSES_ROOT\clsid\{78BCF937-45B0-40A7-9391-DCC03420DB35}\InprocServer32 C:\PROGRA~1\WEBOFF~1\sepng.dll
HKEY_CLASSES_ROOT\clsid\{78BCF937-45B0-40A7-9391-DCC03420DB35}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{78BCF937-45B0-40A7-9391-DCC03420DB35}\ProgID EZulaFSearchEng.SearchHelper.1
HKEY_CLASSES_ROOT\clsid\{78BCF937-45B0-40A7-9391-DCC03420DB35}\TypeLib {370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}
HKEY_CLASSES_ROOT\clsid\{78BCF937-45B0-40A7-9391-DCC03420DB35}\VersionIndependentProgID EZulaFSearchEng.SearchHelper
HKEY_CLASSES_ROOT\clsid\{78BCF937-45B0-40A7-9391-DCC03420DB35} SearchHelper Class
HKEY_CLASSES_ROOT\clsid\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}
HKEY_CLASSES_ROOT\clsid\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}\InprocServer32 C:\PROGRA~1\WEBOFF~1\eapbh.dll
HKEY_CLASSES_ROOT\clsid\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}\ProgID eZulaAgent.IEObject.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EZulaFSearchEng.ResultHelper.1
HKEY_CLASSES_ROOT\clsid\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}\TypeLib {9CFA26C1-81DA-4C9D-A501-F144A4A000FA}
HKEY_CLASSES_ROOT\clsid\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}\VersionIndependentProgID eZulaAgent.IEObject
HKEY_CLASSES_ROOT\clsid\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA} IEObject Class
HKEY_CLASSES_ROOT\clsid\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}
HKEY_CLASSES_ROOT\clsid\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}\LocalServer32 C:\PROGRA~1\WEBOFF~1\wo.exe
HKEY_CLASSES_ROOT\clsid\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}\ProgID EZulaMain.eZulaPopSearchPipe.1
HKEY_CLASSES_ROOT\clsid\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}\TypeLib {9CFA26C0-81DA-4C9D-A501-F144A4A000FA}
HKEY_CLASSES_ROOT\clsid\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}\VersionIndependentProgID EZulaMain.eeZulaPopSearchPipe
HKEY_CLASSES_ROOT\clsid\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7} eZulaPopSearchPipe Class
HKEY_CLASSES_ROOT\clsid\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7} AppID {9CFA26C0-81DA-4C9D-A501-F144A4A000FA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25630B47-53C6-4E66-A945-9D7B6B2171FF}
HKEY_CLASSES_ROOT\clsid\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}
HKEY_CLASSES_ROOT\clsid\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}\InprocServer32 C:\PROGRA~1\WEBOFF~1\sepng.dll
HKEY_CLASSES_ROOT\clsid\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}\ProgID EZulaFSearchEng.PopupDisplay.1
HKEY_CLASSES_ROOT\clsid\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}\TypeLib {4A954C6B-6946-40CF-B211-62385CDB85F9}
HKEY_CLASSES_ROOT\clsid\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}\VersionIndependentProgID EZulaFSearchEng.PopupDisplay
HKEY_CLASSES_ROOT\clsid\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0} PopupDisplay Class
HKEY_CURRENT_USER\Software\Web Offer
HKEY_CURRENT_USER\Software\Web Offer\Setup\ID GEO US;PA;Willow Grove;
HKEY_CURRENT_USER\Software\Web Offer\Setup\ID L_UP 1114654515
HKEY_CLASSES_ROOT\EZulaFSearchEng.eZulaCode.1
HKEY_CURRENT_USER\Software\Web Offer\Setup\ID 132894332
HKEY_CURRENT_USER\Software\Web Offer\Setup\ID Stub 1
HKEY_CURRENT_USER\Software\Web Offer\Setup\Path C:\PROGRA~1\Web Offer\
HKEY_CURRENT_USER\Software\Web Offer Hook on
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF}
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF} BarSize
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\{A166C1B0-5CDB-447A-894A-4B9FD7149D51}
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars\{A166C1B0-5CDB-447A-894A-4B9FD7149D51} BarSize
HKEY_LOCAL_MACHINE\Software\microsoft\windows\currentversion\uninstall\Web Offer
HKEY_LOCAL_MACHINE\Software\microsoft\windows\currentversion\uninstall\Web Offer DisplayName Web Offer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EZulaFSearchEng.eZulaCode.1
HKEY_LOCAL_MACHINE\Software\microsoft\windows\currentversion\uninstall\Web Offer UninstallString C:\WINDOWS\system32\ezPopStub.exe /uninstall
HKEY_LOCAL_MACHINE\Software\microsoft\windows\currentversion\uninstall\Web Offer


TargetSaver Trojan Downloader more information…
Details: TargetSaver is a process run at Windows startup, which opens pop-ups.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
C:\WINDOWS\SYSTEM32\tsuninst.exe

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TSA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TSA DisplayName TSA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TSA UninstallString C:\WINDOWS\system32\tsuninst.exe /u
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TSL Installer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TSL Installer NoRemove 1


Transponder.ABetterInternet.Ceres Spyware more information…
Details: VX2.ABetterInternet.Transponder.2 is a new transponder variant of aBetterInternet.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected registry keys/values detected
HKEY_CLASSES_ROOT\clsid\{00000049-8F91-4D9C-9573-F016E7626484}
HKEY_CURRENT_USER\Software\Ceres CSC4n3trMsgSDisp 0
HKEY_CURRENT_USER\Software\Ceres CSI4d3OfSDist 129|2|0|0|IDL.EXE
HKEY_CLASSES_ROOT\clsid\{00000049-8F91-4D9C-9573-F016E7626484}\InprocServer32 C:\WINDOWS\ceres.dll
HKEY_CLASSES_ROOT\clsid\{00000049-8F91-4D9C-9573-F016E7626484}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{00000049-8F91-4D9C-9573-F016E7626484}\ProgID Ceres.CeresObj.1
HKEY_CLASSES_ROOT\clsid\{00000049-8F91-4D9C-9573-F016E7626484}\TypeLib {92daf5c1-2135-4e0c-b7a0-259abfcd3904}
HKEY_CLASSES_ROOT\clsid\{00000049-8F91-4D9C-9573-F016E7626484}\VersionIndependentProgID Ceres.CeresObj
HKEY_CLASSES_ROOT\clsid\{00000049-8F91-4D9C-9573-F016E7626484} CeresObj Class
HKEY_CURRENT_USER\Software\Ceres
HKEY_CURRENT_USER\Software\Ceres CSI4d3OfSInst {D116D443-40BD-4D00-90CB-F105C53F0B78}


iSearch.DesktopSearch Spyware more information…
Details: Removes the users access to use Windows Search and replaces it with C:\WINDOWS\isrvs\desktop.exe.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\windows\isrvs\ffisearch.exe
c:\windows\isrvs\isearch.xpi
C:\WINDOWS\isrvs\msdbhk.dll

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ffis
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot\Enum 0 Root\LEGACY_DELPROT\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot\Enum Count 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot\Enum NextInstance 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot\Enum INITSTARTFAILED 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot Type 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot Start 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot ErrorControl 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot ImagePath \SystemRoot\system32\drivers\delprot.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot DisplayName delprot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ffis
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ffis
HKEY_CLASSES_ROOT\clsid\{950238FB-C706-4791-8674-4D429F85897E}
HKEY_CLASSES_ROOT\clsid\{950238FB-C706-4791-8674-4D429F85897E}\InprocServer32 C:\WINDOWS\isrvs\mfiltis.dll
HKEY_CLASSES_ROOT\clsid\{950238FB-C706-4791-8674-4D429F85897E} MimeFilter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Desktop Search
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\delprot\Security Security


ClipGenie Adware more information…
Details: ClipGenie displays banner advertisements in its user interface and is usually installed with file-sharing programs. ClipGenie.com is a subscription-based entertainment portal that allows you to purchase and view movies on your computer.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\Software\microsoft\windows\currentversion\uninstall\MediaLoads Enhanced
HKEY_LOCAL_MACHINE\Software\microsoft\windows\currentversion\uninstall\MediaLoads Enhanced UninstallString C:\DRIVERS\AUDIO\INSTALL.EXE "C:\Program Files\Support Software\SS2.DLL",Uninstall
HKEY_LOCAL_MACHINE\Software\microsoft\windows\currentversion\uninstall\MediaLoads Enhanced DisplayName Support Software


IEPlugin Spyware more information…
Details: IEPlugin is an Internet Explorer browser helper object that monitors URLs, content entered into forms, and local filenames and displays pops-up advertisements.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{666DDE35-E955-11D0-A707-000000521958}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{666DDE35-E955-11D0-A707-000000521958}\Contains\Files C:\WINDOWS\wupdt.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{666DDE35-E955-11D0-A707-000000521958}\DownloadInformation CODEBASE http://69.56.176.227/webplugin.cab
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{666DDE35-E955-11D0-A707-000000521958}\DownloadInformation INF C:\WINDOWS\Downloaded Program Files\default.inf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{666DDE35-E955-11D0-A707-000000521958}\InstalledVersion 0,0,0,1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{666DDE35-E955-11D0-A707-000000521958}\InstalledVersion LastModified Thu, 29 Apr 2004 05:51:47 GMT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{666DDE35-E955-11D0-A707-000000521958} SystemComponent 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{666DDE35-E955-11D0-A707-000000521958} Installer MSICD


IPInsight Browser Plug-in more information…
Details: IPInsight is a process or Internet Explorer browser helper object that monitors addresses entered into web forms to compile a database of physical locations of IP addresses.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\software\classes\ezulamain.trayiconm\clsid
HKEY_LOCAL_MACHINE\software\classes\ezulamain.trayiconm\clsid {B1DD8A69-1B96-11D4-B175-0050DAB79376}


DelFin.Media Viewer Adware more information…
Details: DelFin Media Viewer, also called PromulGate, is an adware-based media player.
Status: Removed
Moderate threat - Moderate-risk items have some potential for harm, but may be part of a wanted service. Users may decide to ignore such programs after review.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8BD9566-9895-4FA3-918D-A51D4CD15865}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\ProgID VCCPGDATAACCESS.PgDataAccessCtrl.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\ToolboxBitmap32 C:\WINDOWS\system32\nsvsvc\nsv.ocx, 1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\TypeLib {2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\Version 1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839} PgDataAccess Control
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VCCPGDATAACCESS.PgDataAccessCtrl.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VCCPGDATAACCESS.PgDataAccessCtrl.1\CLSID {D0070620-1E72-42E7-A14C-3A255AD31839}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VCCPGDATAACCESS.PgDataAccessCtrl.1 PgDataAccess Control
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8BD9566-9895-4FA3-918D-A51D4CD15865}\InprocServer32 C:\WINDOWS\system32\nsvsvc\nsv.ocx
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8BD9566-9895-4FA3-918D-A51D4CD15865} PgDataAccess Property Page
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\Control
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\InprocServer32 C:\WINDOWS\system32\nsvsvc\nsv.ocx
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\InprocServer32 ThreadingModel Apartment
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\MiscStatus\1 132241
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\MiscStatus 0


eZula.TopText Adware more information…
Details: eZula.TopText is a browser redirector that alters all pages viewed in Internet Explorer by adding extra links to words and phrases targeted by advertisers.
Status: Removed
Moderate threat - Moderate-risk items have some potential for harm, but may be part of a wanted service. Users may decide to ignore such programs after review.

Infected files detected
c:\program files\ezula\search.src
c:\program files\ezula\param.ez
c:\program files\ezula\rwds.rst
c:\program files\ezula\unwise.exe
c:\program files\ezula\upgrade.vrn
c:\program files\ezula\version.vrn
c:\program files\ezula\images\arrow1.gif
c:\program files\ezula\images\arrow2.gif
c:\program files\ezula\images\button_small.gif
c:\program files\ezula\images\icon.gif
c:\program files\ezula\images\layer_bottom.gif
c:\Program Files\eZula\wndbannn.src
c:\program files\ezula\images\layer_center.gif
c:\program files\ezula\images\layer_top.gif
c:\program files\ezula\images\new.gif
c:\program files\ezula\images\popup_follow_divider.gif
c:\program files\ezula\images\popup_follow_left.gif
c:\program files\ezula\images\popup_follow_off.gif
c:\program files\ezula\images\popup_follow_on.gif
c:\program files\ezula\images\popup_follow_right.gif
c:\program files\ezula\images\popup_top.gif
c:\program files\ezula\images\popup_top_bottom.gif
c:\program files\ezula\basis.dst
c:\program files\ezula\images\side_b.gif
c:\program files\ezula\images\side_l.gif
c:\program files\ezula\images\side_r.gif
c:\program files\ezula\images\side_top.gif
c:\program files\ezula\images\spacer.gif
c:\program files\ezula\basis.kwd
c:\program files\ezula\basis.pu
c:\program files\ezula\basis.rst
c:\program files\ezula\genun.ez
c:\program files\ezula\install.log
c:\program files\ezula\legend.lgn

Infected folders detected
c:\program files\ezula
c:\program files\ezula\images

Infected registry keys/values detected
HKEY_CLASSES_ROOT\appid\{8a044397-5da2-11d4-b185-0050dab79376}
HKEY_CLASSES_ROOT\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be}\InprocServer32 C:\PROGRA~1\ezula\seng.dll
HKEY_CLASSES_ROOT\ezulaagent.ezulactrlhost.1\CLSID {19DFB2CB-9B27-11D4-B192-0050DAB79376}
HKEY_CLASSES_ROOT\ezulaagent.ezulactrlhost.1 eZulaCtrlHost Class
HKEY_CLASSES_ROOT\ezulaagent.ezulactrlhost
HKEY_CLASSES_ROOT\ezulaagent.ezulactrlhost\CLSID {19DFB2CB-9B27-11D4-B192-0050DAB79376}
HKEY_CLASSES_ROOT\ezulaagent.ezulactrlhost\CurVer EZulaAgent.eZulaCtrlHost.1
HKEY_CLASSES_ROOT\ezulaagent.ezulactrlhost eZulaCtrlHost Class
HKEY_CLASSES_ROOT\ezulaagent.ieobject.1
HKEY_CLASSES_ROOT\ezulaagent.ieobject.1\CLSID {9CFA26C0-81DA-4C9D-A501-F144A4A000FA}
HKEY_CLASSES_ROOT\ezulaagent.ieobject.1 IEObject Class
HKEY_CLASSES_ROOT\ezulaagent.ieobject
HKEY_CLASSES_ROOT\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\ezulaagent.ieobject\CLSID {9CFA26C0-81DA-4C9D-A501-F144A4A000FA}
HKEY_CLASSES_ROOT\ezulaagent.ieobject\CurVer eZulaAgent.IEObject.1
HKEY_CLASSES_ROOT\ezulaagent.ieobject IEObject Class
HKEY_CLASSES_ROOT\ezulaagent.plugprot.1
HKEY_CLASSES_ROOT\ezulaagent.plugprot.1\CLSID {2079884B-6EF3-11D4-8A74-0050DA2EE1BE}
HKEY_CLASSES_ROOT\ezulaagent.plugprot.1 PlugProt Class
HKEY_CLASSES_ROOT\ezulaagent.plugprot
HKEY_CLASSES_ROOT\ezulaagent.plugprot\CLSID {2079884B-6EF3-11D4-8A74-0050DA2EE1BE}
HKEY_CLASSES_ROOT\ezulaagent.plugprot\CurVer EZulaAgent.PlugProt.1
HKEY_CLASSES_ROOT\ezulaagent.plugprot PlugProt Class
HKEY_CLASSES_ROOT\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be}\ProgID EZulaFSearchEng.eZulaHash.1
HKEY_CLASSES_ROOT\ezulaagent.toolbarband.1
HKEY_CLASSES_ROOT\ezulaagent.toolbarband.1\CLSID {55910916-8B4E-4C1E-9253-CCE296EA71EB}
HKEY_CLASSES_ROOT\ezulaagent.toolbarband.1 TopText
HKEY_CLASSES_ROOT\ezulaagent.toolbarband
HKEY_CLASSES_ROOT\ezulaagent.toolbarband\CLSID {55910916-8B4E-4C1E-9253-CCE296EA71EB}
HKEY_CLASSES_ROOT\ezulaagent.toolbarband TopText
HKEY_CLASSES_ROOT\ezulabootexe.installctrl.1
HKEY_CLASSES_ROOT\ezulabootexe.installctrl.1\CLSID {C03351A4-6755-11D4-8A73-0050DA2EE1BE}
HKEY_CLASSES_ROOT\ezulabootexe.installctrl.1 InstallCtrl Class
HKEY_CLASSES_ROOT\ezulabootexe.installctrl
HKEY_CLASSES_ROOT\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be}\TypeLib {07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}
HKEY_CLASSES_ROOT\ezulabootexe.installctrl\CLSID {C03351A4-6755-11D4-8A73-0050DA2EE1BE}
HKEY_CLASSES_ROOT\ezulabootexe.installctrl\CurVer EZulaBootExe.InstallCtrl.1
HKEY_CLASSES_ROOT\ezulabootexe.installctrl InstallCtrl Class
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulacode.1
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulacode.1\CLSID {25630B47-53C6-4E66-A945-9D7B6B2171FF}
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulacode.1 eZulaCode Class
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulacode
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulacode\CLSID {25630B47-53C6-4E66-A945-9D7B6B2171FF}
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulacode\CurVer EZulaFSearchEng.eZulaCode.1
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulacode eZulaCode Class
HKEY_CLASSES_ROOT\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be}\VersionIndependentProgID EZulaFSearchEng.eZulaHash
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulahash.1
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulahash.1\CLSID {788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulahash.1 eZulaHash Class
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulahash
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulahash\CLSID {788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulahash\CurVer EZulaFSearchEng.eZulaHash.1
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulahash eZulaHash Class
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulasearch.1
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulasearch.1\CLSID {370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulasearch.1 eZulaSearch Class
HKEY_CLASSES_ROOT\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be} eZulaHash Class
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulasearch
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulasearch\CLSID {370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulasearch\CurVer EZulaFSearchEng.eZulaSearch.1
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulasearch eZulaSearch Class
HKEY_CLASSES_ROOT\ezulafsearcheng.popupdisplay.1
HKEY_CLASSES_ROOT\ezulafsearcheng.popupdisplay.1\CLSID {F75521B8-76F1-4A4D-84B1-9E642E9C51D0}
HKEY_CLASSES_ROOT\ezulafsearcheng.popupdisplay.1 PopupDisplay Class
HKEY_CLASSES_ROOT\ezulafsearcheng.popupdisplay
HKEY_CLASSES_ROOT\ezulafsearcheng.popupdisplay\CLSID {F75521B8-76F1-4A4D-84B1-9E642E9C51D0}
HKEY_CLASSES_ROOT\ezulafsearcheng.popupdisplay\CurVer EZulaFSearchEng.PopupDisplay.1
HKEY_CLASSES_ROOT\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\ezulafsearcheng.popupdisplay PopupDisplay Class
HKEY_CLASSES_ROOT\ezulafsearcheng.resulthelper.1
HKEY_CLASSES_ROOT\ezulafsearcheng.resulthelper.1\CLSID {2306ABE4-4D42-11D4-8A6D-0050DA2EE1BE}
HKEY_CLASSES_ROOT\ezulafsearcheng.resulthelper.1 ResultHelper Class
HKEY_CLASSES_ROOT\ezulafsearcheng.resulthelper
HKEY_CLASSES_ROOT\ezulafsearcheng.resulthelper\CLSID {2306ABE4-4D42-11D4-8A6D-0050DA2EE1BE}
HKEY_CLASSES_ROOT\ezulafsearcheng.resulthelper\CurVer EZulaFSearchEng.ResultHelper.1
HKEY_CLASSES_ROOT\ezulafsearcheng.resulthelper ResultHelper Class
HKEY_CLASSES_ROOT\ezulafsearcheng.searchhelper.1
HKEY_CLASSES_ROOT\ezulafsearcheng.searchhelper.1\CLSID {78BCF937-45B0-40A7-9391-DCC03420DB35}
HKEY_CLASSES_ROOT\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be}\InprocServer32 C:\PROGRA~1\ezula\seng.dll
HKEY_CLASSES_ROOT\ezulafsearcheng.searchhelper.1 SearchHelper Class
HKEY_CLASSES_ROOT\ezulafsearcheng.searchhelper
HKEY_CLASSES_ROOT\ezulafsearcheng.searchhelper\CLSID {78BCF937-45B0-40A7-9391-DCC03420DB35}
HKEY_CLASSES_ROOT\ezulafsearcheng.searchhelper\CurVer EZulaFSearchEng.SearchHelper.1
HKEY_CLASSES_ROOT\ezulafsearcheng.searchhelper SearchHelper Class
HKEY_CLASSES_ROOT\ezulamain.ezulasearchpipe.1
HKEY_CLASSES_ROOT\ezulamain.ezulasearchpipe.1\CLSID {2BABD334-5C3F-11D4-B184-0050DAB79376}
HKEY_CLASSES_ROOT\ezulamain.ezulasearchpipe.1 eZulaSearchPipe Class
HKEY_CLASSES_ROOT\ezulamain.ezulasearchpipe
HKEY_CLASSES_ROOT\ezulamain.ezulasearchpipe\CLSID {2BABD334-5C3F-11D4-B184-0050DAB79376}
HKEY_CLASSES_ROOT\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\ezulamain.ezulasearchpipe\CurVer EZulaMain.eZulaSearchPipe.1
HKEY_CLASSES_ROOT\ezulamain.ezulasearchpipe eZulaSearchPipe Class
HKEY_CLASSES_ROOT\ezulamain.trayiconm.1
HKEY_CLASSES_ROOT\ezulamain.trayiconm.1\CLSID {B1DD8A69-1B96-11D4-B175-0050DAB79376}
HKEY_CLASSES_ROOT\ezulamain.trayiconm.1 TrayIConM Class
HKEY_CLASSES_ROOT\ezulamain.trayiconm
HKEY_CLASSES_ROOT\ezulamain.trayiconm\CLSID {B1DD8A69-1B96-11D4-B175-0050DAB79376}
HKEY_CLASSES_ROOT\ezulamain.trayiconm\CurVer EZulaMain.TrayIConM.1
HKEY_CLASSES_ROOT\ezulamain.trayiconm TrayIConM Class
HKEY_CLASSES_ROOT\interface\{07f0a542-47ba-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be}\ProgID EZulaFSearchEng.eZulaSearch.1
HKEY_CLASSES_ROOT\interface\{07f0a542-47ba-11d4-8a6d-0050da2ee1be}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{07f0a542-47ba-11d4-8a6d-0050da2ee1be}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{07f0a542-47ba-11d4-8a6d-0050da2ee1be}\TypeLib {07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{07f0a542-47ba-11d4-8a6d-0050da2ee1be}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{07f0a542-47ba-11d4-8a6d-0050da2ee1be} IeZulaHash
HKEY_CLASSES_ROOT\interface\{07f0a544-47ba-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{07f0a544-47ba-11d4-8a6d-0050da2ee1be}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{07f0a544-47ba-11d4-8a6d-0050da2ee1be}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{07f0a544-47ba-11d4-8a6d-0050da2ee1be}\TypeLib {07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{07f0a544-47ba-11d4-8a6d-0050da2ee1be}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\appid\{8a044397-5da2-11d4-b185-0050dab79376} eZulaMain
HKEY_CLASSES_ROOT\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be}\TypeLib {07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{07f0a544-47ba-11d4-8a6d-0050da2ee1be} IeZulaSearch
HKEY_CLASSES_ROOT\interface\{1823bc4b-a253-4767-9cfc-9aca62a6b136}
HKEY_CLASSES_ROOT\interface\{1823bc4b-a253-4767-9cfc-9aca62a6b136}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{1823bc4b-a253-4767-9cfc-9aca62a6b136}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{1823bc4b-a253-4767-9cfc-9aca62a6b136}\TypeLib {07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{1823bc4b-a253-4767-9cfc-9aca62a6b136}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{1823bc4b-a253-4767-9cfc-9aca62a6b136} IPopupDisplay
HKEY_CLASSES_ROOT\interface\{19dfb2ca-9b27-11d4-b192-0050dab79376}
HKEY_CLASSES_ROOT\interface\{19dfb2ca-9b27-11d4-b192-0050dab79376}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{19dfb2ca-9b27-11d4-b192-0050dab79376}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be}\VersionIndependentProgID EZulaFSearchEng.eZulaSearch
HKEY_CLASSES_ROOT\interface\{19dfb2ca-9b27-11d4-b192-0050dab79376}\TypeLib {58359011-BF36-11D3-99A2-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{19dfb2ca-9b27-11d4-b192-0050dab79376}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{19dfb2ca-9b27-11d4-b192-0050dab79376} IeZulaCtrlHost
HKEY_CLASSES_ROOT\interface\{27bc6871-4d5a-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{27bc6871-4d5a-11d4-8a6d-0050da2ee1be}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{27bc6871-4d5a-11d4-8a6d-0050da2ee1be}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{27bc6871-4d5a-11d4-8a6d-0050da2ee1be}\TypeLib {07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{27bc6871-4d5a-11d4-8a6d-0050da2ee1be}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{27bc6871-4d5a-11d4-8a6d-0050da2ee1be} IResultHelper
HKEY_CLASSES_ROOT\interface\{3d7247f1-5db8-11d4-8a72-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be} eZulaSearch Class
HKEY_CLASSES_ROOT\interface\{3d7247f1-5db8-11d4-8a72-0050da2ee1be}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{3d7247f1-5db8-11d4-8a72-0050da2ee1be}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{3d7247f1-5db8-11d4-8a72-0050da2ee1be}\TypeLib {07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{3d7247f1-5db8-11d4-8a72-0050da2ee1be}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{3d7247f1-5db8-11d4-8a72-0050da2ee1be} IeZulaCode
HKEY_CLASSES_ROOT\interface\{4fd8645f-9b3e-46c1-9727-9837842a84ab}
HKEY_CLASSES_ROOT\interface\{4fd8645f-9b3e-46c1-9727-9837842a84ab}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{4fd8645f-9b3e-46c1-9727-9837842a84ab}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{4fd8645f-9b3e-46c1-9727-9837842a84ab}\TypeLib {58359011-BF36-11D3-99A2-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{4fd8645f-9b3e-46c1-9727-9837842a84ab}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376}
HKEY_CLASSES_ROOT\interface\{4fd8645f-9b3e-46c1-9727-9837842a84ab} IToolBarBand
HKEY_CLASSES_ROOT\interface\{58359012-bf36-11d3-99a2-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{58359012-bf36-11d3-99a2-0050da2ee1be}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{58359012-bf36-11d3-99a2-0050da2ee1be}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{58359012-bf36-11d3-99a2-0050da2ee1be}\TypeLib {58359011-BF36-11D3-99A2-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{58359012-bf36-11d3-99a2-0050da2ee1be}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{58359012-bf36-11d3-99a2-0050da2ee1be} IIEObject
HKEY_CLASSES_ROOT\interface\{7edc96e1-5dd3-11d4-b185-0050dab79376}
HKEY_CLASSES_ROOT\interface\{7edc96e1-5dd3-11d4-b185-0050dab79376}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{7edc96e1-5dd3-11d4-b185-0050dab79376}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376}\InprocServer32 C:\PROGRA~1\eZula\eabh.dll
HKEY_CLASSES_ROOT\interface\{7edc96e1-5dd3-11d4-b185-0050dab79376}\TypeLib {8A044396-5DA2-11D4-B185-0050DAB79376}
HKEY_CLASSES_ROOT\interface\{7edc96e1-5dd3-11d4-b185-0050dab79376}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{7edc96e1-5dd3-11d4-b185-0050dab79376} IeZulaSearchPipe
HKEY_CLASSES_ROOT\interface\{8a0443a2-5da2-11d4-b185-0050dab79376}
HKEY_CLASSES_ROOT\interface\{8a0443a2-5da2-11d4-b185-0050dab79376}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{8a0443a2-5da2-11d4-b185-0050dab79376}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{8a0443a2-5da2-11d4-b185-0050dab79376}\TypeLib {9CFA26C0-81DA-4C9D-A501-F144A4A000FA}
HKEY_CLASSES_ROOT\interface\{8a0443a2-5da2-11d4-b185-0050dab79376}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{8a0443a2-5da2-11d4-b185-0050dab79376} ITrayIConM
HKEY_CLASSES_ROOT\interface\{8ebb1743-9a2f-11d4-8a7e-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\interface\{8ebb1743-9a2f-11d4-8a7e-0050da2ee1be}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{8ebb1743-9a2f-11d4-8a7e-0050da2ee1be}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{8ebb1743-9a2f-11d4-8a7e-0050da2ee1be}\TypeLib {58359011-BF36-11D3-99A2-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{8ebb1743-9a2f-11d4-8a7e-0050da2ee1be}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{8ebb1743-9a2f-11d4-8a7e-0050da2ee1be} IPlugProt
HKEY_CLASSES_ROOT\interface\{c03351a3-6755-11d4-8a73-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{c03351a3-6755-11d4-8a73-0050da2ee1be}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{c03351a3-6755-11d4-8a73-0050da2ee1be}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{c03351a3-6755-11d4-8a73-0050da2ee1be}\TypeLib {C0335197-6755-11D4-8A73-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{c03351a3-6755-11d4-8a73-0050da2ee1be}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376}\ProgID EZulaAgent.eZulaCtrlHost.1
HKEY_CLASSES_ROOT\interface\{c03351a3-6755-11d4-8a73-0050da2ee1be} IInstallCtrl
HKEY_CLASSES_ROOT\interface\{c4fee4a6-4b8b-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{c4fee4a6-4b8b-11d4-8a6d-0050da2ee1be}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{c4fee4a6-4b8b-11d4-8a6d-0050da2ee1be}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{c4fee4a6-4b8b-11d4-8a6d-0050da2ee1be}\TypeLib {07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{c4fee4a6-4b8b-11d4-8a6d-0050da2ee1be}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{c4fee4a6-4b8b-11d4-8a6d-0050da2ee1be} ISearchHelper
HKEY_CLASSES_ROOT\interface\{ef0372dc-f552-11d3-8528-0050dab79376}
HKEY_CLASSES_ROOT\interface\{ef0372dc-f552-11d3-8528-0050dab79376}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{ef0372dc-f552-11d3-8528-0050dab79376}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376}\TypeLib {58359011-BF36-11d3-99A2-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{ef0372dc-f552-11d3-8528-0050dab79376}\TypeLib {58359011-BF36-11D3-99A2-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{ef0372dc-f552-11d3-8528-0050dab79376}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{ef0372dc-f552-11d3-8528-0050dab79376} IIEButton
HKEY_CLASSES_ROOT\interface\{ef0372de-f552-11d3-8528-0050dab79376}
HKEY_CLASSES_ROOT\interface\{ef0372de-f552-11d3-8528-0050dab79376}\ProxyStubClsid {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{ef0372de-f552-11d3-8528-0050dab79376}\ProxyStubClsid32 {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\interface\{ef0372de-f552-11d3-8528-0050dab79376}\TypeLib {58359011-BF36-11D3-99A2-0050DA2EE1BE}
HKEY_CLASSES_ROOT\interface\{ef0372de-f552-11d3-8528-0050dab79376}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\interface\{ef0372de-f552-11d3-8528-0050dab79376} _IIEButtonEvents
HKEY_CLASSES_ROOT\typelib\{07f0a536-47ba-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376}\VersionIndependentProgID EZulaAgent.eZulaCtrlHost
HKEY_CLASSES_ROOT\typelib\{07f0a536-47ba-11d4-8a6d-0050da2ee1be}\1.0\0\win32 C:\PROGRA~1\ezula\seng.dll
HKEY_CLASSES_ROOT\typelib\{07f0a536-47ba-11d4-8a6d-0050da2ee1be}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\typelib\{07f0a536-47ba-11d4-8a6d-0050da2ee1be}\1.0\HELPDIR C:\PROGRA~1\ezula\
HKEY_CLASSES_ROOT\typelib\{07f0a536-47ba-11d4-8a6d-0050da2ee1be}\1.0 eZulaFSearchEng 1.0 Type Library
HKEY_CLASSES_ROOT\typelib\{083fa8f4-84f4-11d4-8a77-0050da2ee1be}
HKEY_CLASSES_ROOT\typelib\{083fa8f4-84f4-11d4-8a77-0050da2ee1be}\1.0\0\win32 C:\Program Files\Web Offer\CHPON.dll
HKEY_CLASSES_ROOT\typelib\{083fa8f4-84f4-11d4-8a77-0050da2ee1be}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\typelib\{083fa8f4-84f4-11d4-8a77-0050da2ee1be}\1.0\HELPDIR C:\Program Files\Web Offer\
HKEY_CLASSES_ROOT\typelib\{083fa8f4-84f4-11d4-8a77-0050da2ee1be}\1.0 AOLHook 1.0 Type Library
HKEY_CLASSES_ROOT\typelib\{58359011-bf36-11d3-99a2-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376} eZulaCtrlHost Class
HKEY_CLASSES_ROOT\typelib\{58359011-bf36-11d3-99a2-0050da2ee1be}\1.0\0\win32 C:\Program Files\eZula\eabh.dll
HKEY_CLASSES_ROOT\typelib\{58359011-bf36-11d3-99a2-0050da2ee1be}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\typelib\{58359011-bf36-11d3-99a2-0050da2ee1be}\1.0\HELPDIR C:\Program Files\eZula\
HKEY_CLASSES_ROOT\typelib\{58359011-bf36-11d3-99a2-0050da2ee1be}\1.0 eZulaAgent 1.0 Type Library
HKEY_CLASSES_ROOT\typelib\{8a044396-5da2-11d4-b185-0050dab79376}
HKEY_CLASSES_ROOT\typelib\{8a044396-5da2-11d4-b185-0050dab79376}\1.0\0\win32 C:\PROGRA~1\eZula\mmod.exe
HKEY_CLASSES_ROOT\typelib\{8a044396-5da2-11d4-b185-0050dab79376}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\typelib\{8a044396-5da2-11d4-b185-0050dab79376}\1.0\HELPDIR C:\PROGRA~1\eZula\
HKEY_CLASSES_ROOT\typelib\{8a044396-5da2-11d4-b185-0050dab79376}\1.0 eZulaMain 1.0 Type Library
HKEY_CLASSES_ROOT\typelib\{c0335197-6755-11d4-8a73-0050da2ee1be}
HKEY_CLASSES_ROOT\appid\{c0335198-6755-11d4-8a73-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be}
HKEY_CLASSES_ROOT\typelib\{c0335197-6755-11d4-8a73-0050da2ee1be}\1.0\0\win32 C:\WINDOWS\SYSTEM32\EZPOPS~1.EXE
HKEY_CLASSES_ROOT\typelib\{c0335197-6755-11d4-8a73-0050da2ee1be}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\typelib\{c0335197-6755-11d4-8a73-0050da2ee1be}\1.0\HELPDIR C:\WINDOWS\SYSTEM32\
HKEY_CLASSES_ROOT\typelib\{c0335197-6755-11d4-8a73-0050da2ee1be}\1.0 eZulaBootExe 1.0 Type Library
HKEY_CURRENT_USER\software\ezula
HKEY_CURRENT_USER\software\ezula\Setup\ID GEO US;PA;Willow Grove;
HKEY_CURRENT_USER\software\ezula\Setup\ID L_UP 1114275518
HKEY_CURRENT_USER\software\ezula\Setup\ID 132487469
HKEY_CURRENT_USER\software\ezula\Setup\ID Stub 1
HKEY_CURRENT_USER\software\ezula\Setup\path ImagesPath C:\PROGRA~1\eZula\images\
HKEY_CLASSES_ROOT\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be}\InprocServer32 C:\PROGRA~1\eZula\eabh.dll
HKEY_CURRENT_USER\software\ezula\Setup\path genun C:\PROGRA~1\ezula\genun.ez
HKEY_CURRENT_USER\software\ezula\Setup\path C:\PROGRA~1\eZula\
HKEY_CURRENT_USER\software\ezula\Setup BMK 1
HKEY_CURRENT_USER\software\ezula Hook on
HKEY_CURRENT_USER\software\ezula STRUP 1
HKEY_CURRENT_USER\software\ezula TPV 0
HKEY_CURRENT_USER\software\ezula NP 0
HKEY_CURRENT_USER\software\ezula ZP 0
HKEY_CURRENT_USER\software\ezula PP 0
HKEY_CURRENT_USER\software\ezula EP 0
HKEY_CLASSES_ROOT\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be}\InprocServer32 ThreadingModel Apartment
HKEY_CURRENT_USER\software\ezula HP 0
HKEY_CURRENT_USER\software\ezula BP 0
HKEY_CURRENT_USER\software\ezula WP 0
HKEY_LOCAL_MACHINE\software\classes\appid\{8a044397-5da2-11d4-b185-0050dab79376}
HKEY_LOCAL_MACHINE\software\classes\appid\{8a044397-5da2-11d4-b185-0050dab79376} eZulaMain
HKEY_LOCAL_MACHINE\software\classes\appid\{c0335198-6755-11d4-8a73-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\appid\{c0335198-6755-11d4-8a73-0050da2ee1be} eZulaBootExe
HKEY_LOCAL_MACHINE\software\classes\appid\ezulabootexe.exe
HKEY_LOCAL_MACHINE\software\classes\appid\ezulabootexe.exe AppID {C0335198-6755-11D4-8A73-0050DA2EE1BE}
HKEY_LOCAL_MACHINE\software\classes\appid\ezulamain.exe
HKEY_CLASSES_ROOT\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be}\ProgID EZulaAgent.PlugProt.1
HKEY_LOCAL_MACHINE\software\classes\appid\ezulamain.exe AppID {8A044397-5DA2-11D4-B185-0050DAB79376}
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be}\InprocServer32 C:\PROGRA~1\ezula\seng.dll
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be}\InprocServer32 ThreadingModel Apartment
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be}\ProgID EZulaFSearchEng.eZulaHash.1
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be}\TypeLib {07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be}\VersionIndependentProgID EZulaFSearchEng.eZulaHash
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a543-47ba-11d4-8a6d-0050da2ee1be} eZulaHash Class
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be}\InprocServer32 C:\PROGRA~1\ezula\seng.dll
HKEY_CLASSES_ROOT\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be}\TypeLib {58359011-BF36-11d3-99A2-0050DA2EE1BE}
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be}\InprocServer32 ThreadingModel Apartment
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be}\ProgID EZulaFSearchEng.eZulaSearch.1
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be}\TypeLib {07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be}\VersionIndependentProgID EZulaFSearchEng.eZulaSearch
HKEY_LOCAL_MACHINE\software\classes\clsid\{07f0a545-47ba-11d4-8a6d-0050da2ee1be} eZulaSearch Class
HKEY_LOCAL_MACHINE\software\classes\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376}
HKEY_LOCAL_MACHINE\software\classes\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376}\InprocServer32 C:\PROGRA~1\eZula\eabh.dll
HKEY_LOCAL_MACHINE\software\classes\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376}\InprocServer32 ThreadingModel Apartment
HKEY_LOCAL_MACHINE\software\classes\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376}\ProgID EZulaAgent.eZulaCtrlHost.1
HKEY_LOCAL_MACHINE\software\classes\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376}\TypeLib {58359011-BF36-11d3-99A2-0050DA2EE1BE}
HKEY_CLASSES_ROOT\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be}\VersionIndependentProgID EZulaAgent.PlugProt
HKEY_LOCAL_MACHINE\software\classes\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376}\VersionIndependentProgID EZulaAgent.eZulaCtrlHost
HKEY_LOCAL_MACHINE\software\classes\clsid\{19dfb2cb-9b27-11d4-b192-0050dab79376} eZulaCtrlHost Class
HKEY_LOCAL_MACHINE\software\classes\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be}\InprocServer32 C:\PROGRA~1\eZula\eabh.dll
HKEY_LOCAL_MACHINE\software\classes\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be}\InprocServer32 ThreadingModel Apartment
HKEY_LOCAL_MACHINE\software\classes\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be}\ProgID EZulaAgent.PlugProt.1
HKEY_LOCAL_MACHINE\software\classes\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be}\TypeLib {58359011-BF36-11d3-99A2-0050DA2EE1BE}
HKEY_LOCAL_MACHINE\software\classes\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be}\VersionIndependentProgID EZulaAgent.PlugProt
HKEY_LOCAL_MACHINE\software\classes\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be} PlugProt Class
HKEY_LOCAL_MACHINE\software\classes\clsid\{2306abe4-4d42-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\clsid\{2079884b-6ef3-11d4-8a74-0050da2ee1be} PlugProt Class
HKEY_LOCAL_MACHINE\software\classes\clsid\{2306abe4-4d42-11d4-8a6d-0050da2ee1be}\InprocServer32 C:\PROGRA~1\WEBOFF~1\sepng.dll
HKEY_LOCAL_MACHINE\software\classes\clsid\{2306abe4-4d42-11d4-8a6d-0050da2ee1be}\InprocServer32 ThreadingModel Apartment
HKEY_LOCAL_MACHINE\software\classes\clsid\{2306abe4-4d42-11d4-8a6d-0050da2ee1be}\ProgID EZulaFSearchEng.ResultHelper.1
HKEY_LOCAL_MACHINE\software\classes\clsid\{2306abe4-4d42-11d4-8a6d-0050da2ee1be}\TypeLib {370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}
HKEY_LOCAL_MACHINE\software\classes\clsid\{2306abe4-4d42-11d4-8a6d-0050da2ee1be}\VersionIndependentProgID EZulaFSearchEng.ResultHelper
HKEY_LOCAL_MACHINE\software\classes\clsid\{2306abe4-4d42-11d4-8a6d-0050da2ee1be} ResultHelper Class
HKEY_LOCAL_MACHINE\software\classes\clsid\{2babd334-5c3f-11d4-b184-0050dab79376}
HKEY_LOCAL_MACHINE\software\classes\clsid\{2babd334-5c3f-11d4-b184-0050dab79376}\LocalServer32 C:\PROGRA~1\eZula\mmod.exe
HKEY_LOCAL_MACHINE\software\classes\clsid\{2babd334-5c3f-11d4-b184-0050dab79376}\ProgID EZulaMain.eZulaSearchPipe.1
HKEY_LOCAL_MACHINE\software\classes\clsid\{2babd334-5c3f-11d4-b184-0050dab79376}\TypeLib {8A044396-5DA2-11D4-B185-0050DAB79376}
HKEY_CLASSES_ROOT\clsid\{2306abe4-4d42-11d4-8a6d-0050da2ee1be}
HKEY_LOCAL_MACHINE\software\classes\clsid\{2babd334-5c3f-11d4-b184-0050dab79376}\VersionIndependentProgID EZulaMain.eZulaSearchPipe
HKEY_LOCAL_MACHINE\software\classes\clsid\{2babd334-5c3f-11d4-b184-0050dab79376} eZulaSearchPipe Class
HKEY_LOCAL_MACHINE\software\classes\clsid\{2babd334-5c3f-11d4-b184-0050dab
Hijack:
Logfile of HijackThis v1.99.1
Scan saved at 4:06:53 PM, on 4/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R3 - URLSearchHook: (no name) - _{9368D063-44BE-49B9-BD14-BB9663FD38FC} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.com/"); (C:\Documents and Settings\Gary Jr\Application Data\Mozilla\Profiles\default\vdsuqq7a.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\Gary Jr\Application Data\Mozilla\Profiles\default\vdsuqq7a.slt\prefs.js)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Shorten URL - http://www.cjb.net/menuext.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…s/yinst0401.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_41.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…72/mcinsctl.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {9FC87BC7-7963-4B70-8485-B1A41034C9A1} (Sony Pictures Game Downloader) - http://www.sonypictures.com/charliesangels…eDownloader.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_In…ller/dwnldr.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - (no file)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI