This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis log For a newbie

90 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 5:39:06 PM, on 10/29/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\CNDNDlg.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\dtipgz.exe
C:\WINDOWS\System32\hnstsn.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\devldr32.exe
C:\Documents and Settings\Rameez\Desktop\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: VIPTToolbarManager Class - {1A2641AE-2C42-4C51-A05F-8ECEC3FDC94D} - C:\Program Files\Visual IP Trace\VisualIPTraceIE.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Visual IP Trace - {E70C26AE-DFF1-40A8-8D37-19180F56F0AA} - C:\Program Files\Visual IP Trace\VisualIPTraceIE.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [NeroCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [WebInstall2] C:\WINDOWS\temp\Adware\WebInstall.exe /R
O4 - HKLM\..\Run: [PP3100b] C:\WINDOWS\twain_32\paprport\3100b\flatbed.exe
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [60601443.exe] C:\WINDOWS\System32\60601443.exe
O4 - HKLM\..\Run: [5XXW7GN4CLNTRC] C:\WINDOWS\System32\Iecyl.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [Kazaa Download Accelerator Updater] regsvr32 /s C:\WINDOWS\System32\kdpupd.dll
O4 - HKLM\..\Run: [Popup Defence Updater] regsvr32 /s C:\WINDOWS\System32\pdfupd.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [{12EE7A5E-0674-42f9-A76B-000000004D00}] rundll32.exe stlb2.dll,DllRunMain
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe
O4 - HKLM\..\Run: [SurfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_5174.dll"
O4 - HKLM\..\Run: [EasyMessage] "C:\Program Files\Easy Messenger\em2.exe" -wait
O4 - HKLM\..\Run: [sau] c:\program files\180search assistant\sau.exe
O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPass.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 - HKLM\..\Run: [C:\WINDOWS\IEXPLOR.EXE] C:\WINDOWS\IEXPLOR.EXE
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [AtxBrw] C:\WINDOWS\IEXPLOR.exe
O4 - HKLM\..\Run: [1dskb6ml] C:\Program Files\1dskb6ml\1dskb6ml.exe
O4 - HKLM\..\Run: [irkx] C:\WINDOWS\irkx.exe
O4 - HKLM\..\Run: [6f84f8b4e712] C:\WINDOWS\System32\BINDFILE.exe
O4 - HKLM\..\Run: [XJFFDLL] C:\WINDOWS\XJFFDLL.EXE
O4 - HKLM\..\Run: [EWBXENC] C:\WINDOWS\EWBXENC.EXE
O4 - HKLM\..\Run: [180sacidinstaller] C:\DOCUME~1\Rameez\LOCALS~1\Temp\180SACIDInstaller.exe /did=5592
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [WebRebates0] C:\Program Files\Web_Rebates\WebRebates0.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitenbt32.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\dtipgz.exe reg_run
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [SAHBundle] C:\DOCUME~1\Rameez\LOCALS~1\Temp\sahagent-cdt1004.exe run
O4 - HKLM\..\Run: [C:\WINDOWS\VCMnet11.exe] C:\WINDOWS\VCMnet11.exe
O4 - HKLM\..\Run: [qfcjob] C:\WINDOWS\qfcjob.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0715] "C:\WINDOWS\Downloaded Program Files\CONFLICT.11\UWFX5LP_0001_0715NetInstaller.exe"
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0802] "C:\WINDOWS\Downloaded Program Files\CONFLICT.5\UWFX5LP_0001_0802NetInstaller.exe"
O4 - HKLM\..\Run: [sealmon] C:\Program Files\SealedMedia\sealmon.exe
O4 - HKLM\..\Run: [lsass] C:\windows\system32\elitevty32.exe
O4 - HKLM\..\Run: [WinFixer 2005] C:\Program Files\WinFixer 2005\wfx5.exe
O4 - HKLM\..\Run: [System service65] C:\WINDOWS\etb\pokapoka65.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127792641\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [Visualware Security Suite] "C:\Program Files\Visualware Security Suite\tscore.exe" -autostartup
O4 - HKLM\..\Run: [jbtjmzx] C:\WINDOWS\System32\hnstsn.exe r
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunOnce: [CanonWIA] rundll32 C:\WINDOWS\TWAIN_32\PSS230_W\psExtend.dll,EraceTemp
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [DR_S] C:\Program Files\DR_S\DR_S.exe
O4 - HKCU\..\Run: [sysmonnt] C:\WINDOWS\System32\sysmonnt
O4 - HKCU\..\Run: [SurfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_5174.dll"
O4 - HKCU\..\Run: [rsfmui] C:\WINDOWS\System32\rsfmui.exe
O4 - HKCU\..\Run: [Wmdt] C:\Program Files\ramc\enie.exe
O4 - HKCU\..\Run: [Wpqylvna] C:\WINDOWS\System32\w?nspool.exe
O4 - HKCU\..\Run: [areslite] "C:\Program Files\Ares Lite Edition\AresLite.exe" -h
O4 - HKCU\..\Run: [cdf1ui] C:\WINDOWS\System32\cdf1ui.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_2
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Norton System Doctor.lnk = C:\Program Files\Norton Utilities\SYSDOC32.EXE
O4 - Global Startup: Phone Connection Monitor.lnk = C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: raik.exe
O4 - Global Startup: m-trip Launcher.lnk = ?
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ConferenceRoom Java Client - http://chat.privatefeeds.com:8000/java/cr.cab
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.netpaloffers.net/NetpalOffers/DMO1/aess2.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MusicUnl…Bridge-c135.cab
O16 - DPF: {1C955F3B-5B32-4393-A05D-24B4970CD2A1} - http://streamp.babenet.com/cabs/videox.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {2ABE804B-4D3A-41BF-A172-304627874B45} - http://akamai.downloadv3.com/binaries/Dial…DHTML_US_XP.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {486E48B5-ABF2-42BB-A327-2679DF3FB822} - http://akamai.downloadv3.com/binaries/IA/ia_XP.cab
O16 - DPF: {6D5FCFCB-FA6C-4CFB-9918-5F0A9F7365F2} (GigexCtrl ActiveX) - http://www.gigex.com/tv/igor/gigexagent.dll
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4…006_regular.cab
O16 - DPF: {8522F9B3-0000-0000-0000-000000000000} - http://38.144.58.87/sex/xxxmovies.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c8.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://flashcasino.playboy.com/playboy/FlashAX.cab
O16 - DPF: {E0B795B4-FD95-4ABD-A375-27962EFCE8CF} - http://install.serviceurl.de/StarInstall.ocx
O16 - DPF: {EB623776-492A-42CA-9571-3AA39F58530B} - http://www.alwaysupdatednews.com/install/aun_0011.exe
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.logitech.com/companion/lo…1/bin/imvid.cab
O16 - DPF: {EF86873F-04C2-4A95-A373-5703C08EFC7B} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://download.rfwnad.com/cab/crack.CAB
O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} - http://66.230.146.53/EPlugin.cab
O20 - Winlogon Notify: Applets - C:\WINDOWS\system32\mvrpfs35.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MrobeService - OLYMPUS IMAGING CORP. - C:\WINDOWS\SYSTEM32\MrobeService.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Speed Disk service - Unknown owner - C:\Program Files\Speed Disk\nopdb.exe (file missing)
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)
Logfile of HijackThis v1.99.1
Scan saved at 9:23:33 AM, on 11/7/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\MrobeService.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wdtnrvq.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Alarm Clock\Alarm Clock.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Rameez\Desktop\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: VIPTToolbarManager Class - {1A2641AE-2C42-4C51-A05F-8ECEC3FDC94D} - C:\Program Files\Visual IP Trace\VisualIPTraceIE.dll
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg_5174.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Core Library - {D4D505DF-D582-400c-91B6-84921012AFE3} - C:\WINDOWS\System32\pdfupd.dll
O2 - BHO: Core Library - {F281FFC7-6C63-4bf9-83F2-AB7A6157B109} - C:\WINDOWS\System32\kdpupd.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Visual IP Trace - {E70C26AE-DFF1-40A8-8D37-19180F56F0AA} - C:\Program Files\Visual IP Trace\VisualIPTraceIE.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [NeroCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [WebInstall2] C:\WINDOWS\temp\Adware\WebInstall.exe /R
O4 - HKLM\..\Run: [PP3100b] C:\WINDOWS\twain_32\paprport\3100b\flatbed.exe
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [60601443.exe] C:\WINDOWS\System32\60601443.exe
O4 - HKLM\..\Run: [5XXW7GN4CLNTRC] C:\WINDOWS\System32\MftR.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [Kazaa Download Accelerator Updater] regsvr32 /s C:\WINDOWS\System32\kdpupd.dll
O4 - HKLM\..\Run: [Popup Defence Updater] regsvr32 /s C:\WINDOWS\System32\pdfupd.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [{12EE7A5E-0674-42f9-A76B-000000004D00}] rundll32.exe stlb2.dll,DllRunMain
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe
O4 - HKLM\..\Run: [SurfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_5174.dll"
O4 - HKLM\..\Run: [EasyMessage] "C:\Program Files\Easy Messenger\em2.exe" -wait
O4 - HKLM\..\Run: [sau] c:\program files\180search assistant\sau.exe
O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPass.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 - HKLM\..\Run: [C:\WINDOWS\IEXPLOR.EXE] C:\WINDOWS\IEXPLOR.EXE
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [AtxBrw] C:\WINDOWS\IEXPLOR.exe
O4 - HKLM\..\Run: [1dskb6ml] C:\Program Files\1dskb6ml\1dskb6ml.exe
O4 - HKLM\..\Run: [irkx] C:\WINDOWS\irkx.exe
O4 - HKLM\..\Run: [6f84f8b4e712] C:\WINDOWS\System32\BINDFILE.exe
O4 - HKLM\..\Run: [XJFFDLL] C:\WINDOWS\XJFFDLL.EXE
O4 - HKLM\..\Run: [EWBXENC] C:\WINDOWS\EWBXENC.EXE
O4 - HKLM\..\Run: [180sacidinstaller] C:\DOCUME~1\Rameez\LOCALS~1\Temp\180SACIDInstaller.exe /did=5592
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [WebRebates0] C:\Program Files\Web_Rebates\WebRebates0.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitenbt32.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\dtipgz.exe reg_run
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [SAHBundle] C:\DOCUME~1\Rameez\LOCALS~1\Temp\sahagent-cdt1004.exe run
O4 - HKLM\..\Run: [C:\WINDOWS\VCMnet11.exe] C:\WINDOWS\VCMnet11.exe
O4 - HKLM\..\Run: [qfcjob] C:\WINDOWS\qfcjob.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0715] "C:\WINDOWS\Downloaded Program Files\CONFLICT.11\UWFX5LP_0001_0715NetInstaller.exe"
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0802] "C:\WINDOWS\Downloaded Program Files\CONFLICT.5\UWFX5LP_0001_0802NetInstaller.exe"
O4 - HKLM\..\Run: [sealmon] C:\Program Files\SealedMedia\sealmon.exe
O4 - HKLM\..\Run: [lsass] C:\windows\system32\elitevty32.exe
O4 - HKLM\..\Run: [WinFixer 2005] C:\Program Files\WinFixer 2005\wfx5.exe
O4 - HKLM\..\Run: [System service65] C:\WINDOWS\etb\pokapoka65.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127792641\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [Visualware Security Suite] "C:\Program Files\Visualware Security Suite\tscore.exe" -autostartup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [fkulaxn] C:\WINDOWS\System32\wdtnrvq.exe r
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [DR_S] C:\Program Files\DR_S\DR_S.exe
O4 - HKCU\..\Run: [sysmonnt] C:\WINDOWS\System32\sysmonnt
O4 - HKCU\..\Run: [SurfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_5174.dll"
O4 - HKCU\..\Run: [rsfmui] C:\WINDOWS\System32\rsfmui.exe
O4 - HKCU\..\Run: [Wpqylvna] C:\WINDOWS\System32\w?nspool.exe
O4 - HKCU\..\Run: [areslite] "C:\Program Files\Ares Lite Edition\AresLite.exe" -h
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_2
O4 - HKCU\..\Run: [Wmdt] "C:\Program Files\ramc\enie.exe" -vt rbnd
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Norton System Doctor.lnk = C:\Program Files\Norton Utilities\SYSDOC32.EXE
O4 - Global Startup: Phone Connection Monitor.lnk = C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: raik.exe
O4 - Global Startup: m-trip Launcher.lnk = ?
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ConferenceRoom Java Client - http://chat.privatefeeds.com:8000/java/cr.cab
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.netpaloffers.net/NetpalOffers/DMO1/aess2.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MusicUnl…Bridge-c135.cab
O16 - DPF: {1C955F3B-5B32-4393-A05D-24B4970CD2A1} - http://streamp.babenet.com/cabs/videox.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {2ABE804B-4D3A-41BF-A172-304627874B45} - http://akamai.downloadv3.com/binaries/Dial…DHTML_US_XP.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {486E48B5-ABF2-42BB-A327-2679DF3FB822} - http://akamai.downloadv3.com/binaries/IA/ia_XP.cab
O16 - DPF: {6D5FCFCB-FA6C-4CFB-9918-5F0A9F7365F2} (GigexCtrl ActiveX) - http://www.gigex.com/tv/igor/gigexagent.dll
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4…006_regular.cab
O16 - DPF: {8522F9B3-0000-0000-0000-000000000000} - http://38.144.58.87/sex/xxxmovies.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c8.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://flashcasino.playboy.com/playboy/FlashAX.cab
O16 - DPF: {E0B795B4-FD95-4ABD-A375-27962EFCE8CF} - http://install.serviceurl.de/StarInstall.ocx
O16 - DPF: {EB623776-492A-42CA-9571-3AA39F58530B} - http://www.alwaysupdatednews.com/install/aun_0011.exe
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.logitech.com/companion/lo…1/bin/imvid.cab
O16 - DPF: {EF86873F-04C2-4A95-A373-5703C08EFC7B} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://download.rfwnad.com/cab/crack.CAB
O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} - http://66.230.146.53/EPlugin.cab
O20 - Winlogon Notify: Applets - C:\WINDOWS\system32\mvrpfs35.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MrobeService - OLYMPUS IMAGING CORP. - C:\WINDOWS\SYSTEM32\MrobeService.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Speed Disk service - Unknown owner - C:\Program Files\Speed Disk\nopdb.exe (file missing)
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)
Make sure you keep your Windows OS current by visiting Windows update
download and install any critical updates and service packs. With out these you are leaving the backdoor open.


Merged these threads ,donot start any more please.
I did not get MS-antispyware… or anything of the sort. I was considering going through my win32 file. Any help you can offer would be great.
hello little eagle, I updated windows as you said. but I did not recieve the program of which you spoke. I can try going through the wndows updater again. Beyond that I am not really sure what to do?
Logfile of HijackThis v1.99.1
Scan saved at 8:43:12 PM, on 11/10/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\winupdt.exe
C:\WINDOWS\SYSTEM32\MrobeService.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\sngsdvt.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Rameez\Desktop\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [NeroCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [WebInstall2] C:\WINDOWS\temp\Adware\WebInstall.exe /R
O4 - HKLM\..\Run: [PP3100b] C:\WINDOWS\twain_32\paprport\3100b\flatbed.exe
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [60601443.exe] C:\WINDOWS\System32\60601443.exe
O4 - HKLM\..\Run: [5XXW7GN4CLNTRC] C:\WINDOWS\System32\Iecyl.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [Kazaa Download Accelerator Updater] regsvr32 /s C:\WINDOWS\System32\kdpupd.dll
O4 - HKLM\..\Run: [Popup Defence Updater] regsvr32 /s C:\WINDOWS\System32\pdfupd.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [{12EE7A5E-0674-42f9-A76B-000000004D00}] rundll32.exe stlb2.dll,DllRunMain
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe
O4 - HKLM\..\Run: [SurfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_5174.dll"
O4 - HKLM\..\Run: [EasyMessage] "C:\Program Files\Easy Messenger\em2.exe" -wait
O4 - HKLM\..\Run: [sau] c:\program files\180search assistant\sau.exe
O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPass.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 - HKLM\..\Run: [C:\WINDOWS\IEXPLOR.EXE] C:\WINDOWS\IEXPLOR.EXE
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [AtxBrw] C:\WINDOWS\IEXPLOR.exe
O4 - HKLM\..\Run: [1dskb6ml] C:\Program Files\1dskb6ml\1dskb6ml.exe
O4 - HKLM\..\Run: [irkx] C:\WINDOWS\irkx.exe
O4 - HKLM\..\Run: [6f84f8b4e712] C:\WINDOWS\System32\BINDFILE.exe
O4 - HKLM\..\Run: [XJFFDLL] C:\WINDOWS\XJFFDLL.EXE
O4 - HKLM\..\Run: [EWBXENC] C:\WINDOWS\EWBXENC.EXE
O4 - HKLM\..\Run: [180sacidinstaller] C:\DOCUME~1\Rameez\LOCALS~1\Temp\180SACIDInstaller.exe /did=5592
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [WebRebates0] C:\Program Files\Web_Rebates\WebRebates0.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitenbt32.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\dtipgz.exe reg_run
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [SAHBundle] C:\DOCUME~1\Rameez\LOCALS~1\Temp\sahagent-cdt1004.exe run
O4 - HKLM\..\Run: [C:\WINDOWS\VCMnet11.exe] C:\WINDOWS\VCMnet11.exe
O4 - HKLM\..\Run: [qfcjob] C:\WINDOWS\qfcjob.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0715] "C:\WINDOWS\Downloaded Program Files\CONFLICT.11\UWFX5LP_0001_0715NetInstaller.exe"
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [sealmon] C:\Program Files\SealedMedia\sealmon.exe
O4 - HKLM\..\Run: [lsass] C:\windows\system32\elitevty32.exe
O4 - HKLM\..\Run: [WinFixer 2005] C:\Program Files\WinFixer 2005\wfx5.exe
O4 - HKLM\..\Run: [Visualware Security Suite] "C:\Program Files\Visualware Security Suite\tscore.exe" -autostartup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [System service79] C:\WINDOWS\etb\pokapoka79.exe
O4 - HKLM\..\Run: [hqcsxoy] C:\WINDOWS\System32\sngsdvt.exe r
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [DR_S] C:\Program Files\DR_S\DR_S.exe
O4 - HKCU\..\Run: [sysmonnt] C:\WINDOWS\System32\sysmonnt
O4 - HKCU\..\Run: [SurfSideKick 2] C:\Program Files\SurfSideKick 2\Ssk.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_5174.dll"
O4 - HKCU\..\Run: [rsfmui] C:\WINDOWS\System32\rsfmui.exe
O4 - HKCU\..\Run: [Wpqylvna] C:\WINDOWS\System32\w?nspool.exe
O4 - HKCU\..\Run: [areslite] "C:\Program Files\Ares Lite Edition\AresLite.exe" -h
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_2
O4 - HKCU\..\Run: [Wmdt] "C:\Program Files\ramc\enie.exe" -vt rbnd
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Norton System Doctor.lnk = C:\Program Files\Norton Utilities\SYSDOC32.EXE
O4 - Global Startup: Phone Connection Monitor.lnk = C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: m-trip Launcher.lnk = ?
O4 - Global Startup: ozjh.exe
O4 - Global Startup: raik.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ConferenceRoom Java Client - http://chat.privatefeeds.com:8000/java/cr.cab
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.netpaloffers.net/NetpalOffers/DMO1/aess2.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MusicUnl…Bridge-c135.cab
O16 - DPF: {1C955F3B-5B32-4393-A05D-24B4970CD2A1} - http://streamp.babenet.com/cabs/videox.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {2ABE804B-4D3A-41BF-A172-304627874B45} - http://akamai.downloadv3.com/binaries/Dial…DHTML_US_XP.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {486E48B5-ABF2-42BB-A327-2679DF3FB822} - http://akamai.downloadv3.com/binaries/IA/ia_XP.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6D5FCFCB-FA6C-4CFB-9918-5F0A9F7365F2} (GigexCtrl ActiveX) - http://www.gigex.com/tv/igor/gigexagent.dll
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4…006_regular.cab
O16 - DPF: {8522F9B3-0000-0000-0000-000000000000} - http://38.144.58.87/sex/xxxmovies.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c8.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://flashcasino.playboy.com/playboy/FlashAX.cab
O16 - DPF: {E0B795B4-FD95-4ABD-A375-27962EFCE8CF} - http://install.serviceurl.de/StarInstall.ocx
O16 - DPF: {EB623776-492A-42CA-9571-3AA39F58530B} - http://www.alwaysupdatednews.com/install/aun_0011.exe
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.logitech.com/companion/lo…1/bin/imvid.cab
O16 - DPF: {EF86873F-04C2-4A95-A373-5703C08EFC7B} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://download.rfwnad.com/cab/crack.CAB
O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} - http://66.230.146.53/EPlugin.cab
O20 - Winlogon Notify: Applets - C:\WINDOWS\system32\mvrpfs35.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MrobeService - OLYMPUS IMAGING CORP. - C:\WINDOWS\SYSTEM32\MrobeService.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Speed Disk service - Unknown owner - C:\Program Files\Speed Disk\nopdb.exe (file missing)
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)
Start Spybot at the top you will see mode make sure advanced mode is check. Then on the left click tools > view report In the body right click > select all > and copy the report to your next post.
— Search result list —


— System information —
Windows XP (Build: 2600)
/ DataAccess: Patch Available For XMLHTTP Vulnerability
/ DataAccess: Patch Available For XMLHTTP Vulnerability
/ DataAccess: Security update for Microsoft Data Access Components
/ DataAccess: Security Update for Microsoft Data Access Components
/ Internet Explorer 6 / SP0: Windows XP Hotfix - KB834707
/ MSXML4: Patch Available For XMLHTTP Vulnerability
/ Windows Media Player / SP0: Windows Media Player Hotfix [See wm828026 for more information]
/ Windows Media Player: Windows Media Update 320920
/ Windows Media Player: Windows Media Update 817787
/ Windows Media Player: Windows Media Update 828026
/ Windows XP / SP1: Windows XP Hotfix - KB821557
/ Windows XP / SP1: Windows XP Hotfix - KB823182
/ Windows XP / SP1: Windows XP Hotfix - KB823980
/ Windows XP / SP1: Windows XP Hotfix - KB824105
/ Windows XP / SP1: Windows XP Hotfix - KB824141
/ Windows XP / SP1: Windows XP Hotfix - KB824146
/ Windows XP / SP1: Windows XP Hotfix - KB828028
/ Windows XP / SP1: Windows XP Hotfix - KB828035
/ Windows XP / SP1 / Q309521: Windows XP Hotfix (SP1) [See Q309521 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q311889 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q311967 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q313450 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q314147 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q314862 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q315000 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q315403 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q317277 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q318138 for more information]
/ Windows XP / SP1: Windows XP Application Compatibility Update[Q319580]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q323172 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q324096 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q324380 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q326830 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q328310
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q328940 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q329048 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q329170
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q329390 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q329441 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q329834 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q331953
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q810577
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q810833
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q811493
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q811630
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q815021
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q817606
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q819696
/ Windows XP / SP2: Windows XP Hotfix - KB810217
/ Windows XP / SP2: Windows XP Hotfix - KB823559
/ Windows XP / SP2: Windows XP Hotfix - KB825119
/ Windows XP / SP2: Windows XP Hotfix - KB828741
/ Windows XP / SP2: Windows XP Hotfix - KB833987
/ Windows XP / SP2: Windows XP Hotfix - KB835732
/ Windows XP / SP2: Windows XP Hotfix - KB837001
/ Windows XP / SP2: Windows XP Hotfix - KB840987
/ Windows XP / SP2: Windows XP Hotfix - KB841356
/ Windows XP / SP2: Windows XP Hotfix - KB841533
/ Windows XP / SP2: Windows XP Hotfix - KB842773
/ Windows XP / SP2: Windows XP Hotfix - KB873376
/ Windows XP / SP2: Windows XP Hotfix - KB887822
/ Windows XP / SP2: Windows XP Hotfix (SP2) [See Q323255 for more information]
/ Windows XP / SP2: Windows XP Hotfix (SP2) [See Q329115 for more information]


— Startup entries list —
Located: HK_LM:Run, {12EE7A5E-0674-42f9-A76B-000000004D00}
command: rundll32.exe stlb2.dll,DllRunMain
file: C:\WINDOWS\system32\rundll32.exe
size: 31744
MD5: 0fb22dd37c17f80ad71316049f725170

Located: HK_LM:Run, 180sacidinstaller
command: C:\DOCUME~1\Rameez\LOCALS~1\Temp\180SACIDInstaller.exe /did=5592
file:

Located: HK_LM:Run, 1dskb6ml
command: C:\Program Files\1dskb6ml\1dskb6ml.exe
file:

Located: HK_LM:Run, 5XXW7GN4CLNTRC
command: C:\WINDOWS\System32\Iecyl.exe
file: C:\WINDOWS\System32\Iecyl.exe
size: 499742
MD5: cc7c954005f727dd4d077e7c46934680

Located: HK_LM:Run, 60601443.exe
command: C:\WINDOWS\System32\60601443.exe
file:

Located: HK_LM:Run, 6f84f8b4e712
command: C:\WINDOWS\System32\BINDFILE.exe
file:

Located: HK_LM:Run, 98D0CE0C16B1
command: rundll32.exe D0CE0C16B1,D0CE0C16B1
file: C:\WINDOWS\system32\rundll32.exe
size: 31744
MD5: 0fb22dd37c17f80ad71316049f725170

Located: HK_LM:Run, A70F6A1D-0195-42a2-934C-D8AC0F7C08EB
command: rundll32.exe E6F1873B.DLL,D9EBC318C
file: C:\WINDOWS\system32\rundll32.exe
size: 31744
MD5: 0fb22dd37c17f80ad71316049f725170

Located: HK_LM:Run, alchem
command: C:\WINDOWS\alchem.exe
file: C:\WINDOWS\alchem.exe
size: 245850
MD5: a6ddd314df702f38de44cd8944d6c417

Located: HK_LM:Run, AtxBrw
command: C:\WINDOWS\IEXPLOR.exe
file:

Located: HK_LM:Run, AudioHQ
command: C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
file: C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
size: 180224
MD5: 3c9e8a339cc7799d670454bac7675340

Located: HK_LM:Run, AUNPS2
command: RUNDLL32 AUNPS2.DLL,_Run@16
file:

Located: HK_LM:Run, BullsEye Network
command: C:\Program Files\BullsEye Network\bin\bargains.exe
file:

Located: HK_LM:Run, C:\WINDOWS\IEXPLOR.EXE
command: C:\WINDOWS\IEXPLOR.EXE
file:

Located: HK_LM:Run, C:\WINDOWS\VCMnet11.exe
command: C:\WINDOWS\VCMnet11.exe
file: C:\WINDOWS\VCMnet11.exe
size: 39835
MD5: 0c3b8c47b25c347602eb9f4d870a3ff2

Located: HK_LM:Run, cfgmgr52
command: RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
file: C:\WINDOWS\system32\RunDLL32.EXE
size: 31744
MD5: 0fb22dd37c17f80ad71316049f725170

Located: HK_LM:Run, checkrun
command: C:\windows\system32\elitenbt32.exe
file:

Located: HK_LM:Run, Dinst
command: C:\WINDOWS\dinst.exe
file: C:\WINDOWS\dinst.exe
size: 65536
MD5: a7cd14f70fe54faea5e2a6b030dcaa3a

Located: HK_LM:Run, EasyMessage
command: "C:\Program Files\Easy Messenger\em2.exe" -wait
file:

Located: HK_LM:Run, EWBXENC
command: C:\WINDOWS\EWBXENC.EXE
file: C:\WINDOWS\EWBXENC.EXE
size: 126976
MD5: 260b728a83e713b13e06e7c2d1e79602

Located: HK_LM:Run, exp.exe
command: C:\WINDOWS\System32\exp.exe
file:

Located: HK_LM:Run, hqcsxoy
command: C:\WINDOWS\System32\sngsdvt.exe r
file: C:\WINDOWS\System32\sngsdvt.exe
size: 91136
MD5: 7975326325d8ca306c12b9eecc01b052

Located: HK_LM:Run, Internet Optimizer
command: "C:\Program Files\Internet Optimizer\optimize.exe"
file:

Located: HK_LM:Run, irkx
command: C:\WINDOWS\irkx.exe
file:

Located: HK_LM:Run, iTunesHelper
command: "C:\Program Files\iTunes\iTunesHelper.exe"
file: C:\Program Files\iTunes\iTunesHelper.exe
size: 278528
MD5: ff95f200b0cb3810382b355cf9f0bed9

Located: HK_LM:Run, Kazaa Download Accelerator Updater
command: regsvr32 /s C:\WINDOWS\System32\kdpupd.dll
file:

Located: HK_LM:Run, lsass
command: C:\windows\system32\elitevty32.exe
file:

Located: HK_LM:Run, Media Access
command: C:\Program Files\Media Access\MediaAccK.exe
file:

Located: HK_LM:Run, Media Pass
command: C:\Program Files\Media Pass\MediaPass.exe
file:

Located: HK_LM:Run, msnappau
command: "C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-us\msnappau.exe"
file:

Located: HK_LM:Run, navapp
command: C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
file: C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
size: 167936
MD5: 1cca2dfb6515c4bcba5b1b1b2da6c0d7

Located: HK_LM:Run, NaviSearch
command: C:\Program Files\NaviSearch\bin\nls.exe
file:

Located: HK_LM:Run, NeroCheck
command: C:\windows\system32\NeroCheck.exe
file: C:\windows\system32\NeroCheck.exe
size: 155648
MD5: 3e4c03cefad8de135263236b61a49c90

Located: HK_LM:Run, NI.UWFX5LP_0001_0715
command: "C:\WINDOWS\Downloaded Program Files\CONFLICT.11\UWFX5LP_0001_0715NetInstaller.exe"
file: C:\WINDOWS\Downloaded Program Files\CONFLICT.11\UWFX5LP_0001_0715NetInstaller.exe
size: 34304
MD5: dfa7132be409353572bf6abf5d02b763

Located: HK_LM:Run, NvCplDaemon
command: RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 31744
MD5: 0fb22dd37c17f80ad71316049f725170

Located: HK_LM:Run, PCShield
command: regsvr32 /s "C:\WINDOWS\System32\sfg_5174.dll"
file:

Located: HK_LM:Run, Popup Defence Updater
command: regsvr32 /s C:\WINDOWS\System32\pdfupd.dll
file:

Located: HK_LM:Run, PP3100b
command: C:\WINDOWS\twain_32\paprport\3100b\flatbed.exe
file:

Located: HK_LM:Run, qfcjob
command: C:\WINDOWS\qfcjob.exe
file: C:\WINDOWS\qfcjob.exe
size: 94208
MD5: bf8489ef5e9bdfc21ffd2b7de5bb546c

Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 155648
MD5: 216b3acc656cda8a5a0c3071ec0a408b

Located: HK_LM:Run, SAHBundle
command: C:\DOCUME~1\Rameez\LOCALS~1\Temp\sahagent-cdt1004.exe run
file:

Located: HK_LM:Run, salm
command: c:\temp\salm.exe
file: c:\temp\salm.exe
size: 282624
MD5: 97d1792f15d0a1f1701002885cfbd981

Located: HK_LM:Run, sau
command: c:\program files\180search assistant\sau.exe
file:

Located: HK_LM:Run, sealmon
command: C:\Program Files\SealedMedia\sealmon.exe
file: C:\Program Files\SealedMedia\sealmon.exe
size: 94208
MD5: d2a6040c53e4d99c9ba6ad623b79ef2e

Located: HK_LM:Run, SM1BG
command: C:\WINDOWS\SM1BG.EXE
file:

Located: HK_LM:Run, SunJavaUpdateSched
command: C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
file: C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
size: 36975
MD5: 70de314a16e5a486a0ef2425014685b2

Located: HK_LM:Run, SurfSideKick 2
command: C:\Program Files\SurfSideKick 2\Ssk.exe
file:

Located: HK_LM:Run, System service79
command: C:\WINDOWS\etb\pokapoka79.exe
file: C:\WINDOWS\etb\pokapoka79.exe
size: 148480
MD5: 807fcb10c817836af1f0f6f5e9b944f4

Located: HK_LM:Run, SystemTray
command: SysTray.Exe
file: C:\WINDOWS\system32\SysTray.Exe
size: 3072
MD5: 46e07fd3a40760fda18cf6b4fc691742

Located: HK_LM:Run, TkBellExe
command: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
file: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
size: 180269
MD5: f9b47f830dd55fedd6ef27d063c29a42

Located: HK_LM:Run, VBouncer
command: C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
file:

Located: HK_LM:Run, Visualware Security Suite
command: "C:\Program Files\Visualware Security Suite\tscore.exe" -autostartup
file: C:\Program Files\Visualware Security Suite\tscore.exe
size: 92955
MD5: d8a054baa43d47cbea3451154d4db332

Located: HK_LM:Run, WebInstall2
command: C:\WINDOWS\temp\Adware\WebInstall.exe /R
file:

Located: HK_LM:Run, WebRebates0
command: C:\Program Files\Web_Rebates\WebRebates0.exe
file:

Located: HK_LM:Run, Win Server Updt
command: C:\WINDOWS\wupdt.exe
file:

Located: HK_LM:Run, WinFixer 2005
command: C:\Program Files\WinFixer 2005\wfx5.exe
file: C:\Program Files\WinFixer 2005\wfx5.exe
size: 2002944
MD5: 945afff3719210d425566121fea08ea4

Located: HK_LM:Run, winsync
command: C:\WINDOWS\System32\dtipgz.exe reg_run
file: C:\WINDOWS\System32\dtipgz.exe
size: 417792
MD5: 152d612d51828633db2aba8b7958b340

Located: HK_LM:Run, WinTask driver
command: C:\WINDOWS\System32\wintask.exe
file:

Located: HK_LM:Run, WinTools
command: C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
file:

Located: HK_LM:Run, winupdtl
command: C:\WINDOWS\System32\winupdt.exe
file: C:\WINDOWS\System32\winupdt.exe
size: 36864
MD5: b6dbd6cbbfd55f036576d7cdaee6436d

Located: HK_LM:Run, XJFFDLL
command: C:\WINDOWS\XJFFDLL.EXE
file: C:\WINDOWS\XJFFDLL.EXE
size: 61440
MD5: 1f3d6ed7a2e109acef7f0deb7b6f6d7c

Located: HK_CU:Run, areslite
command: "C:\Program Files\Ares Lite Edition\AresLite.exe" -h
file:

Located: HK_CU:Run, DR_S
command: C:\Program Files\DR_S\DR_S.exe
file:

Located: HK_CU:Run, msnmsgr
command: "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
file: C:\Program Files\MSN Messenger\MsnMsgr.Exe
size: 6856704
MD5: 79ac63592f9b6750f2026a2520c11bee

Located: HK_CU:Run, NVIEW
command: rundll32.exe nview.dll,nViewLoadHook
file: C:\WINDOWS\system32\rundll32.exe
size: 31744
MD5: 0fb22dd37c17f80ad71316049f725170

Located: HK_CU:Run, PCShield
command: regsvr32 /s "C:\WINDOWS\System32\sfg_5174.dll"
file:

Located: HK_CU:Run, rsfmui
command: C:\WINDOWS\System32\rsfmui.exe
file:

Located: HK_CU:Run, SurfSideKick 2
command: C:\Program Files\SurfSideKick 2\Ssk.exe
file:

Located: HK_CU:Run, sysmonnt
command: C:\WINDOWS\System32\sysmonnt
file: C:\WINDOWS\System32\sysmonnt.exe
size: 110592
MD5: 3ee451b5b43c5361300a3854f1a24e4c

Located: HK_CU:Run, updateMgr
command: C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_2
file:

Located: HK_CU:Run, Wmdt
command: "C:\Program Files\ramc\enie.exe" -vt rbnd
file: C:\Program Files\ramc\enie.exe
size: 68096
MD5: 0f027b4464e91b280bf853494879e2e6

Located: HK_CU:Run, Wpqylvna
command: C:\WINDOWS\System32\w?nspool.exe
file: C:\WINDOWS\System32\w?nspool.exe
size: 0
MD5: d41d8cd98f00b204e9800998ecf8427e ???

Located: Startup (common), Adobe Gamma Loader.lnk
command: C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
file: C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
size: 110592
MD5: 5cd0cd0ec4dc5df459b3ac016764f5aa

Located: Startup (common), Adobe Reader Speed Launch.lnk
command: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
file: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
size: 29696
MD5: deb88aef013dd1eefb462d7cad642166

Located: Startup (common), Microsoft Office.lnk
command: C:\Program Files\Microsoft Office\Office\Osa9.exe
file:

Located: Startup (common), Microsoft Works Calendar Reminders.lnk
command: C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
file: C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
size: 24633
MD5: 7084b58a098d2f83b304832251a8c6a8

Located: Startup (common), m-trip Launcher.lnk
command: C:\Program Files\OLYMPUS\m-trip\Bin\m-tripLauncher.exe
file: C:\Program Files\OLYMPUS\m-trip\Bin\m-tripLauncher.exe
size: 53248
MD5: e240719adac411c8b2aa1da444ae2303

Located: Startup (common), Norton System Doctor.lnk
command: C:\Program Files\Norton Utilities\SYSDOC32.EXE
file:

Located: Startup (common), Phone Connection Monitor.lnk
command: C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe
file: C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe
size: 795136
MD5: c5dddafe8f70543b818138cd15be1b39

Located: WinLogon, Applets
command: C:\WINDOWS\system32\mvrpfs35.dll
file: C:\WINDOWS\system32\mvrpfs35.dll

Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll

Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll

Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll

Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll

Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll

Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll

Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll

Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll

Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll



— Browser helper object list —
{00F1D395-4744-40f0-A611-980F61AE2C59} (Band Class)
BHO name:
CLSID name: Band Class
Path: C:\WINDOWS\
Long name: dsr.dll
Short name:
Date (created): 7/25/2005 5:17:14 PM
Date (last access): 11/11/2005
Date (last write): 7/5/2005 11:58:40 AM
Filesize: 286720
Attributes: archive
MD5: 38EE1BD59165FDD85DEEF431BF0B0EAB
CRC32: 5DB82FAD
Version: 1.0.8.2

{53707962-6F74-2D53-2644-206D7942484F} ()
BHO name:
CLSID name:
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDhelper.dll
info link: http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\Program Files\Spybot - Search & Destroy\
Long name: SDHelper.dll
Short name: SDHELPER.DLL
Date (created): 11/11/2005 1:53:46 PM
Date (last access): 11/11/2005
Date (last write): 5/31/2005 1:04:00 AM
Filesize: 853672
Attributes: archive
MD5: 250D787A5712D7768DDC133B3E477759
CRC32: D4589A41
Version: 1.4.0.0

{7C554162-8CB7-45A4-B8F4-8EA1C75885F9} (AOL Toolbar Launcher)
BHO name: AOL Toolbar Launcher
CLSID name: AOL Toolbar Launcher
Path: C:\Program Files\AOL\AOL Toolbar 2.0\
Long name: aoltb.dll
Short name:
Date (created): 8/2/2005 2:41:14 PM
Date (last access): 11/11/2005
Date (last write): 8/2/2005 2:41:14 PM
Filesize: 524288
Attributes: archive
MD5: E9419CBE1260D5C38AE67F7A8EFA768F
CRC32: 6A853EE0
Version: 2.0.4239.61



— ActiveX list —
ConferenceRoom Java Client (ConferenceRoom Java Client)
DPF name: ConferenceRoom Java Client
CLSID name:
Installer:
Codebase: http://chat.privatefeeds.com:8000/java/cr.cab

DirectAnimation Java Classes (DirectAnimation Java Classes)
DPF name: DirectAnimation Java Classes
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\SYSTEM\dajava.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\dajava.cab
info link:
info source: Patrick M. Kolla

Internet Explorer Classes for Java (Internet Explorer Classes for Java)
DPF name: Internet Explorer Classes for Java
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\SYSTEM\iejava.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\iejava.cab
info link:
info source: Patrick M. Kolla

Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\Java\classes\xmldso.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla

{00000075-9980-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\voxacm.inf
Codebase: http://codecs.microsoft.com/codecs/i386/voxacm.CAB
description: Microsoft Audio Codec
classification: Legitimate
known filename: VOXACM.CAB
info link:
info source: Patrick M. Kolla

{00000161-0000-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\msaudio.inf
Codebase: http://codecs.microsoft.com/codecs/i386/msaudio.cab
description: Microsoft Audio Codec
classification: Legitimate
known filename: MSAUDIO.CAB
info link:
info source: Patrick M. Kolla

{00000EF1-0786-4633-87C6-1AA7A44296DA} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\aesss2.inf
Codebase: http://www.netpaloffers.net/NetpalOffers/DMO1/aess2.cab
description: FavoriteMan
classification: Confirmed as malware
known filename: n3tpa1p.dll
Calsdr.dll
Gr0*.dll
* = digit)
td1.dll
random file names
info link: http://www.doxdesk.com/parasite/FavoriteMan.html
info source: TonyKlein

{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object)
DPF name:
CLSID name: QuickTime Object
Installer: C:\WINDOWS\Downloaded Program Files\QTPlugin.inf
Codebase: http://www.apple.com/qtactivex/qtplugin.cab
description: Apple Quicktime
classification: Legitimate
known filename: QTPLUGIN.OCX
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\QuickTime\
Long name: QTPlugin.ocx
Short name: QTPLUGIN.OCX
Date (created): 10/24/2005 5:00:36 AM
Date (last access): 11/9/2005
Date (last write): 10/24/2005 5:00:36 AM
Filesize: 409600
Attributes: archive
MD5: D2B462A22F89C8A74B02EDDA130AF616
CRC32: 99C4835D
Version: 7.0.3.50

{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} ()
DPF name:
CLSID name:
Installer:
Codebase: http://static.windupdates.com/cab/MusicUnl…Bridge-c135.cab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: MediaPassX.dll
Short name: MEDIAP~1.DLL
Date (created): 3/1/2005 4:57:08 PM
Date (last access): 3/7/2005
Date (last write): 3/1/2005 4:57:08 PM
Filesize: 24064
Attributes: archive
MD5: B44DD96C20F6C968F0AB624DB5257E79
CRC32: 6D505971

{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
DPF name:
CLSID name: Shockwave ActiveX Control
Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
Codebase: http://fpdownload.macromedia.com/pub/shock…ector/swdir.cab
description: Macromedia ShockWave Flash Player 7
classification: Unknown
known filename: SWDIR.DLL
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\SYSTEM32\MACROMED\DIRECTOR\
Long name: SWDIR.DLL
Short name:
Date (created): 1/1/1980
Date (last access): 10/31/2005
Date (last write): 9/9/2004 2:49:12 PM
Filesize: 54488
Attributes: archive
MD5: 943193399C341AC34E842CB07B5F29A0
CRC32: 12DEB8F4
Version: 10.1.0.11

{1C955F3B-5B32-4393-A05D-24B4970CD2A1} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\videox.inf
Codebase: http://streamp.babenet.com/cabs/videox.cab
description: Dialer
classification: Confirmed as malware
known filename:
info link:
info source: JavaCool

{205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class)
DPF name:
CLSID name: CInstall Class
Installer: C:\WINDOWS\Downloaded Program Files\Install.inf
Codebase: http://www.errorguard.com/installation/Install.cab
Path: C:\WINDOWS\DOWNLO~1\
Long name: Install.dll
Short name: INSTALL.DLL
Date (created): 9/30/2004 11:46:24 AM
Date (last access): 10/29/2005
Date (last write): 9/30/2004 11:46:24 AM
Filesize: 315392
Attributes: archive
MD5: B2F217B063FFE01DA62EF1181E726F0E
CRC32: C78ECDD3
Version: 2.0.0.6

{2ABE804B-4D3A-41BF-A172-304627874B45} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\EGDHTML.inf
Codebase: http://akamai.downloadv3.com/binaries/Dial…DHTML_US_XP.cab

{31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player)
DPF name:
CLSID name: Cult3D ActiveX Player
Installer: C:\WINDOWS\Downloaded Program Files\Cult.inf
Codebase: http://www.cult3d.com/download/cult.cab
Path: C:\WINDOWS\System32\Cult3D\
Long name: IECult.dll
Short name: IECULT.DLL
Date (created): 1/7/2004 4:00:06 PM
Date (last access): 1/25/2005
Date (last write): 1/7/2004 4:00:06 PM
Filesize: 1888256
Attributes: archive
MD5: 422FE2685963C2A83A8FF2139124FF9B
CRC32: 25DD48C0
Version: 5.3.0.228

{32564D57-9980-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\wmv8dmo.inf
Codebase: http://codecs.microsoft.com/codecs/i386/wmv8dmo.cab

{33363249-0000-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\i263_32.inf
Codebase: http://codecs.microsoft.com/codecs/i386/i263_32.cab

{33564D57-0000-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\WMV9VCM.inf
Codebase: http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB

{486E48B5-ABF2-42BB-A327-2679DF3FB822} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\ia.inf
Codebase: http://akamai.downloadv3.com/binaries/IA/ia_XP.cab
Path: C:\WINDOWS\System32\
Long name: ia.dll

{4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool)
DPF name:
CLSID name: MSN Photo Upload Tool
Installer: C:\WINDOWS\Downloaded Program Files\MSNPupld.inf
Codebase: http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: MsnPUpld.dll
Short name: MSNPUPLD.DLL
Date (created): 10/8/2004 4:01:22 PM
Date (last access): 11/8/2005
Date (last write): 10/8/2004 4:01:22 PM
Filesize: 372736
Attributes: archive
MD5: D2ED523BB0FE94F8F492BEFE1C336040
CRC32: C4677625
Version: 10.0.910.0

{6D5FCFCB-FA6C-4CFB-9918-5F0A9F7365F2} (GigexCtrl ActiveX)
DPF name:
CLSID name: GigexCtrl ActiveX
Installer:
Codebase: http://www.gigex.com/tv/igor/gigexagent.dll
Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
Long name: gigexagent.dll
Short name: GIGEXA~1.DLL
Date (created): 5/18/2002 3:30:20 PM
Date (last access): 5/1/2005
Date (last write): 5/18/2002 3:30:20 PM
Filesize: 116512
Attributes: archive
MD5: 56F1C050E78D55A700443CD9E7D08A95
CRC32: 73BB51CC
Version: 1.0.1.1

{75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl)
DPF name:
CLSID name: SecureLogin.SecureControl
Installer: C:\WINDOWS\Downloaded Program Files\ActiveSecurity.INF
Codebase: http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: ActiveSecurity.ocx
Short name: ACTIVE~1.OCX
Date (created): 1/24/2003 1:04:56 PM
Date (last access): 10/29/2005
Date (last write): 1/24/2003 1:04:56 PM
Filesize: 49152
Attributes: archive
MD5: EDE07DD29CB68347555639D27F789B1B
CRC32: 4732D4F6
Version: 1.0.0.0

{7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class)
DPF name:
CLSID name: Installer Class
Installer:
Codebase: http://www.xxxtoolbar.com/ist/softwares/v4…006_regular.cab
Path: C:\WINDOWS\Downloaded Program Files\CONFLICT.2\
Long name: istactivex.dll
Short name: ISTACT~1.DLL
Date (created): 4/20/2005 1:59:14 PM
Date (last access): 4/21/2005
Date (last write): 4/20/2005 1:59:14 PM
Filesize: 40960
Attributes: archive
MD5: 92DF522BE531F211CF2B636F53AC040E
CRC32: C336C18D
Version: 1.0.0.3

{8522F9B3-0000-0000-0000-000000000000} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\dialer.inf
Codebase: http://38.144.58.87/sex/xxxmovies.cab

{8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} ()
DPF name:
CLSID name:
Installer:
Codebase: http://static.zangocash.com/cab/Zango/ie/bridge-c8.cab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: MediaGatewayX.dll

{9F1C11AA-197B-4942-BA54-47A8489BB47F} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\iuctl.inf
Codebase: http://v4.windowsupdate.microsoft.com/CAB/…7464.6103009259
description: Windows Update
classification: Legitimate
known filename: %WINDIR%\System32\iuctl.dll,iuengine.dll
info link:
info source: Patrick M. Kolla

{B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class)
DPF name:
CLSID name: MsnMessengerSetupDownloadControl Class
Installer: C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.inf
Codebase: http://messenger.msn.com/download/MsnMesse…pDownloader.cab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: MsnMessengerSetupDownloader.ocx
Short name: MSNMES~1.OCX
Date (created): 11/5/2004 3:58:20 PM
Date (last access): 10/29/2005
Date (last write): 11/5/2004 3:58:20 PM
Filesize: 119496
Attributes: archive
MD5: 1B40AA6A5D25E6CB4EDFC4C717113161
CRC32: 4F5D45E3
Version: 1.0.0.1

{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf
Codebase: http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\System32\Macromed\Flash\
Long name: Flash8.ocx
Short name: FLASH8.OCX
Date (created): 8/27/2005 1:38:56 PM
Date (last access): 11/11/2005
Date (last write): 8/27/2005 1:38:56 PM
Filesize: 1435272
Attributes: archive
MD5: 900373C059C2B51CA91BF110DBDECB33
CRC32: F19599BC
Version: 8.0.22.0

{D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object)
DPF name:
CLSID name: FlashXControl Object
Installer: C:\WINDOWS\Downloaded Program Files\FlashAX.inf
Codebase: https://flashcasino.playboy.com/playboy/FlashAX.cab
Path: C:\WINDOWS\System32\FlashAX\
Long name: FlashAX.ocx
Short name: FLASHAX.OCX
Date (created): 7/31/2001 2:50:18 PM
Date (last access): 10/29/2005
Date (last write): 7/31/2001 2:50:18 PM
Filesize: 61440
Attributes: archive
MD5: 158987167DD5A96FEB0E98FC5BC551E7
CRC32: E7E61874
Version: 1.0.0.1

{E0B795B4-FD95-4ABD-A375-27962EFCE8CF} ()
DPF name:
CLSID name:
Installer:
Codebase: http://install.serviceurl.de/StarInstall.ocx
description: StarDialer
classification: Confirmed as malware
known filename:
info link:
info source: JavaCool

{EB623776-492A-42CA-9571-3AA39F58530B} ()
DPF name:
CLSID name:
Installer:
Codebase: http://www.alwaysupdatednews.com/install/aun_0011.exe

{EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class)
DPF name:
CLSID name: IMViewerControl Class
Installer: C:\WINDOWS\Downloaded Program Files\CyclopsV.inf
Codebase: http://companion.logitech.com/companion/lo…1/bin/imvid.cab
Path: C:\WINDOWS\System32\
Long name: CIMVIEW.dll
Short name:
Date (created): 12/6/2002 12:23:34 PM
Date (last access): 1/25/2005
Date (last write): 12/6/2002 12:23:34 PM
Filesize: 233472
Attributes: archive
MD5: 5F17D483D473F7D45CD956471093D42F
CRC32: 14E11832
Version: 1.3.0.2041

{EF86873F-04C2-4A95-A373-5703C08EFC7B} (Installer Class)
DPF name:
CLSID name: Installer Class
Installer: C:\WINDOWS\Downloaded Program Files\CONFLICT.1\istactivex.inf
Codebase: http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
Path: C:\WINDOWS\Downloaded Program Files\CONFLICT.1\
Long name: ISTactivex.dll
Short name: ISTACT~1.DLL
Date (created): 4/13/2004 5:29:38 PM
Date (last access): 1/25/2005
Date (last write): 4/13/2004 5:29:38 PM
Filesize: 15872
Attributes: archive
MD5: 5BA2BC28E0CB39C889C7C0639BAE7A00
CRC32: 0C8201DD
Version: 1.0.0.2

{F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control)
DPF name:
CLSID name: ddm_download.ddm_control
Installer: C:\WINDOWS\Downloaded Program Files\test.INF
Codebase: http://download.rfwnad.com/cab/crack.CAB
Path: C:\WINDOWS\Downloaded Program Files\
Long name: TEST.OCX
Short name:
Date (created): 11/1/2003 12:15:18 AM
Date (last access): 1/25/2005
Date (last write): 11/1/2003 12:15:18 AM
Filesize: 22528
Attributes: archive
MD5: 07DC7D5AB373D8DA0B2BD1832B2B799B
CRC32: 1E2F51AE
Version: 1.0.0.0

{F57D17AE-CE37-4BC8-B232-EA57747BE5E7} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\EPlugin.inf
Codebase: http://66.230.146.53/EPlugin.cab
description: ePlugin dialer
classification: Confirmed as malware
known filename:
info link:
info source: JavaCool



— Process list —
PID: 0 ( 0) [System]
PID: 376 ( 4) \SystemRoot\System32\smss.exe
PID: 456 ( 376) \??\C:\WINDOWS\system32\winlogon.exe
PID: 500 ( 456) C:\WINDOWS\system32\services.exe
size: 101376
MD5: E3DF4A0252D287C44606EE55355E1623
PID: 512 ( 456) C:\WINDOWS\system32\lsass.exe
size: 11776
MD5: 8A590EA109B5E0C7629E022F8A6B17C5
PID: 672 ( 500) C:\WINDOWS\system32\svchost.exe
size: 12800
MD5: 0F7D9C87B0CE1FA520473119752C6F79
PID: 708 ( 500) C:\WINDOWS\System32\svchost.exe
size: 12800
MD5: 0F7D9C87B0CE1FA520473119752C6F79
PID: 1028 ( 500) C:\WINDOWS\system32\spoolsv.exe
size: 51200
MD5: 9B4155BA58192D4073082B8FC5D42612
PID: 1652 (1180) C:\WINDOWS\System32\winupdt.exe
size: 36864
MD5: B6DBD6CBBFD55F036576D7CDAEE6436D
PID: 2012 ( 500) C:\WINDOWS\SYSTEM32\MrobeService.exe
size: 65536
MD5: AAA87053842524EE271A9B8B2016FCA5
PID: 156 ( 500) C:\Program Files\Norton Utilities\NPROTECT.EXE
size: 135168
MD5: 236408D8B6263F3C6FB992B6D2B4BDA6
PID: 268 ( 500) C:\WINDOWS\System32\nvsvc32.exe
size: 61440
MD5: C40149797D2473E63ECF2C716A75DA15
PID: 392 ( 500) C:\WINDOWS\System32\svchost.exe
size: 12800
MD5: 0F7D9C87B0CE1FA520473119752C6F79
PID: 1728 ( 500) C:\Program Files\iPod\bin\iPodService.exe
size: 323584
MD5: 20AF3FDD673B9B4AE6FAE2C52598CC68
PID: 3816 ( 456) C:\WINDOWS\Explorer.exe
size: 1000960
MD5: 5A26FC6010886D25B3E412493DD95ED8
PID: 5076 (3816) C:\WINDOWS\System32\sngsdvt.exe
size: 91136
MD5: 7975326325D8CA306C12B9EECC01B052
PID: 5724 (5076) C:\WINDOWS\System32\devldr32.exe
size: 25600
MD5: D874723E025C465990B5F105715361F7
PID: 8216 (3816) C:\Program Files\MSN Messenger\msnmsgr.exe
size: 6856704
MD5: 79AC63592F9B6750F2026A2520C11BEE
PID: 7824 (2380) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 4393096
MD5: 09CA174A605B480318731E691DC98539
PID: 9152 ( 672) C:\Program Files\Internet Explorer\iexplore.exe
size: 91136
MD5: 92B1834F54EAB14B0B7137E6CEF5E1B2
PID: 4 ( 0) System
PID: 432 ( 376) CSRSS.EXE
PID: 788 ( 500) SVCHOST.EXE
PID: 872 ( 500) SVCHOST.EXE
PID: 808 ( 500) WDFMGR.EXE


— Browser start & search pages list —
Spybot - Search & Destroy browser pages report, 11/11/2005 1:55:32 PM



— Winsock Layered Service Provider list —
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 3: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 4: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6D096F48-BD7E-4B9F-B071-03EFB31D1AF0}] SEQPACKET 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6D096F48-BD7E-4B9F-B071-03EFB31D1AF0}] DATAGRAM 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0548E80F-2509-4337-9CED-1A89708B953E}] SEQPACKET 7
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0548E80F-2509-4337-9CED-1A89708B953E}] DATAGRAM 7
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CA6C27DA-5328-4146-98EA-4253A970F4AE}] SEQPACKET 6
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CA6C27DA-5328-4146-98EA-4253A970F4AE}] DATAGRAM 6
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7675D9EE-5B25-4123-970B-012FFEE68949}] SEQPACKET 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7675D9EE-5B25-4123-970B-012FFEE68949}] DATAGRAM 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{87A54DEC-62A0-4D7B-B490-52196C6702CF}] SEQPACKET 8
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{87A54DEC-62A0-4D7B-B490-52196C6702CF}] DATAGRAM 8
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A28B8032-3916-4B49-BF9C-2B560F4BAE15}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A28B8032-3916-4B49-BF9C-2B560F4BAE15}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip_{59F531F5-7281-4887-B49B-DDD4B3B7161A}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 18: MSAFD NetBIOS [\Device\NetBT_Tcpip_{59F531F5-7281-4887-B49B-DDD4B3B7161A}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 19: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B65836F-A0C5-45A8-9A4B-80D1C6FBFF8C}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 20: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B65836F-A0C5-45A8-9A4B-80D1C6FBFF8C}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 21: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CBC4611F-CFB2-468B-8631-0A1F57DFD18E}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 22: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CBC4611F-CFB2-468B-8631-0A1F57DFD18E}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP

Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS

Namespace Provider 2: Network Location Awareness (NLA) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace



— Uninstall list —
Search Aid (100)
uninstall cmd: C:\Program Files\1dskb6ml\72637472.exe -f5

Alt Win (146)
uninstall cmd: C:\Program Files\1dskb6ml\72637472.exe -f8

URL Display (401)
uninstall cmd: C:\Program Files\1dskb6ml\72637472.exe -f3

IE Host R3 (434937897cc3)
uninstall cmd: C:\WINDOWS\System32\HPFimg20.exe

RON Display (820)
uninstall cmd: C:\Program Files\1dskb6ml\72637472.exe -f7

Context Display (937)
uninstall cmd: C:\Program Files\1dskb6ml\72637472.exe -f4

(AddressBook)
uninstall cmd: "C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:IE50 /UNINSTALL /PROMPT

Adobe Acrobat 5.0 5.0 (Adobe Acrobat 5.0)
version (major): 5
install location: C:\Program Files\Adobe\Acrobat 5.0
install source: C:\Documents and Settings\Rameez\Local Settings\Temp\pft5~tmp\
uninstall cmd: C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
publisher: Adobe Systems, Inc.
help link: http://www.adobe.com/prodindex/acrobat/main.html

Adobe Photoshop 7.0 7.0 (Adobe Photoshop 7.0)
version (major): 7
install location: C:\Program Files\Adobe\Photoshop 7.0
install source: E:\Photoshop\
uninstall cmd: C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
publisher: Adobe Systems, Inc.

Adobe Premiere 6.0 6.0 (Adobe Premiere 6.0)
install location: C:\Program Files\Adobe\Premiere 6.0
install source: E:\ADOBE~17.0\
uninstall cmd: C:\WINDOWS\UNINST.EXE -f"C:\Program Files\Adobe\Premiere 6.0\DeIsL1.isu" -c"C:\Program Files\Adobe\Premiere 6.0\Uninst.dll"
publisher: Adobe Systems, Inc.

Adobe SVG Viewer 3.0 3.0 (Adobe SVG Viewer)
version (major): 3
install location: C:\windows\System32\Adobe\SVG Viewer 3.0
uninstall cmd: C:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Install.log

Adobe Download Manager 2.0 (Remove Only) 2.0 (AdobeESD)
uninstall cmd: "C:\Program Files\Common Files\Adobe\ESD\uninst.exe"

Alarm Clock v1.0 (Alarm Clock_is1)
uninstall cmd: "C:\Program Files\Alarm Clock\unins000.exe"
publisher: Moore Design Lmt.
help link: http://www.scottflute.com

AMD Bus Master IDE Driver (AMD Bus Master IDE Driver)
uninstall cmd: C:\PROGRA~1\AMDEIDE\UNWISE.EXE /A C:\PROGRA~1\AMDEIDE\INSTALL.LOG

AOL Instant Messenger (AOL Instant Messenger)
uninstall cmd: C:\Program Files\AIM95\uninstll.exe -LOG= C:\Program Files\AIM95\install.log -OEM=

AOL Toolbar 2.0 (AOL Toolbar)
uninstall cmd: "C:\Program Files\AOL\AOL Toolbar 2.0\uninstall.exe"

AudioHQ (AudioHQ)
uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Creative\SBLive\AudioHQ.isu"

Babe Arcade (Babe Arcade)
uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\CherrySoft\Babe Arcade\Uninst.isu"

BitComet 0.60 0.60 (BitComet)
uninstall cmd: C:\Program Files\BitComet\uninst.exe
publisher: ~RnySmile~

BitTorrent 3.3 (BitTorrent)
uninstall cmd: "C:\Program Files\BitTorrent\uninstall.exe"

(Branding)

The Best Offers (bsto-1)
uninstall cmd: C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\boncpar.htm
publisher: The Best Offers Network
contact: [removed]
help link: http://www.bestoffersnetworks.com/uninstall

CDex extraction audio (CDex)
uninstall cmd: "C:\Program Files\CDex_150\uninstall.exe"

Cleaner 5 EZ (Cleaner 5 EZ)
uninstall cmd: C:\WINDOWS\unvise32.exe C:\Program Files\Cleaner 5 EZ\uninstal.log

(Connection Manager)

Creative Surround Mixer (Creative Surround Mixer)
uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Creative\SBLive\SurMixer.isu"

dBpowerAMP Music Converter (dBpowerAMP Music Converter)
uninstall cmd: "C:\WINDOWS\System32\SpoonUninstall.exe" C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP Music Converter.dat

dBpowerAMP Real Audio Codec (dBpowerAMP Real Audio Codec)
uninstall cmd: "C:\WINDOWS\System32\SpoonUninstall.exe" C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP Real Audio Codec.dat

dBPowerAMP Real Audio Encoder R3 (dBPowerAMP Real Audio Encoder R3)
uninstall cmd: "C:\WINDOWS\System32\SpoonUninstall.exe" C:\WINDOWS\System32\SpoonUninstall-dBPowerAMP Real Audio Encoder R3.dat

dBpowerAMP WMA V9 Codec (dBpowerAMP WMA V9 Codec)
uninstall cmd: "C:\WINDOWS\System32\SpoonUninstall.exe" C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP WMA V9 Codec.dat

(DeinstKey)

Win32 BI Application (DHost)
uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\payload.inf, Uninstall

(DirectAnimation)

(DirectDrawEx)

Remove DivX Codec (DivX Codec)
uninstall cm
— Search result list —


— System information —
Windows XP (Build: 2600)
/ DataAccess: Patch Available For XMLHTTP Vulnerability
/ DataAccess: Patch Available For XMLHTTP Vulnerability
/ DataAccess: Security update for Microsoft Data Access Components
/ DataAccess: Security Update for Microsoft Data Access Components
/ Internet Explorer 6 / SP0: Windows XP Hotfix - KB834707
/ MSXML4: Patch Available For XMLHTTP Vulnerability
/ Windows Media Player / SP0: Windows Media Player Hotfix [See wm828026 for more information]
/ Windows Media Player: Windows Media Update 320920
/ Windows Media Player: Windows Media Update 817787
/ Windows Media Player: Windows Media Update 828026
/ Windows XP / SP1: Windows XP Hotfix - KB821557
/ Windows XP / SP1: Windows XP Hotfix - KB823182
/ Windows XP / SP1: Windows XP Hotfix - KB823980
/ Windows XP / SP1: Windows XP Hotfix - KB824105
/ Windows XP / SP1: Windows XP Hotfix - KB824141
/ Windows XP / SP1: Windows XP Hotfix - KB824146
/ Windows XP / SP1: Windows XP Hotfix - KB828028
/ Windows XP / SP1: Windows XP Hotfix - KB828035
/ Windows XP / SP1 / Q309521: Windows XP Hotfix (SP1) [See Q309521 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q311889 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q311967 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q313450 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q314147 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q314862 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q315000 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q315403 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q317277 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q318138 for more information]
/ Windows XP / SP1: Windows XP Application Compatibility Update[Q319580]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q323172 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q324096 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q324380 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q326830 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q328310
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q328940 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q329048 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q329170
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q329390 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q329441 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) [See Q329834 for more information]
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q331953
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q810577
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q810833
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q811493
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q811630
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q815021
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q817606
/ Windows XP / SP1: Windows XP Hotfix (SP1) Q819696
/ Windows XP / SP2: Windows XP Hotfix - KB810217
/ Windows XP / SP2: Windows XP Hotfix - KB823559
/ Windows XP / SP2: Windows XP Hotfix - KB825119
/ Windows XP / SP2: Windows XP Hotfix - KB828741
/ Windows XP / SP2: Windows XP Hotfix - KB833987
/ Windows XP / SP2: Windows XP Hotfix - KB835732
/ Windows XP / SP2: Windows XP Hotfix - KB837001
/ Windows XP / SP2: Windows XP Hotfix - KB840987
/ Windows XP / SP2: Windows XP Hotfix - KB841356
/ Windows XP / SP2: Windows XP Hotfix - KB841533
/ Windows XP / SP2: Windows XP Hotfix - KB842773
/ Windows XP / SP2: Windows XP Hotfix - KB873376
/ Windows XP / SP2: Windows XP Hotfix - KB887822
/ Windows XP / SP2: Windows XP Hotfix (SP2) [See Q323255 for more information]
/ Windows XP / SP2: Windows XP Hotfix (SP2) [See Q329115 for more information]


— Startup entries list —
Located: HK_LM:Run, {12EE7A5E-0674-42f9-A76B-000000004D00}
command: rundll32.exe stlb2.dll,DllRunMain
file: C:\WINDOWS\system32\rundll32.exe
size: 31744
MD5: 0fb22dd37c17f80ad71316049f725170

Located: HK_LM:Run, 180sacidinstaller
command: C:\DOCUME~1\Rameez\LOCALS~1\Temp\180SACIDInstaller.exe /did=5592
file:

Located: HK_LM:Run, 1dskb6ml
command: C:\Program Files\1dskb6ml\1dskb6ml.exe
file:

Located: HK_LM:Run, 5XXW7GN4CLNTRC
command: C:\WINDOWS\System32\Iecyl.exe
file: C:\WINDOWS\System32\Iecyl.exe
size: 499742
MD5: cc7c954005f727dd4d077e7c46934680

Located: HK_LM:Run, 60601443.exe
command: C:\WINDOWS\System32\60601443.exe
file:

Located: HK_LM:Run, 6f84f8b4e712
command: C:\WINDOWS\System32\BINDFILE.exe
file:

Located: HK_LM:Run, 98D0CE0C16B1
command: rundll32.exe D0CE0C16B1,D0CE0C16B1
file: C:\WINDOWS\system32\rundll32.exe
size: 31744
MD5: 0fb22dd37c17f80ad71316049f725170

Located: HK_LM:Run, A70F6A1D-0195-42a2-934C-D8AC0F7C08EB
command: rundll32.exe E6F1873B.DLL,D9EBC318C
file: C:\WINDOWS\system32\rundll32.exe
size: 31744
MD5: 0fb22dd37c17f80ad71316049f725170

Located: HK_LM:Run, alchem
command: C:\WINDOWS\alchem.exe
file: C:\WINDOWS\alchem.exe
size: 245850
MD5: a6ddd314df702f38de44cd8944d6c417

Located: HK_LM:Run, AtxBrw
command: C:\WINDOWS\IEXPLOR.exe
file:

Located: HK_LM:Run, AudioHQ
command: C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
file: C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
size: 180224
MD5: 3c9e8a339cc7799d670454bac7675340

Located: HK_LM:Run, AUNPS2
command: RUNDLL32 AUNPS2.DLL,_Run@16
file:

Located: HK_LM:Run, BullsEye Network
command: C:\Program Files\BullsEye Network\bin\bargains.exe
file:

Located: HK_LM:Run, C:\WINDOWS\IEXPLOR.EXE
command: C:\WINDOWS\IEXPLOR.EXE
file:

Located: HK_LM:Run, C:\WINDOWS\VCMnet11.exe
command: C:\WINDOWS\VCMnet11.exe
file: C:\WINDOWS\VCMnet11.exe
size: 39835
MD5: 0c3b8c47b25c347602eb9f4d870a3ff2

Located: HK_LM:Run, cfgmgr52
command: RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
file: C:\WINDOWS\system32\RunDLL32.EXE
size: 31744
MD5: 0fb22dd37c17f80ad71316049f725170

Located: HK_LM:Run, checkrun
command: C:\windows\system32\elitenbt32.exe
file:

Located: HK_LM:Run, Dinst
command: C:\WINDOWS\dinst.exe
file: C:\WINDOWS\dinst.exe
size: 65536
MD5: a7cd14f70fe54faea5e2a6b030dcaa3a

Located: HK_LM:Run, EasyMessage
command: "C:\Program Files\Easy Messenger\em2.exe" -wait
file:

Located: HK_LM:Run, EWBXENC
command: C:\WINDOWS\EWBXENC.EXE
file: C:\WINDOWS\EWBXENC.EXE
size: 126976
MD5: 260b728a83e713b13e06e7c2d1e79602

Located: HK_LM:Run, exp.exe
command: C:\WINDOWS\System32\exp.exe
file:

Located: HK_LM:Run, hqcsxoy
command: C:\WINDOWS\System32\sngsdvt.exe r
file: C:\WINDOWS\System32\sngsdvt.exe
size: 91136
MD5: 7975326325d8ca306c12b9eecc01b052

Located: HK_LM:Run, Internet Optimizer
command: "C:\Program Files\Internet Optimizer\optimize.exe"
file:

Located: HK_LM:Run, irkx
command: C:\WINDOWS\irkx.exe
file:

Located: HK_LM:Run, iTunesHelper
command: "C:\Program Files\iTunes\iTunesHelper.exe"
file: C:\Program Files\iTunes\iTunesHelper.exe
size: 278528
MD5: ff95f200b0cb3810382b355cf9f0bed9

Located: HK_LM:Run, Kazaa Download Accelerator Updater
command: regsvr32 /s C:\WINDOWS\System32\kdpupd.dll
file:

Located: HK_LM:Run, lsass
command: C:\windows\system32\elitevty32.exe
file:

Located: HK_LM:Run, Media Access
command: C:\Program Files\Media Access\MediaAccK.exe
file:

Located: HK_LM:Run, Media Pass
command: C:\Program Files\Media Pass\MediaPass.exe
file:

Located: HK_LM:Run, msnappau
command: "C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-us\msnappau.exe"
file:

Located: HK_LM:Run, navapp
command: C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
file: C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
size: 167936
MD5: 1cca2dfb6515c4bcba5b1b1b2da6c0d7

Located: HK_LM:Run, NaviSearch
command: C:\Program Files\NaviSearch\bin\nls.exe
file:

Located: HK_LM:Run, NeroCheck
command: C:\windows\system32\NeroCheck.exe
file: C:\windows\system32\NeroCheck.exe
size: 155648
MD5: 3e4c03cefad8de135263236b61a49c90

Located: HK_LM:Run, NI.UWFX5LP_0001_0715
command: "C:\WINDOWS\Downloaded Program Files\CONFLICT.11\UWFX5LP_0001_0715NetInstaller.exe"
file: C:\WINDOWS\Downloaded Program Files\CONFLICT.11\UWFX5LP_0001_0715NetInstaller.exe
size: 34304
MD5: dfa7132be409353572bf6abf5d02b763

Located: HK_LM:Run, NvCplDaemon
command: RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 31744
MD5: 0fb22dd37c17f80ad71316049f725170

Located: HK_LM:Run, PCShield
command: regsvr32 /s "C:\WINDOWS\System32\sfg_5174.dll"
file:

Located: HK_LM:Run, Popup Defence Updater
command: regsvr32 /s C:\WINDOWS\System32\pdfupd.dll
file:

Located: HK_LM:Run, PP3100b
command: C:\WINDOWS\twain_32\paprport\3100b\flatbed.exe
file:

Located: HK_LM:Run, qfcjob
command: C:\WINDOWS\qfcjob.exe
file: C:\WINDOWS\qfcjob.exe
size: 94208
MD5: bf8489ef5e9bdfc21ffd2b7de5bb546c

Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 155648
MD5: 216b3acc656cda8a5a0c3071ec0a408b

Located: HK_LM:Run, SAHBundle
command: C:\DOCUME~1\Rameez\LOCALS~1\Temp\sahagent-cdt1004.exe run
file:

Located: HK_LM:Run, salm
command: c:\temp\salm.exe
file: c:\temp\salm.exe
size: 282624
MD5: 97d1792f15d0a1f1701002885cfbd981

Located: HK_LM:Run, sau
command: c:\program files\180search assistant\sau.exe
file:

Located: HK_LM:Run, sealmon
command: C:\Program Files\SealedMedia\sealmon.exe
file: C:\Program Files\SealedMedia\sealmon.exe
size: 94208
MD5: d2a6040c53e4d99c9ba6ad623b79ef2e

Located: HK_LM:Run, SM1BG
command: C:\WINDOWS\SM1BG.EXE
file:

Located: HK_LM:Run, SunJavaUpdateSched
command: C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
file: C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
size: 36975
MD5: 70de314a16e5a486a0ef2425014685b2

Located: HK_LM:Run, SurfSideKick 2
command: C:\Program Files\SurfSideKick 2\Ssk.exe
file:

Located: HK_LM:Run, System service79
command: C:\WINDOWS\etb\pokapoka79.exe
file: C:\WINDOWS\etb\pokapoka79.exe
size: 148480
MD5: 807fcb10c817836af1f0f6f5e9b944f4

Located: HK_LM:Run, SystemTray
command: SysTray.Exe
file: C:\WINDOWS\system32\SysTray.Exe
size: 3072
MD5: 46e07fd3a40760fda18cf6b4fc691742

Located: HK_LM:Run, TkBellExe
command: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
file: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
size: 180269
MD5: f9b47f830dd55fedd6ef27d063c29a42

Located: HK_LM:Run, VBouncer
command: C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
file:

Located: HK_LM:Run, Visualware Security Suite
command: "C:\Program Files\Visualware Security Suite\tscore.exe" -autostartup
file: C:\Program Files\Visualware Security Suite\tscore.exe
size: 92955
MD5: d8a054baa43d47cbea3451154d4db332

Located: HK_LM:Run, WebInstall2
command: C:\WINDOWS\temp\Adware\WebInstall.exe /R
file:

Located: HK_LM:Run, WebRebates0
command: C:\Program Files\Web_Rebates\WebRebates0.exe
file:

Located: HK_LM:Run, Win Server Updt
command: C:\WINDOWS\wupdt.exe
file:

Located: HK_LM:Run, WinFixer 2005
command: C:\Program Files\WinFixer 2005\wfx5.exe
file: C:\Program Files\WinFixer 2005\wfx5.exe
size: 2002944
MD5: 945afff3719210d425566121fea08ea4

Located: HK_LM:Run, winsync
command: C:\WINDOWS\System32\dtipgz.exe reg_run
file: C:\WINDOWS\System32\dtipgz.exe
size: 417792
MD5: 152d612d51828633db2aba8b7958b340

Located: HK_LM:Run, WinTask driver
command: C:\WINDOWS\System32\wintask.exe
file:

Located: HK_LM:Run, WinTools
command: C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
file:

Located: HK_LM:Run, winupdtl
command: C:\WINDOWS\System32\winupdt.exe
file: C:\WINDOWS\System32\winupdt.exe
size: 36864
MD5: b6dbd6cbbfd55f036576d7cdaee6436d

Located: HK_LM:Run, XJFFDLL
command: C:\WINDOWS\XJFFDLL.EXE
file: C:\WINDOWS\XJFFDLL.EXE
size: 61440
MD5: 1f3d6ed7a2e109acef7f0deb7b6f6d7c

Located: HK_CU:Run, areslite
command: "C:\Program Files\Ares Lite Edition\AresLite.exe" -h
file:

Located: HK_CU:Run, DR_S
command: C:\Program Files\DR_S\DR_S.exe
file:

Located: HK_CU:Run, msnmsgr
command: "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
file: C:\Program Files\MSN Messenger\MsnMsgr.Exe
size: 6856704
MD5: 79ac63592f9b6750f2026a2520c11bee

Located: HK_CU:Run, NVIEW
command: rundll32.exe nview.dll,nViewLoadHook
file: C:\WINDOWS\system32\rundll32.exe
size: 31744
MD5: 0fb22dd37c17f80ad71316049f725170

Located: HK_CU:Run, PCShield
command: regsvr32 /s "C:\WINDOWS\System32\sfg_5174.dll"
file:

Located: HK_CU:Run, rsfmui
command: C:\WINDOWS\System32\rsfmui.exe
file:

Located: HK_CU:Run, SurfSideKick 2
command: C:\Program Files\SurfSideKick 2\Ssk.exe
file:

Located: HK_CU:Run, sysmonnt
command: C:\WINDOWS\System32\sysmonnt
file: C:\WINDOWS\System32\sysmonnt.exe
size: 110592
MD5: 3ee451b5b43c5361300a3854f1a24e4c

Located: HK_CU:Run, updateMgr
command: C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_2
file:

Located: HK_CU:Run, Wmdt
command: "C:\Program Files\ramc\enie.exe" -vt rbnd
file: C:\Program Files\ramc\enie.exe
size: 68096
MD5: 0f027b4464e91b280bf853494879e2e6

Located: HK_CU:Run, Wpqylvna
command: C:\WINDOWS\System32\w?nspool.exe
file: C:\WINDOWS\System32\w?nspool.exe
size: 0
MD5: d41d8cd98f00b204e9800998ecf8427e ???

Located: Startup (common), Adobe Gamma Loader.lnk
command: C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
file: C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
size: 110592
MD5: 5cd0cd0ec4dc5df459b3ac016764f5aa

Located: Startup (common), Adobe Reader Speed Launch.lnk
command: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
file: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
size: 29696
MD5: deb88aef013dd1eefb462d7cad642166

Located: Startup (common), Microsoft Office.lnk
command: C:\Program Files\Microsoft Office\Office\Osa9.exe
file:

Located: Startup (common), Microsoft Works Calendar Reminders.lnk
command: C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
file: C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
size: 24633
MD5: 7084b58a098d2f83b304832251a8c6a8

Located: Startup (common), m-trip Launcher.lnk
command: C:\Program Files\OLYMPUS\m-trip\Bin\m-tripLauncher.exe
file: C:\Program Files\OLYMPUS\m-trip\Bin\m-tripLauncher.exe
size: 53248
MD5: e240719adac411c8b2aa1da444ae2303

Located: Startup (common), Norton System Doctor.lnk
command: C:\Program Files\Norton Utilities\SYSDOC32.EXE
file:

Located: Startup (common), Phone Connection Monitor.lnk
command: C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe
file: C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe
size: 795136
MD5: c5dddafe8f70543b818138cd15be1b39

Located: WinLogon, Applets
command: C:\WINDOWS\system32\mvrpfs35.dll
file: C:\WINDOWS\system32\mvrpfs35.dll

Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll

Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll

Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll

Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll

Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll

Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll

Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll

Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll

Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll



— Browser helper object list —
{00F1D395-4744-40f0-A611-980F61AE2C59} (Band Class)
BHO name:
CLSID name: Band Class
Path: C:\WINDOWS\
Long name: dsr.dll
Short name:
Date (created): 7/25/2005 5:17:14 PM
Date (last access): 11/11/2005
Date (last write): 7/5/2005 11:58:40 AM
Filesize: 286720
Attributes: archive
MD5: 38EE1BD59165FDD85DEEF431BF0B0EAB
CRC32: 5DB82FAD
Version: 1.0.8.2

{53707962-6F74-2D53-2644-206D7942484F} ()
BHO name:
CLSID name:
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDhelper.dll
info link: http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\Program Files\Spybot - Search & Destroy\
Long name: SDHelper.dll
Short name: SDHELPER.DLL
Date (created): 11/11/2005 1:53:46 PM
Date (last access): 11/11/2005
Date (last write): 5/31/2005 1:04:00 AM
Filesize: 853672
Attributes: archive
MD5: 250D787A5712D7768DDC133B3E477759
CRC32: D4589A41
Version: 1.4.0.0

{7C554162-8CB7-45A4-B8F4-8EA1C75885F9} (AOL Toolbar Launcher)
BHO name: AOL Toolbar Launcher
CLSID name: AOL Toolbar Launcher
Path: C:\Program Files\AOL\AOL Toolbar 2.0\
Long name: aoltb.dll
Short name:
Date (created): 8/2/2005 2:41:14 PM
Date (last access): 11/11/2005
Date (last write): 8/2/2005 2:41:14 PM
Filesize: 524288
Attributes: archive
MD5: E9419CBE1260D5C38AE67F7A8EFA768F
CRC32: 6A853EE0
Version: 2.0.4239.61



— ActiveX list —
ConferenceRoom Java Client (ConferenceRoom Java Client)
DPF name: ConferenceRoom Java Client
CLSID name:
Installer:
Codebase: http://chat.privatefeeds.com:8000/java/cr.cab

DirectAnimation Java Classes (DirectAnimation Java Classes)
DPF name: DirectAnimation Java Classes
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\SYSTEM\dajava.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\dajava.cab
info link:
info source: Patrick M. Kolla

Internet Explorer Classes for Java (Internet Explorer Classes for Java)
DPF name: Internet Explorer Classes for Java
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\SYSTEM\iejava.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\iejava.cab
info link:
info source: Patrick M. Kolla

Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\Java\classes\xmldso.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla

{00000075-9980-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\voxacm.inf
Codebase: http://codecs.microsoft.com/codecs/i386/voxacm.CAB
description: Microsoft Audio Codec
classification: Legitimate
known filename: VOXACM.CAB
info link:
info source: Patrick M. Kolla

{00000161-0000-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\msaudio.inf
Codebase: http://codecs.microsoft.com/codecs/i386/msaudio.cab
description: Microsoft Audio Codec
classification: Legitimate
known filename: MSAUDIO.CAB
info link:
info source: Patrick M. Kolla

{00000EF1-0786-4633-87C6-1AA7A44296DA} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\aesss2.inf
Codebase: http://www.netpaloffers.net/NetpalOffers/DMO1/aess2.cab
description: FavoriteMan
classification: Confirmed as malware
known filename: n3tpa1p.dll
Calsdr.dll
Gr0*.dll
* = digit)
td1.dll
random file names
info link: http://www.doxdesk.com/parasite/FavoriteMan.html
info source: TonyKlein

{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object)
DPF name:
CLSID name: QuickTime Object
Installer: C:\WINDOWS\Downloaded Program Files\QTPlugin.inf
Codebase: http://www.apple.com/qtactivex/qtplugin.cab
description: Apple Quicktime
classification: Legitimate
known filename: QTPLUGIN.OCX
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\QuickTime\
Long name: QTPlugin.ocx
Short name: QTPLUGIN.OCX
Date (created): 10/24/2005 5:00:36 AM
Date (last access): 11/9/2005
Date (last write): 10/24/2005 5:00:36 AM
Filesize: 409600
Attributes: archive
MD5: D2B462A22F89C8A74B02EDDA130AF616
CRC32: 99C4835D
Version: 7.0.3.50

{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} ()
DPF name:
CLSID name:
Installer:
Codebase: http://static.windupdates.com/cab/MusicUnl…Bridge-c135.cab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: MediaPassX.dll
Short name: MEDIAP~1.DLL
Date (created): 3/1/2005 4:57:08 PM
Date (last access): 3/7/2005
Date (last write): 3/1/2005 4:57:08 PM
Filesize: 24064
Attributes: archive
MD5: B44DD96C20F6C968F0AB624DB5257E79
CRC32: 6D505971

{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
DPF name:
CLSID name: Shockwave ActiveX Control
Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
Codebase: http://fpdownload.macromedia.com/pub/shock…ector/swdir.cab
description: Macromedia ShockWave Flash Player 7
classification: Unknown
known filename: SWDIR.DLL
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\SYSTEM32\MACROMED\DIRECTOR\
Long name: SWDIR.DLL
Short name:
Date (created): 1/1/1980
Date (last access): 10/31/2005
Date (last write): 9/9/2004 2:49:12 PM
Filesize: 54488
Attributes: archive
MD5: 943193399C341AC34E842CB07B5F29A0
CRC32: 12DEB8F4
Version: 10.1.0.11

{1C955F3B-5B32-4393-A05D-24B4970CD2A1} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\videox.inf
Codebase: http://streamp.babenet.com/cabs/videox.cab
description: Dialer
classification: Confirmed as malware
known filename:
info link:
info source: JavaCool

{205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class)
DPF name:
CLSID name: CInstall Class
Installer: C:\WINDOWS\Downloaded Program Files\Install.inf
Codebase: http://www.errorguard.com/installation/Install.cab
Path: C:\WINDOWS\DOWNLO~1\
Long name: Install.dll
Short name: INSTALL.DLL
Date (created): 9/30/2004 11:46:24 AM
Date (last access): 10/29/2005
Date (last write): 9/30/2004 11:46:24 AM
Filesize: 315392
Attributes: archive
MD5: B2F217B063FFE01DA62EF1181E726F0E
CRC32: C78ECDD3
Version: 2.0.0.6

{2ABE804B-4D3A-41BF-A172-304627874B45} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\EGDHTML.inf
Codebase: http://akamai.downloadv3.com/binaries/Dial…DHTML_US_XP.cab

{31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player)
DPF name:
CLSID name: Cult3D ActiveX Player
Installer: C:\WINDOWS\Downloaded Program Files\Cult.inf
Codebase: http://www.cult3d.com/download/cult.cab
Path: C:\WINDOWS\System32\Cult3D\
Long name: IECult.dll
Short name: IECULT.DLL
Date (created): 1/7/2004 4:00:06 PM
Date (last access): 1/25/2005
Date (last write): 1/7/2004 4:00:06 PM
Filesize: 1888256
Attributes: archive
MD5: 422FE2685963C2A83A8FF2139124FF9B
CRC32: 25DD48C0
Version: 5.3.0.228

{32564D57-9980-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\wmv8dmo.inf
Codebase: http://codecs.microsoft.com/codecs/i386/wmv8dmo.cab

{33363249-0000-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\i263_32.inf
Codebase: http://codecs.microsoft.com/codecs/i386/i263_32.cab

{33564D57-0000-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\WMV9VCM.inf
Codebase: http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB

{486E48B5-ABF2-42BB-A327-2679DF3FB822} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\ia.inf
Codebase: http://akamai.downloadv3.com/binaries/IA/ia_XP.cab
Path: C:\WINDOWS\System32\
Long name: ia.dll

{4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool)
DPF name:
CLSID name: MSN Photo Upload Tool
Installer: C:\WINDOWS\Downloaded Program Files\MSNPupld.inf
Codebase: http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: MsnPUpld.dll
Short name: MSNPUPLD.DLL
Date (created): 10/8/2004 4:01:22 PM
Date (last access): 11/8/2005
Date (last write): 10/8/2004 4:01:22 PM
Filesize: 372736
Attributes: archive
MD5: D2ED523BB0FE94F8F492BEFE1C336040
CRC32: C4677625
Version: 10.0.910.0

{6D5FCFCB-FA6C-4CFB-9918-5F0A9F7365F2} (GigexCtrl ActiveX)
DPF name:
CLSID name: GigexCtrl ActiveX
Installer:
Codebase: http://www.gigex.com/tv/igor/gigexagent.dll
Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
Long name: gigexagent.dll
Short name: GIGEXA~1.DLL
Date (created): 5/18/2002 3:30:20 PM
Date (last access): 5/1/2005
Date (last write): 5/18/2002 3:30:20 PM
Filesize: 116512
Attributes: archive
MD5: 56F1C050E78D55A700443CD9E7D08A95
CRC32: 73BB51CC
Version: 1.0.1.1

{75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl)
DPF name:
CLSID name: SecureLogin.SecureControl
Installer: C:\WINDOWS\Downloaded Program Files\ActiveSecurity.INF
Codebase: http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: ActiveSecurity.ocx
Short name: ACTIVE~1.OCX
Date (created): 1/24/2003 1:04:56 PM
Date (last access): 10/29/2005
Date (last write): 1/24/2003 1:04:56 PM
Filesize: 49152
Attributes: archive
MD5: EDE07DD29CB68347555639D27F789B1B
CRC32: 4732D4F6
Version: 1.0.0.0

{7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class)
DPF name:
CLSID name: Installer Class
Installer:
Codebase: http://www.xxxtoolbar.com/ist/softwares/v4…006_regular.cab
Path: C:\WINDOWS\Downloaded Program Files\CONFLICT.2\
Long name: istactivex.dll
Short name: ISTACT~1.DLL
Date (created): 4/20/2005 1:59:14 PM
Date (last access): 4/21/2005
Date (last write): 4/20/2005 1:59:14 PM
Filesize: 40960
Attributes: archive
MD5: 92DF522BE531F211CF2B636F53AC040E
CRC32: C336C18D
Version: 1.0.0.3

{8522F9B3-0000-0000-0000-000000000000} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\dialer.inf
Codebase: http://38.144.58.87/sex/xxxmovies.cab

{8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} ()
DPF name:
CLSID name:
Installer:
Codebase: http://static.zangocash.com/cab/Zango/ie/bridge-c8.cab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: MediaGatewayX.dll

{9F1C11AA-197B-4942-BA54-47A8489BB47F} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\iuctl.inf
Codebase: http://v4.windowsupdate.microsoft.com/CAB/…7464.6103009259
description: Windows Update
classification: Legitimate
known filename: %WINDIR%\System32\iuctl.dll,iuengine.dll
info link:
info source: Patrick M. Kolla

{B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class)
DPF name:
CLSID name: MsnMessengerSetupDownloadControl Class
Installer: C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.inf
Codebase: http://messenger.msn.com/download/MsnMesse…pDownloader.cab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: MsnMessengerSetupDownloader.ocx
Short name: MSNMES~1.OCX
Date (created): 11/5/2004 3:58:20 PM
Date (last access): 10/29/2005
Date (last write): 11/5/2004 3:58:20 PM
Filesize: 119496
Attributes: archive
MD5: 1B40AA6A5D25E6CB4EDFC4C717113161
CRC32: 4F5D45E3
Version: 1.0.0.1

{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf
Codebase: http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\System32\Macromed\Flash\
Long name: Flash8.ocx
Short name: FLASH8.OCX
Date (created): 8/27/2005 1:38:56 PM
Date (last access): 11/11/2005
Date (last write): 8/27/2005 1:38:56 PM
Filesize: 1435272
Attributes: archive
MD5: 900373C059C2B51CA91BF110DBDECB33
CRC32: F19599BC
Version: 8.0.22.0

{D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object)
DPF name:
CLSID name: FlashXControl Object
Installer: C:\WINDOWS\Downloaded Program Files\FlashAX.inf
Codebase: https://flashcasino.playboy.com/playboy/FlashAX.cab
Path: C:\WINDOWS\System32\FlashAX\
Long name: FlashAX.ocx
Short name: FLASHAX.OCX
Date (created): 7/31/2001 2:50:18 PM
Date (last access): 10/29/2005
Date (last write): 7/31/2001 2:50:18 PM
Filesize: 61440
Attributes: archive
MD5: 158987167DD5A96FEB0E98FC5BC551E7
CRC32: E7E61874
Version: 1.0.0.1

{E0B795B4-FD95-4ABD-A375-27962EFCE8CF} ()
DPF name:
CLSID name:
Installer:
Codebase: http://install.serviceurl.de/StarInstall.ocx
description: StarDialer
classification: Confirmed as malware
known filename:
info link:
info source: JavaCool

{EB623776-492A-42CA-9571-3AA39F58530B} ()
DPF name:
CLSID name:
Installer:
Codebase: http://www.alwaysupdatednews.com/install/aun_0011.exe

{EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class)
DPF name:
CLSID name: IMViewerControl Class
Installer: C:\WINDOWS\Downloaded Program Files\CyclopsV.inf
Codebase: http://companion.logitech.com/companion/lo…1/bin/imvid.cab
Path: C:\WINDOWS\System32\
Long name: CIMVIEW.dll
Short name:
Date (created): 12/6/2002 12:23:34 PM
Date (last access): 1/25/2005
Date (last write): 12/6/2002 12:23:34 PM
Filesize: 233472
Attributes: archive
MD5: 5F17D483D473F7D45CD956471093D42F
CRC32: 14E11832
Version: 1.3.0.2041

{EF86873F-04C2-4A95-A373-5703C08EFC7B} (Installer Class)
DPF name:
CLSID name: Installer Class
Installer: C:\WINDOWS\Downloaded Program Files\CONFLICT.1\istactivex.inf
Codebase: http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
Path: C:\WINDOWS\Downloaded Program Files\CONFLICT.1\
Long name: ISTactivex.dll
Short name: ISTACT~1.DLL
Date (created): 4/13/2004 5:29:38 PM
Date (last access): 1/25/2005
Date (last write): 4/13/2004 5:29:38 PM
Filesize: 15872
Attributes: archive
MD5: 5BA2BC28E0CB39C889C7C0639BAE7A00
CRC32: 0C8201DD
Version: 1.0.0.2

{F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control)
DPF name:
CLSID name: ddm_download.ddm_control
Installer: C:\WINDOWS\Downloaded Program Files\test.INF
Codebase: http://download.rfwnad.com/cab/crack.CAB
Path: C:\WINDOWS\Downloaded Program Files\
Long name: TEST.OCX
Short name:
Date (created): 11/1/2003 12:15:18 AM
Date (last access): 1/25/2005
Date (last write): 11/1/2003 12:15:18 AM
Filesize: 22528
Attributes: archive
MD5: 07DC7D5AB373D8DA0B2BD1832B2B799B
CRC32: 1E2F51AE
Version: 1.0.0.0

{F57D17AE-CE37-4BC8-B232-EA57747BE5E7} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\EPlugin.inf
Codebase: http://66.230.146.53/EPlugin.cab
description: ePlugin dialer
classification: Confirmed as malware
known filename:
info link:
info source: JavaCool



— Process list —
PID: 0 ( 0) [System]
PID: 376 ( 4) \SystemRoot\System32\smss.exe
PID: 456 ( 376) \??\C:\WINDOWS\system32\winlogon.exe
PID: 500 ( 456) C:\WINDOWS\system32\services.exe
size: 101376
MD5: E3DF4A0252D287C44606EE55355E1623
PID: 512 ( 456) C:\WINDOWS\system32\lsass.exe
size: 11776
MD5: 8A590EA109B5E0C7629E022F8A6B17C5
PID: 672 ( 500) C:\WINDOWS\system32\svchost.exe
size: 12800
MD5: 0F7D9C87B0CE1FA520473119752C6F79
PID: 708 ( 500) C:\WINDOWS\System32\svchost.exe
size: 12800
MD5: 0F7D9C87B0CE1FA520473119752C6F79
PID: 1028 ( 500) C:\WINDOWS\system32\spoolsv.exe
size: 51200
MD5: 9B4155BA58192D4073082B8FC5D42612
PID: 1652 (1180) C:\WINDOWS\System32\winupdt.exe
size: 36864
MD5: B6DBD6CBBFD55F036576D7CDAEE6436D
PID: 2012 ( 500) C:\WINDOWS\SYSTEM32\MrobeService.exe
size: 65536
MD5: AAA87053842524EE271A9B8B2016FCA5
PID: 156 ( 500) C:\Program Files\Norton Utilities\NPROTECT.EXE
size: 135168
MD5: 236408D8B6263F3C6FB992B6D2B4BDA6
PID: 268 ( 500) C:\WINDOWS\System32\nvsvc32.exe
size: 61440
MD5: C40149797D2473E63ECF2C716A75DA15
PID: 392 ( 500) C:\WINDOWS\System32\svchost.exe
size: 12800
MD5: 0F7D9C87B0CE1FA520473119752C6F79
PID: 1728 ( 500) C:\Program Files\iPod\bin\iPodService.exe
size: 323584
MD5: 20AF3FDD673B9B4AE6FAE2C52598CC68
PID: 3816 ( 456) C:\WINDOWS\Explorer.exe
size: 1000960
MD5: 5A26FC6010886D25B3E412493DD95ED8
PID: 5076 (3816) C:\WINDOWS\System32\sngsdvt.exe
size: 91136
MD5: 7975326325D8CA306C12B9EECC01B052
PID: 5724 (5076) C:\WINDOWS\System32\devldr32.exe
size: 25600
MD5: D874723E025C465990B5F105715361F7
PID: 8216 (3816) C:\Program Files\MSN Messenger\msnmsgr.exe
size: 6856704
MD5: 79AC63592F9B6750F2026A2520C11BEE
PID: 7824 (2380) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 4393096
MD5: 09CA174A605B480318731E691DC98539
PID: 9152 ( 672) C:\Program Files\Internet Explorer\iexplore.exe
size: 91136
MD5: 92B1834F54EAB14B0B7137E6CEF5E1B2
PID: 4 ( 0) System
PID: 432 ( 376) CSRSS.EXE
PID: 788 ( 500) SVCHOST.EXE
PID: 872 ( 500) SVCHOST.EXE
PID: 808 ( 500) WDFMGR.EXE


— Browser start & search pages list —
Spybot - Search & Destroy browser pages report, 11/11/2005 1:55:32 PM



— Winsock Layered Service Provider list —
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]


Protocol 3: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 4: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6D096F48-BD7E-4B9F-B071-03EFB31D1AF0}] SEQPACKET 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6D096F48-BD7E-4B9F-B071-03EFB31D1AF0}] DATAGRAM 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0548E80F-2509-4337-9CED-1A89708B953E}] SEQPACKET 7
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0548E80F-2509-4337-9CED-1A89708B953E}] DATAGRAM 7
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CA6C27DA-5328-4146-98EA-4253A970F4AE}] SEQPACKET 6
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CA6C27DA-5328-4146-98EA-4253A970F4AE}] DATAGRAM 6
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7675D9EE-5B25-4123-970B-012FFEE68949}] SEQPACKET 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7675D9EE-5B25-4123-970B-012FFEE68949}] DATAGRAM 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{87A54DEC-62A0-4D7B-B490-52196C6702CF}] SEQPACKET 8
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{87A54DEC-62A0-4D7B-B490-52196C6702CF}] DATAGRAM 8
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A28B8032-3916-4B49-BF9C-2B560F4BAE15}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A28B8032-3916-4B49-BF9C-2B560F4BAE15}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip_{59F531F5-7281-4887-B49B-DDD4B3B7161A}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 18: MSAFD NetBIOS [\Device\NetBT_Tcpip_{59F531F5-7281-4887-B49B-DDD4B3B7161A}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 19: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B65836F-A0C5-45A8-9A4B-80D1C6FBFF8C}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 20: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B65836F-A0C5-45A8-9A4B-80D1C6FBFF8C}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 21: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CBC4611F-CFB2-468B-8631-0A1F57DFD18E}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 22: MSAFD NetBIOS [\Device\NetBT_Tcpip_{CBC4611F-CFB2-468B-8631-0A1F57DFD18E}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP

Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS

Namespace Provider 2: Network Location Awareness (NLA) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace



— Uninstall list —
Search Aid (100)
uninstall cmd: C:\Program Files\1dskb6ml\72637472.exe -f5

Alt Win (146)
uninstall cmd: C:\Program Files\1dskb6ml\72637472.exe -f8

URL Display (401)
uninstall cmd: C:\Program Files\1dskb6ml\72637472.exe -f3

IE Host R3 (434937897cc3)
uninstall cmd: C:\WINDOWS\System32\HPFimg20.exe

RON Display (820)
uninstall cmd: C:\Program Files\1dskb6ml\72637472.exe -f7

Context Display (937)
uninstall cmd: C:\Program Files\1dskb6ml\72637472.exe -f4

(AddressBook)
uninstall cmd: "C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:IE50 /UNINSTALL /PROMPT

Adobe Acrobat 5.0 5.0 (Adobe Acrobat 5.0)
version (major): 5
install location: C:\Program Files\Adobe\Acrobat 5.0
install source: C:\Documents and Settings\Rameez\Local Settings\Temp\pft5~tmp\
uninstall cmd: C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
publisher: Adobe Systems, Inc.
help link: http://www.adobe.com/prodindex/acrobat/main.html

Adobe Photoshop 7.0 7.0 (Adobe Photoshop 7.0)
version (major): 7
install location: C:\Program Files\Adobe\Photoshop 7.0
install source: E:\Photoshop\
uninstall cmd: C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
publisher: Adobe Systems, Inc.

Adobe Premiere 6.0 6.0 (Adobe Premiere 6.0)
install location: C:\Program Files\Adobe\Premiere 6.0
install source: E:\ADOBE~17.0\
uninstall cmd: C:\WINDOWS\UNINST.EXE -f"C:\Program Files\Adobe\Premiere 6.0\DeIsL1.isu" -c"C:\Program Files\Adobe\Premiere 6.0\Uninst.dll"
publisher: Adobe Systems, Inc.

Adobe SVG Viewer 3.0 3.0 (Adobe SVG Viewer)
version (major): 3
install location: C:\windows\System32\Adobe\SVG Viewer 3.0
uninstall cmd: C:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Install.log

Adobe Download Manager 2.0 (Remove Only) 2.0 (AdobeESD)
uninstall cmd: "C:\Program Files\Common Files\Adobe\ESD\uninst.exe"

Alarm Clock v1.0 (Alarm Clock_is1)
uninstall cmd: "C:\Program Files\Alarm Clock\unins000.exe"
publisher: Moore Design Lmt.
help link: http://www.scottflute.com

AMD Bus Master IDE Driver (AMD Bus Master IDE Driver)
uninstall cmd: C:\PROGRA~1\AMDEIDE\UNWISE.EXE /A C:\PROGRA~1\AMDEIDE\INSTALL.LOG

AOL Instant Messenger (AOL Instant Messenger)
uninstall cmd: C:\Program Files\AIM95\uninstll.exe -LOG= C:\Program Files\AIM95\install.log -OEM=

AOL Toolbar 2.0 (AOL Toolbar)
uninstall cmd: "C:\Program Files\AOL\AOL Toolbar 2.0\uninstall.exe"

AudioHQ (AudioHQ)
uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Creative\SBLive\AudioHQ.isu"

Babe Arcade (Babe Arcade)
uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\CherrySoft\Babe Arcade\Uninst.isu"

BitComet 0.60 0.60 (BitComet)
uninstall cmd: C:\Program Files\BitComet\uninst.exe
publisher: ~RnySmile~

BitTorrent 3.3 (BitTorrent)
uninstall cmd: "C:\Program Files\BitTorrent\uninstall.exe"

(Branding)

The Best Offers (bsto-1)
uninstall cmd: C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\boncpar.htm
publisher: The Best Offers Network
contact: [removed]
help link: http://www.bestoffersnetworks.com/uninstall

CDex extraction audio (CDex)
uninstall cmd: "C:\Program Files\CDex_150\uninstall.exe"

Cleaner 5 EZ (Cleaner 5 EZ)
uninstall cmd: C:\WINDOWS\unvise32.exe C:\Program Files\Cleaner 5 EZ\uninstal.log

(Connection Manager)

Creative Surround Mixer (Creative Surround Mixer)
uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Creative\SBLive\SurMixer.isu"

dBpowerAMP Music Converter (dBpowerAMP Music Converter)
uninstall cmd: "C:\WINDOWS\System32\SpoonUninstall.exe" C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP Music Converter.dat

dBpowerAMP Real Audio Codec (dBpowerAMP Real Audio Codec)
uninstall cmd: "C:\WINDOWS\System32\SpoonUninstall.exe" C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP Real Audio Codec.dat

dBPowerAMP Real Audio Encoder R3 (dBPowerAMP Real Audio Encoder R3)
uninstall cmd: "C:\WINDOWS\System32\SpoonUninstall.exe" C:\WINDOWS\System32\SpoonUninstall-dBPowerAMP Real Audio Encoder R3.dat

dBpowerAMP WMA V9 Codec (dBpowerAMP WMA V9 Codec)
uninstall cmd: "C:\WINDOWS\System32\SpoonUninstall.exe" C:\WINDOWS\System32\SpoonUninstall-dBpowerAMP WMA V9 Codec.dat

(DeinstKey)

Win32 BI Application (DHost)
uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\payload.inf, Uninstall

(DirectAnimation)

(DirectDrawEx)

Remove DivX Codec (DivX Codec)
uninstall cm
RemoteCapture 2.6 2.6.0 ({B08894AF-D523-46B1-9B9B-2DA6B29CDD23}) version: 33947648 version (major): 2 version (minor): 6 estimated size: 8865 install date: 20031010 install source: E:\SOFTWARE\REMCAP\ENGLISH\ publisher: Your Company Name comments: contact: help link: help telephone: readme: SealedMedia Unsealer 4.0.11.0 ({B11BF9FF-7A12-42D5-BE71-9C3C05833D89}) uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B11BF9FF-7A12-42D5-BE71-9C3C05833D89}\Setup.exe" -l0x9 Canon Camera WIA Driver 5.0.0 ({B8CD1189-53D6-4C51-8082-14B812EABBA8}) version: 83886080 version (major): 5 estimated size: 32 install date: 20031010 install source: E:\SOFTWARE\WIA\PS_S230\ENGLISH\ publisher: Canon comments: contact: help link: help telephone: readme: Canon Camera WIA Driver 5.0.0 ({B94061DC-B2BB-42F7-800D-BCBF678AA8B3}) version: 83886080 version (major): 5 estimated size: 32 install date: 20031010 install source: E:\SOFTWARE\WIA\PS_G3\ENGLISH\ publisher: Canon comments: contact: help link: help telephone: readme: Napster 2.0.6.1 ({BBBCAE4B-B416-4182-A6F2-438180894A81}) uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchiSetup -ether"C:\Program Files\InstallShield Installation Information\{BBBCAE4B-B416-4182-A6F2-438180894A81}" -l0x9 publisher: Napster contact: Customer Support help link: mailto:[removed] m:trip ({FABFD4E4-9216-4CF8-A594-F63AC74FEC3C}) uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FABFD4E4-9216-4CF8-A594-F63AC74FEC3C}\SETUP.exe" -l0x9 UNINSTALL PC Suite for P800 1.1.0 1.1.0 ({FC18114B-05A0-11D6-8140-000102E745A6}) install location: C:\Program Files\Sony Ericsson\Mobile uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC18114B-05A0-11D6-8140-000102E745A6}\Setup.exe" -l0x9 — System Services — Service (registry key): 61883 Display name: 61883 Unit Device Image path: System32\DRIVERS\61883.sys Image size: 45952 Image MD5: 5BEE618443DE08BAE98047D631ED3872 Start: 3 Type: 1 Error Control: 1 Service (registry key): Abiosdsk Start: 4 Type: 1 Error Control: 0 Service (registry key): abp480n5 Start: 4 Type: 1 Error Control: 1 Service (registry key): ACPI Display name: Microsoft ACPI Driver Image path: System32\DRIVERS\ACPI.sys Image size: 179200 Image MD5: 45E0D94158CA0EC71FF12DBB81B39ED3 Start: 0 Type: 1 Error Control: 1 Service (registry key): ACPIEC Start: 4 Type: 1 Error Control: 1 Service (registry key): adpu160m Start: 4 Type: 1 Error Control: 1 Service (registry key): aec Display name: Microsoft Kernel Acoustic Echo Canceller Image path: system32\drivers\aec.sys Image size: 122472 Image MD5: B45A744CA0A15A59D8B0307CE9741E92 Start: 3 Type: 1 Error Control: 1 Service (registry key): AFD Display name: AFD Networking Support Environment Image path: \SystemRoot\System32\drivers\afd.sys Start: 2 Type: 1 Error Control: 1 Service (registry key): Aha154x Start: 4 Type: 1 Error Control: 1 Service (registry key): aic78u2 Start: 4 Type: 1 Error Control: 1 Service (registry key): aic78xx Start: 4 Type: 1 Error Control: 1 Service (registry key): Alerter Display name: Alerter Description: Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalService Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 3 Type: 32 Error Control: 1 Depends On services: LanmanWorkstation Service (registry key): ALG Display name: Application Layer Gateway Service Description: Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Internet Connection Firewall Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\alg.exe Image size: 40960 Image MD5: C23EB4661BF60C77280F8A3620D43B8E Start: 3 Type: 16 Error Control: 1 Service (registry key): AliIde Start: 4 Type: 1 Error Control: 1 Service (registry key): amdagp Display name: AMD AGP Bus Filter Driver Image path: System32\DRIVERS\amdagp.sys Image size: 27648 Image MD5: 8D49DB427F7C6EB6A044FEA26CFAD4FF Start: 0 Type: 1 Error Control: 1 Service (registry key): amdagpxp Display name: AMD NB AGP Bus Filter Image path: System32\DRIVERS\amdagpxp.sys Start: 0 Type: 1 Error Control: 1 Service (registry key): amdeide Image path: System32\DRIVERS\amdeide.sys Image size: 4864 Image MD5: 53E37E7B969ADFD0E49C7FF97BA49A7C Start: 0 Type: 1 Error Control: 1 Service (registry key): AMDPCI Display name: AMDPCI Image path: \??\C:\DOCUME~1\Rameez\LOCALS~1\Temp\AMDPCI.sys Start: 3 Type: 1 Error Control: 1 Service (registry key): amsint Start: 4 Type: 1 Error Control: 1 Service (registry key): AN983 Display name: ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter Image path: System32\DRIVERS\AN983.sys Image size: 34112 Image MD5: 80BDAEAEF5488B89797FFD4B9CFEBAAD Start: 3 Type: 1 Error Control: 1 Service (registry key): AppMgmt Display name: Application Management Description: Provides software installation services such as Assign, Publish, and Remove. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 3 Type: 32 Error Control: 1 Service (registry key): Arp1394 Display name: 1394 ARP Client Protocol Description: 1394 ARP Client Protocol Image path: System32\DRIVERS\arp1394.sys Image size: 54016 Image MD5: BAC00074336440DD961F4AB86D81B118 Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): asc Start: 4 Type: 1 Error Control: 1 Service (registry key): asc3350p Start: 4 Type: 1 Error Control: 1 Service (registry key): asc3550 Start: 4 Type: 1 Error Control: 1 Service (registry key): ASPI32 Start: 1 Type: 1 Error Control: 1 Service (registry key): AsyncMac Display name: RAS Asynchronous Media Driver Description: RAS Asynchronous Media Driver Image path: System32\DRIVERS\asyncmac.sys Image size: 13568 Image MD5: 03F403B07A884FC2AA54A0916C410931 Start: 3 Type: 1 Error Control: 1 Service (registry key): atapi Display name: Standard IDE/ESDI Hard Disk Controller Image path: System32\DRIVERS\atapi.sys Image size: 86656 Image MD5: A64013E98426E1877CB653685C5C0009 Start: 0 Type: 1 Error Control: 1 Service (registry key): Atdisk Start: 4 Type: 1 Error Control: 0 Service (registry key): Atmarpc Display name: ATM ARP Client Protocol Description: ATM ARP Client Protocol Image path: System32\DRIVERS\atmarpc.sys Image size: 57216 Image MD5: 8D735CA1CBDB0081B0E3B9FF0EB222D0 Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): AudioSrv Display name: Windows Audio Description: Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 2 Type: 32 Error Control: 1 Depends On services: PlugPlay,RpcSs Service (registry key): audstub Display name: Audio Stub Driver Image path: System32\DRIVERS\audstub.sys Image size: 3072 Image MD5: D9F724AA26C010A217C97606B160ED68 Start: 3 Type: 1 Error Control: 1 Service (registry key): Avc Display name: AVC Device Image path: System32\DRIVERS\avc.sys Image size: 35584 Image MD5: 991BD56AA395E53B8B81FB70036FFBDD Start: 3 Type: 1 Error Control: 1 Service (registry key): BattC Start: 0 Type: 0 Error Control: 0 Service (registry key): Beep Start: 1 Type: 1 Error Control: 1 Service (registry key): BITS Display name: Background Intelligent Transfer Service Description: Uses idle network bandwidth to transfer data. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 3 Type: 32 Error Control: 1 Depends On services: Rpcss Service (registry key): Bridge Display name: MAC Bridge Image path: System32\DRIVERS\bridge.sys Image size: 53376 Image MD5: ACF63D624E76E290E109F9B823D43461 Start: 3 Type: 1 Error Control: 1 Service (registry key): BridgeMP Display name: MAC Bridge Miniport Image path: System32\DRIVERS\bridge.sys Image size: 53376 Image MD5: ACF63D624E76E290E109F9B823D43461 Start: 3 Type: 1 Error Control: 1 Service (registry key): Browser Display name: Computer Browser Description: Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 3 Type: 32 Error Control: 1 Depends On services: LanmanWorkstation,LanmanServer Service (registry key): cbidf2k Start: 4 Type: 1 Error Control: 1 Service (registry key): CCDECODE Display name: Closed Caption Decoder Image path: System32\DRIVERS\CCDECODE.sys Image size: 16384 Image MD5: FDC06E2ADA8C468EBB161624E03976CF Start: 3 Type: 1 Error Control: 1 Service (registry key): cd20xrnt Start: 4 Type: 1 Error Control: 1 Service (registry key): Cdaudio Start: 1 Type: 1 Error Control: 0 Service (registry key): Cdfs Start: 4 Type: 2 Error Control: 1 Depends On group: "SCSI CDROM Class" Service (registry key): Cdr4_2K Start: 1 Type: 1 Error Control: 1 Service (registry key): Cdr4_xp Start: 1 Type: 1 Error Control: 1 Service (registry key): Cdralw2k Start: 1 Type: 1 Error Control: 0 Service (registry key): Cdrom Display name: CD-ROM Driver Image path: System32\DRIVERS\cdrom.sys Image size: 47488 Image MD5: CB762E814F602229A574F4D78D3D6A30 Start: 1 Type: 1 Error Control: 1 Depends On group: "SCSI miniport" Service (registry key): Changer Start: 1 Type: 1 Error Control: 0 Service (registry key): CINEMSUP Display name: Software Cinemaster NT4.0 Driver Image path: \SystemRoot\SYSTEM32\DRIVERS\CINEMSUP.SYS Start: 1 Type: 1 Error Control: 1 Service (registry key): cisvc Display name: Indexing Service Description: Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language. Object name: LocalSystem Image path: C:\WINDOWS\System32\cisvc.exe Image size: 5120 Image MD5: 325F1D50AFD0D6CE830938262AC2AE14 Start: 3 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): ClipSrv Display name: ClipBook Description: Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\clipsrv.exe Image size: 30720 Image MD5: 08EBC742345AB7EF2EC29BC92D6D33DD Start: 3 Type: 16 Error Control: 1 Depends On services: NetDDE Service (registry key): CmdIde Start: 4 Type: 1 Error Control: 1 Service (registry key): COMSysApp Display name: COM+ System Application Description: Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} Image size: 4608 Image MD5: 6AE95FAF782E6F6AC6E4B3ACBF3D1573 Start: 3 Type: 16 Error Control: 1 Depends On services: rpcss Service (registry key): ContentFilter Start: 0 Type: 0 Error Control: 0 Service (registry key): ContentIndex Start: 0 Type: 0 Error Control: 0 Service (registry key): Cpqarray Start: 4 Type: 1 Error Control: 1 Service (registry key): CryptSvc Display name: Cryptographic Services Description: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): ctljystk Display name: Creative SBLive! Gameport Image path: System32\DRIVERS\ctljystk.sys Image size: 3712 Image MD5: 71007BD2E1E26927FE3E4EB00C0BEEDF Start: 3 Type: 1 Error Control: 0 Service (registry key): ctlntsvc Start: 0 Type: 0 Error Control: 0 Service (registry key): dac2w2k Start: 4 Type: 1 Error Control: 0 Service (registry key): dac960nt Start: 4 Type: 1 Error Control: 1 Service (registry key): Dhcp Display name: DHCP Client Description: Manages network configuration by registering and updating IP addresses and DNS names. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 2 Type: 32 Error Control: 1 Depends On services: Tcpip,Afd,NetBT Service (registry key): Disk Display name: Disk Driver Image path: System32\DRIVERS\disk.sys Image size: 33664 Image MD5: 43A10CD19D648E57ED039A6CAA667A56 Start: 0 Type: 1 Error Control: 1 Depends On group: "SCSI miniport" Service (registry key): dmadmin Display name: Logical Disk Manager Administrative Service Description: Configures hard disk drives and volumes. The service only runs for configuration processes and then stops. Object name: LocalSystem Image path: %SystemRoot%\System32\dmadmin.exe /com Image size: 204800 Image MD5: 67648497FDC9A9235A2642950E326756 Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs,PlugPlay,DmServer Service (registry key): dmboot Image path: System32\drivers\dmboot.sys Image size: 780928 Image MD5: E18132D39407AADCA6B1D19ADF408A8A Start: 4 Type: 1 Error Control: 1 Service (registry key): dmio Display name: Logical Disk Manager Driver Image path: System32\drivers\dmio.sys Image size: 146304 Image MD5: ACA44E9A8E2FF7C833664263C8478629 Start: 0 Type: 1 Error Control: 1 Service (registry key): dmload Image path: System32\drivers\dmload.sys Image size: 5888 Image MD5: E9317282A63CA4D188C0DF5E09C6AC5F Start: 0 Type: 1 Error Control: 1 Service (registry key): dmserver Display name: Logical Disk Manager Description: Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs,PlugPlay Service (registry key): DMusic Display name: Microsoft Kernel DLS Syntheiszer Image path: system32\drivers\DMusic.sys Image size: 50048 Image MD5: EF05974D47D56FA8387F170F05BAE5E7 Start: 3 Type: 1 Error Control: 1 Service (registry key): Dnscache Display name: DNS Client Description: Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\System32\svchost.exe -k NetworkService Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 2 Type: 32 Error Control: 1 Depends On services: Tcpip Service (registry key): dpti2o Start: 4 Type: 1 Error Control: 1 Service (registry key): drmkaud Display name: Microsoft Kernel DRM Audio Descrambler Image path: system32\drivers\drmkaud.sys Image size: 2816 Image MD5: AA94E0CBD79DB63100D0EAE061EB69BC Start: 3 Type: 1 Error Control: 1 Service (registry key): emu10k Display name: Creative SB Live! Value (WDM) Image path: system32\drivers\emu10k1f.sys Image size: 775296 Image MD5: EAC137EB2C92C524CBB91B60F82DB27E Start: 3 Type: 1 Error Control: 1 Service (registry key): emu10k1 Display name: Creative Interface Manager Driver (WDM) Image path: system32\drivers\ctlface.sys Image size: 6912 Image MD5: AADC81E967C25DD7C90E150FEC6EAB74 Start: 3 Type: 1 Error Control: 1 Service (registry key): Eplpdx02 Display name: Eplpdx02 Image path: \??\C:\WINDOWS\System32\Drivers\EPLPDX02.SYS Image size: 70084 Image MD5: F9472131367D39435D750F5FA3D23582 Start: 3 Type: 1 Error Control: 1 Service (registry key): ERSvc Display name: Error Reporting Service Description: Allows error reporting for services and applictions running in non-standard environments. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 2 Type: 32 Error Control: 0 Depends On services: RpcSs Service (registry key): es1371 Display name: Creative AudioPCI (ES1371,ES1373) (WDM) Image path: system32\drivers\es1371mp.sys Image size: 40704 Image MD5: A55DD7D8CED5D2624A9EE2DDA7BE0319 Start: 3 Type: 1 Error Control: 1 Service (registry key): Eventlog Display name: Event Log Description: Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped. Object name: LocalSystem Image path: %SystemRoot%\system32\services.exe Image size: 101376 Image MD5: E3DF4A0252D287C44606EE55355E1623 Start: 2 Type: 32 Error Control: 1 Service (registry key): EventSystem Display name: COM+ Event System Description: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 3 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): Fastfat Start: 4 Type: 2 Error Control: 1 Service (registry key): FastUserSwitchingCompatibility Display name: Fast User Switching Compatibility Description: Provides management for applications that require assistance in a multiple user environment. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 3 Type: 32 Error Control: 1 Depends On services: TermService Service (registry key): Fdc Display name: Floppy Disk Controller Driver Image path: System32\DRIVERS\fdc.sys Image size: 26240 Image MD5: 19C5C7EAC0190A42522290BF002F64EA Start: 3 Type: 1 Error Control: 1 Service (registry key): Fips Start: 1 Type: 1 Error Control: 1 Service (registry key): Flpydisk Display name: Floppy Disk Driver Image path: System32\DRIVERS\flpydisk.sys Image size: 19712 Image MD5: 21E41E89B9B191B685F99B7A8885310B Start: 3 Type: 1 Error Control: 1 Service (registry key): Fs_Rec Start: 1 Type: 8 Error Control: 0 Service (registry key): Ftdisk Display name: Volume Manager Driver Image path: System32\DRIVERS\ftdisk.sys Image size: 125056 Image MD5: 6AC26732762483366C3969C9E4D2259D Start: 0 Type: 1 Error Control: 1 Service (registry key): gameenum Display name: Game Port Enumerator Image path: System32\DRIVERS\gameenum.sys Image size: 9728 Image MD5: 90D951A8876631E617ED64A9DDF0BAFC Start: 3 Type: 1 Error Control: 0 Service (registry key): GEARAspiWDM Display name: GEARAspiWDM Image path: System32\Drivers\GEARAspiWDM.sys Image size: 14408 Image MD5: 32A73A8952580B284A47290ADB62032A Start: 3 Type: 1 Error Control: 1 Service (registry key): Gpc Display name: Generic Packet Classifier Description: Generic Packet Classifier Image path: System32\DRIVERS\msgpc.sys Image size: 33792 Image MD5: 13591E0A02E85DE2A388F3EC4BD206DF Start: 3 Type: 1 Error Control: 1 Service (registry key): HCF_MSFT Image path: System32\DRIVERS\HCF_MSFT.sys Image size: 907456 Image MD5: 4236E014632F4163F53EBB717F41594C Start: 3 Type: 1 Error Control: 0 Service (registry key): helpsvc Display name: Help and Support Description: Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 2 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): HidServ Display name: Human Interface Device Access Description: Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 4 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): hpn Start: 4 Type: 1 Error Control: 1 Service (registry key): hpt3xx Start: 4 Type: 1 Error Control: 1 Service (registry key): i2omgmt Start: 1 Type: 1 Error Control: 1 Service (registry key): i2omp Start: 4 Type: 1 Error Control: 1 Service (registry key): i8042prt Display name: i8042 Keyboard and PS/2 Mouse Port Driver Image path: System32\DRIVERS\i8042prt.sys Image size: 50944 Image MD5: 54AE656490B33F84B4417194AA127B25 Start: 1 Type: 1 Error Control: 1 Service (registry key): IDriverT Display name: InstallDriver Table Manager Description: Provides support for the Running Object Table for InstallShield Drivers Object name: LocalSystem Image path: C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe Image size: 69632 Image MD5: 1CF03C69B49ACB70C722DF92755C0C8C Start: 3 Type: 16 Error Control: 0 Service (registry key): Imapi Start: 1 Type: 1 Error Control: 0 Service (registry key): ImapiService Display name: IMAPI CD-Burning COM Service Description: Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\System32\imapi.exe Image size: 118784 Image MD5: F6069827B0A39DC75D251CFB37C4E9C9 Start: 3 Type: 16 Error Control: 1 Service (registry key): inetaccs Start: 0 Type: 0 Error Control: 0 Service (registry key): ini910u Start: 4 Type: 1 Error Control: 1 Service (registry key): Inport Start: 0 Type: 0 Error Control: 0 Service (registry key): IntelIde Start: 4 Type: 1 Error Control: 1 Service (registry key): IpFilterDriver Display name: IP Traffic Filter Driver Description: IP Traffic Filter Driver Image path: System32\DRIVERS\ipfltdrv.sys Image size: 32896 Image MD5: 731F22BA402EE4B62748ADAF6363C182 Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): IpInIp Display name: IP in IP Tunnel Driver Description: IP in IP Tunnel Driver Image path: System32\DRIVERS\ipinip.sys Image size: 19584 Image MD5: F56DD863BA732A4E8EE58D486C31250F Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): IPN2120 Display name: Wireless-B PCI Adapter Driver Image path: System32\DRIVERS\LSIPNDS.sys Image size: 96256 Image MD5: 0A7D745E718CF0D90BE6AE4AB9428B3D Start: 3 Type: 1 Error Control: 1 Service (registry key): IpNat Display name: IP Network Address Translator Description: IP Network Address Translator Image path: System32\DRIVERS\ipnat.sys Image size: 76288 Image MD5: 561E2AEDE82CAE972D572C60D4E090BF Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): iPodService Display name: iPodService Description: iPod hardware management services Object name: LocalSystem Image path: C:\Program Files\iPod\bin\iPodService.exe Image size: 323584 Image MD5: 20AF3FDD673B9B4AE6FAE2C52598CC68 Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): IPSec Display name: IPSEC driver Description: IPSEC driver Image path: System32\DRIVERS\ipsec.sys Image size: 56064 Image MD5: 87AD207BC4437F215508024559D72F30 Start: 1 Type: 1 Error Control: 1 Service (registry key): IRENUM Display name: IR Enumerator Service Image path: System32\DRIVERS\irenum.sys Image size: 10496 Image MD5: B43201394646B7E98C89056EDDA686B5 Start: 3 Type: 1 Error Control: 1 Service (registry key): ISAPISearch Start: 0 Type: 0 Error Control: 0 Service (registry key): isapnp Display name: PnP ISA/EISA Bus Driver Image path: System32\DRIVERS\isapnp.sys Image size: 35840 Image MD5: E504F706CCB699C2596E9A3DA1596E87 Start: 0 Type: 1 Error Control: 3 Service (registry key): Kbdclass Display name: Keyboard Class Driver Image path: System32\DRIVERS\kbdclass.sys Image size: 23424 Image MD5: 9C30CD464D87102497FD7C32910E6253 Start: 1 Type: 1 Error Control: 1 Service (registry key): kmixer Display name: Microsoft Kernel Wave Audio Mixer Image path: system32\drivers\kmixer.sys Image size: 159232 Image MD5: ECD42891ECC1CA80FCB849511D3DF186 Start: 3 Type: 1 Error Control: 1 Service (registry key): KSecDD Start: 0 Type: 1 Error Control: 1 Service (registry key): lanmanserver Display name: Server Description: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 2 Type: 32 Error Control: 1 Service (registry key): lanmanworkstation Display name: Workstation Description: Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 2 Type: 32 Error Control: 1 Service (registry key): lbrtfdc Start: 1 Type: 1 Error Control: 0 Service (registry key): ldap Start: 0 Type: 0 Error Control: 0 Service (registry key): LicenseService Start: 0 Type: 0 Error Control: 0 Service (registry key): LmHosts Display name: TCP/IP NetBIOS Helper Description: Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\svchost.exe -k LocalService Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 2 Type: 32 Error Control: 1 Depends On services: NetBT,Afd Service (registry key): Messenger Display name: Messenger Description: Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 2 Type: 32 Error Control: 1 Depends On services: LanmanWorkstation,NetBIOS,PlugPlay,RpcSS Service (registry key): mnmdd Start: 1 Type: 1 Error Control: 0 Service (registry key): mnmsrvc Display name: NetMeeting Remote Desktop Sharing Description: Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\System32\mnmsrvc.exe Image size: 32768 Image MD5: 743AEA1D5DB177ED3F1A0A25B3F5D6A6 Start: 3 Type: 272 Error Control: 1 Service (registry key): Modem Start: 3 Type: 1 Error Control: 0 Service (registry key): Mouclass Display name: Mouse Class Driver Image path: System32\DRIVERS\mouclass.sys Image size: 22016 Image MD5: E534CCBA5714E8BFFF4FB97D6453898F Start: 1 Type: 1 Error Control: 1 Service (registry key): MountMgr Start: 0 Type: 1 Error Control: 1 Service (registry key): mraid35x Start: 4 Type: 1 Error Control: 1 Service (registry key): MrobeService Display name: MrobeService Object name: LocalSystem Image path: "C:\WINDOWS\SYSTEM32\MrobeService.exe" Image size: 65536 Image MD5: AAA87053842524EE271A9B8B2016FCA5 Start: 2 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): MRxDAV Display name: WebDav Client Redirector Description: WebDav Client Redirector Image path: System32\DRIVERS\mrxdav.sys Image size: 172672 Image MD5: D30CBA20CC355D3648B9FED5BB55A9D5 Start: 3 Type: 2 Error Control: 1 Service (registry key): MRxSmb Display name: MRXSMB Description: MRXSMB Image path: System32\DRIVERS\mrxsmb.sys Image size: 391936 Image MD5: 852F6FCA866E68B3A4A78C2E86EFB874 Start: 1 Type: 2 Error Control: 1 Service (registry key): MSDTC Display name: Distributed Transaction Coordinator Description: Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\NetworkService Image path: C:\WINDOWS\System32\msdtc.exe Image size: 6144 Image MD5: 073D2F5B53580583FEB704084CBA39CE Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS,SamSS Service (registry key): MSDV Display name: Microsoft DV Camera and VCR Image path: System32\DRIVERS\msdv.sys Image size: 52096 Image MD5: 8575D788395C4D6378D98D1ED7CDADB9 Start: 3 Type: 1 Error Control: 1 Service (registry key): Msfs Start: 1 Type: 2 Error Control: 1 Service (registry key): MSIServer Display name: Windows Installer Object name: LocalSystem Image path: C:\WINDOWS\System32\msiexec.exe /V Image size: 63488 Image MD5: E7A49533944654EDD82D26338DF0FD05 Start: 3 Type: 288 Error Control: 1 Service (registry key): MSKSSRV Display name: Microsoft Streaming Service Proxy Image path: system32\drivers\MSKSSRV.sys Image size: 7424 Image MD5: 85736F804191CB420A31ACA2A7F0674F Start: 3 Type: 1 Error Control: 1 Service (registry key): MSPCLOCK Display name: Microsoft Streaming Clock Proxy Image path: system32\drivers\MSPCLOCK.sys Image size: 5248 Image MD5: E943ADB93D83C5CBC0CA3F53F53B48CC Start: 3 Type: 1 Error Control: 1 Service (registry key): MSPQM Display name: Microsoft Streaming Quality Manager Proxy Image path: system32\drivers\MSPQM.sys Image size: 4608 Image MD5: F6A726B8832DB1F88326B8BE98B11981 Start: 3 Type: 1 Error Control: 1 Service (registry key): MSTEE Display name: Microsoft Streaming Tee/Sink-to-Sink Converter Image path: system32\drivers\MSTEE.sys Image size: 5504 Image MD5: D5059366B361F0E1124753447AF08AA2 Start: 3 Type: 1 Error Control: 1 Service (registry key): Mup Display name: Mup Start: 0 Type: 2 Error Control: 1 Service (registry key): NABTSFEC Display name: NABTS/FEC VBI Codec Image path: System32\DRIVERS\NABTSFEC.sys Image size: 83968 Image MD5: AC31B352CE5E92704056D409834BEB74 Start: 3 Type: 1 Error Control: 1 Service (registry key): NAVAP Display name: NAVAP Image path: \??\C:\Program Files\NavNT\NAVAP.sys Start: 3 Type: 1 Error Control: 1 Service (registry key): NDIS Display name: NDIS System Driver Start: 0 Type: 1 Error Control: 1 Service (registry key): NdisIP Display name: Microsoft TV/Video Connection Image path: System32\DRIVERS\NdisIP.sys Image size: 10112 Image MD5: ABD7629CF2796250F315C1DD0B6CF7A0 Start: 3 Type: 1 Error Control: 1 Service (registry key): NdisTapi Display name: Remote Access NDIS TAPI Driver Description: Remote Access NDIS TAPI Driver Image path: System32\DRIVERS\ndistapi.sys Image size: 9600 Image MD5: 08D43BBDACDF23F34D79E44ED35C1B4C Start: 3 Type: 1 Error Control: 1 Service (registry key): Ndisuio Display name: NDIS Usermode I/O Protocol Description: NDIS Usermode I/O Protocol Image path: System32\DRIVERS\ndisuio.sys Image size: 12160 Image MD5: DA77857D9F9BC724D779DF64DA15164B Start: 3 Type: 1 Error Control: 1 Service (registry key): NdisWan Display name: Remote Access NDIS WAN Driver Description: Remote Access NDIS WAN Driver Image path: System32\DRIVERS\ndiswan.sys Image size: 88320 Image MD5: DF101384699C87C70E9BD71DDF0E8509 Start: 3 Type: 1 Error Control: 1 Service (registry key): NDProxy Start: 3 Type: 1 Error Control: 1 Service (registry key): NetBIOS Display name: NetBIOS Interface Description: NetBIOS Interface Image path: System32\DRIVERS\netbios.sys Image size: 33152 Image MD5: 9F880D46EF6DCC865B8EF5C5A4956E3B Start: 1 Type: 2 Error Control: 1 Service (registry key): NetBT Display name: NetBT Description: NetBios over Tcpip Image path: System32\DRIVERS\netbt.sys Image size: 149120 Image MD5: 26891E42CDA5A9EDE7003229BBEB7EA2 Start: 1 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): NetDDE Display name: Network DDE Description: Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\netdde.exe Image size: 107008 Image MD5: 32DE95F3FE559D7A1A3D9366DE355BFC Start: 3 Type: 32 Error Control: 1 Depends On services: NetDDEDSDM Service (registry key): NetDDEdsdm Display name: Network DDE DSDM Description: Manages Dynamic Data Exchange (DDE) network shares. If this service is stopped, DDE network shares will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\netdde.exe Image size: 107008 Image MD5: 32DE95F3FE559D7A1A3D9366DE355BFC Start: 3 Type: 32 Error Control: 1 Service (registry key): Netlogon Display name: Net Logon Description: Supports pass-through authentication of account logon events for computers in a domain. Object name: LocalSystem Image path: %SystemRoot%\System32\lsass.exe Image size: 11776 Image MD5: 8A590EA109B5E0C7629E022F8A6B17C5 Start: 3 Type: 32 Error Control: 1 Depends On services: LanmanWorkstation Service (registry key): Netman Display name: Network Connections Description: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 3 Type: 288 Error Control: 1 Depends On services: RpcSs Service (registry key): NIC1394 Display name: 1394 Net Driver Image path: System32\DRIVERS\nic1394.sys Image size: 56960 Image MD5: 807E924D54EC8B3203430CA4D4C08314 Start: 3 Type: 1 Error Control: 1 Service (registry key): Nla Display name: Network Location Awareness (NLA) Description: Collects and stores network configuration and location information, and notifies applications when this information changes. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 3 Type: 32 Error Control: 1 Depends On services: Tcpip,Afd Service (registry key): NPDriver Display name: Norton Unerase Protection Driver Image path: \??\C:\windows\System32\Drivers\NPDRIVER.SYS Image size: 34578 Image MD5: C0E6AFD4C945331475141F0FBB7F950E Start: 3 Type: 1 Error Control: 1 Depends On services: SYMEVENT Service (registry key): Npfs Start: 1 Type: 2 Error Control: 1 Service (registry key): NProtectService Display name: Norton Unerase Protection Object name: LocalSystem Image path: "C:\Program Files\Norton Utilities\NPROTECT.EXE" Image size: 135168 Image MD5: 236408D8B6263F3C6FB992B6D2B4BDA6 Start: 2 Type: 272 Error Control: 1 Service (registry key): Ntfs Start: 4 Type: 2 Error Control: 1 Service (registry key): NtLmSsp Display name: NT LM Security Support Provider Description: Provides security to remote procedure call (RPC) programs that use transports other than named pipes. Object name: LocalSystem Image path: %SystemRoot%\System32\lsass.exe Image size: 11776 Image MD5: 8A590EA109B5E0C7629E022F8A6B17C5 Start: 3 Type: 32 Error Control: 1 Service (registry key): NtmsSvc Display name: Removable Storage Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): Null Start: 1 Type: 1 Error Control: 1 Service (registry key): nv Image path: System32\DRIVERS\nv4_mini.sys Image size: 981466 Image MD5: 21CEEDFA76170A6CF19AD833AA948393 Start: 3 Type: 1 Error Control: 0 Service (registry key): nv4 Image path: System32\DRIVERS\nv4.sys Image size: 731648 Image MD5: 4D31783965B0B7CED7DB3F4EE14CF260 Start: 3 Type: 1 Error Control: 0 Service (registry key): NVSvc Display name: NVIDIA Driver Helper Service Object name: LocalSystem Image path: %SystemRoot%\System32\nvsvc32.exe Image size: 61440 Image MD5: C40149797D2473E63ECF2C716A75DA15 Start: 2 Type: 16 Error Control: 1 Service (registry key): NwlnkFlt Display name: IPX Traffic Filter Driver Description: IPX Traffic Filter Driver Image path: System32\DRIVERS\nwlnkflt.sys Image size: 12416 Image MD5: B305F3FAD35083837EF46A0BBCE2FC57 Start: 3 Type: 1 Error Control: 1 Depends On services: NwlnkFwd Service (registry key): NwlnkFwd Display name: IPX Traffic Forwarder Driver Description: IPX Traffic Forwarder Driver Image path: System32\DRIVERS\nwlnkfwd.sys Image size: 32512 Image MD5: C99B3415198D1AAB7227F2C88FD664B9 Start: 3 Type: 1 Error Control: 1 Service (registry key): ohci1394 Display name: Texas Instruments OHCI Compliant IEEE 1394 Host Controller Image path: System32\DRIVERS\ohci1394.sys Image size: 55424 Image MD5: D72273FEFCC1FB32F214E344667C243F Start: 0 Type: 1 Error Control: 1 Service (registry key): Parport Display name: Parallel port driver Image path: System32\DRIVERS\parport.sys Image size: 76160 Image MD5: 1424FFBF560627B07CCE5082FA837F5C Start: 3 Type: 1 Error Control: 1 Service (registry key): PartMgr Start: 0 Type: 1 Error Control: 1 Service (registry key): ParVdm Start: 2 Type: 1 Error Control: 0 Depends On services: Parport Depends On group: "Parallel arbitrator" Service (registry key): PCI Display name: PCI Bus Driver Image path: System32\DRIVERS\pci.sys Image size: 62464 Image MD5: 1F96EECDF5D1E3385AC44C6A457B381F Start: 0 Type: 1 Error Control: 3 Service (registry key): PCIDump Start: 1 Type: 1 Error Control: 0 Service (registry key): PCIIde Image path: System32\DRIVERS\pciide.sys Image size: 3328 Image MD5: CCF5F451BB1A5A2A522A76E670000FF0 Start: 0 Type: 1 Error Control: 1 Service (registry key): Pcmcia Start: 4 Type: 1 Error Control: 1 Service (registry key): PDCOMP Start: 3 Type: 1 Error Control: 0 Service (registry key): PDFRAME Start: 3 Type: 1 Error Control: 0 Service (registry key): PDRELI Start: 3 Type: 1 Error Control: 0 Service (registry key): PDRFRAME Start: 3 Type: 1 Error Control: 0 Service (registry key): perc2 Start: 4 Type: 1 Error Control: 1 Service (registry key): perc2hib Start: 4 Type: 1 Error Control: 1 Service (registry key): PerfDisk Start: 0 Type: 0 Error Control: 0 Service (registry key): PerfNet Start: 0 Type: 0 Error Control: 0 Service (registry key): PerfOS Start: 0 Type: 0 Error Control: 0 Service (registry key): PerfProc Start: 0 Type: 0 Error Control: 0 Service (registry key): PfModNT Image path: \??\C:\WINDOWS\System32\PfModNT.sys Image size: 6752 Image MD5: 2F5532F9B0F903B26847DA674B4F55B2 Start: 2 Type: 1 Error Control: 1 Service (registry key): PlugPlay Display name: Plug and Play Description: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability. Object name: LocalSystem Image path: %SystemRoot%\system32\services.exe Image size: 101376 Image MD5: E3DF4A0252D287C44606EE55355E1623 Start: 2 Type: 32 Error Control: 1 Service (registry key): PolicyAgent Display name: IPSEC Services Description: Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver. Object name: LocalSystem Image path: %SystemRoot%\System32\lsass.exe Image size: 11776 Image MD5: 8A590EA109B5E0C7629E022F8A6B17C5 Start: 2 Type: 32 Error Control: 1 Depends On services: RPCSS,Tcpip,IPSec Service (registry key): ppsio2 Display name: PPDevice Start: 0 Type: 0 Error Control: 0 Service (registry key): PptpMiniport Display name: WAN Miniport (PPTP) Description: WAN Miniport (PPTP) Image path: System32\DRIVERS\raspptp.sys Image size: 46208 Image MD5: E0A8E63E75333AB0D742F9DBFB1688BA Start: 3 Type: 1 Error Control: 1 Service (registry key): Processor Display name: Processor Driver Image path: System32\DRIVERS\processr.sys Image size: 30592 Image MD5: 72F923F0A0FDFBE3252579CA1D1D8948 Start: 1 Type: 1 Error Control: 1 Service (registry key): ProtectedStorage Display name: Protected Storage Description: Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users. Object name: LocalSystem Image path: %SystemRoot%\system32\lsass.exe Image size: 11776 Image MD5: 8A590EA109B5E0C7629E022F8A6B17C5 Start: 2 Type: 288 Error Control: 1 Depends On services: RpcSs Service (registry key): Ptilink Display name: Direct Parallel Link Driver Description: Direct Parallel Link Driver Image path: System32\DRIVERS\ptilink.sys Image size: 17792 Image MD5: 80D317BD1C3DBC5D4FE7B1678C60CADD Start: 3 Type: 1 Error Control: 1 Service (registry key): PxHelp20 Image path: System32\DRIVERS\PxHelp20.sys Image size: 20016 Image MD5: B572ED0C3E6165643FA116AF20425A54 Start: 0 Type: 1 Error Control: 1 Service (registry key): QCDonner Display name: Logitech QuickCam Express Image path: System32\DRIVERS\OVCD.sys Image size: 28032 Image MD5: FDDD1AEB9F81EF1E6E48AE1EDC2A97D6 Start: 3 Type: 1 Error Control: 1 Service (registry key): ql1080 Start: 4 Type: 1 Error Control: 1 Service (registry key): Ql10wnt Start: 4 Type: 1 Error Control: 1 Service (registry key): ql12160 Start: 4 Type: 1 Error Control: 1 Service (registry key): ql1240 Start: 4 Type: 1 Error Control: 1 Service (registry key): ql1280 Start: 4 Type: 1 Error Control: 1 Service (registry key): RasAcd Display name: Remote Access Auto Connection Driver Description: Remote Access Auto Connection Driver Image path: System32\DRIVERS\rasacd.sys Image size: 8832 Image MD5: FE0D99D6F31E4FAD8159F690D68DED9C Start: 1 Type: 1 Error Control: 1 Service (registry key): RasAuto Display name: Remote Access Auto Connection Manager Description: Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 3 Type: 32 Error Control: 1 Depends On services: RasMan,Tapisrv Service (registry key): Rasl2tp Display name: WAN Miniport (L2TP) Description: WAN Miniport (L2TP) Image path: System32\DRIVERS\rasl2tp.sys Image size: 48640 Image MD5: 01BD60CDE35D8B60F46EBDF5358D7127 Start: 3 Type: 1 Error Control: 1 Service (registry key): RasMan Display name: Remote Access Connection Manager Description: Creates a network connection. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 12800 Image MD5: 0F7D9C87B0CE1FA520473119752C6F79 Start: 3 Type: 32 Error Control: 1 Depends On services: Tapisrv Service (registry key): RasPppoe Display name: Remote Access PPPOE Driver Description: Remote Access PPPOE Driver Image path: System32\DRIVERS\raspppoe.sys Image size: 38912 Image MD5: 888335B3BE346119CF7B4EFF3A3FCA7C Start: 3 Type: 1 Error Control: 1 Service (registry key): Raspti Display name: Direct Parallel Description: Direct Parallel Image path: System32\DRIVERS\raspti.sys Image size: 16512 Image MD5: FDBB1D60066FCFBB7452FD8F9829B242 Start: 3 Type: 1 Error Control: 1 Service (registry key): Rdbss Display name: Rdbss Description: Rdbss Image path: System32\DRIVERS\rdbss.sys Image size: 163840 Image MD5: DE300831C74CFF09091E954A1844BDBF Start: 1 Type: 2 Error Control: 1 Service (registry key): RDPCDD Image path: System32\DRIVERS\RDPCDD.sys Image size: 4224 Image MD5: 4912D5B403614CE99C28420F75353332 Start: 1 Type: 1 Error Control: 0 Service (registry key): RDPDD Start: 0 Type: 0 Error Control: 0 Service (registry key): rdpdr Display name: Terminal Server Device Redirector Driver Image path: System32\DRIVERS\rdpdr.sys Image size: 181632 Image MD5: 57F34F83E278DD804BA4A0593D789312 Start: 3 Type: 1 Error Control: 1 Service (registry key): RDPNP Start: 0 Type: 0 Error Control: 0 Service (registry key): RDPWD Start: 3 Type: 1 Error Control: 0 Service (registry key): RDSessMgr Display name: Remote Desktop Help Session Manager Description: Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box. Object name: LocalSystem Image path: C:\WINDOWS\system32\sessmgr.exe Image size: 130048 Image MD5: E6E3C190B143A6190C73F049EC39C37C Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): redbook Display name: Digital CD Audio Playback Filter Driver Image path: System32\DRIVERS\redbook.sys Image size: 55808 Image MD5: DD2183A5092FEEE8961A1E19ABD1A0FC Start: 1 Type: 1 Error Control: 1 Service (registry key): RemoteAccess Display name: Routing and Remote Access Description: Offers routing services to businesses in local area and wide area network environments. Object name: LocalSystem Imag
For some reason your updates did not install can you run hijackthis again an post another log. Sorry for the delay. <_<

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI