computerwannabe
Topic Starter
For almost two weeks I have been unable to update AVG Free, it starts the process, even tells me what updates are available and starts downloading, but then it just closes the connection and sits there trying to open the connection again. I uninstalled avg and reinstalled it, even downloaded vcleaner from grisoft and ran it in safe mode, but still no difference.
Today AVG found and deleted sinstaller.exe, and is calling it Trojan Horse 8.AP. It did not solve the problem.
I am also using microsoft's automatic update, so I should have all of the patches, etc. (It is telling me I need to download new updates today, though)
Your help would be greatly appreciated!
Here is my Hijack this file, as well as my Spybot file
Logfile of HijackThis v1.99.1
Scan saved at 9:09:16 AM, on 8/25/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ContentWatch\Internet Protection\ContentProtect\cwsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\hkcmd.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\Program Files\ContentWatch\Internet Protection\gui\cwcptray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\hijackthis\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Iowa Telecommunications
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy
O2 - BHO: (no name) - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINNT\system32\sfg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINNT\system32\sfg.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [cwcptray] C:\Program Files\ContentWatch\Internet Protection\gui\cwcptray.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINNT\system32\sfg.dll"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\winnt\system32\cwlsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\cwlsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\cwlsp.dll
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://dl.filekicker.com/send/file/128985-NZIL/PhPSetup.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {3AE9ED90-4B59-47A0-873B-7B71554B3C3E} (JoystickCtl Class) - http://www.radicalplay.com/socca/joystick.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1123465362860
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155948898018
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} -
O16 - DPF: {9294206B-A9B2-4F73-938E-89F694F48101} - http://xlonhcld.xlontech.net/100348/movemi…4/ldsdlprod.cab
O16 - DPF: {A0EAC162-A012-4AD8-B2E1-D5A0BBBCDA51} (PopupSh Control) - http://64.246.32.69/PopupSh.ocx
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java Plug-in 1.5.0) -
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - https://www.contentwatch.com/audit/includes…uditControl.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DB6D4758-0AC3-4B84-A239-D9D4B3F61A2E} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://xlonhcld.xlontech.net/100348/qmpdev…2ie05092801.cab
O20 - Winlogon Notify: CwWLEvent - C:\Program Files\ContentWatch\Internet Protection\common\cwplc001.dll
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ContentProtect (CwCpSvc20) - ContentWatch, Inc. - C:\Program Files\ContentWatch\Internet Protection\ContentProtect\cwsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
Here is the Spybot S&D log: (It says here that nothing was done on any of these things,but after I saved this report I did have it clean mysearch and Starware.)
Cache: Cache (14434) (Cache, nothing done)
Adobe Acrobat Reader 4: Recent file #4 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile4!=
Adobe Acrobat Reader 4: Recent file #1 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile1!=
Adobe Acrobat Reader 4: Recent file #2 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile2!=
Adobe Acrobat Reader 4: Recent file #3 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile3!=
Common Dialogs: History (137 files) (Registry key, nothing done)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU
Cookie: Cookie (565) (Cookie, nothing done)
Internet Explorer: Download directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Internet Explorer\Download Directory!=
Internet Explorer: Last used directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Internet Explorer\Main\Save Directory!=
Internet Explorer: Typed URL list (25 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Internet Explorer\TypedURLs
Log: Shutdown: System32\wbem\logs\wmiprov.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\wmiprov.log
Log: Activity: COM+.log (Backup file, nothing done)
C:\WINNT\COM+.log
Log: Activity: imsins.log (Backup file, nothing done)
C:\WINNT\imsins.log
Log: Activity: mmdet.log (Backup file, nothing done)
C:\WINNT\mmdet.log
Log: Activity: ModemDet.txt (Backup file, nothing done)
C:\WINNT\ModemDet.txt
Log: Activity: ntbtlog.txt (Backup file, nothing done)
C:\WINNT\ntbtlog.txt
Log: Activity: OEWABLog.txt (Backup file, nothing done)
C:\WINNT\OEWABLog.txt
Log: Activity: SchedLgU.Txt (Backup file, nothing done)
C:\WINNT\SchedLgU.Txt
Log: Install: Active Setup Log.txt (Backup file, nothing done)
C:\WINNT\Active Setup Log.txt
Log: Install: comsetup.log (Backup file, nothing done)
C:\WINNT\comsetup.log
Log: Install: Directx.log (Backup file, nothing done)
C:\WINNT\Directx.log
Log: Install: iis5.log (Backup file, nothing done)
C:\WINNT\iis5.log
Log: Install: ocgen.log (Backup file, nothing done)
C:\WINNT\ocgen.log
Log: Install: ockodak.log (Backup file, nothing done)
C:\WINNT\ockodak.log
Log: Install: setupact.log (Backup file, nothing done)
C:\WINNT\setupact.log
Log: Install: setupapi.log (Backup file, nothing done)
C:\WINNT\setupapi.log
Log: Install: setuplog.txt (Backup file, nothing done)
C:\WINNT\setuplog.txt
Log: Install: svcpack.log (Backup file, nothing done)
C:\WINNT\svcpack.log
Log: Install: wmsetup.log (Backup file, nothing done)
C:\WINNT\wmsetup.log
Log: Shutdown: System32\wbem\logs\mofcomp.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\mofcomp.log
Log: Shutdown: System32\wbem\logs\wbemcore.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\wbemcore.log
Log: Shutdown: System32\wbem\logs\wbemess.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\wbemess.log
Log: Shutdown: System32\wbem\logs\wbemprox.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\wbemprox.log
Log: Shutdown: System32\wbem\logs\wbemsnmp.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\wbemsnmp.log
Log: Shutdown: System32\wbem\logs\winmgmt.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\winmgmt.log
Log: Shutdown: System32\wbem\logs\wmiadap.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\wmiadap.log
MS ClipArt Gallery 9.0: Used cliparts (4 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\ClipArt Gallery\2.0\MRUDescription
MS ClipArt Gallery 9.0: Last import directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\ClipArt Gallery\ImportDirectory!=
MS ClipArt Gallery 9.0: Recently used captions (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\ClipArt Gallery\2.0\MRUCaption
MS Direct3D: Most recent application (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Direct3D\MostRecentApplication\Name!=
MS Direct3D: Most recent application (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\MostRecentApplication\Name!=
MS DirectDraw: Most recent application (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name!=
MS DirectInput: Most recent application ID (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\DirectInput\MostRecentApplication\Id!=
MS DirectInput: Most recent application (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\DirectInput\MostRecentApplication\Name!=
MS Management Console: Recent command list (4 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Microsoft Management Console\Recent File List
MS Media Player: Anonymous ID (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Preferences\SendUserGUID!=B=0
MS Media Player: Client ID (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Player\Settings\Client ID!=
MS Media Player: Client ID (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\MediaPlayer\Player\Settings\Client ID!=
MS Media Player: Last opened playlist (Registry value, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Preferences\LastPlaylist
MS Media Player: Last selected node (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\MediaLibraryUI\MLLastSelectedNode!=
MS Media Player: Last selected track index (Registry value, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Preferences\LastPlaylistIndex
MS Media Player: Manually modified tags history (36 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\AutoComplete\MediaEdit
MS Media Player: Recent file list (9 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Player\RecentFileList
MS Media Player: Recent open directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Player\Settings\OpenDir!=
MS Media Player: Recent URL list (1 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Player\RecentURLList
MS Media Player: Save as Directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Player\Settings\SaveAsDir!=
MS Office 9.0 (Finder): Search terms history (1 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Office\9.0\Outlook\Office Finder
MS Office 9.0 (PowerPoint): Recent file list (5 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Office\9.0\PowerPoint\Recent File List
MS Office 9.0 (Start Assistant): Last opened file directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Office\9.0\Osa\FindFile\Place!=
MS Office 9.0 (Start Assistant): Last new file (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Office\9.0\Osa\FileNew\Place!=
MS Office 9.0 (Word): Recently used file list (Registry value, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Office\9.0\Word\Data\Settings
MS Office 9.0: Access recent file (20 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Office\9.0\Access\Settings
MS Office 9.0: Internet history (Registry value, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Office\9.0\Common\Internet\LocationOfComponents
MS Office 9.0: Recently used files (106 files) (Directory, nothing done)
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Recent\
MS Paint: Recent file list (4 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List
MS Regedit: Recent open key (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\LastKey!=
MS Windows Backup 5.0: Backup logs history (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Ntbackup\Log Files
MS Windows Backup 5.0: Last created backup set (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Ntbackup\Hardware\Logical Disk File!=
MS Wordpad: Recent file list (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List
MusicMatch JukeBox: Last add song folder (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\MusicMatch\MusicMatch Jukebox\4.0\MusicLibraryUI\Last add song dir!=
MusicMatch JukeBox: Last conversion destination folder (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\MusicMatch\MusicMatch Jukebox\4.0\FileConv\DestDir!=
MusicMatch JukeBox: Last conversion source folder (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\MusicMatch\MusicMatch Jukebox\4.0\FileConv\SourceDir!=
MyWay.MySearch: Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{014DA6C1-189F-421a-88CD-07CFE51CFF10}
RealOne Player 2 (aka RealPlayer 6.0): Open URL clips #1 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips1\!=
RealOne Player 2 (aka RealPlayer 6.0): Last login time (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\LastLoginTime\!=
RealOne Player 2 (aka RealPlayer 6.0): Last open file directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\LastOpenFileDir\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #1 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips1\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #2 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips2\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #3 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips3\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #4 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips4\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #5 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips5\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #6 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips6\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #7 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips7\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #8 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips8\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent skins #1 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins1\!=
StarWare: Program directory (Directory, nothing done)
C:\Documents and Settings\Administrator\Application Data\Starware\
Windows Explorer: Recent file global history (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
Windows Explorer: File search history (25 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU
Windows Explorer: Last visited history (13 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU
Windows Explorer: Run history (6 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
Windows Explorer: Stream history (178 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
Windows Explorer: Stream history (1 files) (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
Windows Explorer: User Assistant history files (354 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
Windows Explorer: User Assistant history files (4 files) (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
Windows Explorer: User Assistant history IE (483 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count
Windows Explorer: User Assistant history IE (1 files) (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count
Windows Media SDK: Volume serial number (Registry value, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
Windows Media SDK: Computer name (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName
Windows Media SDK: Unique ID (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!={00000000-0000-0000-0000-000000000000}
Windows.OpenWith: Open with list - .CSS extension (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CSS\OpenWithList
Windows.OpenWith: Open with list - .ADP extension (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADP\OpenWithList
Windows.OpenWith: Open with list - .BIN extension (3 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BIN\OpenWithList
Windows.OpenWith: Open with list - .BMP extension (3 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP\OpenWithList
Windows.OpenWith: Open with list - .CIL extension (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CIL\OpenWithList
Today AVG found and deleted sinstaller.exe, and is calling it Trojan Horse 8.AP. It did not solve the problem.
I am also using microsoft's automatic update, so I should have all of the patches, etc. (It is telling me I need to download new updates today, though)
Your help would be greatly appreciated!
Here is my Hijack this file, as well as my Spybot file
Logfile of HijackThis v1.99.1
Scan saved at 9:09:16 AM, on 8/25/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ContentWatch\Internet Protection\ContentProtect\cwsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\hkcmd.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\Program Files\ContentWatch\Internet Protection\gui\cwcptray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\hijackthis\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Iowa Telecommunications
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy
O2 - BHO: (no name) - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINNT\system32\sfg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINNT\system32\sfg.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [cwcptray] C:\Program Files\ContentWatch\Internet Protection\gui\cwcptray.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINNT\system32\sfg.dll"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\winnt\system32\cwlsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\cwlsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\cwlsp.dll
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://dl.filekicker.com/send/file/128985-NZIL/PhPSetup.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {3AE9ED90-4B59-47A0-873B-7B71554B3C3E} (JoystickCtl Class) - http://www.radicalplay.com/socca/joystick.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1123465362860
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155948898018
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} -
O16 - DPF: {9294206B-A9B2-4F73-938E-89F694F48101} - http://xlonhcld.xlontech.net/100348/movemi…4/ldsdlprod.cab
O16 - DPF: {A0EAC162-A012-4AD8-B2E1-D5A0BBBCDA51} (PopupSh Control) - http://64.246.32.69/PopupSh.ocx
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java Plug-in 1.5.0) -
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - https://www.contentwatch.com/audit/includes…uditControl.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DB6D4758-0AC3-4B84-A239-D9D4B3F61A2E} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://xlonhcld.xlontech.net/100348/qmpdev…2ie05092801.cab
O20 - Winlogon Notify: CwWLEvent - C:\Program Files\ContentWatch\Internet Protection\common\cwplc001.dll
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ContentProtect (CwCpSvc20) - ContentWatch, Inc. - C:\Program Files\ContentWatch\Internet Protection\ContentProtect\cwsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
Here is the Spybot S&D log: (It says here that nothing was done on any of these things,but after I saved this report I did have it clean mysearch and Starware.)
Cache: Cache (14434) (Cache, nothing done)
Adobe Acrobat Reader 4: Recent file #4 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile4!=
Adobe Acrobat Reader 4: Recent file #1 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile1!=
Adobe Acrobat Reader 4: Recent file #2 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile2!=
Adobe Acrobat Reader 4: Recent file #3 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Adobe\Acrobat Reader\4.0\AdobeViewer\avpRecentFile3!=
Common Dialogs: History (137 files) (Registry key, nothing done)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU
Cookie: Cookie (565) (Cookie, nothing done)
Internet Explorer: Download directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Internet Explorer\Download Directory!=
Internet Explorer: Last used directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Internet Explorer\Main\Save Directory!=
Internet Explorer: Typed URL list (25 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Internet Explorer\TypedURLs
Log: Shutdown: System32\wbem\logs\wmiprov.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\wmiprov.log
Log: Activity: COM+.log (Backup file, nothing done)
C:\WINNT\COM+.log
Log: Activity: imsins.log (Backup file, nothing done)
C:\WINNT\imsins.log
Log: Activity: mmdet.log (Backup file, nothing done)
C:\WINNT\mmdet.log
Log: Activity: ModemDet.txt (Backup file, nothing done)
C:\WINNT\ModemDet.txt
Log: Activity: ntbtlog.txt (Backup file, nothing done)
C:\WINNT\ntbtlog.txt
Log: Activity: OEWABLog.txt (Backup file, nothing done)
C:\WINNT\OEWABLog.txt
Log: Activity: SchedLgU.Txt (Backup file, nothing done)
C:\WINNT\SchedLgU.Txt
Log: Install: Active Setup Log.txt (Backup file, nothing done)
C:\WINNT\Active Setup Log.txt
Log: Install: comsetup.log (Backup file, nothing done)
C:\WINNT\comsetup.log
Log: Install: Directx.log (Backup file, nothing done)
C:\WINNT\Directx.log
Log: Install: iis5.log (Backup file, nothing done)
C:\WINNT\iis5.log
Log: Install: ocgen.log (Backup file, nothing done)
C:\WINNT\ocgen.log
Log: Install: ockodak.log (Backup file, nothing done)
C:\WINNT\ockodak.log
Log: Install: setupact.log (Backup file, nothing done)
C:\WINNT\setupact.log
Log: Install: setupapi.log (Backup file, nothing done)
C:\WINNT\setupapi.log
Log: Install: setuplog.txt (Backup file, nothing done)
C:\WINNT\setuplog.txt
Log: Install: svcpack.log (Backup file, nothing done)
C:\WINNT\svcpack.log
Log: Install: wmsetup.log (Backup file, nothing done)
C:\WINNT\wmsetup.log
Log: Shutdown: System32\wbem\logs\mofcomp.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\mofcomp.log
Log: Shutdown: System32\wbem\logs\wbemcore.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\wbemcore.log
Log: Shutdown: System32\wbem\logs\wbemess.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\wbemess.log
Log: Shutdown: System32\wbem\logs\wbemprox.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\wbemprox.log
Log: Shutdown: System32\wbem\logs\wbemsnmp.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\wbemsnmp.log
Log: Shutdown: System32\wbem\logs\winmgmt.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\winmgmt.log
Log: Shutdown: System32\wbem\logs\wmiadap.log (Backup file, nothing done)
C:\WINNT\System32\wbem\logs\wmiadap.log
MS ClipArt Gallery 9.0: Used cliparts (4 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\ClipArt Gallery\2.0\MRUDescription
MS ClipArt Gallery 9.0: Last import directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\ClipArt Gallery\ImportDirectory!=
MS ClipArt Gallery 9.0: Recently used captions (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\ClipArt Gallery\2.0\MRUCaption
MS Direct3D: Most recent application (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Direct3D\MostRecentApplication\Name!=
MS Direct3D: Most recent application (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\MostRecentApplication\Name!=
MS DirectDraw: Most recent application (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name!=
MS DirectInput: Most recent application ID (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\DirectInput\MostRecentApplication\Id!=
MS DirectInput: Most recent application (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\DirectInput\MostRecentApplication\Name!=
MS Management Console: Recent command list (4 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Microsoft Management Console\Recent File List
MS Media Player: Anonymous ID (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Preferences\SendUserGUID!=B=0
MS Media Player: Client ID (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Player\Settings\Client ID!=
MS Media Player: Client ID (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\MediaPlayer\Player\Settings\Client ID!=
MS Media Player: Last opened playlist (Registry value, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Preferences\LastPlaylist
MS Media Player: Last selected node (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\MediaLibraryUI\MLLastSelectedNode!=
MS Media Player: Last selected track index (Registry value, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Preferences\LastPlaylistIndex
MS Media Player: Manually modified tags history (36 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\AutoComplete\MediaEdit
MS Media Player: Recent file list (9 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Player\RecentFileList
MS Media Player: Recent open directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Player\Settings\OpenDir!=
MS Media Player: Recent URL list (1 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Player\RecentURLList
MS Media Player: Save as Directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\MediaPlayer\Player\Settings\SaveAsDir!=
MS Office 9.0 (Finder): Search terms history (1 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Office\9.0\Outlook\Office Finder
MS Office 9.0 (PowerPoint): Recent file list (5 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Office\9.0\PowerPoint\Recent File List
MS Office 9.0 (Start Assistant): Last opened file directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Office\9.0\Osa\FindFile\Place!=
MS Office 9.0 (Start Assistant): Last new file (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Office\9.0\Osa\FileNew\Place!=
MS Office 9.0 (Word): Recently used file list (Registry value, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Office\9.0\Word\Data\Settings
MS Office 9.0: Access recent file (20 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Office\9.0\Access\Settings
MS Office 9.0: Internet history (Registry value, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Office\9.0\Common\Internet\LocationOfComponents
MS Office 9.0: Recently used files (106 files) (Directory, nothing done)
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Recent\
MS Paint: Recent file list (4 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List
MS Regedit: Recent open key (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\LastKey!=
MS Windows Backup 5.0: Backup logs history (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Ntbackup\Log Files
MS Windows Backup 5.0: Last created backup set (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Ntbackup\Hardware\Logical Disk File!=
MS Wordpad: Recent file list (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List
MusicMatch JukeBox: Last add song folder (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\MusicMatch\MusicMatch Jukebox\4.0\MusicLibraryUI\Last add song dir!=
MusicMatch JukeBox: Last conversion destination folder (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\MusicMatch\MusicMatch Jukebox\4.0\FileConv\DestDir!=
MusicMatch JukeBox: Last conversion source folder (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\MusicMatch\MusicMatch Jukebox\4.0\FileConv\SourceDir!=
MyWay.MySearch: Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{014DA6C1-189F-421a-88CD-07CFE51CFF10}
RealOne Player 2 (aka RealPlayer 6.0): Open URL clips #1 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\OpenLocationClips1\!=
RealOne Player 2 (aka RealPlayer 6.0): Last login time (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\LastLoginTime\!=
RealOne Player 2 (aka RealPlayer 6.0): Last open file directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\LastOpenFileDir\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #1 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips1\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #2 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips2\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #3 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips3\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #4 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips4\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #5 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips5\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #6 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips6\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #7 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips7\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent clips #8 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentClips8\!=
RealOne Player 2 (aka RealPlayer 6.0): Most recent skins #1 (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\RealNetworks\RealPlayer\6.0\Preferences\MostRecentSkins1\!=
StarWare: Program directory (Directory, nothing done)
C:\Documents and Settings\Administrator\Application Data\Starware\
Windows Explorer: Recent file global history (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
Windows Explorer: File search history (25 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU
Windows Explorer: Last visited history (13 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU
Windows Explorer: Run history (6 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
Windows Explorer: Stream history (178 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
Windows Explorer: Stream history (1 files) (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
Windows Explorer: User Assistant history files (354 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
Windows Explorer: User Assistant history files (4 files) (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
Windows Explorer: User Assistant history IE (483 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count
Windows Explorer: User Assistant history IE (1 files) (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count
Windows Media SDK: Volume serial number (Registry value, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
Windows Media SDK: Computer name (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName
Windows Media SDK: Unique ID (Registry change, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!={00000000-0000-0000-0000-000000000000}
Windows.OpenWith: Open with list - .CSS extension (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CSS\OpenWithList
Windows.OpenWith: Open with list - .ADP extension (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADP\OpenWithList
Windows.OpenWith: Open with list - .BIN extension (3 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BIN\OpenWithList
Windows.OpenWith: Open with list - .BMP extension (3 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP\OpenWithList
Windows.OpenWith: Open with list - .CIL extension (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-790525478-1078145449-1202660629-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CIL\OpenWithList