This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan infection not resolved via basic methods

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am dealing with a serious trojan infection that I can't seem to shake. The symptoms include an increasingly slower system start time as well as active performance loss and frequently non-responsive programs. The following are my step by step attepts at resolution to this point (as close as I can recall ion this order). 01. I began with simple Avast and Spybot scans under the running environment to eliminate a minor threat. Spybot succesfully removed several problems, as did Avast. However, Avast encountered several problems while trying to repair/delete/move to chest: ( Win32ownloader-DS [Trj] ) C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\OPQFGH6V\L2[1].exe ( Win32:Trojan-gen. {UPX!} ) C:\Program Files\Alwil Software\Avast4\Data\moved\A0608462.exe.vir ( Win32elf-BIP [Trj] ) C:\Program Files\Alwil Software\Avast4\Data\moved\admparsek.dll.vir ( Win32elf-CFA [Trj] ) C:\WINDOWS\g204200324.dll ( Win32:Agent-RY [Trj] ) C:\WINDOWS\system32\hfohwb.dll\[PECompact] ( Win32:Purityscan-Q [Trj] ) C:\WINDOWS\system32\?ssembly\dexplore.exe\[PECompact] ( Win32elf-BTD [Trj] ) C:\WINDOWS\system32\fontextd.dll\[PECompact] ( Win32elf-CFE [Trj] ) C:\WINDOWS\system32\sxserv101.exe\[UPX] ( Win32elfBIP [Trj] ) C:\WINDOWS\system32\admparsek.dll ( Win32:Agent-AKV [Trj] ) C:\WINDOWS\system32\clc.exe ( Win32:Agent-AKV [Trj] ) C:\WINDOWS\system32\clc_my.exe\[UPX] 02. At this point I realized my infection was more serious then I had hoped, so I began by running add/remove programs where I came across the "IpWins" file (After some forum reading I went ahead and deleted this) 03. In trying to empty my virus chest (Avast) I encountered errors: "Initialization of Chest files: Action was completed with errors" ->Errors report "Program cannot use Chest client: (null)—>Description: Virus chest server is not running. RPC communication failed" ->Detailed information "Initialization of Chest files/Program will try to lead all Chest files from the following server; (null)/Action was complered with errors!" 04. At this point I scheduled a boot-time scan for both Spybot and Avast. And restarted into safe mode. 05. Avast failed to open, citing "keyboard error" and went on to load windows. (Could this be due to my wireless keyboard?) 06. Spybot found several new issues which it resolved, but cited errors with two programs: "Smitfraud_C.Toolbar888" and "Virtumonde". To which I scheduled a further boot-time scan. 07. Finally Safe Mode loaded, but under both my administrator account and my normal user account (after a restart) I recieved nothing but a blank Safe Mode screen stating my version information: "Microsoft ® WindowsXP ® (Build2600.XPSP_SP2_GDR.050301-1519:serv.pack2)" 08. My only option at this point was to restore to my previous system. 09. At this point windows started normally, untill my desktop came up. All my desktop items failed to show up, and instead i was given an error message saying windows was unable to find '(null)' 10. Running the explorer through the start menu (still operative) resulted in the same error. 11. I then ran Ccleaner via the "run" prompt, and allowed it to fix all the errors found. 12. It was while i was waiting for Ccleaner to finish that my desktop finally loaded. along with it came 2 pages of adware spam ive been experiencing far more frequently then desired (they always show up on MSIE as opposed to Firefox, my default browser). along with the browsers came another prompt that is a recurring problem: "NOTICE: If your computer has errors in the registry database or file system, it could cause unpredictable or erratic behavior, freezes and crashes. Fixing these errors can increase your computer's performance and prevent data loss. Would you like to install SysProtect to check your computer for free? (Recommended)", there are several other versions of this message, all offering SysProtect or other virus programs. 13. At this point I ran Spybot again, including a fresh update and immunization. It was still unabel to fix "Smitfraud_C.Toolbar888" and "Virtumonde" due to User Settings. 14. Next I ran CounterSpy (However it was unable to update definitions) I accepted the default action for all 9 issues. [See counterspy.txt] 15. Around this point I noticed for the first time two "antivirus" programs in my toolbar which i did not install: both where for "virus-busters 6.3" neither of these qould close in the toolbar. and continue to give system alerts for various spyware. 16. Then came the online scans, first BitDefender- after accepting the user agreement and clicking start scan, bitdefender because unresponsive even after several attempts. I gave up on this one for the time being and went on to the next scan 17. Next was pandascan (for which i had to open MSIE) At this point i am waiting for pandascan to finish…. I only will have internet access for the next 48 hours, so i am trying to resolve this issue before then, thus the incomplete post. included with this post is a premature getrunkey and Shownew log. I will wait untill the current scan is finished before trying to post a HJT log. at this point I posted this thread on a similar support forum and it was suggested i run SmitfraudFix (by S!Ri) in normal environment, and then under safe mode. attached is the first Smitfraudfix log, as well as the activescan log from pandascan. I then attempted to restart into safe mode, but as you can see from my first post, I was previously unable to run any programs of any sort, or input commands at all from safe mode. Possibly this has something to do with why my normal desktop is taking so long to show up, so i gave it 30 minutes to attempt to load safe mode. And as I suspected, I was still unable to do anything under safe mode. This time however, there was no system restore profile to revert to, so lacking other options i had to manually edit the boot.ini file to remove the /SAFEBOOT line and return to my "normal" OS. for the sake of completion I have left the process at that, but went ahead and created new logfiles which are included below. It should also be noted that i ran vundofix and removed several entries it found based on my forum research. [counterspy.txt] Spyware Scan Details Start Date: 12/4/2006 5:42:23 PM End Date: 12/4/2006 7:33:23 PM Total Time: 1 hrs 51 mins Detected spyware more information… Status: Quarantined Infected files detected C:\Program Files\Common Files\oowi\oowid\oowic.dll more information… Status: Quarantined Infected files detected C:\Program Files\Common Files\oowi\oowid\vocabulary more information… Status: Quarantined Infected files detected C:\WINDOWS\system32\ot.ico C:\WINDOWS\system32\ts.ico more information… Status: Quarantined Infected files detected C:\WINDOWS\Temp\VBLanguage.ini Weatherbug Low Risk Adware more information… Details: Weatherbug is an ad supported desktop weather applicaton that provides updates on weather conditions and displays real time temperatures in the taskbar icon. Status: Deleted Infected registry entries detected HKEY_CLASSES_ROOT\interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} HKEY_CLASSES_ROOT\interface\{04a38f6b-006f-4247-ba4c-02a139d5531c}\ProxyStubClsid {00020424-0000-0000-C000-000000000046} HKEY_CLASSES_ROOT\interface\{04a38f6b-006f-4247-ba4c-02a139d5531c}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046} HKEY_CLASSES_ROOT\interface\{04a38f6b-006f-4247-ba4c-02a139d5531c}\TypeLib {3C2D2A1E-031F-4397-9614-87C932A848E0} HKEY_CLASSES_ROOT\interface\{04a38f6b-006f-4247-ba4c-02a139d5531c}\TypeLib Version 1.0 HKEY_CLASSES_ROOT\interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} IMiniBugTransporterX HKEY_CLASSES_ROOT\typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} HKEY_CLASSES_ROOT\typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0}\1.0\0\win32 C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll HKEY_CLASSES_ROOT\typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0}\1.0\FLAGS 0 HKEY_CLASSES_ROOT\typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0}\1.0\HELPDIR C:\Program Files\AWS\WeatherBug\ HKEY_CLASSES_ROOT\typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0}\1.0 MiniBugTransporter 1.0 Type Library HKEY_CURRENT_USER\Software\AWS HKEY_CURRENT_USER\Software\AWS\weather\Command GetStationURL6 HKEY_CURRENT_USER\Software\AWS\weather\Command GetDesignURL6 _34{Cvs2d:4jqvlHhhw3Krp2fxjuekhdwzh42q:ljhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Command GetDataURL6 Y34*:4wdHdhwCKjl2fSMVEdMdw{H3ZSMVEdMdw{H3Zrp2fxj{e2z:4slvd3l>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Command GetCompactDataURL6 Y344*d:dwGHhwCKjl2fSMVEdMdw{H3ZSMVEdMdw{H3Zrp2fxj{e2z:4slvd3l>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Command GetForecastURL6 ]34*:4vwfduhJrhwCKjl2fSMVEwMdvhfru3JSMVEwMdvhfru3irp2fxj{e2z:4slvd3l>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Command GetWarningURL6 ]344*w:huEohwCKjl2fslvdwMhuEoZ{M3ESMVuwoh{E3Zrp2fxj{e2z:4slvd3l>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Command GetDesignURLASP6 _34{Cvs2d:4jqvlHhhw3Krp2fxjuekhdwzh42q:ljhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\CurrentStation StationID H78I\$Y6 HKEY_CURRENT_USER\Software\AWS\weather\CurrentStation ZIPCityState X78 I4(gntt|gYg6 HKEY_CURRENT_USER\Software\AWS\weather\Design ReqParas =34*V89**VV67**VV55*dy*#y6#d4*E5*X55XEH*H!8**E58XE!*!Y#*6*E5*X57XEY*7*XE4*H55*H57**]]65**]MWX#5**HG5*JH76**HH98**HH;:**HG<*JH<=*JG;*JG9*ZR8*ZR;*ZR:*ZR5*ZR:*JG7*ZR6*ZR:*VS9*JG8*VS9*VS6*VS7*VSV**ZS5*VE HKEY_CURRENT_USER\Software\AWS\weather\Design DesignInterval 21600 HKEY_CURRENT_USER\Software\AWS\weather\Design AdFreshInterval 300 HKEY_CURRENT_USER\Software\AWS\weather\Design BackgroundImageURL ^34jmsw2xoidHh:4w3xoidHh:4v3ohVdv3dsZu{3nzhv3grp2fxjuekhdwzh42q:ljhv2Hpj3M>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design BackgroundImageFile c34sj2mowdxhi4H_:xjuFkhdwZhd_dw$Hrqwlfdolss_Ehuxvv_qjwlhw$Vqg$dwvhqxprf_HG>3 HKEY_CURRENT_USER\Software\AWS\weather\Design BackgroundImageSize 97191 HKEY_CURRENT_USER\Software\AWS\weather\Design MaskImageURL ^34ps2evnpdw1xoidHh:4w3xoidHh:4v3ohVdv3dsZu{3nzhv3grp2fxjuekhdwzh42q:ljhv2Hpj3M>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design MaskImageFile c34sepn2dv1powdxhi4H_:xjuFkhdwZhd_dw$Hrqwlfdolss_Ehuxvv_qjwlhw$Vqg$dwvhqxprf_HG>3 HKEY_CURRENT_USER\Software\AWS\weather\Design MaskImageSize 85864 HKEY_CURRENT_USER\Software\AWS\weather\Design BrandImageURL HKEY_CURRENT_USER\Software\AWS\weather\Design BrandImageFile HKEY_CURRENT_USER\Software\AWS\weather\Design BrandClickURL HKEY_CURRENT_USER\Software\AWS\weather\Design BrandImageSize 0 HKEY_CURRENT_USER\Software\AWS\weather\Design AffiliateLogo ]34sj2mdgjrorM":E{=4635hvdjMph3dwolilEi{3nzhv3grp2fxjuekhdwzh42q:ljhv2Hpj3M>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design AffiliateLogoFile `34sj2mdgjrorM":E{=46_5xjuFkhdwZhd_dw$Hrqwlfdolss_Ehuxvv_qjwlhw$Vqg$dwvhqxprf_HG>3 HKEY_CURRENT_USER\Software\AWS\weather\Design AffiliateClick e34*$vbxwbjrqwldfjbex>bhwujwdCbs{dvq2lrlvhfhgdwolildiq3prrp3frp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design AffiliateImageSize 5645 HKEY_CURRENT_USER\Software\AWS\weather\Design BottomURL =34*((E5((5A*E((E6((6A*E((H5((5A*H((H6((6A*H((H7((7A*H((H8((8A*H((H<(( HKEY_CURRENT_USER\Software\AWS\weather\Design DataR 15 HKEY_CURRENT_USER\Software\AWS\weather\Design DataG 33 HKEY_CURRENT_USER\Software\AWS\weather\Design DataB 135 HKEY_CURRENT_USER\Software\AWS\weather\Design DataShadownR 0 HKEY_CURRENT_USER\Software\AWS\weather\Design DataShadownG 0 HKEY_CURRENT_USER\Software\AWS\weather\Design DataShadownB 0 HKEY_CURRENT_USER\Software\AWS\weather\Design DataShadownDepth 0 HKEY_CURRENT_USER\Software\AWS\weather\Design ArrowR 253 HKEY_CURRENT_USER\Software\AWS\weather\Design ArrowG 0 HKEY_CURRENT_USER\Software\AWS\weather\Design ArrowB 0 HKEY_CURRENT_USER\Software\AWS\weather\Design ConditionR 15 HKEY_CURRENT_USER\Software\AWS\weather\Design ConditionG 33 HKEY_CURRENT_USER\Software\AWS\weather\Design ConditionB 135 HKEY_CURRENT_USER\Software\AWS\weather\Design ConditionShadowR 0 HKEY_CURRENT_USER\Software\AWS\weather\Design ConditionShadowG 0 HKEY_CURRENT_USER\Software\AWS\weather\Design ConditionShadowB 0 HKEY_CURRENT_USER\Software\AWS\weather\Design ConditionShadowDepth 0 HKEY_CURRENT_USER\Software\AWS\weather\Design FillerR 253 HKEY_CURRENT_USER\Software\AWS\weather\Design FillerG 0 HKEY_CURRENT_USER\Software\AWS\weather\Design FillerB 0 HKEY_CURRENT_USER\Software\AWS\weather\Design TitleR 70 HKEY_CURRENT_USER\Software\AWS\weather\Design TitleG 0 HKEY_CURRENT_USER\Software\AWS\weather\Design TitleB 172 HKEY_CURRENT_USER\Software\AWS\weather\Design TitleShadowR 0 HKEY_CURRENT_USER\Software\AWS\weather\Design TitleShadowG 0 HKEY_CURRENT_USER\Software\AWS\weather\Design TitleShadowB 0 HKEY_CURRENT_USER\Software\AWS\weather\Design TitleShadowDepth 0 HKEY_CURRENT_USER\Software\AWS\weather\Design LastPopupID 0 HKEY_CURRENT_USER\Software\AWS\weather\Design NewVersion 6.04 HKEY_CURRENT_USER\Software\AWS\weather\Design AdDormantFreshInterval 1800 HKEY_CURRENT_USER\Software\AWS\weather\Design TimeToDormant 60 HKEY_CURRENT_USER\Software\AWS\weather\Design LA 0 HKEY_CURRENT_USER\Software\AWS\weather\Design TdURL6 V34(5((EA(E5b*UIb degWzEgrlquZkhdwZhVb UAbdedwzb*z((rzqgZlZ{d|lgrogLzhlhwYdv(!A(z{d|lgrobkyzow(*G((SA(ghfr*}((E9(XA(E9*X((E5(XA(E5*XIb UsbrVqHZlZ{Vb UAbvsgr(*z(grlq{Z|ZgdhnZhhghzYlvw!d(({A|zgdhnzhzbwy* HKEY_CURRENT_USER\Software\AWS\weather\Design TdInterval 3600 HKEY_CURRENT_USER\Software\AWS\weather\Design PartnerName g34xjuFkhdwZh3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftNavTabCount 11 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftNavImageURL a34jmsf2ildiwuybqdzborhoh|oxbe:4h3djlp43w:xoidgh{3nzhv3grp2fxjuekhdwzh42q:ljhv2H pj3M>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftNavImageFileName e34sj2mlfiiudbwdybqrzoo|hxheo4b_:xjuFkhdwZhd_dw$Hrqwlfdolss_Ehuxvv_qjwlhw$Vqg$dwvhqxprf_HG>3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftNavImageSize 55585 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTip0 _342hquhvfh$rp$kxu|rr$$wKr3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabName0 O34IbMYb!EFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabAction0 M34bYI!M#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabURL0 &34&&3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTop0 0 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabBottom0 20 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTip1 ]34w2dvhfru$id|1g$;xu|rw$Kh3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabName1 Q34WbEVIGRUbJEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabAction1 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabURL1 P34bZIb d|;HGbAJY6#EVb Z*bIb ZGbAJY5#EVb Z*b(*H(E#(UA(qg*u(((YA(hu*y((#I]R((hArq*}((HIGRMS(]A(ls*}((SG((hArg}f(*!(!Y((oAoyoCwp2kvwfduhJrw3dvhfru3Jrp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTop1 20 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabBottom1 40 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTip2 ^34222uhpr$$qg$dsvpdh$xudwhupswh0$wholhodw$vu0gdudu$ohssHr3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabName2 Q34bEUEHbUEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabAction2 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabURL2 P34Ib ZubohssHr"bAUY6#EVb Z*bIb Z"bAUY5#EVb Z*b(*H(E#(UA(qg*u(((YA(hu*y((HIGRMS(]A(ls*}((SG((hArg}f(*!(!Y((oAoyoCwp2kdudg3Ududg3Urp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTop2 40 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabBottom2 60 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTip3 a342wvhudoo$qdlrdw$qqg$ddorf$ohzYl3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabName3 N34bUW!IbEEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabAction3 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabURL3 S34Ib ZqbrznqXqZbAVY6#EVb Z*bIb ZZbAVY5#EVb Z*b(*H(E#(UA(qg*u(((YA(hu*y((HIGRMS(]A(ls*}((SG((hArg}f(*!(!Y((oAoyoCwp2khuwkhdhZhuhy3VhuwkhdhZhuhy3Vrp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTop3 60 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabBottom3 80 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTip4 ]3422h2ru$pqg$dqvlrsw$rvhds$ophwl0$dvhudp$fdorf$oyh!l3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabName4 L34EbIUE"bGEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabAction4 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabURL4 O34bZIb pvGddorfb!!G6AEYb#ZVb b*ZIb !G5AEYb#ZVb **((#HUE((gAuq(*Y(((uAyh(*H(#MMREWVW((wAwd*v((HIGRMS(]A(ls*}((SG((hArg}f(*!(!Y((oAoyoCwp2kudphGdd3hudp3Grp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTop4 80 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabBottom4 100 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTip5 b342rqwlfdoru$khrwdqw$$dvwfduhirg$dqu$khdwzhw$hquufxh$wkn$hfGk3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabName5 O34!bYIUEbWEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabAction5 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabURL5 Q34(G((SA(ghfr*}Ib ZVbbXWZ6AEYb#ZVb b*ZIb WZ5AEYb#ZVb **((#HUE((gAuq(*Y(((uAyh(*!(!Y((oAoyoCwp2khodyWuo3yhud3Wrp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTop5 100 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabBottom5 120 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTip6 c34v2wrkr$szq$rxu|rg$hq$vru|$lwxqppfrj$Fxhuwkhd$Zkh$wrpiuv$wrkr$shzYl3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabName6 J34bW\#M"XR"bGEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabAction6 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabURL6 S34bZIb pvexEoSbA\Y6#EVb Z*bIb ZSbA\Y5#EVb Z*b(*H(E#(UA(qg*u((S9(VA(vswbdv*o(((YA(hu*y((SG((hArg}f(*!(!Y((oAoyoCwp2krvrwSkxu\rv3wrkruSrx3\rp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTop6 120 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabBottom6 140 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTip7 `3422h2ru$pqg$dsvwl|$hwdi$vq0lrdwupirlqh$qflhvf0$hvlqgohd$khuwkhd$zvwwhodh$wkw$Kh3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabName7 P34VbIZb#EFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabAction7 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabURL7 T34b*ZIb hufnudhWdqlfuuLxJbA#y6#dVb Z*bIb ZJbA#y5#dVb Z*bA8debwuufx(*H(E#(UA(qg*u(((YA(hu*y((SG((hArg}f(*!(!Y((oAoyoCwp2kdowuhqpGruVwv3hz3#rp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTop7 140 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabBottom7 160 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTip8 f34wkdoLh3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabName8 M34Lb!WIEbLEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabAction8 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabURL8 Q34bZIb w|olxduTElRbALY6#EVb Z*bIb ZRbALY5#EVb Z*b(*H(E#(UA(qg*u(((YA(hu*y((HIGRMS(]A(ls*}((SG((hArg}f(*!(!Y((oAoyoCwp2kwkdoLhk3owhd3Lrp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTop8 160 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabBottom8 180 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTip9 b342hvwlylwldfg$whoduhu1khdwzhq$ixu$rxw$rxn$hfGk3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabName9 O34#bJXIUWLIEbZEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabAction9 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabURL9 Z34Ib Zhbrqq]JxJbAZY6#EVb Z*bIb ZJbAZY5#EVb Z*b(*H(E#(UA(qg*uIb UdbylulqWJxZ{Vb UAbl{wupddbylul*wIb UvbhuvzEqldlyWuxq{JbZUVb gAuhzhqvbdldlywub*UIb fwuhrudGylulqWJxZ{Vb UAbfwuhrubfldlywu5*eAwdubxu* HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTop9 180 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabBottom9 200 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTip10 c34rqwlpdruqi$llfiiud$wdorf$oyh!l3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabName10 Q34bMGJJUEbWEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabAction10 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabURL10 T34(*H(E#(UA(qg*u(((YA(hu*y((SG((hArg}f(*!(!Y((oAoyb*UIb rqjlUhlfiiudwWdvb!UVb gAblrqjluh(*5((!A(!5oCwp2klfiiud3Wlfiiud3Wrp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabTop10 200 HKEY_CURRENT_USER\Software\AWS\weather\Design LeftTabBottom10 220 HKEY_CURRENT_USER\Software\AWS\weather\Design TopNavTabCount 7 HKEY_CURRENT_USER\Software\AWS\weather\Design TopNavImageURL & #96;34jmsq2hhKugbxqUrhbuhbJdys#Wrh3djlp43w:xoidgh{3nzhv3grp2fxjuekhdwzh42q:ljhv2 Hpj3M>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopNavImageFileName d34sj2mhquhbKqgrxbUhhJuyb#drs_WxjuFkhdwZhd_dw$Hrqwlfdolss_Ehuxvv_qjwlhw$Vqg$dwvhqxprf_HG>3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopNavImageSize 28269 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabTip0 ]34%gv$d#Rk$lw$zhvxudwihp$lxhpSu3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabName0 J34!bE!V"Vb!XbSIWbKEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabAction0 O34bR#WMYEWMEGRbSU#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabURL0 Z34(*H(E#(UA(qg*u86A8f|*b86A;f{Cbs{dvq2lrdwlyfwvEox3SxvSop3frj2exhuwkhd2zoj{gnzh v3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabLeft0 0 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabRight0 63 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabTip1 `342uhwr$vqholrqu$rxq$$lrsVk3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabName1 K34b!!"EbVUIWRbVEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabAction1 O34bMI#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabURL1 _344544A=lgCfs{dvh2rp3kxvsop3frj2exhuwkhd2zuhwr3v>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabLeft1 63 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabRight1 105 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabTip2 d34hvlfuyvhv$hvholu$zxwer$duh"r3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabName2 I34!bE!V"VbIVI!MUbZEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabAction2 O34bMI#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabURL2 ]34*69gAvl(*I(RHSG]M((sA}luwohwdw{(*H(KMUI((gAblhjCus{dvq2lrdwwulvhjhUqvsrhvwUhf lu3Hrp2fxjuekhdwzhs2ps2vhe3z>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabLeft2 105 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabRight2 160 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabTip3 [34G$Sxu|rn$hfGk3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabName3 H34!bE!V"GbbSG LIbGEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabAction3 O34bMI#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabURL3 f343uj2rhuxwpsfrxu|rfnkh3f>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabLeft3 167 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabRight3 246 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabTip4 g34u|wrhflu$gqwwhrq$fooJx3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabName4 V34oopdbVESI"MWbVEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabAction4 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabURL4 U34(G((SA(ghfr*}(*H(E#(UA(qg*u((Y!(!A(yoCopokw{2ghMqq3prrp3Grp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabLeft4 246 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabRight4 304 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabTip5 f342jvlqwwvhg$dqv$rqwlrsh$l}rpvwGx3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabName5 T34oopdbVIV#GUIJIUIbSEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabAction5 L34bRKE!HMVbGII#IUIJSU#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabURL5 T34(*H(E#(UA(qg*u(((YA(hu*y((SG((hArg}f(*!(!Y((oAoyoCwp2khuogkrfhod3srp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabLeft5 304 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabRight5 376 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabTip6 ]34w2russvxh$lqqo$rqg$dTvJE0$osLh3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabName6 N34SbI!bLEFbW3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabAction6 O34bMI#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabURL6 P34(*G((SA(ghfr*}((Y!(& #33;A(yo*o(((YA(rqvlhu*y((MHIK(UA(lg*u((HIGRMS(]A(ls*}((#HUE((gAuq(*Y(((uAyh{Cvs 2dosLhs3ho3Lrp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabLeft6 376 HKEY_CURRENT_USER\Software\AWS\weather\Design TopTabRight6 416 HKEY_CURRENT_USER\Software\AWS\weather\Design StartCount 65269145 HKEY_CURRENT_USER\Software\AWS\weather\Design EndCount 65288334 HKEY_CURRENT_USER\Software\AWS\weather\Design ShreBugText c34xjuFkhdwZhh$duVk3 HKEY_CURRENT_USER\Software\AWS\weather\Design DownloadText k34vdgorzqHr3 HKEY_CURRENT_USER\Software\AWS\weather\Design MoreObs Y34(*Y(((uAyh(*H(#MMREWVW((wAwdCvpokwv2uwoh|E3"wvhuEo"|v3ox3Srp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design StatClks V34bWVKX#bMRGWbEXKbFWAKIEUbW(*Y(((uAyh(*W(#M(XA(wvql*x((HIGRMS(]A(ls*}((MHR#WMWE (VA(dwvwoCwp2kqvlrdwuyvhRev3rqwlydhuev3Rrp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design LocMan ]347*9=|Abf7*:<{Abf{Cvs2drqwlfd!ru3jhqd"drqwlfd!rp3frj2exhuwkhd2zoj{gnzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design InsWiz e34Cs{dv{2ghlqg3dul}oZdovwMqp3frj2exhuwkhd2zoj{gnzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Design Zone >34<55KE3 HKEY_CURRENT_USER\Software\AWS\weather\Design PMClicks 2 HKEY_CURRENT_USER\Software\AWS\weather\Forecast Title0 k34wjkqlWr3 HKEY_CURRENT_USER\Software\AWS\weather\Forecast Hi0 134113 HKEY_CURRENT_USER\Software\AWS\weather\Forecast Low0 834°:63 HKEY_CURRENT_USER\Software\AWS\weather\Forecast Cond0 106 HKEY_CURRENT_USER\Software\AWS\weather\Forecast CondText1_0 a34$dwkzl|$xgor$fo|vw"r3 HKEY_CURRENT_USER\Software\AWS\weather\Forecast CondText2_0 ]3422v2hurzvki$$rfhdqfk3 HKEY_CURRENT_USER\Software\AWS\weather\Forecast Title1 j34|gdhvgqZh3 HKEY_CURRENT_USER\Software\AWS\weather\Forecast Hi1 :34°<93 HKEY_CURRENT_USER\Software\AWS\weather\Forecast Low1 834°:63 HKEY_CURRENT_USER\Software\AWS\weather\Forecast Cond1 93 HKEY_CURRENT_USER\Software\AWS\weather\Forecast CondText1_1 c34$dwkzl|$xgor$fo|uwSd3 HKEY_CURRENT_USER\Software\AWS\weather\Forecast CondText2_1 ]3422v2hurzvki$$rfhdqfk3 HKEY_CURRENT_USER\Software\AWS\weather\Forecast Title2 m34d|vgxuWk3 HKEY_CURRENT_USER\Software\AWS\weather\Forecast Hi2 <34°<<3 HKEY_CURRENT_USER\Software\AWS\weather\Forecast Low2 834°:63 HKEY_CURRENT_USER\Software\AWS\weather\Forecast Cond2 3 HKEY_CURRENT_USER\Software\AWS\weather\Forecast CondText1_2 b34hwkq$$lq|xq$vo|vw"r3 HKEY_CURRENT_USER\Software\AWS\weather\Forecast CondText2_2 Y34222hqwk22j2lquqpr3 HKEY_CURRENT_USER\Software\AWS\weather\Forecast Interval 3600 HKEY_CURRENT_USER\Software\AWS\weather\Forecast UpdateTime 1115781552 HKEY_CURRENT_USER\Software\AWS\weather\Links CustomLinkNum 5 HKEY_CURRENT_USER\Software\AWS\weather\Links CLinkName0 c34xvSoj$Fxhuwkhd$ZwhydwlEf3 HKEY_CURRENT_USER\Software\AWS\weather\Links CLinkURL0 Z34#bMREWMYGWbEURbSR#WMEGKbFX>bIWUKWE*b86A8f|*b86A;f{Cbs{dvq2lrdwlyfwvEox3SxvSop3frj2exhuwkhd2zoj{gnzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Links CLinkName1 b34xvSoj$Fxhuwkhd$Zwrh$lefuevVx3 HKEY_CURRENT_USER\Software\AWS\weather\Links CLinkURL1 Z34#bMREWMYGWbEURbSR#WMEGKbFX>bIWUKWE*b86A8f|*b86A;f{Cbs{dvq2lrdwlyfwvEox3SxvSop3frj2exhuwkhd2zoj{gnzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Links CLinkName2 13413 HKEY_CURRENT_USER\Software\AWS\weather\Links CLinkURL2 13413 HKEY_CURRENT_USER\Software\AWS\weather\Links CLinkName3 c34xjuFkhdwZhh$duVk3 HKEY_CURRENT_USER\Software\AWS\weather\Links CLinkURL3 W34*((SG((hArg}f(*H(KMUI((gAulb*WVKX#bMRGWbEXKbFW>KIEUbW{Cvs2dxjhFWkuhkd3VxjhFWkuhkd3Vrp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Links CLinkName4 _34jhSdh$rp$LxjuFkhdwZh3 HKEY_CURRENT_USER\Software\AWS\weather\Links CLinkURL4 d34pfrj2exhuwkhd2zzz3z>3wskw3 HKEY_CURRENT_USER\Software\AWS\weather\Options path C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE HKEY_CURRENT_USER\Software\AWS\weather\Options Version 6.04 HKEY_CURRENT_USER\Software\AWS\weather\Options Start 1115678037 HKEY_CURRENT_USER\Software\AWS\weather\Options CheckInstance 0 HKEY_CURRENT_USER\Software\AWS\weather\Options OldVersion 8466:<43 HKEY_CURRENT_USER\Software\AWS\weather\Options ZipCode 31401 HKEY_CURRENT_USER\Software\AWS\weather\Options Temperature 64° HKEY_CURRENT_USER\Software\AWS\weather\Options ObTime 1115781552 HKEY_CURRENT_USER\Software\AWS\weather\Options FirstMin 0 HKEY_CURRENT_USER\Software\AWS\weather\Options ClosePrompt 1 HKEY_CURRENT_USER\Software\AWS\weather\Reg UA5 :58:=A=889=992 HKEY_CURRENT_USER\Software\AWS\weather\Reg FC4 7349659;<59553 HKEY_CURRENT_USER\Software\AWS\weather\Reg UA10 8 HKEY_CURRENT_USER\Software\AWS\weather\Reg UA7 8 HKEY_CURRENT_USER\Software\AWS\weather\Reg N =78>>9A=>?86 HKEY_CURRENT_USER\Software\AWS\weather\Reg WXID 70561966 HKEY_CURRENT_USER\Software\AWS\weather\Reg DEC 0 HKEY_CURRENT_USER\Software\AWS\weather\Reg UA1 ;78>:A=889=996 HKEY_CURRENT_USER\Software\AWS\weather\Reg A2 7444<7:6;59554 HKEY_CURRENT_USER\Software\AWS\weather\Reg A1 534454943 HKEY_CURRENT_USER\Software\AWS\weather\Reg L1 834;943 HKEY_CURRENT_USER\Software\AWS\weather\Reg L2 i34dkqqydVd3 HKEY_CURRENT_USER\Software\AWS\weather\Reg L3 H34KE3 HKEY_CURRENT_USER\Software\AWS\weather\Reg UA13 73469;7;:59553 HKEY_CURRENT_USER\Software\AWS\weather\setup ZipCode 31401 HKEY_CURRENT_USER\Software\AWS\weather\setup ZCode Z3959 HKEY_CURRENT_USER\Software\AWS\weather\setup DOWNLOADID 1800 HKEY_CURRENT_USER\Software\AWS\weather\setup y 100 HKEY_CURRENT_USER\Software\AWS\weather\setup x 100 HKEY_CURRENT_USER\Software\AWS\weather\Warning TVNetwork 0 HKEY_CURRENT_USER\Software\AWS\weather\Warning WarningInterval 300 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data0 634"$S56=>>5553 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data1 534494335493 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data2 73428:83 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data3 734=543 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data4 :34:3 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data5 9346=3 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data6 634583 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data7 334E#33 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data8 334E#33 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data9 ?346v24743 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data10 434)=83 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data11 :34°<83 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data12 734°:43 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data13 834°:73 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data14 934°:83 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data15 334E#33 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data16 23424/43 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data17 23424/43 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data18 8343k4&24/43 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data19 8342<=73 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data20 8342=7<3 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data21 2348&24743 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data22 5349&2=6=3 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data23 334E#33 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data24 G34s9<=>3 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data25 4344553 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data26 :34:3 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data27 234°143 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data28 5347193 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data29 43443 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data30 334E#33 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data31 ;34k°324/43 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData Data32 23424/43 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData StationName1 g34dorqwlqdhuqw$MdkqqydVd3 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData StationName2 l34wruusEl3 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData CityState W34KE0$huroSr3 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData ActiveFrequency 300 HKEY_CURRENT_USER\Software\AWS\weather\WeatherData InactiveFrequency 3600 HKEY_CURRENT_USER\Software\AWS\weather\Web NAV1 #58!&3 HKEY_CURRENT_USER\Software\AWS\weather\Web NAV2 ^58zqqrqnbX!&3 HKEY_CURRENT_USER\Software\AWS\weather\Web WxWinViewCount ?58?3 HKEY_CURRENT_USER\Software\AWS\weather\Web LastGetDesign 958899:<;9=993 HKEY_CURRENT_USER\Software\AWS\weather\Web GutsClicks 85883 HKEY_CURRENT_USER\Software\AWS\weather\Web EnlargeClicks 85883 HKEY_CURRENT_USER\Software\AWS\weather\Web LastViewedWeekendWxWindow 9579877:?8<883 HKEY_CURRENT_USER\Software\AWS\Weather HKEY_CURRENT_USER\Software\AWS\Weather\Command GetStationURL6 HKEY_CURRENT_USER\Software\AWS\Weather\Command GetDesignURL6 _34{Cvs2d:4jqvlHhhw3Krp2fxjuekhdwzh42q:ljhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Command GetDataURL6 Y34*:4wdHdhwCKjl2fSMVEdMdw{H3ZSMVEdMdw{H3Zrp2fxj{e2z:4slvd3l>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Command GetCompactDataURL6 Y344*d:dwGHhwCKjl2fSMVEdMdw{H3ZSMVEdMdw{H3Zrp2fxj{e2z:4slvd3l>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Command GetForecastURL6 ]34*:4vwfduhJrhwCKjl2fSMVEwMdvhfru3JSMVEwMdvhfru3irp2fxj{e2z:4slvd3l>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Command GetWarningURL6 ]344*w:huEohwCKjl2fslvdwMhuEoZ{M3ESMVuwoh{E3Zrp2fxj{e2z:4slvd3l>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Command GetDesignURLASP6 _34{Cvs2d:4jqvlHhhw3Krp2fxjuekhdwzh42q:ljhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\CurrentStation StationID H78I\$Y6 HKEY_CURRENT_USER\Software\AWS\Weather\CurrentStation ZIPCityState X78 I4(gntt|gYg6 HKEY_CURRENT_USER\Software\AWS\Weather\Design ReqParas =34*V89**VV67**VV55*dy*#y6#d4*E5*X55XEH*H!8**E58XE!*!Y#*6*E5*X57XEY*7*XE4*H55*H57**]]65**]MWX#5**HG5*JH76**HH98**HH;:**HG<*JH<=*JG;*JG9*ZR8*ZR;*ZR:*ZR5*ZR:*JG7*ZR6*ZR:*VS9*JG8*VS9*VS6*VS7*VSV**ZS5*VE HKEY_CURRENT_USER\Software\AWS\Weather\Design DesignInterval 21600 HKEY_CURRENT_USER\Software\AWS\Weather\Design AdFreshInterval 300 HKEY_CURRENT_USER\Software\AWS\Weather\Design BackgroundImageURL ^34jmsw2xoidHh:4w3xoidHh:4v3ohVdv3dsZu{3nzhv3grp2fxjuekhdwzh42q:ljhv2Hpj3M>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design BackgroundImageFile c34sj2mowdxhi4H_:xjuFkhdwZhd_dw$Hrqwlfdolss_Ehuxvv_qjwlhw$Vqg$dwvhqxprf_HG>3 HKEY_CURRENT_USER\Software\AWS\Weather\Design BackgroundImageSize 97191 HKEY_CURRENT_USER\Software\AWS\Weather\Design MaskImageURL ^34ps2evnpdw1xoidHh:4w3xoidHh:4v3ohVdv3dsZu{3nzhv3grp2fxjuekhdwzh42q:ljhv2Hpj3M>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design MaskImageFile c34sepn2dv1powdxhi4H_:xjuFkhdwZhd_dw$Hrqwlfdolss_Ehuxvv_qjwlhw$Vqg$dwvhqxprf_HG>3 HKEY_CURRENT_USER\Software\AWS\Weather\Design MaskImageSize 85864 HKEY_CURRENT_USER\Software\AWS\Weather\Design BrandImageURL HKEY_CURRENT_USER\Software\AWS\Weather\Design BrandImageFile HKEY_CURRENT_USER\Software\AWS\Weather\Design BrandClickURL HKEY_CURRENT_USER\Software\AWS\Weather\Design BrandImageSize 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design AffiliateLogo ]34sj2mdgjrorM":E{=4635hvdjMph3dwolilEi{3nzhv3grp2fxjuekhdwzh42q:ljhv2Hpj3M>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design AffiliateLogoFile `34sj2mdgjrorM":E{=46_5xjuFkhdwZhd_dw$Hrqwlfdolss_Ehuxvv_qjwlhw$Vqg$dwvhqxprf_HG>3 HKEY_CURRENT_USER\Software\AWS\Weather\Design AffiliateClick e34*$vbxwbjrqwldfjbex>bhwujwdCbs{dvq2lrlvhfhgdwolildiq3prrp3frp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design AffiliateImageSize 5645 HKEY_CURRENT_USER\Software\AWS\Weather\Design BottomURL =34*((E5((5A*E((E6((6A*E((H5((5A*H((H6((6A*H((H7((7A*H((H8((8A*H((H<(( HKEY_CURRENT_USER\Software\AWS\Weather\Design DataR 15 HKEY_CURRENT_USER\Software\AWS\Weather\Design DataG 33 HKEY_CURRENT_USER\Software\AWS\Weather\Design DataB 135 HKEY_CURRENT_USER\Software\AWS\Weather\Design DataShadownR 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design DataShadownG 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design DataShadownB 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design DataShadownDepth 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design ArrowR 253 HKEY_CURRENT_USER\Software\AWS\Weather\Design ArrowG 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design ArrowB 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design ConditionR 15 HKEY_CURRENT_USER\Software\AWS\Weather\Design ConditionG 33 HKEY_CURRENT_USER\Software\AWS\Weather\Design ConditionB 135 HKEY_CURRENT_USER\Software\AWS\Weather\Design ConditionShadowR 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design ConditionShadowG 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design ConditionShadowB 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design ConditionShadowDepth 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design FillerR 253 HKEY_CURRENT_USER\Software\AWS\Weather\Design FillerG 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design FillerB 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design TitleR 70 HKEY_CURRENT_USER\Software\AWS\Weather\Design TitleG 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design TitleB 172 HKEY_CURRENT_USER\Software\AWS\Weather\Design TitleShadowR 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design TitleShadowG 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design TitleShadowB 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design TitleShadowDepth 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design LastPopupID 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design NewVersion 6.04 HKEY_CURRENT_USER\Software\AWS\Weather\Design AdDormantFreshInterval 1800 HKEY_CURRENT_USER\Software\AWS\Weather\Design TimeToDormant 60 HKEY_CURRENT_USER\Software\AWS\Weather\Design LA 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design TdURL6 V34(5((EA(E5b*UIb degWzEgrlquZkhdwZhVb UAbdedwzb*z((rzqgZlZ{d|lgrogLzhlhwYdv(!A(z{d|lgrobkyzow(*G((SA(ghfr*}((E9(XA(E9*X((E5(XA(E5*XIb UsbrVqHZlZ{Vb UAbvsgr(*z(grlq{Z|ZgdhnZhhghzYlvw!d(({A|zgdhnzhzbwy* HKEY_CURRENT_USER\Software\AWS\Weather\Design TdInterval 3600 HKEY_CURRENT_USER\Software\AWS\Weather\Design PartnerName g34xjuFkhdwZh3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftNavTabCount 11 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftNavImageURL a34jmsf2ildiwuybqdzborhoh|oxbe:4h3djlp43w:xoidgh{3nzhv3grp2fxjuekhdwzh42q:ljhv2H pj3M>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftNavImageFileName e34sj2mlfiiudbwdybqrzoo|hxheo4b_:xjuFkhdwZhd_dw$Hrqwlfdolss_Ehuxvv_qjwlhw$Vqg$dwvhqxprf_HG>3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftNavImageSize 55585 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTip0 _342hquhvfh$rp$kxu|rr$$wKr3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabName0 O34IbMYb!EFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabAction0 M34bYI!M#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabURL0 &34&&3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTop0 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabBottom0 20 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTip1 ]34w2dvhfru$id|1g$;xu|rw$Kh3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabName1 Q34WbEVIGRUbJEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabAction1 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabURL1 P34bZIb d|;HGbAJY6#EVb Z*bIb ZGbAJY5#EVb Z*b(*H(E#(UA(qg*u(((YA(hu*y((#I]R((hArq*}((HIGRMS(]A(ls*}((SG((hArg}f(*!(!Y((oAoyoCwp2kvwfduhJrw3dvhfru3Jrp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTop1 20 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabBottom1 40 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTip2 ^34222uhpr$$qg$dsvpdh$xudwhupswh0$wholhodw$vu0gdudu$ohssHr3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabName2 Q34bEUEHbUEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabAction2 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabURL2 P34Ib ZubohssHr"bAUY6#EVb Z*bIb Z"bAUY5#EVb Z*b(*H(E#(UA(qg*u(((YA(hu*y((HIGRMS(]A(ls*}((SG((hArg}f(*!(!Y((oAoyoCwp2kdudg3Ududg3Urp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTop2 40 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabBottom2 60 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTip3 a342wvhudoo$qdlrdw$qqg$ddorf$ohzYl3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabName3 N34bUW!IbEEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabAction3 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabURL3 S34Ib ZqbrznqXqZbAVY6#EVb Z*bIb ZZbAVY5#EVb Z*b(*H(E#(UA(qg*u(((YA(hu*y((HIGRMS(]A(ls*}((SG((hArg}f(*!(!Y((oAoyoCwp2khuwkhdhZhuhy3VhuwkhdhZhuhy3Vrp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTop3 60 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabBottom3 80 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTip4 ]3422h2ru$pqg$dqvlrsw$rvhds$ophwl0$dvhudp$fdorf$oyh!l3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabName4 L34EbIUE"bGEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabAction4 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabURL4 O34bZIb pvGddorfb!!G6AEYb#ZVb b*ZIb !G5AEYb#ZVb **((#HUE((gAuq(*Y(((uAyh(*H(#MMREWVW((wAwd*v((HIGRMS(]A(ls*}((SG((hArg}f(*!(!Y((oAoyoCwp2kudphGdd3hudp3Grp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTop4 80 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabBottom4 100 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTip5 b342rqwlfdoru$khrwdqw$$dvwfduhirg$dqu$khdwzhw$hquufxh$wkn$hfGk3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabName5 O34!bYIUEbWEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabAction5 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabURL5 Q34(G((SA(ghfr*}Ib ZVbbXWZ6AEYb#ZVb b*ZIb WZ5AEYb#ZVb **((#HUE((gAuq(*Y(((uAyh(*!(!Y((oAoyoCwp2khodyWuo3yhud3Wrp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTop5 100 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabBottom5 120 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTip6 c34v2wrkr$szq$rxu|rg$hq$vru|$lwxqppfrj$Fxhuwkhd$Zkh$wrpiuv$wrkr$shzYl3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabName6 J34bW\#M"XR"bGEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabAction6 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabURL6 S34bZIb pvexEoSbA\Y6#EVb Z*bIb ZSbA\Y5#EVb Z*b(*H(E#(UA(qg*u((S9(VA(vswbdv*o(((YA(hu*y((SG((hArg}f(*!(!Y((oAoyoCwp2krvrwSkxu\rv3wrkruSrx3\rp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTop6 120 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabBottom6 140 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTip7 `3422h2ru$pqg$dsvwl|$hwdi$vq0lrdwupirlqh$qflhvf0$hvlqgohd$khuwkhd$zvwwhodh$wkw$Kh3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabName7 P34VbIZb#EFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabAction7 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabURL7 T34b*ZIb hufnudhWdqlfuuLxJbA#y6#dVb Z*bIb ZJbA#y5#dVb Z*bA8debwuufx(*H(E#(UA(qg*u(((YA(hu*y((SG((hArg}f(*!(!Y((oAoyoCwp2kdowuhqpGruVwv3hz3#rp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTop7 140 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabBottom7 160 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTip8 f34wkdoLh3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabName8 M34Lb!WIEbLEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabAction8 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabURL8 Q34bZIb w|olxduTElRbALY6#EVb Z*bIb ZRbALY5#EVb Z*b(*H(E#(UA(qg*u(((YA(hu*y((HIGRMS(]A(ls*}((SG((hArg}f(*!(!Y((oAoyoCwp2kwkdoLhk3owhd3Lrp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTop8 160 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabBottom8 180 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTip9 b342hvwlylwldfg$whoduhu1khdwzhq$ixu$rxw$rxn$hfGk3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabName9 O34#bJXIUWLIEbZEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabAction9 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabURL9 Z34Ib Zhbrqq]JxJbAZY6#EVb Z*bIb ZJbAZY5#EVb Z*b(*H(E#(UA(qg*uIb UdbylulqWJxZ{Vb UAbl{wupddbylul*wIb UvbhuvzEqldlyWuxq{JbZUVb gAuhzhqvbdldlywub*UIb fwuhrudGylulqWJxZ{Vb UAbfwuhrubfldlywu5*eAwdubxu* HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTop9 180 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabBottom9 200 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTip10 c34rqwlpdruqi$llfiiud$wdorf$oyh!l3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabName10 Q34bMGJJUEbWEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabAction10 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabURL10 T34(*H(E#(UA(qg*u(((YA(hu*y((SG((hArg}f(*!(!Y((oAoyb*UIb rqjlUhlfiiudwWdvb!UVb gAblrqjluh(*5((!A(!5oCwp2klfiiud3Wlfiiud3Wrp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabTop10 200 HKEY_CURRENT_USER\Software\AWS\Weather\Design LeftTabBottom10 220 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopNavTabCount 7 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopNavImageURL & #96;34jmsq2hhKugbxqUrhbuhbJdys#Wrh3djlp43w:xoidgh{3nzhv3grp2fxjuekhdwzh42q:ljhv2 Hpj3M>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopNavImageFileName d34sj2mhquhbKqgrxbUhhJuyb#drs_WxjuFkhdwZhd_dw$Hrqwlfdolss_Ehuxvv_qjwlhw$Vqg$dwvhqxprf_HG>3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopNavImageSize 28269 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabTip0 ]34%gv$d#Rk$lw$zhvxudwihp$lxhpSu3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabName0 J34!bE!V"Vb!XbSIWbKEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabAction0 O34bR#WMYEWMEGRbSU#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabURL0 Z34(*H(E#(UA(qg*u86A8f|*b86A;f{Cbs{dvq2lrdwlyfwvEox3SxvSop3frj2exhuwkhd2zoj{gnzh v3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabLeft0 0 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabRight0 63 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabTip1 `342uhwr$vqholrqu$rxq$$lrsVk3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabName1 K34b!!"EbVUIWRbVEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabAction1 O34bMI#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabURL1 _344544A=lgCfs{dvh2rp3kxvsop3frj2exhuwkhd2zuhwr3v>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabLeft1 63 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabRight1 105 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabTip2 d34hvlfuyvhv$hvholu$zxwer$duh"r3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabName2 I34!bE!V"VbIVI!MUbZEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabAction2 O34bMI#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabURL2 ]34*69gAvl(*I(RHSG]M((sA}luwohwdw{(*H(KMUI((gAblhjCus{dvq2lrdwwulvhjhUqvsrhvwUhf lu3Hrp2fxjuekhdwzhs2ps2vhe3z>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabLeft2 105 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabRight2 160 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabTip3 [34G$Sxu|rn$hfGk3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabName3 H34!bE!V"GbbSG LIbGEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabAction3 O34bMI#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabURL3 f343uj2rhuxwpsfrxu|rfnkh3f>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabLeft3 167 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabRight3 246 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabTip4 g34u|wrhflu$gqwwhrq$fooJx3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabName4 V34oopdbVESI"MWbVEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabAction4 Q34bWVKX#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabURL4 U34(G((SA(ghfr*}(*H(E#(UA(qg*u((Y!(!A(yoCopokw{2ghMqq3prrp3Grp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabLeft4 246 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabRight4 304 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabTip5 f342jvlqwwvhg$dqv$rqwlrsh$l}rpvwGx3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabName5 T34oopdbVIV#GUIJIUIbSEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabAction5 L34bRKE!HMVbGII#IUIJSU#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabURL5 T34(*H(E#(UA(qg*u(((YA(hu*y((SG((hArg}f(*!(!Y((oAoyoCwp2khuogkrfhod3srp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabLeft5 304 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabRight5 376 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabTip6 ]34w2russvxh$lqqo$rqg$dTvJE0$osLh3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabName6 N34SbI!bLEFbW3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabAction6 O34bMI#bMRGWbEXKbF3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabURL6 P34(*G((SA(ghfr*}((Y!(& #33;A(yo*o(((YA(rqvlhu*y((MHIK(UA(lg*u((HIGRMS(]A(ls*}((#HUE((gAuq(*Y(((uAyh{Cvs 2dosLhs3ho3Lrp2fxjuekhdwzh{2nzhv3g>3wskw3 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabLeft6 376 HKEY_CURRENT_USER\Software\AWS\Weather\Design TopTabRight6 416 HKEY_CURRENT_USER\Software\AWS\Weather\Design StartCount 65269145 HKEY_CURRENT_USER\Software\AWS\Weather\Design EndCount 65288334 HKEY_CURRENT_USER\Software\AWS\Weather
[activescan.txt] Incident Status Location Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\LocalService\Cookies\system@ccbill[2].txt Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\LocalService\Cookies\[removed][2].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\LocalService\Cookies\system@questionmarket[2].txt Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\yw76ccz9.default\cookies-1.txt[.maxserving.com/] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\yw76ccz9.default\cookies-1.txt[ad.yieldmanager.com/] Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\yw76ccz9.default\cookies-1.txt[.zedo.com/] Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\yw76ccz9.default\cookies-1.txt[.as-us.falkag.net/] Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\yw76ccz9.default\cookies-1.txt[.adrevolver.com/] Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\yw76ccz9.default\cookies-1.txt[.statcounter.com/] Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\yw76ccz9.default\cookies-1.txt[.atwola.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\yw76ccz9.default\cookies-1.txt[.serving-sys.com/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\yw76ccz9.default\cookies-1.txt[.realmedia.com/] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\user\Cookies\[removed][1].txt Spyware:Cookie/Malwarewipe Not disinfected C:\Documents and Settings\user\Cookies\user@malwarewipe[1].txt Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\user\Cookies\user@mediaplex[1].txt Adware:adware/securityerror Not disinfected C:\Documents and Settings\user\Favorites\Antivirus Test Online.url Potentially unwanted tool:Application/VirusBursters Not disinfected C:\Documents and Settings\user\Local Settings\Temp\~nsu.tmp\Au_.exe Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\49UFK16N\anti4[1].exe Adware:Adware/Yazzle Not disinfected C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\85QPK7MB\mulbin32[1].exe Possible Virus. Not disinfected C:\Documents and Settings\user\My Documents\??curity\attrib.exe Adware:Adware/Sqwire Not disinfected C:\Program Files\Common Files\oowi\oowid\oowic.dll Adware:Adware/YazzleSudoku Not disinfected C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe Adware:Adware/PurityScan Not disinfected C:\Program Files\Common Files\Yazzle1162OinAdmin.exe Adware:Adware/Yazzle Not disinfected C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe Potentially unwanted tool:Application/Zango Not disinfected C:\Program Files\Mozilla Firefox\plugins\npclntax.dll Adware:Adware/CommAd Not disinfected C:\WINDOWS\b3duZXI\vaxRtrK.vbs Adware:Adware/WebSearch Not disinfected C:\WINDOWS\system32\byuatfsx.dll Adware:Adware/WebSearch Not disinfected C:\WINDOWS\system32\cyqggosq.dll Possible Virus. Not disinfected C:\WINDOWS\system32\ddcaw.dll Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\deuyjtyo.dll Adware:Adware/Adservice Not disinfected C:\WINDOWS\system32\drvvex.dll Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\system32\gidyppee.exe Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\kldibtna.dll Possible Virus. Not disinfected C:\WINDOWS\system32\mlraakb.dll Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\raokutqi.dll Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\system32\vnlcjtda.exe Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\whqthoxi.dll Virus:Trj/Nebule.A Disinfected C:\WINDOWS\system32\winzue32.dll Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\wvurqop.dll Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\wvutsrp.dll Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\ydcsrybe.dll Adware:Adware/Yazzle Not disinfected C:\WINDOWS\Temp\win106.tmp.exe [rapport.txt] SmitFraudFix v2.128 Scan done at 8:16:28.32, Tue 12/05/2006 Run from C:\Documents and Settings\user\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\ismini.exe FOUND ! C:\WINDOWS\system32\issearch.exe FOUND ! C:\WINDOWS\system32\ixt?.dll FOUND ! C:\WINDOWS\system32\ixt??.dll FOUND ! C:\WINDOWS\system32\mlraakb.dll FOUND ! C:\WINDOWS\system32\ot.ico FOUND ! C:\WINDOWS\system32\components\flx?.dll FOUND ! C:\WINDOWS\system32\components\flx??.dll FOUND ! C:\WINDOWS\system32\components\flx???.dll FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\user »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\user\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND ! C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\user\FAVORI~1 C:\DOCUME~1\user\FAVORI~1\Antivirus Test Online.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files C:\Program Files\Safety Bar\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{9cc1c589-4b22-4dae-8e12-4c3b5fa12b3f}"="gloomily" [HKEY_CLASSES_ROOT\CLSID\{9cc1c589-4b22-4dae-8e12-4c3b5fa12b3f}\InProcServer32] @="C:\WINDOWS\system32\mlraakb.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{9cc1c589-4b22-4dae-8e12-4c3b5fa12b3f}\InProcServer32] @="C:\WINDOWS\system32\mlraakb.dll" »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End [runkeys.txt] **************************************************************************** * GetRunKeys.Bat - © 01/28/2006 By Chaslang * * Beta only partially supports Win9x and ME * * 10/27/2006 Version 1.50 beta * * - Add flag for script mode install * * - SuperHidden reg key values * **************************************************************************** * Most of the information reported below is not necessarily bad. You must * * not take any steps on any of these lines without consulting an expert. * **************************************************************************** Windows OS is Microsoft Windows XP [Version 5.1.2600] It's Tue December 5, 2006 09:44:37 AM ****************************************************************************** ShowNew installation folder and files "C:\Documents and Settings\user\Desktop\Security Programs\GetRunKey\" getrun~1.bat Oct 27 2006 45591 "GetRunKey.bat" grep.exe Apr 14 2003 80412 "grep.exe" locate.com Jan 13 2005 11254 "locate.com" ltime.exe Oct 28 1986 13184 "ltime.exe" 4 items found: 4 files, 0 directories. Total of file sizes: 150,441 bytes 146.91 K —————————————————————————- Listing Standard Startup (Run) Registry Keys —————————————————————————- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Apou"="\"C:\\DOCUME~1\\user\\MYDOCU~1\\CURITY~1\\attrib.exe\" -vt ndrv" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run] "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" "D-Link RangeBooster G WDA-2320"="C:\\Program Files\\D-Link\\RangeBooster G WDA-2320\\AirPlusCFG.exe" "ANIWZCS2Service"="C:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe" "WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "SunServer"="C:\\Program Files\\Sunbelt Software\\CounterSpy\\Consumer\\sunserver.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnce] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnceEx] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] —————————————————————————- Listing MSCONFIG Registry Keys —————————————————————————- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state] "system.ini"=dword:00000000 "win.ini"=dword:00000000 "bootini"=dword:00000000 "services"=dword:00000000 "startup"=dword:00000000 —————————————————————————- Listing ModuleUsage Registry Keys —————————————————————————- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/asinst.dll] ".Owner"="{9A9307A0-7DA4-4DAF-B042-5009F29E09E1}" "{9A9307A0-7DA4-4DAF-B042-5009F29E09E1}"="" —————————————————————————- Listing HKCU Policies Registry Keys —————————————————————————- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\policies\Explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] "{6C4AD437-031B-1033-1102-990521040001}"="\"C:\\Program Files\\Common Files\\{6C4AD437-031B-1033-1102-990521040001}\\Update.exe\" mc-110-12-0000272" —————————————————————————- Listing HKCU Explorer\Advanced//Hidden and SuperHidden Registry Keys we want their values to be all equal to 1 if Hidden = 0 then Hidden Files and Folders are not shown if SuperHidden = 0 then File Extension are not shown if ShowSuperHidden = 0 then Operation System Files are not shown —————————————————————————- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Hidden"=dword:00000001 "SuperHidden"=dword:00000001 "ShowSuperHidden"=dword:00000001 —————————————————————————- Listing HKLM Policies Registry Keys —————————————————————————- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 —————————————————————————- Listing BHO Registry Keys —————————————————————————- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}] "NoExplorer"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35F7813A-AF74-4474-B1DC-7EE6FB6C43C6}] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3F634120-467F-4D25-9775-EE7CCAD38E51}] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6F1DF4AE-1769-4AED-3808-4A31C6B3FBCB}] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7A9BC6B1-7F27-47c6-A66D-13582E81E537}] @="CleanMyPC Popup Blocker" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}] @="AOL Toolbar Launcher" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C671A733-A4AA-4B5F-8CEE-006242C457B5}] —————————————————————————- Listing SharedTaskScheduler Registry Keys —————————————————————————- [HKEY_LOCAL_MACHINE\software\Microsoft\windows\currentversion\Explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" "{9cc1c589-4b22-4dae-8e12-4c3b5fa12b3f}"="gloomily" —————————————————————————- Listing ShellExecuteHooks Registry Keys —————————————————————————- [HKEY_LOCAL_MACHINE\software\Microsoft\windows\currentversion\Explorer\ShellExecuteHooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{9EF34FF2-3396-4527-9D27-04C8C1C67806}"="Microsoft AntiSpyware Service Hook" "{076394AD-7FDD-44EF-A075-32C68DBAB99B}"="" "{C671A733-A4AA-4B5F-8CEE-006242C457B5}"="" —————————————————————————- Listing ShellServiceObjectDelayLoad Registry Keys —————————————————————————- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" "gloomily"="{9cc1c589-4b22-4dae-8e12-4c3b5fa12b3f}" —————————————————————————- Listing Default URL Prefix Keys - a possible hijack point —————————————————————————- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix] @="http://" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes] "ftp"="ftp://" "gopher"="gopher://" "home"="http://" "mosaic"="http://" "www"="http://" —————————————————————————- HKEY_CURRENT_USER ZoneMap ProtocolDefaults —————————————————————————- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] @="" "http"=dword:00000003 "https"=dword:00000003 "ftp"=dword:00000003 "file"=dword:00000003 "@ivt"=dword:00000001 "shell"=dword:00000000 —————————————————————————- Miscellaneous Malware Detection Report —————————————————————————- List of Malware found in SharedTaskScheduler ———————————————————————— No Malware found in SharedTaskScheduler ———————————————————————— List of Malware found in C:\WINDOWS\system32 ———————————————————————— SmitFraud in C:\WINDOWS\system32\ot.ico ———————————————————————— Check for Troj-Torpig-D,E,J Keylogger ———————————————————————— Troj-Torpig-D,E,J Keylogger was not found ———————————————————————— Looking for winlogonhook/conhook trojan ———————————————————————— winlogonhook/conhook key not found ———————————————————————— [newfiles.txt] ****************************************************************************** * ShowNew.Bat - © 07/01/2006 By Chaslang * * * * 12/02/2006 Version 0.24 beta - check for W32.Beagle.FF@mm worm * ****************************************************************************** * Most of the information reported below is not necessarily bad. You must * * not take any steps on any of these lines without consulting an expert. * ****************************************************************************** Windows OS is Microsoft Windows XP [Version 5.1.2600] It's Tue December 5, 2006 09:46:59 AM ****************************************************************************** ShowNew installation folder and files "C:\Documents and Settings\user\Desktop\Security Programs\ShowNew\" grep.exe Apr 14 2003 80412 "grep.exe" locate.com Jan 13 2005 11254 "locate.com" ltime.exe Oct 28 1986 13184 "ltime.exe" shownew.bat Dec 3 2006 34966 "ShowNew.bat" 4 items found: 4 files, 0 directories. Total of file sizes: 139,816 bytes 136.54 K 2 Dir(s) 54,173,696 bytes free ****************************************************************************** System Environment Variables ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\user\Application Data CLASSPATH=.;C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=COMPUTER ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\user LOGONSERVER=\\COMPUTER NUMBER_OF_PROCESSORS=1 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\QuickTime\QTSystem\ PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 6 Model 8 Stepping 3, GenuineIntel PROCESSOR_LEVEL=6 PROCESSOR_REVISION=0803 ProgramFiles=C:\Program Files PROMPT=$P$G QTJAVA=C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\user\LOCALS~1\Temp TMP=C:\DOCUME~1\user\LOCALS~1\Temp USERDOMAIN=COMPUTER USERNAME=user USERPROFILE=C:\Documents and Settings\user windir=C:\WINDOWS __COMPAT_LAYER=EnableNXShowUI ****************************************************************************** Showing any Pocket Killbox backup files No matches found. ****************************************************************************** Not All Files Found are bad files: DO NOT TOUCH THEM WITHOUT EXPERT HELP!!!! ****************************************************************************** Locating all files created in C:\Documents and Settings\user\Desktop within the last 90 days. "C:\Documents and Settings\user\Desktop\" active~1.txt Dec 5 2006 15828 "Activescan.txt" cc_200~1.reg Dec 4 2006 104156 "cc_20061204_1808.reg" cc_200~2.reg Dec 4 2006 7831 "cc_20061204_1811.reg" cc_200~3.reg Dec 4 2006 94 "cc_20061204_1814.reg" counte~1.txt Dec 4 2006 53577 "counterspy.txt" HIJACK~1 Dec 4 2006 "hijackthis" hijack~1.log Dec 5 2006 5214 "hijackthis.log" hijack~1.zip Dec 4 2006 212849 "hijackthis.zip" SMITFR~1 Dec 5 2006 "SmitfraudFix" smitfr~1.zip Dec 5 2006 689448 "SmitfraudFix.zip" step2~1.txt Dec 5 2006 1558 "step 2.txt" ULTIMA~1 Sep 10 2006 "Ultimate X-Men" ULTIMA~2 Sep 26 2006 "Ultimate Universe" viruses.txt Dec 4 2006 4904 "viruses.txt" waters~1.ogg Nov 26 2006 1084968 "Waters_Loses_Temper_With_Audience.ogg" 15 items found: 11 files, 4 directories. Total of file sizes: 2,180,427 bytes 2.08 M ****************************************************************************** Locating all files created in C:\Documents and Settings\user\Start Menu\Programs\Startup within the last 90 days. No matches found. ****************************************************************************** Locating all files created in C:\Documents and Settings\All Users\Start Menu within the last 90 days. "C:\Documents and Settings\All Users\Start Menu\" online~1.url Dec 4 2006 107 "Online Security Guide.url" securi~1.url Dec 4 2006 102 "Security Troubleshooting.url" 2 items found: 2 files, 0 directories. Total of file sizes: 209 bytes 0.20 K ****************************************************************************** Locating all files created in C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ within the last 90 days. No matches found. ****************************************************************************** Locating all files created in C:\Documents and Settings\All Users\Desktop\ within the last 90 days. "C:\Documents and Settings\All Users\Desktop\" darkcr~1.lnk Nov 25 2006 553 "Dark Crusade.lnk" 1 item found: 1 file, 0 directories. Total of file sizes: 553 bytes 0.54 K ****************************************************************************** Locating all files created in C:\Documents and Settings\user\Application Data\ within the last 90 days. "C:\Documents and Settings\user\Application Data\" INSTAL~1 Nov 25 2006 "InstallShield" MYSPACE Nov 8 2006 "MySpace" 2 items found: 0 files, 2 directories. ****************************************************************************** Locating W32.Beagle.FF@mm worm in C:\Documents and Settings\user\Application Data\hidn *** If it reports "No matches found" then you do not have the worm *** No matches found. ****************************************************************************** Locating all files created in C:\Documents and Settings\user\Local Settings\Application Data\ within the last 90 days. "C:\Documents and Settings\user\Local Settings\Application Data\" dcbc2a~1.ini Dec 1 2006 45056 "DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini" iconca~1.db Dec 4 2006 3170082 "IconCache.db" SUN Dec 4 2006 "Sun" SUNBEL~1 Dec 4 2006 "Sunbelt Software" 4 items found: 2 files (1 H/S), 2 directories. Total of file sizes: 3,215,138 bytes 3.06 M ****************************************************************************** Locating all files created in C:\Documents and Settings\All Users\Application Data\ within the last 90 days. "C:\Documents and Settings\All Users\Application Data\" MACROM~1 Sep 21 2006 "Macromedia" NVIEW_~1 Oct 7 2006 "nView_Profiles" 2 items found: 0 files, 2 directories. ****************************************************************************** Locating all files created in C:\Program Files\ within the last 90 days. "C:\Program Files\" APPLES~1 Oct 14 2006 "Apple Software Update" CLEANM~1 Nov 26 2006 "CleanMyPC Popup Blocker" HJT Dec 4 2006 "HJT" ITUNES Oct 14 2006 "iTunes" MACROM~1 Sep 21 2006 "Macromedia" MSXML4~1.0 Nov 18 2006 "MSXML 4.0" MYSPACE Nov 8 2006 "MySpace" SAFETY~1 Dec 4 2006 "Safety Bar" SUNBEL~1 Dec 4 2006 "Sunbelt Software" WARCRA~1 Oct 20 2006 "Warcraft III" SSEMBL~1 Dec 1 2006 "?ssembly" 11 items found: 0 files, 11 directories. ****************************************************************************** DeluxeCommunications Search (new form of SurfSideKick) Locating all files created in C:\Program Files\DeluxeCommunications\ within the last 90 days. No matches found. ****************************************************************************** WebHancer - dohancer form Search Locating all files created in C:\Program Files\em\ within the last 90 days. No matches found. ****************************************************************************** WebHancer - hancmmnew form Search Locating all files created in C:\Program Files\mm\ within the last 90 days. No matches found. ****************************************************************************** Locating all files created in C:\Program Files\Common Files\ within the last 90 days. "C:\Program Files\Common Files\" AOL Sep 16 2006 "AOL" MACROM~1 Sep 21 2006 "Macromedia" OOWI Nov 25 2006 "oowi" SMANTE~1 Nov 30 2006 "S?mantec" yazzle~4.exe Nov 25 2006 32177 "Yazzle1122OinUninstaller.exe" {3C4AD~1 Dec 4 2006 "{3C4AD437-031B-1033-1102-990521040001}" {6C4AD~1 Dec 4 2006 "{6C4AD437-031B-1033-1102-990521040001}" 7 items found: 1 file (1 H/S), 6 directories. Total of file sizes: 32,177 bytes 31.42 K ****************************************************************************** Locating all files created in C:\Program Files\Common Files\Microsoft Shared\Web Folders within the last 120 days. No matches found. ****************************************************************************** Locating all files created in C:\ within the last 90 days. "C:\" boot.ini Dec 5 2006 211 "boot.ini" CONFIG.MSI Oct 14 2006 "Config.Msi" hiberfil.sys Dec 5 2006 670666752 "hiberfil.sys" newfiles.txt Dec 5 2006 11051 "newfiles.txt" pagefile.sys Dec 5 2006 1006632960 "pagefile.sys" rapport.txt Dec 5 2006 2766 "rapport.txt" runkeys.txt Dec 5 2006 11700 "runkeys.txt" 7 items found: 6 files (3 H/S), 1 directory (1 H/S). Total of file sizes: 1,677,325,440 bytes 1.56 G ****************************************************************************** Locating all files created in C:\WINDOWS\Downloaded Program Files\ within the last 90 days. No matches found. ****************************************************************************** Locating all files in C:\WINDOWS\PCHealth\HelpCtr\Binaries "C:\WINDOWS\pchealth\helpctr\binaries\" brpinfo.dll Aug 4 2004 21504 "brpinfo.dll" hcappres.dll Aug 4 2004 6656 "HCAppRes.dll" helpctr.exe Aug 4 2004 768512 "HelpCtr.exe" helphost.exe Aug 4 2004 99840 "HelpHost.exe" helpsvc.exe Aug 4 2004 743936 "HelpSvc.exe" hscsp_p3.cab Aug 4 2004 286777 "hscsp_p3.cab" hscupd.exe Aug 4 2004 18944 "HscUpd.exe" msconfig.exe Aug 4 2004 158208 "msconfig.exe" msinfo.dll Aug 4 2004 376320 "msinfo.dll" notiflag.exe Aug 4 2004 35328 "notiflag.exe" pchdt_p3.cab Aug 4 2004 2334260 "pchdt_p3.cab" pchshell.dll Aug 4 2004 102400 "pchshell.dll" pchsvc.dll Aug 4 2004 38912 "pchsvc.dll" 13 items found: 13 files, 0 directories. Total of file sizes: 4,991,597 bytes 4.76 M ****************************************************************************** Locating .EXE files created in C:\WINDOWS within the last 360 days. "C:\WINDOWS\" atmoun.exe Apr 3 2006 37027 "atmoUn.exe" bwunin~1.exe Feb 13 2006 81920 "bwUnin-6.1.4.68-8876480L.exe" bwunin~2.exe Apr 19 2006 118784 "bwUnin-[removed]-8876480SL.exe" uninst~1.exe Dec 13 2005 99965 "UninstallFirefox.exe" war3unin.exe Dec 28 2005 139264 "War3Unin.exe" 5 items found: 5 files, 0 directories. Total of file sizes: 476,960 bytes 465.78 K ****************************************************************************** Locating .EXE files created in C:\WINDOWS\system32 within the last 90 days. "C:\WINDOWS\system32\" aswboot.exe Sep 25 2006 666240 "aswBoot.exe" gidyppee.exe Nov 28 2006 88340 "gidyppee.exe" ismini.exe Dec 5 2006 6144 "ismini.exe" issearch.exe Dec 4 2006 31232 "issearch.exe" mrt.exe Nov 16 2006 10474920 "MRT.exe" swxcacls.exe Dec 1 2006 79360 "swxcacls.exe" vnlcjtda.exe Nov 25 2006 110612 "vnlcjtda.exe" wapitr.exe Dec 1 2006 2 "wapitr.exe" 8 items found: 8 files, 0 directories. Total of file sizes: 11,456,850 bytes 10.93 M ****************************************************************************** Locating .DLL files created in C:\WINDOWS within the last 360 days. No matches found. ****************************************************************************** Locating .DLL files created in C:\WINDOWS\System32 within the last 90 days. "C:\WINDOWS\system32\" browseui.dll Sep 14 2006 1022976 "browseui.dll" byuatfsx.dll Nov 25 2006 38420 "byuatfsx.dll" byvuv.dll Dec 5 2006 2 "byvuv.dll" cdfview.dll Sep 14 2006 151040 "cdfview.dll" cmdlin~1.dll Nov 24 2006 43520 "CmdLineExt03.dll" cyqggosq.dll Nov 28 2006 42516 "cyqggosq.dll" danim.dll Sep 14 2006 1054208 "danim.dll" ddcaw.dll Nov 25 2006 708660 "ddcaw.dll" deuyjtyo.dll Nov 26 2006 126996 "deuyjtyo.dll" drvtiv.dll Dec 4 2006 72704 "drvtiv.dll" drvvex.dll Nov 25 2006 71168 "drvvex.dll" dxtmsft.dll Sep 14 2006 357888 "dxtmsft.dll" dxtrans.dll Sep 14 2006 205312 "dxtrans.dll" extmgr.dll Sep 14 2006 55808 "extmgr.dll" iepeers.dll Sep 14 2006 251392 "iepeers.dll" inseng.dll Sep 14 2006 96256 "inseng.dll" ixt1.dll Dec 4 2006 18432 "ixt1.dll" jsproxy.dll Sep 14 2006 16384 "jsproxy.dll" kldibtna.dll Nov 25 2006 126996 "kldibtna.dll" mlraakb.dll Dec 4 2006 18432 "mlraakb.dll" mshtml.dll Sep 14 2006 3054592 "mshtml.dll" mshtmled.dll Sep 14 2006 448512 "mshtmled.dll" msrating.dll Sep 14 2006 146432 "msrating.dll" mstime.dll Sep 14 2006 532480 "mstime.dll" msxml3.dll Sep 13 2006 1084416 "msxml3.dll" msxml4.dll Nov 4 2006 1245696 "msxml4.dll" nwprovau.dll Oct 13 2006 142336 "nwprovau.dll" pngfilt.dll Sep 14 2006 39424 "pngfilt.dll" qomkl.dll Dec 5 2006 2 "qomkl.dll" raokutqi.dll Dec 4 2006 126996 "raokutqi.dll" shlwapi.dll Sep 14 2006 474112 "shlwapi.dll" urlmon.dll Sep 14 2006 613888 "urlmon.dll" whqthoxi.dll Dec 4 2006 126996 "whqthoxi.dll" wininet.dll Sep 14 2006 658944 "wininet.dll" wvurqop.dll Nov 25 2006 40973 "wvurqop.dll" wvutsrp.dll Dec 4 2006 40973 "wvutsrp.dll" xpsp3res.dll Oct 16 2006 248320 "xpsp3res.dll" ydcsrybe.dll Dec 1 2006 126996 "ydcsrybe.dll" 38 items found: 38 files (3 H/S), 0 directories. Total of file sizes: 13,631,198 bytes 12.99 M ****************************************************************************** Locating .TMP files created in C:\WINDOWS\System32 within the last 90 days. "C:\WINDOWS\system32\" mcrh.tmp Nov 30 2006 143 "mcrh.tmp" wacdd.tmp Nov 25 2006 774069 "wacdd.tmp" 2 items found: 2 files (1 H/S), 0 directories. Total of file sizes: 774,212 bytes 756.07 K ****************************************************************************** Locating .INI files created in C:\WINDOWS\System32 within the last 90 days. "C:\WINDOWS\system32\" perfst~1.ini Oct 29 2006 482856 "PerfStringBackup.INI" wacdd.ini Nov 25 2006 774069 "wacdd.ini" wacdd~1.ini Dec 5 2006 774253 "wacdd.ini2" 3 items found: 3 files (2 H/S), 0 directories. Total of file sizes: 2,031,178 bytes 1.93 M ****************************************************************************** Locating .DAT files created in C:\WINDOWS\System32 within the last 90 days. "C:\WINDOWS\system32\" fntcache.dat Sep 27 2006 351664 "FNTCACHE.DAT" perfc009.dat Oct 29 2006 61052 "perfc009.dat" perfh009.dat Oct 29 2006 414128 "perfh009.dat" 3 items found: 3 files, 0 directories. Total of file sizes: 826,844 bytes 807.46 K ****************************************************************************** Locating all files created in C:\WINDOWS\System32\components within the last 90 days. This folder is now being used by Trojan.FakeAlert.CX aka SmitFraud "C:\WINDOWS\system32\components\" flx7.dll Dec 4 2006 29216 "flx7.dll" 1 item found: 1 file, 0 directories. Total of file sizes: 29,216 bytes 28.53 K ****************************************************************************** Locating C:\WINDOWS\TEMP files created with in the last 90 days. "C:\WINDOWS\Temp\" 2f49ce31.tmp Dec 1 2006 117 "2F49CE31.TMP" ASHEUR~1 Dec 4 2006 "ASHeuristic" mst107.tmp Dec 4 2006 72704 "mst107.tmp" remova~1.bat Dec 4 2006 43 "removalfile.bat" vblang~1.ini Dec 4 2006 32723 "VBLanguage.ini" wgaerr~1.txt Dec 5 2006 255 "WGAErrLog.txt" wganot~1.set Dec 5 2006 409 "WGANotify.settings" win101.tmp Dec 4 2006 0 "win101.tmp" win102~1.exe Dec 4 2006 138565 "win102.tmp.exe" win103.tmp Dec 4 2006 0 "win103.tmp" win105.tmp Dec 4 2006 0 "win105.tmp" win106~1.exe Dec 4 2006 184689 "win106.tmp.exe" win108.tmp Dec 4 2006 0 "win108.tmp" win10a.tmp Dec 4 2006 0 "win10A.tmp" win10b.tmp Dec 4 2006 11573 "win10B.tmp" win10d.tmp Dec 4 2006 0 "win10D.tmp" win116.tmp Dec 4 2006 0 "win116.tmp" win13c.tmp Dec 4 2006 0 "win13C.tmp" win13d.tmp Dec 4 2006 0 "win13D.tmp" win19f.tmp Dec 4 2006 0 "win19F.tmp" win1ae.tmp Dec 4 2006 0 "win1AE.tmp" win1b0.tmp Dec 4 2006 0 "win1B0.tmp" win1b1.tmp Dec 4 2006 944 "win1B1.tmp" win1b3.tmp Dec 4 2006 0 "win1B3.tmp" win1d5.tmp Dec 4 2006 0 "win1D5.tmp" win1e3.tmp Dec 4 2006 0 "win1E3.tmp" win202.tmp Dec 4 2006 0 "win202.tmp" win341.tmp Dec 4 2006 0 "win341.tmp" win41c.tmp Dec 4 2006 0 "win41C.tmp" win41d.tmp Dec 4 2006 944 "win41D.tmp" win41f.tmp Dec 4 2006 0 "win41F.tmp" win420.tmp Dec 4 2006 0 "win420.tmp" win421.tmp Dec 4 2006 0 "win421.tmp" win422.tmp Dec 4 2006 0 "win422.tmp" win423.tmp Dec 5 2006 0 "win423.tmp" win424.tmp Dec 5 2006 0 "win424.tmp" win425.tmp Dec 5 2006 944 "win425.tmp" win42e.tmp Dec 5 2006 0 "win42E.tmp" win452.tmp Dec 5 2006 0 "win452.tmp" winb1.tmp Dec 4 2006 0 "winB1.tmp" winb2.tmp Dec 4 2006 0 "winB2.tmp" winf9.tmp Dec 4 2006 0 "winF9.tmp" winfa.tmp Dec 4 2006 0 "winFA.tmp" winfb.tmp Dec 4 2006 0 "winFB.tmp" winfc.tmp Dec 4 2006 0 "winFC.tmp" winfe.tmp Dec 4 2006 944 "winFE.tmp" winff.tmp Dec 4 2006 0 "winFF.tmp" 47 items found: 46 files (1 H/S), 1 directory. Total of file sizes: 444,854 bytes 434.43 K ****************************************************************************** Locating C:\Documents and Settings\user\Local Settings\TEMP files created within the last 90 days. "C:\Documents and Settings\user\Local Settings\Temp\" 2f49ce31.tmp Dec 1 2006 117 "2F49CE31.TMP" fe612.tmp Dec 5 2006 0 "fe612.tmp" MSOHTML Dec 4 2006 "msohtml" MSOHTML1 Dec 4 2006 "msohtml1" ODUT Dec 4 2006 "Odut" ~df2be3.tmp Dec 5 2006 16384 "~DF2BE3.tmp" ~df35a4.tmp Dec 5 2006 16384 "~DF35A4.tmp" ~df4cf5.tmp Dec 5 2006 49152 "~DF4CF5.tmp" ~df6733.tmp Dec 5 2006 16384 "~DF6733.tmp" ~df6a1f.tmp Dec 4 2006 1212416 "~DF6A1F.tmp" ~df77d0.tmp Dec 5 2006 32768 "~DF77D0.tmp" ~df7b40.tmp Dec 5 2006 32768 "~DF7B40.tmp" ~df8e67.tmp Dec 4 2006 16384 "~DF8E67.tmp" ~df9739.tmp Dec 5 2006 16384 "~DF9739.tmp" ~df9b.tmp Dec 5 2006 16384 "~DF9B.tmp" ~df9f0.tmp Dec 5 2006 32768 "~DF9F0.tmp" ~dfa6c2.tmp Dec 5 2006 32768 "~DFA6C2.tmp" ~dfba05.tmp Dec 5 2006 32768 "~DFBA05.tmp" ~dfc29.tmp Dec 5 2006 49152 "~DFC29.tmp" ~dfc2ec.tmp Dec 4 2006 32768 "~DFC2EC.tmp" ~dfc74b.tmp Dec 5 2006 49152 "~DFC74B.tmp" ~dfce87.tmp Dec 4 2006 49152 "~DFCE87.tmp" ~dfd7d.tmp Dec 5 2006 16384 "~DFD7D.tmp" ~NSU.TMP Dec 4 2006 "~nsu.tmp" 24 items found: 20 files, 4 directories. Total of file sizes: 1,720,437 bytes 1.64 M ****************************************************************************** Locating .COM files in the C:\WINDOWS\System32 folder "C:\WINDOWS\system32\" chcp.com Aug 4 2004 7680 "chcp.com" command.com Aug 4 2004 50
diskcomp.com Aug 4 2004 9216 "diskcomp.com"
diskcopy.com Aug 4 2004 7168 "diskcopy.com"
edit.com Aug 4 2004 69886 "edit.com"
format.com Aug 4 2004 25600 "format.com"
graftabl.com Aug 4 2004 26112 "graftabl.com"
graphics.com Aug 4 2004 19694 "graphics.com"
kb16.com Aug 4 2004 14710 "kb16.com"
loadfix.com Aug 4 2004 1131 "loadfix.com"
locate.com Jan 13 2005 11254 "locate.com"
mode.com Aug 4 2004 19456 "mode.com"
more.com Aug 4 2004 15872 "more.com"
tree.com Aug 4 2004 11264 "tree.com"
win.com Aug 4 2004 18432 "win.com"

15 items found: 15 files, 0 directories.
Total of file sizes: 308,095 bytes 300.87 K
******************************************************************************

Checking for .COM files to Delete. They will only print if deleted!

******************************************************************************

Dumping HKLM Uninstall Programs list

"DisplayName"="530TX"
"DisplayName"="AC3Filter (remove only)"
"DisplayName"="Ad-Aware SE Personal"
"DisplayName"="Adobe Atmosphere Player for Acrobat and Adobe Reader"
"DisplayName"="Adobe Creative Suite"
"DisplayName"="Adobe Flash Player 9 ActiveX"
"DisplayName"="Adobe SVG Viewer 3.0"
"DisplayName"="Ahead Nero Burning ROM"
"DisplayName"="ANIO Service"
"DisplayName"="ANIWZCS2 Service"
"DisplayName"="AOL Instant Messenger"
"DisplayName"="Apple Software Update"
"DisplayName"="AutoUpdate"
"DisplayName"="avast! Antivirus"
"DisplayName"="Azureus"
"DisplayName"="Blaze Media Pro"
"DisplayName"="Blaze Media Pro"
"DisplayName"="Canon Camera WIA Driver"
"DisplayName"="Canon EOS 20D WIA Driver"
"DisplayName"="Canon PIXMA iP6000D"
"DisplayName"="CCleaner (remove only)"
"DisplayName"="CDisplay 1.8"
"DisplayName"="CleanMyPC Popup Blocker"
"DisplayName"="D-Link NICSET"
"DisplayName"="D-Link PCI Fast Ethernet Adapter"
"DisplayName"="DAEMON Tools"
"DisplayName"="Dawn of War - Dark Crusade"
"DisplayName"="DawnOfWar"
"DisplayName"="DawnOfWar"
"DisplayName"="DFE-530TX Driver"
"DisplayName"="DivX"
"DisplayName"="eMusic - 100 Free MP3 offer"
"DisplayName"="G-Force"
"DisplayName"="GiPo@MoveOnBoot 1.9.5"
"DisplayName"="Google Earth"
"DisplayName"="GSpot Codec Information Appliance"
"DisplayName"="HijackThis 1.99.1"
"DisplayName"="Hotfix for Windows XP (KB914440)"
"DisplayName"="iPod Updater 2004-11-15"
"DisplayName"="iPod Updater 2004-11-15"
"DisplayName"="IrfanView (remove only)"
"DisplayName"="iTunes"
"DisplayName"="J2SE Runtime Environment 5.0 Update 1"
"DisplayName"="J2SE Runtime Environment 5.0 Update 2"
"DisplayName"="J2SE Runtime Environment 5.0 Update 6"
"DisplayName"="Logitech Desktop Messenger"
"DisplayName"="Logitech SetPoint"
"DisplayName"="Macromedia Dreamweaver 8"
"DisplayName"="Macromedia Extension Manager"
"DisplayName"="MediaTickets by OIN"
"DisplayName"="Microsoft .NET Framework 1.1"
"DisplayName"="Microsoft AntiSpyware"
"DisplayName"="Microsoft Office Access MUI Edition (English) 12 [pre-release]"
"DisplayName"="Microsoft Office Excel MUI Edition (English) 12 [pre-release]"
"DisplayName"="Microsoft Office InfoPath MUI Edition (English) 12 [pre-release]"
"DisplayName"="Microsoft Office Outlook MUI Edition (English) 12 [pre-release]"
"DisplayName"="Microsoft Office PowerPoint MUI Edition (English) 12 [pre-release]"
"DisplayName"="Microsoft Office Professional Edition 12 [pre-release]"
"DisplayName"="Microsoft Office Professional Edition 2003"
"DisplayName"="Microsoft Office Professional Enterprise Edition 12 [pre-release]"
"DisplayName"="Microsoft Office Proof Edition (English) 12 [pre-release]"
"DisplayName"="Microsoft Office Publisher MUI Edition (English) 12 [pre-release]"
"DisplayName"="Microsoft Office Shared MUI Edition (English) 12 [pre-release]"
"DisplayName"="Microsoft Office Word MUI Edition (English) 12 [pre-release]"
"DisplayName"="Monitor Calibration Wizard 1.0"
"DisplayName"="Mozilla Firefox (1.0.7)"
"DisplayName"="MSN Music Assistant"
"DisplayName"="MSXML 4.0 SP2 (KB927978)"
"DisplayName"="MySpaceIM"
"DisplayName"="NVIDIA Drivers"
"DisplayName"="Panda ActiveScan"
"DisplayName"="Quick Screen Capture 2.2"
"DisplayName"="QuickTime"
"DisplayName"="RangeBooster G WDA-2320"
"DisplayName"="RangeBooster G WDA-2320"
"DisplayName"="RawShooter essentials 2006"
"DisplayName"="Real Alternative 1.45"
"DisplayName"="Safety Bar"
"DisplayName"="Security Update for Windows Media Player (KB911564)"
"DisplayName"="Security Update for Windows Media Player 10 (KB911565)"
"DisplayName"="Security Update for Windows Media Player 10 (KB917734)"
"DisplayName"="Security Update for Windows XP (KB883939)"
"DisplayName"="Security Update for Windows XP (KB890046)"
"DisplayName"="Security Update for Windows XP (KB893756)"
"DisplayName"="Security Update for Windows XP (KB896358)"
"DisplayName"="Security Update for Windows XP (KB896422)"
"DisplayName"="Security Update for Windows XP (KB896423)"
"DisplayName"="Security Update for Windows XP (KB896424)"
"DisplayName"="Security Update for Windows XP (KB896428)"
"DisplayName"="Security Update for Windows XP (KB896688)"
"DisplayName"="Security Update for Windows XP (KB899587)"
"DisplayName"="Security Update for Windows XP (KB899588)"
"DisplayName"="Security Update for Windows XP (KB899591)"
"DisplayName"="Security Update for Windows XP (KB900725)"
"DisplayName"="Security Update for Windows XP (KB901017)"
"DisplayName"="Security Update for Windows XP (KB901214)"
"DisplayName"="Security Update for Windows XP (KB902400)"
"DisplayName"="Security Update for Windows XP (KB903235)"
"DisplayName"="Security Update for Windows XP (KB904706)"
"DisplayName"="Security Update for Windows XP (KB905414)"
"DisplayName"="Security Update for Windows XP (KB905749)"
"DisplayName"="Security Update for Windows XP (KB905915)"
"DisplayName"="Security Update for Windows XP (KB908519)"
"DisplayName"="Security Update for Windows XP (KB908531)"
"DisplayName"="Security Update for Windows XP (KB911280)"
"DisplayName"="Security Update for Windows XP (KB911562)"
"DisplayName"="Security Update for Windows XP (KB911567)"
"DisplayName"="Security Update for Windows XP (KB911927)"
"DisplayName"="Security Update for Windows XP (KB912812)"
"DisplayName"="Security Update for Windows XP (KB912919)"
"DisplayName"="Security Update for Windows XP (KB913433)"
"DisplayName"="Security Update for Windows XP (KB913446)"
"DisplayName"="Security Update for Windows XP (KB913580)"
"DisplayName"="Security Update for Windows XP (KB914388)"
"DisplayName"="Security Update for Windows XP (KB914389)"
"DisplayName"="Security Update for Windows XP (KB916281)"
"DisplayName"="Security Update for Windows XP (KB917159)"
"DisplayName"="Security Update for Windows XP (KB917344)"
"DisplayName"="Security Update for Windows XP (KB917422)"
"DisplayName"="Security Update for Windows XP (KB917953)"
"DisplayName"="Security Update for Windows XP (KB918439)"
"DisplayName"="Security Update for Windows XP (KB918899)"
"DisplayName"="Security Update for Windows XP (KB919007)"
"DisplayName"="Security Update for Windows XP (KB920213)"
"DisplayName"="Security Update for Windows XP (KB920214)"
"DisplayName"="Security Update for Windows XP (KB920670)"
"DisplayName"="Security Update for Windows XP (KB920683)"
"DisplayName"="Security Update for Windows XP (KB920685)"
"DisplayName"="Security Update for Windows XP (KB921398)"
"DisplayName"="Security Update for Windows XP (KB921883)"
"DisplayName"="Security Update for Windows XP (KB922616)"
"DisplayName"="Security Update for Windows XP (KB922760)"
"DisplayName"="Security Update for Windows XP (KB922819)"
"DisplayName"="Security Update for Windows XP (KB923191)"
"DisplayName"="Security Update for Windows XP (KB923414)"
"DisplayName"="Security Update for Windows XP (KB923980)"
"DisplayName"="Security Update for Windows XP (KB924191)"
"DisplayName"="Security Update for Windows XP (KB924270)"
"DisplayName"="Security Update for Windows XP (KB924496)"
"DisplayName"="Security Update for Windows XP (KB925486)"
"DisplayName"="Spybot - Search & Destroy 1.3"
"DisplayName"="SpywareBlaster v3.5.1"
"DisplayName"="Sunbelt CounterSpy"
"DisplayName"="TeamSpeak 2 RC2"
"DisplayName"="Update for Windows XP (KB894391)"
"DisplayName"="Update for Windows XP (KB896727)"
"DisplayName"="Update for Windows XP (KB898461)"
"DisplayName"="Update for Windows XP (KB900485)"
"DisplayName"="Update for Windows XP (KB904942)"
"DisplayName"="Update for Windows XP (KB910437)"
"DisplayName"="Update for Windows XP (KB916595)"
"DisplayName"="Update for Windows XP (KB920872)"
"DisplayName"="Update for Windows XP (KB922582)"
"DisplayName"="WebFldrs XP"
"DisplayName"="Winamp (remove only)"
"DisplayName"="Windows Genuine Advantage Notifications (KB905474)"
"DisplayName"="Windows Genuine Advantage v1.3.0254.0"
"DisplayName"="Windows Installer 3.1 (KB893803)"
"DisplayName"="Windows Installer 3.1 (KB893803)"
"DisplayName"="Windows Media Format Runtime"
"DisplayName"="Windows Media Player 10"
"DisplayName"="Windows XP Hotfix - KB867282"
"DisplayName"="Windows XP Hotfix - KB873333"
"DisplayName"="Windows XP Hotfix - KB873339"
"DisplayName"="Windows XP Hotfix - KB885250"
"DisplayName"="Windows XP Hotfix - KB885835"
"DisplayName"="Windows XP Hotfix - KB885836"
"DisplayName"="Windows XP Hotfix - KB885884"
"DisplayName"="Windows XP Hotfix - KB886185"
"DisplayName"="Windows XP Hotfix - KB887472"
"DisplayName"="Windows XP Hotfix - KB887742"
"DisplayName"="Windows XP Hotfix - KB888113"
"DisplayName"="Windows XP Hotfix - KB888302"
"DisplayName"="Windows XP Hotfix - KB890047"
"DisplayName"="Windows XP Hotfix - KB890175"
"DisplayName"="Windows XP Hotfix - KB890859"
"DisplayName"="Windows XP Hotfix - KB890923"
"DisplayName"="Windows XP Hotfix - KB891781"
"DisplayName"="Windows XP Hotfix - KB893066"
"DisplayName"="Windows XP Hotfix - KB893086"
"DisplayName"="WinRAR archiver"
"DisplayName"="WinZip"
"DisplayName"="World of Warcraft"
"DisplayName"="Yahoo! Toolbar"
"DisplayName"="Yahoo! Toolbar"

[hijackthis.log]
Logfile of HijackThis v1.99.1
Scan saved at 9:48:37 AM, on 12/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
C:\Program Files\D-Link\RangeBooster G WDA-2320\AirPlusCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\Program Files\Common Files\{6C4AD437-031B-1033-1102-990521040001}\Update.exe
C:\DOCUME~1\user\MYDOCU~1\CURITY~1\attrib.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HJT\Analyse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {6F1DF4AE-1769-4AED-3808-4A31C6B3FBCB} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\system32\cyqggosq.dll
O2 - BHO: (no name) - {3F634120-467F-4D25-9775-EE7CCAD38E51} - C:\WINDOWS\system32\ddcaw.dll
O2 - BHO: (no name) - {6F1DF4AE-1769-4AED-3808-4A31C6B3FBCB} - (no file)
O2 - BHO: CleanMyPC Popup Blocker - {7A9BC6B1-7F27-47c6-A66D-13582E81E537} - C:\Program Files\CleanMyPC Popup Blocker\CleanBHO.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
O2 - BHO: (no name) - {C671A733-A4AA-4B5F-8CEE-006242C457B5} - C:\WINDOWS\system32\wvutsrp.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: CleanMyPC Toolbar - {04164EC4-1E48-4279-818E-3721931E7636} - C:\Program Files\CleanMyPC Popup Blocker\CleanBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [D-Link RangeBooster G WDA-2320] C:\Program Files\D-Link\RangeBooster G WDA-2320\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKCU\..\Run: [Apou] "C:\DOCUME~1\user\MYDOCU~1\CURITY~1\attrib.exe" -vt ndrv
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: ddcaw - C:\WINDOWS\system32\ddcaw.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winzue32 - winzue32.dll (file missing)
O20 - Winlogon Notify: wvutsrp - C:\WINDOWS\SYSTEM32\wvutsrp.dll
O21 - SSODL: gloomily - {9cc1c589-4b22-4dae-8e12-4c3b5fa12b3f} - C:\WINDOWS\system32\mlraakb.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SX Service (SXServ) - Unknown owner - C:\WINDOWS\system32\sxserv101.exe (file missing)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI