Win XP Home SP0
Two users, with HJT logs below.
Steps taken thus far:
scanned at Panda, which found 7 trojans & repaired them;
scanned with Norton, locally, latest definitions, which found nothing;
CWShredder run; "an error occurred" when trying to update;
LOP remover run;
VX2 cleaner add-in for AAWSE - deemed clean;
Peper fixer - found nothing;
*****
At boot, there is an error that a line from win.ini cannot load. It refers to a line of small rectangles.
In the System Config startup group, it loads from:
HKCU_Software\Microsoft\Wi
ndowsNT\Cu
rrentVersi
on\Windows
\Load
and
HKCU_Software\Microsoft\Wi
ndowsNT\Cu
rrentVersi
on\Windows
\Run
The values associated with these keys are blank, empty, nothing.
Win.ini
; for 16-bit app support
[fonts]
[extensions]
[mci extensions]
[files]
[Mail]
MAPI=1
MAPIX=1
[MCI Extensions.BAK]
aif=MPEGVideo
aifc=MPEGVideo
aiff=MPEGVideo
asf=MPEGVideo2
asx=MPEGVideo2
au=MPEGVideo
m1v=MPEGVideo
m3u=MPEGVideo2
mp2=MPEGVideo
mp2v=MPEGVideo
mp3=MPEGVideo2
mpa=MPEGVideo
mpe=MPEGVideo
mpeg=MPEGVideo
mpg=MPEGVideo
mpv2=MPEGVideo
snd=MPEGVideo
wax=MPEGVideo2
wm=MPEGVideo2
wma=MPEGVideo2
wmp=MPEGVideo2
wmv=MPEGVideo2
wmx=MPEGVideo2
wvx=MPEGVideo2
wpl=MPEGVideo
ivf=MPEGVideo2
[WCS2000]
AppPath=C:\Program Files\CompuServe 2000
SharedPath=C:\Program Files\Common Files\CSSHARE
[midi studio 7 deLuxe]
MidiOut_SoundMAX_Wavetable
_Synth=1
MidiOut_Microsoft_GS_Wavet
able_SW_Sy
nth=1
[midi studio deLuxe]
[midi studio 2003]
[midi studio 7 demo]
SampleEditor=C:\MAGIX\ms7_
demo\AudSt
u.exe
[midi studio 7]
MidiOut_SoundMAX_Wavetable
_Synth=1
MidiOut_Microsoft_GS_Wavet
able_SW_Sy
nth=1
[fontopts]
alignparam=JFKEJEJGE
[ABBYY]
Splash5=-1910415685
[annie]
CaptureFile=
VideoDevice=0
AudioDevice=0
FrameRate=667111
UseFrameRate=1
CaptureAudio=1
WantPreview=0
MasterStream=-1
[programs]
NOTEPAD.EXE=C:\Documents and Settings\User_Name_DP\Rece
nt\MYIMAGE
2.lnk
*****
When I create a log file, after running HJT for example, notepad appears.
HOWEVER, if I save that file as a *.txt & later open the file, I am informed that the OS cannot find notepad.exe.
Could it be that notepad.exe has been manipulated such that every time we create a *.txt, we are re-infecting / re-infesting the computer?
****
User 1
Initial AAW SE log:
180Solutions(TAC index:8):19 total references
AdDestroyer(TAC index:5):1 total references
AdRotator(TAC index:6):4 total references
Adsincontext(TAC index:6):1 total references
BargainBuddy(TAC index:8):3 total references
BlazeFind(TAC index:5):6 total references
BrilliantDigital(TAC index:6):1 total references
ClearSearch(TAC index:7):8 total references
ClipGenie(TAC index:4):4 total references
CoolWebSearch(TAC index:10):13 total references
DownloadWare(TAC index:8):6 total references
DyFuCA(TAC index:3):2 total references
eAcceleration(TAC index:7):13 total references
IBIS Toolbar(TAC index:5):399 total references
ImIServer IEPlugin(TAC index:5):16 total references
istbar.dotcomToolbar(TAC index:5):1 total references
istbar(TAC index:6):2 total references
Lycos Sidesearch(TAC index:7):6 total references
MediaCharger(TAC index:5):1 total references
Other(TAC index:5):11 total references
Possible Browser Hijack attempt(TAC index:3):7 total references
Roings(TAC index:5):1 total references
SecondThought(TAC index:4):3 total references
Tracking Cookie(TAC index:3):26 total references
Virtumundo(TAC index:10):1 total references
VX2(TAC index:10):66 total references
WhenU(TAC index:10):40 total references
Win32.Adverts.TrojanDownlo
ader(TAC index:6):1 total references
WinFavorites(TAC index:6):14 total references
Hi Jack This Logs
Peper found nothing.
Logfile of HijackThis v1.99.0
Scan saved at 4:03:14 AM, on 1/15/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\PROGRA~1\STOPZI~1\sznts
vc.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\Packet
hSvc.exe
C:\WINDOWS\System32\cisvc.
exe
c:\program files\cox\applications\app
\CurtainsS
ysSvcNt.ex
e
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\RUNDLL
32.exe
C:\Program Files\Synaptics\SynTP\SynT
PLpr.exe
C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Compaq\EAB\EabServr.
exe
C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\CTP
DPSRV.EXE
C:\Program Files\BearShare\BearShare.
exe
C:\WINDOWS\system32\fxssvc
.exe
C:\Program Files\BearShare\BearShare.
exe
C:\PROGRA~1\COMMON~1\AOL\A
OLSPY~1\AO
LSP Scheduler.exe
C:\PROGRA~1\SPRINT~1.0OF\S
print\CAge
nt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\THEWEA~1\DWHea
rtbeatMoni
tor.exe
C:\Program Files\mozilla.org\Mozilla\
Mozilla.ex
e
C:\Program Files\AIM\aim.exe
C:\Program Files\Compaq A3000\CPQA3000.exe
C:\Program Files\SpywareGuard\sgmain.
exe
C:\Program Files\SpywareGuard\sgbhp.e
xe
C:\WINDOWS\System32\cidaem
on.exe
C:\WINDOWS\System32\dumpre
p.exe
C:\WINDOWS\System32\dumpre
p.exe
C:\WINDOWS\System32\dumpre
p.exe
C:\WINDOWS\System32\dumpre
p.exe
C:\WINDOWS\System32\dumpre
p.exe
C:\WINDOWS\System32\dumpre
p.exe
C:\WINDOWS\System32\dwwin.
exe
C:\WINDOWS\System32\dwwin.
exe
C:\WINDOWS\System32\dwwin.
exe
C:\WINDOWS\System32\dwwin.
exe
C:\WINDOWS\System32\dwwin.
exe
C:\WINDOWS\System32\dwwin.
exe
C:\utilities_14Jan2005\hij
ackthis\Hi
jackThis.e
xe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://store.presario.net/scripts/r...&c=1c02&lc=0409R1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,ShellNext =
http://store.presario.net/scripts/r...&c=1c02&lc=0409R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
F3 - REG:win.ini: load=??? ??? ??? ? ? ?? ? , ??? ??? ??? ? ? ?????
F2 - REG:system.ini: UserInit=C:\WINDOWS\System
32\Userini
t.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7
695ECA0567
0} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn0
\ycomp5_3_
16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH
elper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0
B27DDD11DB
2} - C:\Program Files\SpywareGuard\dlprote
ct.dll
O2 - BHO: AuthBHO.cBHO - {A4D90779-6CB2-4752-83C2-A
2AB4D9A672
D} - C:\Program Files\Cox\Applications\app
\AuthBHO.d
ll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-0
0D0B743919
D} - (no file)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn0
\ycomp5_3_
16_0.dll
O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9
620D33362C
1} - C:\Program Files\Cox\Applications\app
\AuthBHO.d
ll
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA
\cdaEngine
0400.dll",
cdaEngineM
ain
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynT
PLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla
.exe" /autorun
O4 - HKLM\..\Run: [StopSignStatus] Rundll32.exe "C:\Program Files\Common Files\eAcceleration\Instal
ler\stopsi
nfo.dll",V
erifyStatu
s
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [P2P Networking2] C:\WINDOWS\System32\P2P Networking\P2P Networking2.exe /AUTOSTART
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.
exe /Start
O4 - HKLM\..\Run: [CTPDPSRV] C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\CTP
DPSRV.EXE
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.
exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.
exe" /pause
O4 - HKLM\..\Run: [AuthConsoleStart] C:\Program Files\Cox\Applications\app
\cox.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\
AOLSPY~1\A
OLSP Scheduler.exe"
O4 - HKLM\..\Run: [ABBYY Community Agent] C:\PROGRA~1\SPRINT~1.0OF\S
print\CAge
nt.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [DWHeartbeatMonitor] C:\PROGRA~1\THEWEA~1\DWHea
rtbeatMoni
tor.exe
O4 - HKCU\..\Run: [Desktop Weather 3] C:\PROGRA~1\THEWEA~1\The Weather Channel.exe
O4 - HKCU\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTo
ols\WTools
A.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\mozilla.org\Mozilla\
Mozilla.ex
e" -turbo
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Compaq A3000 Settings Utility.lnk = C:\Program Files\Compaq A3000\CPQA3000.exe
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\Precis
ionTime.ex
e
O4 - Global Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.
exe
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-0
00103C116D
5} - C:\Program Files\Yahoo!\Common\ylogin
.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-0
00103C116D
5} - C:\Program Files\Yahoo!\Common\ylogin
.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-0
0010333D0A
D} - C:\Program Files\Yahoo!\Companion\Mod
ules\messm
od2\v4\yhe
xbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-0
0010333D0A
D} - C:\Program Files\Yahoo!\Companion\Mod
ules\messm
od2\v4\yhe
xbmes.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
0B0D0A1DE4
5} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Advisor - {76026873-0935-499C-B66A-9
FF5EEF45BE
A} - C:\Program Files\COMPAQ\Compaq Advisor\bin\rbaLauncher.ex
e (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O14 - IERESET.INF: START_PAGE_URL=
http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409O16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/gam...ts/y/pote_x.cabO16 - DPF: {CA034DCC-A580-4333-B52F-1
5F98C42E04
C} (Downloader Class) -
http://www.stopzilla.com/_download/...ller/dwnldr.cabO23 - Service: Compaq Advisor - NeoPlanet - C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Curtains for Windows System Service - Authentium, Inc. - c:\program files\cox\applications\app
\CurtainsS
ysSvcNt.ex
e
O23 - Service: Virtual NIC Service - America Online, Inc. - C:\WINDOWS\System32\Packet
hSvc.exe
O23 - Service: STOPzilla Local Service - International Software Systems Solutions - C:\PROGRA~1\STOPZI~1\sznts
vc.exe
O23 - Service: Windows User Mode Driver Framework - Unknown - C:\WINDOWS\System32\wdfmgr
.exe (file missing)
****
User 2
AAWSE VX2 found nothing.
Peper found nothing.
Logfile of HijackThis v1.99.0
Scan saved at 3:39:18 AM, on 1/15/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\PROGRA~1\STOPZI~1\sznts
vc.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL
32.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\Program Files\Synaptics\SynTP\SynT
PLpr.exe
C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Compaq\EAB\EabServr.
exe
C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\CTP
DPSRV.EXE
C:\Program Files\BearShare\BearShare.
exe
C:\Program Files\BearShare\BearShare.
exe
C:\PROGRA~1\COMMON~1\AOL\A
OLSPY~1\AO
LSP Scheduler.exe
C:\PROGRA~1\SPRINT~1.0OF\S
print\CAge
nt.exe
C:\Program Files\Compaq A3000\CPQA3000.exe
C:\Program Files\SpywareGuard\sgmain.
exe
C:\WINDOWS\System32\Packet
hSvc.exe
C:\WINDOWS\System32\cisvc.
exe
c:\program files\cox\applications\app
\CurtainsS
ysSvcNt.ex
e
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\SpywareGuard\sgbhp.e
xe
C:\WINDOWS\System32\cidaem
on.exe
C:\utilities_14Jan2005\hij
ackthis\Hi
jackThis.e
xe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) = about:blank
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page_bak =
http://www.blacksun.box.skR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,AutoConfigURL = JUGG92.COM
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3
D5FEC94A18
3} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\System
32\Userini
t.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7
695ECA0567
0} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn0
\ycomp5_3_
16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH
elper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0
B27DDD11DB
2} - C:\Program Files\SpywareGuard\dlprote
ct.dll
O2 - BHO: AuthBHO.cBHO - {A4D90779-6CB2-4752-83C2-A
2AB4D9A672
D} - C:\Program Files\Cox\Applications\app
\AuthBHO.d
ll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-0
0D0B743919
D} - (no file)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn0
\ycomp5_3_
16_0.dll
O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9
620D33362C
1} - C:\Program Files\Cox\Applications\app
\AuthBHO.d
ll
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA
\cdaEngine
0400.dll",
cdaEngineM
ain
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynT
PLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla
.exe" /autorun
O4 - HKLM\..\Run: [StopSignStatus] Rundll32.exe "C:\Program Files\Common Files\eAcceleration\Instal
ler\stopsi
nfo.dll",V
erifyStatu
s
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [P2P Networking2] C:\WINDOWS\System32\P2P Networking\P2P Networking2.exe /AUTOSTART
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.
exe /Start
O4 - HKLM\..\Run: [CTPDPSRV] C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\CTP
DPSRV.EXE
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.
exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.
exe" /pause
O4 - HKLM\..\Run: [AuthConsoleStart] C:\Program Files\Cox\Applications\app
\cox.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\
AOLSPY~1\A
OLSP Scheduler.exe"
O4 - HKLM\..\Run: [ABBYY Community Agent] C:\PROGRA~1\SPRINT~1.0OF\S
print\CAge
nt.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.
exe
O4 - Startup: Virtual Bouncer.lnk = C:\Program Files\VBouncer\VirtualBoun
cer.exe
O4 - Global Startup: Compaq A3000 Settings Utility.lnk = C:\Program Files\Compaq A3000\CPQA3000.exe
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\Precis
ionTime.ex
e
O4 - Global Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.
exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsear
ch.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar
.dll/cmsea
rch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch
.htm
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar
.dll/cmbac
klinks.htm
l
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar
.dll/cmcac
he.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar
.dll/cmsim
ilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar
.dll/cmtra
ns.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict
.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict
.htm
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-0
00103C116D
5} - C:\Program Files\Yahoo!\Common\ylogin
.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-0
00103C116D
5} - C:\Program Files\Yahoo!\Common\ylogin
.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-0
0010333D0A
D} - C:\Program Files\Yahoo!\Companion\Mod
ules\messm
od2\v4\yhe
xbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-0
0010333D0A
D} - C:\Program Files\Yahoo!\Companion\Mod
ules\messm
od2\v4\yhe
xbmes.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
0B0D0A1DE4
5} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9
A5F3A62F68
3} - file://C:\Program Files\Ebates_MoeMoneyMaker
\Sy350\Tp3
50\scri350
a.htm (file missing) (HKCU)
O9 - Extra button: Advisor - {76026873-0935-499C-B66A-9
FF5EEF45BE
A} - C:\Program Files\COMPAQ\Compaq Advisor\bin\rbaLauncher.ex
e (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O14 - IERESET.INF: START_PAGE_URL=
http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409O16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/gam...ts/y/pote_x.cabO16 - DPF: {CA034DCC-A580-4333-B52F-1
5F98C42E04
C} (Downloader Class) -
http://www.stopzilla.com/_download/...ller/dwnldr.cabO23 - Service: Compaq Advisor - NeoPlanet - C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Curtains for Windows System Service - Authentium, Inc. - c:\program files\cox\applications\app
\CurtainsS
ysSvcNt.ex
e
O23 - Service: Virtual NIC Service - America Online, Inc. - C:\WINDOWS\System32\Packet
hSvc.exe
O23 - Service: STOPzilla Local Service - International Software Systems Solutions - C:\PROGRA~1\STOPZI~1\sznts
vc.exe
O23 - Service: Windows User Mode Driver Framework - Unknown - C:\WINDOWS\System32\wdfmgr
.exe (file missing)
ED