Results 1 to 10 of 31

Thread: Problems with DealAssistant and MyWebSearch

Hybrid View

  1. #1
    Junior Member
    Join Date
    Aug 2009
    Posts
    20

    Default Problems with DealAssistant and MyWebSearch

    Hi, I have problems with DealAssistant and MyWebSearch and can't seem to get rid of them. I'm a very basic computer user, but have followed your instructions and hopefully have done it right. Could you help me with this please.


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:42:34 PM, on 2/10/2009
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.18813)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\Windows\SOUNDMAN.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
    C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\sdclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredigames.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    R3 - URLSearchHook: (no name) - {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - (no file)
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
    O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: PremiereAdvertisingPlatform - {547395D9-934A-CED6-B851-F238C86079E5} - C:\Program Files\PremiereAdvertisingPlatform\PremiereAdvertisingPlatform.dll (file missing)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [DealAssistant] C:\Users\Owner\AppData\Roaming\DealAssistant\dealassistant.exe
    O4 - HKCU\..\Run: [SfKg6wIPuSpdcduD7] C:\Users\Owner\AppData\Roaming\Microsoft\Windows\oulwsv.exe
    O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
    O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1150596.exe -Update -1150596 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; FunWebProducts; SLCC1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"http://www.box10.com/moto-x-freestyle.html"
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
    O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &Search - ?p=ZKxdm220YYAU
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O13 - Gopher Prefix:
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/The%20Enchanting%20Islands/Images/stg_drm.ocx
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/res.../wlscctrl2.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/.../GAME_UNO1.cab
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab2.cab
    O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...Uploader55.cab
    O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader2.cab
    O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} (Diagnostics ActiveX WebControl) - http://support.microsoft.com/mats/DiagWebControl.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Tropix%202%20-%20Quest%20for%20the%20Golden%20Banana/Images/armhelper.ocx
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\516\G2AWinLogon.dll (file missing)
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Findbasic Service - Unknown owner - C:\ProgramData\Findbasic\findbasic125.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\516\g2aservice.exe
    O23 - Service: Google Update Service (gupdate1ca352042073a72) (gupdate1ca352042073a72) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: iWinTrusted - iWin Inc. - C:\Program Files\iWin Games\iWinTrusted.exe
    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

    --
    End of file - 13247 bytes

  2. #2
    Emeritus Shaba's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,644

    Default

    Hi toladogold

    Please post spybot report next
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Junior Member
    Join Date
    Aug 2009
    Posts
    20

    Default

    Sorry, don't know what report you're talking about. Do you mean i should do a scan and send you the results?

  4. #4
    Emeritus Shaba's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,644

    Default

    Yes if spybot finds those
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  5. #5
    Junior Member
    Join Date
    Aug 2009
    Posts
    20

    Default

    --- Search result list ---

    --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

    2009-01-26 blindman.exe (1.0.0.8)
    2009-01-26 SDFiles.exe (1.6.1.7)
    2009-01-26 SDMain.exe (1.0.0.6)
    2009-01-26 SDShred.exe (1.0.2.5)
    2009-01-26 SDUpdate.exe (1.6.0.12)
    2009-01-26 SDWinSec.exe (1.0.0.12)
    2009-01-26 SpybotSD.exe (1.6.2.46)
    2009-03-05 TeaTimer.exe (1.6.6.32)
    2009-08-20 unins000.exe (51.49.0.0)
    2009-01-26 Update.exe (1.6.0.7)
    2009-07-28 advcheck.dll (1.6.3.17)
    2007-04-02 aports.dll (2.1.0.0)
    2008-06-14 DelZip179.dll (1.79.11.1)
    2009-01-26 SDHelper.dll (1.6.2.14)
    2008-06-19 sqlite3.dll
    2009-01-26 Tools.dll (2.1.6.10)
    2009-01-16 UninsSrv.dll (1.0.0.0)
    2009-05-19 Includes\Adware.sbi (*)
    2009-09-08 Includes\AdwareC.sbi (*)
    2009-01-22 Includes\Cookies.sbi (*)
    2009-05-19 Includes\Dialer.sbi (*)
    2009-09-08 Includes\DialerC.sbi (*)
    2009-01-22 Includes\HeavyDuty.sbi (*)
    2009-05-26 Includes\Hijackers.sbi (*)
    2009-09-08 Includes\HijackersC.sbi (*)
    2009-06-23 Includes\Keyloggers.sbi (*)
    2009-09-08 Includes\KeyloggersC.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2009-08-19 Includes\Malware.sbi (*)
    2009-09-08 Includes\MalwareC.sbi (*)
    2009-03-25 Includes\PUPS.sbi (*)
    2009-09-08 Includes\PUPSC.sbi (*)
    2009-01-22 Includes\Revision.sbi (*)
    2009-01-13 Includes\Security.sbi (*)
    2009-09-08 Includes\SecurityC.sbi (*)
    2008-06-03 Includes\Spybots.sbi (*)
    2008-06-03 Includes\SpybotsC.sbi (*)
    2009-04-07 Includes\Spyware.sbi (*)
    2009-09-08 Includes\SpywareC.sbi (*)
    2009-06-08 Includes\Tracks.uti
    2009-08-25 Includes\Trojans.sbi (*)
    2009-09-08 Includes\TrojansC.sbi (*)
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2007-12-24 Plugins\TCPIPAddress.dll



    --- System information ---
    Windows Vista (Build: 6002) Service Pack 2 (6.0.6002)
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB929729)
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
    / MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2
    / MSXML4SP2: Security update for MSXML4 SP2 (KB936181)
    / MSXML4SP2: Security update for MSXML4 SP2 (KB941833)
    / MSXML4SP2: Security update for MSXML4 SP2 (KB954430)


    --- Startup entries list ---
    Located: HK_LM:Run, Adobe Reader Speed Launcher
    command: "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    file: C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    size: 35696
    MD5: 452FA961163EF4AEE4815796A13AB2CF

    Located: HK_LM:Run, AppleSyncNotifier
    command: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    file: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    size: 177440
    MD5: 633B66014DDEDA70C21CFD327BDC214A

    Located: HK_LM:Run, iTunesHelper
    command: "C:\Program Files\iTunes\iTunesHelper.exe"
    file: C:\Program Files\iTunes\iTunesHelper.exe
    size: 305440
    MD5: D1458A77A6E15462CB96D34089549BAC

    Located: HK_LM:Run, mcagent_exe
    command: "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    file: C:\Program Files\McAfee.com\Agent\mcagent.exe
    size: 645328
    MD5: EAE3C29E6B437F970D014E59D462A66E

    Located: HK_LM:Run, QuickTime Task
    command: "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    file: C:\Program Files\QuickTime\QTTask.exe
    size: 417792
    MD5: 8CBD57D84729DEBEE1E83CB5FA3E3D7A

    Located: HK_LM:Run, SoundMan
    command: SOUNDMAN.EXE
    file: C:\Windows\SOUNDMAN.EXE
    size: 598016
    MD5: A41A73F3D1BE4350CBA9125247EFF330

    Located: HK_CU:Run, MySpaceIM
    where: .DEFAULT...
    command: C:\Program Files\MySpace\IM\MySpaceIM.exe
    file: C:\Program Files\MySpace\IM\MySpaceIM.exe
    size: 9117696
    MD5: 24FB0BE24236C791201486D04DB7C41B

    Located: HK_CU:Run, Picasa Media Detector
    where: .DEFAULT...
    command: C:\Program Files\Picasa2\PicasaMediaDetector.exe
    file: C:\Program Files\Picasa2\PicasaMediaDetector.exe
    size: 443968
    MD5: EF1ECB9DF42AF6BF7514BB5EBC5C59EC

    Located: HK_CU:Run, Sidebar
    where: S-1-5-19...
    command: %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
    file: C:\Program Files\Windows Sidebar\Sidebar.exe
    size: 1233920
    MD5: 9E35FF7F943AE0FB89192BFE058B7FD4

    Located: HK_CU:Run, WindowsWelcomeCenter
    where: S-1-5-19...
    command: rundll32.exe oobefldr.dll,ShowWelcomeCenter
    file: C:\Windows\system32\oobefldr.dll
    size: 2153472
    MD5: 16FC5B430123238E522B18E63C257AF8

    Located: HK_CU:Run, Sidebar
    where: S-1-5-20...
    command: %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
    file: C:\Program Files\Windows Sidebar\Sidebar.exe
    size: 1233920
    MD5: 9E35FF7F943AE0FB89192BFE058B7FD4

    Located: HK_CU:Run, WindowsWelcomeCenter
    where: S-1-5-20...
    command: rundll32.exe oobefldr.dll,ShowWelcomeCenter
    file: C:\Windows\system32\oobefldr.dll
    size: 2153472
    MD5: 16FC5B430123238E522B18E63C257AF8

    Located: HK_CU:Run, DealAssistant
    where: S-1-5-21-2490314987-2349913300-1285092130-1000...
    command: C:\Users\Owner\AppData\Roaming\DealAssistant\dealassistant.exe
    file: C:\Users\Owner\AppData\Roaming\DealAssistant\dealassistant.exe
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_CU:Run, EA Core
    where: S-1-5-21-2490314987-2349913300-1285092130-1000...
    command: "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
    file: C:\Program Files\Electronic Arts\EADM\Core.exe
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_CU:Run, SfKg6wIPuSpdcduD7
    where: S-1-5-21-2490314987-2349913300-1285092130-1000...
    command: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\oulwsv.exe
    file: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\oulwsv.exe
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_CU:Run, Skype
    where: S-1-5-21-2490314987-2349913300-1285092130-1000...
    command: "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    file: C:\Program Files\Skype\Phone\Skype.exe
    size: 25623336
    MD5: 9780A4EC41060F6164CC5DDDC815DB34

    Located: HK_CU:Run, SpybotSD TeaTimer
    where: S-1-5-21-2490314987-2349913300-1285092130-1000...
    command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    size: 2260480
    MD5: 390679F7A217A5E73D756276C40AE887

    Located: HK_CU:RunOnce, Shockwave Updater
    where: S-1-5-21-2490314987-2349913300-1285092130-1000...
    command: C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1150596.exe -Update -1150596 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; FunWebProducts; SLCC1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"http://www.box10.com/moto-x-freestyle.html"
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_CU:Run, MySpaceIM
    where: S-1-5-18...
    command: C:\Program Files\MySpace\IM\MySpaceIM.exe
    file: C:\Program Files\MySpace\IM\MySpaceIM.exe
    size: 9117696
    MD5: 24FB0BE24236C791201486D04DB7C41B

    Located: HK_CU:Run, Picasa Media Detector
    where: S-1-5-18...
    command: C:\Program Files\Picasa2\PicasaMediaDetector.exe
    file: C:\Program Files\Picasa2\PicasaMediaDetector.exe
    size: 443968
    MD5: EF1ECB9DF42AF6BF7514BB5EBC5C59EC

    Located: Startup (common), Microsoft Office.lnk
    where: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup...
    command: C:\Program Files\Microsoft Office\Office10\OSA.EXE
    file: C:\Program Files\Microsoft Office\Office10\OSA.EXE
    size: 83360
    MD5: 5BC65464354A9FD3BEAA28E18839734A

    Located: Startup (user), OneNote 2007 Screen Clipper and Launcher.lnk
    where: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup...
    command: C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    file: C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    size: 98696
    MD5: A6D772AA861E673636D48B6EB452ADE3

    Located: Startup (disabled), LimeWire On Startup (DISABLED)
    command: C:\PROGRA~1\LimeWire\LimeWire.exe -startup
    file: C:\PROGRA~1\LimeWire\LimeWire.exe
    size: 122880
    MD5: 7B5D624FBB163CE7ACA3BDA9290F6702

    Located: WinLogon, GoToAssist
    command: C:\Program Files\Citrix\GoToAssist\516\G2AWinLogon.dll
    file: C:\Program Files\Citrix\GoToAssist\516\G2AWinLogon.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!



    --- Browser helper object list ---
    {18DF081C-E8AD-4283-A596-FA578C2EBDC3} (AcroIEHelperStub)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name: AcroIEHelperStub
    CLSID name: Adobe PDF Link Helper
    Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\
    Long name: AcroIEHelperShim.dll
    Short name: ACROIE~2.DLL
    Date (created): 27/02/2009 12:07:26 PM
    Date (last access): 22/05/2009 9:28:38 PM
    Date (last write): 27/02/2009 12:07:26 PM
    Filesize: 75128
    Attributes: archive
    MD5: 5CF6190CD875DA6B35256FEE573E7908
    CRC32: 764BA81B
    Version: 9.1.0.163

    {22BF413B-C6D2-4d91-82A9-A0F997BA588C} (Skype add-on (mastermind))
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name: Skype add-on (mastermind)
    CLSID name: Skype add-on (mastermind)
    Path: C:\Program Files\Skype\Toolbars\Internet Explorer\
    Long name: SkypeIEPlugin.dll
    Short name: SKYPEI~1.DLL
    Date (created): 4/08/2009 3:47:42 PM
    Date (last access): 15/09/2009 8:38:18 PM
    Date (last write): 4/08/2009 3:47:42 PM
    Filesize: 1586472
    Attributes: archive
    MD5: D419F7E912A83A86B41FC1AE11AED22B
    CRC32: 4A645895
    Version: 3.3.0.3928

    {243B17DE-77C7-46BF-B94B-0B5F309A0E64} ()
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name:
    description: Microsoft Money
    classification: Open for discussion
    known filename: mnyside.dll
    info link: http://www.microsoft.com/money/default.asp
    info source: TonyKlein
    Path: C:\Program Files\Microsoft Money\System\
    Long name: mnyside.dll
    Short name:
    Date (created): 17/07/2002 11:00:00 AM
    Date (last access): 16/06/2007 3:05:38 PM
    Date (last write): 17/07/2002 11:00:00 AM
    Filesize: 163906
    Attributes: archive
    MD5: BEED9AE28E5696C7C2EEA11075E258CE
    CRC32: D7C7E8B5
    Version: 11.0.0.716

    {27B4851A-3207-45A2-B947-BE8AFE6163AB} (McAfee Phishing Filter)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name: McAfee Phishing Filter
    CLSID name: McAfee Phishing Filter
    Path: c:\PROGRA~1\mcafee\msk\
    Long name: mskapbho.dll
    Short name:
    Date (created): 22/09/2009 6:10:46 PM
    Date (last access): 8/07/2009 2:48:48 PM
    Date (last write): 8/07/2009 2:48:48 PM
    Filesize: 246800
    Attributes: archive
    MD5: 7B54980334E33FC209B5C56D80BF5A60
    CRC32: DDC1BCFD
    Version: 10.15.101.0

    {3049C3E9-B461-4BC5-8870-4C09146192CA} (RealPlayer Download and Record Plugin for Internet Explorer)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: RealPlayer Download and Record Plugin for Internet Explorer
    Path: C:\Program Files\Real\RealPlayer\
    Long name: rpbrowserrecordplugin.dll
    Short name: RPBROW~1.DLL
    Date (created): 24/12/2008 8:43:18 PM
    Date (last access): 24/12/2008 8:43:18 PM
    Date (last write): 24/12/2008 8:43:18 PM
    Filesize: 308856
    Attributes: archive
    MD5: 33440A3EF90AF7ED74EE55CA634A9CFA
    CRC32: B00E58A9
    Version: 1.0.1.57

    {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Spybot-S&D IE Protection
    description: Spybot-S&D IE Browser plugin
    classification: Legitimate
    known filename: SDhelper.dll
    info link: http://spybot.eon.net.au/
    info source: Patrick M. Kolla
    Path: C:\PROGRA~1\SPYBOT~1\
    Long name: SDHelper.dll
    Short name:
    Date (created): 20/08/2009 1:50:56 PM
    Date (last access): 20/08/2009 1:50:56 PM
    Date (last write): 26/01/2009 3:31:02 PM
    Filesize: 1879896
    Attributes: archive
    MD5: 022C2F6DCCDFA0AD73024D254E62AFAC
    CRC32: 5BA24007
    Version: 1.6.2.14

    {547395D9-934A-CED6-B851-F238C86079E5} (PremiereAdvertisingPlatform)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name: PremiereAdvertisingPlatform
    CLSID name: PremiereAdvertisingPlatform
    Path: C:\Program Files\PremiereAdvertisingPlatform\
    Long name: PremiereAdvertisingPlatform.dll

    {5C255C8A-E604-49b4-9D64-90988571CECB} ()
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name:

    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: SSVHelper Class
    Path: C:\Program Files\Java\jre1.6.0_03\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 19/10/2007 10:58:54 AM
    Date (last access): 24/09/2007 11:31:44 PM
    Date (last write): 25/09/2007 1:11:34 AM
    Filesize: 501136
    Attributes: archive
    MD5: D787E3123FAD2BD58AB45B9A5C360ACD
    CRC32: DDC625C2
    Version: 6.0.30.5

    {7DB2D5A0-7241-4E79-B68D-6309F01C5231} (scriptproxy)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name: scriptproxy
    CLSID name: scriptproxy
    Path: c:\PROGRA~1\mcafee\VIRUSS~1\
    Long name: scriptsn.dll
    Short name:
    Date (created): 20/03/2009 8:46:44 PM
    Date (last access): 8/07/2009 1:43:46 PM
    Date (last write): 8/07/2009 1:43:46 PM
    Filesize: 62784
    Attributes: archive
    MD5: E7FD30A856E6BD3EAB92B9D6C76E6B1B
    CRC32: EA160385
    Version: 14.0.0.433

    {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Windows Live Sign-in Helper
    Path: C:\Program Files\Common Files\Microsoft Shared\Windows Live\
    Long name: WindowsLiveLogin.dll
    Short name: WINDOW~1.DLL
    Date (created): 22/01/2009 3:41:30 PM
    Date (last access): 16/09/2009 5:01:04 PM
    Date (last write): 22/01/2009 3:41:30 PM
    Filesize: 408448
    Attributes: archive
    MD5: B7899C3E21B299D7A3C0DA96CAE340BD
    CRC32: 288935F8
    Version: 5.0.818.5

    {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Google Toolbar Helper
    description: Google toolbar
    classification: Open for discussion
    known filename: googletoolbar.dll<br>googletoolbar*.dll<br>(* = number)<br>googletoolbar_en_*.**-big.dll<br>Googletoolbar_en_*.*.**-deleon.dll
    info link: http://toolbar.google.com/
    info source: TonyKlein
    Path: c:\program files\google\
    Long name: GoogleToolbar1.dll
    Short name: GOOGLE~1.DLL
    Date (created): 16/06/2009 12:46:04 AM
    Date (last access): 16/06/2009 12:46:04 AM
    Date (last write): 16/06/2009 12:46:04 AM
    Filesize: 2403392
    Attributes: readonly archive
    MD5: 6319F2D4708DBCAE37CFA03DA10782C0
    CRC32: D51D8296
    Version: 4.0.1601.4978

    {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Google Toolbar Notifier BHO
    Path: C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\
    Long name: swg.dll
    Short name:
    Date (created): 24/03/2009 10:52:22 AM
    Date (last access): 24/03/2009 10:52:22 AM
    Date (last write): 24/03/2009 10:52:22 AM
    Filesize: 668656
    Attributes: archive
    MD5: D1585B06DED161E13B905DC4FFBF7F12
    CRC32: 88D5BAA5
    Version: 5.1.1309.3572

    {B164E929-A1B6-4A06-B104-2CD0E90A88FF} (McAfee SiteAdvisor BHO)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: McAfee SiteAdvisor BHO
    Path: c:\PROGRA~1\mcafee\SITEAD~1\
    Long name: McIEPlg.dll
    Short name:
    Date (created): 20/03/2009 8:49:36 PM
    Date (last access): 13/02/2009 11:44:56 AM
    Date (last write): 13/02/2009 11:44:56 AM
    Filesize: 150032
    Attributes: archive
    MD5: 4428FA80C5AC5D0C8F764207E651B65E
    CRC32: 2025B4F6
    Version: 1.0.2.158

    {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} ()
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name:
    description: Microsoft Money
    classification: Open for discussion
    known filename: mnyviewer.dll
    info link: http://www.microsoft.com/money/default.asp
    info source: TonyKlein



    --- ActiveX list ---
    {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control)
    DPF name:
    CLSID name: SpinTop DRM Control
    Installer:
    Codebase: file:///C:/Program%20Files/The%20Enchanting%20Islands/Images/stg_drm.ocx
    Path: C:\Program Files\Women's Murder Club - Twice in a Blue Moon\Images\
    Long name: stg_drm.ocx
    Short name:
    Date (created): 10/09/2009 5:53:44 AM
    Date (last access): 3/10/2009 8:58:12 PM
    Date (last write): 10/09/2009 5:53:44 AM
    Filesize: 181584
    Attributes: archive
    MD5: C3068473076E4FC48E45EF16706C75B9
    CRC32: 888A0DC0
    Version: 1.0.0.8

    {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class)
    DPF name:
    CLSID name: Checkers Class
    Installer:
    Codebase: http://messenger.zone.msn.com/binary...r.cab56986.cab
    Path: C:\Windows\Downloaded Program Files\
    Long name: msgrchkr.dll
    Short name:
    Date (created): 28/02/2007 2:21:04 PM
    Date (last access): 28/02/2007 2:21:04 PM
    Date (last write): 28/02/2007 2:21:04 PM
    Filesize: 131472
    Attributes: archive
    MD5: 1E5CFDF9AEBDD84305A4C8154277A269
    CRC32: 73C871D0
    Version: 9.5.7087.1

    {233C1507-6A77-46A4-9443-F871F945D258} (Shockwave ActiveX Control)
    DPF name:
    CLSID name: Shockwave ActiveX Control
    Installer: C:\Windows\Downloaded Program Files\swdir.inf
    Codebase: http://download.macromedia.com/pub/s...irector/sw.cab
    description:
    classification: Legitimate
    known filename: SwDir.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Windows\system32\Adobe\Director\
    Long name: SwDir.dll
    Short name:
    Date (created): 29/04/2009 6:29:00 PM
    Date (last access): 16/06/2009 12:45:14 AM
    Date (last write): 29/04/2009 6:29:00 PM
    Filesize: 202168
    Attributes: archive
    MD5: 1B3A14C57997CC19974BA9F2BE5BD543
    CRC32: D43621A2
    Version: 11.5.0.596

    {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control)
    DPF name:
    CLSID name: Windows Live OneCare safety scanner control
    Installer: C:\Windows\Downloaded Program Files\wlscCtrl2.inf
    Codebase: http://cdn.scan.onecare.live.com/res.../wlscctrl2.cab
    Path: %ProgramFiles%\Windows Live Safety Center\
    Long name: wlscCtrl2.dll

    {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class)
    DPF name:
    CLSID name: UnoCtrl Class
    Installer: C:\Windows\Downloaded Program Files\GAME_UNO1.INF
    Codebase: http://messenger.zone.msn.com/EN-AU/.../GAME_UNO1.cab
    description:
    classification: Legitimate
    known filename: unomsnger.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Windows\Downloaded Program Files\
    Long name: GAME_UNO1.dll
    Short name: GAME_U~1.DLL
    Date (created): 28/09/2007 4:41:28 AM
    Date (last access): 28/09/2007 4:41:28 AM
    Date (last write): 28/09/2007 4:41:28 AM
    Filesize: 381960
    Attributes: archive
    MD5: 80F4A456633F78A26A3C6B16E64EFEC5
    CRC32: 7DFC41A5
    Version: 1.0.1201.1

    {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab)
    DPF name: System Requirements Lab
    CLSID name: System Requirements Lab Class
    Installer:
    Codebase: http://www.nvidia.com/content/Driver...sysreqlab2.cab
    Path: C:\Windows\Downloaded Program Files\
    Long name: sysreqlab2.dll
    Short name: SYSREQ~1.DLL
    Date (created): 29/03/2007 11:07:12 AM
    Date (last access): 29/03/2007 11:07:12 AM
    Date (last write): 29/03/2007 11:07:12 AM
    Filesize: 206384
    Attributes: archive
    MD5: ED3B0F1BA60554B9D2E5AE1B02AD9306
    CRC32: E2F1D780
    Version: 2.30.0.0

    {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class)
    DPF name:
    CLSID name: ContactExtractor Class
    Installer:
    Codebase: http://www.facebook.com/controls/contactx.dll
    Path: C:\Windows\Downloaded Program Files\
    Long name: contactx.dll
    Short name:
    Date (created): 7/12/2008 1:51:50 PM
    Date (last access): 7/12/2008 1:51:50 PM
    Date (last write): 7/12/2008 1:51:42 PM
    Filesize: 160488
    Attributes: archive
    MD5: 238A6FFC7EE17330C1C5859C7827EE2D
    CRC32: 79676D36
    Version: 1.0.0.1

    {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control)
    DPF name:
    CLSID name: Facebook Photo Uploader 5 Control
    Installer: C:\Windows\Downloaded Program Files\PhotoUploader55.inf
    Codebase: http://upload.facebook.com/controls/...Uploader55.cab
    Path: C:\Windows\Downloaded Program Files\
    Long name: PhotoUploader55.ocx
    Short name: PHOTOU~2.OCX
    Date (created): 29/07/2009 9:21:24 PM
    Date (last access): 29/07/2009 9:21:24 PM
    Date (last write): 29/07/2009 9:21:24 PM
    Filesize: 3540488
    Attributes: archive
    MD5: B36353934BB8B0E7CC8557AC5143EF41
    CRC32: 3AC3C312
    Version: 5.5.8.1

    {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_03
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    description: Sun Java
    classification: Legitimate
    known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
    info link:
    info source: Patrick M. Kolla
    Path: C:\Program Files\Java\jre1.6.0_03\bin\
    Long name: npjpi160_03.dll
    Short name: NPJPI1~1.DLL
    Date (created): 24/09/2007 11:31:44 PM
    Date (last access): 24/09/2007 11:31:44 PM
    Date (last write): 25/09/2007 1:11:34 AM
    Filesize: 132496
    Attributes: archive
    MD5: D6A4682A6FF41832A3F1A7AB9AE08199
    CRC32: 9080B537
    Version: 6.0.30.5

    {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ()
    DPF name:
    CLSID name:
    Installer: C:\Windows\Downloaded Program Files\erma.inf
    Codebase: http://fpdownload.macromedia.com/get.../ultrashim.cab
    description:
    classification: Open for discussion
    known filename:
    info link:
    info source: Safer Networking Ltd.

    {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control)
    DPF name:
    CLSID name: MySpace Uploader Control
    Installer: C:\Windows\Downloaded Program Files\MySpaceUploader2.inf
    Codebase: http://lads.myspace.com/upload/MySpaceUploader2.cab
    Path: C:\Windows\Downloaded Program Files\
    Long name: MySpaceUploader2.ocx
    Short name: MYSPAC~1.OCX
    Date (created): 14/05/2009 6:00:56 PM
    Date (last access): 14/05/2009 6:00:56 PM
    Date (last write): 14/05/2009 6:00:56 PM
    Filesize: 3525696
    Attributes: archive
    MD5: DCE8E7C3E671006011C042F9A1F96DEC
    CRC32: 9F1551E2
    Version: 5.7.16.0

    {A3256902-51FA-45A0-8A97-FC1143C169D9} (Diagnostics ActiveX WebControl)
    DPF name:
    CLSID name: Diagnostics ActiveX WebControl
    Installer: C:\Windows\Downloaded Program Files\DiagWebControl.inf
    Codebase: http://support.microsoft.com/mats/DiagWebControl.cab
    Path: C:\Windows\Downloaded Program Files\
    Long name: DiagWAPI.dll
    Short name:
    Date (created): 25/08/2009 11:43:10 AM
    Date (last access): 25/08/2009 11:43:10 AM
    Date (last write): 25/08/2009 11:43:10 AM
    Filesize: 128240
    Attributes: archive
    MD5: 807C94C248848A2C5A6CF67F75CF04B4
    CRC32: 461CE22F
    Version: 1.5.0.15

    {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer)
    DPF name:
    CLSID name: MSN Games - Installer
    Installer:
    Codebase: http://messenger.zone.msn.com/binary...o.cab56649.cab
    description:
    classification: Legitimate
    known filename: ZIntro.ocx
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Windows\Downloaded Program Files\
    Long name: ZIntro.ocx
    Short name:
    Date (created): 19/02/2007 11:26:28 AM
    Date (last access): 19/02/2007 11:26:28 AM
    Date (last write): 19/02/2007 11:26:28 AM
    Filesize: 159128
    Attributes: archive
    MD5: E681AC948003CCA59C6C00D3F5EC3D4B
    CRC32: C8723760
    Version: 9.5.6649.1

    {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class)
    DPF name:
    CLSID name: MessengerStatsClient Class
    Installer:
    Codebase: http://messenger.zone.msn.com/binary...t.cab56907.cab
    description:
    classification: Legitimate
    known filename: MessengerStatsPAClient.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Windows\Downloaded Program Files\
    Long name: MessengerStatsPAClient.dll
    Short name: MESSEN~1.DLL
    Date (created): 22/02/2007 10:41:12 PM
    Date (last access): 22/02/2007 10:41:12 PM
    Date (last write): 22/02/2007 10:41:12 PM
    Filesize: 304544
    Attributes: archive
    MD5: 8945CCA5FC4F25168E8B6F401EFAF51F
    CRC32: 0F12FD23
    Version: 9.5.6907.1

    {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_01
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: npjpi160_01.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre1.6.0_03\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 19/10/2007 10:58:54 AM
    Date (last access): 24/09/2007 11:31:44 PM
    Date (last write): 25/09/2007 1:11:34 AM
    Filesize: 501136
    Attributes: archive
    MD5: D787E3123FAD2BD58AB45B9A5C360ACD
    CRC32: DDC625C2
    Version: 6.0.30.5

    {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_02
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: npjpi160_02.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre1.6.0_03\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 19/10/2007 10:58:54 AM
    Date (last access): 24/09/2007 11:31:44 PM
    Date (last write): 25/09/2007 1:11:34 AM
    Filesize: 501136
    Attributes: archive
    MD5: D787E3123FAD2BD58AB45B9A5C360ACD
    CRC32: DDC625C2
    Version: 6.0.30.5

    {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_03
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    Path: C:\Program Files\Java\jre1.6.0_03\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 19/10/2007 10:58:54 AM
    Date (last access): 24/09/2007 11:31:44 PM
    Date (last write): 25/09/2007 1:11:34 AM
    Filesize: 501136
    Attributes: archive
    MD5: D787E3123FAD2BD58AB45B9A5C360ACD
    CRC32: DDC625C2
    Version: 6.0.30.5

    {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_03
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: npjpi150_06.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre1.6.0_03\bin\
    Long name: npjpi160_03.dll
    Short name: NPJPI1~1.DLL
    Date (created): 24/09/2007 11:31:44 PM
    Date (last access): 24/09/2007 11:31:44 PM
    Date (last write): 25/09/2007 1:11:34 AM
    Filesize: 132496
    Attributes: archive
    MD5: D6A4682A6FF41832A3F1A7AB9AE08199
    CRC32: 9080B537
    Version: 6.0.30.5

    {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control)
    DPF name:
    CLSID name: ArmHelper Control
    Installer:
    Codebase: file:///C:/Program%20Files/Tropix%202%20-%20Quest%20for%20the%20Golden%20Banana/Images/armhelper.ocx
    Path:
    Long name: ./Images/armhelper.ocx

    {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
    DPF name:
    CLSID name: Shockwave Flash Object
    Installer: C:\Windows\Downloaded Program Files\CONFLICT.55\swflash.inf
    Codebase: http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    description: Macromedia Shockwave Flash Player
    classification: Legitimate
    known filename:
    info link:
    info source: Patrick M. Kolla
    Path: C:\Windows\system32\Macromed\Flash\
    Long name: Flash10c.ocx
    Short name:
    Date (created): 18/07/2009 11:12:12 AM
    Date (last access): 20/08/2009 10:08:50 AM
    Date (last write): 18/07/2009 11:12:12 AM
    Filesize: 3979680
    Attributes: readonly archive
    MD5: 43C6ACDFB92A18C3E516E6BD5F1ACD51
    CRC32: D6F40D46
    Version: 10.0.32.18

    {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class)
    DPF name:
    CLSID name: Minesweeper Flags Class
    Installer:
    Codebase: http://messenger.zone.msn.com/binary...r.cab56986.cab
    description:
    classification: Legitimate
    known filename: MineSweeper.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Windows\Downloaded Program Files\
    Long name: MineSweeper.dll
    Short name: MINESW~1.DLL
    Date (created): 28/02/2007 2:21:04 PM
    Date (last access): 28/02/2007 2:21:04 PM
    Date (last write): 28/02/2007 2:21:04 PM
    Filesize: 130472
    Attributes: archive
    MD5: E661E91B5929632665683222D509D271
    CRC32: 63A9B975
    Version: 9.5.6986.1



    --- Process list ---
    PID: 3764 (1940) C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    size: 186904
    MD5: 9E41266C68C11D7101A2D18CD1F7553E
    PID: 1636 (1048) C:\Windows\system32\Dwm.exe
    size: 81920
    MD5: 01DD1004181FD46ECDC3628228EB269D
    PID: 4032 (3840) C:\Windows\Explorer.EXE
    size: 2926592
    MD5: D07D4C3038F3578FFCE1C0237F2A1253
    PID: 1964 ( 832) c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    size: 645328
    MD5: EAE3C29E6B437F970D014E59D462A66E
    PID: 2704 (1100) C:\Windows\system32\taskeng.exe
    size: 169984
    MD5: E5BBFC283D6F5D69B41E464676361020
    PID: 3104 (4032) C:\Windows\SOUNDMAN.EXE
    size: 598016
    MD5: A41A73F3D1BE4350CBA9125247EFF330
    PID: 3752 (4032) C:\Program Files\iTunes\iTunesHelper.exe
    size: 305440
    MD5: D1458A77A6E15462CB96D34089549BAC
    PID: 1536 (4032) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    size: 2260480
    MD5: 390679F7A217A5E73D756276C40AE887
    PID: 3728 (4032) C:\Program Files\Skype\Phone\Skype.exe
    size: 25623336
    MD5: 9780A4EC41060F6164CC5DDDC815DB34
    PID: 4104 (4032) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    size: 98696
    MD5: A6D772AA861E673636D48B6EB452ADE3
    PID: 5280 (3728) C:\Program Files\Skype\Plugin Manager\skypePM.exe
    size: 77360
    MD5: A3996F435192AAEE6CB5D7E45E3A51FF
    PID: 3604 (1100) C:\Windows\system32\taskeng.exe
    size: 169984
    MD5: E5BBFC283D6F5D69B41E464676361020
    PID: 5436 (1100) C:\Windows\system32\wuauclt.exe
    size: 53472
    MD5: 62BB79160F86CD962F312C68C6239BFD
    PID: 5900 (3604) C:\Windows\system32\sdclt.exe
    size: 1169408
    MD5: 0427038DD4FC9C653AEE8B0E0C36323A
    PID: 1992 ( 832) C:\PROGRA~1\INCRED~1\bin\IMApp.exe
    size: 143408
    MD5: 82DE7916EAB1FE749BCBC2C997BB7F88
    PID: 2228 (4032) C:\Program Files\Internet Explorer\iexplore.exe
    size: 638216
    MD5: C33BD196A0301F9B23D9A003D30ED8B0
    PID: 6128 (2228) C:\Program Files\Internet Explorer\iexplore.exe
    size: 638216
    MD5: C33BD196A0301F9B23D9A003D30ED8B0
    PID: 6104 ( 832) C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
    size: 257440
    MD5: AE619F242F2CE340F3B33DDEAA88248D
    PID: 5176 ( 832) C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
    size: 238888
    MD5: AE82B3B6A33DC23019B604DA5920D726
    PID: 764 (4032) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    size: 5365592
    MD5: 0477C2F9171599CA5BC3307FDFBA8D89
    PID: 0 ( 0) [System Process]
    PID: 4 ( 0) System
    PID: 452 ( 4) smss.exe
    size: 64000
    PID: 524 ( 512) csrss.exe
    size: 6144
    PID: 572 ( 512) wininit.exe
    size: 96768
    PID: 584 ( 564) csrss.exe
    size: 6144
    PID: 616 ( 572) services.exe
    size: 279552
    PID: 628 ( 572) lsass.exe
    size: 9728
    PID: 640 ( 572) lsm.exe
    size: 229888
    PID: 724 ( 564) winlogon.exe
    size: 314368
    PID: 832 ( 616) svchost.exe
    size: 21504
    PID: 892 ( 616) svchost.exe
    size: 21504
    PID: 932 ( 616) svchost.exe
    size: 21504
    PID: 1020 ( 616) svchost.exe
    size: 21504
    PID: 1048 ( 616) svchost.exe
    size: 21504
    PID: 1060 ( 616) LVPrcSrv.exe
    PID: 1100 ( 616) svchost.exe
    size: 21504
    PID: 1204 (1020) audiodg.exe
    size: 88576
    PID: 1236 ( 616) svchost.exe
    size: 21504
    PID: 1288 ( 616) SLsvc.exe
    size: 3408896
    PID: 1392 ( 616) svchost.exe
    size: 21504
    PID: 1524 ( 616) svchost.exe
    size: 21504
    PID: 1744 ( 616) spoolsv.exe
    size: 127488
    PID: 1772 ( 616) svchost.exe
    size: 21504
    PID: 2032 ( 616) alg.exe
    size: 59392
    PID: 292 ( 616) AppleMobileDeviceService.exe
    PID: 340 ( 616) mDNSResponder.exe
    PID: 360 ( 616) svchost.exe
    size: 21504
    PID: 484 ( 616) findbasic125.exe
    PID: 1520 ( 616) iWinTrusted.exe
    PID: 1412 ( 12) GoogleUpdate.exe
    PID: 1940 ( 616) LVComSer.exe
    PID: 1168 ( 616) McSACore.exe
    PID: 1232 ( 616) McProxy.exe
    PID: 372 (1168) rundll32.exe
    size: 44544
    PID: 1972 ( 616) Mcshield.exe
    PID: 2160 ( 616) MpfSrv.exe
    PID: 2212 ( 616) msdtc.exe
    size: 105984
    PID: 2268 ( 616) msksrver.exe
    PID: 2356 ( 616) svchost.exe
    size: 21504
    PID: 2412 ( 616) svchost.exe
    size: 21504
    PID: 2484 ( 616) svchost.exe
    size: 21504
    PID: 2556 ( 616) TosBtSrv.exe
    PID: 2616 ( 616) UI0Detect.exe
    size: 35840
    PID: 2712 ( 616) svchost.exe
    size: 21504
    PID: 2772 ( 616) SearchIndexer.exe
    size: 441344
    PID: 2864 ( 616) SDWinSec.exe
    size: 1153368
    MD5: 794D4B48DFB6E999537C7C3947863463
    PID: 3784 (1100) taskeng.exe
    size: 169984
    PID: 2612 ( 616) mcmscsvc.exe
    PID: 1340 ( 484) findbasic.exe
    PID: 3856 ( 616) mcsysmon.exe
    PID: 4516 ( 616) iPodService.exe
    PID: 4688 ( 616) McNASvc.exe
    PID: 6048 ( 616) svchost.exe
    size: 21504
    PID: 240 (4804) mcbuilder.exe
    size: 275968


    --- Browser start & search pages list ---
    Spybot - Search & Destroy browser pages report, 7/10/2009 9:19:03 PM

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\Windows\system32\blank.htm
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
    http://www.google.com
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
    about:blank
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
    http://mystart.incredigames.com/
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\Windows\System32\blank.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
    http://go.microsoft.com/fwlink/?LinkId=54896
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar
    about:blank
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
    http://go.microsoft.com/fwlink/?LinkId=69157
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
    http://go.microsoft.com/fwlink/?LinkId=69157
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
    http://go.microsoft.com/fwlink/?LinkId=54896


    --- Winsock Layered Service Provider list ---
    Protocol 0: MSAFD Tcpip [TCP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 1: MSAFD Tcpip [UDP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 2: MSAFD Tcpip [RAW/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 3: MSAFD Tcpip [TCP/IPv6]
    GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IPv6 protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 4: MSAFD Tcpip [UDP/IPv6]
    GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IPv6 protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 5: MSAFD Tcpip [RAW/IPv6]
    GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IPv6 protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 6: RSVP TCPv6 Service Provider
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 7: RSVP TCP Service Provider
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 8: RSVP UDPv6 Service Provider
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 9: RSVP UDP Service Provider
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 10: MSAFD RfComm [Bluetooth]
    GUID: {9FC48064-7298-43E4-B7BD-181F2089792A}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Bluetooth
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD RfComm [Bluetooth]

    Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F0F36E5B-E2CF-490B-B78A-39ED5D75B194}] SEQPACKET 6
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F0F36E5B-E2CF-490B-B78A-39ED5D75B194}] DATAGRAM 6
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{818D500F-D943-4257-95A5-CFD5C3AE9A9C}] SEQPACKET 8
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{818D500F-D943-4257-95A5-CFD5C3AE9A9C}] DATAGRAM 8
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{842C9C07-BF36-4E9E-B0FE-BB8E50363DEA}] SEQPACKET 4
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{842C9C07-BF36-4E9E-B0FE-BB8E50363DEA}] DATAGRAM 4
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6A52C23F-71F7-4E2E-98F5-C1D094991C61}] SEQPACKET 0
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 18: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6A52C23F-71F7-4E2E-98F5-C1D094991C61}] DATAGRAM 0
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 19: MSAFD NetBIOS [\Device\NetBT_Tcpip_{84515D64-3732-42BE-8168-D4B7565F6FCF}] SEQPACKET 2
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 20: MSAFD NetBIOS [\Device\NetBT_Tcpip_{84515D64-3732-42BE-8168-D4B7565F6FCF}] DATAGRAM 2
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 21: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{9301A1AA-AFB7-488A-A016-617ACB5804D9}] SEQPACKET 11
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 22: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{9301A1AA-AFB7-488A-A016-617ACB5804D9}] DATAGRAM 11
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 23: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{EE4FFEE7-7514-475C-99A5-3F696951B124}] SEQPACKET 10
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 24: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{EE4FFEE7-7514-475C-99A5-3F696951B124}] DATAGRAM 10
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 25: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{F0F36E5B-E2CF-490B-B78A-39ED5D75B194}] SEQPACKET 7
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 26: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{F0F36E5B-E2CF-490B-B78A-39ED5D75B194}] DATAGRAM 7
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 27: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{818D500F-D943-4257-95A5-CFD5C3AE9A9C}] SEQPACKET 9
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 28: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{818D500F-D943-4257-95A5-CFD5C3AE9A9C}] DATAGRAM 9
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 29: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{842C9C07-BF36-4E9E-B0FE-BB8E50363DEA}] SEQPACKET 5
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 30: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{842C9C07-BF36-4E9E-B0FE-BB8E50363DEA}] DATAGRAM 5
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 31: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{6A52C23F-71F7-4E2E-98F5-C1D094991C61}] SEQPACKET 1
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 32: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{6A52C23F-71F7-4E2E-98F5-C1D094991C61}] DATAGRAM 1
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 33: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{84515D64-3732-42BE-8168-D4B7565F6FCF}] SEQPACKET 3
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 34: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{84515D64-3732-42BE-8168-D4B7565F6FCF}] DATAGRAM 3
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Namespace Provider 0: Network Location Awareness Legacy (NLAv1) Namespace
    GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
    Filename:
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: NLA-Namespace

    Namespace Provider 1: E-mail Naming Shim Provider
    GUID: {964ACBA2-B2BC-40EB-8C6A-A6DB40161CAE}
    Filename:

    Namespace Provider 2: PNRP Cloud Namespace Provider
    GUID: {03FE89CE-766D-4976-B9C1-BB9BC42C7B4D}
    Filename:

    Namespace Provider 3: PNRP Name Namespace Provider
    GUID: {03FE89CD-766D-4976-B9C1-BB9BC42C7B4D}
    Filename:

    Namespace Provider 4: mdnsNSP
    GUID: {B600E6E9-553B-4A19-8696-335E5C896153}
    Filename: C:\Program Files\Bonjour\mdnsNSP.dll
    Description: Apple Rendezvous protocol
    DB filename: %ProgramFiles%\Rendezvous\bin\mdnsNSP.dll
    DB protocol: mdnsNSP

    Namespace Provider 5: Bluetooth Namespace
    GUID: {06AA63E0-7D60-41FF-AFB2-3EE6D2D9392D}
    Filename: %SystemRoot%\system32\wshbth.dll
    Description: Bluetooth
    DB filename: %SystemRoot%\system32\wshbth.dll
    DB protocol: Bluetooth-Namespace

    Namespace Provider 6: Tcpip
    GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
    Filename:
    Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: TCP/IP

    Namespace Provider 7: NTDS
    GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
    Filename: %SystemRoot%\System32\winrnr.dll
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\winrnr.dll
    DB protocol: NTDS

  6. #6
    Emeritus Shaba's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,644

    Default

    So looks like it didn't find anything.

    • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
    • Double click on RSIT.exe to run RSIT.
    • Click Continue at the disclaimer screen.
    • Once it has finished, two logs will open. Please post the contents of both log.txt (<< will be maximized) and info.txt (<< will be minimized)
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •