Page 4 of 11 FirstFirst 12345678 ... LastLast
Results 31 to 40 of 102

Thread: can't remove virtumonde & smitfraud-c.toolbar 888

  1. #31
    Senior Member
    Join Date
    Nov 2006
    Posts
    104

    Default

    Hi

    Have just run Spybot again - Virtumonde has gone but Smitfraud is still there

  2. #32
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Ok, please post then spybot report here.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #33
    Senior Member
    Join Date
    Nov 2006
    Posts
    104

    Default

    Hi

    Ok but how do I get report from Spybot?

  4. #34
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    You can get a Spybot report, if you switch Spybot into advanced mode (Mode -> Advance Mode), then click on "Tools", and then "View Report". There confirm that the checkboxes are checked and click on the green button with the arrow labeled "View report" . Export the report to a text file and copy/paste it to your next post.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  5. #35
    Senior Member
    Join Date
    Nov 2006
    Posts
    104

    Default

    Hi

    Have just run Spybot again and Smitfraud is no longer showing, looks like it's sorted.

    Could you tell me how to reset the restore point so that I don't get these back again and also is there anything else I can add to the protection that I have already got to stop this from happening again. My daughter is always using Windows Messenger and Bebo.com (is this likely to be where these came from)?

    Can I also ask whether this has cleaned the entire computer or just my log-in?

    thanks

  6. #36
    Senior Member
    Join Date
    Nov 2006
    Posts
    104

    Default

    Sorry but I didn't tell what I already have

    AVG anti-virus, ZoneAlarm firewall, SpywareBlaster, AdAware SE Personal and of course Spybot (all free programs)

  7. #37
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    "Can I also ask whether this has cleaned the entire computer or just my log-in?"

    Well you can post a HijackThis log from also other user accounts if unsure.

    I'll give you system restore flush instructions etc. after your decision.

    "Sorry but I didn't tell what I already have

    AVG anti-virus, ZoneAlarm firewall, SpywareBlaster, AdAware SE Personal and of course Spybot (all free programs)"

    I can see from HjT log that you have AVG anti-virus, ZoneAlarm firewall and Spybot
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  8. #38
    Senior Member
    Join Date
    Nov 2006
    Posts
    104

    Default

    Hi

    Have just run Spybot again having logged back in (after running HJT on daughter's account) and Smitfraud is back.

    Here is the Spybot report

    --- Search result list ---
    Smitfraud-C.Toolbar888: Settings (Registry key, nothing done)
    HKEY_USERS\S-1-5-21-2726807402-1454960028-1985393105-1007\Software\Microsoft\aldd


    --- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

    2005-05-31 blindman.exe (1.0.0.1)
    2005-05-31 SpybotSD.exe (1.4.0.3)
    2005-05-31 TeaTimer.exe (1.4.0.2)
    2006-12-06 unins000.exe (51.41.0.0)
    2005-05-31 Update.exe (1.4.0.0)
    2007-04-18 advcheck.dll (1.5.1.0)
    2005-05-31 aports.dll (2.1.0.0)
    2005-05-31 borlndmm.dll (7.0.4.453)
    2005-05-31 delphimm.dll (7.0.4.453)
    2005-05-31 SDHelper.dll (1.4.0.0)
    2007-01-02 Tools.dll (2.0.1.0)
    2005-05-31 UnzDll.dll (1.73.1.1)
    2005-05-31 ZipDll.dll (1.73.2.0)
    2007-05-09 Includes\Cookies.sbi (*)
    2006-12-08 Includes\Dialer.sbi (*)
    2007-05-09 Includes\DialerC.sbi (*)
    2007-04-04 Includes\Hijackers.sbi (*)
    2007-05-09 Includes\HijackersC.sbi (*)
    2006-10-27 Includes\Keyloggers.sbi (*)
    2007-05-09 Includes\KeyloggersC.sbi (*)
    2007-03-21 Includes\Malware.sbi (*)
    2007-05-09 Includes\MalwareC.sbi (*)
    2007-03-21 Includes\PUPS.sbi (*)
    2007-05-09 Includes\PUPSC.sbi (*)
    2007-05-09 Includes\Revision.sbi (*)
    2006-12-08 Includes\Security.sbi (*)
    2007-05-09 Includes\SecurityC.sbi (*)
    2007-03-21 Includes\Spybots.sbi (*)
    2007-05-09 Includes\SpybotsC.sbi (*)
    2005-02-17 Includes\Tracks.uti
    2007-05-02 Includes\Trojans.sbi (*)
    2007-05-09 Includes\TrojansC.sbi (*)



    --- System information ---
    Windows XP (Build: 2600) Service Pack 2
    / .NETFramework / 1.0: Microsoft .NET Framework 1.0 Hotfix (KB887998)
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB886903)
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
    / Media Center 2005 / SP4: Update Rollup 2 for Windows XP Media Center Edition 2005
    / MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2
    / Step By Step Interactive Training / SP2: Security Update for Step By Step Interactive Training (KB898458)
    / Step By Step Interactive Training / SP2: Security Update for Step By Step Interactive Training (KB923723)
    / Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
    / Windows / SP1: Microsoft National Language Support Downlevel APIs
    / Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
    / Windows Media Player 10: Update for Windows Media Player 10 (KB913800)
    / Windows Media Player 10: Security Update for Windows Media Player 10 (KB917734)
    / Windows Media Player 10: Update for Windows Media Player 10 (KB926251)
    / Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398)
    / Windows XP: Security Update for Windows XP (KB923689)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB928090)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB929969)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB931768)
    / Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
    / Windows XP / SP3: Windows XP Hotfix - KB873333
    / Windows XP / SP3: Windows XP Hotfix - KB873339
    / Windows XP / SP3: Windows XP Hotfix - KB883667
    / Windows XP / SP3: Windows XP Hotfix - KB885250
    / Windows XP / SP3: Windows XP Hotfix - KB885835
    / Windows XP / SP3: Windows XP Hotfix - KB885836
    / Windows XP / SP3: Windows XP Hotfix - KB885855
    / Windows XP / SP3: Windows XP Hotfix - KB886185
    / Windows XP / SP3: Windows XP Hotfix - KB887472
    / Windows XP / SP3: Microsoft .NET Framework 1.0 Hotfix (KB887998)
    / Windows XP / SP3: Windows XP Hotfix - KB888113
    / Windows XP / SP3: Windows XP Hotfix - KB888239
    / Windows XP / SP3: Windows XP Hotfix - KB888302
    / Windows XP / SP3: Hotfix for Windows XP (KB888795)
    / Windows XP / SP3: Windows XP Hotfix - KB890546
    / Windows XP / SP3: Windows XP Hotfix - KB890859
    / Windows XP / SP3: Windows XP Hotfix - KB891220
    / Windows XP / SP3: Hotfix for Windows XP (KB891593)
    / Windows XP / SP3: Windows XP Hotfix - KB891781
    / Windows XP / SP3: Windows XP Hotfix - KB892559
    / Windows XP / SP3: Security Update for Windows XP (KB893066)
    / Windows XP / SP3: Security Update for Windows XP (KB893756)
    / Windows XP / SP3: Windows Installer 3.1 (KB893803)
    / Windows XP / SP3: Update for Windows XP (KB894391)
    / Windows XP / SP3: Hotfix for Windows XP (KB896256)
    / Windows XP / SP3: Security Update for Windows XP (KB896358)
    / Windows XP / SP3: Security Update for Windows XP (KB896422)
    / Windows XP / SP3: Security Update for Windows XP (KB896423)
    / Windows XP / SP3: Security Update for Windows XP (KB896424)
    / Windows XP / SP3: Security Update for Windows XP (KB896428)
    / Windows XP / SP3: Update for Windows XP (KB896727)
    / Windows XP / SP3: Update for Windows XP (KB898461)
    / Windows XP / SP3: Hotfix for Windows XP (KB899337)
    / Windows XP / SP3: Hotfix for Windows XP (KB899510)
    / Windows XP / SP3: Security Update for Windows XP (KB899587)
    / Windows XP / SP3: Security Update for Windows XP (KB899591)
    / Windows XP / SP3: Update for Windows XP (KB900485)
    / Windows XP / SP3: Security Update for Windows XP (KB900725)
    / Windows XP / SP3: Security Update for Windows XP (KB901017)
    / Windows XP / SP3: Security Update for Windows XP (KB901190)
    / Windows XP / SP3: Security Update for Windows XP (KB901214)
    / Windows XP / SP3: Security Update for Windows XP (KB902400)
    / Windows XP / SP3: Hotfix for Windows XP (KB902841)
    / Windows XP / SP3: Security Update for Windows XP (KB903235)
    / Windows XP / SP3: Security Update for Windows XP (KB904706)
    / Windows XP / SP3: Update for Windows XP (KB904942)
    / Windows XP / SP3: Security Update for Windows XP (KB905414)
    / Windows XP / SP3: Security Update for Windows XP (KB905749)
    / Windows XP / SP3: Security Update for Windows XP (KB908519)
    / Windows XP / SP3: Update for Windows XP (KB908531)
    / Windows XP / SP3: Hotfix for Windows XP (KB909095)
    / Windows XP / SP3: Update for Windows XP (KB910437)
    / Windows XP / SP3: Hotfix for Windows XP (KB910728)
    / Windows XP / SP3: Update for Windows XP (KB911164)
    / Windows XP / SP3: Update for Windows XP (KB911280)
    / Windows XP / SP3: Security Update for Windows XP (KB911562)
    / Windows XP / SP3: Security Update for Windows XP (KB911567)
    / Windows XP / SP3: Security Update for Windows XP (KB911927)
    / Windows XP / SP3: Hotfix for Windows XP (KB912436)
    / Windows XP / SP3: Security Update for Windows XP (KB912919)
    / Windows XP / SP3: Update for Windows XP (KB912945)
    / Windows XP / SP3: Security Update for Windows XP (KB913446)
    / Windows XP / SP3: Security Update for Windows XP (KB913580)
    / Windows XP / SP3: Security Update for Windows XP (KB914388)
    / Windows XP / SP3: Security Update for Windows XP (KB914389)
    / Windows XP / SP3: Hotfix for Windows XP (KB914440)
    / Windows XP / SP3: Hotfix for Windows XP (KB915865)
    / Windows XP / SP3: Update for Windows XP (KB916595)
    / Windows XP / SP3: Security Update for Windows XP (KB917344)
    / Windows XP / SP3: Security Update for Windows XP (KB917422)
    / Windows XP / SP3: Security Update for Windows XP (KB917953)
    / Windows XP / SP3: Hotfix for Windows XP (KB918005)
    / Windows XP / SP3: Security Update for Windows XP (KB918118)
    / Windows XP / SP3: Security Update for Windows XP (KB918439)
    / Windows XP / SP3: Security Update for Windows XP (KB919007)
    / Windows XP / SP3: Security Update for Windows XP (KB920213)
    / Windows XP / SP3: Security Update for Windows XP (KB920214)
    / Windows XP / SP3: Security Update for Windows XP (KB920670)
    / Windows XP / SP3: Security Update for Windows XP (KB920683)
    / Windows XP / SP3: Security Update for Windows XP (KB920685)
    / Windows XP / SP3: Update for Windows XP (KB920872)
    / Windows XP / SP3: Security Update for Windows XP (KB921398)
    / Windows XP / SP3: Update for Windows XP (KB922582)
    / Windows XP / SP3: Security Update for Windows XP (KB922616)
    / Windows XP / SP3: Security Update for Windows XP (KB922760)
    / Windows XP / SP3: Security Update for Windows XP (KB922819)
    / Windows XP / SP3: Security Update for Windows XP (KB923191)
    / Windows XP / SP3: Security Update for Windows XP (KB923414)
    / Windows XP / SP3: Security Update for Windows XP (KB923694)
    / Windows XP / SP3: Security Update for Windows XP (KB923980)
    / Windows XP / SP3: Security Update for Windows XP (KB924191)
    / Windows XP / SP3: Security Update for Windows XP (KB924270)
    / Windows XP / SP3: Security Update for Windows XP (KB924496)
    / Windows XP / SP3: Security Update for Windows XP (KB924667)
    / Windows XP / SP3: Security Update for Windows XP (KB925486)
    / Windows XP / SP3: Security Update for Windows XP (KB925902)
    / Windows XP / SP3: Hotfix for Windows XP (KB926239)
    / Windows XP / SP3: Security Update for Windows XP (KB926255)
    / Windows XP / SP3: Security Update for Windows XP (KB926436)
    / Windows XP / SP3: Security Update for Windows XP (KB927779)
    / Windows XP / SP3: Security Update for Windows XP (KB927802)
    / Windows XP / SP3: Security Update for Windows XP (KB928255)
    / Windows XP / SP3: Security Update for Windows XP (KB928843)
    / Windows XP / SP3: Update for Windows XP (KB929338)
    / Windows XP / SP3: Security Update for Windows XP (KB930178)
    / Windows XP / SP3: Update for Windows XP (KB930916)
    / Windows XP / SP3: Security Update for Windows XP (KB931261)
    / Windows XP / SP3: Security Update for Windows XP (KB931784)
    / Windows XP / SP3: Update for Windows XP (KB931836)
    / Windows XP / SP3: Security Update for Windows XP (KB932168)

  9. #39
    Senior Member
    Join Date
    Nov 2006
    Posts
    104

    Default

    --- Startup entries list ---
    Located: HK_LM:Run, AVG7_CC
    command: C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    file: C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    size: 416256
    MD5: 2200c98c049de1a7638ea0edba1c8882

    Located: HK_LM:Run, Cpqset
    command: C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
    file: C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
    size: 40960
    MD5: 99f6a49a51d6045152f935eef0be235f

    Located: HK_LM:Run, ehTray
    command: C:\WINDOWS\ehome\ehtray.exe
    file: C:\WINDOWS\ehome\ehtray.exe
    size: 64512
    MD5: 7a21e06385e748e9cb0252f1bbc493f1

    Located: HK_LM:Run, EPSON Stylus D88 Series
    command: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABE.EXE /P23 "EPSON Stylus D88 Series" /O6 "USB001" /M "Stylus D88"
    file: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABE.EXE
    size: 98304
    MD5: 2db5d295cc797561f01af10750af219a

    Located: HK_LM:Run, High Definition Audio Property Page Shortcut
    command: CHDAudPropShortcut.exe
    file: C:\WINDOWS\system32\CHDAudPropShortcut.exe
    size: 61952
    MD5: 8eac49bf89c0fe814ec4e7f404211839

    Located: HK_LM:Run, HP Software Update
    command: C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    file: C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    size: 49152
    MD5: 821f73b833c4daebc33c1a9a4b16bb5a

    Located: HK_LM:Run, hpWirelessAssistant
    command: C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    file: C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    size: 458752
    MD5: 1e4037f987986b200eb8421a1ceeee68

    Located: HK_LM:Run, MsmqIntCert
    command: regsvr32 /s mqrt.dll
    file:

    Located: HK_LM:Run, NvCplDaemon
    command: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    file: C:\WINDOWS\system32\RUNDLL32.EXE
    size: 33280
    MD5: da285490bbd8a1d0ce6623577d5ba1ff

    Located: HK_LM:Run, NvMediaCenter
    command: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    file: C:\WINDOWS\system32\RUNDLL32.EXE
    size: 33280
    MD5: da285490bbd8a1d0ce6623577d5ba1ff

    Located: HK_LM:Run, nwiz
    command: nwiz.exe /installquiet /nodetect
    file: C:\WINDOWS\system32\nwiz.exe
    size: 1617920
    MD5: 762e035fdc5a477ae258af375ad22e61

    Located: HK_LM:Run, QlbCtrl
    command: %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    file:

    Located: HK_LM:Run, QPService
    command: "C:\Program Files\HP\QuickPlay\QPService.exe"
    file: C:\Program Files\HP\QuickPlay\QPService.exe
    size: 102400
    MD5: cd7a1d584fc809b82d6a391bbdb42a44

    Located: HK_LM:Run, RecGuard
    command: C:\Windows\SMINST\RecGuard.exe
    file: C:\Windows\SMINST\RecGuard.exe
    size: 1187840
    MD5: c764f15f0ae8a02df1523cb24f355b22

    Located: HK_LM:Run, SunJavaUpdateSched
    command: "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    file: C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    size: 83608
    MD5: 9c1c80bbf8e6044980890e2d2d91091c

    Located: HK_LM:Run, SynTPEnh
    command: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    file: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    size: 761946
    MD5: 69775adc944c2f37d3fb3b04e8a7eb7b

    Located: HK_LM:Run, ZoneAlarm Client
    command: "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    file: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    size: 919280
    MD5: 3e1731c55f77d150791d4c7e87ad4e5c

    Located: HK_CU:Run, ctfmon.exe
    command: C:\WINDOWS\system32\ctfmon.exe
    file: C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 24232996a38c0b0cf151c2140ae29fc8

    Located: HK_CU:Run, swg
    command: C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    file: C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    size: 171448
    MD5: 0fa44ea8b03aba3e1d240b5a333d8e6a

    Located: HK_CU:Run, WMPNSCFG
    command: C:\Program Files\Windows Media Player\WMPNSCFG.exe
    file: C:\Program Files\Windows Media Player\WMPNSCFG.exe
    size: 204288
    MD5: 7eaed08ccca4ddde61a388c82598cfa9

    Located: Startup (common), Adobe Reader Speed Launch.lnk
    command: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    file: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    size: 29696
    MD5: 43362b96870ce8649f4f2ec893da93f0

    Located: Startup (common), HP Photosmart Premier Fast Start.lnk
    command: C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    file: C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    size: 73728
    MD5: b2ddff1f7ff31e8103dc221772353417

    Located: System.ini, crypt32chain
    command: crypt32.dll
    file: crypt32.dll

    Located: System.ini, cryptnet
    command: cryptnet.dll
    file: cryptnet.dll

    Located: System.ini, cscdll
    command: cscdll.dll
    file: cscdll.dll

    Located: System.ini, ScCertProp
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, Schedule
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, sclgntfy
    command: sclgntfy.dll
    file: sclgntfy.dll

    Located: System.ini, SensLogn
    command: WlNotify.dll
    file: WlNotify.dll

    Located: System.ini, termsrv
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, wlballoon
    command: wlnotify.dll
    file: wlnotify.dll

  10. #40
    Senior Member
    Join Date
    Nov 2006
    Posts
    104

    Default

    --- Browser helper object list ---
    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
    BHO name:
    CLSID name: AcroIEHlprObj Class
    description: Adobe Acrobat reader
    classification: Legitimate
    known filename: AcroIEhelper.ocx<br>AcroIEhelper.dll
    info link: http://www.adobe.com/products/acrobat/readstep2.html
    info source: TonyKlein
    Path: C:\Program Files\Adobe\Acrobat 7.0\ActiveX\
    Long name: AcroIEHelper.dll
    Short name: ACROIE~1.DLL
    Date (created): 23/09/2005 20:12:08
    Date (last access): 13/05/2007 11:12:22
    Date (last write): 23/09/2005 20:12:08
    Filesize: 63136
    Attributes: archive
    MD5: B61D5D651ECC6055C29BF826CA7B1141
    CRC32: FEF15799
    Version: 7.0.5.172

    {53707962-6F74-2D53-2644-206D7942484F} ()
    BHO name:
    CLSID name:
    description: Spybot-S&D IE Browser plugin
    classification: Legitimate
    known filename: SDhelper.dll
    info link: http://spybot.eon.net.au/
    info source: Patrick M. Kolla
    Path: C:\PROGRA~1\SPYBOT~1\
    Long name: SDHelper.dll
    Short name:
    Date (created): 06/12/2006 11:13:06
    Date (last access): 13/05/2007 11:12:22
    Date (last write): 31/05/2005 02:04:00
    Filesize: 853672
    Attributes: archive
    MD5: 250D787A5712D7768DDC133B3E477759
    CRC32: D4589A41
    Version: 1.4.0.0

    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
    BHO name:
    CLSID name: SSVHelper Class
    Path: C:\Program Files\Java\jre1.6.0_01\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 16/04/2007 15:53:18
    Date (last access): 13/05/2007 11:28:00
    Date (last write): 14/03/2007 03:43:40
    Filesize: 501400
    Attributes: archive
    MD5: 70FD57D6EDBED8D80C1995257C99D27E
    CRC32: 3CE654AC
    Version: 6.0.10.6

    {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
    BHO name:
    CLSID name: Windows Live Sign-in Helper
    Path: C:\Program Files\Common Files\Microsoft Shared\Windows Live\
    Long name: WindowsLiveLogin.dll
    Short name: WINDOW~1.DLL
    Date (created): 31/08/2006 21:33:06
    Date (last access): 13/05/2007 11:12:22
    Date (last write): 31/08/2006 21:33:06
    Filesize: 322368
    Attributes: archive
    MD5: E43F7CFDEE2B00A22C96C168147B20D3
    CRC32: 2AEACC43
    Version: 4.100.313.1

    {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
    BHO name:
    CLSID name: Google Toolbar Helper
    description: Google toolbar
    classification: Open for discussion
    known filename: googletoolbar.dll<br>googletoolbar*.dll<br>(* = number)<br>googletoolbar_en_*.**-big.dll<br>Googletoolbar_en_*.*.**-deleon.dll
    info link: http://toolbar.google.com/
    info source: TonyKlein
    Path: c:\program files\google\
    Long name: GoogleToolbar3.dll
    Short name: GOOGLE~3.DLL
    Date (created): 27/01/2007 18:46:32
    Date (last access): 13/05/2007 11:12:22
    Date (last write): 20/01/2007 00:55:32
    Filesize: 2403392
    Attributes: readonly archive
    MD5: 6319F2D4708DBCAE37CFA03DA10782C0
    CRC32: D51D8296
    Version: 4.0.1601.4978

    {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
    BHO name:
    CLSID name: EpsonToolBandKicker Class
    Path: C:\Program Files\EPSON\EPSON Web-To-Page\
    Long name: EPSON Web-To-Page.dll
    Short name: EPSONW~1.DLL
    Date (created): 30/11/2006 16:14:38
    Date (last access): 13/05/2007 11:12:22
    Date (last write): 22/02/2005 14:50:34
    Filesize: 368640
    Attributes: archive
    MD5: 01319CF4030B3740BA8261E7024ACAD1
    CRC32: D484DB79
    Version: 1.1.0.0



    --- ActiveX list ---
    {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class)
    DPF name:
    CLSID name: Checkers Class
    Installer:
    Codebase: http://messenger.zone.msn.com/binary...r.cab31267.cab
    description:
    classification: Legitimate
    known filename: msgrchkr.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: msgrchkr.dll
    Short name:
    Date (created): 29/05/2003 16:00:18
    Date (last access): 13/05/2007 11:16:44
    Date (last write): 29/05/2003 16:00:18
    Filesize: 77408
    Attributes: archive
    MD5: 42D567DF86B9B7AC4A89664C9651B68B
    CRC32: 47FF3D19
    Version: 7.1.9502.1

    {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object)
    DPF name:
    CLSID name: CKAVWebScan Object
    Installer: C:\WINDOWS\Downloaded Program Files\kavwebscan.inf
    Codebase: http://www.kaspersky.com/kos/english...an_unicode.cab
    description:
    classification: Legitimate
    known filename:
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\
    Long name: kavwebscan.dll
    Short name: KAVWEB~1.DLL
    Date (created): 21/02/2007 17:49:08
    Date (last access): 13/05/2007 11:28:00
    Date (last write): 21/02/2007 17:49:08
    Filesize: 946176
    Attributes: archive
    MD5: 5011129171D8DB17D519270B9C13DB1C
    CRC32: 0837FD01
    Version: 5.0.93.0

    {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class)
    DPF name:
    CLSID name: Checkers Class
    Installer:
    Codebase: http://messenger.zone.msn.com/binary...r.cab56986.cab
    Path: C:\WINDOWS\Downloaded Program Files\CONFLICT.1\
    Long name: msgrchkr.dll
    Short name:
    Date (created): 28/02/2007 15:21:04
    Date (last access): 13/05/2007 11:28:00
    Date (last write): 28/02/2007 15:21:04
    Filesize: 131472
    Attributes: archive
    MD5: 1E5CFDF9AEBDD84305A4C8154277A269
    CRC32: 73C871D0
    Version: 9.5.7087.1

    {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class)
    DPF name:
    CLSID name: Minesweeper Flags Class
    Installer:
    Codebase: http://messenger.zone.msn.com/binary...r.cab31267.cab
    description:
    classification: Legitimate
    known filename: minesweeper.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: minesweeper.dll
    Short name: MINESW~1.DLL
    Date (created): 29/05/2003 16:00:22
    Date (last access): 13/05/2007 11:16:44
    Date (last write): 29/05/2003 16:00:22
    Filesize: 84064
    Attributes: archive
    MD5: F951FD0EA383DF2D49CA0359E4A86968
    CRC32: 50A69718
    Version: 7.1.9502.1

    {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class)
    DPF name:
    CLSID name: UnoCtrl Class
    Installer: C:\WINDOWS\Downloaded Program Files\GAME_UNO1.INF
    Codebase: http://messenger.zone.msn.com/EN-GB/.../GAME_UNO1.cab
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: GAME_UNO1.dll
    Short name: GAME_U~1.DLL
    Date (created): 23/11/2006 00:22:42
    Date (last access): 13/05/2007 11:16:44
    Date (last write): 23/11/2006 00:22:42
    Filesize: 372736
    Attributes: archive
    MD5: 491C8F47C0DCFBC1B1329B9B368AA78F
    CRC32: 5BFD37C9
    Version: 1.0.1123.1

    {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class)
    DPF name:
    CLSID name: WScanCtl Class
    Installer: C:\WINDOWS\Downloaded Program Files\webscan.inf
    Codebase: http://www.ca.com/gb/securityadvisor...fo/webscan.cab
    description:
    classification: Legitimate
    known filename: webscan.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: webscan.dll
    Short name:
    Date (created): 20/11/2006 12:02:34
    Date (last access): 13/05/2007 11:16:44
    Date (last write): 20/11/2006 12:02:34
    Filesize: 180282
    Attributes: archive
    MD5: 76EA3ABECE61FBA3C07F61E42BB0CA48
    CRC32: AECD0E4D
    Version: 1.1.0.1049

    {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_01
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    description: Sun Java
    classification: Legitimate
    known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
    info link:
    info source: Patrick M. Kolla
    Path: C:\Program Files\Java\jre1.6.0_01\bin\
    Long name: npjpi160_01.dll
    Short name: NPJPI1~1.DLL
    Date (created): 14/03/2007 02:04:46
    Date (last access): 13/05/2007 11:28:00
    Date (last write): 14/03/2007 03:43:42
    Filesize: 132760
    Attributes: archive
    MD5: F112FB2FD2EF66D439799E3F834DF000
    CRC32: D2B09219
    Version: 6.0.0.6

    {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class)
    DPF name:
    CLSID name: MessengerStatsClient Class
    Installer:
    Codebase: http://messenger.zone.msn.com/binary...t.cab31267.cab
    description:
    classification: Legitimate
    known filename: messengerstatsclient.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: messengerstatsclient.dll
    Short name: MESSEN~1.DLL
    Date (created): 29/05/2003 16:00:20
    Date (last access): 13/05/2007 11:16:44
    Date (last write): 29/05/2003 16:00:20
    Filesize: 160864
    Attributes: archive
    MD5: B069B555A00AA026F657AA4FD13AE154
    CRC32: 89BB01E1
    Version: 7.1.9502.1

    {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class)
    DPF name:
    CLSID name: ActiveScan Installer Class
    Installer: C:\WINDOWS\Downloaded Program Files\asinst.inf
    Codebase: http://acs.pandasoftware.com/actives...ree/asinst.cab
    description:
    classification: Legitimate
    known filename: ASINST.DLL
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: asinst.dll
    Short name:
    Date (created): 24/08/2006 08:28:54
    Date (last access): 13/05/2007 11:16:42
    Date (last write): 24/08/2006 08:28:54
    Filesize: 141424
    Attributes: archive
    MD5: CB0EBD772D7D003BD11A999FF515A89A
    CRC32: 3CFE74C1
    Version: 58.6.0.0

    {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class)
    DPF name:
    CLSID name: MessengerStatsClient Class
    Installer:
    Codebase: http://messenger.zone.msn.com/binary...t.cab56907.cab
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: MessengerStatsPAClient.dll
    Short name: MESSEN~2.DLL
    Date (created): 23/02/2007 00:41:12
    Date (last access): 13/05/2007 11:16:44
    Date (last write): 23/02/2007 00:41:12
    Filesize: 304544
    Attributes: archive
    MD5: 8945CCA5FC4F25168E8B6F401EFAF51F
    CRC32: 0F12FD23
    Version: 9.5.6907.1

    {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
    DPF name: Java Runtime Environment 1.5.0
    CLSID name: Java Plug-in 1.5.0_06
    Installer:
    Codebase: http://java.sun.com/update/1.5.0/jin...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: npjpi150_06.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre1.5.0_06\bin\
    Long name: NPJPI150_06.dll
    Short name: NPJPI1~1.DLL
    Date (created): 11/11/2005 05:22:10
    Date (last access): 13/05/2007 11:24:34
    Date (last write): 11/11/2005 05:22:10
    Filesize: 69746
    Attributes: archive
    MD5: D2CF6BB5E9020E6707B62575F8083954
    CRC32: 7F39DC54
    Version: 5.0.60.5

    {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_01
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    Path: C:\Program Files\Java\jre1.6.0_01\bin\
    Long name: npjpi160_01.dll
    Short name: NPJPI1~1.DLL
    Date (created): 14/03/2007 02:04:46
    Date (last access): 13/05/2007 11:28:00
    Date (last write): 14/03/2007 03:43:42
    Filesize: 132760
    Attributes: archive
    MD5: F112FB2FD2EF66D439799E3F834DF000
    CRC32: D2B09219
    Version: 6.0.0.6

    {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_01
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: npjpi150_06.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre1.6.0_01\bin\
    Long name: npjpi160_01.dll
    Short name: NPJPI1~1.DLL
    Date (created): 14/03/2007 02:04:46
    Date (last access): 13/05/2007 11:28:00
    Date (last write): 14/03/2007 03:43:42
    Filesize: 132760
    Attributes: archive
    MD5: F112FB2FD2EF66D439799E3F834DF000
    CRC32: D2B09219
    Version: 6.0.0.6

    {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
    DPF name:
    CLSID name: Shockwave Flash Object
    Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf
    Codebase: http://fpdownload.macromedia.com/get...nt/swflash.cab
    description: Macromedia Shockwave Flash Player
    classification: Legitimate
    known filename:
    info link:
    info source: Patrick M. Kolla
    Path: C:\WINDOWS\system32\Macromed\Flash\
    Long name: Flash9b.ocx
    Short name:
    Date (created): 09/11/2006 15:46:28
    Date (last access): 13/05/2007 11:28:00
    Date (last write): 09/11/2006 15:46:28
    Filesize: 2262648
    Attributes: readonly archive
    MD5: F3B3EE66CA76C94510555ABE9D00A353
    CRC32: A51F3CB4
    Version: 9.0.28.0

    {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object)
    DPF name:
    CLSID name: PopCapLoader Object
    Installer: C:\WINDOWS\Downloaded Program Files\popcaploader.inf
    Codebase: http://games.ntlworld.com/online/onl...ploader_v5.cab
    description:
    classification: Legitimate
    known filename: POPCAPLOADER.DLL
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: popcaploader.dll
    Short name: POPCAP~1.DLL
    Date (created): 19/12/2003 18:02:06
    Date (last access): 13/05/2007 11:16:44
    Date (last write): 19/12/2003 18:02:06
    Filesize: 126976
    Attributes: archive
    MD5: 3FDDB5EE807DD371405B305ABDAE3529
    CRC32: F4B06292
    Version: 1.0.0.5

    {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class)
    DPF name:
    CLSID name: Solitaire Showdown Class
    Installer:
    Codebase: http://messenger.zone.msn.com/binary...n.cab31267.cab
    description:
    classification: Legitimate
    known filename: solitaireshowdown.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: solitaireshowdown.dll
    Short name: SOLITA~1.DLL
    Date (created): 29/05/2003 16:00:20
    Date (last access): 13/05/2007 11:16:44
    Date (last write): 29/05/2003 16:00:20
    Filesize: 86112
    Attributes: archive
    MD5: 6E0E81210B17C225AD8DBB86F0C41E32
    CRC32: 1C944476
    Version: 7.1.9502.1

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •