Page 1 of 3 123 LastLast
Results 1 to 10 of 27

Thread: Smitfraud.c removal

  1. #1
    Junior Member
    Join Date
    Sep 2007
    Posts
    24

    Default Smitfraud.c removal

    Hello Everybody, I followed the directions to the T. Here are my results....

    So far I ran the online Kaspersky scan and ran SB in safe mode and removed all files except the smitfraud one didn't remove. here are the LOGS!


    HJT Log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:39:53 PM, on 9/15/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\Program Files\Softex\OmniPass\Omniserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\Program Files\Softex\OmniPass\OPXPApp.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\windows\system\hpsysdrv.exe
    C:\WINDOWS\system32\ps2.exe
    C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
    C:\Program Files\AIM6\aim6.exe
    C:\Program Files\Palm\Hotsync.exe
    C:\Program Files\Java\jre1.5.0_04\bin\jucheck.exe
    C:\Program Files\AIM6\aolsoftware.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    c:\program files\aim6\anotify.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us8.hpwis.com/
    O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
    O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - Startup: Palm Registration.lnk = C:\Program Files\Palm\register.exe
    O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?Link...04&clcid=0x409
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\hpdj.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    --
    End of file - 4803 bytes

    kaspersky:

    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Saturday, September 15, 2007 12:53:29 AM
    Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.93.1
    Kaspersky Anti-Virus database last update: 15/09/2007
    Kaspersky Anti-Virus database records: 418828
    -------------------------------------------------------------------------------

    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - My Computer:
    A:\
    C:\
    D:\
    E:\
    F:\

    Scan Statistics:
    Total number of scanned objects: 98148
    Number of viruses found: 5
    Number of infected objects: 11
    Number of suspicious objects: 0
    Duration of the scan process: 02:45:01

    Infected Object Name / Virus Name / Last Action
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\akctmbsa.star\cert8.db Object is locked skipped
    C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\akctmbsa.star\formhistory.dat Object is locked skipped
    C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\akctmbsa.star\history.dat Object is locked skipped
    C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\akctmbsa.star\key3.db Object is locked skipped
    C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\akctmbsa.star\parent.lock Object is locked skipped
    C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\akctmbsa.star\search.sqlite Object is locked skipped
    C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\akctmbsa.star\urlclassifier2.sqlite Object is locked skipped
    C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Application Data\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Application Data\AOL OCP\AIM\Storage\data\sl33pingb00ty21\localStorage\common.cls Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\akctmbsa.star\Cache\_CACHE_001_ Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\akctmbsa.star\Cache\_CACHE_002_ Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\akctmbsa.star\Cache\_CACHE_003_ Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\akctmbsa.star\Cache\_CACHE_MAP_ Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012007091420070915\index.dat Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
    C:\hp\bin\KillWind.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped
    C:\RECYCLER\S-1-5-21-150501968-833719775-691271504-1003\Dc100.exe Infected: not-a-virus:AdWare.Win32.180Solutions.as skipped
    C:\RECYCLER\S-1-5-21-150501968-833719775-691271504-1003\Dc115.exe Infected: not-a-virus:AdWare.Win32.180Solutions.ax skipped
    C:\RECYCLER\S-1-5-21-150501968-833719775-691271504-1003\Dc155\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
    C:\RECYCLER\S-1-5-21-150501968-833719775-691271504-1003\Dc173.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
    C:\RECYCLER\S-1-5-21-150501968-833719775-691271504-1003\Dc173.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
    C:\RECYCLER\S-1-5-21-150501968-833719775-691271504-1003\Dc173.exe RarSFX: infected - 2 skipped
    C:\RECYCLER\S-1-5-21-150501968-833719775-691271504-1003\Dc99.exe/data0018/data0003 Infected: not-a-virus:AdWare.Win32.HotBar.bi skipped
    C:\RECYCLER\S-1-5-21-150501968-833719775-691271504-1003\Dc99.exe/data0018/data0004 Infected: not-a-virus:AdWare.Win32.HotBar.bi skipped
    C:\RECYCLER\S-1-5-21-150501968-833719775-691271504-1003\Dc99.exe/data0018 Infected: not-a-virus:AdWare.Win32.HotBar.bi skipped
    C:\RECYCLER\S-1-5-21-150501968-833719775-691271504-1003\Dc99.exe NSIS: infected - 3 skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\System Volume Information\_restore{F20DC6C2-5212-4F33-8959-AB7D05D4CDB6}\RP796\change.log Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    C:\WINDOWS\Sti_Trace.log Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\default Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\software Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\system Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    C:\WINDOWS\wiadebug.log Object is locked skipped
    C:\WINDOWS\wiaservc.log Object is locked skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    Scan process completed.

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi mrtrojanap7

    Please post spybot report
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Junior Member
    Join Date
    Sep 2007
    Posts
    24

    Default

    Quote Originally Posted by Shaba View Post
    Hi mrtrojanap7

    Please post spybot report
    Shaba, thank you for responding! I didn't save the whole report to a file...and I found the Logs for the scans. Which files do you need to see? on the day that I posted there are 8 files that are "checks" and one that is "fixes" please let me know what you want! making an assumption, I'll post here the file that was the largest in size:


    --- Report generated: 2007-09-15 20:26 ---

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\75tz.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\adulthell.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bin.wordsx.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\cc20foreva.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crl.thawte.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\datingforlove.org\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\dl.ad-ware.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\e-finder.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ewizard.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\fast-look.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\fuck-fuck.org\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ga31.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\greg-tut.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\letgohome.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\love-catalog.net\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\makechoice.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\meetyourfriend.biz\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\msnprotection.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\new.8ad.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\rf104.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\s13.remove.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\s2.kav.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\solongas.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\super-spider.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\t34rulit.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\terra.hcworld.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\toprefsys.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tracking.allposters.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\u45.cx\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\u46.cx\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\u47.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\u48.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\v-224.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\veryeasysearch.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\visitfriend.net\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webpidor.biz\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\www.6o9.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\www.niger.ru\*!=W=4

    BurstMedia: Tracking cookie (Firefox: default) (Cookie, nothing done)


    BurstMedia: Tracking cookie (Firefox: default) (Cookie, nothing done)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, nothing done)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, nothing done)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, nothing done)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, nothing done)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, nothing done)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, nothing done)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, nothing done)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, nothing done)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, nothing done)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, nothing done)


    DoubleClick: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Winsoftware: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Winsoftware: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Winsoftware: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Winsoftware: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Winsoftware: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    ErrorProtector: Tracking cookie (Firefox: star) (Cookie, nothing done)


    ErrorProtector: Tracking cookie (Firefox: star) (Cookie, nothing done)


    ErrorSafe: Tracking cookie (Firefox: star) (Cookie, nothing done)


    ErrorSafe: Tracking cookie (Firefox: star) (Cookie, nothing done)


    FastClick: Tracking cookie (Firefox: star) (Cookie, nothing done)


    FastClick: Tracking cookie (Firefox: star) (Cookie, nothing done)


    FastClick: Tracking cookie (Firefox: star) (Cookie, nothing done)


    FastClick: Tracking cookie (Firefox: star) (Cookie, nothing done)


    FastClick: Tracking cookie (Firefox: star) (Cookie, nothing done)


    FastClick: Tracking cookie (Firefox: star) (Cookie, nothing done)


    FastClick: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    MediaPlex: Tracking cookie (Firefox: star) (Cookie, nothing done)


    MediaPlex: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Statcounter: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Statcounter: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Statcounter: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Statcounter: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Statcounter: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Statcounter: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Statcounter: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Tradedoubler: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Zedo: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Zedo: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Zedo: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Zedo: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Zedo: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Zedo: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitsLink: Tracking cookie (Firefox: star) (Cookie, nothing done)


    CoreMetrics: Tracking cookie (Firefox: star) (Cookie, nothing done)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, nothing done)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, nothing done)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, nothing done)


    WebTrends live: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Winsoftware: Tracking cookie (Firefox: star) (Cookie, nothing done)


    ErrorProtector: Tracking cookie (Firefox: star) (Cookie, nothing done)


    ErrorProtector: Tracking cookie (Firefox: star) (Cookie, nothing done)



    --- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

    2005-05-31 blindman.exe (1.0.0.1)
    2005-05-31 SpybotSD.exe (1.4.0.3)
    2005-05-31 TeaTimer.exe (1.4.0.2)
    2005-11-03 unins000.exe (51.41.0.0)
    2005-05-31 Update.exe (1.4.0.0)
    2007-05-23 advcheck.dll (1.5.3.0)
    2005-05-31 aports.dll (2.1.0.0)
    2005-05-31 borlndmm.dll (7.0.4.453)
    2005-05-31 delphimm.dll (7.0.4.453)
    2007-07-31 Tools.dll (2.1.2.0)
    2005-05-31 UnzDll.dll (1.73.1.1)
    2005-05-31 ZipDll.dll (1.73.2.0)
    2007-09-12 Includes\Cookies.sbi (*)
    2007-07-25 Includes\Dialer.sbi (*)
    2007-09-12 Includes\DialerC.sbi (*)
    2007-08-29 Includes\Hijackers.sbi (*)
    2007-09-12 Includes\HijackersC.sbi (*)
    2007-07-25 Includes\Keyloggers.sbi (*)
    2007-09-12 Includes\KeyloggersC.sbi (*)
    2007-09-12 Includes\Malware.sbi (*)
    2007-09-12 Includes\MalwareC.sbi (*)
    2007-09-05 Includes\PUPS.sbi (*)
    2007-09-12 Includes\PUPSC.sbi (*)
    2007-09-12 Includes\Revision.sbi (*)
    2007-05-30 Includes\Security.sbi (*)
    2007-09-12 Includes\SecurityC.sbi (*)
    2007-09-12 Includes\Spybots.sbi (*)
    2007-09-12 Includes\SpybotsC.sbi (*)
    2007-08-21 Includes\Tracks.uti
    2007-09-12 Includes\Trojans.sbi (*)
    2007-09-12 Includes\TrojansC.sbi (*)
    2007-06-06 Plugins\TCPIPAddress.dll

  4. #4
    Junior Member
    Join Date
    Sep 2007
    Posts
    24

    Default

    and the associated fixes file:

    --- Report generated: 2007-09-15 20:29 ---

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\75tz.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\adulthell.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bin.wordsx.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\cc20foreva.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\crl.thawte.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\datingforlove.org\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\dl.ad-ware.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\e-finder.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ewizard.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\fast-look.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\fuck-fuck.org\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ga31.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\greg-tut.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\letgohome.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\love-catalog.net\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\makechoice.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\meetyourfriend.biz\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\msnprotection.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\new.8ad.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\rf104.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\s13.remove.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\s2.kav.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\solongas.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\super-spider.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\t34rulit.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\terra.hcworld.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\toprefsys.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\tracking.allposters.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\u45.cx\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\u46.cx\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\u47.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\u48.cc\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\v-224.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\veryeasysearch.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\visitfriend.net\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webpidor.biz\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\www.6o9.com\*!=W=4

    Smitfraud-C.: User settings (Registry change, fixing failed)
    HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\www.niger.ru\*!=W=4

    BurstMedia: Tracking cookie (Firefox: default) (Cookie, fixed)


    BurstMedia: Tracking cookie (Firefox: default) (Cookie, fixed)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, fixed)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, fixed)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, fixed)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, fixed)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, fixed)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, fixed)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, fixed)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, fixed)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, fixed)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, fixed)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, fixed)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, fixed)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, fixed)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, fixed)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, fixed)


    DoubleClick: Tracking cookie (Firefox: star) (Cookie, fixed)


    Winsoftware: Tracking cookie (Firefox: star) (Cookie, fixed)


    Winsoftware: Tracking cookie (Firefox: star) (Cookie, fixed)


    Winsoftware: Tracking cookie (Firefox: star) (Cookie, fixed)


    Winsoftware: Tracking cookie (Firefox: star) (Cookie, fixed)


    Winsoftware: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitBox: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitBox: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitBox: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitBox: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitBox: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitBox: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitBox: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitBox: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitBox: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitBox: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitBox: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitBox: Tracking cookie (Firefox: star) (Cookie, fixed)


    ErrorProtector: Tracking cookie (Firefox: star) (Cookie, fixed)


    ErrorProtector: Tracking cookie (Firefox: star) (Cookie, fixed)


    ErrorSafe: Tracking cookie (Firefox: star) (Cookie, fixed)


    ErrorSafe: Tracking cookie (Firefox: star) (Cookie, fixed)


    FastClick: Tracking cookie (Firefox: star) (Cookie, fixed)


    FastClick: Tracking cookie (Firefox: star) (Cookie, fixed)


    FastClick: Tracking cookie (Firefox: star) (Cookie, fixed)


    FastClick: Tracking cookie (Firefox: star) (Cookie, fixed)


    FastClick: Tracking cookie (Firefox: star) (Cookie, fixed)


    FastClick: Tracking cookie (Firefox: star) (Cookie, fixed)


    FastClick: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitBox: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitBox: Tracking cookie (Firefox: star) (Cookie, fixed)


    MediaPlex: Tracking cookie (Firefox: star) (Cookie, fixed)


    MediaPlex: Tracking cookie (Firefox: star) (Cookie, fixed)


    Statcounter: Tracking cookie (Firefox: star) (Cookie, fixed)


    Statcounter: Tracking cookie (Firefox: star) (Cookie, fixed)


    Statcounter: Tracking cookie (Firefox: star) (Cookie, fixed)


    Statcounter: Tracking cookie (Firefox: star) (Cookie, fixed)


    Statcounter: Tracking cookie (Firefox: star) (Cookie, fixed)


    Statcounter: Tracking cookie (Firefox: star) (Cookie, fixed)


    Statcounter: Tracking cookie (Firefox: star) (Cookie, fixed)


    Tradedoubler: Tracking cookie (Firefox: star) (Cookie, fixed)


    Zedo: Tracking cookie (Firefox: star) (Cookie, fixed)


    Zedo: Tracking cookie (Firefox: star) (Cookie, fixed)


    Zedo: Tracking cookie (Firefox: star) (Cookie, fixed)


    Zedo: Tracking cookie (Firefox: star) (Cookie, fixed)


    Zedo: Tracking cookie (Firefox: star) (Cookie, fixed)


    Zedo: Tracking cookie (Firefox: star) (Cookie, fixed)


    HitsLink: Tracking cookie (Firefox: star) (Cookie, fixed)


    CoreMetrics: Tracking cookie (Firefox: star) (Cookie, fixed)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, fixed)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, fixed)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, fixed)


    WebTrends live: Tracking cookie (Firefox: star) (Cookie, fixed)


    Winsoftware: Tracking cookie (Firefox: star) (Cookie, fixed)


    ErrorProtector: Tracking cookie (Firefox: star) (Cookie, fixed)


    ErrorProtector: Tracking cookie (Firefox: star) (Cookie, fixed)



    --- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

    2005-05-31 blindman.exe (1.0.0.1)
    2005-05-31 SpybotSD.exe (1.4.0.3)
    2005-05-31 TeaTimer.exe (1.4.0.2)
    2005-11-03 unins000.exe (51.41.0.0)
    2005-05-31 Update.exe (1.4.0.0)
    2007-05-23 advcheck.dll (1.5.3.0)
    2005-05-31 aports.dll (2.1.0.0)
    2005-05-31 borlndmm.dll (7.0.4.453)
    2005-05-31 delphimm.dll (7.0.4.453)
    2007-07-31 Tools.dll (2.1.2.0)
    2005-05-31 UnzDll.dll (1.73.1.1)
    2005-05-31 ZipDll.dll (1.73.2.0)
    2007-09-12 Includes\Cookies.sbi (*)
    2007-07-25 Includes\Dialer.sbi (*)
    2007-09-12 Includes\DialerC.sbi (*)
    2007-08-29 Includes\Hijackers.sbi (*)
    2007-09-12 Includes\HijackersC.sbi (*)
    2007-07-25 Includes\Keyloggers.sbi (*)
    2007-09-12 Includes\KeyloggersC.sbi (*)
    2007-09-12 Includes\Malware.sbi (*)
    2007-09-12 Includes\MalwareC.sbi (*)
    2007-09-05 Includes\PUPS.sbi (*)
    2007-09-12 Includes\PUPSC.sbi (*)
    2007-09-12 Includes\Revision.sbi (*)
    2007-05-30 Includes\Security.sbi (*)
    2007-09-12 Includes\SecurityC.sbi (*)
    2007-09-12 Includes\Spybots.sbi (*)
    2007-09-12 Includes\SpybotsC.sbi (*)
    2007-08-21 Includes\Tracks.uti
    2007-09-12 Includes\Trojans.sbi (*)
    2007-09-12 Includes\TrojansC.sbi (*)
    2007-06-06 Plugins\TCPIPAddress.dll

  5. #5
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    First we'll need to backup registry:

    Start -> Run -> regedit -> ok. Then File -> Export. Give it a name and press Save.

    Save text below as fix.reg on Notepad (save it as all files (*.*)) on Desktop

    Windows Registry Editor Version 5.00

    [-HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]

    [HKEY_USERS\S-1-5-21-150501968-833719775-691271504-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]

    It should look like this ->

    Doubleclick fix.reg, press Yes and ok.

    (In case you are unsure how to create a reg file, take a look here with screenshots.)

    Re-scan with spybot

    Post back a fresh spybot report.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  6. #6
    Junior Member
    Join Date
    Sep 2007
    Posts
    24

    Default

    --- Search result list ---
    Advertising.com: Tracking cookie (Internet Explorer: Owner) (Cookie, nothing done)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, nothing done)


    Advertising.com: Tracking cookie (Firefox: star) (Cookie, nothing done)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, nothing done)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, nothing done)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, nothing done)


    CasaleMedia: Tracking cookie (Firefox: star) (Cookie, nothing done)


    DoubleClick: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    FastClick: Tracking cookie (Firefox: star) (Cookie, nothing done)


    FastClick: Tracking cookie (Firefox: star) (Cookie, nothing done)


    FastClick: Tracking cookie (Firefox: star) (Cookie, nothing done)


    FastClick: Tracking cookie (Firefox: star) (Cookie, nothing done)


    FastClick: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    HitBox: Tracking cookie (Firefox: star) (Cookie, nothing done)


    MediaPlex: Tracking cookie (Firefox: star) (Cookie, nothing done)


    MediaPlex: Tracking cookie (Firefox: star) (Cookie, nothing done)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, nothing done)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, nothing done)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, nothing done)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, nothing done)


    AdRevolver: Tracking cookie (Firefox: star) (Cookie, nothing done)



    --- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

    2005-05-31 blindman.exe (1.0.0.1)
    2005-05-31 SpybotSD.exe (1.4.0.3)
    2005-05-31 TeaTimer.exe (1.4.0.2)
    2005-11-03 unins000.exe (51.41.0.0)
    2005-05-31 Update.exe (1.4.0.0)
    2007-05-23 advcheck.dll (1.5.3.0)
    2005-05-31 aports.dll (2.1.0.0)
    2005-05-31 borlndmm.dll (7.0.4.453)
    2005-05-31 delphimm.dll (7.0.4.453)
    2007-07-31 Tools.dll (2.1.2.0)
    2005-05-31 UnzDll.dll (1.73.1.1)
    2005-05-31 ZipDll.dll (1.73.2.0)
    2007-09-12 Includes\Cookies.sbi (*)
    2007-07-25 Includes\Dialer.sbi (*)
    2007-09-12 Includes\DialerC.sbi (*)
    2007-08-29 Includes\Hijackers.sbi (*)
    2007-09-12 Includes\HijackersC.sbi (*)
    2007-07-25 Includes\Keyloggers.sbi (*)
    2007-09-12 Includes\KeyloggersC.sbi (*)
    2007-09-12 Includes\Malware.sbi (*)
    2007-09-12 Includes\MalwareC.sbi (*)
    2007-09-05 Includes\PUPS.sbi (*)
    2007-09-12 Includes\PUPSC.sbi (*)
    2007-09-12 Includes\Revision.sbi (*)
    2007-05-30 Includes\Security.sbi (*)
    2007-09-12 Includes\SecurityC.sbi (*)
    2007-09-12 Includes\Spybots.sbi (*)
    2007-09-12 Includes\SpybotsC.sbi (*)
    2007-08-21 Includes\Tracks.uti
    2007-09-12 Includes\Trojans.sbi (*)
    2007-09-12 Includes\TrojansC.sbi (*)
    2007-06-06 Plugins\TCPIPAddress.dll

  7. #7
    Junior Member
    Join Date
    Sep 2007
    Posts
    24

    Default

    --- System information ---
    Windows XP (Build: 2600) Service Pack 2
    / Internet Explorer 6 / SP1: Windows XP Hotfix - KB890923
    / MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2
    / MSXML4SP2: Security update for MSXML4 SP2 (KB936181)
    / Step By Step Interactive Training / SP2: Security Update for Step By Step Interactive Training (KB898458)
    / Step By Step Interactive Training / SP2: Security Update for Step By Step Interactive Training (KB923723)
    / Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
    / Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782)
    / Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683)
    / Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398)
    / Windows Media Player 9: Security Update for Windows Media Player 9 (KB917734)
    / Windows Media Player 9 / SP0: Windows Media Player 9 Hotfix [See KB885492 for more information]
    / Windows XP: Security Update for Windows XP (KB923689)
    / Windows XP / SP2: Windows XP Service Pack 2
    / Windows XP / SP3: Windows XP Hotfix - KB873333
    / Windows XP / SP3: Windows XP Hotfix - KB873339
    / Windows XP / SP3: Security Update for Windows XP (KB883939)
    / Windows XP / SP3: Windows XP Hotfix - KB885250
    / Windows XP / SP3: Windows XP Hotfix - KB885835
    / Windows XP / SP3: Windows XP Hotfix - KB885836
    / Windows XP / SP3: Windows XP Hotfix - KB886185
    / Windows XP / SP3: Windows XP Hotfix - KB887472
    / Windows XP / SP3: Windows XP Hotfix - KB887742
    / Windows XP / SP3: Windows XP Hotfix - KB888113
    / Windows XP / SP3: Windows XP Hotfix - KB888302
    / Windows XP / SP3: Security Update for Windows XP (KB890046)
    / Windows XP / SP3: Windows XP Hotfix - KB890175
    / Windows XP / SP3: Windows XP Hotfix - KB890859
    / Windows XP / SP3: Windows XP Hotfix - KB890923
    / Windows XP / SP3: Windows XP Hotfix - KB891781
    / Windows XP / SP3: Security Update for Windows XP (KB893066)
    / Windows XP / SP3: Windows XP Hotfix - KB893086
    / Windows XP / SP3: Security Update for Windows XP (KB893756)
    / Windows XP / SP3: Windows Installer 3.1 (KB893803)
    / Windows XP / SP3: Update for Windows XP (KB894391)
    / Windows XP / SP3: Security Update for Windows XP (KB896358)
    / Windows XP / SP3: Security Update for Windows XP (KB896422)
    / Windows XP / SP3: Security Update for Windows XP (KB896423)
    / Windows XP / SP3: Security Update for Windows XP (KB896424)
    / Windows XP / SP3: Security Update for Windows XP (KB896428)
    / Windows XP / SP3: Security Update for Windows XP (KB896688)
    / Windows XP / SP3: Update for Windows XP (KB896727)
    / Windows XP / SP3: Update for Windows XP (KB898461)
    / Windows XP / SP3: Security Update for Windows XP (KB899587)
    / Windows XP / SP3: Security Update for Windows XP (KB899588)
    / Windows XP / SP3: Security Update for Windows XP (KB899591)
    / Windows XP / SP3: Update for Windows XP (KB900485)
    / Windows XP / SP3: Security Update for Windows XP (KB900725)
    / Windows XP / SP3: Security Update for Windows XP (KB901017)
    / Windows XP / SP3: Security Update for Windows XP (KB901214)
    / Windows XP / SP3: Security Update for Windows XP (KB902400)
    / Windows XP / SP3: Security Update for Windows XP (KB903235)
    / Windows XP / SP3: Security Update for Windows XP (KB904706)
    / Windows XP / SP3: Security Update for Windows XP (KB905414)
    / Windows XP / SP3: Security Update for Windows XP (KB905749)
    / Windows XP / SP3: Security Update for Windows XP (KB905915)
    / Windows XP / SP3: Security Update for Windows XP (KB908519)
    / Windows XP / SP3: Update for Windows XP (KB908531)
    / Windows XP / SP3: Update for Windows XP (KB910437)
    / Windows XP / SP3: Security Update for Windows XP (KB911280)
    / Windows XP / SP3: Security Update for Windows XP (KB911562)
    / Windows XP / SP3: Security Update for Windows XP (KB911567)
    / Windows XP / SP3: Security Update for Windows XP (KB911927)
    / Windows XP / SP3: Security Update for Windows XP (KB912812)
    / Windows XP / SP3: Security Update for Windows XP (KB912919)
    / Windows XP / SP3: Security Update for Windows XP (KB913446)
    / Windows XP / SP3: Security Update for Windows XP (KB913580)
    / Windows XP / SP3: Security Update for Windows XP (KB914388)
    / Windows XP / SP3: Security Update for Windows XP (KB914389)
    / Windows XP / SP3: Security Update for Windows XP (KB916281)
    / Windows XP / SP3: Update for Windows XP (KB916595)
    / Windows XP / SP3: Security Update for Windows XP (KB917159)
    / Windows XP / SP3: Security Update for Windows XP (KB917344)
    / Windows XP / SP3: Security Update for Windows XP (KB917422)
    / Windows XP / SP3: Security Update for Windows XP (KB917953)
    / Windows XP / SP3: Security Update for Windows XP (KB918118)
    / Windows XP / SP3: Security Update for Windows XP (KB918439)
    / Windows XP / SP3: Security Update for Windows XP (KB918899)
    / Windows XP / SP3: Security Update for Windows XP (KB919007)
    / Windows XP / SP3: Security Update for Windows XP (KB920213)
    / Windows XP / SP3: Security Update for Windows XP (KB920214)
    / Windows XP / SP3: Security Update for Windows XP (KB920670)
    / Windows XP / SP3: Security Update for Windows XP (KB920683)
    / Windows XP / SP3: Security Update for Windows XP (KB920685)
    / Windows XP / SP3: Update for Windows XP (KB920872)
    / Windows XP / SP3: Security Update for Windows XP (KB921398)
    / Windows XP / SP3: Security Update for Windows XP (KB921503)
    / Windows XP / SP3: Security Update for Windows XP (KB921883)
    / Windows XP / SP3: Update for Windows XP (KB922582)
    / Windows XP / SP3: Security Update for Windows XP (KB922616)
    / Windows XP / SP3: Security Update for Windows XP (KB922760)
    / Windows XP / SP3: Security Update for Windows XP (KB922819)
    / Windows XP / SP3: Security Update for Windows XP (KB923191)
    / Windows XP / SP3: Security Update for Windows XP (KB923414)
    / Windows XP / SP3: Security Update for Windows XP (KB923694)
    / Windows XP / SP3: Security Update for Windows XP (KB923980)
    / Windows XP / SP3: Security Update for Windows XP (KB924191)
    / Windows XP / SP3: Security Update for Windows XP (KB924270)
    / Windows XP / SP3: Security Update for Windows XP (KB924496)
    / Windows XP / SP3: Security Update for Windows XP (KB924667)
    / Windows XP / SP3: Security Update for Windows XP (KB925454)
    / Windows XP / SP3: Security Update for Windows XP (KB925486)
    / Windows XP / SP3: Security Update for Windows XP (KB925902)
    / Windows XP / SP3: Hotfix for Windows XP (KB926239)
    / Windows XP / SP3: Security Update for Windows XP (KB926255)
    / Windows XP / SP3: Security Update for Windows XP (KB926436)
    / Windows XP / SP3: Security Update for Windows XP (KB927779)
    / Windows XP / SP3: Security Update for Windows XP (KB927802)
    / Windows XP / SP3: Update for Windows XP (KB927891)
    / Windows XP / SP3: Security Update for Windows XP (KB928090)
    / Windows XP / SP3: Security Update for Windows XP (KB928255)
    / Windows XP / SP3: Security Update for Windows XP (KB928843)
    / Windows XP / SP3: Security Update for Windows XP (KB929123)
    / Windows XP / SP3: Update for Windows XP (KB929338)
    / Windows XP / SP3: Security Update for Windows XP (KB929969)
    / Windows XP / SP3: Security Update for Windows XP (KB930178)
    / Windows XP / SP3: Update for Windows XP (KB930916)
    / Windows XP / SP3: Security Update for Windows XP (KB931261)
    / Windows XP / SP3: Security Update for Windows XP (KB931768)
    / Windows XP / SP3: Security Update for Windows XP (KB931784)
    / Windows XP / SP3: Update for Windows XP (KB931836)
    / Windows XP / SP3: Security Update for Windows XP (KB932168)
    / Windows XP / SP3: Update for Windows XP (KB933360)
    / Windows XP / SP3: Security Update for Windows XP (KB933566)
    / Windows XP / SP3: Security Update for Windows XP (KB935839)
    / Windows XP / SP3: Security Update for Windows XP (KB935840)
    / Windows XP / SP3: Security Update for Windows XP (KB936021)
    / Windows XP / SP3: Update for Windows XP (KB936357)
    / Windows XP / SP3: Security Update for Windows XP (KB937143)
    / Windows XP / SP3: Security Update for Windows XP (KB938127)
    / Windows XP / SP3: Update for Windows XP (KB938828)
    / Windows XP / SP3: Security Update for Windows XP (KB938829)

  8. #8
    Junior Member
    Join Date
    Sep 2007
    Posts
    24

    Default

    --- Startup entries list ---
    Located: HK_LM:Run, hpsysdrv
    command: c:\windows\system\hpsysdrv.exe
    file: c:\windows\system\hpsysdrv.exe
    size: 52736
    MD5: 06a1ecb63df139ec639e084d4ab3c9d7

    Located: HK_LM:Run, PS2
    command: C:\WINDOWS\system32\ps2.exe
    file: C:\WINDOWS\system32\ps2.exe
    size: 81920
    MD5: c4c523e78774e05d06efe3e10017cf6d

    Located: HK_LM:Run, Recguard
    command: C:\WINDOWS\SMINST\RECGUARD.EXE
    file: C:\WINDOWS\SMINST\RECGUARD.EXE
    size: 212992
    MD5: d3cc7a3813123e955b3a497c04b404e2

    Located: HK_LM:Run, SunJavaUpdateSched
    command: C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    file: C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    size: 36975
    MD5: d3e445a99a1142c35d8d3100b5564591

    Located: HK_LM:Run, vptray
    command: C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
    file: C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
    size: 90224
    MD5: c1711f15294ac20a8e47b1f8862fb7cc

    Located: HK_CU:Run, Aim6
    command: "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    file: C:\Program Files\AIM6\aim6.exe
    size: 50736
    MD5: b6c1d859d1c25e80ab655bd5f4a6884b

    Located: Startup (common), HOTSYNCSHORTCUTNAME.lnk
    command: C:\Program Files\Palm\Hotsync.exe
    file: C:\Program Files\Palm\Hotsync.exe
    size: 471040
    MD5: f8fb2ca91f25d3eaa2cae2f0b55fec54

    Located: Startup (user), Palm Registration.lnk
    command: C:\Program Files\Palm\register.exe
    file: C:\Program Files\Palm\register.exe
    size: 2494464
    MD5: 533773cc598066297984dcae9788639a

    Located: System.ini, crypt32chain
    command: crypt32.dll
    file: crypt32.dll

    Located: System.ini, cryptnet
    command: cryptnet.dll
    file: cryptnet.dll

    Located: System.ini, cscdll
    command: cscdll.dll
    file: cscdll.dll

    Located: System.ini, igfxcui
    command: igfxsrvc.dll
    file: igfxsrvc.dll

    Located: System.ini, NavLogon
    command: C:\WINDOWS\system32\NavLogon.dll
    file: C:\WINDOWS\system32\NavLogon.dll
    size: 45172
    MD5: b445846da3c966586a2cc39f3233ee57

    Located: System.ini, OPXPGina
    command: C:\Program Files\Softex\OmniPass\opxpgina.dll
    file: C:\Program Files\Softex\OmniPass\opxpgina.dll
    size: 40960
    MD5: 35ab1f0280a73c419cb6759abf9ea44f

    Located: System.ini, ScCertProp
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, Schedule
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, sclgntfy
    command: sclgntfy.dll
    file: sclgntfy.dll

    Located: System.ini, SensLogn
    command: WlNotify.dll
    file: WlNotify.dll

    Located: System.ini, termsrv
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, wlballoon
    command: wlnotify.dll
    file: wlnotify.dll



    --- Browser helper object list ---
    {A7327C09-B521-4EDB-8509-7D2660C9EC98} (Viewpoint Toolbar BHO)
    BHO name:
    CLSID name: Viewpoint Toolbar BHO
    Path: C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\
    Long name: ViewBarBHO.dll
    Short name: VIEWBA~1.DLL
    Date (created): 3/17/2007 11:16:52 AM
    Date (last access): 9/17/2007 11:19:52 PM
    Date (last write): 2/24/2007 11:33:52 AM
    Filesize: 38584
    Attributes: archive
    MD5: 2DA0FFCCE5416A23952D4EA88270CAE2
    CRC32: 5574A892
    Version: 3.8.0.29



    --- ActiveX list ---
    {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ()
    DPF name:
    CLSID name:
    Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
    Codebase: http://fpdownload.macromedia.com/get.../ultrashim.cab
    description:
    classification: Open for discussion
    known filename:
    info link:
    info source: Safer Networking Ltd.

  9. #9
    Junior Member
    Join Date
    Sep 2007
    Posts
    24

    Default

    --- Process list ---
    PID: 0 ( 0) [System]
    PID: 344 ( 4) \SystemRoot\System32\smss.exe
    PID: 496 ( 344) \??\C:\WINDOWS\system32\csrss.exe
    PID: 520 ( 344) \??\C:\WINDOWS\system32\winlogon.exe
    PID: 564 ( 520) C:\WINDOWS\system32\services.exe
    size: 108032
    MD5: C6CE6EEC82F187615D1002BB3BB50ED4
    PID: 576 ( 520) C:\WINDOWS\system32\lsass.exe
    size: 13312
    MD5: 84885F9B82F4D55C6146EBF6065D75D2
    PID: 728 ( 564) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 784 ( 564) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 856 ( 564) C:\WINDOWS\System32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 896 ( 564) C:\WINDOWS\System32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 944 ( 564) C:\WINDOWS\System32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 1144 ( 564) C:\WINDOWS\system32\spoolsv.exe
    size: 57856
    MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
    PID: 1264 ( 564) C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    size: 32884
    MD5: CA5CFCDF32E0CFF86BF2159D49CC85F2
    PID: 1316 ( 564) C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    size: 655482
    MD5: 041AEB8B6BDF9F8039BF2AC20EB44D51
    PID: 1364 ( 564) C:\Program Files\Softex\OmniPass\Omniserv.exe
    size: 68704
    MD5: 7FA2A1A45435DC851790C0FD5F54612B
    PID: 1424 ( 564) C:\WINDOWS\System32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 1456 ( 564) C:\Program Files\Viewpoint\Common\ViewpointService.exe
    size: 24652
    MD5: 5F974FDE801C73952770736BECDE11E7
    PID: 1512 ( 564) C:\WINDOWS\wanmpsvc.exe
    size: 65536
    MD5: 909F2DC0DA7F57D229A05EE90647B2C3
    PID: 1708 ( 520) C:\Program Files\Softex\OmniPass\OPXPApp.exe
    size: 53248
    MD5: 435BA80D203F84B31909D6B1389F9E80
    PID: 1960 ( 564) C:\WINDOWS\System32\alg.exe
    size: 44544
    MD5: F1958FBF86D5C004CF19A5951A9514B7
    PID: 3272 (3116) C:\WINDOWS\Explorer.EXE
    size: 1033216
    MD5: 97BD6515465659FF8F3B7BE375B2EA87
    PID: 3328 ( 856) C:\WINDOWS\system32\wscntfy.exe
    size: 13824
    MD5: 49911DD39E023BB6C45E4E436CFBD297
    PID: 3392 (3272) C:\windows\system\hpsysdrv.exe
    size: 52736
    MD5: 06A1ECB63DF139EC639E084D4AB3C9D7
    PID: 3408 (3272) C:\WINDOWS\system32\ps2.exe
    size: 81920
    MD5: C4C523E78774E05D06EFE3E10017CF6D
    PID: 3416 (3272) C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    size: 36975
    MD5: D3E445A99A1142C35D8D3100B5564591
    PID: 3448 (3272) C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
    size: 90224
    MD5: C1711F15294AC20A8E47B1F8862FB7CC
    PID: 3524 (3416) C:\Program Files\Java\jre1.5.0_04\bin\jucheck.exe
    size: 241775
    MD5: E526D10A3E8CCD7BA0DF5664B553B821
    PID: 3548 (3272) C:\Program Files\Palm\Hotsync.exe
    size: 471040
    MD5: F8FB2CA91F25D3EAA2CAE2F0B55FEC54
    PID: 3876 ( 564) C:\WINDOWS\System32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 3100 (1456) C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    size: 112336
    MD5: 1FF94B386646925D2B153C8A083115C7
    PID: 3356 (3476) C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    size: 7644520
    MD5: E169EEF3C383D7A86F11B60220822A34
    PID: 5860 (3272) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    size: 4393096
    MD5: 09CA174A605B480318731E691DC98539
    PID: 4 ( 0) System


    --- Browser start & search pages list ---
    Spybot - Search & Destroy browser pages report, 9/18/2007 12:01:19 AM

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\windows\system32\blank.htm
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
    http://www.microsoft.com/isapi/redir...ie&ar=iesearch
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
    http://www.microsoft.com/isapi/redir...r=6&ar=msnhome
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
    http://www.microsoft.com/isapi/redir...ie&ar=iesearch
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
    about:blank
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
    http://home.microsoft.com/access/autosearch.asp?p=%s
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\windows\system32\blank.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
    http://www.microsoft.com/isapi/redir...ie&ar=iesearch
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
    http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
    http://www.microsoft.com/isapi/redir...r=6&ar=msnhome
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
    http://www.microsoft.com/isapi/redir...ie&ar=iesearch
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
    http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
    http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


    --- Winsock Layered Service Provider list ---
    Protocol 0: SpamSubtract over [MSAFD Tcpip [TCP/IP]]
    GUID: {60999653-6790-4E68-8593-9D3D0F6EB95F}
    Filename: SpSubLSP.dll

    Protocol 1: SpamSubtract over [MSAFD Tcpip [UDP/IP]]
    GUID: {23B17EEC-606D-4EF8-8C36-14EAD38D83F7}
    Filename: SpSubLSP.dll

    Protocol 2: SpamSubtract over [MSAFD Tcpip [RAW/IP]]
    GUID: {9CF1FDB3-1F7A-4159-93AF-39A5AB75BDEB}
    Filename: SpSubLSP.dll

    Protocol 3: SpamSubtract over [RSVP UDP Service Provider]
    GUID: {D8E6B737-32CC-48FF-B7C6-3318F25806FB}
    Filename: SpSubLSP.dll

    Protocol 4: SpamSubtract over [RSVP TCP Service Provider]
    GUID: {6A6C03C9-C7D1-48E5-9D6F-D5ABC28CC1F6}
    Filename: SpSubLSP.dll

    Protocol 16: SpamSubtract
    GUID: {BBC551FB-0ADB-49D9-AF74-03ED9BB58F77}
    Filename: SpSubLSP.dll

  10. #10
    Junior Member
    Join Date
    Sep 2007
    Posts
    24

    Default

    --- Uninstall list ---
    Ad-Aware SE Personal 1.06 (Ad-Aware SE Personal)
    uninstall cmd: C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
    publisher: Lavasoft
    help link: http://www.lavasoft.com

    (AddressBook)

    Adobe Acrobat 5.0 5.0 (Adobe Acrobat 5.0)
    version (major): 5
    install location: C:\Program Files\Adobe\Acrobat 5.0
    uninstall cmd: C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
    publisher: Adobe Systems, Inc.
    help link: http://www.adobe.com/prodindex/acrobat/main.html

    Adobe Flash Player ActiveX 9.0.47.0 (Adobe Flash Player ActiveX)
    uninstall cmd: C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    publisher: Adobe Systems Incorporated
    help link: http://www.adobe.com/go/flashplayer_support/

    AIM 6.0 (AIM_6.0)
    uninstall cmd: C:\Program Files\AIM6\uninst.exe

    AOL Instant Messenger (AOL Instant Messenger)
    uninstall cmd: C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=

    AOL Uninstaller (Choose which Products to Remove) (AOL Uninstaller)
    uninstall cmd: C:\Program Files\Common Files\AOL\uninstaller.exe

    AOL Coach Version 1.0(Build:20020823.1) (AolCoach)
    uninstall cmd: C:\WINDOWS\AolCInUn.exe

    ArcSoft Picture Software (ArcSoft Software Suite)
    uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ArcSoft\Software Suite\Uninst.isu"

    Updates from HP (BackWeb-137903 Uninstaller)
    uninstall cmd: C:\WINDOWS\BWUnin-6.2.3.66.exe -AppId 137903

    (Connection Manager)

    (DirectAnimation)

    (DirectDrawEx)

    (DXM_Runtime)

    ffdshow [rev 1413] [2007-08-10] 1.0 (ffdshow_is1)
    install date: 20070812
    install location: C:\Program Files\ffdshow\
    uninstall cmd: "C:\Program Files\ffdshow\unins000.exe"

    (Fontcore)

    HijackThis 2.0.2 2.0.2 (HijackThis)
    uninstall cmd: "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
    publisher: TrendMicro

    HP Instant Support 4.03.03 (hp instant support)
    uninstall cmd: C:\PROGRA~1\HPINST~1\UNWISE.EXE C:\PROGRA~1\HPINST~1\INSTALL.LOG
    publisher: Motive Communications, Inc.

    toolkit (HPTOOLKIT)
    uninstall cmd: c:\Windows\HPTK\unhptkit.exe

    (ICW)

    (IE40)

    (IE4Data)

    (IE5BAKEX)

    (IEData)

    ImTOO FLV Converter 3.1.39.0817b (ImTOO FLV Converter)
    uninstall cmd: C:\Program Files\ImTOO\FLV Converter 3\Uninstall.exe
    publisher: ImTOO
    help link: http://www.imtoo.com

    (InstallShield Uninstall Information)

    (InstallShield_{2A267BC6-F77F-4DD4-825F-7AEB1F68B4B1})

    iTunes 6.0.4.2 (InstallShield_{59C4F14F-7590-45FC-BE9F-A67AB3590709})
    version: 100663300
    version (major): 6
    estimated size: 79285
    install date: 20060423
    install location: C:\Program Files\iTunes\
    install source: C:\WINDOWS\Downloaded Installations\{59C4F14F-7590-45FC-BE9F-A67AB3590709}\
    uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{59C4F14F-7590-45FC-BE9F-A67AB3590709} /l1033
    publisher: Apple Computer, Inc.
    contact: AppleCare Support
    help link: http://www.info.apple.com/
    help telephone: 1-800-275-2273

    QuickTime 7.0.4 (InstallShield_{929408E6-D265-4174-805F-81D1D914E2A4})
    version: 117440516
    version (major): 7
    estimated size: 66739
    install date: 20060423
    install location: C:\Program Files\QuickTime\
    install source: C:\DOCUME~1\Owner\LOCALS~1\Temp\_is1B9\
    uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{929408E6-D265-4174-805F-81D1D914E2A4} /l1033
    publisher: Apple Computer, Inc.
    contact: AppleCare Support
    help link: http://www.info.apple.com/
    help telephone: 1-800-275-2273

    InterActual Player (InterActual Player)
    uninstall cmd: C:\Program Files\InterActual\InterActual Player\inuninst.exe

    IrfanView (remove only) (IrfanView)
    uninstall cmd: C:\Program Files\IrfanView\iv_uninstall.exe

    Kaspersky Online Scanner 5.0 (Kaspersky Online Scanner)
    install location: C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner
    uninstall cmd: C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
    publisher: Kaspersky Lab
    contact: Customer Support Department
    help link: http://support.kaspersky.com/helpdesk.html?LANG=en

    Windows XP Hotfix - KB873333 20050114.005213 (KB873333)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB873333$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=873333

    Windows XP Hotfix - KB873339 20041117.092459 (KB873339)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=873339

    Security Update for Windows XP (KB883939) 1 (KB883939)
    install date: 20050616
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB883939$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=883939

    (KB884016)

    (KB884267)

    Windows XP Hotfix - KB885250 20050118.202711 (KB885250)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB885250$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=885250

    (KB885353)

    Windows Media Player 9 Hotfix [See KB885492 for more information] (KB885492)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB885492$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=885492

    Windows XP Hotfix - KB885835 20041027.181713 (KB885835)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=885835

    Windows XP Hotfix - KB885836 20041028.173203 (KB885836)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=885836

    Windows XP Hotfix - KB886185 20041021.090540 (KB886185)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=886185

    (KB886612)

    (KB887078)

    Windows XP Hotfix - KB887472 20041014.162858 (KB887472)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=887472

    (KB887626)

    Windows XP Hotfix - KB887742 20041103.095002 (KB887742)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB887742$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=887742

    Windows XP Hotfix - KB888113 20041116.131036 (KB888113)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=888113

    Windows XP Hotfix - KB888302 20041207.111426 (KB888302)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=888302

    (KB888656)

    (KB889858)

    Security Update for Windows XP (KB890046) 1 (KB890046)
    install date: 20050616
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=890046

    Windows XP Hotfix - KB890175 20041201.233338 (KB890175)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB890175$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=890175

    Windows XP Hotfix - KB890859 1 (KB890859)
    install date: 20050612
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=890859

    Windows XP Hotfix - KB890923 1 (KB890923)
    install date: 20050612
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB890923$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=890923

    (KB891122)

    Windows XP Hotfix - KB891781 20050110.165439 (KB891781)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=891781

    (KB892313)

    Windows XP Hotfix - KB893066 1 (KB893066)
    install date: 20050612
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=893066

    Windows XP Hotfix - KB893086 1 (KB893086)
    install date: 20050612
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB893086$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=893086

    (KB893240)

    (KB893241)

    Security Update for Windows XP (KB893756) 1 (KB893756)
    install date: 20050813
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=893756

    (KB893803)

    Windows Installer 3.1 (KB893803) 3.1 (KB893803v2)
    uninstall cmd: "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://go.microsoft.com/fwlink/?LinkId=42467

    Update for Windows XP (KB894391) 1 (KB894391)
    install date: 20050813
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=894391

    (KB895181)

    (KB895316)

    (KB895572)

    Security Update for Windows XP (KB896358) 1 (KB896358)
    install date: 20050616
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=896358

    Security Update for Windows XP (KB896422) 1 (KB896422)
    install date: 20050616
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB896422$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=896422

    Security Update for Windows XP (KB896423) 1 (KB896423)
    install date: 20050813
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=896423

    Security Update for Windows XP (KB896424) 1 (KB896424)
    install date: 20051110
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=896424

    Security Update for Windows XP (KB896428) 1 (KB896428)
    install date: 20050616
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=896428

    Security Update for Windows XP (KB896688) 1 (KB896688)
    install date: 20051016
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB896688$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=896688

    Update for Windows XP (KB896727) 1 (KB896727)
    install date: 20050813
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB896727$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=896727

    (KB897586)

    Security Update for Step By Step Interactive Training (KB898458) 20050502.101010 (KB898458)
    install date: 20050616
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/kb/898458

    Update for Windows XP (KB898461) 1 (KB898461)
    install date: 20050628
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=898461

    (KB898549)

    Security Update for Windows XP (KB899587) 1 (KB899587)
    install date: 20050813
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=899587

    Security Update for Windows XP (KB899588) 1 (KB899588)
    install date: 20050813
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB899588$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=899588

    Security Update for Windows XP (KB899591) 1 (KB899591)
    install date: 20050813
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=899591

    (KB900399)

    Update for Windows XP (KB900485) 2 (KB900485)
    install date: 20060425
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=900485

    Security Update for Windows XP (KB900725) 1 (KB900725)
    install date: 20051016
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=900725

    Security Update for Windows XP (KB901017) 1 (KB901017)
    install date: 20051016
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=901017

    Security Update for Windows XP (KB901214) 1 (KB901214)
    install date: 20050712
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=901214

    (KB902344)

    Security Update for Windows XP (KB902400) 1 (KB902400)
    install date: 20051016
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=902400

    Security Update for Windows XP (KB903235) 1 (KB903235)
    install date: 20050712
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB903235$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=903235

    Security Update for Windows XP (KB904706) 1 (KB904706)
    install date: 20051016
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=904706

    Security Update for Windows XP (KB905414) 1 (KB905414)
    install date: 20051016
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=905414

    Security Update for Windows XP (KB905749) 1 (KB905749)
    install date: 20051016
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=905749

    Security Update for Windows XP (KB905915) 1 (KB905915)
    install date: 20051214
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB905915$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=905915

    (KB907658)

    Security Update for Windows XP (KB908519) 1 (KB908519)
    install date: 20060119
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=908519

    Security Update for Windows XP (KB908531) 1 (KB908531)
    install date: 20060416
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=908531

    Update for Windows XP (KB910437) 1 (KB910437)
    install date: 20051214
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=910437

    Security Update for Windows XP (KB911280) 1 (KB911280)
    install date: 20060616
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=911280

    Security Update for Windows XP (KB911562) 1 (KB911562)
    install date: 20060416
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=911562

    Security Update for Windows Media Player (KB911564) (KB911564)
    install date: 20060218
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=911564

    Security Update for Windows Media Player 9 (KB911565) (KB911565)
    install date: 20060218
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=911565

    Security Update for Windows XP (KB911567) 1 (KB911567)
    install date: 20060416
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB911567$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=911567

    (KB911854)

    Security Update for Windows XP (KB911927) 1 (KB911927)
    install date: 20060218
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=911927

    Security Update for Windows XP (KB912812) 1 (KB912812)
    install date: 20060416
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB912812$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=912812

    Security Update for Windows XP (KB912919) 1 (KB912919)
    install date: 20060119
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=912919

    Security Update for Windows XP (KB913446) 1 (KB913446)
    install date: 20060218
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB913446$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=913446

    Security Update for Windows XP (KB913580) 1 (KB913580)
    install date: 20060511
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=913580

    Security Update for Windows XP (KB914388) 1 (KB914388)
    install date: 20060715
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=914388

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •