Results 1 to 10 of 43

Thread: Please help delete the following spyware?

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Junior Member
    Join Date
    Feb 2006
    Posts
    3

    Default Please help delete the following spyware?

    Hi,

    I just run spybot, and came across spyware, however spybot is unable to delete them, here they are, thanks in advance for your help.
    - FunWeb
    - FunWebProducts
    - Myway.MyWebSearch
    - MyWebSearch

    more detailed:

    FunWebProducts: Class ID (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}

    FunWebProducts: Class ID (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}

    FunWebProducts: Class ID (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}

    FunWebProducts: Class ID (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}

    FunWebProducts: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.HistoryKillerScheduler

    FunWebProducts: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.HistoryKillerScheduler.1

    FunWebProducts: Class ID (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}

    FunWebProducts: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.HistorySwatterControlBar

    FunWebProducts: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.HistorySwatterControlBar.1

    FunWebProducts: Class ID (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}

    FunWebProducts: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.IECookiesManager

    FunWebProducts: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.IECookiesManager.1

    FunWebProducts: Class ID (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}

    FunWebProducts: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.KillerObjManager

    FunWebProducts: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.KillerObjManager.1

    FunWebProducts: Class ID (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}

    MyWay.MyWebSearch: Class ID (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\CLSID\{07B18EA3-A523-4961-B6BB-170DE4475CCA}

    MyWay.MyWebSearch: Class ID (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}

    MyWay.MyWebSearch: Class ID (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}

    MyWay.MyWebSearch: Class ID (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}

    MyWay.MyWebSearch: Class ID (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}

    MyWay.MyWebSearch: Class ID (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}

    MyWay.MyWebSearch: Class ID (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}

    MyWay.MyWebSearch: Class ID (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}

    MyWay.MyWebSearch: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\MyWebSearch.OutlookAddin

    MyWay.MyWebSearch: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\MyWebSearch.OutlookAddin.1

    MyWay.MyWebSearch: Class ID (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}

    MyWay.MyWebSearch: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\MyWebSearchToolBar.SettingsPlugin

    MyWay.MyWebSearch: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\MyWebSearchToolBar.SettingsPlugin.1

    MyWay.MyWebSearch: Class ID (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}

    MyWay.MyWebSearch: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\ScreenSaverControl.ScreenSaverInstaller

    MyWay.MyWebSearch: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\ScreenSaverControl.ScreenSaverInstaller.1

    MyWay.MyWebSearch: Class ID (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}

    MyWay.MyWebSearch: Type library (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}

    MyWay.MyWebSearch: Type library (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}

    MyWay.MyWebSearch: Type library (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}

    MyWay.MyWebSearch: Type library (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}

    MyWay.MyWebSearch: Type library (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}

    MyWay.MyWebSearch: Browser helper object (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\FocusInteractive

    MyWay.MyWebSearch: Settings (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin

    MyWay.MyWebSearch: Uninstall settings (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall

    MyWay.MyWebSearch: Settings (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\MyWebSearch

    FunWeb: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.HTMLMenu

    FunWeb: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.HTMLMenu.2

    FunWeb: Class ID (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}

    FunWeb: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.HTMLMenu.1

    FunWeb: Class ID (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}

    FunWeb: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.PopSwatterBarButton

    FunWeb: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.PopSwatterBarButton.1

    FunWeb: Class ID (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}

    FunWeb: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.PopSwatterSettingsControl

    FunWeb: Root class (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\FunWebProducts.PopSwatterSettingsControl.1

    FunWeb: Class ID (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}

    FunWeb: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}

    FunWeb: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}

    FunWeb: Settings (Registry key, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Fun Web Products

    FunWeb: Settings (Registry value, fixing failed)
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{120927BF-1700-43BC-810F-FAB92549B390}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{991AAC62-B100-47CE-8B75-253965244F69}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}

    MyWebSearch: Interface (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}

    MyWebSearch: Type library (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}

    MyWebSearch: Type library (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}


    --- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

    2005-05-31 blindman.exe (1.0.0.1)
    2005-05-31 SpybotSD.exe (1.4.0.3)
    2005-05-31 TeaTimer.exe (1.4.0.2)
    2006-01-16 unins000.exe (51.41.0.0)
    2005-05-31 Update.exe (1.4.0.0)
    2005-05-31 advcheck.dll (1.0.2.0)
    2005-05-31 aports.dll (2.1.0.0)
    2005-05-31 borlndmm.dll (7.0.4.453)
    2005-05-31 delphimm.dll (7.0.4.453)
    2005-05-31 SDHelper.dll (1.4.0.0)
    2005-05-31 Tools.dll (2.0.0.2)
    2005-05-31 UnzDll.dll (1.73.1.1)
    2005-05-31 ZipDll.dll (1.73.2.0)
    2006-02-03 Includes\Cookies.sbi (*)
    2006-02-03 Includes\Dialer.sbi (*)
    2006-02-03 Includes\Hijackers.sbi (*)
    2006-02-03 Includes\Keyloggers.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2006-02-03 Includes\Malware.sbi (*)
    2006-02-03 Includes\PUPS.sbi (*)
    2006-02-03 Includes\Revision.sbi (*)
    2006-02-03 Includes\Security.sbi (*)
    2006-02-03 Includes\Spybots.sbi (*)
    2005-02-17 Includes\Tracks.uti
    2006-02-03 Includes\Trojans.sbi (*)

  2. #2
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default

    Hello jeremy.

    Did you reboot so that Spybot-S&D could try to remove on startup?
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  3. #3
    Junior Member
    Join Date
    Feb 2006
    Posts
    1

    Default

    Hi Tashi, Jeremy,

    I've been having the same problem for some time now however I'm only getting the FunWebProducts entry.

    When Spybot says it can't fix the problem and asks whether to try again at startup, I select yes however I keep getting the same error after the scan at startup and seem to just go round and round in circles

    Cheers
    Renee

  4. #4
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    supernay:

    Go to Add/Remove programs and try to remove both Downlaod Accelerator Plus and FunWebProducts. Then rerun your Spybot scan and see if the results are better.

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz IntelŪ PentiumŪ 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  5. #5
    Junior Member
    Join Date
    Feb 2006
    Posts
    3

    Default

    Quote Originally Posted by md usa spybot fan
    supernay:

    Go to Add/Remove programs and try to remove both Downlaod Accelerator Plus and FunWebProducts. Then rerun your Spybot scan and see if the results are better.
    This programs don't appear in the Add/Remove menu, and I'm unable to remove them. Any help

  6. #6
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default

    Hi jeremy.

    • Open SpyBot, check for and get any updates available.
    • Close all browsers, check for problems and fix everything found in red
    • Then on the toolbar menu select mode and switch to advanced mode, on the left lower down select tools, and view report, ensure all the options are selected near the bottom except
    • Uncheck[ ] do not report disabled or known legitimate Items.
    • uncheck[ ] Include a list of services in report.
    • Uncheck[ ] Include uninstall list in report.
    • Now select (near the top) view report.
    • Press export in the save in box choose a place such as your my documents folder, then in your next post near the bottom select the "browse" button; navigate to and attach or post that report please.


    Cheers.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  7. #7
    Junior Member
    Join Date
    Jan 2008
    Posts
    1

    Default

    Quote Originally Posted by jeremy View Post
    This programs don't appear in the Add/Remove menu, and I'm unable to remove them. Any help
    I had the same problem - spybot couldn't remove the program and it didn't show on the programs list to uninstall it. After much searching the web I think I found a solution (spybot was able to delete the program after I did this).

    Bring up the 'run' dialog box (hold the windows button +R)

  8. #8
    Junior Member
    Join Date
    Feb 2010
    Posts
    1

    Default

    Quote Originally Posted by tashi View Post
    Hello jeremy.

    Did you reboot so that Spybot-S&D could try to remove on startup?
    I have tried to remove Myway.Mywebsearch several times the last couple of months.

    I have included the required report. I do not have any of the My Web Search, Acceleration or Fun Game files on my system any longer. They were removed a while ago.

    Can you please help.

    Thx,
    bdspear

  9. #9
    Senior Member
    Join Date
    Oct 2005
    Location
    Germany
    Posts
    5,263

    Default

    Hello,

    Please delete the following registry key:
    HKEY_USERS\S-1-5-21-3678852198-808917815-963407370-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

    Open the registry editor by:
    (a)
    press windowskey + r then enter "regedit" (without quotation marks)
    or
    (b)
    click on "start" , then "run" and enter "regedit" (without quotation marks)

    (a+b)
    and then browse to the path:
    HKEY_USERS\S-1-5-21-3678852198-808917815-963407370-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

    Best regards
    Sandra
    Team Spybot

  10. #10
    Junior Member
    Join Date
    Jul 2007
    Posts
    5

    Default myway.mywebsearch problem

    hi tashi. i have the same problem with the rest here. i have read the previous message of yours and i followed it. i already saved the report.txt and here it is. kindly help me what to do next. pls. Thank u so much. hope to hear from u soon.

    --- Search result list ---
    MyWay.MyWebSearch: Program directory (Directory, fixing failed)
    C:\Program Files\MyWebSearch\


    --- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

    2005-05-31 blindman.exe (1.0.0.1)
    2005-05-31 SpybotSD.exe (1.4.0.3)
    2005-05-31 TeaTimer.exe (1.4.0.2)
    2007-07-12 unins000.exe (51.41.0.0)
    2005-05-31 Update.exe (1.4.0.0)
    2007-05-23 advcheck.dll (1.5.3.0)
    2005-05-31 aports.dll (2.1.0.0)
    2005-05-31 borlndmm.dll (7.0.4.453)
    2005-05-31 delphimm.dll (7.0.4.453)
    2005-05-31 SDHelper.dll (1.4.0.0)
    2007-01-02 Tools.dll (2.0.1.0)
    2005-05-31 UnzDll.dll (1.73.1.1)
    2005-05-31 ZipDll.dll (1.73.2.0)
    2007-07-11 Includes\Cookies.sbi (*)
    2007-05-30 Includes\Dialer.sbi (*)
    2007-07-11 Includes\DialerC.sbi (*)
    2007-07-11 Includes\Hijackers.sbi (*)
    2007-07-11 Includes\HijackersC.sbi (*)
    2007-07-11 Includes\Keyloggers.sbi (*)
    2007-07-11 Includes\KeyloggersC.sbi (*)
    2007-07-11 Includes\Malware.sbi (*)
    2007-07-11 Includes\MalwareC.sbi (*)
    2007-07-11 Includes\PUPS.sbi (*)
    2007-07-11 Includes\PUPSC.sbi (*)
    2007-07-11 Includes\Revision.sbi (*)
    2007-05-30 Includes\Security.sbi (*)
    2007-07-11 Includes\SecurityC.sbi (*)
    2007-07-11 Includes\Spybots.sbi (*)
    2007-07-11 Includes\SpybotsC.sbi (*)
    2005-02-17 Includes\Tracks.uti
    2007-07-03 Includes\Trojans.sbi (*)
    2007-07-11 Includes\TrojansC.sbi (*)
    2007-06-06 Plugins\TCPIPAddress.dll



    --- System information ---
    Unknown Windows version 6.0 (Build: 6000)
    / MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2


    --- Startup entries list ---
    Located: HK_LM:Run, Acer Tour
    command:
    file:

    Located: HK_LM:Run, Acer Tour Reminder
    command: C:\Acer\AcerTour\Reminder.exe
    file: C:\Acer\AcerTour\Reminder.exe
    size: 151552
    MD5: c9a427b89a40727b0098f574d4fce371

    Located: HK_LM:Run, AcerOrbicamRibbon
    command: "C:\Program Files\Acer\OrbiCam10\OrbiCam.exe" /hide
    file: C:\Program Files\Acer\OrbiCam10\OrbiCam.exe
    size: 754712
    MD5: 0fda0dcaf7010d2ea924ebf5c1ed0281

    Located: HK_LM:Run, AVG7_CC
    command: C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    file: C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    size: 416256
    MD5: 2200c98c049de1a7638ea0edba1c8882

    Located: HK_LM:Run, eDataSecurity Loader
    command: C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    file: C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    size: 464168
    MD5: 0921a68e8fe9b25dd0effab949376b5f

    Located: HK_LM:Run, eRecoveryService
    command:
    file:

    Located: HK_LM:Run, HotKeysCmds
    command: C:\Windows\system32\hkcmd.exe
    file: C:\Windows\system32\hkcmd.exe
    size: 106496
    MD5: bf3e01c18ce6cdef16b0df23e1dcf376

    Located: HK_LM:Run, IgfxTray
    command: C:\Windows\system32\igfxtray.exe
    file: C:\Windows\system32\igfxtray.exe
    size: 98304
    MD5: 1c64dd02fde078608549c62398de2fef

    Located: HK_LM:Run, LManager
    command: C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
    file: C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
    size: 483328
    MD5: 7a657bb5e406ebc7ad8fd099a54f3bb7

    Located: HK_LM:Run, LogitechCommunicationsManager
    command: "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
    file: C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
    size: 304664
    MD5: c81579a9763263fb6fe79334f5029dc4

    Located: HK_LM:Run, LVCOMSX
    command: "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
    file: C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
    size: 244512
    MD5: 31e73e0fd0ffb364c4b32f46a6775db1

    Located: HK_LM:Run, My Web Search Bar Search Scope Monitor
    command: "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
    file:

    Located: HK_LM:Run, NvCplDaemon
    command: RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    file: C:\Windows\system32\RUNDLL32.EXE
    size: 44544
    MD5: 4b555106290bd117334e9a08761c035a

    Located: HK_LM:Run, NvMediaCenter
    command: RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    file: C:\Windows\system32\RUNDLL32.EXE
    size: 44544
    MD5: 4b555106290bd117334e9a08761c035a

    Located: HK_LM:Run, NvSvc
    command: RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    file: C:\Windows\system32\RUNDLL32.EXE
    size: 44544
    MD5: 4b555106290bd117334e9a08761c035a

    Located: HK_LM:Run, OneCareUI
    command: "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
    file: C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
    size: 66944
    MD5: 0d5c785bbe8fd4545738f17e9e6d025a

    Located: HK_LM:Run, PCMService
    command: "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
    file: C:\Program Files\Acer\Acer Arcade\PCMService.exe
    size: 151552
    MD5: 2862436e1ce0825b561ef37c2143c18a

    Located: HK_LM:Run, Persistence
    command: C:\Windows\system32\igfxpers.exe
    file: C:\Windows\system32\igfxpers.exe
    size: 81920
    MD5: 8e899a1a7c4670ce4ec1337cbf989787

    Located: HK_LM:Run, RtHDVCpl
    command: RtHDVCpl.exe
    file: C:\Windows\RtHDVCpl.exe
    size: 4186112
    MD5: 32e4e820edbd675009605f90dd97ee6c

    Located: HK_LM:Run, SetPanel
    command:
    file:

    Located: HK_LM:Run, SynTPEnh
    command: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    file: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    size: 815104
    MD5: f98281ef23616f751fabe97a6ec5dbe6

    Located: HK_LM:Run, Windows Defender
    command: %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    file:

    Located: HK_LM:Run, WPCUMI
    command: C:\Windows\system32\WpcUmi.exe
    file: C:\Windows\system32\WpcUmi.exe
    size: 176128
    MD5: c456658af90f42be3cdf1048f9cdb5ca

    Located: HK_LM:RunOnce, SpybotSnD
    command: "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
    file: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    size: 4393096
    MD5: 09ca174a605b480318731e691dc98539

    Located: HK_CU:Run, ISUSPM Startup
    command: "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
    file: C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
    size: 249856
    MD5: 1c46fc1ab600766b8554580204806e84

    Located: HK_CU:Run, msnmsgr
    command: "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    file: C:\Program Files\MSN Messenger\msnmsgr.exe
    size: 5674352
    MD5: c4281ad865739e71fd1e4dac19a68d60

    Located: HK_CU:Run, WMPNSCFG
    command: C:\Program Files\Windows Media Player\WMPNSCFG.exe
    file: C:\Program Files\Windows Media Player\WMPNSCFG.exe
    size: 201728
    MD5: 20ef9002cff89c4c1077e4415ec7297b

    Located: HK_CU:Run, Yahoo! Pager
    command: "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
    file: C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
    size: 4670968
    MD5: 81bcd9b9a86c3559f5bcfe56519a9a19

    Located: Startup (common), Adobe Reader Speed Launch.lnk
    command: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    file: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    size: 29696
    MD5: deb88aef013dd1eefb462d7cad642166

    Located: Startup (common), Bluetooth.lnk
    command: C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    file: C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    size: 703280
    MD5: 3fac23d4b003c1bf7a8f355cf3a504b6

    Located: Startup (common), Empowering Technology Launcher.lnk
    command: C:\Acer\Empowering Technology\eAPLauncher.exe
    file: C:\Acer\Empowering Technology\eAPLauncher.exe
    size: 528384
    MD5: c849d57292e58a9e1c55559930fd1082

    Located: Startup (common), WinZip Quick Pick.lnk
    command: C:\Program Files\WinZip\WZQKPICK.EXE
    file: C:\Program Files\WinZip\WZQKPICK.EXE
    size: 394856
    MD5: d79ddd73eee4266ae7dc2cbd87b56090

    Located: System.ini, avgwlntf
    command: avgwlntf.dll
    file: avgwlntf.dll

    Located: System.ini, igfxcui
    command: igfxdev.dll
    file: igfxdev.dll

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •