Second Half
{BDF3E430-B101-42AD-A544-FADC6B084872} ()
          BHO name: 
        CLSID name: 
       description: Norton Antivirus
    classification: Legitimate
    known filename: NavShExt.dll
         info link: 
http://www.symantec.com/nav/nav_9xnt/
       info source: TonyKlein
--- ActiveX list ---
{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
          DPF name: 
        CLSID name: Shockwave ActiveX Control
         Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
          Codebase: 
http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
       description: Macromedia ShockWave Flash Player 7
    classification: Legitimate
    known filename: SWDIR.DLL
         info link: 
       info source: Patrick M. Kolla
              Path: C:\WINDOWS\system32\macromed\Director\
         Long name:          SwDir.dll
        Short name:                   
    Date (created): 5/12/2006 2:54:10 PM
Date (last access): 7/6/2006 4:40:02 PM
 Date (last write): 6/26/2006 10:10:34 AM
          Filesize:              54960
        Attributes:           archive 
               MD5: 7E8A1C5DC0F1372BB2D170B0A88ED0C3
             CRC32:           0DEDE8C7
           Version:          10.1.3.18
{193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control)
          DPF name: 
        CLSID name: ewidoOnlineScan Control
         Installer: 
          Codebase: 
http://download.ewido.net/ewidoOnlineScan.cab
       description: 
    classification: Legitimate
    known filename: EWIDOO~1.DLL
         info link: 
       info source: Safer Networking Ltd.
              Path: C:\WINDOWS\DOWNLO~1\
         Long name: ewidoOnlineScan.dll
        Short name:       EWIDOO~1.DLL
    Date (created): 7/11/2006 9:41:36 AM
Date (last access): 7/11/2006 9:41:36 AM
 Date (last write): 7/11/2006 9:41:36 AM
          Filesize:             345656
        Attributes:           archive 
               MD5: B284992540E0FA2B76DEA56F93D49A16
             CRC32:           FD2E709C
           Version:            1.0.0.4
{6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
          DPF name: 
        CLSID name: ExentInf Class
         Installer: 
          Codebase: 
       description: Yahoo games?
    classification: Legitimate
    known filename: EXENTCTL_0_0_0_0.OCX
         info link: 
       info source: Patrick M. Kolla
              Path: C:\WINDOWS\Downloaded Program Files\
         Long name:       ExentCtl.ocx
        Short name:                   
    Date (created): 6/25/2006 1:12:44 PM
Date (last access): 6/25/2006 1:12:44 PM
 Date (last write): 7/19/2005 4:35:04 PM
          Filesize:             247416
        Attributes:           archive 
               MD5: CD2EF2E6949E439940444B2D192AA408
             CRC32:           1E24AEDE
           Version:           5.2.0.11
{9F1C11AA-197B-4942-BA54-47A8489BB47F} ()
          DPF name: 
        CLSID name: 
         Installer: 
          Codebase: 
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38848.3279513889
       description: Windows Update
    classification: Legitimate
    known filename: %WINDIR%\System32\iuctl.dll,iuengine.dll
         info link: 
       info source: Patrick M. Kolla
--- Process list ---
PID:    0 (   0) [System]
PID:  660 (   4) \SystemRoot\System32\smss.exe
PID:  732 ( 660) \??\C:\WINDOWS\system32\csrss.exe
PID:  756 ( 660) \??\C:\WINDOWS\system32\winlogon.exe
PID:  800 ( 756) C:\WINDOWS\system32\services.exe
 size: 108032
  MD5: C6CE6EEC82F187615D1002BB3BB50ED4
PID:  812 ( 756) C:\WINDOWS\system32\lsass.exe
 size: 13312
  MD5: 84885F9B82F4D55C6146EBF6065D75D2
PID:  968 ( 800) C:\WINDOWS\system32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1048 ( 800) C:\WINDOWS\system32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1164 ( 800) C:\WINDOWS\System32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1460 ( 800) C:\WINDOWS\system32\LEXBCES.EXE
 size: 303104
  MD5: 027D03D9D8AB95194A115A999E960AC0
PID: 1500 ( 800) C:\WINDOWS\system32\spoolsv.exe
 size: 57856
  MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
PID: 1808 ( 800) C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 size: 336896
  MD5: 9BF46D959F713D64C8FF3DE2B2437863
PID: 1824 ( 800) C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 size: 84480
  MD5: 66093610FA61142F6BCFD83AFB7E8A29
PID: 1848 ( 800) C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 size: 281088
  MD5: 07C595396C6F4631E88F9792E1BECD7E
PID: 1916 ( 800) C:\Program Files\Shavlik Technologies\NetChk\5.6.0.446\HfNetChkProService.exe
 size: 730736
  MD5: D7F78993CE9C524C6764B83C2579597B
PID: 1948 ( 800) C:\WINDOWS\system32\nvsvc32.exe
 size: 143436
  MD5: AA78C4677E06CFD4FE048718EE7F6332
PID:  244 ( 800) C:\WINDOWS\ProPatches\Scheduler\stSchedEx.exe
 size: 181872
  MD5: 7EC837F1896475BE7B4B857BDFFBAC5B
PID:  304 ( 800) C:\WINDOWS\system32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID:  532 ( 800) C:\WINDOWS\System32\wdfmgr.exe
 size: 38912
  MD5: AB0A7CA90D9E3D6A193905DC1715DED0
PID:  604 ( 800) C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 size: 75768
  MD5: ACE93FFFFD1F6B2C3E9F9C996BDEC6DB
PID: 2300 (2452) C:\WINDOWS\Explorer.EXE
 size: 1032192
  MD5: A0732187050030AE399B241436565E64
PID: 2444 (2300) C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 size: 369664
  MD5: 32E0D24EAD2A5C7EE7B6AD516EAFE8EE
PID: 2932 (2300) C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 size: 968696
  MD5: D1D3726A8508B6183C620B4F6CE82F70
PID: 1692 (2300) C:\WINDOWS\system32\lexpps.exe
 size: 174592
  MD5: 8D836E60877ED79C409712B9BE2DFC3B
PID: 1244 ( 968) C:\Program Files\Internet Explorer\iexplore.exe
 size: 93184
  MD5: E7484514C0464642BE7B4DC2689354C8
PID: 2540 (2300) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
 size: 4393096
  MD5: 09CA174A605B480318731E691DC98539
PID:    4 (   0) System
--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 8/24/2006 3:46:57 PM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
  C:\WINDOWS\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
  
http://www.google.com
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
  
http://www.google.com/ie
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
  
http://www.google.ca/
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
  
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
  http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
  
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
  
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
  
http://www.google.com/ie
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
  http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
--- Winsock Layered Service Provider list ---
Protocol  0: MSAFD Tcpip [TCP/IP]
        GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP IP protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD Tcpip [*]
Protocol  1: MSAFD Tcpip [UDP/IP]
        GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP IP protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD Tcpip [*]
Protocol  2: MSAFD Tcpip [RAW/IP]
        GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP IP protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD Tcpip [*]
Protocol  3: RSVP UDP Service Provider
        GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\rsvpsp.dll
 Description: Microsoft Windows NT/2k/XP RVSP
 DB filename: %SystemRoot%\system32\rsvpsp.dll
 DB protocol: RSVP * Service Provider
Protocol  4: RSVP TCP Service Provider
        GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\rsvpsp.dll
 Description: Microsoft Windows NT/2k/XP RVSP
 DB filename: %SystemRoot%\system32\rsvpsp.dll
 DB protocol: RSVP * Service Provider
Protocol  5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{BDA3C356-F90E-4A21-A450-4AE377DF9EE9}] SEQPACKET 5
        GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP NetBios protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD NetBIOS *
Protocol  6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{BDA3C356-F90E-4A21-A450-4AE377DF9EE9}] DATAGRAM 5
        GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP NetBios protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD NetBIOS *
Protocol  7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7A8C8E67-98A0-4441-8184-A021D131E944}] SEQPACKET 0
        GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP NetBios protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD NetBIOS *
Protocol  8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7A8C8E67-98A0-4441-8184-A021D131E944}] DATAGRAM 0
        GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP NetBios protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD NetBIOS *
Protocol  9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{879D2174-83F6-4EE0-AF06-F6AF21C07060}] SEQPACKET 1
        GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP NetBios protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD NetBIOS *
Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{879D2174-83F6-4EE0-AF06-F6AF21C07060}] DATAGRAM 1
        GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP NetBios protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD NetBIOS *
Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{75791F15-E760-426E-A7D5-531593CADE6B}] SEQPACKET 2
        GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP NetBios protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD NetBIOS *
Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{75791F15-E760-426E-A7D5-531593CADE6B}] DATAGRAM 2
        GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP NetBios protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD NetBIOS *
Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{85976A40-1147-4BF3-8297-E010D356A1FA}] SEQPACKET 3
        GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP NetBios protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD NetBIOS *
Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{85976A40-1147-4BF3-8297-E010D356A1FA}] DATAGRAM 3
        GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP NetBios protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD NetBIOS *
Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{9BEBC8C5-7253-45F4-886E-F7BF9FD3C889}] SEQPACKET 4
        GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP NetBios protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD NetBIOS *
Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{9BEBC8C5-7253-45F4-886E-F7BF9FD3C889}] DATAGRAM 4
        GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP NetBios protocol
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: MSAFD NetBIOS *
Namespace Provider  0: Tcpip
        GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
    Filename: %SystemRoot%\System32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: TCP/IP
Namespace Provider  1: NTDS
        GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
    Filename: %SystemRoot%\System32\winrnr.dll
 Description: Microsoft Windows NT/2k/XP name space provider
 DB filename: %SystemRoot%\system32\winrnr.dll
 DB protocol: NTDS
Namespace Provider  2: Network Location Awareness (NLA) Namespace
        GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
    Filename: %SystemRoot%\System32\mswsock.dll
 Description: Microsoft Windows NT/2k/XP name space provider
 DB filename: %SystemRoot%\system32\mswsock.dll
 DB protocol: NLA-Namespace