Part 1 of 4
--- Search result list ---
Microsoft.Windows.RedirectedHosts: [SBI $ECD8F8C6] Redirected host (Redirected host, fixed)
www.experts-exchange.com=127.0.0.1
Microsoft.Windows.RedirectedHosts: [SBI $BE4D29D7] Redirected host (Redirected host, fixed)
experts-exchange.com=127.0.0.1
Microsoft.Windows.RedirectedHosts: [SBI $B1534D36] Redirected host (Redirected host, fixed)
ask.com=127.0.0.1
Microsoft.Windows.RedirectedHosts: [SBI $A81A96E0] Redirected host (Redirected host, fixed)
www.ask.com=127.0.0.1
--- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---
2008-01-28 blindman.exe (1.0.0.7)
2008-01-28 SDDelFile.exe (1.0.2.4)
2008-01-28 SDMain.exe (1.0.0.5)
2007-10-07 SDShred.exe (1.0.1.2)
2008-01-28 SDUpdate.exe (1.0.8.8)
2008-01-28 SDWinSec.exe (1.0.0.11)
2008-01-28 SpybotSD.exe (1.5.2.20)
2008-01-28 TeaTimer.exe (1.5.2.16)
2008-04-25 unins000.exe (51.49.0.0)
2008-01-28 Update.exe (1.4.0.6)
2008-01-28 advcheck.dll (1.5.4.5)
2007-04-02 aports.dll (2.1.0.0)
2007-11-17 DelZip179.dll (1.79.7.4)
2008-01-28 SDFiles.dll (1.5.1.19)
2008-01-28 SDHelper.dll (1.5.0.11)
2008-01-28 Tools.dll (2.1.3.3)
2008-04-16 Includes\Adware.sbi (*)
2008-04-24 Includes\AdwareC.sbi (*)
2008-04-24 Includes\Cookies.sbi (*)
2007-12-26 Includes\Dialer.sbi (*)
2008-04-24 Includes\DialerC.sbi (*)
2008-04-24 Includes\HeavyDuty.sbi (*)
2008-03-19 Includes\Hijackers.sbi (*)
2008-04-24 Includes\HijackersC.sbi (*)
2008-02-27 Includes\Keyloggers.sbi (*)
2008-04-24 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-04-22 Includes\Malware.sbi (*)
2008-04-24 Includes\MalwareC.sbi (*)
2008-03-26 Includes\PUPS.sbi (*)
2008-04-24 Includes\PUPSC.sbi (*)
2008-04-24 Includes\Revision.sbi (*)
2008-01-09 Includes\Security.sbi (*)
2008-04-24 Includes\SecurityC.sbi (*)
2008-04-16 Includes\Spybots.sbi (*)
2008-04-24 Includes\SpybotsC.sbi (*)
2008-04-16 Includes\Spyware.sbi (*)
2008-04-24 Includes\SpywareC.sbi (*)
2007-11-06 Includes\Tracks.uti
2008-04-24 Includes\Trojans.sbi (*)
2008-04-24 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
--- System information ---
Windows XP (Build: 2600) Service Pack 3, v.3311 (5.1.2600)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
/ MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2
/ MSXML4SP2: Security update for MSXML4 SP2 (KB936181)
/ Step By Step Interactive Training / SP2: Security Update for Step By Step Interactive Training (KB898458)
/ Step By Step Interactive Training / SP2: Security Update for Step By Step Interactive Training (KB923723)
/ Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
/ Windows / SP1: Microsoft National Language Support Downlevel APIs
/ Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
/ Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782)
/ Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683)
/ Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398)
/ Windows Media Player 9: Security Update for Windows Media Player 9 (KB917734)
/ Windows Presentation Foundation: This Hotfix is for Microsoft .NET Framework 3.0. \n
If you later install a more recent service pack, this Hotfix will be uninstalled automatically. \n
For more information, visit
http://support.microsoft.com/kb/932471
/ Windows XP: Security Update for Windows XP (KB923689)
/ Windows XP: Security Update for Windows XP (KB941569)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB928090)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB929969)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB931768)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB933566)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB937143)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB939653)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB942615)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB944533)
/ Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
/ Windows XP / SP2: Windows XP Service Pack 2
/ Windows XP / SP3: Windows XP Service Pack 3
/ XML Paper Specification Shared Components Pack 1.0: XML Paper Specification Shared Components Pack 1.0
--- Startup entries list ---
Located: HK_LM:Run, avast!
command: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
file: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
size: 79224
MD5: E1E4780C87DACC69BE77DA4A1B3EC692
Located: HK_LM:Run, BMMGAG
command: RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, BMMLREF
command: C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
file: C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
size: 20480
MD5: 35E286D663AFE6D1F55B7F845F9133CA
Located: HK_LM:Run, BMMMONWND
command: rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, dla
command: C:\WINDOWS\system32\dla\tfswctrl.exe
file: C:\WINDOWS\system32\dla\tfswctrl.exe
size: 114741
MD5: 9FAAC65931211B08A6BC5089AA32C1BB
Located: HK_LM:Run, EZEJMNAP
command: C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
file: C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
size: 208896
MD5: 849CA567BC0ECE5BCF407B06B5B3A183
Located: HK_LM:Run, HotKeysCmds
command: C:\WINDOWS\system32\hkcmd.exe
file: C:\WINDOWS\system32\hkcmd.exe
size: 77824
MD5: FBC32DBF9E460E9CAA516BBABB730925
Located: HK_LM:Run, ibmmessages
command: C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, igfxtray
command: C:\WINDOWS\system32\igfxtray.exe
file: C:\WINDOWS\system32\igfxtray.exe
size: 94208
MD5: FA680935110ECE1BF93E9AADEBDC865B
Located: HK_LM:Run, kmw_run.exe
command: kmw_run.exe
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, MSWheel
command:
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, PRONoMgrWired
command: C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
file: C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
size: 86016
MD5: 31F4726648A033F3000B340331D9C55B
Located: HK_LM:Run, QCTRAY
command: C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, QCWLICON
command: C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, S3TRAY2
command: S3Tray2.exe
file: C:\WINDOWS\system32\S3Tray2.exe
size: 69632
MD5: C11D79B0421D833CBC2A182E708A170A
Located: HK_LM:Run, SoundMAX
command: "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
file: C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
size: 794624
MD5: 0A83AEDEFADE30B5CD28049031E149FA
Located: HK_LM:Run, SoundMAXPnP
command: C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
file: C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
size: 1368064
MD5: D3333768300F462F6B309AB53F75BB25
Located: HK_LM:Run, TP4EX
command: tp4ex.exe
file: C:\WINDOWS\system32\tp4ex.exe
size: 53248
MD5: 15CFE57F05D7FD80D1C5E70BCDCB01FF
Located: HK_LM:Run, TPHOTKEY
command: C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
file: C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
size: 94208
MD5: 5CD7051EEB1926D305E24092E893A6D0
Located: HK_LM:Run, TPKMAPHELPER
command: C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
file: C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe
size: 897024
MD5: 40C48D5DD0BF8D2BECC05D4D9202A7B4
Located: HK_LM:Run, TrackPointSrv
command: tp4serv.exe
file: C:\WINDOWS\system32\tp4serv.exe
size: 91184
MD5: 8309A9274A1D07827AAAD01C0F383A87
Located: HK_LM:Run, UC_Start
command: C:\Program Files\IBM\Updater\\ucstartup.exe
file: C:\Program Files\IBM\Updater\\ucstartup.exe
size: 36864
MD5: 26D7756857B8C374BBD67E537803F8AA
Located: HK_LM:Run, UpdateManager
command: "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
file: C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
size: 110592
MD5: 22FD4E58D69969A9165721C797D54931
Located: HK_CU:Run, AWMON
where: S-1-5-21-384269087-4006903996-2036936361-1005...
command: "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
file: C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
size: 517632
MD5: 107AF2DE3AF10D6D09C1B36FE9EF9156
Located: HK_CU:Run, ibmmessages
where: S-1-5-21-384269087-4006903996-2036936361-1005...
command: C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:Run, SpybotSD TeaTimer
where: S-1-5-21-384269087-4006903996-2036936361-1005...
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 2097488
MD5: A9A5DB6AC3721BE698B996913693D73F
Located: Startup (user), Wallpaper Changer.lnk
where: C:\Documents and Settings\Kevin\Start Menu\Programs\Startup...
command: C:\Program Files\WallpaperToy\Wallpapertoy.Exe
file: C:\Program Files\WallpaperToy\Wallpapertoy.Exe
size: 110592
MD5: C55BB6B2ADCA699620BF7ED0E6075B4E
Located: Startup (user), Yahoo! Widget Engine.lnk
where: C:\Documents and Settings\Kevin\Start Menu\Programs\Startup...
command: C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
file: C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
size: 1806336
MD5: 7515DC58C1296AD6CED6327DBB432E7D
Located: Startup (user), YPOPs.lnk
where: C:\Documents and Settings\Kevin\Start Menu\Programs\Startup...
command: C:\Program Files\YPOPs\YPOPs.exe
file: C:\Program Files\YPOPs\YPOPs.exe
size: 1331200
MD5: 0498370F0E95617374FAAE6D234281F7
Located: Startup (disabled), Adobe Reader Speed Launch (DISABLED)
command: C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE
file: C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE
size: 39792
MD5: 8B9145D229D4E89D15ACB820D4A3A90F
Located: Startup (disabled), Adobe Reader Synchronizer (DISABLED)
command: C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE
file: C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE
size: 738968
MD5: 1C1C6ABBC3408A373C731EC3F41EAE16
Located: Startup (disabled), Digital Line Detect (DISABLED)
command: C:\PROGRA~1\DIGITA~1\DLG.exe
file: C:\PROGRA~1\DIGITA~1\DLG.exe
size: 24576
MD5: B66E56733E2CD6A10FDA5919625FBF46
Located: Startup (disabled), Microsoft Office (DISABLED)
command: C:\PROGRA~1\MICROS~2\Office\OSA9.EXE -b -l
file: C:\PROGRA~1\MICROS~2\Office\OSA9.EXE
size: 65588
MD5: F7D6FC2CC9886F34B986986DB1B7C06B
Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, dimsntfy
command: %SystemRoot%\System32\dimsntfy.dll
file: %SystemRoot%\System32\dimsntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, igfxcui
command: igfxdev.dll
file: igfxdev.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, WgaLogon
command: WgaLogon.dll
file: WgaLogon.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
--- Browser helper object list ---
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Adobe PDF Reader Link Helper
description: Adobe Acrobat reader
classification: Legitimate
known filename: AcroIEhelper.ocx<br>AcroIEhelper.dll
info link:
http://www.adobe.com/products/acrobat/readstep2.html
info source: TonyKlein
Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\
Long name: AcroIEHelper.dll
Short name: ACROIE~1.DLL
Date (created): 10/23/2006 12:08:42 AM
Date (last access): 2/11/2008 7:13:22 PM
Date (last write): 10/23/2006 12:08:42 AM
Filesize: 62080
Attributes: archive
MD5: C11F6A1F61481E24BE3FDC06EA6F7D2A
CRC32: E388508F
Version: 8.0.0.456
{53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Spybot-S&D IE Protection
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDhelper.dll
info link:
http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\PROGRA~1\SPYBOT~1\
Long name: SDHelper.dll
Short name:
Date (created): 4/25/2008 7:34:02 AM
Date (last access): 4/25/2008 7:34:02 AM
Date (last write): 1/28/2008 11:43:28 AM
Filesize: 1554256
Attributes: archive
MD5: 5248E02EFBCB64D328647CD00E384B85
CRC32: C1B426A9
Version: 1.5.0.11
{5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: DriveLetterAccess
description: Hewlett-Packard's DLA software
classification: Unknown
known filename: tfswshx.dll
info link:
info source: TonyKlein
Path: C:\WINDOWS\system32\dla\
Long name: tfswshx.dll
Short name:
Date (created): 1/17/2007 10:14:44 PM
Date (last access): 1/17/2007 10:14:44 PM
Date (last write): 9/26/2003 2:04:00 AM
Filesize: 106548
Attributes: archive
MD5: A4529BF862DA0DB2067C463207E158C2
CRC32: 79C1AD83
Version: 1.4.7.0
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: SSVHelper Class
Path: C:\Program Files\Java\jre1.6.0_05\bin\
Long name: ssv.dll
Short name:
Date (created): 3/6/2008 11:58:38 AM
Date (last access): 2/22/2008 3:33:32 AM
Date (last write): 2/22/2008 5:25:20 AM
Filesize: 509328
Attributes: archive
MD5: 5B42CB6A121256465B251840FDB1B2FE
CRC32: 6EF0BCE9
Version: 6.0.50.13
--- ActiveX list ---
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object)
DPF name:
CLSID name: QuickTime Object
Installer:
Codebase:
description: Apple Quicktime
classification: Legitimate
known filename: QTPLUGIN.OCX
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\QuickTime\
Long name: QTPlugin.ocx
Short name:
Date (created): 2/1/2008 12:13:52 AM
Date (last access): 2/29/2008 6:35:14 PM
Date (last write): 2/1/2008 12:13:52 AM
Filesize: 750896
Attributes: archive
MD5: 02D754B790F277B5B088B5FBE2692908
CRC32: AE2617C3
Version: 7.4.1.14
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object)
DPF name:
CLSID name: CKAVWebScan Object
Installer:
Codebase:
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\
Long name: kavwebscan.dll
Short name: KAVWEB~1.DLL
Date (created): 8/29/2007 3:49:54 PM
Date (last access): 8/29/2007 3:49:54 PM
Date (last write): 8/29/2007 3:49:54 PM
Filesize: 950272
Attributes: archive
MD5: BC915C49931CE46222F9B0A7EFB56CEE
CRC32: 11048171
Version: 5.0.98.0
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class)
DPF name:
CLSID name: YInstStarter Class
Installer: C:\Program Files\Yahoo!\Common\yinst.inf
Codebase: C:\Program Files\Yahoo!\Common\yinsthelper.dll
description: Yahoo! Installation helper
classification: Legitimate
known filename: %SystemRoot%\Downloaded Program Files\yinsthelper.dll
info link:
info source: Patrick M. Kolla
Path: C:\PROGRA~1\Yahoo!\Common\
Long name: yinsthelper.dll
Short name: YINSTH~1.DLL
Date (created): 3/1/2008 5:58:52 PM
Date (last access): 3/1/2008 5:58:52 PM
Date (last write): 7/30/2006 2:25:34 PM
Filesize: 188968
Attributes: archive
MD5: 18B54B53CEE0E7204495BAB864EBBF03
CRC32: 6D72BB93
Version: 2006.4.14.2
{6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
DPF name:
CLSID name: WUWebControl Class
Installer:
Codebase:
description:
classification: Legitimate
known filename: wuweb.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\
Long name: wuweb.dll
Short name:
Date (created): 12/17/2006 4:18:54 PM
Date (last access): 8/23/2007 5:30:34 PM
Date (last write): 7/30/2007 7:19:28 PM
Filesize: 203096
Attributes: archive
MD5: 5C9A003E7C6BA03F04DC2D9C82A7E6E0
CRC32: E29E0153
Version: 7.0.6000.381
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
DPF name:
CLSID name: MUWebControl Class
Installer:
Codebase:
description:
classification: Legitimate
known filename: muweb.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\
Long name: muweb.dll
Short name:
Date (created): 5/26/2005 5:19:32 AM
Date (last access): 8/23/2007 5:31:08 PM
Date (last write): 7/30/2007 7:19:04 PM
Filesize: 207736
Attributes: archive
MD5: 2DEE560CCEF55353EB62FDA870446393
CRC32: 5AA71F7B
Version: 7.0.6000.381
{74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support)
DPF name:
CLSID name: IBM Access Support
Installer:
Codebase:
description:
classification: Legitimate
known filename: IbmEgath.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\
Long name: IbmEgath.dll
Short name:
Date (created): 12/17/2006 4:38:48 PM
Date (last access): 12/25/2006 10:44:14 AM
Date (last write): 6/29/2006 6:22:48 PM
Filesize: 180224
Attributes: archive
MD5: 2FF8E0FC23D4F142BFBAE78D7960921C
CRC32: 7A7F3465
Version: 3.20.284.0
{76E5AF9D-2B3E-4FEB-A31F-A9E63A27FA29} ()
DPF name:
CLSID name:
Installer:
Codebase:
description:
classification: Legitimate
known filename: ACPIR.dll
info link:
info source: Safer Networking Ltd.
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_05)
DPF name:
CLSID name: Java Plug-in 1.6.0_05
Installer:
Codebase:
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\jre1.6.0_05\bin\
Long name: npjpi160_05.dll
Short name: NPJPI1~1.DLL
Date (created): 2/22/2008 3:33:32 AM
Date (last access): 2/22/2008 3:33:32 AM
Date (last write): 2/22/2008 5:25:20 AM
Filesize: 132496
Attributes: archive
MD5: 4FDFB86D78994BD71CBB779A7809E9CD
CRC32: 5A0EB880
Version: 6.0.50.13
{C7DB51B4-BCF7-4923-8874-7F1A0DC92277} ()
DPF name:
CLSID name:
Installer:
Codebase:
description:
classification: Legitimate
known filename: opuc.dll
info link:
info source: Safer Networking Ltd.
{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} ()
DPF name:
CLSID name:
Installer:
Codebase:
description:
classification: Legitimate
known filename: NPJPI141.dll
info link:
info source: Safer Networking Ltd.
{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} (Java Plug-in 1.5.0_10)
DPF name:
CLSID name: Java Plug-in 1.5.0_10
Installer:
Codebase:
description:
classification: Legitimate
known filename: npjpi150_10.dll
info link:
info source: Safer Networking Ltd.
{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} ()
DPF name:
CLSID name:
Installer:
Codebase:
description:
classification: Legitimate
known filename: npjpi150_11.dll
info link:
info source: Safer Networking Ltd.
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.6.0_02)
DPF name:
CLSID name: Java Plug-in 1.6.0_02
Installer:
Codebase:
description:
classification: Legitimate
known filename: npjpi160_02.dll
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files\Java\jre1.6.0_02\bin\
Long name: npjpi160_02.dll
Short name: NPJPI1~1.DLL
Date (created): 7/12/2007 2:22:38 AM
Date (last access): 7/12/2007 2:22:38 AM
Date (last write): 7/12/2007 4:00:36 AM
Filesize: 132496
Attributes: archive
MD5: E3811F1A1C5063C941EC0E2766C3EA39
CRC32: AEFD3747
Version: 6.0.20.6
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03)
DPF name:
CLSID name: Java Plug-in 1.6.0_03
Installer:
Codebase:
Path: C:\Program Files\Java\jre1.6.0_03\bin\
Long name: npjpi160_03.dll
Short name: NPJPI1~1.DLL
Date (created): 9/25/2007 12:31:44 AM
Date (last access): 9/25/2007 12:31:44 AM
Date (last write): 9/25/2007 2:11:34 AM
Filesize: 132496
Attributes: archive
MD5: D6A4682A6FF41832A3F1A7AB9AE08199
CRC32: 9080B537
Version: 6.0.30.5
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05)
DPF name:
CLSID name: Java Plug-in 1.6.0_05
Installer:
Codebase:
Path: C:\Program Files\Java\jre1.6.0_05\bin\
Long name: npjpi160_05.dll
Short name: NPJPI1~1.DLL
Date (created): 2/22/2008 3:33:32 AM
Date (last access): 2/22/2008 3:33:32 AM
Date (last write): 2/22/2008 5:25:20 AM
Filesize: 132496
Attributes: archive
MD5: 4FDFB86D78994BD71CBB779A7809E9CD
CRC32: 5A0EB880
Version: 6.0.50.13
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05)
DPF name:
CLSID name: Java Plug-in 1.6.0_05
Installer:
Codebase:
description:
classification: Legitimate
known filename: npjpi150_06.dll
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files\Java\jre1.6.0_05\bin\
Long name: npjpi160_05.dll
Short name: NPJPI1~1.DLL
Date (created): 2/22/2008 3:33:32 AM
Date (last access): 2/22/2008 3:33:32 AM
Date (last write): 2/22/2008 5:25:20 AM
Filesize: 132496
Attributes: archive
MD5: 4FDFB86D78994BD71CBB779A7809E9CD
CRC32: 5A0EB880
Version: 6.0.50.13
{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
Installer:
Codebase:
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\system32\Macromed\Flash\
Long name: Flash9c.ocx
Short name:
Date (created): 3/23/2007 2:59:38 PM
Date (last access): 4/29/2007 9:58:16 PM
Date (last write): 3/23/2007 2:59:38 PM
Filesize: 2267368
Attributes: readonly archive
MD5: 18AE02A4195292C692D5B006F1421D01
CRC32: B8EED2E6
Version: 9.0.45.0
--- Process list ---
PID: 0 ( 0) [System]
PID: 736 ( 4) \SystemRoot\System32\smss.exe
size: 50688
PID: 800 ( 736) \??\C:\WINDOWS\system32\csrss.exe
size: 6144
PID: 824 ( 736) \??\C:\WINDOWS\system32\winlogon.exe
size: 507904
PID: 868 ( 824) C:\WINDOWS\system32\services.exe
size: 108544
MD5: 3BF0DF2D99EE82B08C1E76B72FA562C7
PID: 880 ( 824) C:\WINDOWS\system32\lsass.exe
size: 13312
MD5: 70885577298B92939F3B7AF54D5F8943
PID: 1052 ( 868) C:\WINDOWS\system32\ibmpmsvc.exe
size: 36400
MD5: A75CE11915E4ECC5E1597D6E0F7BB2DB
PID: 1080 ( 868) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 0C54D685CFA1D5054F59F08ADAF71248
PID: 1200 ( 868) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 0C54D685CFA1D5054F59F08ADAF71248
PID: 1320 ( 868) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 0C54D685CFA1D5054F59F08ADAF71248
PID: 1380 ( 868) C:\WINDOWS\system32\S24EvMon.exe
size: 286787
MD5: 6083FE94CAE83EE40A9A2BB6B440A5EE
PID: 1584 ( 868) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 0C54D685CFA1D5054F59F08ADAF71248
PID: 1804 ( 868) C:\Program Files\Tall Emu\Online Armor\oasrv.exe
size: 5414464
MD5: 7B2384CE743A9FC78F503E85AFFC1A1B
PID: 372 ( 224) C:\WINDOWS\Explorer.EXE
size: 1033728
MD5: CB7C9E2BA846DA0AFABD19DE6B6F2006
PID: 448 ( 868) C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
size: 17272
MD5: 3CA72CEA90DF8DA569D35CEC89676749
PID: 504 ( 868) C:\Program Files\Alwil Software\Avast4\ashServ.exe
size: 144760
MD5: 6A0A14F60654DF588F55160CB1B6DA8D
PID: 1616 ( 372) C:\WINDOWS\system32\tp4serv.exe
size: 91184
MD5: 8309A9274A1D07827AAAD01C0F383A87
PID: 1892 ( 372) C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
size: 208896
MD5: 849CA567BC0ECE5BCF407B06B5B3A183
PID: 1368 ( 868) C:\WINDOWS\system32\spoolsv.exe
size: 57856
MD5: 8B7AF2E5DACFD5A6204FA276136D82CC
PID: 556 ( 372) C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
size: 79224
MD5: E1E4780C87DACC69BE77DA4A1B3EC692
PID: 596 ( 372) C:\WINDOWS\system32\dla\tfswctrl.exe
size: 114741
MD5: 9FAAC65931211B08A6BC5089AA32C1BB
PID: 1192 ( 372) C:\WINDOWS\system32\hkcmd.exe
size: 77824
MD5: FBC32DBF9E460E9CAA516BBABB730925
PID: 1412 ( 372) C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
size: 94208
MD5: 5CD7051EEB1926D305E24092E893A6D0
PID: 1884 ( 372) C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
size: 1368064
MD5: D3333768300F462F6B309AB53F75BB25
PID: 232 ( 372) C:\WINDOWS\system32\RunDll32.exe
size: 33280
MD5: 081002D8F4176A10BCA3A2F93C4D31C2
PID: 576 (1412) C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
size: 77824
MD5: 8BEE87B1634BBE6E7F5EA4B180A99C6D
PID: 420 (1412) C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
size: 65536
MD5: 16BFB24721A3B38598E7CACC56F453C5
PID: 1856 ( 372) C:\Program Files\Tall Emu\Online Armor\oaui.exe
size: 5519424
MD5: 7BD8ED8A4753908675CBCD7EBA9EBB69
PID: 1560 ( 372) C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
size: 517632
MD5: 107AF2DE3AF10D6D09C1B36FE9EF9156
PID: 540 ( 868) C:\Program Files\Lenovo\TrackPoint\TP4SERVINST.EXE
size: 35616
MD5: B219409358C4CE8CD9B21664D2866234
PID: 244 ( 868) C:\WINDOWS\system32\cisvc.exe
size: 5632
MD5: D8EF9DDF0D8EB0C3ED59C0FABA97D499
PID: 2072 ( 372) C:\Program Files\WallpaperToy\Wallpapertoy.Exe
size: 110592
MD5: C55BB6B2ADCA699620BF7ED0E6075B4E
PID: 2124 ( 868) C:\WINDOWS\system32\inetsrv\inetinfo.exe
size: 15360
MD5: C425CF4E31BF15C302924CD8A803DE93
PID: 2184 ( 372) C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
size: 1806336
MD5: 7515DC58C1296AD6CED6327DBB432E7D
PID: 2300 ( 372) C:\Program Files\YPOPs\YPOPs.exe
size: 1331200
MD5: 0498370F0E95617374FAAE6D234281F7
PID: 2348 ( 868) C:\WINDOWS\System32\snmp.exe
size: 33280
MD5: 35240F37F6947C591CC5B6E8E49F2BBC
PID: 2520 ( 868) C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
size: 45056
MD5: 3978F082274F723AD5A0A8058C2417DD
PID: 2872 ( 868) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 0C54D685CFA1D5054F59F08ADAF71248
PID: 2948 ( 868) C:\WINDOWS\system32\TpKmpSVC.exe
size: 32768
MD5: DFB268FF0A6DCB9280015FF527F892FF
PID: 3656 (2184) C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
size: 1806336
MD5: 7515DC58C1296AD6CED6327DBB432E7D
PID: 3772 (2184) C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
size: 1806336
MD5: 7515DC58C1296AD6CED6327DBB432E7D
PID: 3956 ( 868) C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
size: 247160
MD5: 7FBDDB77353D3EB6ABF70F8122292CEC
PID: 4084 ( 868) C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
size: 345464
MD5: A697E8A40037783358CD5A2CB5F532E0
PID: 2324 ( 868) C:\WINDOWS\System32\alg.exe
size: 44544
MD5: B3F4D7870D95478A4771EB42B7927EAB
PID: 3412 ( 868) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 0C54D685CFA1D5054F59F08ADAF71248
PID: 2332 ( 244) C:\WINDOWS\system32\cidaemon.exe
size: 8192
MD5: 582304F6F1946FA5068CF143D729D7ED
PID: 2448 ( 244) C:\WINDOWS\system32\cidaemon.exe
size: 8192
MD5: 582304F6F1946FA5068CF143D729D7ED
PID: 2116 (3464) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 2097488
MD5: A9A5DB6AC3721BE698B996913693D73F
PID: 3404 (1904) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 5146448
MD5: 2ECA8CDEED7C82F879E766DA92A3561A
PID: 2824 ( 372) C:\Program Files\Winamp\winamp.exe
size: 1307648
MD5: DC737441C92DB834F91B588EF6A12059
PID: 4 ( 0) System
--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 4/25/2008 8:51:53 AM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
http://www.google.com/ie
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://my.yahoo.com/
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
%SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
--- Winsock Layered Service Provider list ---
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 3: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 4: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{DBCE41FD-73C4-4C06-8D1D-A24184EA5C1F}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{DBCE41FD-73C4-4C06-8D1D-A24184EA5C1F}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{29EE967B-DBB1-4FD8-BE1D-95D5CCFFB9A7}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{29EE967B-DBB1-4FD8-BE1D-95D5CCFFB9A7}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{540EDC66-559A-45F3-8DEE-9D7B4A790609}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{540EDC66-559A-45F3-8DEE-9D7B4A790609}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C950863B-73E6-4536-B3A8-9FF67342CC9D}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C950863B-73E6-4536-B3A8-9FF67342CC9D}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP
Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS
Namespace Provider 2: Network Location Awareness (NLA) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace
--- Uninstall list ---
7-Zip 4.42 (7-Zip)
uninstall cmd: "C:\Program Files\7-Zip\Uninstall.exe"
Ad-Aware SE Plus 1.06 (Ad-Aware SE Plus)
uninstall cmd: C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
publisher: Lavasoft
help link:
http://www.lavasoft.com
(AddressBook)
Adobe Flash Player ActiveX 9.0.45.0 (Adobe Flash Player ActiveX)
uninstall cmd: C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
publisher: Adobe Systems Incorporated
help link:
http://www.adobe.com/go/flashplayer_support/
Atomic Clock Sync (Atomic Clock Sync)
uninstall cmd: C:\PROGRA~1\ATOMIC~1\UNWISE.EXE C:\PROGRA~1\ATOMIC~1\INSTALL.LOG
avast! Antivirus 4.8 (avast!)
version (major): 4
version (minor): 8
install location: C:\PROGRA~1\ALWILS~1\Avast4
install source: C:\PROGRA~1\ALWILS~1\Avast4\setup
uninstall cmd: C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
publisher: Alwil Software
help link:
http://www.avast.com
BHODemon 2.0.0.23 (BHODemon_is1)
uninstall cmd: "C:\Program Files\BHODemon 2\unins000.exe"
publisher: Definitive Solutions, Inc.
help link:
http://www.definitivesolutions.com
(Branding)
Cacheman 5.50 5.50 (Cacheman 5.50)
uninstall cmd: C:\PROGRA~1\Cacheman\UNWISE.EXE C:\PROGRA~1\Cacheman\install.dat
publisher: Outer Technologies
comments: Recover RAM and improve performance
Canon iP1600 (CANONBJ_Deinstall_CNMCP75.DLL)
uninstall cmd: C:\WINDOWS\system32\CNMCP75.exe "-PRINTERNAMECanon iP1600" "-HELPERDLLC:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600 Installer\Inst2\cnmis.dll" "-RCDLLcnmi0409.dll"
Capn Voyager 5.3 (Capn Voyager)
uninstall cmd: C:\PROGRA~1\CAPNVO~1\UNWISE.EXE C:\PROGRA~1\CAPNVO~1\INSTALL.LOG
publisher: Nautical Technologies Ltd.
help link:
www.thecapn.com
help telephone: 207-942-4751
CCleaner (remove only) (CCleaner)
uninstall cmd: "C:\Program Files\CCleaner\uninst.exe"
ThinkPad Integrated 56K Modem 7.22.00.52 (CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_05591014)
uninstall cmd: C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_05591014\HXFSETUP.EXE -U -ITkp0559K.INF
(Connection Manager)
dBpoweramp FLAC Codec (dBpoweramp FLAC Codec)
uninstall cmd: "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
dBpoweramp Monkeys Audio Codec (dBpoweramp Monkeys Audio Codec)
uninstall cmd: "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Monkeys Audio Codec.dat
dBpoweramp Music Converter (dBpoweramp Music Converter)
uninstall cmd: "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
dBpoweramp Ogg Vorbis Codec (dBpoweramp Ogg Vorbis Codec)
uninstall cmd: "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
(DirectAnimation)
(DirectDrawEx)
(dlatray.exe)
uninstall cmd: C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
(DXM_Runtime)
IBM ThinkPad EasyEject Utility 2.04 (EasyEject Utility)
uninstall cmd: C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\Unezej.isu -c"C:\Program Files\ThinkPad\Utilities\Tpinsej.dll"
Eraser (Eraser)
install location: C:\Program Files\Eraser
uninstall cmd: "C:\Documents and Settings\All Users\Application Data\{74D61F17-FFC2-41AF-96E5-1DCB0631B6D1}\EraserSetup32.exe" REMOVE=TRUE MODIFY=FALSE
publisher: Heidi Computers Ltd.
comments: All rights reserved
contact: Heidi Computers Ltd.
help link:
http://www.heidi.ie/eraser/
FastStone Image Viewer 3.5 3.5 (FastStone Image Viewer)
uninstall cmd: C:\Program Files\FastStone Image Viewer\uninst.exe
publisher: FastStone Soft
FastStone MaxView 2.1 2.1 (FastStone MaxView)
uninstall cmd: C:\Program Files\FastStone MaxView\uninst.exe
publisher: FastStone Soft.
FLAC 1.1.4b (remove only) 1.1.4b (FLAC)
version (major): 1
version (minor): 1
install location: C:\Program Files\FLAC
uninstall cmd: C:\Program Files\FLAC\uninstall.exe
publisher: Xiph.org
help link:
http://flac.sourceforge.net/documentation.html
Microsoft Flight Simulator 2004 A Century of Flight 9.0 (Flight Simulator 9.0)
version (major): 9
install location: C:\Program Files\Microsoft Games\Flight Simulator 9
uninstall cmd: "C:\Program Files\Microsoft Games\Flight Simulator 9\UNINSTAL.EXE" /runtemp /addremove
publisher: Microsoft
help link:
http://www.microsoft.com/support
readme: C:\Program Files\Microsoft Games\Flight Simulator 9\Readme.rtf
(Fontcore)
GV De Havilland Mosquito for FS2004 (GV De Havilland Mosquito for FS2004)
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\Uninstal.exe
HijackThis 2.0.2 2.0.2 (HijackThis)
uninstall cmd: "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
publisher: TrendMicro
(ICW)
Microsoft Internationalized Domain Names Mitigation APIs (IDNMitigationAPIs)
install date: 20061218
uninstall cmd: "C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
(IE40)
(IE4Data)
(IE5BAKEX)
Windows Internet Explorer 7 20061107.210142 (ie7)
install date: 20061218
publisher: Microsoft Corporation
help link:
http://www.microsoft.com/ie
(IEData)
(InstallShield Uninstall Information)
Canon Utilities PhotoStitch 3.1 3.1.9 (InstallShield_{03CDDD00-BD57-4326-9480-4C74449AF597})
version: 50397193
version (major): 3
version (minor): 1
estimated size: 1364
install date: 20061218
install source: D:\SOFTWARE\PSTITCH\ENGLISH\
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{03CDDD00-BD57-4326-9480-4C74449AF597}
publisher: Canon
comments:
contact:
help link:
help telephone:
readme:
Kaspersky Online Scanner 5.0 (Kaspersky Online Scanner)
install location: C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner
uninstall cmd: C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
publisher: Kaspersky Lab
contact: Customer Support Department
help link:
http://support.kaspersky.com/helpdesk.html?LANG=en
(KB884016)
(KB884267)
(KB885353)
(KB886612)
(KB887078)
(KB887626)
(KB888656)
(KB889858)
(KB891122)
Windows Genuine Advantage Validation Tool (KB892130) (KB892130)
install date: 20070630
publisher: Microsoft Corporation
help link:
http://support.microsoft.com?kbid=892130
(KB892313)
(KB893240)
(KB893241)
(KB893803)
(KB895181)
(KB895316)
(KB895572)
(KB897586)
(KB898549)
(KB900399)
(KB902344)
(KB907658)
(KB911565)
(KB911854)
(KB923689)
Security Update for Windows Internet Explorer 7 (KB928090) 20070117.120000 (KB928090-IE7)
install date: 20070214
uninstall cmd: "C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link:
http://support.microsoft.com?kbid=928090
Security Update for Windows Internet Explorer 7 (KB929969) 20061222.120000 (KB929969)
install date: 20070109
uninstall cmd: "C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link:
http://support.microsoft.com?kbid=929969
Security Update for Windows Internet Explorer 7 (KB931768) 1 (KB931768-IE7)
install date: 20070508
uninstall cmd: "C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link:
http://support.microsoft.com?kbid=931768
Security Update for CAPICOM (KB931906) 2.1.0.2 (KB931906)
uninstall cmd: MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
publisher: Microsoft Corporation
help link:
http://support.microsoft.com?kbid=931906
Hotfix for Microsoft .NET Framework 3.0 (KB932471) 1 (KB932471.T301_380ToU433_380)
uninstall cmd: C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {ECD292A0-0347-4244-8C24-5DBCE990FB40} /package {BAF78226-3200-4DB4-BE33-4D922A799840}
publisher: Microsoft Corporation
help link:
http://support.microsoft.com/kb/932471
Security Update for Windows Internet Explorer 7 (KB933566) 1 (KB933566-IE7)
install date: 20070613
uninstall cmd: "C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link:
http://support.microsoft.com?kbid=933566
Security Update for Windows Internet Explorer 7 (KB937143) 1 (KB937143-IE7)
install date: 20070815
uninstall cmd: "C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link:
http://support.microsoft.com?kbid=937143
Security Update for Windows Internet Explorer 7 (KB938127) 1 (KB938127-IE7)
install date: 20070815
uninstall cmd: "C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link:
http://support.microsoft.com?kbid=938127
Security Update for Windows Internet Explorer 7 (KB939653) 1 (KB939653-IE7)
install date: 20071010
uninstall cmd: "C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link:
http://support.microsoft.com?kbid=939653
Security Update for Windows Internet Explorer 7 (KB942615) 1 (KB942615-IE7)
install date: 20071211
uninstall cmd: "C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link:
http://support.microsoft.com?kbid=942615
Security Update for Windows Internet Explorer 7 (KB944533) 1 (KB944533-IE7)
install date: 20080213
uninstall cmd: "C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link:
http://support.microsoft.com?kbid=944533
Microsoft .NET Framework 1.1 Hotfix (KB928366) (M928366)
uninstall cmd: "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Malwarebytes' Anti-Malware (Malwarebytes' Anti-Malware_is1)
install date: 20080420
install location: C:\Program Files\Malwarebytes' Anti-Malware\
uninstall cmd: "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
publisher: Malwarebytes
help link:
http://www.malwarebytes.org
Microsoft .NET Framework 1.1 (Microsoft .NET Framework 1.1 (1033))
uninstall cmd: msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
readme: file://C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\RepairRedist.htm
(Microsoft Interactive Training)
uninstall cmd: C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
(MobileOptionPack)
Mozilla Firefox (2.0.0.14) 2.0.0.14 (en-US) (Mozilla Firefox (2.0.0.14))
install location: C:\Program Files\Mozilla Firefox
uninstall cmd: C:\Program Files\Mozilla Firefox\uninstall\helper.exe
publisher: Mozilla
comments: Mozilla Firefox
Mozilla Thunderbird (2.0.0.12) 2.0.0.12 (en-US) (Mozilla Thunderbird (2.0.0.12))
install location: C:\Program Files\Mozilla Thunderbird
uninstall cmd: C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
publisher: Mozilla
comments: Mozilla Thunderbird
(MPlayer2)
Microsoft Compression Client Pack 1.0 for Windows XP 1 (MSCompPackV1)
install date: 20061219
uninstall cmd: "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link:
http://go.microsoft.com/fwlink/?LinkId=74087
(MSI30-Beta1)
(MSI30-Beta2)
(MSI30-KB884016)
(MSI30-RC1)
(MSI30-RC2)
(MSI30a-KB884016)
(MSI31-Beta)
(MSI31-RC1)
(NetMeeting)
Network Stumbler 0.4.0 (remove only) (Network Stumbler)
uninstall cmd: "C:\Program Files\Network Stumbler\uninst.exe"
Microsoft National Language Support Downlevel APIs (NLSDownlevelMapping)
install date: 20061218
uninstall cmd: "C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
oggcodecs 0.71.0946 0.71.0946 (oggcodecs)
uninstall cmd: C:\Program Files\illiminable\oggcodecs\uninst.exe
publisher: illiminable
Online Armor 2.1 (OnlineArmor_is1)
install location: C:\Program Files\Tall Emu\Online Armor\
uninstall cmd: "C:\Program Files\Tall Emu\Online Armor\unins000.exe"
publisher: Tall Emu Pty Ltd
help link:
http://www.tallemu.com
(OutlookExpress)
PFJ Fokker F28 v1 (PFJ Fokker F28 v1 for FS2004_is1)
install date: 20071113
install location: C:\Program Files\Microsoft Games\Flight Simulator 9\
uninstall cmd: "C:\Program Files\Microsoft Games\Flight Simulator 9\Aircraft\PFJ Fokker F28-library\unins000.exe"
publisher: PROJECT Fokker Jetline (PFJ)
help link:
http://fokker.avsim.net
1.37 (Power Features)
uninstall cmd: C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\Unbmm.isu -c"C:\Program Files\ThinkPad\Utilities\Tpinsbmm.dll"
ThinkPad Power Management Driver 1.43 (Power Management Driver)
uninstall cmd: RunDll32.exe tpinspm.dll,Uninstall
Intel(R) PRO Network Connections Drivers (PROSet)
uninstall cmd: Prounstl.exe
(RealJukebox 1.0)
uninstall cmd: C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
RealPlayer (RealPlayer 6.0)
uninstall cmd: C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
(RecordNow.exe)
uninstall cmd: C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
(SchedulingAgent)
(SGTRAY.EXE)
uninstall cmd: C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
IBM ThinkPad Configuration 1.36 (ThinkPad Configuration)
uninstall cmd: C:\WINDOWS\IsUninst.exe -fC:\PROGRA~1\ThinkPad\UTILIT~1\UNTPUW.ISU -c"C:\Program Files\ThinkPad\Utilities\Tpinswin.dll"
ThinkPad FullScreen Magnifier 1.10 (ThinkPad FullScreen Magnifier)
uninstall cmd: RunDll32 setupapi.dll,InstallHinfSection DefaultUninstall.NT 132 C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.inf
ThinkPad Software Installer 2.30.0481 (ThinkPadSoftwareInstaller)
uninstall cmd: _tpiu000.exe /U
ThinkPad TrackPoint Driver 4.63.0.0 (TrackPoint)
uninstall cmd: C:\Program Files\Lenovo\TrackPoint\tp4unins.exe
Transload Virtual Airlines Lockheed C-5A Galaxy (Transload Virtual Airlines Lockheed C-5A Galaxy)
uninstall cmd: C:\Program Files\Microsoft Games\Flight Simulator 9\Uninstal.exe
TreeSize Free V1.78 (TreeSize Free_is1)
install location: C:\Program Files\JAM Software\TreeSize\
uninstall cmd: "C:\Program Files\JAM Software\TreeSize\unins000.exe"
publisher: JAM Software
help link: mailto:support@jam-software.com
Tweak UI (Tweak UI 2.10)
uninstall cmd: "C:\WINDOWS\system32\mshta.exe" "res://C:\WINDOWS\system32\TweakUI.exe/uninstall.hta"
Wallpaper Changer for Windows XP (WallpaperToy)
uninstall cmd: C:\WINDOWS\walltoyUninst.exe UNINSTALL
(Wdf01000)
Microsoft Kernel-Mode Driver Framework Feature Pack 1.1 (Wdf01001)
install date: 20070912
uninstall cmd: "C:\WINDOWS\$NtUninstallWdf01001$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
(Wdf01005)
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 (Wdf01007)
install date: 20080128
uninstall cmd: "C:\WINDOWS\$NtUninstallWdf01007$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
Windows Genuine Advantage Validation Tool (KB892130) 1.7.0036.0 (WGA)
install date: 20061218
publisher: Microsoft Corporation
help link:
http://support.microsoft.com?kbid=892130
Windows Genuine Advantage Notifications (KB905474) 1.7.0018.5 (WgaNotify)
install date: 20070329
publisher: Microsoft Corporation
help link:
http://support.microsoft.com?kbid=905474
Windows Imaging Component 3.0.0.0 (WIC)
install date: 20070214
uninstall cmd: "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
Winamp 5.531 (Winamp)
uninstall cmd: "C:\Program Files\Winamp\UninstWA.exe"
publisher: Nullsoft, Inc
help link:
http://forums.winamp.com
Windows Live OneCare safety scanner (Windows Live OneCare safety scanner)
uninstall cmd: RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
Windows Media Format 11 runtime (Windows Media Format Runtime)
uninstall cmd: "C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
help link:
http://go.microsoft.com/fwlink/?LinkId=62768