--- Search result list ---
Win32.Wemon.sh: [SBI $A549C0EB] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\
Win32.Wemon.sh: [SBI $704D6C77] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2009-07-08 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2010-06-29 Includes\Adware.sbi (*)
2010-07-27 Includes\AdwareC.sbi (*)
2010-01-25 Includes\Cookies.sbi (*)
2009-11-03 Includes\Dialer.sbi (*)
2010-07-27 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2010-07-27 Includes\HijackersC.sbi (*)
2010-06-29 Includes\iPhone.sbi (*)
2010-07-27 Includes\Keyloggers.sbi (*)
2010-07-27 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2010-06-01 Includes\Malware.sbi (*)
2010-07-27 Includes\MalwareC.sbi (*)
2010-05-18 Includes\PUPS.sbi (*)
2010-07-20 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-07-27 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-06-29 Includes\Spyware.sbi (*)
2010-07-27 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-07-26 Includes\Trojans.sbi (*)
2010-07-28 Includes\TrojansC-02.sbi (*)
2010-07-28 Includes\TrojansC-03.sbi (*)
2010-07-28 Includes\TrojansC-04.sbi (*)
2010-07-28 Includes\TrojansC-05.sbi (*)
2010-07-28 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
--- System information ---
Windows XP (Build: 2600) Service Pack 3 (5.1.2600)
/ MSXML4SP2: Security update for MSXML4 SP2 (KB954430)
/ MSXML4SP2: Security update for MSXML4 SP2 (KB973688)
/ Windows Media Player: Security Update for Windows Media Player (KB952069)
/ Windows Media Player: Security Update for Windows Media Player (KB954155)
/ Windows Media Player: Security Update for Windows Media Player (KB968816)
/ Windows Media Player: Security Update for Windows Media Player (KB973540)
/ Windows Media Player: Security Update for Windows Media Player (KB978695)
/ Windows XP: Security Update for Windows XP (KB923689)
/ Windows XP: Security Update for Windows XP (KB941569)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB969897)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB971961)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB972260)
/ Windows XP / SP0: Update for Windows Internet Explorer 8 (KB972636)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB974455)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB976325)
/ Windows XP / SP0: Update for Windows Internet Explorer 8 (KB976662)
/ Windows XP / SP0: Update for Windows Internet Explorer 8 (KB976749)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB978207)
/ Windows XP / SP0: Update for Windows Internet Explorer 8 (KB980182)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB981332)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB982381)
/ Windows XP / SP3: Update for Windows XP (KB898461)
/ Windows XP / SP3: Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
/ Windows XP / SP4: Security Update for Windows XP (KB2229593)
/ Windows XP / SP4: Security Update for Windows XP (KB923561)
/ Windows XP / SP4: Security Update for Windows XP (KB938464-v2)
/ Windows XP / SP4: Hotfix for Windows XP (KB942288-v3)
/ Windows XP / SP4: Security Update for Windows XP (KB946648)
/ Windows XP / SP4: Security Update for Windows XP (KB950762)
/ Windows XP / SP4: Security Update for Windows XP (KB950974)
/ Windows XP / SP4: Security Update for Windows XP (KB951066)
/ Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951748)
/ Windows XP / SP4: Update for Windows XP (KB951978)
/ Windows XP / SP4: Security Update for Windows XP (KB952004)
/ Windows XP / SP4: Hotfix for Windows XP (KB952117-v2)
/ Windows XP / SP4: Hotfix for Windows XP (KB952287)
/ Windows XP / SP4: Security Update for Windows XP (KB952954)
/ Windows XP / SP4: Security Update for Windows XP (KB954459)
/ Windows XP / SP4: Hotfix for Windows XP (KB954550-v5)
/ Windows XP / SP4: Security Update for Windows XP (KB954600)
/ Windows XP / SP4: Security Update for Windows XP (KB955069)
/ Windows XP / SP4: Update for Windows XP (KB955759)
/ Windows XP / SP4: Update for Windows XP (KB955839)
/ Windows XP / SP4: Security Update for Windows XP (KB956572)
/ Windows XP / SP4: Security Update for Windows XP (KB956744)
/ Windows XP / SP4: Security Update for Windows XP (KB956802)
/ Windows XP / SP4: Security Update for Windows XP (KB956803)
/ Windows XP / SP4: Security Update for Windows XP (KB956844)
/ Windows XP / SP4: Security Update for Windows XP (KB957097)
/ Windows XP / SP4: Security Update for Windows XP (KB958644)
/ Windows XP / SP4: Hotfix for Windows XP (KB958655-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB958687)
/ Windows XP / SP4: Security Update for Windows XP (KB958869)
/ Windows XP / SP4: Security Update for Windows XP (KB959426)
/ Windows XP / SP4: Security Update for Windows XP (KB960225)
/ Windows XP / SP4: Security Update for Windows XP (KB960803)
/ Windows XP / SP4: Security Update for Windows XP (KB960859)
/ Windows XP / SP4: Hotfix for Windows XP (KB961118)
/ Windows XP / SP4: Security Update for Windows XP (KB961371)
/ Windows XP / SP4: Security Update for Windows XP (KB961501)
/ Windows XP / SP4: Update for Windows XP (KB967715)
/ Windows XP / SP4: Update for Windows XP (KB968389)
/ Windows XP / SP4: Security Update for Windows XP (KB968537)
/ Windows XP / SP4: Security Update for Windows XP (KB969059)
/ Windows XP / SP4: Security Update for Windows XP (KB969897)
/ Windows XP / SP4: Security Update for Windows XP (KB969947)
/ Windows XP / SP4: Security Update for Windows XP (KB970238)
/ Windows XP / SP4: Security Update for Windows XP (KB970430)
/ Windows XP / SP4: Hotfix for Windows XP (KB970653-v3)
/ Windows XP / SP4: Security Update for Windows XP (KB971468)
/ Windows XP / SP4: Security Update for Windows XP (KB971486)
/ Windows XP / SP4: Security Update for Windows XP (KB971557)
/ Windows XP / SP4: Security Update for Windows XP (KB971633)
/ Windows XP / SP4: Security Update for Windows XP (KB971657)
/ Windows XP / SP4: Update for Windows XP (KB971737)
/ Windows XP / SP4: Security Update for Windows XP (KB972270)
/ Windows XP / SP4: Security Update for Windows XP (KB973346)
/ Windows XP / SP4: Security Update for Windows XP (KB973354)
/ Windows XP / SP4: Security Update for Windows XP (KB973507)
/ Windows XP / SP4: Security Update for Windows XP (KB973525)
/ Windows XP / SP4: Update for Windows XP (KB973687)
/ Windows XP / SP4: Update for Windows XP (KB973815)
/ Windows XP / SP4: Security Update for Windows XP (KB973869)
/ Windows XP / SP4: Security Update for Windows XP (KB973904)
/ Windows XP / SP4: Security Update for Windows XP (KB974112)
/ Windows XP / SP4: Security Update for Windows XP (KB974318)
/ Windows XP / SP4: Security Update for Windows XP (KB974392)
/ Windows XP / SP4: Security Update for Windows XP (KB974571)
/ Windows XP / SP4: Security Update for Windows XP (KB975025)
/ Windows XP / SP4: Security Update for Windows XP (KB975467)
/ Windows XP / SP4: Security Update for Windows XP (KB975560)
/ Windows XP / SP4: Security Update for Windows XP (KB975561)
/ Windows XP / SP4: Security Update for Windows XP (KB975562)
/ Windows XP / SP4: Security Update for Windows XP (KB975713)
/ Windows XP / SP4: Hotfix for Windows XP (KB976098-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB977165)
/ Windows XP / SP4: Security Update for Windows XP (KB977816)
/ Windows XP / SP4: Security Update for Windows XP (KB977914)
/ Windows XP / SP4: Security Update for Windows XP (KB978037)
/ Windows XP / SP4: Security Update for Windows XP (KB978251)
/ Windows XP / SP4: Security Update for Windows XP (KB978262)
/ Windows XP / SP4: Security Update for Windows XP (KB978338)
/ Windows XP / SP4: Security Update for Windows XP (KB978542)
/ Windows XP / SP4: Security Update for Windows XP (KB978601)
/ Windows XP / SP4: Security Update for Windows XP (KB978706)
/ Windows XP / SP4: Hotfix for Windows XP (KB979306)
/ Windows XP / SP4: Security Update for Windows XP (KB979309)
/ Windows XP / SP4: Security Update for Windows XP (KB979482)
/ Windows XP / SP4: Security Update for Windows XP (KB979559)
/ Windows XP / SP4: Security Update for Windows XP (KB979683)
/ Windows XP / SP4: Security Update for Windows XP (KB980195)
/ Windows XP / SP4: Security Update for Windows XP (KB980218)
/ Windows XP / SP4: Security Update for Windows XP (KB980232)
/ Windows XP / SP4: Hotfix for Windows XP (KB981793)
--- Startup entries list ---
Located: HK_LM:Run, \\ckaymo\EPSON Stylus CX3800 Series
command: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P35 "\\ckaymo\EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"
file: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
size: 179200
MD5: F6BEE047EFD364569570AA84DEFABD28
Located: HK_LM:Run, Alcmtr
command: ALCMTR.EXE
file: C:\WINDOWS\ALCMTR.EXE
size: 57344
MD5: EA31039E691C6F8F5469649526EEA5FB
Located: HK_LM:Run, Auto EPSON Stylus CX3800 Series on ckaymo
command: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P41 "Auto EPSON Stylus CX3800 Series on ckaymo" /O14 "\\CKAYMO\Epson" /M "Stylus CX3800"
file: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
size: 179200
MD5: F6BEE047EFD364569570AA84DEFABD28
Located: HK_LM:Run, BatteryManager
command: C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
file: C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
size: 2768896
MD5: 4C3D13615705ABE391917F3B773A2E4E
Located: HK_LM:Run, Dell 968 AIO Printer Fax Server
command: "C:\Program Files\Dell 968 AIO Printer\fm3032.exe" /s
file: C:\Program Files\Dell 968 AIO Printer\fm3032.exe
size: 312560
MD5: D85AA2C10DDACBF2ACDD019AA718E99E
Located: HK_LM:Run, dldomon.exe
command: "C:\Program Files\Dell 968 AIO Printer\dldomon.exe"
file: C:\Program Files\Dell 968 AIO Printer\dldomon.exe
size: 455920
MD5: 326C3A0474BA3CDFF451AC9CA0284B32
Located: HK_LM:Run, DMHotKey
command: C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe
file: C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe
size: 466944
MD5: BD6A56DD05AF6B77288BC7A03B492E7D
Located: HK_LM:Run, EDS
command: C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
file: C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
size: 659456
MD5: 57B463FB782C46D30E680ACF8983CFD3
Located: HK_LM:Run, Google Desktop Search
command: "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
file: C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
size: 30192
MD5: 9F5F2F0FB0A7F5AA9F16B9A7B6DAD89F
Located: HK_LM:Run, googletalk
command: C:\Program Files\Google\Google Talk\googletalk.exe /autostart
file: C:\Program Files\Google\Google Talk\googletalk.exe
size: 3739648
MD5: BCD9CBF0621F9A6767276A2E0BF1DD15
Located: HK_LM:Run, HotKeysCmds
command: C:\WINDOWS\system32\hkcmd.exe
file: C:\WINDOWS\system32\hkcmd.exe
size: 166424
MD5: 4C53C44E7C20E65445037954DC3A6BA4
Located: HK_LM:Run, IgfxTray
command: C:\WINDOWS\system32\igfxtray.exe
file: C:\WINDOWS\system32\igfxtray.exe
size: 141848
MD5: 9F6B6D0BE4F77F8693E9FD15D81C8A01
Located: HK_LM:Run, MagicKeyboard
command: C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe
file: C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe
size: 151552
MD5: 30D0552CFA5B80FD6B907DFB9957E68A
Located: HK_LM:Run, MemoryCardManager
command: "C:\Program Files\Dell 968 AIO Printer\memcard.exe"
file: C:\Program Files\Dell 968 AIO Printer\memcard.exe
size: 410864
MD5: A1F947531E295D04A0DF7D6CE61389C8
Located: HK_LM:Run, Nuance PDF Reader-reminder
command: "C:\Program Files\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\PDF Reader\Ereg\Ereg.ini"
file: C:\Program Files\Nuance\PDF Reader\Ereg\Ereg.exe
size: 328992
MD5: 757A595F75E7840A7132EC11E6E6188A
Located: HK_LM:Run, Persistence
command: C:\WINDOWS\system32\igfxpers.exe
file: C:\WINDOWS\system32\igfxpers.exe
size: 137752
MD5: D8F3B455D3FA4B40C9BF544F55647C19
Located: HK_LM:Run, PMBVolumeWatcher
command: C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
file: C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
size: 597792
MD5: F81BB17F053CCF309C49107B0B09F2DA
Located: HK_LM:Run, RTHDCPL
command: RTHDCPL.EXE
file: C:\WINDOWS\RTHDCPL.EXE
size: 16851456
MD5: B376AF03DEFF319984E58ADB84D78FE7
Located: HK_LM:Run, SearchSettings
command: C:\Program Files\pdfforge Toolbar\SearchSettings.exe
file: C:\Program Files\pdfforge Toolbar\SearchSettings.exe
size: 974848
MD5: 589B64EBB836582C46FAD4F16F837815
Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
file: C:\Program Files\Common Files\Java\Java Update\jusched.exe
size: 248552
MD5: 93DB1FF92B03D24738A71E6E4992DFD3
Located: HK_LM:Run, SynTPEnh
command: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
file: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
size: 1044480
MD5: FFD1C110E23B515EE0EFE15D9993EC45
Located: HK_CU:Run, \\BOSS\EPSON Stylus CX3800 Series
where: S-1-5-21-3776996906-2358007643-454500428-1005...
command: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /FU "C:\DOCUME~1\marty\LOCALS~1\Temp\E_S15C.tmp" /EF "HKCU"
file: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
size: 179200
MD5: F6BEE047EFD364569570AA84DEFABD28
Located: HK_CU:Run, Auto EPSON Stylus CX3800 Series on BOSS
where: S-1-5-21-3776996906-2358007643-454500428-1005...
command: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /FU "C:\WINDOWS\TEMP\E_S17C.tmp" /EF "HKCU"
file: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
size: 179200
MD5: F6BEE047EFD364569570AA84DEFABD28
Located: HK_CU:Run, ctfmon.exe
where: S-1-5-21-3776996906-2358007643-454500428-1005...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
Located: HK_CU:Run, Google Update
where: S-1-5-21-3776996906-2358007643-454500428-1005...
command: "C:\Documents and Settings\marty\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
file: C:\Documents and Settings\marty\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
size: 133104
MD5: 626A24ED1228580B9518C01930936DF9
Located: HK_CU:Run, ISUSPM
where: S-1-5-21-3776996906-2358007643-454500428-1005...
command: C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe -scheduler
file: C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe
size: 222496
MD5: 6BF7676296D5359AFC135A5397000053
Located: HK_CU:Run, swg
where: S-1-5-21-3776996906-2358007643-454500428-1005...
command: "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
file: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
size: 39408
MD5: 5D61BE7DB55B026A5D61A3EED09D0EAD
Located: Startup (common), Bluetooth.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
file: C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
size: 580200
MD5: ECBFD7D34F00BE71C95F649F41EADFAB
Located: Startup (disabled), Apache Web Server Monitor (DISABLED)
command: C:\PROGRA~1\Zend\Apache2\bin\APACHE~1.EXE
file: C:\PROGRA~1\Zend\Apache2\bin\APACHE~1.EXE
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: Startup (disabled), Google Calendar Sync (DISABLED)
command: C:\PROGRA~1\Google\GO208F~1\GOOGLE~1.EXE
file: C:\PROGRA~1\Google\GO208F~1\GOOGLE~1.EXE
size: 546288
MD5: F61C52DC14E28DAF9C7EED5E200545F5
Located: Startup (disabled), Microsoft Office (DISABLED)
command: C:\PROGRA~1\MICROS~2\Office\OSA9.EXE -b -l
file: C:\PROGRA~1\MICROS~2\Office\OSA9.EXE
size: 65588
MD5: 0E2EBB670C1476F2964FF292F9E57203
Located: Startup (disabled), Zend Controller (DISABLED)
command: C:\PROGRA~1\Zend\ZENDSE~1\bin\ZENDCO~1.EXE
file: C:\PROGRA~1\Zend\ZENDSE~1\bin\ZENDCO~1.EXE
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: Startup (disabled), OpenOffice.org 3.1 (DISABLED)
command: C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE
file: C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE
size: 1195008
MD5: A9A9F5163F79DF7134BF9735850E2ABD
Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, dimsntfy
command: %SystemRoot%\System32\dimsntfy.dll
file: %SystemRoot%\System32\dimsntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, igfxcui
command: igfxdev.dll
file: igfxdev.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
--- Browser helper object list ---
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} (AcroIEHelperStub)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: AcroIEHelperStub
CLSID name: Adobe PDF Link Helper
Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\
Long name: AcroIEHelperShim.dll
Short name: ACROIE~2.DLL
Date (created): 6/19/2010 2:29:34 PM
Date (last access): 7/31/2010 3:26:40 PM
Date (last write): 6/19/2010 2:29:34 PM
Filesize: 75200
Attributes: archive
MD5: 6D9042F1443A601DA8DC24D991EDDD0A
CRC32: 10990AC8
Version: 9.3.3.177
{AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Google Toolbar Helper
description: Google toolbar
classification: Open for discussion
known filename: googletoolbar.dll<br>googletoolbar*.dll<br>(* = number)<br>googletoolbar_en_*.**-big.dll<br>Googletoolbar_en_*.*.**-deleon.dll
info link:
http://toolbar.google.com/
info source: TonyKlein
Path: C:\Program Files\Google\Google Toolbar\
Long name: GoogleToolbar.dll
Short name: GOOGLE~1.DLL
Date (created): 4/1/2009 9:05:28 PM
Date (last access): 7/31/2010 3:31:08 PM
Date (last write): 7/9/2009 12:51:00 AM
Filesize: 259696
Attributes: archive
MD5: B2A3EE0D6570BAE9BD90892E0009A6AB
CRC32: 230192E8
Version: 6.1.1715.1442
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Google Toolbar Notifier BHO
Path: C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\
Long name: swg.dll
Short name:
Date (created): 12/20/2009 10:07:32 AM
Date (last access): 7/31/2010 2:13:44 PM
Date (last write): 12/20/2009 10:07:32 AM
Filesize: 764912
Attributes: archive
MD5: CD91E666B2446530583FBFFCF537BE4C
CRC32: 34534F50
Version: 5.4.4525.1752
{B922D405-6D13-4A2B-AE89-08A030DA4402} (pdfforge Toolbar)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: pdfforge Toolbar
Path: C:\Program Files\pdfforge Toolbar\IE\1.1.2\
Long name: pdfforgeToolbarIE.dll
Short name: PDFFOR~1.DLL
Date (created): 1/8/2010 3:17:38 AM
Date (last access): 7/31/2010 3:39:32 PM
Date (last write): 1/8/2010 3:17:38 AM
Filesize: 700416
Attributes: archive
MD5: 1C87D50F3792BB26F316FC70F7389157
CRC32: B552AE6D
Version: 1.1.2.16
{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} (Google Dictionary Compression sdch)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: Google Dictionary Compression sdch
CLSID name: Google Dictionary Compression sdch
{DBC80044-A445-435b-BC74-9C25C1C588A9} (Java(tm) Plug-In 2 SSV Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Java(tm) Plug-In 2 SSV Helper
Path: C:\Program Files\Java\jre6\bin\
Long name: jp2ssv.dll
Short name:
Date (created): 6/22/2010 6:07:10 AM
Date (last access): 7/31/2010 3:31:28 PM
Date (last write): 6/22/2010 6:07:10 AM
Filesize: 41760
Attributes: archive
MD5: 213D90E1CE5514318AFA77D8ED016DD8
CRC32: EE52878C
Version: 6.0.210.6
{E312764E-7706-43F1-8DAB-FCDD2B1E416D} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:
Path: C:\Program Files\pdfforge Toolbar\
Long name: SearchSettings.dll
Short name: SEARCH~1.DLL
Date (created): 1/8/2010 1:27:40 AM
Date (last access): 7/31/2010 4:08:22 PM
Date (last write): 1/8/2010 1:27:40 AM
Filesize: 1109504
Attributes: archive
MD5: B2370F9E01367E37D6A5F3BE1A02E1D1
CRC32: 410B8E10
Version: 1.2.3.16
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} (JQSIEStartDetectorImpl)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: JQSIEStartDetectorImpl
CLSID name: JQSIEStartDetectorImpl Class
Path: C:\Program Files\Java\jre6\lib\deploy\jqs\ie\
Long name: jqs_plugin.dll
Short name: JQS_PL~1.DLL
Date (created): 6/22/2010 6:07:10 AM
Date (last access): 7/31/2010 3:28:40 PM
Date (last write): 6/22/2010 6:07:10 AM
Filesize: 79648
Attributes: archive
MD5: 7B0F250208DA410CBB98F725540C6168
CRC32: 1126B1F5
Version: 6.0.210.6
--- ActiveX list ---
{41861299-EAB2-4DCC-986C-802AE12AC499} (RSClientPrint 2005 Class)
DPF name:
CLSID name: RSClientPrint 2005 Class
Installer: C:\WINDOWS\Downloaded Program Files\RSClientPrint.inf
Codebase:
https://grenzebachglierandassociate...&UICulture=1033&ReportStack=1&OpType=PrintCab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: RSClientPrint.dll
Short name: RSCLIE~1.DLL
Date (created): 8/5/2008 9:08:58 AM
Date (last access): 7/14/2010 6:47:08 AM
Date (last write): 8/5/2008 9:08:58 AM
Filesize: 582168
Attributes: archive
MD5: FE068A40A8C42E8488C9BACCEBFC8A59
CRC32: 3805532D
Version: 2005.90.3282.0
{5554DCB0-700B-498D-9B58-4E40E5814405} (RSClientPrint 2008 Class)
DPF name:
CLSID name: RSClientPrint 2008 Class
Installer: C:\WINDOWS\Downloaded Program Files\CONFLICT.1\RSClientPrint-x86.inf
Codebase:
https://grenzebachglierandassociate...&UICulture=1033&ReportStack=1&OpType=PrintCab
Path: C:\WINDOWS\Downloaded Program Files\CONFLICT.1\
Long name: rsclientprint.dll
Short name: RSCLIE~1.DLL
Date (created): 7/10/2008 2:49:14 AM
Date (last access): 7/23/2010 1:18:58 PM
Date (last write): 7/10/2008 2:49:14 AM
Filesize: 583704
Attributes: archive
MD5: 5DF42E28E01872F5CFA95E26D8E5CF00
CRC32: 7BAE5129
Version: 2007.100.1600.22
{6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
DPF name:
CLSID name: WUWebControl Class
Installer: C:\WINDOWS\Downloaded Program Files\wuweb.inf
Codebase:
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1248370283171
description:
classification: Legitimate
known filename: wuweb.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\
Long name: wuweb.dll
Short name:
Date (created): 4/1/2009 8:53:36 PM
Date (last access): 7/31/2010 3:25:26 PM
Date (last write): 8/6/2009 7:24:18 PM
Filesize: 209632
Attributes: archive
MD5: 033AF4CE25B6D871F0DE2C982658E049
CRC32: 2C204902
Version: 7.4.7600.226
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
DPF name:
CLSID name: MUWebControl Class
Installer: C:\WINDOWS\Downloaded Program Files\muweb.inf
Codebase:
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1248624411062
description:
classification: Legitimate
known filename: muweb.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\
Long name: muweb.dll
Short name:
Date (created): 10/16/2008 2:07:48 PM
Date (last access): 7/31/2010 3:25:34 PM
Date (last write): 8/6/2009 7:23:46 PM
Filesize: 215920
Attributes: archive
MD5: A1350D646EF6E57E8F4F33EBE7320D08
CRC32: AB3CA24F
Version: 7.4.7600.226
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_21
Installer:
Codebase:
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_21.dll
Short name: NPJPI1~1.DLL
Date (created): 6/22/2010 2:24:30 AM
Date (last access): 6/22/2074 4:37:36 AM
Date (last write): 6/22/2010 4:36:32 AM
Filesize: 141088
Attributes: archive
MD5: 2CE5AE60752BF2015561A989E0F0859F
CRC32: E77C1309
Version: 6.0.210.6
{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
DPF name: Java Runtime Environment 1.5.0
CLSID name:
Installer:
Codebase:
http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
description:
classification: Legitimate
known filename: NPJPI150.dll
info link:
info source: Safer Networking Ltd.
{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
DPF name: Java Runtime Environment 1.5.0
CLSID name:
Installer:
Codebase:
http://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab
description:
classification: Legitimate
known filename: NPJPI150_08.dll
info link:
info source: Safer Networking Ltd.
{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_21
Installer:
Codebase:
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_21.dll
Short name: NPJPI1~1.DLL
Date (created): 6/22/2010 2:24:30 AM
Date (last access): 7/31/2010 4:22:24 PM
Date (last write): 6/22/2010 4:36:32 AM
Filesize: 141088
Attributes: archive
MD5: 2CE5AE60752BF2015561A989E0F0859F
CRC32: E77C1309
Version: 6.0.210.6
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_21
Installer:
Codebase:
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
description:
classification: Legitimate
known filename: npjpi150_06.dll
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_21.dll
Short name: NPJPI1~1.DLL
Date (created): 6/22/2010 2:24:30 AM
Date (last access): 7/31/2010 4:22:24 PM
Date (last write): 6/22/2010 4:36:32 AM
Filesize: 141088
Attributes: archive
MD5: 2CE5AE60752BF2015561A989E0F0859F
CRC32: E77C1309
Version: 6.0.210.6
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\gp.inf
Codebase:
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
{EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class)
DPF name:
CLSID name: McFreeScan Class
Installer: C:\WINDOWS\Downloaded Program Files\mcfscan.inf
Codebase:
http://download.mcafee.com/molbin/iss-loc/mcfscan/3,0,0,5918/mcfscan.cab
description:
classification: Legitimate
known filename: mcfscan.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\McAfee.com\FreeScan\
Long name: mcfscan.dll
Short name:
Date (created): 3/12/2010 5:02:22 PM
Date (last access): 7/14/2010 6:47:08 AM
Date (last write): 3/12/2010 5:02:22 PM
Filesize: 244488
Attributes: archive
MD5: 24F8C030589F6807A77DE6C16DEB0144
CRC32: 04660683
Version: 3.0.0.5918
--- Process list ---
PID: 0 ( 0) [System]
PID: 640 ( 4) \SystemRoot\System32\smss.exe
size: 50688
PID: 708 ( 640) \??\C:\WINDOWS\system32\csrss.exe
size: 6144
PID: 732 ( 640) \??\C:\WINDOWS\system32\winlogon.exe
size: 507904
PID: 780 ( 732) C:\WINDOWS\system32\services.exe
size: 110592
MD5: 65DF52F5B8B6E9BBD183505225C37315
PID: 792 ( 732) C:\WINDOWS\system32\lsass.exe
size: 13312
MD5: BF2466B3E18E970D8A976FB95FC1CA85
PID: 960 ( 780) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1032 ( 780) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1076 ( 780) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1180 ( 780) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
size: 264800
MD5: 9D67887E051FDFC892CA480D814B06B5
PID: 1284 ( 780) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1324 ( 780) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1488 ( 780) C:\WINDOWS\system32\spoolsv.exe
size: 57856
MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B
PID: 1556 ( 780) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1604 ( 780) C:\Program Files\Application Updater\ApplicationUpdater.exe
size: 380928
MD5: 293E66AA529F0FBA1AA56340E293A389
PID: 1668 ( 780) C:\Program Files\Java\jre6\bin\jqs.exe
size: 153376
MD5: E4AE0CBC0B55A5FAA6996E38CE6C981B
PID: 1724 ( 780) c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
size: 43010392
MD5: B05640AC812FCCB488328DF34E7F663A
PID: 112 (2020) C:\WINDOWS\Explorer.EXE
size: 1033728
MD5: 12896823FB95BFB3DC9B46BCAEDC9923
PID: 540 ( 780) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
size: 360224
MD5: 627FA58ADC043704F9D14CA44340956F
PID: 1204 ( 780) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
size: 98840
MD5: 637A0F23F9012358E92E6F99835494D1
PID: 1248 ( 780) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1228 ( 780) C:\WINDOWS\system32\wdfmgr.exe
size: 38912
MD5: AB0A7CA90D9E3D6A193905DC1715DED0
PID: 1436 ( 780) C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: 037B1E7798960E0420003D05BB577EE6
PID: 252 ( 112) C:\WINDOWS\RTHDCPL.EXE
size: 16851456
MD5: B376AF03DEFF319984E58ADB84D78FE7
PID: 344 ( 112) C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
size: 659456
MD5: 57B463FB782C46D30E680ACF8983CFD3
PID: 364 ( 112) C:\WINDOWS\system32\igfxtray.exe
size: 141848
MD5: 9F6B6D0BE4F77F8693E9FD15D81C8A01
PID: 400 ( 112) C:\WINDOWS\system32\hkcmd.exe
size: 166424
MD5: 4C53C44E7C20E65445037954DC3A6BA4
PID: 408 ( 112) C:\WINDOWS\system32\igfxpers.exe
size: 137752
MD5: D8F3B455D3FA4B40C9BF544F55647C19
PID: 424 ( 112) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
size: 1044480
MD5: FFD1C110E23B515EE0EFE15D9993EC45
PID: 464 ( 112) C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
size: 2768896
MD5: 4C3D13615705ABE391917F3B773A2E4E
PID: 512 ( 960) C:\WINDOWS\system32\igfxsrvc.exe
size: 256536
MD5: F56197D5CBDCC6A87C242DC8B8EEEE34
PID: 560 ( 112) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
size: 30192
MD5: 9F5F2F0FB0A7F5AA9F16B9A7B6DAD89F
PID: 1136 ( 112) C:\Program Files\Dell 968 AIO Printer\dldomon.exe
size: 455920
MD5: 326C3A0474BA3CDFF451AC9CA0284B32
PID: 172 ( 112) C:\Program Files\Dell 968 AIO Printer\memcard.exe
size: 410864
MD5: A1F947531E295D04A0DF7D6CE61389C8
PID: 1320 ( 112) C:\Program Files\Google\Google Talk\googletalk.exe
size: 3739648
MD5: BCD9CBF0621F9A6767276A2E0BF1DD15
PID: 1764 ( 112) C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
size: 597792
MD5: F81BB17F053CCF309C49107B0B09F2DA
PID: 2120 ( 448) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
size: 679936
MD5: 01921762F0525B17057ECEAD1ADFC22D
PID: 2156 ( 468) C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
size: 372736
MD5: 50E187E0EC23EF6C46E68109FB75D31B
PID: 2152 ( 112) C:\Program Files\Common Files\Java\Java Update\jusched.exe
size: 248552
MD5: 93DB1FF92B03D24738A71E6E4992DFD3
PID: 2180 ( 112) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
size: 39408
MD5: 5D61BE7DB55B026A5D61A3EED09D0EAD
PID: 2200 ( 468) C:\Program Files\SAMSUNG\MagicKBD\PerformanceManager.exe
size: 299008
MD5: 3048C513A620837E94F527435012E25B
PID: 2224 ( 112) C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
PID: 2452 ( 960) C:\WINDOWS\system32\igfxext.exe
size: 170520
MD5: 7C36AFFA39FF126EB483F289604EFCC1
PID: 2504 ( 112) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
size: 580200
MD5: ECBFD7D34F00BE71C95F649F41EADFAB
PID: 2736 ( 960) C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
size: 1440384
MD5: F81E9721D98D6CB7D3ECF87DADD5D70E
PID: 3356 ( 780) C:\WINDOWS\system32\dldocoms.exe
size: 595184
MD5: 98D48215940238EBA5606E0D3EB3DE9D
PID: 3544 ( 780) C:\WINDOWS\System32\alg.exe
size: 44544
MD5: 8C515081584A38AA007909CD02020B3D
PID: 3748 ( 112) C:\Documents and Settings\marty\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
size: 945720
MD5: ACFB580CF019C28EC17E34398BE199AA
PID: 468 (3748) C:\Documents and Settings\marty\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
size: 945720
MD5: ACFB580CF019C28EC17E34398BE199AA
PID: 2440 (3748) C:\Documents and Settings\marty\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
size: 945720
MD5: ACFB580CF019C28EC17E34398BE199AA
PID: 2664 (3748) C:\Documents and Settings\marty\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
size: 945720
MD5: ACFB580CF019C28EC17E34398BE199AA
PID: 3060 (3748) C:\Documents and Settings\marty\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
size: 945720
MD5: ACFB580CF019C28EC17E34398BE199AA
PID: 224 (3748) C:\Documents and Settings\marty\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
size: 945720
MD5: ACFB580CF019C28EC17E34398BE199AA
PID: 1868 (3748) C:\Documents and Settings\marty\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
size: 945720
MD5: ACFB580CF019C28EC17E34398BE199AA
PID: 2352 ( 112) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 5365592
MD5: 0477C2F9171599CA5BC3307FDFBA8D89
PID: 3836 ( 112) C:\Program Files\TechSmith\SnagIt 9\Snagit32.exe
size: 6287176
MD5: 1C68ACDF1A8213C62DA1E503ED9AE073
PID: 1496 (3836) C:\Program Files\TechSmith\SnagIt 9\TSCHelp.exe
size: 53064
MD5: 07660E65EEF0A16A94572C2A40DCD54A
PID: 3172 (3836) C:\Program Files\TechSmith\SnagIt 9\SnagPriv.exe
size: 66888
MD5: A03C611C8676FAD6F62B387486DEDB03
PID: 744 (3836) C:\Program Files\TechSmith\SnagIt 9\snagiteditor.exe
size: 7168328
MD5: 70813C4106C871F9BD879A312F677386
PID: 2616 ( 112) C:\Program Files\Safer Networking\RegAlyzer\RegAlyzer.exe
size: 3156208
MD5: EB62144848244C3768A855C6136289A7
PID: 4 ( 0) System
--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 7/31/2010 4:22:29 PM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.google.com
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
http://www.google.com/ie
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
https://login.live.com/login.srf?wa....aspx%253FOrigin%253DPortal&lc=1033&id=252280
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.google.com/ig/redirectdomain?brand=SMSN&bmod=SMSN
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://www.google.com/ie
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
http://www.google.com/search?q=%s
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://www.google.com/ie
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
osoft Corporation