Logfile of HijackThis v1.99.1
Scan saved at 11:07:14 PM, on 11/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\gearsec.exe
C:\windows\System32\tcpsvcs.exe
C:\windows\System32\snmp.exe
C:\windows\System32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\windows\system32\ctfmon.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell AIO 810\dlcgmon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\windows\SOUNDMAN.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\AnalogX\NetStat Live\nsl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\windows\AGRSMMSG.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dlcgcoms.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\windows\system32\cidaemon.exe
C:\windows\explorer.exe
C:\WINDOWS\System32\WISPTIS.EXE
C:\Documents and Settings\Roger\My Documents\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.yahoo.com/search/ie.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://yahoo.sbc.com/dslR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhomeR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [dlcgmon.exe] "C:\Program Files\Dell AIO 810\dlcgmon.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [DLCGCATS] rundll32 C:\windows\System32\spool\DRIVERS\W32X86\3\DLCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [ymetray] "C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe" -preload
O4 - HKLM\..\Run: [NetStat Live] C:\Program Files\AnalogX\NetStat Live\nsl.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
http://support.dell.com/systemprofiler/SysPro.CABO16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=58813O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -
https://www-secure.symantec.com/techsupp/as...rl/LSSupCtl.cabO16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) -
http://www.runaware.com/dolphin/wficat.cabO16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) -
http://dlmanager.akamaitools.com.edgesuite...vex-2.0.5.0.cabO16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/...nst_current.cabO16 - DPF: {49232000-16E4-426C-A231-62846947304B} -
http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cabO16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) -
http://aolcc.aol.com/computercheckup/qdiagcc.cabO16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
http://tools.ebayimg.com/eps/wl/activex/eB...l_v1-0-3-36.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/...b?1141962591593O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1142570135828O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) -
http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cabO16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} -
http://mediaplayer.walmart.com/installer/install.cabO16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) -
http://ipgweb.cce.hp.com/rdqcpc/downloads/msxml4.cabO16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) -
http://javadl-esd.sun.com/update/1.5.0/jin...ows-i586-jc.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) -
http://photo.walmart.com/photo/uploads/Fuj...ploadClient.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cabO16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
https://www-secure.symantec.com/techsupp/as...rl/SymAData.cabO20 - Winlogon Notify: igfxcui - C:\windows\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\windows\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: dlcg_device - - C:\WINDOWS\system32\dlcgcoms.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
AVG Report Log---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 1:16:17 PM 11/23/2006
+ Scan result:
C:\Documents and Settings\Roger\Cookies\roger@cnetaustralia.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Roger\Cookies\roger@libertymutual.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Roger\Cookies\roger@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Roger\Cookies\roger@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Roger\Cookies\roger@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Roger\Cookies\roger@e-2dj6wjkyeldjgdp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Roger\Cookies\roger@e-2dj6wjliemd5wcp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Roger\Cookies\roger@data2.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Roger\Cookies\roger@data3.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Roger\Cookies\roger@data4.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Roger\Cookies\roger@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Roger\Cookies\roger@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Roger\Cookies\roger@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
::Report end
A-SQUAREDa-squared Free - Version 2.1
Scan settings:
Objects: Memory, Traces, Cookies, C:\windows\, C:\Program Files
Scan archives: On
Heuristics: On
ADS Scan: On
Scan start: 11/23/2006 6:08:06 AM
C:\Program Files\adwarealert detected: Trace.Directory.AdwareAlert
C:\Program Files\mail passview detected: Trace.Directory.Mail PassView
C:\Documents and Settings\Roger\Start Menu\Programs\mail passview detected: Trace.Directory.Mail PassView
C:\Documents and Settings\All Users\Start Menu\Programs\spysubtract detected: Trace.Directory.SpySubtract
C:\Program Files\intermute\spysubtract detected: Trace.Directory.SpySubtract
C:\Program Files\intermute\spysubtract\help detected: Trace.Directory.SpySubtract
C:\Program Files\intermute\spysubtract\sounds detected: Trace.Directory.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\pinball detected: Trace.Directory.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat detected: Trace.Directory.SpySubtract
C:\Program Files\intermute\spysubtract\themes detected: Trace.Directory.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default detected: Trace.Directory.SpySubtract
C:\Program Files\aws\weatherbug detected: Trace.Directory.WeatherBug
C:\Program Files\adwarealert\databasenew.ref detected: Trace.File.AdwareAlert
C:\Program Files\mail passview\mailpv.chm detected: Trace.File.Mail PassView
C:\Program Files\mail passview\readme.txt detected: Trace.File.Mail PassView
C:\Documents and Settings\Roger\Start Menu\Programs\mail passview\mail passview help.lnk detected: Trace.File.Mail PassView
C:\Documents and Settings\Roger\Start Menu\Programs\mail passview\mail passview.lnk detected: Trace.File.Mail PassView
C:\Documents and Settings\Roger\Start Menu\Programs\mail passview\readme.lnk detected: Trace.File.Mail PassView
C:\Documents and Settings\All Users\Desktop\spysubtract.lnk detected: Trace.File.SpySubtract
C:\Documents and Settings\All Users\Start Menu\Programs\spysubtract\cwshredder.lnk detected: Trace.File.SpySubtract
C:\Documents and Settings\All Users\Start Menu\Programs\spysubtract\readme.lnk detected: Trace.File.SpySubtract
C:\Documents and Settings\All Users\Start Menu\Programs\spysubtract\spysubtract help.lnk detected: Trace.File.SpySubtract
C:\Documents and Settings\All Users\Start Menu\Programs\spysubtract\spysubtract.lnk detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\en-us.dll detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\help\en-us.chm detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\install.log detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\readme.txt detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\pinball\cl2.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\pinball\cl3.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\pinball\cl4.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\pinball\cld.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\pinball\sc1.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\pinball\sc11.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\pinball\sc2.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\pinball\sc3.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\pinball\sc4.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\pinball\sc5.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\pinball\sc6.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\pinball\scd.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat\cl2.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat\cl3.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat\cl4.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat\cld.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat\sc1.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat\sc10.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat\sc11.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat\sc12.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat\sc3.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat\sc4.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat\sc6.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat\sc7.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat\sc8.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sounds\tomcat\scd.wav detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\spuninst.exe detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\spysub.exe detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\spysubtract.log detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\spyware.dat detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\ssengine.dll detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\sshook.dll detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\bg_common.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\bg_main.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\bg_messagedlg.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_activate.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_add.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_allow.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_bigdelete.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_bighelp.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_bigupdates.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_buy.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_cancel.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_clean.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_cleanprivacy.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_clear.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_config.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_cws.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_dbupdate.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_deny.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_details.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_feedback.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_help.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_home.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_ok.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_options.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_remove.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_restore.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_save.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_scan.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_selecttoggle.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_start.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_stop.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_updates.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\btn_viewlog.ico detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\copyright.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\detailstemplate.htm detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_check_blank.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_check_finished.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_check_off.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_check_on.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_check_working.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_config_adv_scanners.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_config_cleaning.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_config_general.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_config_scanner.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_config_scanners.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_config_scheduling.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_config_sounds.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_msg_bad.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_msg_error.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_msg_good.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_msg_info.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_msg_question.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_msg_uncertain.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_msg_verybad.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_msg_warning.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_scanner_cookie.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_scanner_folder.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_scanner_none.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_scanner_process.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_scanner_regykey.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_scanner_regyval.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_scanner_shortcutlink.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_scanner_suspect.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_scanner_winfile.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\icon_threat_3.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\productlogo.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\splash.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\splashbasic.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\splashpro.bmp detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\themes\default\theme.ini detected: Trace.File.SpySubtract
C:\Program Files\intermute\spysubtract\webregister.exe detected: Trace.File.SpySubtract
C:\Program Files\aws\weatherbug\remove.exe detected: Trace.File.WeatherBug
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mail PassView --> Description detected: Trace.Registry.Mail PassView
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mail PassView --> DisplayName detected: Trace.Registry.Mail PassView
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mail PassView --> DisplayVersion detected: Trace.Registry.Mail PassView
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mail PassView --> InstallLocation detected: Trace.Registry.Mail PassView
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mail PassView --> Publisher detected: Trace.Registry.Mail PassView
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mail PassView --> UninstallString detected: Trace.Registry.Mail PassView
Value: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\SpyOnThis --> Order detected: Trace.Registry.SpyOnThis
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> app-access-scan detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> auto-backup detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> check-network-integrity detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> clean-privacy-on-startup detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> ConfigDir detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> ConnectionType detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> current-theme detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> Days-remaining detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> db-message-on-startup detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> debug-messages detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> Email detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> Evaluation detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> first-run detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> language detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> Message detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> monitor-ms detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> Oem detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> periodic-browser-settings-scan detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> periodic-process-scan detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> ProductTag detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> ProductVersion detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> Pushcount detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> scan-quick-on-win-startup detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> show-splash detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> sound-scheme detected: Trace.Registry.SpySubtract
Value: HKEY_CURRENT_USER\Software\interMute\SpySubtract --> Trial-days detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> app-access-scan detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> auto-backup detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> check-network-integrity detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> clean-privacy-on-startup detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> ConfigDir detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> ConnectionType detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> current-theme detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> db-message-on-startup detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> debug-messages detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> Email detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> Evaluation detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> first-run detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> language detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> monitor-ms detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> Oem detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> periodic-browser-settings-scan detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> periodic-process-scan detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> ProductTag detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> ProductVersion detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> scan-quick-on-win-startup detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> show-splash detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> sound-scheme detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\interMute\SpySubtract --> Trial-days detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpySubtract --> DisplayIcon detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpySubtract --> DisplayName detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpySubtract --> HelpLink detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpySubtract --> InstallLocation detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpySubtract --> Publisher detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpySubtract --> UninstallString detected: Trace.Registry.SpySubtract
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpySubtract --> URLInfoAbout detected: Trace.Registry.SpySubtract
Key: HKEY_CLASSES_ROOT\.vnc detected: Trace.Registry.VNC.CommonComponents
Key: HKEY_CLASSES_ROOT\vncviewer.config detected: Trace.Registry.VNC.CommonComponents
Value: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run --> winvnc detected: Trace.Registry.VNC.CommonComponents
Key: HKEY_LOCAL_MACHINE\software\orl\winvnc3 detected: Trace.Registry.VNC.CommonComponents
Key: HKEY_CLASSES_ROOT\.vnc detected: Trace.Registry.VNC
Value: HKEY_CLASSES_ROOT\CLSID\{62289CBE-3BE2-4ba9-AC20-A911C900039A}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_CLASSES_ROOT\CLSID\{66A21AEA-5A05-46b5-B7CD-C1AAAF4770CD}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_CLASSES_ROOT\CLSID\{795514CB-A81C-48f6-87AB-5B22D433D5D8}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_CLASSES_ROOT\CLSID\{B195FE25-16D9-4d1b-AD10-0701F9A5E277}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_CLASSES_ROOT\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_CLASSES_ROOT\CLSID\{D1698320-77BD-4776-96FD-C3C8D71E57E2}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_CLASSES_ROOT\CLSID\{E28DD8A6-E9BC-4d3e-A7F7-BC9644138CE2}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_CLASSES_ROOT\CLSID\{EC2EC911-E047-4810-9535-6CAFE1ADC3AD}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_CLASSES_ROOT\CLSID\{EDBA2AAC-8A00-4eed-A2E4-74BFB760BE10}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F442C2-5C9E-4ae5-AF7D-FB4E0350C2E3}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{13AFA3A3-5687-487c-93F2-63D5DA468F4E}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32239586-29DE-4268-8AF3-CE7658D3D672}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5AAECB3B-3D56-47c7-8706-77899E73802A}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62289CBE-3BE2-4ba9-AC20-A911C900039A}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66A21AEA-5A05-46b5-B7CD-C1AAAF4770CD}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{795514CB-A81C-48f6-87AB-5B22D433D5D8}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B195FE25-16D9-4d1b-AD10-0701F9A5E277}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA8C584B-209C-4d54-8BB1-8AB5F1DCA18E}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D1698320-77BD-4776-96FD-C3C8D71E57E2}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E28DD8A6-E9BC-4d3e-A7F7-BC9644138CE2}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC2EC911-E047-4810-9535-6CAFE1ADC3AD}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EDBA2AAC-8A00-4eed-A2E4-74BFB760BE10}\InprocServer32 --> ThreadingModel detected: Trace.Registry.YourKeyloggerProgramName
C:\Documents and Settings\Roger\Cookies\roger@com[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Roger\Cookies\roger@com[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Roger\Cookies\roger@media.adrevolver[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Roger\Cookies\roger@zedo[2].txt detected: Trace.TrackingCookie
C:\Program Files\BackWeb\BackWeb Client\6.2.3.66L\Program\runner.exe detected: Adware.BackWeb.a
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe detected: Adware.BackWeb.a
C:\Program Files\Online Services\PeoplePC\Utilities\PPCODIAG.exe detected: Heuristic.Dialer
C:\Program Files\Online Services\PeoplePC\Utilities\PPCODUN.exe detected: Heuristic.Dialer
PANDA ACTIVESCAN
Scanned
Files: 92779
Traces: 84342
Cookies: 157
Processes: 53
Found
Files: 4
Traces: 221
Cookies: 4
Processes: 0
Registry keys: 0
Scan end: 11/23/2006 8:27:44 AM
Scan time: 2:19:38 AM
[size=4]BITDEFENDERQuarantined
Files: 0
Traces: 0
Cookies: 0BitDefender Online Scanner
Scan report generated at: Thu, Nov 23, 2006 - 21:05:53
Scan path: A:\;C:\;D:\;E:\;H:\;I:\;J:\;K:\;
Statistics
Time
03:10:46
Files
1104427
Folders
10295
Boot Sectors
4
Archives
22230
Packed Files
87192
Results
Identified Viruses
1
Infected Files
1
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
1
Engines Info
Virus Definitions
318462
Engine build
AVCORE v1.0 (build 2368) (i386) (Nov 16 2006 11:31:19)
Scan plugins
14
Archive plugins
38
Unpack plugins
6
E-mail plugins
6
System plugins
1
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Program Files\mailpv_setup.exe=>(ZIP Sfx o)=>mailpv.exe
Infected with: Backdoor.Delf.Agf.28.E
C:\Program Files\mailpv_setup.exe=>(ZIP Sfx o)=>mailpv.exe
Disinfection failed
C:\Program Files\mailpv_setup.exe=>(ZIP Sfx o)=>mailpv.exe
Deleted
C:\Program Files\mailpv_setup.exe=>(ZIP Sfx o)
Updated
C:\Program Files\mailpv_setup.exe
Update failed
I am pretty sure I messed up on some of this. I don't know of any problems yet, I wanted to get this to you as soon as possible. It looks like a lot of reading. I know I put too much on here but I didn't want to leave anything out. I hope I at least took care of most of it. I had a couple of problems getting things to work just right but I tried. If there is something I need to redo please let me know. Thank you for taking your time to do all of this. You don't know how much I appreciate it.