Dear Moderator,
I am relatively new to the world of adware, malware and other such inventions consisting of malicious/annoying code, and it is a great relief for me to discover, that there does exist, those few individuals who are dedicated to both fighting it and assisting others to protect themselves from it. It is in all seriousness that I say I believe :it is people like yourself (someone dedicated to assisting others in their time of need) who make the world a better place. I thank you in advance for any time and effort you expend in the process of assisting me, and I hope that my profusive thanks and whatever experience you may gain through assisting me, are sufficient payment for your kindness.
My System Parameters are as follows:System=Windows XP Pro. ServicePack1, Processor=Pentium 1.5 GHz, 512 MB of RAM
These logs are all from scans that were performed after my computer was fixed using the following tools:Ad-Aware SE Personal, ewido-security suite, WinsockxpFix.exe, Cleanup.exe,CWS Shredder, PCRescue Trial Version, hsremove.exe,Nailfix(nailfix.cmd/Process.exe) and Online scan :Bit Defender Online.
'THIS IS A LAST RESORT'
My computer still performs relatively slow, I receive popups, and I cannot use Internet explorer directly [every time I try I see the following in the status bar (res://C:\WINNT\System32\shdoclc.dll/dnserror.htm) ] (although, I can browse the web through Microsoft Outlook), 1 or more virus detection programs have detected the presence of some sort of unwanted data/programs - I don't know what to remove or how to remove it without causing damage to my system
I hope that these logs will be of some assistance
logs are listed in the following order and are relatively long: HJT Log, ewido, Ad-Aware SE, and XOFTSPY
(All scans were done in "safe mode")
HJT Log:
[log]
Logfile of HijackThis v1.99.1
Scan saved at 12:06:03 AM, on 6/27/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZCfgSvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\NOTEPAD.EXE
C:\Program Files\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Gateway Ink Monitor] "C:\Program Files\Gateway Utilities\GWInkMonitor.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] D:\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=052305 serial=DR12WTX-9999998-YSP lang=EN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [checkrun] C:\winnt\system32\eliteckt32.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINNT\System32\nrarap.exe reg_run
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Documents and Settings\boe2206\My Documents\Mine!\Other than Rhino\Downloads\msnmes\New Folder\MsgPlus.exe"
O4 - HKLM\..\Run: [wiphadt] c:\winnt\system32\dlvxkqp.exe r
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary/Upwords.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {15589FA1-C456-11CE-BF01-000000000000} - http://www.errornuker.com/products/errn2004/installers/default/ErrorNukerInstaller.exe
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {EC51659D-721F-4CBF-9CEA-5E776D89CEA9} - http://www.pacimedia.com/install/pcs_0006.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4519/mcfscan.cab
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O20 - Winlogon Notify: Sebring - C:\WINNT\System32\LgNotify.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Documents and Settings\boe2206\My Documents\Mine!\Other than Rhino\Downloads\msnmes\q\ewido\security suite\ewidoctrl.exe
O23 - Service: Adapter Switching (IntelRoam) - Intel Corporation - C:\Program Files\Intel\Switching\User\RoamSvc.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: RegSrvc - Intel Corporation - C:\WINNT\System32\RegSrvc.exe
O23 - Service: RoamMgr - Intel Corporation - C:\WINNT\System32\RoamMgr.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINNT\System32\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe[/log]
ewido Log:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 11:54:03 PM, 6/26/2005
+ Report-Checksum: 21DB64F0
+ Scan result:
No infected files found!
::Report End
NOTE: During the 'ewido' scan I recieved the following errors:[heuristic rule error,??,38,54,135,97,151,89,??,106,12, and146]??=numbers that I failed to record
NOTE:upon completion of the scan I attempted to refresh the Qurantine list whereas I received the following notification: (Exception:unknown error) and ewido immediately closed thereafter.
Ad-Aware SE Log:
[log]Ad-Aware SE Build 1.06r1
Logfile Created on:Monday, June 27, 2005 12:08:41 AM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R51 21.06.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):46 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Obtain command line of scanned processes
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Write-protect system files after repair (Hosts file, etc.)
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
6-27-2005 12:08:41 AM - Scan started. (Custom mode)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
ModuleName : \SystemRoot\System32\smss.exe
Command Line : n/a
ProcessID : 180
ThreadCreationTime : 6-27-2005 2:44:02 AM
BasePriority : Normal
#:2 [csrss.exe]
ModuleName : \??\C:\WINNT\system32\csrss.exe
Command Line : C:\WINNT\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThre
ProcessID : 228
ThreadCreationTime : 6-27-2005 2:44:14 AM
BasePriority : Normal
#:3 [winlogon.exe]
ModuleName : \??\C:\WINNT\system32\winlogon.exe
Command Line : winlogon.exe
ProcessID : 252
ThreadCreationTime : 6-27-2005 2:44:16 AM
BasePriority : High
#:4 [services.exe]
ModuleName : C:\WINNT\system32\services.exe
Command Line : C:\WINNT\system32\services.exe
ProcessID : 296
ThreadCreationTime : 6-27-2005 2:44:22 AM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
#:5 [lsass.exe]
ModuleName : C:\WINNT\system32\lsass.exe
Command Line : C:\WINNT\system32\lsass.exe
ProcessID : 308
ThreadCreationTime : 6-27-2005 2:44:22 AM
BasePriority : Normal
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
ModuleName : C:\WINNT\system32\svchost.exe
Command Line : C:\WINNT\system32\svchost -k rpcss
ProcessID : 472
ThreadCreationTime : 6-27-2005 2:44:25 AM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
ModuleName : C:\WINNT\system32\svchost.exe
Command Line : C:\WINNT\system32\svchost.exe -k netsvcs
ProcessID : 496
ThreadCreationTime : 6-27-2005 2:44:25 AM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [zcfgsvc.exe]
ModuleName : C:\WINNT\system32\ZCfgSvc.exe
Command Line : n/a
ProcessID : 656
ThreadCreationTime : 6-27-2005 2:44:40 AM
BasePriority : Normal
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
ProductName : ZeroCfgSvc Application
CompanyName : Intel Corporation
FileDescription : ZeroCfgSvc MFC Application
InternalName : ZeroCfgSvc
LegalCopyright : Copyright © 2002 - 2003 Intel Corporation
OriginalFilename : ZeroCfgSvc.EXE
#:9 [explorer.exe]
ModuleName : C:\WINNT\Explorer.EXE
Command Line : C:\WINNT\Explorer.EXE
ProcessID : 732
ThreadCreationTime : 6-27-2005 2:44:41 AM
BasePriority : Normal
FileVersion : 6.00.2800.1221 (xpsp2.030511-1403)
ProductVersion : 6.00.2800.1221
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
#:10 [notepad.exe]
ModuleName : C:\WINNT\system32\NOTEPAD.EXE
Command Line : C:\WINNT\system32\NOTEPAD.EXE C:\Documents and Settings\boe2206\Desktop\c.txt
ProcessID : 1516
ThreadCreationTime : 6-27-2005 3:45:29 AM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Notepad
InternalName : Notepad
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : NOTEPAD.EXE
#:11 [notepad.exe]
ModuleName : C:\WINNT\system32\NOTEPAD.EXE
Command Line : C:\WINNT\system32\NOTEPAD.EXE C:\Program Files\hijackthis\hijackthis.log
ProcessID : 1760
ThreadCreationTime : 6-27-2005 4:06:03 AM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Notepad
InternalName : Notepad
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : NOTEPAD.EXE
#:12 [ad-aware.exe]
ModuleName : C:\Documents and Settings\boe2206\My Documents\Mine!\Other than Rhino\Downloads\msnmes\q\Ad-Aware SE Personal\Ad-Aware.exe
Command Line : "C:\Documents and Settings\boe2206\My Documents\Mine!\Other than Rhino\Downloads\msnmes\q\Ad-Aware SE Personal\Ad-Aware.exe"
ProcessID : 1848
ThreadCreationTime : 6-27-2005 4:08:25 AM
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
MRU List Object Recognized!
Location: : C:\Documents and Settings\boe2206\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office
MRU List Object Recognized!
Location: : C:\Documents and Settings\boe2206\recent
Description : list of recently opened documents
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\adobe\acrobat reader\5.0\avgeneral\crecentfiles
Description : list of recently used files in adobe reader
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\internet explorer\main
Description : last save directory used in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\mediaplayer\medialibraryui
Description : last selected node in the microsoft windows media player media library
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\mediaplayer\player\recentfilelist
Description : list of recently used files in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\mediaplayer\player\settings
Description : last open directory used in jasc paint shop pro
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\mediaplayer\preferences
Description : last cd record path used in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\mediaplayer\preferences
Description : last playlist index loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\mediaplayer\preferences
Description : last search path used in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\microsoft management console\recent file list
Description : list of recent snap-ins used in the microsoft management console
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\office\10.0\clip organizer\search\last query
Description : last query in microsoft clip organizer
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\office\10.0\common\general
Description : list of recently used symbols in microsoft office
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\office\10.0\common\open find\microsoft powerpoint\settings\insert picture\file name mru
Description : list of recent pictured inserted in microsoft powerpoint
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\office\10.0\common\open find\microsoft powerpoint\settings\save as\file name mru
Description : list of recent documents saved by microsoft powerpoint
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\office\10.0\common\open find\microsoft word\settings\open\file name mru
Description : list of recent documents opened by microsoft word
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\office\10.0\common\open find\microsoft word\settings\save as\file name mru
Description : list of recent documents saved by microsoft word
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\office\10.0\common\search\last query
Description : last query in microsoft office
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\office\10.0\excel\recent files
Description : list of recent files used by microsoft excel
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\office\10.0\powerpoint\recent file list
Description : list of recent files used by microsoft powerpoint
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\office\10.0\powerpoint\recent templates
Description : list of recent templates used by microsoft powerpoint
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\office\10.0\powerpoint\recent typeface list
Description : list of recently used typefaces in microsoft powerpoint
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\office\10.0\powerpoint\recenttemplatelist
Description : list of recent templates used by microsoft powerpoint
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\office\10.0\word\recent templates
Description : list of recent templates used by microsoft word
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\search assistant\acmru
Description : list of recent search terms used with the search assistant
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\terminal server client\default
Description : list of recent systems connected to using remote desktop / terminal services
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened
MRU List Object Recognized!
Location: : software\musicmatch
Description : download location of the musicmatch installer
MRU List Object Recognized!
Location: : software\musicmatch\musicmatch jukebox\4.0\fileconv
Description : file conversion location settings in musicmatch jukebox
MRU List Object Recognized!
Location: : software\musicmatch\musicmatch jukebox\4.0\mmradio
Description : information on the last station listened to using musicmatch radio
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\nico mak computing\winzip\filemenu
Description : winzip recently used archives
MRU List Object Recognized!
Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
MRU List Object Recognized!
Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
MRU List Object Recognized!
Location: : S-1-5-21-2785951302-267654794-1488859256-1011\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 46
Deep scanning and examining files ( C: )
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 46
Scanning Hosts file......
Hosts file location:"C:\WINNT\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 46
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 46
12:18:07 AM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:09:25.754
Objects scanned:101762
Objects identified:0
Objects ignored:0
New critical objects:0[/log]
XOFTSPY log:
[log]<?xml version = "1.0"?>
<Session START = "27 Jun 05 00:31:19" END = "27 Jun 05 00:31:19">
<Information Version = "4.13" DatabaseVersion = "94" DataBaseDate = "23 June 2005"/>
<Information OS = "Win XP"/>
<Information ServicePack = "Service Pack 1"/>
<Information WorkingDirectory = "C:\Documents and Settings\boe2206\My Documents\Mine!\Other than Rhino\Downloads\msnmes\q\xoftspy\"/>
<Information Option = "AdvSpyware Scan" State = "ON"/>
<Information Option = "Scan IE Favorites" State = "ON"/>
<Information Option = "Scan Host Files" State = "ON"/>
<Information Option = "Scan Drives" State = "ON"/>
<Information Option = "Do Not Scan Executables" State = "OFF"/>
<Information Option = "Scan Registry" State = "ON"/>
<Information Option = "Scan Active Processes" State = "ON"/>
<Information Option = "Automatic Database Update" State = "OFF"/>
<Information Option = "Automatic Program Update" State = "OFF"/>
<Information Option = "Automatic Removal" State = "OFF"/>
<Information Option = "Exit When Finished" State = "OFF"/>
<Information RootKey = "HKEY_CURRENT_USER" KeyPath = "Software\Microsoft\Windows\CurrentVersion\Run"/>
<Information Value = "ctfmon.exe" Data = "C:\WINNT\System32\ctfmon.exe" MD5 = "414de7cf9d3f19c3ea902f1bb38ec116" Path = ""/>
<Information Value = "MSMSGS" Data = ""C:\Program Files\Messenger\msmsgs.exe" /background" MD5 = "4f5a3d13650b26c9f140027f3878e194" Path = ""/>
<Information RootKey = "HKEY_CURRENT_USER" KeyPath = "Software\Microsoft\Internet Explorer\Main"/>
<Information Value = "NoUpdateCheck" Data = ""/>
<Information Value = "NoJITSetup" Data = ""/>
<Information Value = "Disable Script Debugger" Data = "no"/>
<Information Value = "Show_ChannelBand" Data = "No"/>
<Information Value = "Anchor Underline" Data = "hover"/>
<Information Value = "Cache_Update_Frequency" Data = "Once_Per_Session"/>
<Information Value = "Display Inline Images" Data = "yes"/>
<Information Value = "Do404Search" Data = ""/>
<Information Value = "Local Page" Data = "C:\WINNT\System32\blank.htm"/>
<Information Value = "Save_Session_History_On_Exit" Data = "no"/>
<Information Value = "Show_FullURL" Data = "no"/>
<Information Value = "Show_StatusBar" Data = "yes"/>
<Information Value = "Show_ToolBar" Data = "yes"/>
<Information Value = "Show_URLinStatusBar" Data = "yes"/>
<Information Value = "Show_URLToolBar" Data = "yes"/>
<Information Value = "Start Page" Data = "http://www.msn.com"/>
<Information Value = "Use_DlgBox_Colors" Data = "yes"/>
<Information Value = "Search Page" Data = ""/>
<Information Value = "FullScreen" Data = "no"/>
<Information Value = "Window_Placement" Data = ","/>
<Information Value = "SmoothScroll" Data = ""/>
<Information Value = "Use FormSuggest" Data = "no"/>
<Information Value = "Error Dlg Displayed On Every Error" Data = "no"/>
<Information Value = "HistoryViewType" Data = ""/>
<Information Value = "HistoryTopNSitesView" Data = ""/>
<Information Value = "NotifyDownloadComplete" Data = "yes"/>
<Information Value = "AddToFavoritesExpanded" Data = ""/>
<Information Value = "FormSuggest PW Ask" Data = "no"/>
<Information Value = "Expand Alt Text" Data = "no"/>
<Information Value = "Move System Caret" Data = "no"/>
<Information Value = "NscSingleExpand" Data = ""/>
<Information Value = "NoWebJITSetup" Data = ""/>
<Information Value = "Page_Transitions" Data = ""/>
<Information Value = "FavIntelliMenus" Data = "no"/>
<Information Value = "Enable Browser Extensions" Data = "yes"/>
<Information Value = "UseThemes" Data = ""/>
<Information Value = "Force Offscreen Composition" Data = ""/>
<Information Value = "AllowWindowReuse" Data = ""/>
<Information Value = "Friendly http errors" Data = "no"/>
<Information Value = "ShowGoButton" Data = "yes"/>
<Information Value = "Enable AutoImageResize" Data = "yes"/>
<Information Value = "Enable_MyPics_Hoverbar" Data = "yes"/>
<Information Value = "Play_Animations" Data = "yes"/>
<Information Value = "Play_Background_Sounds" Data = "yes"/>
<Information Value = "Display Inline Videos" Data = "yes"/>
<Information Value = "Show image placeholders" Data = ""/>
<Information Value = "Print_Background" Data = "no"/>
<Information Value = "LastCheckedHi" Data = "yÅ"/>
<Information Value = "Save Directory" Data = "D:\3D-Animation\anima8or\Help\Tutorials\"/>
<Information Value = "AutoSearch" Data = ""/>
<Information Value = "Search Bar" Data = ""/>
<Information Value = "Check_Associations" Data = "yes"/>
<Information Value = "Use Search Asst" Data = "no"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Internet Explorer\Main"/>
<Information Value = "Default_Page_URL" Data = ""/>
<Information Value = "Default_Search_URL" Data = ""/>
<Information Value = "Search Page" Data = ""/>
<Information Value = "Enable_Disk_Cache" Data = "yes"/>
<Information Value = "Cache_Percent_of_Disk" Data = "
"/>
<Information Value = "Delete_Temp_Files_On_Exit" Data = "yes"/>
<Information Value = "Local Page" Data = "%SystemRoot%\system32\blank.htm"/>
<Information Value = "Anchor_Visitation_Horizon" Data = ""/>
<Information Value = "Use_Async_DNS" Data = "yes"/>
<Information Value = "Placeholder_Width" Data = ""/>
<Information Value = "Placeholder_Height" Data = ""/>
<Information Value = "Start Page" Data = "http://www.msn.com"/>
<Information Value = "FullScreen" Data = "no"/>
<Information Value = "Search Bar" Data = ""/>
<Information Value = "Check_Associations" Data = "yes"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Internet Explorer\Search"/>
<Information Value = "SearchAssistant" Data = "http://ie.search.msn.com"/>
<Information Value = "CustomizeSearch" Data = "http://ie.search.msn.com"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Windows\CurrentVersion\Run"/>
<Information Value = "ATIModeChange" Data = "Ati2mdxx.exe" MD5 = "fae95d6d7651b5629c4e19adbc9a3863" Path = "C:\WINNT\system32\Ati2mdxx.exe"/>
<Information Value = "SynTPLpr" Data = "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" MD5 = "c274b074cea7d9f5f67bd4629446d28f" Path = "C:\WINNT\system32\Ati2mdxx.exe"/>
<Information Value = "SynTPEnh" Data = "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" MD5 = "6e3b8a462eed8037343ff7b37e7b53ec" Path = "C:\WINNT\system32\Ati2mdxx.exe"/>
<Information Value = "ATIPTA" Data = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" MD5 = "5af6c15a062a901065a160ac0eef5be9" Path = "C:\WINNT\system32\Ati2mdxx.exe"/>
<Information Value = "Gateway Ink Monitor" Data = ""C:\Program Files\Gateway Utilities\GWInkMonitor.exe"" MD5 = "f95ed236795db5d70e0f36f208b78ac2" Path = "C:\WINNT\system32\Ati2mdxx.exe"/>
<Information Value = "AdaptecDirectCD" Data = ""C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"" MD5 = "98b9c6e3225d94ab34e4d6a64f91f391" Path = "C:\WINNT\system32\Ati2mdxx.exe"/>
<Information Value = "ccApp" Data = ""C:\Program Files\Common Files\Symantec Shared\ccApp.exe"" MD5 = "371d2fa0dfeb9767b3cc7cae1ab21a5a" Path = "C:\WINNT\system32\Ati2mdxx.exe"/>
<Information Value = "vptray" Data = "C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe" MD5 = "5972a3384ebceaeb99f4216e77ebed59" Path = "C:\WINNT\system32\Ati2mdxx.exe"/>
<Information Value = "Microsoft Works Update Detection" Data = "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" MD5 = "86577b9a2bef98e8121cd9262ea15eb6" Path = "C:\WINNT\system32\Ati2mdxx.exe"/>
<Information Value = "CorelDRAW Graphics Suite 11b" Data = "D:\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=052305 serial=DR12WTX-9999998-YSP lang=EN"/>
<Information Value = "QuickTime Task" Data = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" MD5 = "5d22b4258489575412f6d18affc847a2" Path = "C:\WINNT\system32\Ati2mdxx.exe"/>
<Information Value = "checkrun" Data = "C:\winnt\system32\eliteckt32.exe" MD5 = "825b6e2f440cbff32e340ff0d59b66cc" Path = "C:\WINNT\system32\Ati2mdxx.exe"/>
<Information Value = "KavSvc" Data = "C:\WINNT\System32\nrarap.exe reg_run"/>
<Information Value = "MessengerPlus3" Data = ""C:\Documents and Settings\boe2206\My Documents\Mine!\Other than Rhino\Downloads\msnmes\New Folder\MsgPlus.exe"" MD5 = "a995f7d9e1276d7c75a9c69d73073d25" Path = "C:\WINNT\system32\Ati2mdxx.exe"/>
<Information Value = "wiphadt" Data = "c:\winnt\system32\dlvxkqp.exe r"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "SYSTEM\ControlSet001\Services\Winsock2\Parameters\Protocol_Catalog9"/>
<Information Value = "Num_Catalog_Entries" Data = ""/>
<Information Value = "Next_Catalog_Entry_ID" Data = ""/>
<Information Value = "Serial_Access_Num" Data = ""/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "SYSTEM\ControlSet003\Services\Winsock2\Parameters\Protocol_Catalog9"/>
<Information Value = "Num_Catalog_Entries" Data = ""/>
<Information Value = "Next_Catalog_Entry_ID" Data = ""/>
<Information Value = "Serial_Access_Num" Data = ""/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Windows NT\CurrentVersion\Windows"/>
<Information Value = "AppInit_DLLs" Data = "MsgPlusLoader.dll" MD5 = "63daccd8b53a98e9ef5353397c601a52" Path = "C:\WINNT\system32\MsgPlusLoader.dll"/>
<Information Value = "DeviceNotSelectedTimeout" Data = "15"/>
<Information Value = "GDIProcessHandleQuota" Data = "'"/>
<Information Value = "Spooler" Data = "yes"/>
<Information Value = "swapdisk" Data = ""/>
<Information Value = "TransmissionRetryTimeout" Data = "90"/>
<Information Value = "USERProcessHandleQuota" Data = "'"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Windows NT\CurrentVersion\Windows"/>
<Information Value = "AppInit_DLLs" Data = "MsgPlusLoader.dll" MD5 = "63daccd8b53a98e9ef5353397c601a52" Path = "C:\WINNT\system32\MsgPlusLoader.dll"/>
<Information Value = "DeviceNotSelectedTimeout" Data = "15"/>
<Information Value = "GDIProcessHandleQuota" Data = "'"/>
<Information Value = "Spooler" Data = "yes"/>
<Information Value = "swapdisk" Data = ""/>
<Information Value = "TransmissionRetryTimeout" Data = "90"/>
<Information Value = "USERProcessHandleQuota" Data = "'"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler"/>
<Information Value = "{438755C2-A8BA-11D1-B96B-00A0C90312E1}" Data = "Browseui preloader"/>
<Information Value = "{8C7461EF-2B13-11d2-BE35-3078302C2030}" Data = "Component Categories cache daemon"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Windows\CurrentVersion\Policies\System"/>
<Information Value = "dontdisplaylastusername" Data = ""/>
<Information Value = "caption" Data = "STATEMENT"/>
<Information Value = "text" Data = "This is a computer system. "/>
<Information Value = "shutdownwithoutlogon" Data = ""/>
<Information Value = "undockwithoutlogon" Data = ""/>
<Information RootKey = "HKEY_CURRENT_USER" KeyPath = "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run"/>
<Information Value = "rdssfnqv.exe" Data = "C:\WINNT\system\rdssfnqv.exe"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad"/>
<Information Value = "PostBootReminder" Data = "{7849596a-48ea-486e-8937-a2a3009f31a9}"/>
<Information Value = "CDBurn" Data = "{fbeb8a05-beee-4442-804e-409d6c4515e9}"/>
<Information Value = "WebCheck" Data = "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"/>
<Information Value = "SysTray" Data = "{35CEC8A3-2BE6-11D2-8773-92E220524153}"/>
<Information RootKey = "HKEY_CURRENT_USER" KeyPath = "Software\Microsoft\Windows NT\CurrentVersion\Windows"/>
<Information Value = "DebugOptions" Data = "2048"/>
<Information Value = "Documents" Data = ""/>
<Information Value = "DosPrint" Data = "no"/>
<Information Value = "load" Data = ""/>
<Information Value = "NetMessage" Data = "no"/>
<Information Value = "NullPort" Data = "None"/>
<Information Value = "Programs" Data = "com exe bat pif cmd"/>
<Information Value = "NetWarn" Data = "0"/>
<Information RootKey = "HKEY_CURRENT_USER" KeyPath = "Software\Microsoft\Internet Explorer\URLSearchHooks"/>
<Information Value = "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" Data = ""/>
<Scanning TIME = "27 Jun 05 00:31:19">
<PROCESS NAME = "C:\WINNT\system32\services.exe" MD5 = "e3df4a0252d287c44606ee55355e1623"/>
<PROCESS NAME = "C:\WINNT\system32\lsass.exe" MD5 = "b2b6ba905d0e3f8a32a0eb3b4051807b"/>
<PROCESS NAME = "C:\WINNT\system32\svchost.exe" MD5 = "0f7d9c87b0ce1fa520473119752c6f79"/>
<PROCESS NAME = "C:\WINNT\system32\svchost.exe" MD5 = "0f7d9c87b0ce1fa520473119752c6f79"/>
<PROCESS NAME = "C:\WINNT\system32\ZCfgSvc.exe" MD5 = "2e95b5b6d2353d31734631f0865e135f"/>
<PROCESS NAME = "C:\WINNT\Explorer.EXE" MD5 = "a73bc66a95cf4f7b597fc8975778a889"/>
<PROCESS NAME = "C:\WINNT\system32\NOTEPAD.EXE" MD5 = "562a3b03546536307ac47fcb0ceadcde"/>
<PROCESS NAME = "C:\Documents and Settings\boe2206\My Documents\Mine!\Other than Rhino\Downloads\msnmes\q\xoftspy\XoftSpy.exe" MD5 = "25918fbf8f999df39b415caf4f7d4dde"/>
<ScanningRegKeys>
</SW>
<SW NAME = "AFAEnhance">
<REGKEYFOUND NAME = "SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WAFAIE"/>
<REGKEY NAME = "AFAEnhance SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WAFAIE"/>
</ScanningRegKeys>
<ScanningRegValues>
</SW>
<SW NAME = "EliteBar">
<REGVALUE VALUE = "EliteBar software\microsoft\windows\currentversion\run\checkrun"/>
<REGVALUEFOUND NAME = "software\microsoft\windows\currentversion\run\checkrun"/>
</ScanningRegValues>
<ScanningRegValuesChanged>
</ScanningRegValuesChanged>
<FILE PATH = "180Solutions C:\WINNT\salmbundle.exe"/>
<FILE PATH = "C:\WINNT\salmbundle.exe"/>
<FILE PATH = "EliteBar C:\WINNT\System32\eliteckt32.exe"/>
<FILE PATH = "C:\WINNT\System32\eliteckt32.exe"/>
<FILE PATH = "EliteBar C:\WINNT\System32\elitehxc32.exe"/>
<FILE PATH = "C:\WINNT\System32\elitehxc32.exe"/>
<FOLDER PATH = "BookedSpace C:\WINNT\bsx32"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\ASI2.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\ASI50.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\ASICLRE.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\ASICLV.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\ASIEPRE.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\ASIEZ.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\ASIMBC.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\ASIRCPRE.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\ASISS2RE.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\ASISSRE.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPC.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPD.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPE.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPF.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPFAM.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPFI.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPFIN.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPG.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPH.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPHL.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPJ.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPM.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPMTV.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPN.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPR.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPS.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPSHOP.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPSP.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\TMPW.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\WEBS1.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\WEBS2.bsx"/>
<FILE PATH = "BookedSpace C:\WINNT\bsx32\ZNETGP.bsx"/>
<FOLDER PATH = "EliteBar C:\WINNT\EliteToolBar"/>
<FOLDER PATH = "EliteBar C:\WINNT\EliteToolBar\xml"/>
<FOLDER PATH = "EliteBar C:\WINNT\EliteToolBar\xml\categories"/>
<FOLDER PATH = "EliteBar C:\WINNT\EliteToolBar\xml\images"/>
</Scanning>[/log]
P.S.If and when my computer is ever ridded of viruses and other nasties, I would also like to request assistance in fixing my system ,so that it performs with optimal functionality, i.e. repairing Registry Integrity, ActiveX\COM+ActiveX\COM subsections, Windows Shortcuts, if it is not too much to ask. :-|
:) -With Much Gratitude
Y. H.[/