Bazooka Adware and Spyware Scanner Log 305

****************************************
Bazooka Adware and Spyware Scanner v1.13.01
http://www.kephyr.com/spywarescanner/
http://www.kephyr.com/spywarescanner/library/
Log created 22:43:17.
OS: Windows NT 5.1
Database version: 1.860000
Database format version: 1.020000
Database date: 20040308
Current date: 2004-05-17 22:43


****************************************
Result when scanning:

Bargain Buddy 102.997.949 %ProgramsDir%\Bargain Buddy\
C:\Program Files\Bargain Buddy\
http://www.kephyr.com/spywarescanner/library/bargainbuddy/index.phtml

BrowserAid 666.333.911 stlbdist.dll
http://www.kephyr.com/spywarescanner/library/browseraid/index.phtml

Dsi 001.190.001 %SystemDir%\dp-k13w13.exe
C:\WINDOWS\System32\\dp-k13w13.exe
http://www.kephyr.com/spywarescanner/library/dsi/index.phtml

Flingstone Bridge 483.999.000 {9C691A33-7DDA-4C2F-BE4C-C176083F35CF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9C691A33-7DDA-4C2F-BE4C-C176083F35CF}
http://www.kephyr.com/spywarescanner/library/flingstonebridge/index.phtml

Flingstone Bridge 483.999.001 %SystemDir%\bridge.dll
C:\WINDOWS\System32\\bridge.dll
http://www.kephyr.com/spywarescanner/library/flingstonebridge/index.phtml

IEDriver 292.000.000 %SystemDir%\IEDriver\
C:\WINDOWS\System32\\IEDriver\
http://www.kephyr.com/spywarescanner/library/iedriver/index.phtml

IEDriver 292.000.001 IEDriver
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\IEDriver
http://www.kephyr.com/spywarescanner/library/iedriver/index.phtml

Peper Trojan 993.799.000 2P6WFAX43ZHE7C
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\2P6WFAX43ZHE7C
http://www.kephyr.com/spywarescanner/library/pepertrojan/index.phtml

PromulGate 837.700.000 Dpi
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Dpi
http://www.kephyr.com/spywarescanner/library/promulgate/index.phtml

PromulGate 837.700.001 %ProgramsDir%\Common Files\Dpi\
C:\Program Files\Common Files\Dpi\
http://www.kephyr.com/spywarescanner/library/promulgate/index.phtml

PromulGate.pcsvc 434.700.000 Pcsv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Pcsv
http://www.kephyr.com/spywarescanner/library/promulgate.pcsvc/index.phtml

PromulGate.pcsvc 434.700.001 %SystemDir%\pcs\
C:\WINDOWS\System32\\pcs\
http://www.kephyr.com/spywarescanner/library/promulgate.pcsvc/index.phtml

SaveNow 090.090.091 %ProgramsDir%\Save\
C:\Program Files\Save\
http://www.kephyr.com/spywarescanner/library/savenow/index.phtml

Twaintech 523.888.000 %WinDir%\twaintec.dll
C:\WINDOWS\twaintec.dll
http://www.kephyr.com/spywarescanner/library/twaintech/index.phtml

Twaintech 523.888.001 {000020DD-C72E-4113-AF77-DD56626C6C42}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000020DD-C72E-4113-AF77-DD56626C6C42}
http://www.kephyr.com/spywarescanner/library/twaintech/index.phtml

foistware.WildTangent 999.333.999 wcmdmgr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\wcmdmgr
http://www.kephyr.com/spywarescanner/library/wildtangent/index.phtml

foistware.WildTangent 999.888.998 %Windir%\wt
C:\WINDOWS\wt
http://www.kephyr.com/spywarescanner/library/wildtangent/index.phtml

****************************************
Auto start entries:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Quicken\bagent.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Quicken\bagent.exe
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\desktop.ini
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe -q
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\desktop.ini
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe -q

Go here to analyse the startup entries and the associated files:
http://www.kephyr.com/filedb/index.php

****************************************
Run entries:
hpsysdrv c:\windows\system\hpsysdrv.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\hpsysdrv

HotKeysCmds C:\WINDOWS\System32\hkcmd.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\HotKeysCmds

CamMonitor C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\CamMonitor

HP Software Update "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\HP Software Update

HPHUPD05 c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\HPHUPD05

HPHmon05 C:\WINDOWS\System32\hphmon05.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\HPHmon05

KBD C:\HP\KBD\KBD.EXE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\KBD

StorageGuard "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\StorageGuard

TkBellExe "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\TkBellExe

AutoTKit C:\hp\bin\AUTOTKIT.EXE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\AutoTKit

Recguard C:\WINDOWS\SMINST\RECGUARD.EXE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Recguard

NvCplDaemon RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\NvCplDaemon

nwiz nwiz.exe /installquiet /keeploaded /nodetect
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\nwiz

ccApp "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ccApp

ccRegVfy "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ccRegVfy

PS2 C:\WINDOWS\system32\ps2.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\PS2

QuickFinder Scheduler "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\QuickFinder Scheduler

WinampAgent C:\Program Files\Winamp\winampa.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WinampAgent

IPInSightLAN 01 "C:\Program Files\Verizon Online\Visual IP InSight\IPClient.exe" -l
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\IPInSightLAN 01

IPInSightMonitor 01 "C:\Program Files\Verizon Online\Visual IP InSight\IPMon32.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\IPInSightMonitor 01

wcmdmgr C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\wcmdmgr

Share-to-Web Namespace Daemon C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Share-to-Web Namespace Daemon

Microsoft Works Update Detection C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Works Update Detection

HPDJ Taskbar Utility C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\HPDJ Taskbar Utility

mmtask C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\mmtask

Winampa Agent WINAMPA.EXE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Winampa Agent

pbqmequBZ C:\documents and settings\owner\local settings\temp\pbqmequBZ.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\pbqmequBZ

2P6WFAX43ZHE7C C:\WINDOWS\System32\Bin9.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\2P6WFAX43ZHE7C

IEDriver C:\WINDOWS\System32\IEDriver\IEDriver.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\IEDriver

Pcsv C:\WINDOWS\system32\pcs\pcsvc.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Pcsv

Dpi C:\Program Files\Common Files\Dpi\dpi.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Dpi

updmgr C:\Program Files\Common files\updmgr\updmgr.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\updmgr

mswspl
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\mswspl

RunDLL rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\RunDLL

AlcxMonitor ALCXMNTR.EXE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\AlcxMonitor

BackupNotify c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\BackupNotify

NVIEW rundll32.exe nview.dll,nViewLoadHook
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\NVIEW

Notn C:\Documents and Settings\Owner\Application Data\eber.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Notn

WNST C:\WINDOWS\System32\wnsapitr.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\WNST


Go here to analyse the run entries and the associated files:
http://www.kephyr.com/filedb/index.php

****************************************
Browser helper objects:

{00000000-0000-0000-0000-000000000221} IE Agent C:\Program Files\ClearSearch\CSIE.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000000-0000-0000-0000-000000000221}

{000020DD-C72E-4113-AF77-DD56626C6C42} not set C:\WINDOWS\twaintec.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000020DD-C72E-4113-AF77-DD56626C6C42}

{02478D38-C3F9-4efb-9B51-7695ECA05670} not set C:\WINDOWS\Downloaded Program Files\ycomp5_3_12_0.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} not set C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

{243B17DE-77C7-46BF-B94B-0B5F309A0E64} not set C:\Program Files\Microsoft Money\System\mnyside.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{243B17DE-77C7-46BF-B94B-0B5F309A0E64}

{4FC95EDD-4796-4966-9049-29649C80111D} NavErrRedir Class C:\PROGRA~1\INCRED~1\BHO\INCFIN~2.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4FC95EDD-4796-4966-9049-29649C80111D}

{9C691A33-7DDA-4C2F-BE4C-C176083F35CF} not set C:\WINDOWS\System32\bridge.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9C691A33-7DDA-4C2F-BE4C-C176083F35CF}

{BDF3E430-B101-42AD-A544-FADC6B084872} not set c:\Program Files\Norton AntiVirus\NavShExt.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}

{FDD3B846-8D59-4ffb-8758-209B6AD74ACC} not set Error when opening a registry key, the key doesn't exist. Key: HKEY_CLASSES_ROOT\CLSID\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}\InprocServer32

System error message: The system cannot find the file specified.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}


****************************************
Toolbars:

{8E718888-423F-11D2-876E-00A0C9082467} C:\WINDOWS\System32\msdxm.ocx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{8E718888-423F-11D2-876E-00A0C9082467}

Error when opening a registry key, the key doesn't exist. Key: HKEY_CLASSES_ROOT\CLSID\\InprocServer32

System error message: The system cannot find the file specified.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\

{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}

{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} c:\Program Files\Norton AntiVirus\NavShExt.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}

{EF99BD32-C1FB-11D2-892F-0090271D4F88} C:\WINDOWS\Downloaded Program Files\ycomp5_3_12_0.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} C:\Program Files\MSN Toolbar\01.01.1601.0\en-us\msntb.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}

{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}

{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}

{0E5CBF21-D15F-11D0-8301-00AA005B4383} C:\WINDOWS\system32\SHELL32.dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}

{01E04581-4EEE-11D0-BFE9-00AA005B4383} C:\WINDOWS\System32\browseui.dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{01E04581-4EEE-11D0-BFE9-00AA005B4383}

{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} c:\Program Files\Norton AntiVirus\NavShExt.dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}

{EF99BD32-C1FB-11D2-892F-0090271D4F88} C:\WINDOWS\Downloaded Program Files\ycomp5_3_12_0.dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} C:\Program Files\MSN Toolbar\01.01.1601.0\en-us\msntb.dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}

{4D5C8C25-D075-11d0-B416-00C04FB90376} C:\WINDOWS\System32\shdocvw.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}

{8F4902B6-6C04-4ade-8052-AA58578A21BD} Error when opening a registry key, the key doesn't exist. Key: HKEY_CLASSES_ROOT\CLSID\{8F4902B6-6C04-4ade-8052-AA58578A21BD}\InprocServer32

System error message: The system cannot find the file specified.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{8F4902B6-6C04-4ade-8052-AA58578A21BD}

{30D02401-6A81-11D0-8274-00C04FD5AE38} C:\WINDOWS\System32\browseui.dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{30D02401-6A81-11D0-8274-00C04FD5AE38}

{32683183-48a0-441b-a342-7c2a440a9478} C:\WINDOWS\System32\browseui.dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}

{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1} C:\WINDOWS\system32\SHELL32.dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}

{EFA24E61-B078-11D0-89E4-00C04FC9E26E} C:\WINDOWS\System32\shdocvw.dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}

{EFA24E62-B078-11D0-89E4-00C04FC9E26E} C:\WINDOWS\System32\shdocvw.dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}


****************************************
All processes:

[System Process]
System
smss.exe
csrss.exe
winlogon.exe
services.exe
lsass.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
spoolsv.exe
ccEvtMgr.exe
Navapsvc.exe
omniServ.exe
svchost.exe
OPXPApp.exe
explorer.exe
hpsysdrv.exe
hkcmd.exe
HpqCmon.exe
hpwuSchd.exe
hphmon05.exe
kbd.exe
realsched.exe
ccApp.exe
IPClient.exe
ipmon32.exe
hpgs2wnd.exe
WkUFind.exe
wcmdmgr.exe
hpgs2wnf.exe
mmtask.exe
pbqmequBZ.exe
pcsvc.exe
dpi.exe
updmgr.exe
eber.exe
wnsapitr.exe
SpamSubtract.exe
Kbk7.exe
VjliI50.exe
IEXPLORE.EXE
spywarescanner.exe
msmsgs.exe

Go here to analyse the running processes:
http://www.kephyr.com/filedb/index.php

****************************************
Internet Explorer Settings:

Default_Page_URL http://us9.hpwis.com/
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL

Default_Search_URL http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL

Local Page C:\WINDOWS\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page

Search Bar http://srch-us9.hpwis.com/
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar

Search Page http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page

Start Page about:blank
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page

SearchAssistant http://ie.search.msn.com/en-us/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant

CustomizeSearch http://ie.search.msn.com/en-us/srchasst/srchcust.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch

http://
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix\

www http://
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\www

http://home.microsoft.com/access/autosearch.asp?p=%s
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\

provider MSN
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\provider

Default_Page_URL http://us9.hpwis.com/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Page_URL

Default_Search_URL http://srch-us9.hpwis.com/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Search_URL

Local Page C:\WINDOWS\System32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page

Search Bar file://C:\WINDOWS\System32\sb.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar

Search Page http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page

Start Page http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=5.1&bm=ho_home
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page

Use Search Asst no
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Use Search Asst


****************************************




Related links

Bazooka - Free scan for spyware, adware, trojan horses, keyloggers, etc. Detects more than 500 potentially unwanted applications. Freeware!

The File Database - Search the file database for more information. Free!

PopUp Blocker Test - Find out if your pop-up killer can handle all pop-ups. Free!

Kephyr Labs - Find out what is going on at Kephyr. Try products in an early stage of development.



FreeFixer
Read more about FreeFixer, Kephyr's latest spyware removal tool.
Home & Products |  Legal |  Privacy |  Search

© Kephyr, 2003-2012. HtmlTidy, HTML 4.01, CSS andy@kephyr.com