****************************************
Result when scanning:
CoolWebSearch.sys 461.000.001 sys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\sys
http://www.kephyr.com/spywarescanner/library/coolwebsearch.sys/index.phtml MS Media Player GUID 404.888.000
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\Settings\Client ID
http://www.kephyr.com/spywarescanner/library/msmediaplayerguid/index.phtml General Virus, Worm, Trojan 294.000.006 Online Service
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Online Service
http://www.kephyr.com/spywarescanner/library/generalvirus/index.phtml ****************************************
Auto start entries:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l
C:\WINDOWS\Installer\{A839294B-70A9-11D5-9F5A-0050DAD742CD}\_5880C51.exe C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Reboot.exe C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l
C:\WINDOWS\Installer\{A839294B-70A9-11D5-9F5A-0050DAD742CD}\_5880C51.exe C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Reboot.exe C:\Documents and Settings\-\Start Menu\Programs\Startup\desktop.ini
C:\Documents and Settings\-\Start Menu\Programs\Startup\desktop.ini
Go here to analyse the startup entries and the associated files:
http://www.kephyr.com/filedb/index.php ****************************************
Run entries:
Pad39A-HtEHL E:\Pad39A.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Pad39A-HtEHL
NeroCheck C:\WINDOWS\System32\\NeroCheck.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\NeroCheck
InCD C:\Program Files\Ahead\InCD\InCD.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\InCD
Online Service C:\WINDOWS\svchost.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Online Service
sys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\sys
HP Lamp C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan\HPLamp.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\HP Lamp
msconfig C:\WINDOWS\system32\msconfig.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\msconfig
SpyHunter
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\SpyHunter
EnigmaPopupStop C:\Program Files\SpyHunter\PopupBlocker\EnigmaPopupStop.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\EnigmaPopupStop
PxClient.exe "C:\Program Files\Proxyconn\PxUi.exe" /Automation
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\PxClient.exe hpppt C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan\hpppt.exe /ICON
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\hpppt
Pop3trap.exe "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Pop3trap.exe WebTrapNT.exe "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WebTrapNT.exe FilterGate C:\PROGRA~1\FILTER~1\filtergate.exe /ASK
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\FilterGate
MSMSGS "C:\Program Files\Messenger\msmsgs.exe" /background
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\MSMSGS
IncrediMail C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\IncrediMail
msconfig C:\WINDOWS\system32\msconfig.exe HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\msconfig
Go here to analyse the run entries and the associated files:
http://www.kephyr.com/filedb/index.php ****************************************
Browser helper objects:
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} not set C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
{53707962-6F74-2D53-2644-206D7942484F} not set C:\PROGRA~1\SPYBOT~1\SDHelper.dll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}
{7D9E713D-0388-4384-BDD8-2A42EB1C4F04} ProxyConn Browser Helper Object C:\PROGRA~1\PROXYC~1\PRXCNB~1.DLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7D9E713D-0388-4384-BDD8-2A42EB1C4F04}