Arcade File Downloads
Email
Confirm email
Articles Spyware Removal File Help Startup DB Tips Service DB News Hijack This! Analyzer

 

Bad - Remove almost always
OK Most of the time - don't need to touch
Probably not needed - Safe to remove
Generally harmless - third party applications
Bad if you don't know what it is
Unknown Item - Investigate further

Logfile of HijackThis v1.99.1
Up To Date Version of HijackThis
You are using the latest version of HijackThis. Check www.merijn.org frequently for updates.

Scan saved at 6:49:54 PM, on 5/18/06
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
kernel32.dll

What is it?

kernel32.dll is a very important?Windows system file.

What does it do?

Kernel32.dll is considered?the core of the Windows opperating system. It handles Memory addressing, Input/output, Interupts etc.

More info:

There are a few common?error popups that list kernel32.dll as the culprit.?Search microsofts knowledge base at support.microsoft.com for more about kernel errors and patches to fix them.

Keep an eye on this [url=http://www.google.com/search?hl=en&lr=&q=KERNEL32.DLL+%2Bvirus+%2Bspyware+%2Badware]google search[/url] Watch for kernel32.dll with viruses, spyware adware.


C:\WINDOWS\SYSTEM\MSGSRV32.EXE
MSGSRV32.EXE
MSGSRV32.EXE is a part of Windows 9x/Me. This is a 32 bit message server.? For more information on its function and why it's needed, see here.

C:\WINDOWS\SYSTEM\SPOOL32.EXE
SPOOL32.EXE
SPOOL32.EXE is your windows printer spool handler and is important for a stable windows OS.

C:\WINDOWS\SYSTEM\MPREXE.EXE
MPREXE.EXE
MPREXE.EXE is a part of Windows 9x/Me which allows the computer to use multiple network protocols and/or multiple network interface cards. This should always be a background process and shouldn't be ended.

C:\WINDOWS\SYSTEM\STIMON.EXE
STIMON.EXE
STIMON.EXE is a windows process that provides extra functionality when you plug in a scanner, digital camera or some type of video/image hardware.

It is called Still Image Monitor and you can read more about it here. Quote:
Still Image Monitor (Stimon.exe) is a tool that is installed by Windows Millennium Edition (Me) and Windows 98 when a Universal Serial Bus (USB) scanning device is successfully enumerated. Stimon.exe is configured to start automatically during the Windows startup process, and is loaded from the following registry key:

C:\WINDOWS\SYSTEM\MDM.EXE
mdm.exe

What is it?
Machine Debug Manager - mdm.exe

What does it do?
mdm.exe - Below is a direct quote from Microsoft found on THIS page:

The Machine Debug Manager, Mdm.exe, is a program that is installed with the Microsoft Script Editor to provide support for program debugging. The Microsoft Script Editor is included with Microsoft Office 2000, and also can be obtained from the Microsoft Windows Update Web site.

The Machine Debug Manager runs as a service and is loaded when your computer starts. If you do not use your computer for debugging purposes, you can safely turn off the Machine Debug Manager.

This is the user shell, which we see as the familiar taskbar, desktop, and so on. This process isn't as vital to the running of Windows as you might expect, and can be stopped (and restarted) from Task Manager, usually with no negative side effects on the system.

Unless you're a code monkey doing some debugging turn this sucker off!

More Info
More Info

Virus Precaution:
The original file from Microsoft gets placed at C:WINDOWSSystem32mdm.exe . if you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses. At this time I have not found ANY viruses that run themselves using this filename. All of the results currently affect this file in some way, but do not actually run as this filename.


C:\WINDOWS\SYSTEM\MSTASK.EXE
mstask.exe
What is it?
MS Task scheduler - mstask.exe

What does it do?
mstask.exe - Gives you the ability to schedule tasks to be run at certain on certain days and times. I use it to automate as many tasks as I possibly can.

Virus Precaution:
When googling I was able to find

W32/Opaserv -H
W32.Myparty@mm

The mstask.exe which is from Microsoft is located at c:windowsSystem32mstask.exe . If you find it anywhere else then you should be suspicious for sure.

C:\WINDOWS\SYSTEM\SSDPSRV.EXE
ssdpsrv.exe

What is it?

SSDPSRV.EXE is related to services for?network?plug and play functionality known as Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA)

What does it do?

Starts up a web server on port 5000

More info:

Found [url=http://startup.iamnotageek.com/srch-ssdpsrv.exe.html]here[/url] in our startup db.


C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINJECT.EXE
CSINJECT.EXE
CSINJECT.EXE - This process is from Norton Cleansweep, this is mandatory for the correct functioning of this product, this monitors your systems local cofiguration file to find changes made by programs, this is non essential only terminate if causing problems.

C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
KB891711.EXE
KB891711.EXE - This process was installed mainly in Windows 98 it is a Windows security update process it keeps your computer safe from internet bound threats, this is important for a secure computer.

C:\WINDOWS\SYSTEM\mmtask.tsk
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
STMGR.EXE
STMGR.EXE - Microsoft PC state manager

C:\WINDOWS\TASKMON.EXE
taskmon.exe
taskmon.exe - The Task Monitor checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase)

C:\WINDOWS\SYSTEM\SYSTRAY.EXE
systray.exe

What is it?

Your PC's system tray - Systray.exe

What does it do?

Systray.exe is the?windows service?which handles your system tray - the collection of icons found typically at the bottom right hand of your screen. MS also describe it as:

Systray.exe is a tool for system taskbar notifications. The taskbar provides a location for programs and hardware devices to display icons. For example, if your computer supports advanced power management (APM), a Battery Meter icon can appear on the taskbar.

Virus Precautions

Systray.exe is legitimately found in C:WINDOWSSYSTEM32, but?has been known to host viruses and trojans, and being the popular file that it is, it has also been passed off by many viruses and trojans in different folders. Some of?these include:

32.Ghotex.A - Symantec
Backdoor.IRC.Aladinz.P - Symantec
Backdoor.IRC.Mutebot - Symantec
IRC/Flood.av - NetworkAccosiates
W32.HLLP.Systemp - Symantec

In any case, this Google search should keep you up to date on any virus found to reside in systray.exe or create its own phony systray.exe.

How can you tell if your systray.exe is infected outside of a virus scanner? It is said under Windows2000 and XP systray.exe should NOT be displayed in your list of processes in the taskmanager. If you find systray.exe in your taskmanager chances are you have an infection.


C:\PROGRAM FILES\BROWSER MOUSE\BROWSER MOUSE\1.0\LWBWHEEL.EXE
lwbwheel.exe
Mouse driver - required if you use non-standard Windows driver features

C:\WINDOWS\POWERS.EXE
PowerS.exe
PowerS.exe - This is from the University of Ottawa, it is part of Biomech Planar motion analysis system for power analysis and graphing, this is non essential only terminate if causing problems.

C:\PROGRAM FILES\HP CD-DVD\UMBRELLA\DVDTRAY.EXE
DVDTray.exe
HP CD/DVD Tray icon installed with the DVD writer software. Periodically checks for new drive firmware
Required: No

C:\WINDOWS\SYSTEM\WMIEXE.EXE
wmiexe.exe

What is it?
Windows Management Instrumentation - wmiexe.exe

What does it do?
wmiexe.exe - Here's a direct quote from MS about this: (source)
Effective management of PC and server systems in an enterprise network benefits from well-instrumented computer software and hardware, which allow system components to be monitored and controlled, both locally and remotely. Microsoft is committed to simplifying instrumentation of hardware and software under Microsoft? Windows? operating systems. Microsoft is also committed to providing consistent access to this instrumentation for both Windows-based management systems and legacy management systems that are hosted in other environments.

In Win98/NT/2000 this is a seperate process whereas in XP it is a part of svchost

More Info
More Info

Virus Precaution:
The original wmiexe.exe from Microsoft gets placed in the Located at C:WINDOWSSystem32wmiexe.exe . If you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses. At this time I have not found ANY viruses that run themselves using this filename. All of the results currently affect this file in some way, but do not actually run as this filename.


C:\WINDOWS\PCTVOICE.EXE
PCTVOICE.EXE
PCTVOICE.EXE - This process is with the backround task installed PCTEL modem, for a secure computer do not remove.

C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
realsched.exe
What is it?
Real Player Scheduler - realsched.exe


What does it do?

realsched.exe - The Real Player automatic update utility. It has no real functional purpose. I would certainly stop this from running on startup.

Virus Precautions:
You'll want to keep an eye on this google search for any known viruses. The normal location of realsched.exe is C:Program FilesCommon FilesRealUpdate_OBrealsched.exe


.

C:\WINDOWS\CFG32.EXE
cfg32.exe
We Don't know! Please post a comment with information about this file

C:\WINDOWS\PBOBXG.EXE
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOTASKBARICON.EXE
RoboTaskBarIcon.exe
Roboform - password manager and web form filler. Will work without this startup entry, as the "active" component is an integrated Internet Explorer browser plugin More information can be found here.

Quote:
Save and Remember Online Passwords
Every other site these days forces you to create a UserID and Password combination. RoboForm saves the day by saving the online passwords (AutoSave dialog) and then filling login forms from the saved data (AutoFill dialog).


C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\DISTILLR\ACROTRAY.EXE
acrotray.exe

What is it?
Adobe Acrobat Distiller - acrotray.exe

What does it do?
While printing large files to the PDF format this process may consume large chunks of your CPU. Do not end this process if you're printing something to PDF.

Virus Precautions:
You'll want to keep an eye on this google search for any known viruses. The normal location of this file is C:Program FilesAdobeAcrobat 6.0Distillracrotray.exe


Also .


C:\WINDOWS\GKFFX.EXE
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

C:\PROGRAM FILES\WLAN\802.11B+G USB WLAN\ZDWLAN.EXE
ZDWlan.exe
Wireless network utility, please comment about this file and what all it does.

C:\WINDOWS\GKFFX.EXE
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

C:\WINDOWS\GKFFX.EXE
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

C:\WINDOWS\CFG32A.EXE
cfg32a.exe
We Don't know! Please post a comment with information about this file

C:\WINDOWS\SYSTEM\DDHELP.EXE
DDHELP.EXE
DDHELP.EXE is a part of DirectX. This is DirectDraw Helper. You should leave this process as is if you like your video and audio :)

C:\WINDOWS\EXPLORER.EXE
explorer.exe

What is it?
Windows Explorer - explorer.exe

What does it do?
explorer.exe - Below is a direct quote from Microsoft found on THIS page:

This is the user shell, which we see as the familiar taskbar, desktop, and so on. This process isn't as vital to the running of Windows as you might expect, and can be stopped (and restarted) from Task Manager, usually with no negative side effects on the system.

I have found that stopping this process is needed sometimes to stop some other processes.

More Info
More Info

Virus Precaution:
The original file from Microsoft gets placed at C:WINDOWSSystem32explorer.exe . if you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses. There's only one unique virus found through this search. All of the results are the various names of this single virus.

Deloder-A @ Sophos
MyDoom.B @ Symantec


C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE
HijackThis.exe
This is our favorite application for fighting against malware and other trashy application that bog systems down. Our guide to using this software can be found here. We have also taken the time to write a system to process the log files created from this application here.


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.google.com/mail/
Internet Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
Internet Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!

R3 - Default URLSearchHook is missing
Default Search Page
When using the search toolbar this is your default search. Should be either yahoo, msn or google cause all others suck

O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_5_7_1.DLL
Unnamed BHO
Ycomp*_*_*_*.dll yt.dll - Yahoo Companion http://companion.yahoo.com/

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\ACROBAT\ACTIVEX\ACROIEHELPER.OCX
AcroIEhelper.ocx AcroIEhelper.dll - Adobe Acrobat reader http://www.adobe.com/products/acrobat/reads
AcroIEhelper.ocx AcroIEhelper.dll - Adobe Acrobat reader http://www.adobe.com/products/acrobat/readstep2.html

O2 - BHO: (no name) - SOFTWARE - (no file)
File Missing
When a file is missing, you should always have HijackThis fix the item.

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
SDhelper.dll - SpyBot Search&Destroy http://www.safer-networking.org/index.php
SDhelper.dll - SpyBot Search&Destroy http://www.safer-networking.org/index.php

O2 - BHO: Distributed Transaction Coordinator Class - {E9DC6D60-BBD5-4FEE-88CF-82B5E267ED27} - C:\WINDOWS\SYSTEM\MSDTC32.DLL
msdtc32.dll - Microsoft Distributed Transaction Coordinator Extension - see here http://www.microsof
msdtc32.dll - Microsoft Distributed Transaction Coordinator Extension - see here http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/BookofSP1/8fcbafc0-26ff-4091-9dfd-e029d5a1af7d.mspx

O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
Unnamed BHO
RoboForm.dll - RoboForm http://www.roboform.com/

O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\CFG32O.DLL
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\CFG32R.DLL
cfg32r.dll - BookedSpace http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076996 adware varia
cfg32r.dll - BookedSpace http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076996 adware variant

O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_5_7_1.DLL
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
ScanRegistry
"Added by the NERTE TROJAN! Not to be confused with the real ScanRegistry - which is a vital Windows file. This version has the executable as nsrvnt.exe not scanregw.exe"

O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
TaskMonitor
"The Task Monitor checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users

O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
PCHealth
"This is a ""scheduler"" and does not turn off PC Health. For more information refer here"

O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
SystemTray
"For Win9x/Me - System Tray Services. Provides the Volume Control

O4 - HKLM\..\Run: [Microsoft WebServer] C:\Program Files\WebSvr\System\svctrl /init
Microsoft Webserver
Personal web server program which enables you to create and host a web server from your computer. Not required for most people

O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
LWBMOUSE
Mouse driver - required if you use non-standard Windows driver features

O4 - HKLM\..\Run: [PowerS] "C:\WINDOWS\PowerS.exe"
PowerS
"ProlinkTest for either their AGP graphics card or TV/FM capture card. Is it required?"

O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" /NOUI
DVDBitSet
DVD+RW Drive/Disc Compatibility Setting. Installed with HP DVD+RW drives to enhance compatibility with existing readers. You can also set a DVD+RW default drive write mode which is always used

O4 - HKLM\..\Run: [DVDTray] "C:\Program Files\HP CD-DVD\Umbrella\DVDTray.exe
DVDTray
HP CD/DVD Tray icon installed with the DVD writer software. Periodically checks for new drive firmware

O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
PV92TRAY
"PCtel HSP V.92 modem configuration utility"

O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
PCTVOICE
"The program PCTVoice is used by the modem to interface with your computer and also used for some V.80 functions for Video Conferencing. if you uncheck it

O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
LoadPowerProfile
"Added by the CABRO TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
TkBellExe
"Application Scheduler installed along with RealOne Player. Once installed

O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
RegShave
"Part of the USB driver for your Fuji digital cameras - used when uninstalling the USB drivers

O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
QuickTime Task
System Tray access to Apple's "Quick Time" viewer from version 5 onwards

O4 - HKLM\..\Run: [defender] C:\\DEFENDER19A.exe
defender
"DollarRevenue adware"

O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
Configuration Manager
"Added by the SDBOT TROJAN!"

O4 - HKLM\..\Run: [prssxe] C:\WINDOWS\pbobxg.exe reg_run
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O4 - HKLM\..\Run: [SpywareBot] C:\PROGRAM FILES\SPYWAREBOT\SpywareBot.exe -boot
SpywareBot
"SpywareBot spyware remover - not recommended

O4 - HKLM\..\Run: [sys0232731474] C:\WINDOWS\sys0232731474.exe
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O4 - HKLM\..\Run: [ms0473147432] C:\WINDOWS\ms0473147432.exe
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O4 - HKLM\..\Run: [win320747432731] C:\WINDOWS\win320747432731.exe
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O4 - HKLM\..\Run: [sys0874327314] C:\WINDOWS\sys0874327314.exe
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O4 - HKLM\..\Run: [sys0143273147] C:\WINDOWS\sys0143273147.exe
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O4 - HKLM\..\Run: [win320874327314] C:\WINDOWS\win320874327314.exe
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O4 - HKLM\..\Run: [THGuard] "C:\PROGRAM FILES\TROJANHUNTER 4.5\THGUARD.EXE"
THGuard
"Resident memory scanning for TrojanHunter"

O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
StillImageMonitor
"Stimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example

O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
Machine Debug Manager
"Used by developers for debugging and is a component of several MS products including Office and Visual Studio. Those who have encountered it have unchecked it with no degradation in performance. It may cause your computer to ""hang"" if you have Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendation. For this entry it loads under the ""RunServices"" key in Me (located in C:\WINDOWS\SYSTEM). It also loads a service in XP/Vista (located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug)"

O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
LoadPowerProfile
"Added by the CABRO TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll"

O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
SchedulingAgent
"MS Scheduling Agent in Win98/Me/2K - displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting

O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
SSDPSRV
"Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program

O4 - HKLM\..\RunServices: [CSINJECT.EXE] C:\Program Files\Norton SystemWorks\Norton CleanSweep\CSINJECT.EXE
CSINJECT.EXE
"Part of Quarterdeck/Norton CleanSweep. ""Csinject must be loaded in order for Smart Sweep to automatically monitor installations and properly track registry changes"""

O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
*StateMgr
Windows ME default for System Restore. Do NOT disable!

O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
KB891711
"Installed by the Windows KB891711 critical update

O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE" /autocheck
SpybotSnD
"Main program part of the popular Spybot - Search & Destroy spyware removal tool from Safer Networking Limited. A number of other options are available if this runs at start up (enabled under Mode → Advanced : Settings → Settings → Automation → System Start) - including autocheck

O4 - HKLM\..\RunOnce: [AAW] "C:\PROGRAM FILES\LAVASOFT\AD-AWARE SE PERSONAL\AD-AWARE.EXE" "+b1"
AAW
"Ad-Aware SE Personal from Lavasoft - popular spyware/adware removal tool. Now superseded by Ad-Aware 2008 Free"

O4 - HKCU\..\Run: [uoltray] C:\PROGRAM FILES\NETZERO\EXEC.EXE regrun
uoltray
Netzero free ISP software - not required

O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
RoboForm
"Roboform - password manager and web form filler. Will work without this startup entry

O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
RealPlayer
System Tray icon for RealPlayer. If you subsequently start RealPlayer manually it adds itself back to the start-up list. You can stop this from happening by right-clicking on the tray icon and disabling StartCenter via Preferences

O4 - HKCU\..\Run: [loyty] C:\WINDOWS\pbobxg.exe reg_run
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O4 - Startup: Internet Answering Machine.lnk = C:\Program Files\CallWave\IAM.EXE


O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE


O4 - Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe


O4 - Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe


O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe


O4 - Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe


O4 - Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe


O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe


O4 - Startup: 802.11b+g USB Wireless LAN Utility.lnk = C:\Program Files\WLAN\802.11b+g USB WLAN\ZDWlan.exe


O4 - Startup: iiace.exe


O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
Internet Explorer Restrictions
Spybot uses this to lock your homepage. Otherwise ask your administrator. If you're the administrator and you don't know what this is go ahead and clear it.

O8 - Extra context menu item: RoboForm &2 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
Internet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness

O8 - Extra context menu item: Fill Forms &] - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
Internet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness

O8 - Extra context menu item: Save Forms &[ - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Internet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness

O8 - Extra context menu item: Customize Menu &4 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
Internet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
Windows Messenger
Related to Microsoft's Windows Messenger.

O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
Windows Messenger
Related to Microsoft's Windows Messenger.

O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
Real.com
Related to Real Player

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
Sun Java Console
Related to Sun Java

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
Sun Java Console
Related to Sun Java

O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
RoboForm
Related to Roboform Password Manager and Web Form Filler that completely automates password entering and form filling. Note: file is found under C:Program FilesSiber SystemsAI RoboForm folder.

O9 - Extra 'Tools' menuitem: RoboForm &2 - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
RoboForm
Related to Roboform Password Manager and Web Form Filler that completely automates password entering and form filling. Note: file is found under C:Program FilesSiber SystemsAI RoboForm folder.

O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
Compila
Related to Roboform Note: File is located under C:ProgrammiSiber SystemsAI RoboForm

O9 - Extra 'Tools' menuitem: Fill Forms &] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
Compila
Related to Roboform Note: File is located under C:ProgrammiSiber SystemsAI RoboForm

O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Save Forms
Related to Roboform Password Manager and Web Form Filler that completely automates password entering and form filling. Note: file is found under C:Program FilesSiber SystemsAI RoboForm folder.

O9 - Extra 'Tools' menuitem: Save Forms &[ - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Save Forms
Related to Roboform Password Manager and Web Form Filler that completely automates password entering and form filling. Note: file is found under C:Program FilesSiber SystemsAI RoboForm folder.

O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
IE Plugins
Adds support for additional file things such as PDF files

O16 - DPF: {F104576A-91BA-40AD-91DE-2C20801339AB} - http://www.search-climbers.net/download/Keywords.cab
"Keywords001.dll - ""KeyWords"" parasite"
"Keywords001.dll - ""KeyWords"" parasite"

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1_02) -
i586.cab
Sun Microsystems Java_Software

O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
Unnamed BHO
http://java.sun.com/j2se

O16 - DPF: {0854D220-A90A-466D-BC02-6683183802B7} (PrintPreview Class) - http://nnrmls.fnismls.com/Paragon/Codebase/FNISPrintControl.cab
Unknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
Unnamed BHO
http://www.microsoft.com/genuine/downloads/WhyValidate.aspx?FamilyID=b446ae53-3759-40cf-80d5-cde4bbe07999&displaylang=en

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
Unnamed BHO
asinst.cab - Panda AV related