Bazooka Adware and Spyware Scanner Log 131

****************************************
Bazooka Adware and Spyware Scanner v1.13.01
http://www.kephyr.com/spywarescanner/
http://www.kephyr.com/spywarescanner/library/
Log created 23:16:36.
OS: Windows 98
Database version: 1.860000
Database format version: 1.020000
Database date: 20040308
Current date: 2004-03-10 23:16


****************************************
Result when scanning:

MS Media Player GUID 404.888.000
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\Settings\Client ID
http://www.kephyr.com/spywarescanner/library/msmediaplayerguid/index.phtml

General Virus, Worm, Trojan 294.000.006 PowerManager
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\PowerManager
http://www.kephyr.com/spywarescanner/library/generalvirus/index.phtml

****************************************
Auto start entries:
C:\Program Files\Verizon Online\VOLSW\Verizon Online.exe SILIENT
C:\Program Files\installed\MERCURY\loader.exe
C:\utils\slim_ftp\slimftp2.exe
C:\Program Files\installed\MaxMem\maxmem.exe

Go here to analyse the startup entries and the associated files:
http://www.kephyr.com/filedb/index.php

****************************************
Run entries:
TaskMonitor C:\WINDOWS\taskmon.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\TaskMonitor

SystemTray SysTray.Exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\SystemTray

LoadPowerProfile Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\LoadPowerProfile

a-winpoet-service "C:\Program Files\install\WinPoET\winpppoverethernet.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\a-winpoet-service

ScanRegistry C:\WINDOWS\scanregw.exe /autorun
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ScanRegistry

seticlient C:\Program Files\SETI@home\SETI@home.exe -min
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\seticlient

WinampAgent "C:\PROGRAM FILES\INSTALLED\WINAMP\WINAMPa.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WinampAgent

nod32kui C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\nod32kui

LoadPowerProfile Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\LoadPowerProfile

SchedulingAgent mstask.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\SchedulingAgent

PersFw "C:\Program Files\installed\Kerio\persfw.exe" /hide
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\PersFw

PowerManager C:\WINDOWS\SVCHOST.EXE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\PowerManager

NOD32kernel C:\Program Files\Eset\nod32krn.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\NOD32kernel

AIM C:\PROGRAM FILES\INSTALLED\AIM95\aim.exe -cnetwait.odl
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AIM


Go here to analyse the run entries and the associated files:
http://www.kephyr.com/filedb/index.php

****************************************
Browser helper objects:

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}


****************************************
Toolbars:

{01E04581-4EEE-11D0-BFE9-00AA005B4383} C:\WINDOWS\SYSTEM\BROWSEUI.DLL
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{01E04581-4EEE-11D0-BFE9-00AA005B4383}


****************************************
All processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\INSTALLED\KERIO\PERSFW.EXE
C:\PROGRAM FILES\ESET\NOD32KRN.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\INSTALL\WINPOET\WINPPPOVERETHERNET.EXE
C:\PROGRAM FILES\SETI@HOME\SETI@HOME.EXE
C:\PROGRAM FILES\ESET\NOD32KUI.EXE
C:\PROGRAM FILES\INSTALLED\AIM95\AIM.EXE
C:\PROGRAM FILES\INSTALLED\MERCURY\LOADER.EXE
C:\UTILS\SLIM_FTP\SLIMFTP2.EXE
C:\PROGRAM FILES\INSTALLED\MAXMEM\MAXMEM.EXE
C:\PROGRAM FILES\INSTALLED\MERCURY\MERCURY.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\NO-IP\DUC20.EXE
C:\PROGRAM FILES\XNEWS\XNEWS.EXE
C:\PROGRAM FILES\INSTALLED\OPERA7\OPERA.EXE
C:\PROGRAM FILES\INSTALLED\BAZOOKA\SPYWARESCANNER.EXE

Go here to analyse the running processes:
http://www.kephyr.com/filedb/index.php

****************************************
Internet Explorer Settings:

http://
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix\

www http://
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\www


****************************************




Related links

Bazooka - Free scan for spyware, adware, trojan horses, keyloggers, etc. Detects more than 500 potentially unwanted applications. Freeware!

The File Database - Search the file database for more information. Free!

PopUp Blocker Test - Find out if your pop-up killer can handle all pop-ups. Free!

Kephyr Labs - Find out what is going on at Kephyr. Try products in an early stage of development.



FreeFixer
Read more about FreeFixer, Kephyr's latest spyware removal tool.
Home & Products |  Legal |  Privacy |  Search

© Kephyr, 2003-2012. HtmlTidy, HTML 4.01, CSS andy@kephyr.com