Parsed logs from users, sent by RegFreeze
You can view your log here, or get the information about malware entries, marked in parsed logs.


Scan your PC for FREE!
Get RegFreeze Now!
RegFreeze can protect you from threats. RegFreeze is able to delete threats. The best antispyware solution on the Internet! Removes some spyware processes that nobody even could catch! Exclusive invention!

Get RegFreeze Now!



Log from unknown sender, Aug 23, 2006 16:02:50
Lines, marked with red background, contains the bad entries and should be fixed.


Sponsored links


< <Back to logs list

Platform: Microsoft Windows 2000 Professional Service Pack 4 (Build 2195)
MSIE: Internet Explorer 6.0.2800.1106

Running processes:
\SystemRoot\System32\smss.exe
\??\C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\MESSAG~1\StartMessager.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
C:\WINNT\system32\rundll32.exe
C:\Program Files\PDF-Creator\PDF Asst.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINNT\system32\flcss.exeC:\WINNT\system32\flcss.exe


C:\WINNT\system32\internat.exe
C:\Program Files\WINSOS\WINSOS.EXE
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\RegFreeze\regfreeze.exe
C:\WINNT\system32\wuauclt.exe

IE: HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\System32\blank.htm
IE: HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.microsoft.com/search/lobby/search.asp
IE: HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.microsoft.com/access/allinone.asp
IE: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
IE: HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/fr/srchasst/srchasst.htm
IE: HKCU\Software\Microsoft\Internet Explorer\SearchUrl,(default) = http://home.microsoft.com/access/autosearch.asp?p=%s
IE: HKCU\Software\Microsoft\Internet Explorer\SearchUrl,provider = yaho
IE: HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.free.fr/
IE: HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE: HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE: HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE: HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE: HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE: HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - (no file)

BHO: phoneaccess Class - {5054F860-748D-4840-B7B4-DDDB428421AF} - (no file)BHO: phoneaccess Class - {5054F860-748D-4840-B7B4-DDDB428421AF} - (no file)


BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - (no file)BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - (no file)


BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll

Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - (no file)

Toolbar: (no name) - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - (no file)Toolbar: (no name) - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - (no file)


Toolbar: (no name) - {7E66936C-FEA0-4984-AD26-7B6661AC5B2E} - (no file)Toolbar: (no name) - {7E66936C-FEA0-4984-AD26-7B6661AC5B2E} - (no file)


Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll

Extra button: CmdMapping - (no file)
Extra button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (no file)
Extra button: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

HKCU\..\Run: [internat.exe] internat.exe
HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\WINSOS\WINSOS.EXE" MINI
HKCU\..\Run: [WebCamRT.exe]
HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
HKLM\..\Run: [nwiz] nwiz.exe /install
HKLM\..\Run: [LoadQM] loadqm.exe
HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
HKLM\..\Run: [PDF-Creator] "C:\Program Files\PDF-Creator\PDF Asst.exe"
HKLM\..\Run: [sla] C:\WINNT\sla.exe
HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\ereg.ini"
HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
HKLM\..\Run: [SemanticInsight] C:\Program Files\RXToolBar\Semantic Insight\SemanticInsight.exe
HKLM\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

HKLM\..\Run: [KL AntiFunLove] C:\WINNT\system32\flcss.exeHKLM\..\Run: [KL AntiFunLove] C:\WINNT\system32\flcss.exe


HKLM\..\Run: [KL AntiFunLove] C:\WINNT\system32\flcss.exeHKLM\..\Run: [KL AntiFunLove] C:\WINNT\system32\flcss.exe



Extra context menu item: &Search - http://kt.bar.need2find.com/KT/menusearch.html?p=KT
Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file)
URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

Protocol filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)Protocol filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)






< <Back to logs list


Resume of bad entries:
C:\WINNT\system32\flcss.exe
BHO: phoneaccess Class - {5054F860-748D-4840-B7B4-DDDB428421AF} - (no file)
BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - (no file)
Toolbar: (no name) - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - (no file)
Toolbar: (no name) - {7E66936C-FEA0-4984-AD26-7B6661AC5B2E} - (no file)
HKLM\..\Run: [KL AntiFunLove] C:\WINNT\system32\flcss.exe
HKLM\..\Run: [KL AntiFunLove] C:\WINNT\system32\flcss.exe
Protocol filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)


Sponsored links