This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Firefox Google redirects: Adwarefeed.com and clickfrau

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got hit by a whole batch of Virtumonde last week. I managed to clear out pretty much all of it, but I just noticed today that my Google searches in Firefox are still getting redirected. I fired up Firebug and noticed .js files being included for adwarefree.com and Clickfraudmanager. I have so far run Spybot S&D;, MalwareBytes and ComboFix, none of which have managed to detect or remove it (although they all did a great job getting rid of Virtumonde).

I've run HJT (see log below) and OTScanIt (see additional log below); I've also downloaded ERUNT and backed up my registry. I know I'll need to start getting heavy with my registry to get rid of this, so would very much appreciate your help :)

HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:31:08, on 14/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Documents and Settings\Lawrie.GORT\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll
O3 - Toolbar: &Google; Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (file missing)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5036.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://128.243.100.37/activex/AMC.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 7631 bytes


OTScanIt Log:

OTScanIt2 logfile created on: 14/03/2009 16:02:15 - Run 1
OTScanIt2 by OldTimer - Version 1.0.8.0 Folder = C:\Documents and Settings\Lawrie.GORT\Desktop\OTScanIt2
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.44 Gb Available Physical Memory | 72.49% Memory free
3.84 Gb Paging File | 3.41 Gb Available in Paging File | 88.80% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 200.19 Gb Total Space | 55.95 Gb Free Space | 27.95% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 172.42 Gb Total Space | 127.49 Gb Free Space | 73.94% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GORT
Current User Name: Lawrie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days

[Processes - Safe List]
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/10/01 13:06:14 | 00,116,040 | —- | M] (Apple Inc.)
avgrsx.exe -> %ProgramFiles%\AVG\AVG8\avgrsx.exe -> [2008/10/24 23:45:23 | 00,287,000 | —- | M] (AVG Technologies CZ, s.r.o.)
avgwdsvc.exe -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2008/10/24 23:45:19 | 00,231,704 | —- | M] (AVG Technologies CZ, s.r.o.)
bgsvcgen.exe -> %SystemRoot%\system32\bgsvcgen.exe -> [2007/06/14 18:57:42 | 00,145,504 | —- | M] (B.H.A Corporation)
explorer.exe -> %SystemRoot%\explorer.exe -> [2008/04/14 00:12:19 | 01,033,728 | —- | M] (Microsoft Corporation)
googleupdate.exe -> %UserProfile%\Local Settings\Application Data\Google\Update\GoogleUpdate.exe -> [2008/09/03 14:23:45 | 00,133,104 | —- | M] (Google Inc.)
hkcmd.exe -> %SystemRoot%\system32\hkcmd.exe -> [2006/03/19 20:13:40 | 00,077,824 | R— | M] (Intel Corporation)
igfxpers.exe -> %SystemRoot%\system32\igfxpers.exe -> [2006/03/19 20:17:50 | 00,118,784 | R— | M] (Intel Corporation)
jqs.exe -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2009/01/08 11:10:38 | 00,152,984 | —- | M] (Sun Microsystems, Inc.)
jusched.exe -> %ProgramFiles%\Java\jre6\bin\jusched.exe -> [2009/01/08 11:10:38 | 00,136,600 | —- | M] (Sun Microsystems, Inc.)
kservice.exe -> %ProgramFiles%\Kontiki\KService.exe -> [2007/04/23 10:22:14 | 03,068,352 | —- | M] (Kontiki Inc.)
lexbces.exe -> %SystemRoot%\system32\LEXBCES.EXE -> [2006/04/17 17:42:14 | 00,311,296 | —- | M] (Lexmark International, Inc.)
lexpps.exe -> %SystemRoot%\system32\LEXPPS.EXE -> [2006/04/17 17:41:24 | 00,174,592 | —- | M] (Lexmark International, Inc.)
lxczbmgr.exe -> %ProgramFiles%\Lexmark 1200 Series\lxczbmgr.exe -> [2006/07/13 05:22:50 | 00,057,344 | —- | M] (Lexmark International, Inc.)
lxczbmon.exe -> %ProgramFiles%\Lexmark 1200 Series\lxczbmon.exe -> [2006/07/13 05:33:14 | 00,053,248 | —- | M] (Lexmark International, Inc.)
mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.)
openvpnas.exe -> %ProgramFiles%\Hotspot Shield\bin\openvpnas.exe -> [2008/11/25 19:41:50 | 00,088,024 | —- | M] ()
otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2009/02/19 11:15:40 | 00,489,984 | —- | M] (OldTimer Tools)
rthdcpl.exe -> %SystemRoot%\RTHDCPL.EXE -> [2006/10/30 19:49:54 | 16,269,312 | —- | M] (Realtek Semiconductor Corp.)
tsvncache.exe -> %ProgramFiles%\TortoiseSVN\bin\TSVNCache.exe -> [2008/12/23 08:07:16 | 00,577,024 | —- | M] (http://tortoisesvn.net)
viewpointservice.exe -> %ProgramFiles%\Viewpoint\Common\ViewpointService.exe -> [2007/01/04 21:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation)
vsmon.exe -> %SystemRoot%\system32\ZoneLabs\vsmon.exe -> [2008/07/09 08:05:18 | 00,075,304 | —- | M] (Zone Labs, LLC)
wmpnetwk.exe -> %ProgramFiles%\Windows Media Player\WMPNetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)
wmpnscfg.exe -> %ProgramFiles%\Windows Media Player\WMPNSCFG.exe -> [2006/10/18 20:05:26 | 00,204,288 | —- | M] (Microsoft Corporation)
zlclient.exe -> %ProgramFiles%\Zone Labs\ZoneAlarm\zlclient.exe -> [2008/07/09 08:05:20 | 00,919,016 | —- | M] (Zone Labs, LLC)

[Win32 Services - Safe List]
(Adobe LM Service) Adobe LM Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Adobe Systems Shared\Service\Adobelmsvc.exe -> [2007/04/24 18:12:48 | 00,072,704 | —- | M] (Adobe Systems)
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/10/01 13:06:14 | 00,116,040 | —- | M] (Apple Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007/04/13 02:20:52 | 00,033,632 | —- | M] (Microsoft Corporation)
(ATMsrvc) ATM Service [Win32_Own | Disabled | Stopped] -> %SystemRoot%\System32\ATMsrvc.exe -> [2000/05/24 15:20:36 | 00,015,360 | —- | M] (Adobe Systems Incorporated)
(avg8wd) AVG Free8 WatchDog [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2008/10/24 23:45:19 | 00,231,704 | —- | M] (AVG Technologies CZ, s.r.o.)
(bgsvcgen) B's Recorder GOLD Library General Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\bgsvcgen.exe -> [2007/06/14 18:57:42 | 00,145,504 | —- | M] (B.H.A Corporation)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.)
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007/04/13 02:21:18 | 00,068,952 | —- | M] (Microsoft Corporation)
(FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> [2008/10/20 19:42:41 | 00,655,624 | —- | M] (Acresso Software Inc.)
(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2008/12/22 11:30:04 | 00,137,200 | —- | M] (Google)
(helpsvc) Help and Support [Win32_Shared | Auto | Running] -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/14 00:12:02 | 00,038,400 | —- | M] (Microsoft Corporation)
(HotspotShieldService) Hotspot Shield Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Hotspot Shield\bin\openvpnas.exe -> [2008/11/25 19:41:50 | 00,088,024 | —- | M] ()
(iPod Service) iPod Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/10/01 18:57:00 | 00,536,872 | —- | M] (Apple Inc.)
(JavaQuickStarterService) Java Quick Starter [Win32_Own | Auto | Running] -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2009/01/08 11:10:38 | 00,152,984 | —- | M] (Sun Microsystems, Inc.)
(KService) KService [Win32_Own | Auto | Running] -> %ProgramFiles%\Kontiki\KService.exe -> [2007/04/23 10:22:14 | 03,068,352 | —- | M] (Kontiki Inc.)
(LexBceS) LexBce Server [Win32_Own | Auto | Running] -> %SystemRoot%\system32\LEXBCES.EXE -> [2006/04/17 17:42:14 | 00,311,296 | —- | M] (Lexmark International, Inc.)
(Macromedia Licensing Service) Macromedia Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macromedia Shared\Service\Macromedia Licensing.exe -> [2004/07/30 01:19:22 | 00,069,632 | —- | M] (Macromedia)
(usnjsvc) Messenger Sharing Folders USN Journal Reader service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\Messenger\usnsvc.exe -> [2007/10/18 10:31:54 | 00,098,328 | —- | M] (Microsoft Corporation)
(Viewpoint Manager Service) Viewpoint Manager Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Viewpoint\Common\ViewpointService.exe -> [2007/01/04 21:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation)
(vsmon) TrueVector Internet Monitor [Win32_Own | Auto | Running] -> %SystemRoot%\system32\ZoneLabs\vsmon.exe -> [2008/07/09 08:05:18 | 00,075,304 | —- | M] (Zone Labs, LLC)
(WLSetupSvc) Windows Live Setup Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\installer\WLSetupSvc.exe -> [2007/10/25 14:27:54 | 00,266,240 | —- | M] (Microsoft Corporation)
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Windows Media Player\WMPNetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)

[Driver Services - Safe List]
(adfs) adfs [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\adfs.sys -> [2009/01/31 17:28:23 | 00,073,312 | —- | M] (Adobe Systems, Inc.)
(AvgLdx86) AVG Free AVI Loader Driver x86 [Kernel | System | Running] -> %SystemRoot%\System32\Drivers\avgldx86.sys -> [2008/10/24 23:45:37 | 00,097,928 | —- | M] (AVG Technologies CZ, s.r.o.)
(AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> %SystemRoot%\System32\Drivers\avgmfx86.sys -> [2008/10/24 23:45:35 | 00,026,824 | —- | M] (AVG Technologies CZ, s.r.o.)
(cdrbsdrv) cdrbsdrv [Kernel | System | Running] -> %SystemRoot%\System32\drivers\cdrbsdrv.sys -> [2006/02/20 01:17:40 | 00,033,408 | —- | M] (B.H.A Corporation)
(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\Drivers\GEARAspiWDM.sys -> [2008/04/17 13:12:54 | 00,015,464 | —- | M] (GEAR Software Inc.)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HDAudBus.sys -> [2008/04/13 16:36:05 | 00,144,384 | —- | M] (Windows ® Server 2003 DDK provider)
(ialm) ialm [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ialmnt5.sys -> [2006/03/19 20:47:06 | 01,166,972 | R— | M] (Intel Corporation)
(IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\RtkHDAud.sys -> [2006/11/03 09:32:30 | 04,394,496 | —- | M] (Realtek Semiconductor Corp.)
(KLIF) KLIF [File_System | System | Running] -> %SystemRoot%\system32\DRIVERS\klif.sys -> [2007/07/19 14:10:28 | 00,127,768 | —- | M] (Kaspersky Lab)
(MarvinBus) Pinnacle Marvin Bus [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\MarvinBus.sys -> [2005/09/23 22:18:32 | 00,171,520 | —- | M] (Pinnacle Systems GmbH)
(netwg311) NETGEAR WG311v2 802.11g Wireless PCI Adapter [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\netwg311.sys -> [2004/06/17 22:41:16 | 00,386,688 | —- | M] (Texas Instruments)
(pfc) Padus ASPI Shell [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\pfc.sys -> [2003/09/19 15:45:48 | 00,021,248 | —- | M] (Padus, Inc.)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ptilink.sys -> [2006/02/28 12:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.)
(ROOTMODEM) Microsoft Legacy Modem Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\Drivers\RootMdm.sys -> [2006/02/28 12:00:00 | 00,005,888 | —- | M] (Microsoft Corporation)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\secdrv.sys -> [2007/11/13 10:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(SQTECH930B) Trust WB-3500T USB2 Webcam [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\Capt930b.sys -> [2005/04/21 16:55:38 | 00,273,982 | —- | M] (Salix)
(srescan) srescan [Kernel | Boot | Running] -> %SystemRoot%\system32\ZoneLabs\srescan.sys -> [2008/02/27 02:10:44 | 00,051,176 | —- | M] (Zone Labs, LLC)
(tapvpn) TAP VPN Adapter [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\tapvpn.sys -> [2008/01/23 21:25:32 | 00,027,136 | —- | M] (The OpenVPN Project)
(USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\usbaapl.sys -> [2008/02/18 10:16:24 | 00,030,464 | —- | M] (Apple, Inc.)
(usbsermpt) Motorola USB Modem Driver for MPT [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\usbsermpt.sys -> [2008/01/29 22:03:23 | 00,022,768 | —- | M] (Microsoft Corporation)
(vsdatant) vsdatant [Kernel | System | Running] -> %SystemRoot%\System32\vsdatant.sys -> [2008/07/09 08:05:22 | 00,394,952 | —- | M] (Zone Labs, LLC)
(yukonwxp) NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\yk51x86.sys -> [2006/07/04 00:56:00 | 00,248,832 | R— | M] (Marvell)

[Registry - All]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> Reg Error: Invalid data type. ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_CURRENT_USER\: Main\\"Page_Transitions" -> Reg Error: Invalid data type. ->
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch ->
HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.google.com/ ->
HKEY_CURRENT_USER\: URLSearchHooks\\"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" [HKLM] -> %SystemRoot%\system32\ieframe.dll [Microsoft Url Search Hook] -> [2008/12/20 23:15:21 | 06,066,688 | —- | M] (Microsoft Corporation)
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 ->
< FireFox Settings [Default Profile] > -> C:\Documents and Settings\Lawrie.GORT\Application Data\Mozilla\FireFox\Profiles\rsdedr0s.default\prefs.js ->
browser.startup.homepage_override.mstone -> "rv:1.9.0.7" ->
extensions.enabledItems -> {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.1 ->
extensions.enabledItems -> [removed]:1.3.3 ->
extensions.enabledItems -> {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.4 ->
extensions.enabledItems -> {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11 ->
extensions.enabledItems -> [removed]:1.0 ->
extensions.enabledItems -> {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.6 ->
extensions.enabledItems -> {C1572E0F-42E3-4243-88EE-5DB3D978A919}:1.0 ->
extensions.enabledItems -> [removed]:1.0.2 ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7 ->
< HOSTS File > (302083 bytes and 10462 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
First 25 entries…
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1001namen.com
127.0.0.1 1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D; IE Protection] -> [2009/01/26 15:31:02 | 01,879,896 | —- | M] (Safer Networking Limited)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre6\bin\ssv.dll [Java™ Plug-In SSV Helper] -> [2009/01/08 11:10:40 | 00,320,920 | —- | M] (Sun Microsystems, Inc.)
{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [HKLM] -> %ProgramFiles%\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [Google Dictionary Compression sdch] -> [2008/12/22 10:41:45 | 00,522,224 | —- | M] (Google Inc.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> %ProgramFiles%\Java\jre6\bin\jp2ssv.dll [Java™ Plug-In 2 SSV Helper] -> [2009/01/08 11:10:38 | 00,034,816 | —- | M] (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} [HKLM] -> %ProgramFiles%\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [JQSIEStartDetectorImpl Class] -> [2009/01/08 11:10:42 | 00,073,728 | —- | M] (Sun Microsystems, Inc.)
{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} [HKLM] -> %ProgramFiles%\Hotspot Shield\hssie\HssIE.dll [Hotspot Shield Class] -> [2009/01/08 17:57:49 | 00,204,248 | —- | M] (AnchorFree Inc.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google; Toolbar] -> File not found
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\"{01E04581-4EEE-11D0-BFE9-00AA005B4383}" [HKLM] -> %SystemRoot%\system32\browseui.dll [&Address;] -> [2008/04/14 00:11:50 | 01,025,024 | —- | M] (Microsoft Corporation)
WebBrowser\\"{01E04581-4EEE-11D0-BFE9-00AA005B4383}" [HKLM] -> %SystemRoot%\system32\browseui.dll [&Address;] -> [2008/04/14 00:11:50 | 01,025,024 | —- | M] (Microsoft Corporation)
WebBrowser\\"{0E5CBF21-D15F-11D0-8301-00AA005B4383}" [HKLM] -> %SystemRoot%\system32\SHELL32.dll [&Links;] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google; Toolbar] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"AdobeCS4ServiceManager" -> %CommonProgramFiles%\Adobe\CS4ServiceManager\CS4ServiceManager.exe ["C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin] -> [2008/11/13 08:03:18 | 00,611,712 | —- | M] (Adobe Systems Incorporated)
"igfxhkcmd" -> %SystemRoot%\system32\hkcmd.exe [C:\WINDOWS\system32\hkcmd.exe] -> [2006/03/19 20:13:40 | 00,077,824 | R— | M] (Intel Corporation)
"igfxpers" -> %SystemRoot%\system32\igfxpers.exe [C:\WINDOWS\system32\igfxpers.exe] -> [2006/03/19 20:17:50 | 00,118,784 | R— | M] (Intel Corporation)
"igfxtray" -> %SystemRoot%\system32\igfxtray.exe [C:\WINDOWS\system32\igfxtray.exe] -> [2006/03/19 20:17:04 | 00,094,208 | R— | M] (Intel Corporation)
"Lexmark 1200 Series" -> %ProgramFiles%\Lexmark 1200 Series\lxczbmgr.exe ["C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"] -> [2006/07/13 05:22:50 | 00,057,344 | —- | M] (Lexmark International, Inc.)
"QuickTime Task" -> %ProgramFiles%\QuickTime\qttask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> [2008/09/06 15:09:14 | 00,413,696 | —- | M] (Apple Inc.)
"RTHDCPL" -> %SystemRoot%\RTHDCPL.EXE [RTHDCPL.EXE] -> [2006/10/30 19:49:54 | 16,269,312 | —- | M] (Realtek Semiconductor Corp.)
"SunJavaUpdateSched" -> %ProgramFiles%\Java\jre6\bin\jusched.exe ["C:\Program Files\Java\jre6\bin\jusched.exe"] -> [2009/01/08 11:10:38 | 00,136,600 | —- | M] (Sun Microsystems, Inc.)
"ZoneAlarm Client" -> %ProgramFiles%\Zone Labs\ZoneAlarm\zlclient.exe ["C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"] -> [2008/07/09 08:05:20 | 00,919,016 | —- | M] (Zone Labs, LLC)
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"WMPNSCFG" -> %ProgramFiles%\Windows Media Player\WMPNSCFG.exe [C:\Program Files\Windows Media Player\WMPNSCFG.exe] -> [2006/10/18 20:05:26 | 00,204,288 | —- | M] (Microsoft Corporation)
< All Users.WINDOWS Startup Folder > -> C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup ->
< Lawrie.GORT Startup Folder > -> C:\Documents and Settings\Lawrie.GORT\Start Menu\Programs\Startup ->
< Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [323] -> File not found
\\"NoDrives" -> [0] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"HonorAutoRunSetting" -> [1] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" -> [0] -> File not found
\\"legalnoticecaption" -> [] -> File not found
\\"legalnoticetext" -> [] -> File not found
\\"shutdownwithoutlogon" -> [1] -> File not found
\\"undockwithoutlogon" -> [1] -> File not found
\\"DisableRegistryTools" -> [0] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDrives" -> [0] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"NoDriveTypeAutoRun" -> [323] -> File not found
< CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
Sothink SWF Catcher -> %CommonProgramFiles%\SourceTec\SWF Catcher\InternetExplorer.htm [C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm] -> [2008/09/18 23:30:00 | 00,000,191 | —- | M] ()
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Menu: Spybot - Search & Destroy Configuration] -> [2009/01/26 15:31:02 | 01,879,896 | —- | M] (Safer Networking Limited)
{E19ADC6E-3909-43E4-9A89-B7B676377EE3}:C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm [HKLM] -> %CommonProgramFiles%\SourceTec\SWF Catcher\InternetExplorer.htm [Button: Sothink SWF Catcher] -> [2008/09/18 23:30:00 | 00,000,191 | —- | M] ()
{E19ADC6E-3909-43E4-9A89-B7B676377EE3}:C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm [HKLM] -> %CommonProgramFiles%\SourceTec\SWF Catcher\InternetExplorer.htm [Menu: Sothink SWF Catcher] -> [2008/09/18 23:30:00 | 00,000,191 | —- | M] ()
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/14 00:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/14 00:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> [Reg Error: Value error.] -> File not found
CmdMapping\\"{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}" [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> [2009/01/26 15:31:02 | 01,879,896 | —- | M] (Safer Networking Limited)
CmdMapping\\"{E19ADC6E-3909-43E4-9A89-B7B676377EE3}" [HKLM] -> %CommonProgramFiles%\SourceTec\SWF Catcher\SWFCatcher.dll [SWFDecompiler.InternetExplorer] -> [2007/02/09 09:00:00 | 00,397,312 | —- | M] (SourceTec)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 00:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find…=%s&mime;=%s ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5448 domain(s) found. ->
50 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5449 domain(s) found. ->
49 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{1239CC52-59EF-4DFA-8C61-90FFA846DF7E} [HKLM] -> http://www.musicnotes.com/download/mnviewer.cab [Musicnotes Viewer] ->
{166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwa…director/sw.cab [Shockwave ActiveX Control] ->
{4871A87A-BFDD-4106-8153-FFDE2BAC2967} [HKLM] -> http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab [DLM Control] ->
{5ED80217-570B-4DA9-BF44-BE107C0EC166} [HKLM] -> http://cdn.scan.onecare.live.com/resource/…lscbase5036.cab [Windows Live Safety Center Base Module] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab [Java Plug-in 1.6.0_11] ->
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab [Reg Error: Key error.] ->
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab [Java Plug-in 1.6.0_03] ->
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab [Java Plug-in 1.6.0_05] ->
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab [Java Plug-in 1.6.0_07] ->
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab [Java Plug-in 1.6.0_11] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab [Java Plug-in 1.6.0_11] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab [Shockwave Flash Object] ->
{DE625294-70E6-45ED-B895-CFFA13AEB044} [HKLM] -> http://128.243.100.37/activex/AMC.cab [AxisMediaControlEmb Class] ->
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{048A18A9-741B-4785-9540-C16433D3201A} -> () ->
{4820FF25-7CE6-4425-999B-AD9A7284958F} -> (1394 Net Adapter) ->
{7A444C36-76E8-4C6F-8863-0E8D46EA74AA} -> (NETGEAR WG311v2 802.11g Wireless PCI Adapter) ->
{B263F0DD-8276-46F2-9900-5253DFF88FA3} -> (Generic Marvell Yukon Chipset based Ethernet Controller) ->
{B7D89C76-E1D1-4318-AEE1-E2BA4E8B5891} -> () ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> %SystemRoot%\Explorer.exe -> [2008/04/14 00:12:19 | 01,033,728 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
*UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit ->
C:\WINDOWS\system32\userinit.exe -> %SystemRoot%\system32\userinit.exe -> [2008/04/14 00:12:38 | 00,026,112 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
*UIHost* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost ->
logonui.exe -> %SystemRoot%\system32\logonui.exe -> [2008/04/14 00:12:24 | 00,514,560 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet ->
rundll32 shell32 -> %SystemRoot%\System32\shell32.dll -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
Control_RunDLL "sysdm.cpl" -> %SystemRoot%\system32\sysdm.cpl -> [2008/04/14 00:12:41 | 00,300,544 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
crypt32chain -> %SystemRoot%\system32\crypt32.dll -> [2008/04/14 00:11:51 | 00,599,040 | —- | M] (Microsoft Corporation)
cryptnet -> %SystemRoot%\system32\cryptnet.dll -> [2008/04/14 00:11:51 | 00,064,512 | —- | M] (Microsoft Corporation)
cscdll -> %SystemRoot%\system32\cscdll.dll -> [2008/04/14 00:11:51 | 00,101,888 | —- | M] (Microsoft Corporation)
dimsntfy -> %SystemRoot%\System32\dimsntfy.dll -> [2008/04/14 00:11:52 | 00,019,456 | —- | M] (Microsoft Corporation)
igfxcui -> %SystemRoot%\system32\igfxdev.dll -> [2006/03/19 20:12:42 | 00,139,264 | R— | M] (Intel Corporation)
ScCertProp -> %SystemRoot%\system32\wlnotify.dll -> [2008/04/14 00:12:09 | 00,092,672 | —- | M] (Microsoft Corporation)
Schedule -> %SystemRoot%\system32\wlnotify.dll -> [2008/04/14 00:12:09 | 00,092,672 | —- | M] (Microsoft Corporation)
sclgntfy -> %SystemRoot%\system32\sclgntfy.dll -> [2008/04/14 00:12:05 | 00,020,480 | —- | M] (Microsoft Corporation)
SensLogn -> %SystemRoot%\system32\WlNotify.dll -> [2008/04/14 00:12:09 | 00,092,672 | —- | M] (Microsoft Corporation)
termsrv -> %SystemRoot%\system32\wlnotify.dll -> [2008/04/14 00:12:09 | 00,092,672 | —- | M] (Microsoft Corporation)
wlballoon -> %SystemRoot%\system32\wlnotify.dll -> [2008/04/14 00:12:09 | 00,092,672 | —- | M] (Microsoft Corporation)
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad ->
"{fbeb8a05-beee-4442-804e-409d6c4515e9}" [HKLM] -> %SystemRoot%\system32\SHELL32.dll [CDBurn] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
"{7849596a-48ea-486e-8937-a2a3009f31a9}" [HKLM] -> %SystemRoot%\system32\SHELL32.dll [PostBootReminder] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
"{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKLM] -> %SystemRoot%\system32\stobject.dll [SysTray] -> [2008/04/14 00:12:07 | 00,121,856 | —- | M] (Microsoft Corporation)
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> %SystemRoot%\system32\webcheck.dll [WebCheck] -> [2008/12/20 23:15:40 | 00,233,472 | —- | M] (Microsoft Corporation)
"{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" [HKLM] -> %SystemRoot%\system32\WPDShServiceObj.dll [WPDShServiceObj] -> [2006/10/18 21:47:22 | 00,133,632 | —- | M] (Microsoft Corporation)
< SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler ->
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}" [HKLM] -> %SystemRoot%\system32\browseui.dll [Browseui preloader] -> [2008/04/14 00:11:50 | 01,025,024 | —- | M] (Microsoft Corporation)
"{8C7461EF-2B13-11d2-BE35-3078302C2030}" [HKLM] -> %SystemRoot%\system32\browseui.dll [Component Categories cache daemon] -> [2008/04/14 00:11:50 | 01,025,024 | —- | M] (Microsoft Corporation)
< IFEO [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ ->
Your Image File Name Here without a path -> %SystemRoot%\System32\ntsd.exe [Debugger] -> [2006/02/28 12:00:00 | 00,031,744 | —- | M] (Microsoft Corporation)
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" [HKLM] -> %SystemRoot%\system32\shell32.dll [] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
*SecurityProviders* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
msapsspc.dll -> %SystemRoot%\system32\msapsspc.dll -> [2008/04/14 00:11:58 | 00,086,016 | —- | M] (Microsoft Corporation)
schannel.dll -> %SystemRoot%\system32\schannel.dll -> [2008/12/05 06:54:55 | 00,144,896 | —- | M] (Microsoft Corporation)
digest.dll -> %SystemRoot%\system32\digest.dll -> [2008/04/14 00:11:52 | 00,068,608 | —- | M] (Microsoft Corporation)
msnsspc.dll -> %SystemRoot%\system32\msnsspc.dll -> [2008/04/14 00:12:00 | 00,290,816 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages ->
*LSA Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages ->
msv1_0 -> %SystemRoot%\System32\msv1_0.dll -> [2008/04/14 00:12:00 | 00,132,608 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages ->
*LSA Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages ->
kerberos -> %SystemRoot%\System32\kerberos.dll -> [2008/04/14 00:11:56 | 00,299,520 | —- | M] (Microsoft Corporation)
msv1_0 -> %SystemRoot%\System32\msv1_0.dll -> [2008/04/14 00:12:00 | 00,132,608 | —- | M] (Microsoft Corporation)
schannel -> %SystemRoot%\System32\schannel.dll -> [2008/12/05 06:54:55 | 00,144,896 | —- | M] (Microsoft Corporation)
wdigest -> %SystemRoot%\System32\wdigest.dll -> [2008/04/14 00:12:08 | 00,049,152 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 18:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 00:12:34 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\livecall.exe" -> C:\Program Files\Windows Live\Messenger\livecall.exe [C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007/10/02 16:18:24 | 00,304,488 | —- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007/10/18 10:34:02 | 05,724,184 | —- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 18:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 00:12:34 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\installs\utorrent.exe" -> C:\installs\utorrent.exe [C:\installs\utorrent.exe:*:Enabled:µTorrent] -> [2009/02/21 18:26:29 | 00,270,128 | —- | M] (BitTorrent, Inc.)
"C:\Program Files\AVG\AVG8\avgupd.exe" -> C:\Program Files\AVG\AVG8\avgupd.exe [C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe] -> [2008/10/24 23:45:22 | 00,641,304 | —- | M] (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.)
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -> C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4] -> [2008/11/13 08:03:18 | 00,611,712 | —- | M] (Adobe Systems Incorporated)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" -> C:\Program Files\Common Files\AOL\Loader\aolload.exe [C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader] -> [2006/11/03 07:17:27 | 00,010,800 | —- | M] (AOL LLC)
"C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2008/10/01 18:57:04 | 14,258,472 | —- | M] (Apple Inc.)
"C:\Program Files\Kontiki\KService.exe" -> C:\Program Files\Kontiki\KService.exe [C:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service] -> [2007/04/23 10:22:14 | 03,068,352 | —- | M] (Kontiki Inc.)
"C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe" -> C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe [C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe:*:Enabled:Render Manager] -> [2008/05/13 11:42:40 | 00,079,120 | —- | M] (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe" -> C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe [C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe:*:Enabled:Studio] -> [2008/05/13 11:26:04 | 06,034,704 | —- | M] (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe" -> C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe [C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe:*:Enabled:umi] -> [2008/05/13 11:42:42 | 00,087,312 | —- | M] (Pinnacle Systems)
"C:\Program Files\Skype\Phone\Skype.exe" -> C:\Program Files\Skype\Phone\Skype.exe [C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype] -> [2007/09/13 12:31:38 | 22,880,040 | R— | M] (Skype Technologies S.A.)
"C:\Program Files\Spotify\spotify.exe" -> C:\Program Files\Spotify\spotify.exe [C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify] -> [2009/02/27 22:51:24 | 02,517,888 | —- | M] (Spotify AB)
"C:\Program Files\Windows Live\Messenger\livecall.exe" -> C:\Program Files\Windows Live\Messenger\livecall.exe [C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007/10/02 16:18:24 | 00,304,488 | —- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007/10/18 10:34:02 | 05,724,184 | —- | M] (Microsoft Corporation)
"C:\xampplite\apache\bin\apache.exe" -> C:\xampplite\apache\bin\apache.exe [C:\xampplite\apache\bin\apache.exe:*:Enabled:Apache HTTP Server] -> [2007/03/05 10:23:02 | 00,016,896 | —- | M] (Apache Software Foundation)
"C:\xampplite\mysql\bin\mysqld.exe" -> C:\xampplite\mysql\bin\mysqld.exe [C:\xampplite\mysql\bin\mysqld.exe:*:Enabled:mysqld] -> [2007/03/13 09:51:45 | 05,468,160 | —- | M] ()
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> %SystemRoot%\system32\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/04/13 18:40:46 | 00,062,976 | —- | M] (Microsoft Corporation)
< Drives with AutoRun files > -> ->
C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2004/02/06 20:58:24 | 00,000,000 | —- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
\{197fa470-2e28-11dd-8113-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{197fa470-2e28-11dd-8113-000138300101}\Shell\Auto\command
\{197fa470-2e28-11dd-8113-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{197fa470-2e28-11dd-8113-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{197fa470-2e28-11dd-8113-000138300101}\Shell\AutoRun
\{197fa470-2e28-11dd-8113-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{197fa470-2e28-11dd-8113-000138300101}\Shell\AutoRun\command
\{197fa470-2e28-11dd-8113-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{2bfa8dc6-9520-11dd-ab77-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bfa8dc6-9520-11dd-ab77-000138300101}\Shell\Auto\command
\{2bfa8dc6-9520-11dd-ab77-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{2bfa8dc6-9520-11dd-ab77-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bfa8dc6-9520-11dd-ab77-000138300101}\Shell\AutoRun
\{2bfa8dc6-9520-11dd-ab77-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bfa8dc6-9520-11dd-ab77-000138300101}\Shell\AutoRun\command
\{2bfa8dc6-9520-11dd-ab77-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{2bfa8dd3-9520-11dd-ab77-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bfa8dd3-9520-11dd-ab77-000138300101}\Shell\Auto\command
\{2bfa8dd3-9520-11dd-ab77-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{2bfa8dd3-9520-11dd-ab77-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bfa8dd3-9520-11dd-ab77-000138300101}\Shell\AutoRun
\{2bfa8dd3-9520-11dd-ab77-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bfa8dd3-9520-11dd-ab77-000138300101}\Shell\AutoRun\command
\{2bfa8dd3-9520-11dd-ab77-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{54b5f96c-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5f96c-8f93-11dd-ab6e-000138300101}\Shell\Auto\command
\{54b5f96c-8f93-11dd-ab6e-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{54b5f96c-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5f96c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun
\{54b5f96c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5f96c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command
\{54b5f96c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{54b5fb20-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb20-8f93-11dd-ab6e-000138300101}\Shell\Auto\command
\{54b5fb20-8f93-11dd-ab6e-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{54b5fb20-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb20-8f93-11dd-ab6e-000138300101}\Shell\AutoRun
\{54b5fb20-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb20-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command
\{54b5fb20-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{54b5fb2c-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb2c-8f93-11dd-ab6e-000138300101}\Shell\Auto\command
\{54b5fb2c-8f93-11dd-ab6e-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{54b5fb2c-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb2c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun
\{54b5fb2c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb2c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command
\{54b5fb2c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{54b5fb3e-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb3e-8f93-11dd-ab6e-000138300101}\Shell\Auto\command
\{54b5fb3e-8f93-11dd-ab6e-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{54b5fb3e-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb3e-8f93-11dd-ab6e-000138300101}\Shell\AutoRun
\{54b5fb3e-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb3e-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command
\{54b5fb3e-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{79178b5f-eec8-11dd-ada3-00301b434687}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{79178b5f-eec8-11dd-ada3-00301b434687}\Shell
\{79178b5f-eec8-11dd-ada3-00301b434687}\Shell\\"" -> [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{79178b5f-eec8-11dd-ada3-00301b434687}\Shell\AutoRun
\{79178b5f-eec8-11dd-ada3-00301b434687}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{79178b5f-eec8-11dd-ada3-00301b434687}\Shell\AutoRun\command
\{79178b5f-eec8-11dd-ada3-00301b434687}\Shell\AutoRun\command\\"" -> D:\LaunchU3.exe [D:\LaunchU3.exe -a] -> File not found
\{aefd0edc-905e-11dd-ab6f-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aefd0edc-905e-11dd-ab6f-000138300101}\Shell\Auto\command
\{aefd0edc-905e-11dd-ab6f-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{aefd0edc-905e-11dd-ab6f-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aefd0edc-905e-11dd-ab6f-000138300101}\Shell\AutoRun
\{aefd0edc-905e-11dd-ab6f-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aefd0edc-905e-11dd-ab6f-000138300101}\Shell\AutoRun\command
\{aefd0edc-905e-11dd-ab6f-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{e068c68f-6921-11dd-af99-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e068c68f-6921-11dd-af99-000138300101}\Shell\Auto\command
\{e068c68f-6921-11dd-af99-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{e068c68f-6921-11dd-af99-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e068c68f-6921-11dd-af99-000138300101}\Shell\AutoRun
\{e068c68f-6921-11dd-af99-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e068c68f-6921-11dd-af99-000138300101}\Shell\AutoRun\command
\{e068c68f-6921-11dd-af99-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)


[Files/Folders - Created Within 30 Days]
1 C:\*.tmp files -> C:\*.tmp ->
ERUNT -> %ProgramFiles%\ERUNT -> [2009/03/14 14:52:57 | 00,000,000 | —D | C]
OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2009/03/14 14:52:29 | 00,000,000 | —D | C]
stuff.html -> %UserProfile%\Desktop\stuff.html -> [2009/03/14 14:47:26 | 00,007,736 | —- | C] ()
ComboFix -> %SystemDrive%\ComboFix -> [2009/03/14 14:23:37 | 00,000,000 | —D | C]
MRT.exe -> %SystemRoot%\System32\MRT.exe -> [2009/03/12 23:31:10 | 24,768,960 | —- | C] (Microsoft Corporation)
gdlogo.swf -> %UserProfile%\Desktop\gdlogo.swf -> [2009/03/11 19:38:43 | 00,000,846 | —- | C] ()
gdlogo.fla -> %UserProfile%\Desktop\gdlogo.fla -> [2009/03/11 19:38:41 | 00,083,456 | —- | C] ()
push.jpg -> %UserProfile%\Desktop\push.jpg -> [2009/03/11 11:45:34 | 00,198,647 | —- | C] ()
cmldr -> %SystemDrive%\cmldr -> [2009/03/07 17:22:15 | 00,260,272 | —- | C] ()
cmdcons -> %SystemDrive%\cmdcons -> [2009/03/07 17:22:13 | 00,000,000 | RHSD | C]
Malwarebytes -> %AppData%\Malwarebytes -> [2009/03/06 16:47:38 | 00,000,000 | —D | C]
mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009/03/06 16:47:33 | 00,015,504 | —- | C] (Malwarebytes Corporation)
mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009/03/06 16:47:30 | 00,038,496 | —- | C] (Malwarebytes Corporation)
Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [2009/03/06 16:47:29 | 00,000,000 | —D | C]
Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware -> [2009/03/06 16:47:28 | 00,000,000 | —D | C]
Plasmaplugs Scroll Bar Quickstart Guide (Trial).pdf -> %UserProfile%\My Documents\Plasmaplugs Scroll Bar Quickstart Guide (Trial).pdf -> [2009/02/27 22:30:51 | 00,325,610 | —- | C] ()
sqmnoopt04.sqm -> %SystemDrive%\sqmnoopt04.sqm -> [2009/02/24 19:23:57 | 00,000,244 | -H– | C] ()
sqmdata04.sqm -> %SystemDrive%\sqmdata04.sqm -> [2009/02/24 19:23:57 | 00,000,232 | -H– | C] ()
sqmnoopt03.sqm -> %SystemDrive%\sqmnoopt03.sqm -> [2009/02/24 19:23:35 | 00,000,244 | -H– | C] ()
sqmdata03.sqm -> %SystemDrive%\sqmdata03.sqm -> [2009/02/24 19:23:35 | 00,000,232 | -H– | C] ()
Grammatics.zip -> %UserProfile%\Desktop\Grammatics.zip -> [2009/02/20 16:07:13 | 90,643,434 | —- | C] ()

[Files/Folders - Modified Within 30 Days]
1 C:\*.tmp files -> C:\*.tmp ->
1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp ->
2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->
2 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp ->
fidbox.dat -> %SystemRoot%\System32\drivers\fidbox.dat -> [2009/03/14 16:02:59 | 53,960,736 | -HS- | M] ()
rtdrvmon.exe -> %UserProfile%\Local Settings\temp\rtdrvmon.exe -> [2009/03/14 15:40:25 | 00,040,960 | —- | M] (Realtek)
qmgr0.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2009/03/14 15:34:14 | 00,004,232 | —- | M] ()
qmgr1.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2009/03/14 15:34:13 | 00,005,847 | —- | M] ()
GoogleUpdateTaskUserS-1-5-21-1275210071-1580436667-682003330-1004.job -> %SystemRoot%\tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-1580436667-682003330-1004.job -> [2009/03/14 15:33:58 | 00,001,210 | —- | M] ()
NTUSER.DAT -> %UserProfile%\NTUSER.DAT -> [2009/03/14 14:52:59 | 11,796,480 | -H– | M] ()
stuff.html -> %UserProfile%\Desktop\stuff.html -> [2009/03/14 14:47:26 | 00,007,736 | —- | M] ()
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2009/03/14 14:35:58 | 00,000,006 | -H– | M] ()
system.ini -> %SystemRoot%\system.ini -> [2009/03/14 14:30:55 | 00,000,227 | —- | M] ()
vsconfig.xml -> %SystemRoot%\System32\vsconfig.xml -> [2009/03/14 11:19:12 | 00,352,918 | —- | M] ()
Perflib_Perfdata_660.dat -> %SystemRoot%\Temp\Perflib_Perfdata_660.dat -> [2009/03/14 11:19:02 | 00,016,384 | —- | M] ()
Perflib_Perfdata_378.dat -> %SystemRoot%\Temp\Perflib_Perfdata_378.dat -> [2009/03/14 11:19:02 | 00,016,384 | —- | M] ()
bootstat.dat -> %SystemRoot%\bootstat.dat -> [2009/03/14 11:18:28 | 00,002,048 | –S- | M] ()
fidbox.idx -> %SystemRoot%\System32\drivers\fidbox.idx -> [2009/03/13 21:57:50 | 00,633,236 | -HS- | M] ()
ntuser.ini -> %UserProfile%\ntuser.ini -> [2009/03/13 21:57:25 | 00,000,178 | -HS- | M] ()
hosts -> %SystemRoot%\System32\drivers\etc\hosts -> [2009/03/13 17:20:54 | 00,302,083 | R— | M] ()
win.ini -> %SystemRoot%\win.ini -> [2009/03/13 14:42:19 | 00,000,754 | —- | M] ()
gdlogo.swf -> %UserProfile%\Desktop\gdlogo.swf -> [2009/03/12 21:17:37 | 00,000,846 | —- | M] ()
gdlogo.fla -> %UserProfile%\Desktop\gdlogo.fla -> [2009/03/11 19:39:57 | 00,083,456 | —- | M] ()
FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2009/03/11 17:51:37 | 02,614,840 | —- | M] ()
imsins.BAK -> %SystemRoot%\imsins.BAK -> [2009/03/11 14:23:19 | 00,001,374 | —- | M] ()
GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [2009/03/11 12:03:23 | 00,277,768 | —- | M] ()
push.jpg -> %UserProfile%\Desktop\push.jpg -> [2009/03/11 11:45:34 | 00,198,647 | —- | M] ()
wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2009/03/11 11:39:19 | 00,013,646 | —- | M] ()
WORDPAD.INI -> %SystemRoot%\WORDPAD.INI -> [2009/03/08 19:00:35 | 00,000,754 | —- | M] ()
boot.ini -> %SystemDrive%\boot.ini -> [2009/03/07 17:22:16 | 00,000,281 | RHS- | M] ()
puhutibi -> %SystemRoot%\System32\puhutibi -> [2009/03/06 20:08:41 | 00,006,456 | -H– | M] ()
wininit.ini -> %SystemRoot%\wininit.ini -> [2009/03/06 15:34:54 | 00,000,211 | —- | M] ()
hosts.20090313-172054.backup -> %SystemRoot%\System32\drivers\etc\hosts.20090313-172054.backup -> [2009/03/06 14:56:59 | 00,301,855 | R— | M] ()
PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [2009/03/06 14:55:55 | 00,458,340 | —- | M] ()
hosts.20090306-145659.backup -> %SystemRoot%\System32\drivers\etc\hosts.20090306-145659.backup -> [2009/03/06 14:45:19 | 00,301,855 | R— | M] ()
seRapid.INI -> %SystemRoot%\seRapid.INI -> [2009/03/05 18:29:39 | 00,008,581 | —- | M] ()
My Sharing Folders.lnk -> %UserProfile%\My Documents\My Sharing Folders.lnk -> [2009/03/05 18:05:18 | 00,000,598 | —- | M] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009/03/04 20:13:58 | 00,114,688 | —- | M] ()
Boot.bak -> %SystemDrive%\Boot.bak -> [2009/03/01 16:37:43 | 00,000,211 | —- | M] ()
Plasmaplugs Scroll Bar Quickstart Guide (Trial).pdf -> %UserProfile%\My Documents\Plasmaplugs Scroll Bar Quickstart Guide (Trial).pdf -> [2009/02/27 22:30:54 | 00,325,610 | —- | M] ()
MRT.exe -> %SystemRoot%\System32\MRT.exe -> [2009/02/25 12:55:00 | 24,768,960 | —- | M] (Microsoft Corporation)
sqmnoopt04.sqm -> %SystemDrive%\sqmnoopt04.sqm -> [2009/02/24 19:23:57 | 00,000,244 | -H– | M] ()
sqmdata04.sqm -> %SystemDrive%\sqmdata04.sqm -> [2009/02/24 19:23:57 | 00,000,232 | -H– | M] ()
sqmnoopt03.sqm -> %SystemDrive%\sqmnoopt03.sqm -> [2009/02/24 19:23:35 | 00,000,244 | -H– | M] ()
sqmdata03.sqm -> %SystemDrive%\sqmdata03.sqm -> [2009/02/24 19:23:35 | 00,000,232 | -H– | M] ()
Grammatics.zip -> %UserProfile%\Desktop\Grammatics.zip -> [2009/02/20 16:07:33 | 90,643,434 | —- | M] ()

[Alternate Data Streams]
@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
[CatchMe Rootkit Scan by GMER]
< Windows folder & sub-folders >
scanning hidden processes …
scanning hidden services & system hive …
scanning hidden registry entries …
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8087AC70-BFCC-FFCC-CD69-BCEDAE79A4B5}]
"nafaejpagpjnheabmnbhkbnaocao"=hex:6a,61,70,6a,67,6a,6c,6b,70,6c,66,6c,6e,61,62,63,61,6e,6b,67,00,..
"oalaoigdkiafheenbpphbhfjcmkodl"=hex:6a,61,6f,6a,61,6e,62,67,70,66,6e,6d,61,6c,68,67,6a,6f,6f,68,00,..
"gbdonjpjfmeadhemcjgldpindhbhfoljjbkcpdcnpjkiij"=hex:6c,61,69,61,6b,69,6c,68,64,61,66,6c,70,6c,6c,6c,6d,6a,65,67,6f,..
"bbnodjjipgeoeehkifmkmbjccdelfaledoil"=hex:67,61,6e,70,61,6e,69,6c,62,6f,70,67,69,66,00,6c
"oalaoigdkiafheenbpphbhfjplnmnh"=hex:6a,61,70,6a,67,6a,6c,6b,70,6c,66,6c,6e,61,62,63,61,6e,6b,67,00,..
"nafaejpagpjnheabmnbhkboancja"=hex:6a,61,70,6a,67,6a,6c,6b,70,6c,66,6c,6e,61,62,63,61,6e,6b,67,00,..
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 6
< Document and Settings folder & sub folders >
scanning hidden files …
C:\Documents and Settings\All Users\Application Data\Symantec\hpc:3898751835 113 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:364682BC 104 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:8CE646EE 119 bytes
C:\Documents and Settings\Lawrie\Favorites\Abandonia - Home of abandonware DOS games.url:favicon 1150 bytes
C:\Documents and Settings\Lawrie.GORT\Cookies\[removed][2].txt 2194 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Bugmenot.com - login with these free web passwords to bypass compulsory registration.url:favicon 3638 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\CineWord Nottingham.url:favicon 1406 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Em Calculator.url:favicon 1406 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Flickr API Documentation.url:favicon 0 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Krop - Creative & Tech Jobs.url:favicon 1150 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Mumfy\52 Cupcakes.url:favicon 3638 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Mumfy\BBC - Food - Recipes - Chorizo chicken with sauteed chorizo, potatoes and spinach.url:favicon 958 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Mumfy\How To Make A Gumpaste Stargazer Lily (Asian Lily) on CakeCentral.com.url:favicon 1022 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Mumfy\Sprinkles Cupcakes Flavors.url:favicon 3638 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Radio Times TV listings grid.url:favicon 3638 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\The Anonymous Philanthropist.url:favicon 2550 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\tunecore - digital distribution.url:favicon 894 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\WhatTheFont MyFonts.url:favicon 318 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Who is Hosting This.url:favicon 3638 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Zamzar - Free online file conversion.url:favicon 3638 bytes
C:\Documents and Settings\Mumfy\Local Settings\Temporary Internet Files\AntiPhishing\07FB382D-AA75-4683-82F4-EAB265A275CB.dat 78924 bytes
C:\Documents and Settings\Mumfy\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat 78924 bytes
scan completed successfully


Thanks for the help.
Hi,

Please download GooredFix and save it to your Desktop.
  • Double-click GooredFix.exe on your Desktop to run it.
  • Select "2. Fix Goored" by typing 2 and pressing Enter.
  • Make sure all instances of Firefox are closed at this point.
  • Type y at the prompt and press Enter again.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: If you receive a message saying that GooredFix needs your system to be restarted, please close all applications and reboot your system. Please also allow any registry changes that may be prompted by any of your security programs.


Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Thanks.
Done. Here's my GooredFix log (it seems quite short…?)

GooredFix v1.92 by jpshortstuff
Log created at 11:51 on 16/03/2009 running Option #2 (Lawrie)
Firefox version 3.0.7 (en-GB)
(Subsequent Run)

=====Goored Deletions=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.7\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.7\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"


DDS: DDS.txt

DDS (Ver_09-03-16.01) - NTFSx86
Run by [removed] at 11:52:13.18 on 16/03/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2039.1438 [GMT 0:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated)
FW: ZoneAlarm Firewall *enabled*

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Documents and Settings\Lawrie.GORT\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Lawrie.GORT\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
TB: &Google; Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Lexmark 1200 Series] "c:\program files\lexmark 1200 series\lxczbmgr.exe"
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: Sothink SWF Catcher - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://128.243.100.37/activex/AMC.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\lawrie~1.gor\applic~1\mozilla\firefox\profiles\rsdedr0s.default\
FF - component: c:\documents and settings\lawrie.gort\application data\mozilla\firefox\profiles\rsdedr0s.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - plugin: c:\documents and settings\lawrie.gort\local settings\application data\google\update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npitunes.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-10-24 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-10-24 26824]
R1 KLIF;KLIF;c:\windows\system32\drivers\klif.sys [2008-7-15 127768]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2008-1-26 394952]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-10-24 231704]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-3-6 24652]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?]
S3 SQTECH930B;Trust WB-3500T USB2 Webcam;c:\windows\system32\drivers\Capt930b.sys [2008-3-5 273982]

=============== Created Last 30 ================

2009-03-14 14:23

–d—– C:\ComboFix
2009-03-07 17:22 a-dshr– C:\cmdcons
2009-03-06 20:14 3,218 a——- c:\windows\system32\PerfStringBackup.TMP
2009-03-06 16:47 –d—– c:\docume~1\lawrie~1.gor\applic~1\Malwarebytes
2009-03-06 16:47 15,504 a——- c:\windows\system32\drivers\mbam.sys
2009-03-06 16:47 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-06 16:47 –d—– c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2009-03-06 16:47 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-02-24 19:23 244 a—h— C:\sqmnoopt04.sqm
2009-02-24 19:23 232 a—h— C:\sqmdata04.sqm
2009-02-24 19:23 244 a—h— C:\sqmnoopt03.sqm
2009-02-24 19:23 232 a—h— C:\sqmdata03.sqm

==================== Find3M ====================

2009-03-16 11:52 54,028,320 a–sh— c:\windows\system32\drivers\fidbox.dat
2009-03-14 20:57 636,092 a–sh— c:\windows\system32\drivers\fidbox.idx
2009-02-09 11:13 1,846,784 a——- c:\windows\system32\win32k.sys
2009-01-31 17:28 73,312 a——- c:\windows\system32\drivers\adfs.sys
2009-01-08 11:10 410,984 a——- c:\windows\system32\deploytk.dll
2008-12-24 17:49 10,022 a–sh— c:\windows\system32\KGyGaAvL.sys
2008-12-20 23:15 826,368 a——- c:\windows\system32\wininet.dll
2008-01-29 22:03 25,600 a——- c:\documents and settings\lawrie.gort\usbsermptxp.sys
2008-01-29 22:03 22,768 a——- c:\documents and settings\lawrie.gort\usbsermpt.sys
2005-11-02 20:51 186 a——- c:\program files\Warez P2P ClientIPGUARD.LOG
2008-09-21 09:32 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092120080922\index.dat

============= FINISH: 11:53:31.50 ===============


DDS: Attach.txt attached.

Attachments:

Hi,

Yeah, the logs are usually quite short. Didn't find anything though, that surprised me.

Click Start >> Control Panel >> Add/Remove Programs. Find each of these items and select Remove.
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7


Are you getting these redirects in Firefox, Internet Explorer, both?

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :reg
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
    
    :dir
    %programfiles%\Mozilla Firefox\extensions /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Thanks.
It was only happening in Firefox, but I've just done a couple of searches that invariably threw up the redirection ('property' was a real bugger for it), and the redirection isn't happening any more (huzzah!) and from what I can see from Firebug, none of the adwarefeed or clickfraudmanager scripts are appearing anymore. Is it possible that I inadvertently removed it during all my malware scanning?

Here's my systemlook log:

SystemLook v1.0 by jpshortstuff (02.03.09)
Log created at 15:20 on 16/03/2009 by Lawrie (Administrator - Elevation successful)

========== reg ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"aux"="wdmaud.drv"
"midi"="wdmaud.drv"
"midimapper"="midimap.dll"
"mixer"="DrvTrNTm.dll"
"mixer1"="wdmaud.drv"
"msacm.ac3acm"="AC3ACM.acm"
"msacm.alf2cd"="alf2cd.acm"
"msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm"
"msacm.msadpcm"="msadp32.acm"
"msacm.msaudio1"="msaud32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msg723"="msg723.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.scg726"="scg726.acm"
"msacm.siren"="sirenacm.dll"
"msacm.sl_anet"="sl_anet.acm"
"msacm.trspch"="tssoft32.acm"
"msacm.vorbis"="vorbis.acm"
"msacm.voxacm160"="vct3216.acm"
"MSVideo"="CSvidcap.dll"
"MSVideo8"="VfWWDM32.dll"
"vidc.cvid"="iccvid.dll"
"vidc.DIVX"="DivX.dll"
"vidc.dvsd"="mcdvd_32.dll"
"VIDC.FFDS"="C:\Program Files\ffdshow\ffdshow.ax"
"VIDC.I420"="msh263.drv"
"vidc.iv31"="ir32_32.dll"
"vidc.iv32"="ir32_32.dll"
"vidc.iv41"="ir41_32.ax"
"vidc.iv50"="ir50_32.dll"
"VIDC.IYUV"="iyuv_32.dll"
"vidc.M261"="msh261.drv"
"vidc.M263"="msh263.drv"
"vidc.mjpg"="pvmjpg30.dll"
"vidc.mp42"="mpg4c32.dll"
"vidc.mp43"="mpg4c32.dll"
"vidc.mpg4"="mpg4c32.dll"
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"vidc.tscc"="tsccvid.dll"
"VIDC.UYVY"="msyuv.dll"
"vidc.VSPX"="vspxvfw.dll"
"vidc.xvid"="xvidvfw.dll"
"VIDC.YUY2"="msyuv.dll"
"VIDC.YVU9"="tsbyuv.dll"
"VIDC.YVYU"="msyuv.dll"
"wave"="DrvTrNTm.dll"
"wave1"="wdmaud.drv"
"wavemapper"="msacm32.drv"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\Terminal Server]


========== dir ==========

C:\Program Files\Mozilla Firefox\extensions - Parameters: "/s"

—Files—
Extensions.rdf –a— 1109 bytes [11:51 23/09/2004] [11:51 23/09/2004]
installed-extensions-processed.txt –a— 46 bytes [11:51 23/09/2004] [21:57 13/09/2004]

C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} d—– [11:51 23/09/2004]
install.rdf –a— 1390 bytes [11:51 23/09/2004] [17:01 08/03/2009]

C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\chrome d—– [15:25 01/10/2004]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} d—– [13:35 02/06/2007]
chrome.manifest –a— 788 bytes [13:35 02/06/2007] [13:35 02/06/2007]
install.rdf –a— 670 bytes [13:35 02/06/2007] [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome d—– [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\content d—– [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\content\ffjcext d—– [13:35 02/06/2007]
ffjcext.js –a— 1232 bytes [13:35 02/06/2007] [13:35 02/06/2007]
ffjcext.xul –a— 510 bytes [13:35 02/06/2007] [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale d—– [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\de-DE d—– [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext d—– [13:35 02/06/2007]
ffjcext.dtd –a— 94 bytes [13:35 02/06/2007] [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\en-US d—– [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext d—– [13:35 02/06/2007]
ffjcext.dtd –a— 94 bytes [13:35 02/06/2007] [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\es-ES d—– [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext d—– [13:35 02/06/2007]
ffjcext.dtd –a— 94 bytes [13:35 02/06/2007] [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\fr-FR d—– [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext d—– [13:35 02/06/2007]
ffjcext.dtd –a— 94 bytes [13:35 02/06/2007] [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\it-IT d—– [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext d—– [13:35 02/06/2007]
ffjcext.dtd –a— 94 bytes [13:35 02/06/2007] [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\ja-JP d—– [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext d—– [13:35 02/06/2007]
ffjcext.dtd –a— 94 bytes [13:35 02/06/2007] [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\ko-KR d—– [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext d—– [13:35 02/06/2007]
ffjcext.dtd –a— 94 bytes [13:35 02/06/2007] [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\sv-SE d—– [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext d—– [13:35 02/06/2007]
ffjcext.dtd –a— 94 bytes [13:35 02/06/2007] [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\zh-CN d—– [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext d—– [13:35 02/06/2007]
ffjcext.dtd –a— 94 bytes [13:35 02/06/2007] [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\zh-TW d—– [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext d—– [13:35 02/06/2007]
ffjcext.dtd –a— 94 bytes [13:35 02/06/2007] [13:35 02/06/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} d—– [13:04 02/08/2007]
chrome.manifest –a— 788 bytes [13:04 02/08/2007] [13:04 02/08/2007]
install.rdf –a— 671 bytes [13:04 02/08/2007] [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome d—– [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\content d—– [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\content\ffjcext d—– [13:04 02/08/2007]
ffjcext.js –a— 1232 bytes [13:04 02/08/2007] [13:04 02/08/2007]
ffjcext.xul –a— 510 bytes [13:04 02/08/2007] [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale d—– [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\de-DE d—– [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext d—– [13:04 02/08/2007]
ffjcext.dtd –a— 94 bytes [13:04 02/08/2007] [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\en-US d—– [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext d—– [13:04 02/08/2007]
ffjcext.dtd –a— 94 bytes [13:04 02/08/2007] [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\es-ES d—– [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext d—– [13:04 02/08/2007]
ffjcext.dtd –a— 94 bytes [13:04 02/08/2007] [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\fr-FR d—– [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext d—– [13:04 02/08/2007]
ffjcext.dtd –a— 94 bytes [13:04 02/08/2007] [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\it-IT d—– [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext d—– [13:04 02/08/2007]
ffjcext.dtd –a— 94 bytes [13:04 02/08/2007] [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\ja-JP d—– [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext d—– [13:04 02/08/2007]
ffjcext.dtd –a— 94 bytes [13:04 02/08/2007] [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\ko-KR d—– [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext d—– [13:04 02/08/2007]
ffjcext.dtd –a— 94 bytes [13:04 02/08/2007] [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\sv-SE d—– [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext d—– [13:04 02/08/2007]
ffjcext.dtd –a— 94 bytes [13:04 02/08/2007] [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\zh-CN d—– [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext d—– [13:04 02/08/2007]
ffjcext.dtd –a— 94 bytes [13:04 02/08/2007] [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\zh-TW d—– [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext d—– [13:04 02/08/2007]
ffjcext.dtd –a— 94 bytes [13:04 02/08/2007] [13:04 02/08/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} d—– [10:57 03/12/2007]
chrome.manifest –a— 788 bytes [10:57 03/12/2007] [10:33 06/02/2008]
install.rdf –a— 671 bytes [10:57 03/12/2007] [10:33 06/02/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome d—– [10:57 03/12/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\content d—– [10:57 03/12/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\content\ffjcext d—– [10:57 03/12/2007]
ffjcext.js –a— 1232 bytes [10:57 03/12/2007] [10:33 06/02/2008]
ffjcext.xul –a— 510 bytes [10:57 03/12/2007] [10:33 06/02/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale d—– [10:57 03/12/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\de-DE d—– [10:57 03/12/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext d—– [10:57 03/12/2007]
ffjcext.dtd –a— 94 bytes [10:57 03/12/2007] [10:33 06/02/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\en-US d—– [10:57 03/12/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext d—– [10:57 03/12/2007]
ffjcext.dtd –a— 94 bytes [10:57 03/12/2007] [10:33 06/02/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\es-ES d—– [10:57 03/12/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext d—– [10:57 03/12/2007]
ffjcext.dtd –a— 94 bytes [10:57 03/12/2007] [10:33 06/02/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\fr-FR d—– [10:57 03/12/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext d—– [10:57 03/12/2007]
ffjcext.dtd –a— 94 bytes [10:57 03/12/2007] [10:33 06/02/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\it-IT d—– [10:57 03/12/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext d—– [10:57 03/12/2007]
ffjcext.dtd –a— 94 bytes [10:57 03/12/2007] [10:33 06/02/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\ja-JP d—– [10:57 03/12/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext d—– [10:57 03/12/2007]
ffjcext.dtd –a— 94 bytes [10:57 03/12/2007] [10:33 06/02/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\ko-KR d—– [10:57 03/12/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext d—– [10:57 03/12/2007]
ffjcext.dtd –a— 94 bytes [10:57 03/12/2007] [10:33 06/02/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\sv-SE d—– [10:57 03/12/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext d—– [10:57 03/12/2007]
ffjcext.dtd –a— 94 bytes [10:57 03/12/2007] [10:33 06/02/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\zh-CN d—– [10:57 03/12/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext d—– [10:57 03/12/2007]
ffjcext.dtd –a— 94 bytes [10:57 03/12/2007] [10:33 06/02/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\zh-TW d—– [10:57 03/12/2007]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext d—– [10:57 03/12/2007]
ffjcext.dtd –a— 94 bytes [10:57 03/12/2007] [10:33 06/02/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} d—– [09:51 07/07/2008]
chrome.manifest –a— 788 bytes [09:51 07/07/2008] [09:51 07/07/2008]
install.rdf –a— 671 bytes [09:51 07/07/2008] [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome d—– [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\content d—– [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\content\ffjcext d—– [09:51 07/07/2008]
ffjcext.js –a— 1232 bytes [09:51 07/07/2008] [09:51 07/07/2008]
ffjcext.xul –a— 510 bytes [09:51 07/07/2008] [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale d—– [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\de-DE d—– [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext d—– [09:51 07/07/2008]
ffjcext.dtd –a— 94 bytes [09:51 07/07/2008] [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\en-US d—– [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext d—– [09:51 07/07/2008]
ffjcext.dtd –a— 94 bytes [09:51 07/07/2008] [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\es-ES d—– [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext d—– [09:51 07/07/2008]
ffjcext.dtd –a— 94 bytes [09:51 07/07/2008] [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\fr-FR d—– [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext d—– [09:51 07/07/2008]
ffjcext.dtd –a— 94 bytes [09:51 07/07/2008] [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\it-IT d—– [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext d—– [09:51 07/07/2008]
ffjcext.dtd –a— 94 bytes [09:51 07/07/2008] [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\ja-JP d—– [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext d—– [09:51 07/07/2008]
ffjcext.dtd –a— 94 bytes [09:51 07/07/2008] [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\ko-KR d—– [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext d—– [09:51 07/07/2008]
ffjcext.dtd –a— 94 bytes [09:51 07/07/2008] [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\sv-SE d—– [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext d—– [09:51 07/07/2008]
ffjcext.dtd –a— 94 bytes [09:51 07/07/2008] [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\zh-CN d—– [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext d—– [09:51 07/07/2008]
ffjcext.dtd –a— 94 bytes [09:51 07/07/2008] [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\zh-TW d—– [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext d—– [09:51 07/07/2008]
ffjcext.dtd –a— 94 bytes [09:51 07/07/2008] [09:51 07/07/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} d—– [10:20 07/08/2008]
chrome.manifest –a— 788 bytes [10:20 07/08/2008] [10:20 07/08/2008]
install.rdf –a— 671 bytes [10:20 07/08/2008] [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome d—– [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\content d—– [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\content\ffjcext d—– [10:20 07/08/2008]
ffjcext.js –a— 1232 bytes [10:20 07/08/2008] [10:20 07/08/2008]
ffjcext.xul –a— 510 bytes [10:20 07/08/2008] [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale d—– [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\de-DE d—– [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext d—– [10:20 07/08/2008]
ffjcext.dtd –a— 94 bytes [10:20 07/08/2008] [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\en-US d—– [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext d—– [10:20 07/08/2008]
ffjcext.dtd –a— 94 bytes [10:20 07/08/2008] [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\es-ES d—– [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext d—– [10:20 07/08/2008]
ffjcext.dtd –a— 94 bytes [10:20 07/08/2008] [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\fr-FR d—– [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext d—– [10:20 07/08/2008]
ffjcext.dtd –a— 94 bytes [10:20 07/08/2008] [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\it-IT d—– [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext d—– [10:20 07/08/2008]
ffjcext.dtd –a— 94 bytes [10:20 07/08/2008] [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\ja-JP d—– [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext d—– [10:20 07/08/2008]
ffjcext.dtd –a— 94 bytes [10:20 07/08/2008] [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\ko-KR d—– [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext d—– [10:20 07/08/2008]
ffjcext.dtd –a— 94 bytes [10:20 07/08/2008] [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\sv-SE d—– [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext d—– [10:20 07/08/2008]
ffjcext.dtd –a— 94 bytes [10:20 07/08/2008] [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\zh-CN d—– [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext d—– [10:20 07/08/2008]
ffjcext.dtd –a— 94 bytes [10:20 07/08/2008] [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\zh-TW d—– [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext d—– [10:20 07/08/2008]
ffjcext.dtd –a— 94 bytes [10:20 07/08/2008] [10:20 07/08/2008]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} d—– [11:11 08/01/2009]
chrome.manifest –a— 788 bytes [11:11 08/01/2009] [11:11 08/01/2009]
install.rdf –a— 671 bytes [11:11 08/01/2009] [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome d—– [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\content d—– [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\content\ffjcext d—– [11:11 08/01/2009]
ffjcext.js –a— 1232 bytes [11:11 08/01/2009] [11:11 08/01/2009]
ffjcext.xul –a— 510 bytes [11:11 08/01/2009] [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale d—– [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\de-DE d—– [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext d—– [11:11 08/01/2009]
ffjcext.dtd –a— 94 bytes [11:11 08/01/2009] [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\en-US d—– [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext d—– [11:11 08/01/2009]
ffjcext.dtd –a— 94 bytes [11:11 08/01/2009] [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\es-ES d—– [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext d—– [11:11 08/01/2009]
ffjcext.dtd –a— 94 bytes [11:11 08/01/2009] [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\fr-FR d—– [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext d—– [11:11 08/01/2009]
ffjcext.dtd –a— 94 bytes [11:11 08/01/2009] [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\it-IT d—– [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext d—– [11:11 08/01/2009]
ffjcext.dtd –a— 94 bytes [11:11 08/01/2009] [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\ja-JP d—– [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext d—– [11:11 08/01/2009]
ffjcext.dtd –a— 94 bytes [11:11 08/01/2009] [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\ko-KR d—– [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext d—– [11:11 08/01/2009]
ffjcext.dtd –a— 94 bytes [11:11 08/01/2009] [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\sv-SE d—– [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext d—– [11:11 08/01/2009]
ffjcext.dtd –a— 94 bytes [11:11 08/01/2009] [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\zh-CN d—– [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext d—– [11:11 08/01/2009]
ffjcext.dtd –a— 94 bytes [11:11 08/01/2009] [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\zh-TW d—– [11:11 08/01/2009]

C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext d—– [11:11 08/01/2009]
ffjcext.dtd –a— 94 bytes [11:11 08/01/2009] [11:11 08/01/2009]

-=End Of File=-


Thanks!
Hi, Just noticed that you ran GooredFix more than once. Most likely the bad stuff was removed in its first run. Have you got a GooredFix Backups folder on your Desktop and is there anything in it? If there is, then that's all fine. Any other problems/questions? Thanks.
Yep, there's a GooredFix Backups folder. I ran it twice just to make sure that it hadn't frozen the first time (on account of the small log file). I think that's it then! Thanks for your help!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI