This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Registry Logs

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm sure the Registry need cleaning up…let me know.

Big Bob


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:44:01 PM, on 6/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\Program Files\AVG\AVG8\avgrsx.exe
G:\WINDOWS\system32\spoolsv.exe
G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
G:\Program Files\Bonjour\mDNSResponder.exe
G:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
G:\WINDOWS\system32\HPZipm12.exe
G:\WINDOWS\System32\svchost.exe
G:\Program Files\Viewpoint\Common\ViewpointService.exe
G:\WINDOWS\Explorer.EXE
G:\WINDOWS\system32\wscntfy.exe
G:\Program Files\Real\RealPlayer\RealPlay.exe
G:\Program Files\QuickTime\qttask.exe
G:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
G:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
G:\Program Files\iTunes\iTunesHelper.exe
G:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
G:\WINDOWS\system32\devldr32.exe
G:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
G:\Program Files\ICQLite\ICQLite.exe
G:\WINDOWS\System32\hphmon04.exe
G:\Program Files\DownloadWare Engine\DWE.EXE
G:\PROGRA~1\DOWNLO~2\alp2plib.exe
G:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
G:\Program Files\MSN Messenger\MsnMsgr.Exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Messenger\msmsgs.exe
G:\WINDOWS\system32\sol.exe
G:\Program Files\AIM6\aim6.exe
G:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
G:\Program Files\GetRight\GetRight.exe
G:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
G:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
G:\Program Files\iPod\bin\iPodService.exe
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
G:\Program Files\AIM6\aolsoftware.exe
G:\Program Files\Hewlett-Packard\Digital Imaging\Product Assistant\bin\hprblog.exe
G:\Program Files\Mozilla Firefox\firefox.exe
G:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IE to GetRight Helper - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - G:\Program Files\GetRight\xx2gr.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - G:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - G:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - G:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - G:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - G:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {A6ACAE64-F798-4930-AD86-BD3FB32038DB} - G:\Program Files\Video ActiveX Object\isadd.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - G:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - G:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - G:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RealTray] G:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] G:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HP Software Update] G:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "G:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WhenUSave] G:\PROGRA~1\Save\Save.exe
O4 - HKLM\..\Run: [WeatherOnTray] G:\Program Files\Hotbar\bin\4.4.5.0\WeatherOnTray.exe
O4 - HKLM\..\Run: [wcmdmgr] G:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] G:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SearchEnhancement] "G:\Program Files\scbar\v1\scbar.exe" /U
O4 - HKLM\..\Run: [SBHC] G:\Program Files\SuperBar\sbhc.exe
O4 - HKLM\..\Run: [P2P Networking2] G:\WINDOWS\System32\P2P Networking\P2P Networking2.exe /AUTOSTART
O4 - HKLM\..\Run: [P2P Networking] G:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [New.net Startup] rundll32 G:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
O4 - HKLM\..\Run: [NeroFilterCheck] G:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] G:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] G:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [KAZAA] G:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [ICQ Lite] G:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [HPHUPD04] "G:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [HPHmon04] G:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [Hotbar] G:\Program Files\Hotbar\bin\4.4.5.0\HbInst.exe /Upgrade
O4 - HKLM\..\Run: [DownloadWare Engine] "G:\Program Files\DownloadWare Engine\DWE.EXE" /H
O4 - HKLM\..\Run: [DownloadWare] "G:\Program Files\DownloadWare\dw.exe" /H
O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
O4 - HKLM\..\Run: [AVG8_TRAY] G:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] G:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MsnMsgr] "G:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Weather] G:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [WeatherCast] G:\PROGRA~1\WEATHE~1\Weather.exe /q
O4 - HKCU\..\Run: [MSMSGS] "G:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [eZmmod] G:\PROGRA~1\ezula\mmod.exe
O4 - HKCU\..\Run: [Aim6] "G:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\RunOnce: [ICQ Lite] G:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - S-1-5-18 Startup: PowerReg SchedulerV2.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: PowerReg SchedulerV2.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = G:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = G:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: GetRight.lnk = G:\Program Files\GetRight\GetRight.exe
O4 - Global Startup: GStartup.lnk = G:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = G:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = G:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///G:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download with GetRight - G:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - G:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///G:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///G:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///G:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - G:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - G:\Program Files\AIM95\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - G:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - G:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - G:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - G:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{834E90FA-F60A-4D80-A495-EA091A51B150}: NameServer = 216.98.128.70 216.98.138.70
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - G:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - G:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - G:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - G:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - G:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - G:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPH11 - HP - G:\WINDOWS\System32\HPHipm11.exe
O23 - Service: Pml Driver HPZ12 - HP - G:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - G:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 11083 bytes


StartupList report, 6/10/2009, 9:44:25 PM
StartupList version: 1.52.2
Started from : G:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\Program Files\AVG\AVG8\avgrsx.exe
G:\WINDOWS\system32\spoolsv.exe
G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
G:\Program Files\Bonjour\mDNSResponder.exe
G:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
G:\WINDOWS\system32\HPZipm12.exe
G:\WINDOWS\System32\svchost.exe
G:\Program Files\Viewpoint\Common\ViewpointService.exe
G:\WINDOWS\Explorer.EXE
G:\WINDOWS\system32\wscntfy.exe
G:\Program Files\Real\RealPlayer\RealPlay.exe
G:\Program Files\QuickTime\qttask.exe
G:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
G:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
G:\Program Files\iTunes\iTunesHelper.exe
G:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
G:\WINDOWS\system32\devldr32.exe
G:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
G:\Program Files\ICQLite\ICQLite.exe
G:\WINDOWS\System32\hphmon04.exe
G:\Program Files\DownloadWare Engine\DWE.EXE
G:\PROGRA~1\DOWNLO~2\alp2plib.exe
G:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
G:\Program Files\MSN Messenger\MsnMsgr.Exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Messenger\msmsgs.exe
G:\WINDOWS\system32\sol.exe
G:\Program Files\AIM6\aim6.exe
G:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
G:\Program Files\GetRight\GetRight.exe
G:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
G:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
G:\Program Files\iPod\bin\iPodService.exe
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
G:\Program Files\AIM6\aolsoftware.exe
G:\Program Files\Hewlett-Packard\Digital Imaging\Product Assistant\bin\hprblog.exe
G:\Program Files\Mozilla Firefox\firefox.exe
G:\WINDOWS\system32\NOTEPAD.EXE
G:\Program Files\Trend Micro\HijackThis\HijackThis.exe

————————————————–

Listing of startup folders:

Shell folders Common Startup:
[G:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Gamma Loader.exe.lnk = G:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Adobe Reader Speed Launch.lnk = G:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
GetRight.lnk = G:\Program Files\GetRight\GetRight.exe
GStartup.lnk = G:\Program Files\Common Files\GMT\GMT.exe
HP Digital Imaging Monitor.lnk = G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
InterVideo WinCinema Manager.lnk = G:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
Microsoft Office.lnk = G:\Program Files\Microsoft Office\Office10\OSA.EXE

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = G:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

RealTray = G:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
QuickTime Task = "G:\Program Files\QuickTime\qttask.exe" -atboottime
HPDJ Taskbar Utility = G:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
HP Software Update = G:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
iTunesHelper = "G:\Program Files\iTunes\iTunesHelper.exe"
WhenUSave = G:\PROGRA~1\Save\Save.exe
WeatherOnTray = G:\Program Files\Hotbar\bin\4.4.5.0\WeatherOnTray.exe
wcmdmgr = G:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
Share-to-Web Namespace Daemon = G:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
SearchEnhancement = "G:\Program Files\scbar\v1\scbar.exe" /U
SBHC = G:\Program Files\SuperBar\sbhc.exe
P2P Networking2 = G:\WINDOWS\System32\P2P Networking\P2P Networking2.exe /AUTOSTART
P2P Networking = G:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
nwiz = nwiz.exe /install
NvCplDaemon = RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup
New.net Startup = rundll32 G:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
NeroFilterCheck = G:\WINDOWS\system32\NeroCheck.exe
MyWebSearch Email Plugin = G:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
Microsoft Works Update Detection = G:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
KAZAA = G:\Program Files\Kazaa\kazaa.exe /SYSTRAY
ICQ Lite = G:\Program Files\ICQLite\ICQLite.exe -minimize
HPHUPD04 = "G:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
HPHmon04 = G:\WINDOWS\System32\hphmon04.exe
Hotbar = G:\Program Files\Hotbar\bin\4.4.5.0\HbInst.exe /Upgrade
DownloadWare Engine = "G:\Program Files\DownloadWare Engine\DWE.EXE" /H
DownloadWare = "G:\Program Files\DownloadWare\dw.exe" /H
AltnetPointsManager = c:\program files\altnet\points manager\points manager.exe -s
AVG8_TRAY = G:\PROGRA~1\AVG\AVG8\avgtray.exe

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Yahoo! Pager = G:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
MsnMsgr = "G:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
ctfmon.exe = G:\WINDOWS\system32\ctfmon.exe
Weather = G:\Program Files\AWS\WeatherBug\Weather.exe 1
WeatherCast = G:\PROGRA~1\WEATHE~1\Weather.exe /q
MSMSGS = "G:\Program Files\Messenger\msmsgs.exe" /background
eZmmod = G:\PROGRA~1\ezula\mmod.exe
Aim6 = "G:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

ICQ Lite = G:\Program Files\ICQLite\ICQLite.exe -trayboot

————————————————–

Shell & screensaver key from G:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=G:\WINDOWS\System32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - G:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - G:\Program Files\GetRight\xx2gr.dll - {31FF080D-12A3-439A-A2EF-4BA95A3148E8}
WormRadar.com IESiteBlocker.NavFilter - G:\Program Files\AVG\AVG8\avgssie.dll - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
(no name) - G:\Program Files\Yahoo!\Common\yiesrvc.dll - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
(no name) - G:\Program Files\Yahoo!\Common\YIeTagBm.dll - {65D886A2-7CA7-479B-BB95-14D1EFB7946A}
(no name) - (no file) - {7E853D72-626A-48EC-A868-BA8D5E23E045}
(no name) - G:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}
(no name) - G:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll - {9394EDE7-C8B5-483E-8773-474BF36AF6E4}
(no name) - G:\Program Files\Video ActiveX Object\isadd.dll (file missing) - {A6ACAE64-F798-4930-AD86-BD3FB32038DB}
(no name) - G:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}

————————————————–

Enumerating Task Scheduler jobs:

WGASetup.job

————————————————–

Enumerating Download Program Files:

[Microsoft Office Template and Media Control]
InProcServer32 = G:\WINDOWS\Downloaded Program Files\IEAWSDC.DLL
CODEBASE = http://office.microsoft.com/templates/ieawsdc.cab

[Shockwave ActiveX Control]
InProcServer32 = G:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwa…director/sw.cab

[YInstStarter Class]
InProcServer32 = G:\Program Files\Yahoo!\Common\yinsthelper.dll
CODEBASE = G:\Program Files\Yahoo!\Common\yinsthelper.dll

[{9F1C11AA-197B-4942-BA54-47A8489BB47F}]
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/…7599.4661111111

[Shockwave Flash Object]
InProcServer32 = G:\WINDOWS\system32\macromed\flash\Flash.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa…ash/swflash.cab

————————————————–

Enumerating Winsock LSP files:

NameSpace #4: G:\Program Files\Bonjour\mdnsNSP.dll

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: G:\WINDOWS\system32\SHELL32.dll
CDBurn: G:\WINDOWS\system32\SHELL32.dll
WebCheck: G:\WINDOWS\System32\webcheck.dll
SysTray: G:\WINDOWS\System32\stobject.dll

————————————————–
End of report, 10,087 bytes
Report generated in 0.130 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Due, in part, to the large numbers of HJT logs being posted, there are four things that you need to be aware of.

1) If you have already posted this log at another forum, you need to post here that you have done so and this topic will be closed.
Multiple posting not only ties up valuable resources, but could also result is some unpleasant side-effects for your system if you follow two sets of instructions at the same time.
If, during research, an identical log is identified at another forum, this thread will be closed.

2) If you don't post a meaningful reply to any of my posts within five days, this thread will be closed. Due to limited free time, I can only have so many open threads at any one time and if yours isn't active, somebody else's will be.
If, by omission, the thread hasn't be closed after five days and you post, it will just serve as a reminder to me to close it.
Please note that "I just dropped in to say Hi!" isn't a meaningful reply!

3) Malware removal is a tricky business, and malware writers don't tend to worry about the damage their creations do, so it is advisable to back-up all important files BEFORE we start. Although most cases have a successful conclusion, on occasion things don't go according to plan and it is better to be prepared for the worst.

4) Back-ups can get lost or damaged, so make two if the files are that important to you!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pay a visit to the Kaspersky Online Scanner 7 - I.E. is preferred for this scan.
  • Read the Information panel and then click Accept.
  • Allow the ActiveX download if necessary.
  • Both the anti-virus engine and database will need to be downloaded, which may take a little time.
  • Once this has been completed, select My Computer from the Scan section on the left hand side.
  • Put the kettle on!
  • Although it is recommended by Kaspersky that you should disable your anti-virus scanner before starting this scan, it should work OK with it still active - it does on my PC.
    Although you may find the scan speed increases if you carry out this step, I never like to disable my resident scanner while online, so I don't.
  • When the scan has completed, click View scan report at the bottom.
  • Click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save and pick a location for the file - the Desktop is always handy.
Copy and paste the report into your next reply along with a fresh HJT log, run in Normal Mode, and a description of how your PC is behaving.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download Sec-Info2.zip from here and save it to your Desktop. You will need to extract the file.

Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


You should now see a folder with a .vbs file in it. Double click Sec-info2.vbs to run it and a text file called Sec-Info.txt should be created in the same folder - either that or you'll get an error message.
Please copy and paste the contents of the text file into your next reply and then you can delete both of the folders and their contents.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
Unable to provide requested data from Kaspersky Scanner 7. Internet Explorer freezes while attempting download of software. Please advise… Big Bob Ad-aware 6 Personal Adobe Acrobat 5.0 Adobe Download Manager (Remove Only) Adobe Flash Player 10 Plugin Adobe Photoshop 6.0 Adobe Reader 7.0 Adobe SVG Viewer AIM 6 Alchemy Deluxe 1.3z AnalogX POW! AOL Instant Messenger Apple Mobile Device Support Apple Software Update AVG 8.0 BASIC Stamp Editor v2.2 Batch Assistant BlazeDVD V1.5 Bonjour Charlie's Angels Angel X (remove only) Choice Guard Data Compiler DivX 5.0.3 Bundle DownloadWare Engine EPSON Printer Software Fun Web Products Easy Installer GetRight Global DiVX Player GTAIII Hexic Deluxe HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954708) Hotfix for Windows XP (KB961118) HP Extended Capabilities 5.3 HP Image Zone Express HP Imaging Device Functions 5.3 hp instant support HP Memories Disc HP Photo and Imaging 2.0 - Photosmart Printer Series HP PSC & OfficeJet 5.3.B HP Software Update HP Solution Center & Imaging Support Tools 5.3 ICQ Lite Indexing Function InstaForm Invoices & Estimates Pro InterActual Player Internet Explorer Security Plugin 2006 Internet Security Add-On InterVideo Installer InterVideo WinDVD4 iTunes Java 2 Runtime Environment Standard Edition v1.3.1_04 Junk Mail filter update Kazaa Media Desktop 2.6.3 Learn2 Player (Uninstall Only) LimeWire Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 Microsoft Data Access Components KB870669 Microsoft Motocross Madness 2 Microsoft Office Live Add-in 1.3 Microsoft Office XP Professional with FrontPage Microsoft Picture It! Express 2000 Microsoft Picture It! Express 7.0 Microsoft Search Enhancement Pack Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Visual C++ 2005 Redistributable mIRC Mozilla (1.2.1) Mozilla Firefox (3.0.10) MSN Toolbar MSVCRT MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 6 Service Pack 2 (KB954459) Nero 6 Ultra Edition PCB123 V3.3.2 Photosmart 130,230,7150,7345,7350,7550 (Remove only) Print Artist Gold 21 Public Messenger ver 2.03 QuickTime RealPlayer Basic RegistryFix v6.2 Remote Administrator v2.0 Rhapsody Player Engine Safe-Share SBM OS Search Assistant - My Web Search Search OS Security Update for CAPICOM (KB931906) Security Update for CAPICOM (KB931906) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB911565) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB942615) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944338) Security Update for Windows XP (KB944533) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB947864) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB948881) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Segoe UI Shockwave SimCoaster Support Software Tina 7 - TI TinyCAD 2.60.01 TP HTTP Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB925720) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB942840) Update for Windows XP (KB946627) Update for Windows XP (KB951072-v2) Update for Windows XP (KB955839) Update for Windows XP (KB967715) URL.IE APP Video ActiveX Object 2.07 Viewpoint Manager (Remove Only) Viewpoint Media Player Viewpoint Toolbar (Remove Only) WeatherBug WildTangent Web Driver Winamp Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Essentials Windows Live Mail Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Toolbar Windows Live Upload Tool Windows Live Writer Windows Safety Alert Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 Yahoo! extras Yahoo! Install Manager Yahoo! Internet Mail Yahoo! Messenger Yahoo! Toolbar Script run: 6/14/2009 7:43:55 PM ~~~~~~~~~~~~~~~~~~~~~~~~ Company Name: AVG Technologies AV Name: AVG Internet Security Version Number: 8.0 On-Access Scanning Enabled: Yes Product up-to-date: No ~~~~~~~~~~~~~~~~~~~~~~~~ The Windows Firewall is enabled. ~~~~~~~~~~~~~~~~~~~~~~~~ The Security Center Anti-Virus Alerts are enabled. The Security Center Firewall Alerts are enabled. ~~~~~~~~~~~~~~~~~~~~~~~~
Once you start a thread, please reply to that thread rather than starting a fresh one. I receive notification if you post to this one, but not if you start a new one, which is why i've merged the two.

Download Malwarebytes' Anti-Malware from here and save it to your Desktop - unless you already have it, in which case skip to the "updating" bit below.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • Ensure a checkmark is placed next to both Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware and then click Finish.
  • If an update is found, it will download and install the latest version - you'll need to clear it with your firewall.
  • Once the program has loaded, select Perform full scan and then Scan.
  • When the scan has finished, click OK and then Show Results to view the results - no surprise there!
  • If MBAM finds anything, check the box(es) and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Let me have the MBAM log, a fresh HJT log (run in Normal Mode) AND a description of how your PC is behaving.

* Will you also tell me which registry scanner you used.
Novicate,

That Link was to the same place as before, although; I did try it. Result was it did not Download Maware Software it did download: Advanced Registry Optimizer - Trial Version by SAMMsoft. I ran it but I cannot Copy the Scan Results!?

[removed personal information]
The link i've posted shows two links for software when I click it, the one you seem to see which is at the bottom of the page and the one you want, which is at the top -

CNET Download.com is the safe and trusted provider for Malwarebytes Anti-Malware 1.38

To complete your download, click on the link below:

Download Now (3.4MB)
Tested spyware free.

Are you not seeing this?
Novicate

Yes, that is the same Screen. When I click on that Button I get a message to look at the Task Bar. The message there IE does not trust that site for downloads. I close the notice and start downloading the program. Once it is down loaded I try to exicute the file I get a message bubble saying the files are corrupted.
What next Doc???

[removed personal information]
Try this one: http://majorgeeks.com/download5756.html but rename the file BEFORE you click Save - any name will do, just to make sure nothing is interfering with the download.

That Link takes you right back to the Cnet Page…

It might take you back to the Cnet Page, but it takes me to MajorGeeks. Try copy and pasting the link into your browser's address bar and see if that works:

http://majorgeeks.com/download5756.html

If it doesn't, work through the following instead:

Pay a visit to the Kaspersky Online Scanner 7 - I.E. is preferred for this scan.
  • Read the Information panel and then click Accept.
  • Allow the ActiveX download if necessary.
  • Both the anti-virus engine and database will need to be downloaded, which may take a little time.
  • Once this has been completed, select My Computer from the Scan section on the left hand side.
  • Put the kettle on!
  • Although it is recommended by Kaspersky that you should disable your anti-virus scanner before starting this scan, it should work OK with it still active - it does on my PC.
    Although you may find the scan speed increases if you carry out this step, I never like to disable my resident scanner while online, so I don't.
  • When the scan has completed, click View scan report at the bottom.
  • Click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save and pick a location for the file - the Desktop is always handy.
Copy and paste the report into your next reply along with a fresh HJT log, run in Normal Mode, and a description of how your PC is behaving.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
Novicate,

How right you are, that Link does take you to MajorGeeks Webpage…But, Clik on the Link for Malware at MajorGeeks Webpage that Link Opens the Cnet Page…right backe to Square One. Am I stuck in a Mobuis Loop?

[removed personal information]
Which link are you clicking? I can see three download links on that page for MBAM and not one should take you back to CNET -

MajorGeeks - |USA|
MajorGeeks - |USA 2|
Internode - |Australia|

Hey Novucate,

Think everything is here now: MalwareBytes file, HJT file and Sec-Info file. Computer runs sooooooo slooooooooow. Hangs up alot: Freezes in either Internet Explore and/or FireFox. Seems to crash in the middle of applications such as PCB123,etc. And it seems as though something prevents downloading of AntiSpywareMalware Software from the Net. Probably more too but just can't think of it right now.
Ran several Registry Cleaners, some are erased so I don't know what they are but a copuple are still here: LSPFix (cexx.org), Advanced Registry Optimizer by SammSoft (zoombli.com), RegistryFix (Registry Fix.Com). A few weeks ago the lastest Trial Version of AVG was downloaded. Things worked much better for awhile. Included at the bottom is the LSP results. Lastly, at the very end you will find the startuplist file from StartupList v2.02.0 (merijin.org).

This should keep you busy for awhile!!!

[removed personal information]






……………………………………………………………………..
………MalwareBytes…………………………………………………..
.
………………

Malwarebytes' Anti-Malware 1.38
Database version: 2315
Windows 5.1.2600 Service Pack 2

6/20/2009 2:53:45 PM
MalwareBytes-log-2009-06-20 (14-53-09).txt

Scan type: Full Scan (C:\|D:\|G:\|)
Objects scanned: 304617
Time elapsed: 4 hour(s), 37 minute(s), 41 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 39
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 36
Files Infected: 155

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\funwebproductsinstaller.start (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproductsinstaller.start.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\mp.mediapops.1 (Adware.Delphinmediaviewer) -> No action taken.
HKEY_CLASSES_ROOT\uprppchk.uprppchk (Rogue.Privacy.Protector) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{f0e4888b-938d-43e9-8444-787e2ffc178b} (Rogue.Privacy.Protector) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{936301de-ed09-4540-9daf-0c8443a7f334} (Rogue.Privacy.Protector) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{ebf4b37a-6262-40a8-aad6-3a36b08ae98b} (Rogue.Privacy.Protector) -> No action taken.
HKEY_CLASSES_ROOT\uprppchk.uprppchk.1 (Rogue.Privacy.Protector) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{1d4db7d1-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{1d4db7d3-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{4438a5dc-e00b-41a0-b0e6-b63fd3b86eee} (Adware.Delphinmediaviewer) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{1d4db7d0-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{4767c447-ef15-42f2-8809-68adb7fa76f1} (Adware.Delphinmediaviewer) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{0507fdde-f3b7-49f5-9e8f-c557e991f39b} (Adware.Hotbar) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert (Trojan.Zlob) -> No action taken.
HKEY_CLASSES_ROOT\AppID\WeatherOnTray.exe (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\videoaccessactivex.Chl (Trojan.Zlob) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\PrivacyProtector Free (Rogue.Privacy.Protector) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\PrivacyProtector Free (Rogue.Privacy.Protector) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Video ActiveX Object (Trojan.Zlob) -> No action taken.
HKEY_CLASSES_ROOT\wallpaper.wallpapermanager (Adware.Zango) -> No action taken.
HKEY_CLASSES_ROOT\wallpaper.wallpapermanager.1 (Adware.Zango) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearchsearchassistant.auxiliary (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearchsearchassistant.auxiliary.1 (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
g:\program files\SpywareLocked 3.3 (Rogue.SpywareLocked) -> No action taken.
G:\Program Files\Ultimate Defender (Rogue.Ultimate.Defender) -> No action taken.
g:\documents and settings\all users\start menu\Programs\PrivacyProtector Free (Rogue.Privacy.Protector) -> No action taken.
g:\program files\PrivacyProtector Free (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Download (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\img (Rogue.Privacy.Protector) -> No action taken.
G:\Program Files\MyWebSearch (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\bar (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\bar\History (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\SrchAstt (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\SrchAstt\1.bin (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\SrchAstt\Cache (Adware.MyWebSearch) -> No action taken.
G:\Program Files\FunWebProducts (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Installr (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Installr\1.bin (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Installr\Cache (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Installr\setups (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\PopSwatr (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\PopSwatr\History (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Shared (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Shared\Cache (Adware.MyWebSearch) -> No action taken.
g:\documents and settings\Dad\application data\PrivacyProtector Free (Rogue.PrivacyProtector) -> No action taken.
g:\documents and settings\Dad\application data\privacyprotector free\Logs (Rogue.PrivacyProtector) -> No action taken.
g:\documents and settings\Sarena\application data\PrivacyProtector Free (Rogue.PrivacyProtector) -> No action taken.
g:\documents and settings\Sarena\application data\privacyprotector free\Logs (Rogue.PrivacyProtector) -> No action taken.
G:\Program Files\Video ActiveX Object (Trojan.Zlob) -> No action taken.
G:\Program Files\MySearch (Adware.MyWebSearch) -> No action taken.
g:\program files\MySearch\bar (Adware.MyWebSearch) -> No action taken.
g:\program files\MySearch\bar\1.bin (Adware.MyWebSearch) -> No action taken.
G:\Program Files\MyWay (Adware.MyWay) -> No action taken.
g:\program files\MyWay\myBar (Adware.MyWay) -> No action taken.
g:\program files\MyWay\myBar\History (Adware.MyWay) -> No action taken.
g:\program files\MyWay\myBar\Settings (Adware.MyWay) -> No action taken.

Files Infected:
G:\Program Files\PrivacyProtector Free\UPRPPChk.dll (Rogue.Privacy.Protector) -> No action taken.
g:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL (Adware.MyWeb) -> No action taken.
g:\program files\mIRC\mirc.exe (Backdoor.Bot) -> No action taken.
g:\documents and settings\all users\start menu\Programs\privacyprotector free\PrivacyProtector HomePage.lnk (Rogue.Privacy.Protector) -> No action taken.
g:\documents and settings\all users\start menu\Programs\privacyprotector free\PrivacyProtector Online Manual.lnk (Rogue.Privacy.Protector) -> No action taken.
g:\documents and settings\all users\start menu\Programs\privacyprotector free\PrivacyProtector Online Support.lnk (Rogue.Privacy.Protector) -> No action taken.
g:\documents and settings\all users\start menu\Programs\privacyprotector free\Uninstall PrivacyProtector.lnk (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Activate.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\atl71.dll (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\bnlink.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\diagnosis.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\err.log (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\lapv.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\license.rtf (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\manual.url (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\mfc71.dll (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\msvcp71.dll (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\msvcr71.dll (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\pv.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\readme.rtf (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\ScanReport.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Schedule.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\sr.log (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\support.url (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\unins000.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\unins000.exe (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\uninstall.ico (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\UninstallPage.html (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\up.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\updater.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\UPRP.url (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\UPRP.xml (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\vbpv.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\AE_CD_Cr.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\AReadr4.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\AReadr5.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\ASDSEEpv.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\ASPack.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\Babylon.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\BDelphi5.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\CatchUp.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\CBuildr5.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\CCGA.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\CManager.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\CuteFTP4.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\CuteHTML.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\DAcceler.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\DiscJug.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\ECDCreat4.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\Far.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\FFTsks.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\FlashFXP.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\FrntPage.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\FrontPEx.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\FtpEXP.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\FtpVoya.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\GetRight.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\GoZilla.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\GravMRU.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\HomeSite.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\HotDogPr.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\H_TxtPad.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\IconExtr.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\iMesh.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\ImgReady3.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\InsShExp.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\JASC_P_P.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\KaZaA.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\LView.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\MacDir.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\MacDrWea.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\MicAng.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\MicDes.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\MMUnDisk.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\MM_CON.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\Morpheus.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\MPaint.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\MPicPub.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\MPImaGal.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\MSExplorer.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\MSoffice.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\MSRegEdit.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\MSWMP.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\MSWordPad.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\Nero.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\NetShow.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\NTBackup.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\pfilelst.xda (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\PhotShel.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\PHPCoder.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\PowerZIP.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\RapidBr.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\RealAuPl.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\RealDown.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\SecurCRT.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\SL_BlWin.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\SmartClr.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\Sonique.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\StuffIt.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\TelepPro.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\UGifAnim.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\UltraEd.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\UMedStud.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\UPhImpV.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\UPhotoEx.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\UVidStud.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\VNC.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\WebFeret.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\WebReap.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\WinACE.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\WinGate.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\WinRAR.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\WinZIP.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\WiseInst.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\wordslst.xda (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\YahooPl.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\Appbase\ZipMagic.dat (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\img\button.gif (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\img\button2.gif (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\img\header.gif (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\img\logo.gif (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\img\spacer.gif (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\img\top1.jpg (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\img\top2.jpg (Rogue.Privacy.Protector) -> No action taken.
g:\program files\privacyprotector free\img\top_line.gif (Rogue.Privacy.Protector) -> No action taken.
g:\program files\mywebsearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\bar\History\search (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\bar\Settings\prevcfg.htm (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\SrchAstt\1.bin\UNINSTAL.INF (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\SrchAstt\Cache\0003BB01 (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\SrchAstt\Cache\0005BD24 (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\SrchAstt\Cache\00069ADE (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\SrchAstt\Cache\00982AA5 (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\SrchAstt\Cache\00AC683C (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\SrchAstt\Cache\011DDE75 (Adware.MyWebSearch) -> No action taken.
g:\program files\mywebsearch\SrchAstt\Cache\files.ini (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Installr\Cache\00A07815 (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Installr\Cache\00A07EDA (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Installr\Cache\00A08621 (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Installr\Cache\00A08C8B (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Installr\Cache\00A09757 (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Installr\Cache\files.ini (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\PopSwatr\History\allowed (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\PopSwatr\History\notallow (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Shared\Cache\CursorManiaBtn.html (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Shared\Cache\MailStampBtn.html (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Shared\Cache\MailStampBtn.htmlx (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Shared\Cache\MyStationeryBtn.html (Adware.MyWebSearch) -> No action taken.
g:\program files\funwebproducts\Shared\Cache\SmileyCentralBtn.html (Adware.MyWebSearch) -> No action taken.
g:\documents and settings\Dad\application data\privacyprotector free\Logs\update.log (Rogue.PrivacyProtector) -> No action taken.
g:\documents and settings\Sarena\application data\privacyprotector free\Logs\update.log (Rogue.PrivacyProtector) -> No action taken.
g:\program files\MySearch\bar\1.bin\UNINSTALL.INF (Adware.MyWebSearch) -> No action taken.
g:\program files\MyWay\myBar\History\search (Adware.MyWay) -> No action taken.
g:\documents and settings\Dad\favorites\Online Security Test.url (Rogue.Link) -> No action taken.
g:\WINDOWS\smdat32a.sys (Rootkit.Agent) -> No action taken.

……………………………………………………………………..
………HJT…………………………………………………………..
.
……………………..

Ad-aware 6 Personal
Adobe Acrobat 5.0
Adobe Download Manager (Remove Only)
Adobe Flash Player 10 Plugin
Adobe Photoshop 6.0
Adobe Reader 7.0
Adobe SVG Viewer
Advanced Registry Optimizer
AIM 6
Alchemy Deluxe 1.3z
AnalogX POW!
AOL Instant Messenger
Apple Mobile Device Support
Apple Software Update
AVG 8.0
BASIC Stamp Editor v2.2
Batch Assistant
BlazeDVD V1.5
Bonjour
Charlie's Angels Angel X (remove only)
Choice Guard
Data Compiler
DivX 5.0.3 Bundle
DownloadWare Engine
EasyCleaner
EPSON Printer Software
Fun Web Products Easy Installer
GetRight
Global DiVX Player
GTAIII
Hexic Deluxe
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
HP Extended Capabilities 5.3
HP Image Zone Express
HP Imaging Device Functions 5.3
hp instant support
HP Memories Disc
HP Photo and Imaging 2.0 - Photosmart Printer Series
HP PSC & OfficeJet 5.3.B
HP Software Update
HP Solution Center & Imaging Support Tools 5.3
ICQ Lite
Indexing Function
InstaForm Invoices & Estimates Pro
InterActual Player
Internet Explorer Security Plugin 2006
Internet Security Add-On
InterVideo Installer
InterVideo WinDVD4
iTunes
Java 2 Runtime Environment Standard Edition v1.3.1_04
Java™ 6 Update 14
Junk Mail filter update
Learn2 Player (Uninstall Only)
LimeWire
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Data Access Components KB870669
Microsoft Motocross Madness 2
Microsoft Office Live Add-in 1.3
Microsoft Office XP Professional with FrontPage
Microsoft Picture It! Express 2000
Microsoft Picture It! Express 7.0
Microsoft Search Enhancement Pack
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
mIRC
Mozilla (1.2.1)
Mozilla Firefox (3.0.11)
MSN Toolbar
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6 Service Pack 2 (KB954459)
Nero 6 Ultra Edition
PCB123 V3.3.2
Photosmart 130,230,7150,7345,7350,7550 (Remove only)
Print Artist Gold 21
Public Messenger ver 2.03
QuickTime
RealPlayer Basic
RegistryFix v6.2
Remote Administrator v2.0
Rhapsody Player Engine
Safe-Share
SBM OS
Search Assistant - My Web Search
Search OS
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Segoe UI
Shockwave
SimCoaster
Support Software
Tina 7 - TI
TinyCAD 2.60.01
TP HTTP
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
URL.IE APP
Video ActiveX Object 2.07
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Viewpoint Toolbar (Remove Only)
WeatherBug
WildTangent Web Driver
Winamp
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Safety Alert
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
Yahoo! extras
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Toolbar

……………………………………………………………………..
…Sec-Info2.Zip……………………………………………………………..
…………..

Script run: 6/20/2009 3:27:25 PM

~~~~~~~~~~~~~~~~~~~~~~~~

Company Name: AVG Technologies
AV Name: AVG Internet Security
Version Number: 8.0
On-Access Scanning Enabled: Yes
Product up-to-date: No

~~~~~~~~~~~~~~~~~~~~~~~~

The Windows Firewall is enabled.

~~~~~~~~~~~~~~~~~~~~~~~~

The Security Center Anti-Virus Alerts are enabled.
The Security Center Firewall Alerts are enabled.


……………………………………………………………………..
……..LSP……………………………………………………………
.
……………………..

LSP Windsock 2 Repair Utility:

File: Description:
mswsock .dll Tcpip
winrnr.dll NTDS
mdnsNSP.dll mndsNSP
rsvpsp.dll (Protocol handler)

……………………………………………………………………..
……………….StartupList…………………………………………..
.
………………….

StartupList report, 6/20/2009, 4:01:34 PM
StartupList version 2.02.0
Started from: G:\Documents and Settings\Dad\Desktop\StartupList.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Logged on as 'Dad' to 'HOME'
* Using default options (see end of log for possible options)
==================================================

Running processes (54):

[G:\Documents and Settings\Dad\Desktop\StartupList.exe (43)]
G:\Program Files\Yahoo!\Messenger\idle.dll
G:\Program Files\Yahoo!\Messenger\MSVCR71.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\asycfilt.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\COMCTL32.dll
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\DNSAPI.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\System32\MSCOMCTL.OCX
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\system32\MSVBVM60.DLL
G:\WINDOWS\system32\MSVCP60.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\NTDSAPI.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\PSAPI.DLL
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\System32\wbem\fastprox.dll
G:\WINDOWS\System32\wbem\wbemcomn.dll
G:\WINDOWS\System32\wbem\wbemdisp.dll
G:\WINDOWS\System32\wbem\wbemprox.dll
G:\WINDOWS\System32\wbem\wbemsvc.dll
G:\WINDOWS\System32\wbem\wmiutils.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\PROGRA~1\DOWNLO~2\alp2plib.exe (52)]
G:\PROGRA~1\DOWNLO~2\AlComms.dll
G:\PROGRA~1\DOWNLO~2\AlConfig.dll
G:\PROGRA~1\DOWNLO~2\AlDebug.dll
G:\PROGRA~1\DOWNLO~2\AlDLManager.dll
G:\PROGRA~1\DOWNLO~2\AlFile.dll
G:\PROGRA~1\DOWNLO~2\AlUtil.dll
G:\PROGRA~1\DOWNLO~2\AlXML.dll
G:\Program Files\Bonjour\mdnsNSP.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\DNSAPI.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\iphlpapi.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\msv1_0.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\System32\mswsock.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\rasadhlp.dll
G:\WINDOWS\system32\RASAPI32.DLL
G:\WINDOWS\system32\rasman.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rtutils.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\sensapi.dll
G:\WINDOWS\system32\shell32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\TAPI32.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WININET.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\System32\winrnr.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\system32\WSOCK32.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\AVG\AVG8\avgrsx.exe (7)]
G:\Program Files\AVG\AVG8\avgcorex.dll
G:\Program Files\AVG\AVG8\avgcrlpx.dll
G:\Program Files\AVG\AVG8\avglogx.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll

[G:\Program Files\Bonjour\mDNSResponder.exe (30)]
G:\WINDOWS\system32\ACTIVEDS.dll
G:\WINDOWS\system32\adsldpc.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\ATL.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\IPHLPAPI.DLL
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MPRAPI.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\mswsock.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\rtutils.dll
G:\WINDOWS\system32\SAMLIB.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (23)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\mswsock.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\NTMARTA.DLL
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\SAMLIB.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\system32\WSOCK32.dll

[G:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (19)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\psapi.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe (6)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSVCR70.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll

[G:\Program Files\DownloadWare Engine\DWE.EXE (22)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\system32\WSOCK32.dll
G:\WINDOWS\system32\xpsp2res.dll

[G:\Program Files\GetRight\GetRight.exe (46)]
G:\WINDOWS\AppPatch\AcGenral.DLL
G:\WINDOWS\system32\ACTIVEDS.dll
G:\WINDOWS\system32\adsldpc.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\appHelp.dll
G:\WINDOWS\system32\ATL.DLL
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\System32\CSCDLL.dll
G:\WINDOWS\System32\cscui.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\inetmib1.dll
G:\WINDOWS\system32\iphlpapi.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MPRAPI.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\oledlg.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rtutils.dll
G:\WINDOWS\system32\SAMLIB.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\snmpapi.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINSPOOL.DRV
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\ws2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\system32\WSOCK32.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe (69)]
G:\Program Files\Common Files\Microsoft Shared\Ink\SKCHUI.DLL
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpocxi08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpodio08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcob08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcxm08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqmfc09.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqsem08.rsc
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.rsc
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqsti08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqstp08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtap08.dll
G:\WINDOWS\IME\SPGRMR.DLL
G:\WINDOWS\ime\sptip.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\appHelp.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\COMCTL32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\CRYPTUI.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hpzidr12.dll
G:\WINDOWS\system32\hpzipr12.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MFC42.DLL
G:\WINDOWS\system32\MFC42LOC.DLL
G:\WINDOWS\system32\mlang.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\System32\mshtml.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\System32\msimtf.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\System32\msls31.dll
G:\WINDOWS\system32\MSVCP60.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\MSVFW32.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEACC.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\System32\PSAPI.DLL
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\System32\shdoclc.dll
G:\WINDOWS\System32\shdocvw.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHFOLDER.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\urlmon.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WININET.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINSPOOL.DRV
G:\WINDOWS\system32\WINSTA.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\system32\WSOCK32.dll
G:\WINDOWS\system32\WTSAPI32.DLL
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (70)]
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpocxi08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoddcomm09.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpodeb08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpodev08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpodio08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpodvd09.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposcn08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoSCN08.rsc
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotra08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotra08.rsc
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotradd.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcob08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcxm08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqmif08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqrif08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtao08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.rsc
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpquio08.dll
G:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusg.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CFGMGR32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\COMCTL32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hpzidr12.dll
G:\WINDOWS\system32\hpzipr12.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\iphlpapi.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\msv1_0.dll
G:\WINDOWS\system32\MSVCP60.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RASAPI32.DLL
G:\WINDOWS\system32\rasman.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\rtutils.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\sensapi.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHFOLDER.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\STI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\TAPI32.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WININET.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINSPOOL.DRV
G:\WINDOWS\system32\WINSTA.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\system32\WSOCK32.dll
G:\WINDOWS\system32\WTSAPI32.DLL
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\Hewlett-Packard\Digital Imaging\Product Assistant\bin\hprblog.exe (18)]
G:\Program Files\Hewlett-Packard\Digital Imaging\Product Assistant\bin\hprbutil.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\xpsp2res.dll

[G:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe (24)]
G:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnfps.dll
G:\Program Files\Hewlett-Packard\HP Share-to-Web\S2WNSRES.DLL
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe (24)]
G:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnfps.dll
G:\Program Files\Hewlett-Packard\HP Share-to-Web\S2WNSRES.DLL
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (14)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\ICQLite\ICQLite.exe (73)]
G:\Program Files\Common Files\Microsoft Shared\Ink\SKCHUI.DLL
G:\Program Files\ICQLite\actskin4.ocx
G:\Program Files\ICQLite\ICQRT.dll
G:\Program Files\ICQLite\LiteRes.dll
G:\Program Files\ICQLite\LiteSkinUtils.dll
G:\Program Files\ICQLite\LiteUtil.dll
G:\WINDOWS\IME\SPGRMR.DLL
G:\WINDOWS\ime\sptip.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\System32\ATL.DLL
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\System32\credui.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\CRYPTUI.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\Icmp.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\System32\iphlpapi.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MFC42.DLL
G:\WINDOWS\system32\MFC42LOC.DLL
G:\WINDOWS\System32\mlang.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\System32\mshtml.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\System32\msimtf.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\System32\msls31.dll
G:\WINDOWS\system32\MSVCP60.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\System32\netshell.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\NTMARTA.DLL
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEACC.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\OLEPRO32.DLL
G:\WINDOWS\System32\PSAPI.DLL
G:\WINDOWS\system32\RASAPI32.DLL
G:\WINDOWS\system32\rasman.dll
G:\WINDOWS\system32\RICHED20.dll
G:\WINDOWS\system32\RICHED32.DLL
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rtutils.dll
G:\WINDOWS\system32\SAMLIB.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\System32\shdoclc.dll
G:\WINDOWS\System32\shdocvw.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\TAPI32.dll
G:\WINDOWS\system32\urlmon.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\wininet.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINSTA.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\system32\WSOCK32.dll
G:\WINDOWS\system32\Wtsapi32.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll

[G:\Program Files\Internet Explorer\iexplore.exe (117)]
G:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
G:\Program Files\AVG\AVG8\avgapix.dll
G:\Program Files\AVG\AVG8\avgcfgx.dll
G:\Program Files\AVG\AVG8\avglngx.dll
G:\Program Files\AVG\AVG8\avglogx.dll
G:\Program Files\AVG\AVG8\avgssie.dll
G:\Program Files\AVG\AVG8\avgxpl.dll
G:\Program Files\Bonjour\mdnsNSP.dll
G:\Program Files\Common Files\Microsoft Shared\Ink\SKCHUI.DLL
G:\Program Files\Common Files\Microsoft Shared\Windows Live\msidcrl40.dll
G:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
G:\Program Files\GetRight\xx2gr.dll
G:\Program Files\Java\jre6\bin\jp2ssv.dll
G:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
G:\Program Files\Microsoft Office\Office10\msohev.dll
G:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll
G:\Program Files\Microsoft\Search Enhancement Pack\Search Box Extension\srchbxex.dll
G:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
G:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
G:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\mtbres.dll
G:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
G:\Program Files\Windows Live\Toolbar\en\wltcore.dll.mui
G:\Program Files\Windows Live\Toolbar\en-us\wltcore.market.dll.mui
G:\Program Files\Windows Live\Toolbar\msidcrl40.dll
G:\Program Files\Windows Live\Toolbar\sqmapi.dll
G:\Program Files\Windows Live\Toolbar\wltcore.dll
G:\Program Files\Yahoo!\Common\yiesrvc.dll
G:\Program Files\Yahoo!\Common\YIeTagBm.dll
G:\Program Files\Yahoo!\Common\Yshortcut.dll
G:\Program Files\Yahoo!\Messenger\idle.dll
G:\WINDOWS\IME\SPGRMR.DLL
G:\WINDOWS\ime\sptip.dll
G:\WINDOWS\System32\actxprxy.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\appHelp.dll
G:\WINDOWS\system32\ATL.DLL
G:\WINDOWS\system32\browselc.dll
G:\WINDOWS\system32\BROWSEUI.dll
G:\WINDOWS\system32\Cabinet.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\cryptnet.dll
G:\WINDOWS\system32\CRYPTUI.dll
G:\WINDOWS\System32\CSCDLL.dll
G:\WINDOWS\System32\cscui.dll
G:\WINDOWS\system32\DNSAPI.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\System32\iepeers.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\ImgUtil.dll
G:\WINDOWS\system32\Iphlpapi.dll
G:\WINDOWS\System32\jscript.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\System32\mlang.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\System32\mshtml.dll
G:\WINDOWS\System32\mshtmled.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\MSIMG32.dll
G:\WINDOWS\System32\msimtf.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\System32\msls31.dll
G:\WINDOWS\system32\msv1_0.dll
G:\WINDOWS\system32\MSVCP60.dll
G:\WINDOWS\system32\MSVCR71.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\mswsock.dll
G:\WINDOWS\System32\msxml3.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEACC.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\System32\pngfilt.dll
G:\WINDOWS\system32\PSAPI.DLL
G:\WINDOWS\system32\rasadhlp.dll
G:\WINDOWS\system32\RASAPI32.DLL
G:\WINDOWS\system32\rasman.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\rtutils.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SensApi.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\system32\shdoclc.dll
G:\WINDOWS\system32\SHDOCVW.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\TAPI32.dll
G:\WINDOWS\system32\urlmon.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\USP10.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WINHTTP.dll
G:\WINDOWS\system32\WININET.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\System32\winrnr.dll
G:\WINDOWS\system32\WINSPOOL.DRV
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\system32\wsock32.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCP80.dll
G:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\gdiplus.dll

[G:\Program Files\Internet Explorer\iexplore.exe (133)]
G:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
G:\Program Files\AVG\AVG8\avgapix.dll
G:\Program Files\AVG\AVG8\avgcfgx.dll
G:\Program Files\AVG\AVG8\avglngx.dll
G:\Program Files\AVG\AVG8\avglogx.dll
G:\Program Files\AVG\AVG8\avgssie.dll
G:\Program Files\AVG\AVG8\avgxpl.dll
G:\Program Files\Bonjour\mdnsNSP.dll
G:\Program Files\Common Files\Microsoft Shared\Ink\SKCHUI.DLL
G:\Program Files\Common Files\Microsoft Shared\Windows Live\msidcrl40.dll
G:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
G:\Program Files\GetRight\xx2gr.dll
G:\Program Files\Java\jre6\bin\jp2ssv.dll
G:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
G:\Program Files\Microsoft Office\Office10\msohev.dll
G:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll
G:\Program Files\Microsoft\Search Enhancement Pack\Search Box Extension\srchbxex.dll
G:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
G:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
G:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\mtbres.dll
G:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
G:\Program Files\Windows Live\Toolbar\en\wltcore.dll.mui
G:\Program Files\Windows Live\Toolbar\en-us\wltcore.market.dll.mui
G:\Program Files\Windows Live\Toolbar\msidcrl40.dll
G:\Program Files\Windows Live\Toolbar\sqmapi.dll
G:\Program Files\Windows Live\Toolbar\wltcore.dll
G:\Program Files\Yahoo!\Common\yiesrvc.dll
G:\Program Files\Yahoo!\Common\YIeTagBm.dll
G:\Program Files\Yahoo!\Common\Yshortcut.dll
G:\Program Files\Yahoo!\Messenger\idle.dll
G:\WINDOWS\IME\SPGRMR.DLL
G:\WINDOWS\ime\sptip.dll
G:\WINDOWS\System32\actxprxy.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\appHelp.dll
G:\WINDOWS\system32\ATL.DLL
G:\WINDOWS\system32\browselc.dll
G:\WINDOWS\system32\BROWSEUI.dll
G:\WINDOWS\system32\Cabinet.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\cryptnet.dll
G:\WINDOWS\system32\CRYPTUI.dll
G:\WINDOWS\System32\CSCDLL.dll
G:\WINDOWS\System32\cscui.dll
G:\WINDOWS\System32\DCIMAN32.dll
G:\WINDOWS\System32\DDRAW.dll
G:\WINDOWS\System32\ddrawex.dll
G:\WINDOWS\system32\DNSAPI.dll
G:\WINDOWS\system32\dssenh.dll
G:\WINDOWS\System32\dxtmsft.dll
G:\WINDOWS\System32\dxtrans.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\System32\iepeers.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\ImgUtil.dll
G:\WINDOWS\system32\Iphlpapi.dll
G:\WINDOWS\System32\jscript.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\macromed\flash\Flash.ocx
G:\WINDOWS\System32\MFC42.DLL
G:\WINDOWS\system32\MFC42LOC.DLL
G:\WINDOWS\system32\midimap.dll
G:\WINDOWS\System32\mlang.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\msacm32.drv
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\System32\mshtml.dll
G:\WINDOWS\System32\mshtmled.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\MSIMG32.dll
G:\WINDOWS\System32\msimtf.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\System32\msls31.dll
G:\WINDOWS\system32\msv1_0.dll
G:\WINDOWS\system32\MSVCP60.dll
G:\WINDOWS\system32\MSVCR71.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\mswsock.dll
G:\WINDOWS\System32\msxml3.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEACC.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\System32\pngfilt.dll
G:\WINDOWS\system32\PSAPI.DLL
G:\WINDOWS\system32\rasadhlp.dll
G:\WINDOWS\system32\RASAPI32.DLL
G:\WINDOWS\system32\rasman.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\rtutils.dll
G:\WINDOWS\system32\schannel.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SensApi.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\system32\shdoclc.dll
G:\WINDOWS\system32\SHDOCVW.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\TAPI32.dll
G:\WINDOWS\system32\urlmon.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\userenv.dll
G:\WINDOWS\system32\USP10.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\System32\vbscript.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\wdmaud.drv
G:\WINDOWS\system32\WINHTTP.dll
G:\WINDOWS\system32\WININET.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\System32\winrnr.dll
G:\WINDOWS\system32\WINSPOOL.DRV
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\system32\wsock32.dll
G:\WINDOWS\system32\wuapi.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCP80.dll
G:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\gdiplus.dll

[G:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (19)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MFC42.DLL
G:\WINDOWS\system32\MFC42LOC.DLL
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\iPod\bin\iPodService.exe (28)]
G:\Program Files\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.DLL
G:\Program Files\iPod\bin\iPodService.Resources\iPodService.DLL
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CFGMGR32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\setupapi.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WINSTA.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\Wtsapi32.dll
G:\WINDOWS\system32\xpsp2res.dll

[G:\Program Files\iTunes\iTunesHelper.exe (47)]
G:\Program Files\Common Files\Apple\Mobile Device Support\bin\iTunesMobileDevice.dll
G:\Program Files\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.DLL
G:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.DLL
G:\Program Files\QuickTime\QTSystem\QuickTime.qts
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\COMCTL32.dll
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\DCIMAN32.dll
G:\WINDOWS\system32\ddraw.dll
G:\WINDOWS\system32\DSOUND.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\mswsock.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WININET.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINSTA.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\system32\WSOCK32.dll
G:\WINDOWS\system32\Wtsapi32.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\gdiplus.dll

[G:\Program Files\Java\jre6\bin\jqs.exe (31)]
G:\Program Files\Java\jre6\bin\MSVCR71.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\COMCTL32.dll
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\mswsock.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ODBC32.dll
G:\WINDOWS\system32\odbcbcp.dll
G:\WINDOWS\system32\odbcint.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\pdh.dll
G:\WINDOWS\system32\perfdisk.dll
G:\WINDOWS\system32\perfos.dll
G:\WINDOWS\system32\psapi.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\Java\jre6\bin\jusched.exe (44)]
G:\Program Files\Bonjour\mdnsNSP.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\Apphelp.dll
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\DNSAPI.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\iphlpapi.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msv1_0.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\System32\mswsock.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\rasadhlp.dll
G:\WINDOWS\system32\RASAPI32.DLL
G:\WINDOWS\system32\rasman.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\rtutils.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\sensapi.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\TAPI32.dll
G:\WINDOWS\system32\urlmon.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WININET.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\System32\winrnr.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\system32\wsock32.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (33)]
G:\Program Files\Malwarebytes' Anti-Malware\ssubtmr6.dll
G:\Program Files\Malwarebytes' Anti-Malware\vbalsgrid6.ocx
G:\Program Files\Malwarebytes' Anti-Malware\zlib.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\advpack.dll
G:\WINDOWS\system32\asycfilt.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRTDLL.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\system32\MSVBVM60.DLL
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\OLEPRO32.DLL
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\shell32.dll
G:\WINDOWS\system32\shfolder.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.DLL

[G:\Program Files\Messenger\msmsgs.exe (39)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\credui.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\cryptdll.dll
G:\WINDOWS\System32\es.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\iphlpapi.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\MSIMG32.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WININET.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINSTA.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\system32\WSOCK32.dll
G:\WINDOWS\system32\wtsapi32.dll
G:\WINDOWS\system32\XPOB2RES.DLL
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\gdiplus.dll

[G:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (44)]
G:\Program Files\Bonjour\mdnsNSP.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\cryptnet.dll
G:\WINDOWS\system32\DHCPCSVC.DLL
G:\WINDOWS\system32\DNSAPI.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\Iphlpapi.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\mswsock.dll
G:\WINDOWS\System32\msxml3.dll
G:\WINDOWS\system32\netapi32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\rasadhlp.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SensApi.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\userenv.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WINHTTP.dll
G:\WINDOWS\System32\winrnr.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\system32\WSOCK32.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\QuickTime\qttask.exe (15)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\Real\RealPlayer\RealPlay.exe (88)]
G:\Program Files\Common Files\Real\Common\pnen3260.dll
G:\Program Files\Common Files\Real\Common\pngu3266.dll
G:\Program Files\Common Files\Real\Common\pnrs3260.dll
G:\Program Files\Common Files\Real\Common\rpcl3260.dll
G:\Program Files\Common Files\Real\Plugins\audp3260.dll
G:\Program Files\Common Files\Real\Plugins\auth3260.dll
G:\Program Files\Common Files\Real\Plugins\basc3260.dll
G:\Program Files\Common Files\Real\Plugins\Dbc_hbrf.dll
G:\Program Files\Common Files\Real\Plugins\Dbc_hbrr.dll
G:\Program Files\Common Files\Real\Plugins\http3260.dll
G:\Program Files\Common Files\Real\Plugins\memf3260.dll
G:\Program Files\Common Files\Real\Plugins\meta3260.dll
G:\Program Files\Common Files\Real\Plugins\mp3f3260.dll
G:\Program Files\Common Files\Real\Plugins\mp3m3260.dll
G:\Program Files\Common Files\Real\Plugins\mp3r3260.dll
G:\Program Files\Common Files\Real\Plugins\ntau3260.dll
G:\Program Files\Common Files\Real\Plugins\plus3260.dll
G:\Program Files\Common Files\Real\Plugins\pnxr3260.dll
G:\Program Files\Common Files\Real\Plugins\ppff3260.dll
G:\Program Files\Common Files\Real\Plugins\pxcg3260.dll
G:\Program Files\Common Files\Real\Plugins\pxcj3260.dll
G:\Program Files\Common Files\Real\Plugins\pxcp3260.dll
G:\Program Files\Common Files\Real\Plugins\pxff3260.dll
G:\Program Files\Common Files\Real\Plugins\pxgf3260.dll
G:\Program Files\Common Files\Real\Plugins\pxgr3260.dll
G:\Program Files\Common Files\Real\Plugins\pxjf3260.dll
G:\Program Files\Common Files\Real\Plugins\pxjr3260.dll
G:\Program Files\Common Files\Real\Plugins\pxpf3260.dll
G:\Program Files\Common Files\Real\Plugins\pxpr3260.dll
G:\Program Files\Common Files\Real\Plugins\pxre3260.dll
G:\Program Files\Common Files\Real\Plugins\rare3260.dll
G:\Program Files\Common Files\Real\Plugins\rmff3260.dll
G:\Program Files\Common Files\Real\Plugins\rn5a3260.dll
G:\Program Files\Common Files\Real\Plugins\rtff3260.dll
G:\Program Files\Common Files\Real\Plugins\rtre3260.dll
G:\Program Files\Common Files\Real\Plugins\rupf3260.dll
G:\Program Files\Common Files\Real\Plugins\rupr3260.dll
G:\Program Files\Common Files\Real\Plugins\rvre3260.dll
G:\Program Files\Common Files\Real\Plugins\sdpp3260.dll
G:\Program Files\Common Files\Real\Plugins\smlf3260.dll
G:\Program Files\Common Files\Real\Plugins\smlr3260.dll
G:\Program Files\Common Files\Real\Plugins\smmr3260.dll
G:\Program Files\Common Files\Real\Plugins\smpl3260.dll
G:\Program Files\Common Files\Real\Plugins\stub3260.dll
G:\Program Files\Common Files\Real\Plugins\swff3260.dll
G:\Program Files\Common Files\Real\Plugins\swfr3260.dll
G:\Program Files\Common Files\Real\Plugins\vidp3260.dll
G:\Program Files\Common Files\Real\Update\rnqu3260.dll
G:\Program Files\Common Files\Real\Update\rpup3260.dll
G:\Program Files\Common Files\Real\Update\setu3260.dll
G:\Program Files\Common Files\Real\Update\upgr3260.dll
G:\Program Files\Real\RealPlayer\rnms3260.dll
G:\Program Files\Real\RealPlayer\rpap3260.dll
G:\WINDOWS\AppPatch\AcGenral.DLL
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\midimap.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\msacm32.drv
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\MSVFW32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\PNCRT.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\wdmaud.drv
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\system32\WSOCK32.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\Viewpoint\Common\ViewpointService.exe (17)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\ATL.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (65)]
G:\Program Files\Bonjour\mdnsNSP.dll
G:\Program Files\Viewpoint\Viewpoint Manager\VETScriptInterpreter.dll
G:\Program Files\Viewpoint\Viewpoint Manager\ViewMgrCore.dll
G:\WINDOWS\system32\ACTIVEDS.dll
G:\WINDOWS\system32\adsldpc.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\appHelp.dll
G:\WINDOWS\system32\ATL.DLL
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\CRYPTUI.dll
G:\WINDOWS\system32\DNSAPI.dll
G:\WINDOWS\system32\dssenh.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\iphlpapi.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\mlang.dll
G:\WINDOWS\system32\MPRAPI.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\msv1_0.dll
G:\WINDOWS\system32\MSVCP60.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\mswsock.dll
G:\WINDOWS\System32\mydocs.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ntshrui.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\oleacc.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\rasadhlp.dll
G:\WINDOWS\system32\RASAPI32.DLL
G:\WINDOWS\system32\rasman.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\rtutils.dll
G:\WINDOWS\system32\SAMLIB.dll
G:\WINDOWS\system32\schannel.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\System32\shdocvw.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\TAPI32.dll
G:\WINDOWS\system32\urlmon.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\userenv.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WININET.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\wintrust.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\system32\wsock32.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\Windows Live\Messenger\msnmsgr.exe (98)]
G:\PROGRA~1\WINDOW~4\MESSEN~1\vvpltfrm.dll
G:\Program Files\Common Files\Microsoft Shared\Ink\SKCHUI.DLL
G:\Program Files\Windows Live\Messenger\LiveNatTrav.dll
G:\Program Files\Windows Live\Messenger\LiveTransport.dll
G:\Program Files\Windows Live\Messenger\msgslang.14.0.8064.0206.dll
G:\Program Files\Windows Live\Messenger\msgsres.dll
G:\Program Files\Windows Live\Messenger\msgswcam.dll
G:\Program Files\Windows Live\Messenger\msidcrl40.dll
G:\Program Files\Windows Live\Messenger\PresenceIM.dll
G:\Program Files\Windows Live\Messenger\RTMPLTFM.dll
G:\Program Files\Windows Live\Messenger\sqmapi.dll
G:\Program Files\Windows Live\Messenger\uccapi.dll
G:\Program Files\Windows Live\Messenger\UXCalendar.dll
G:\Program Files\Windows Live\Messenger\uxcontacts.dll
G:\Program Files\Windows Live\Messenger\UXCore.dll
G:\Program Files\Windows Live\Messenger\WLDCore.dll
G:\Program Files\Windows Live\Messenger\wldlog.dll
G:\WINDOWS\IME\SPGRMR.DLL
G:\WINDOWS\ime\sptip.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\CRYPTNET.dll
G:\WINDOWS\system32\CRYPTUI.dll
G:\WINDOWS\system32\D3DIM700.DLL
G:\WINDOWS\system32\DCIMAN32.dll
G:\WINDOWS\system32\DDRAW.dll
G:\WINDOWS\System32\devenum.dll
G:\WINDOWS\system32\dnsapi.dll
G:\WINDOWS\system32\DSOUND.dll
G:\WINDOWS\System32\es.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hid.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\IMM32.dll
G:\WINDOWS\system32\inetcomm.dll
G:\WINDOWS\system32\inetres.dll
G:\WINDOWS\system32\iphlpapi.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\midimap.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\msacm32.drv
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msdmo.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\MSIMG32.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\system32\MSOERT2.dll
G:\WINDOWS\system32\MSVCP60.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\mswsock.dll
G:\WINDOWS\System32\msxml3.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEACC.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\PSAPI.DLL
G:\WINDOWS\System32\quartz.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\schannel.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SensApi.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\system32\SHDOCVW.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\sirenacm.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\urlmon.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\USP10.dll
G:\WINDOWS\system32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\wdmaud.drv
G:\WINDOWS\system32\WINHTTP.dll
G:\WINDOWS\system32\WININET.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINSTA.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\system32\WSOCK32.dll
G:\WINDOWS\system32\wtsapi32.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
G:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\MSVCP90.dll
G:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\MSVCR90.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\gdiplus.dll

[G:\Program Files\Windows Live\Toolbar\wltuser.exe (60)]
G:\Program Files\Bonjour\mdnsNSP.dll
G:\Program Files\Windows Live\Toolbar\msidcrl40.dll
G:\Program Files\Windows Live\Toolbar\sqmapi.dll
G:\WINDOWS\System32\actxprxy.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\DNSAPI.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\inetcomm.dll
G:\WINDOWS\system32\inetres.dll
G:\WINDOWS\system32\iphlpapi.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\mlang.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\MSOERT2.dll
G:\WINDOWS\system32\msv1_0.dll
G:\WINDOWS\system32\MSVCP60.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\mswsock.dll
G:\WINDOWS\System32\msxml3.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEACC.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\PSAPI.DLL
G:\WINDOWS\system32\rasadhlp.dll
G:\WINDOWS\system32\RASAPI32.DLL
G:\WINDOWS\system32\rasman.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\rtutils.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SensApi.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\TAPI32.dll
G:\WINDOWS\system32\urlmon.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WININET.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\system32\wsock32.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\Program Files\Yahoo!\Messenger\YPager.exe (119)]
G:\Program Files\Bonjour\mdnsNSP.dll
G:\Program Files\Common Files\Microsoft Shared\Ink\SKCHUI.DLL
G:\Program Files\Yahoo!\Messenger\AEC_PC_DLL.dll
G:\Program Files\Yahoo!\Messenger\D32-FW.DLL
G:\Program Files\Yahoo!\Messenger\eyeBeamAsDLL.dll
G:\Program Files\Yahoo!\Messenger\ft60.dll
G:\Program Files\Yahoo!\Messenger\idle.dll
G:\Program Files\Yahoo!\Messenger\MSVCP71.dll
G:\Program Files\Yahoo!\Messenger\MSVCR71.dll
G:\Program Files\Yahoo!\Messenger\MyYahoo.dll
G:\Program Files\Yahoo!\Messenger\pcre.dll
G:\Program Files\Yahoo!\Messenger\res_msgr.dll
G:\Program Files\Yahoo!\Messenger\rvads.dll
G:\Program Files\Yahoo!\Messenger\rvcommon.dll
G:\Program Files\Yahoo!\Messenger\rvsdp.dll
G:\Program Files\Yahoo!\Messenger\rvsip.dll
G:\Program Files\Yahoo!\Messenger\stock.dll
G:\Program Files\Yahoo!\Messenger\xmlparse.dll
G:\Program Files\Yahoo!\Messenger\xmltok.dll
G:\Program Files\Yahoo!\Messenger\yaudiomgr.dll
G:\Program Files\Yahoo!\Messenger\ygxa_2.dll
G:\Program Files\Yahoo!\Messenger\YImage.dll
G:\Program Files\Yahoo!\Messenger\YML.dll
G:\Program Files\Yahoo!\Messenger\yv_res.dll
G:\Program Files\Yahoo!\Messenger\yvoicesm.dll
G:\Program Files\Yahoo!\Messenger\yvoiceui.dll
G:\Program Files\Yahoo!\Messenger\yxtldr.dll
G:\Program Files\Yahoo!\Shared\YAlertCenter.dll
G:\Program Files\Yahoo!\Shared\YbSkin2.dll
G:\WINDOWS\IME\SPGRMR.DLL
G:\WINDOWS\ime\sptip.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\appHelp.dll
G:\WINDOWS\system32\AVIFIL32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\CRYPTUI.dll
G:\WINDOWS\system32\DNSAPI.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\icm32.dll
G:\WINDOWS\system32\ICMP.DLL
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\ImgUtil.dll
G:\WINDOWS\system32\IMM32.dll
G:\WINDOWS\system32\Iphlpapi.dll
G:\WINDOWS\System32\jscript.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\Macromed\Common\SwSupport.dll
G:\WINDOWS\system32\macromed\flash\Flash.ocx
G:\WINDOWS\System32\MFC42.DLL
G:\WINDOWS\system32\MFC42LOC.DLL
G:\WINDOWS\system32\midimap.dll
G:\WINDOWS\system32\mlang.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\msacm32.drv
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\mscms.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\System32\mshtml.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\system32\msimg32.dll
G:\WINDOWS\System32\msimtf.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\System32\msls31.dll
G:\WINDOWS\system32\msv1_0.dll
G:\WINDOWS\system32\MSVCP60.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\MSVFW32.dll
G:\WINDOWS\System32\mswsock.dll
G:\WINDOWS\System32\msxml3.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ODBC32.dll
G:\WINDOWS\system32\odbcbcp.dll
G:\WINDOWS\system32\odbcint.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEACC.DLL
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\pdh.dll
G:\WINDOWS\system32\perfos.dll
G:\WINDOWS\System32\pngfilt.dll
G:\WINDOWS\System32\PSAPI.DLL
G:\WINDOWS\system32\rasadhlp.dll
G:\WINDOWS\system32\RASAPI32.DLL
G:\WINDOWS\system32\rasman.dll
G:\WINDOWS\system32\RICHED20.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\rtutils.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\System32\shdoclc.dll
G:\WINDOWS\system32\SHDOCVW.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\TAPI32.dll
G:\WINDOWS\system32\urlmon.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\System32\vbscript.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\wdmaud.drv
G:\WINDOWS\system32\WININET.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\System32\winrnr.dll
G:\WINDOWS\system32\WINSPOOL.DRV
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\system32\WSOCK32.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll

[G:\Program Files\Yahoo!\Messenger\yupdater.exe (40)]
G:\Program Files\Bonjour\mdnsNSP.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\COMCTL32.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\DNSAPI.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\iphlpapi.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msv1_0.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\System32\mswsock.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\rasadhlp.dll
G:\WINDOWS\system32\RASAPI32.DLL
G:\WINDOWS\system32\rasman.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\rtutils.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\TAPI32.dll
G:\WINDOWS\system32\urlmon.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WININET.DLL
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\system32\wsock32.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\WINDOWS\Explorer.EXE (130)]
G:\PROGRA~1\Yahoo!\Common\ymmapi20041123.dll
G:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
G:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
G:\Program Files\AVG\AVG8\avgse.dll
G:\Program Files\Bonjour\mdnsNSP.dll
G:\Program Files\GetRight\xx2gr.dll
G:\Program Files\ICQLite\ICQLiteShell.dll
G:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
G:\Program Files\Yahoo!\Messenger\idle.dll
G:\WINDOWS\AppPatch\AcGenral.DLL
G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\culture.dll
G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Fusion.dll
G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Shfusion.dll
G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
G:\WINDOWS\system32\ACTIVEDS.dll
G:\WINDOWS\system32\adsldpc.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\appHelp.dll
G:\WINDOWS\system32\ATL.DLL
G:\WINDOWS\System32\BatMeter.dll
G:\WINDOWS\system32\browselc.dll
G:\WINDOWS\system32\BROWSEUI.dll
G:\WINDOWS\system32\Cabinet.dll
G:\WINDOWS\System32\CFGMGR32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\credui.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\cryptnet.dll
G:\WINDOWS\system32\CRYPTUI.dll
G:\WINDOWS\System32\CSCDLL.dll
G:\WINDOWS\System32\cscui.dll
G:\WINDOWS\System32\davclnt.dll
G:\WINDOWS\system32\dfshim.dll
G:\WINDOWS\system32\DNSAPI.dll
G:\WINDOWS\System32\drprov.dll
G:\WINDOWS\system32\DUSER.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\iphlpapi.dll
G:\WINDOWS\System32\jscript.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\LINKINFO.dll
G:\WINDOWS\system32\MFC42.DLL
G:\WINDOWS\system32\MFC42LOC.DLL
G:\WINDOWS\system32\midimap.dll
G:\WINDOWS\system32\MLANG.dll
G:\WINDOWS\system32\MPR.dll
G:\WINDOWS\system32\MPRAPI.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\msacm32.drv
G:\WINDOWS\system32\msadp32.acm
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\mscoree.dll
G:\WINDOWS\System32\MSCTF.dll
G:\WINDOWS\system32\MSGINA.dll
G:\WINDOWS\system32\msi.dll
G:\WINDOWS\System32\MSIMG32.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\System32\mstask.dll
G:\WINDOWS\System32\msutb.dll
G:\WINDOWS\system32\msv1_0.dll
G:\WINDOWS\system32\MSVCR71.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\mswsock.dll
G:\WINDOWS\System32\msxml3.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\System32\NETRAP.dll
G:\WINDOWS\system32\NETSHELL.dll
G:\WINDOWS\System32\NETUI0.dll
G:\WINDOWS\System32\NETUI1.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\System32\NTDSAPI.dll
G:\WINDOWS\System32\ntlanman.dll
G:\WINDOWS\system32\ntshrui.dll
G:\WINDOWS\system32\ODBC32.dll
G:\WINDOWS\system32\odbcint.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\System32\POWRPROF.dll
G:\WINDOWS\system32\rasadhlp.dll
G:\WINDOWS\system32\RASAPI32.dll
G:\WINDOWS\system32\RASDLG.dll
G:\WINDOWS\system32\rasman.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\rtutils.dll
G:\WINDOWS\System32\SAMLIB.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SensApi.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\system32\shdoclc.dll
G:\WINDOWS\system32\SHDOCVW.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\System32\sti.dll
G:\WINDOWS\System32\stobject.dll
G:\WINDOWS\system32\SXS.DLL
G:\WINDOWS\system32\TAPI32.dll
G:\WINDOWS\System32\themeui.dll
G:\WINDOWS\system32\urlmon.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\wdmaud.drv
G:\WINDOWS\System32\webcheck.dll
G:\WINDOWS\system32\WINHTTP.dll
G:\WINDOWS\system32\WININET.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\System32\WINSPOOL.DRV
G:\WINDOWS\system32\WINSTA.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\System32\WS2_32.dll
G:\WINDOWS\System32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\System32\WSOCK32.dll
G:\WINDOWS\System32\WTSAPI32.dll
G:\WINDOWS\system32\wuapi.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\System32\zipfldr.dll
G:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCP80.dll
G:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\WINDOWS\system32\ctfmon.exe (22)]
G:\WINDOWS\AppPatch\AcGenral.DLL
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\MSUTB.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\WINDOWS\system32\devldr32.exe (27)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\ATL.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\DEVCON32.DLL
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\midimap.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\msacm32.drv
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SFMAN32.DLL
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\wdmaud.drv
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\WINDOWS\System32\hphmon04.exe (19)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\System32\CFGMGR32.dll
G:\WINDOWS\system32\COMCTL32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\System32\setupapi.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\System32\SHFOLDER.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\System32\WINSPOOL.DRV
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\WINDOWS\system32\HPZipm12.exe (19)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\HPZidr12.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\NTMARTA.DLL
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\SAMLIB.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WINSPOOL.DRV
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\system32\WSOCK32.dll

[G:\WINDOWS\system32\lsass.exe (56)]
G:\WINDOWS\AppPatch\AcGenral.DLL
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\AUTHZ.dll
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\cryptdll.dll
G:\WINDOWS\system32\DNSAPI.dll
G:\WINDOWS\system32\dssenh.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hnetcfg.dll
G:\WINDOWS\system32\iphlpapi.dll
G:\WINDOWS\system32\ipsecsvc.dll
G:\WINDOWS\system32\kerberos.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\LSASRV.dll
G:\WINDOWS\system32\MPR.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\msprivs.dll
G:\WINDOWS\system32\msv1_0.dll
G:\WINDOWS\system32\MSVCP60.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\mswsock.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\netlogon.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\NTDSAPI.dll
G:\WINDOWS\system32\oakley.DLL
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\psbase.dll
G:\WINDOWS\system32\pstorsvc.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\SAMLIB.dll
G:\WINDOWS\system32\SAMSRV.dll
G:\WINDOWS\system32\scecli.dll
G:\WINDOWS\system32\schannel.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\w32time.dll
G:\WINDOWS\system32\wdigest.dll
G:\WINDOWS\system32\WINIPSEC.DLL
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\WINDOWS\system32\NOTEPAD.EXE (24)]
G:\WINDOWS\AppPatch\AcGenral.DLL
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINSPOOL.DRV
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll

[G:\WINDOWS\system32\NOTEPAD.EXE (26)]
G:\Program Files\Yahoo!\Messenger\idle.dll
G:\Program Files\Yahoo!\Messenger\MSVCR71.dll
G:\WINDOWS\AppPatch\AcGenral.DLL
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINSPOOL.DRV
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll

[G:\WINDOWS\system32\NOTEPAD.EXE (26)]
G:\Program Files\Yahoo!\Messenger\idle.dll
G:\Program Files\Yahoo!\Messenger\MSVCR71.dll
G:\WINDOWS\AppPatch\AcGenral.DLL
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINSPOOL.DRV
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll

[G:\WINDOWS\system32\NOTEPAD.EXE (26)]
G:\Program Files\Yahoo!\Messenger\idle.dll
G:\Program Files\Yahoo!\Messenger\MSVCR71.dll
G:\WINDOWS\AppPatch\AcGenral.DLL
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINSPOOL.DRV
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll

[G:\WINDOWS\system32\services.exe (34)]
G:\WINDOWS\AppPatch\AcGenral.DLL
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\Apphelp.dll
G:\WINDOWS\system32\AUTHZ.dll
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\eventlog.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\MSVCP60.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\NCObjAPI.DLL
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\PSAPI.DLL
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\SCESRV.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\umpnpmgr.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINSTA.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\system32\wtsapi32.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\WINDOWS\System32\smss.exe (1)]
G:\WINDOWS\system32\ntdll.dll

[G:\WINDOWS\system32\sol.exe (25)]
G:\Program Files\Yahoo!\Messenger\idle.dll
G:\Program Files\Yahoo!\Messenger\MSVCR71.dll
G:\WINDOWS\AppPatch\AcGenral.DLL
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CARDS.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\mslbui.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll

[G:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe (16)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\COMCTL32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\System32\spool\drivers\w32x86\3\HPZR3212.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\WINSPOOL.DRV
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\WINDOWS\system32\spoolsv.exe (61)]
G:\Program Files\Bonjour\mdnsNSP.dll
G:\WINDOWS\AppPatch\AcGenral.DLL
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\CLUSAPI.dll
G:\WINDOWS\system32\cnbjmon.dll
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\DNSAPI.dll
G:\WINDOWS\system32\EBPMON24.DLL
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hptcpmib.dll
G:\WINDOWS\system32\HpTcpMon.dll
G:\WINDOWS\system32\HPTcpMUI.dll
G:\WINDOWS\system32\hpzjrd01.dll
G:\WINDOWS\system32\hpzsnt12.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\inetpp.dll
G:\WINDOWS\system32\iphlpapi.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\localspl.dll
G:\WINDOWS\system32\mgmtapi.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\System32\mswsock.dll
G:\WINDOWS\system32\netapi32.dll
G:\WINDOWS\system32\NETRAP.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\NTDSAPI.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\pjlmon.dll
G:\WINDOWS\system32\rasadhlp.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\sfc_os.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\snmpapi.dll
G:\WINDOWS\System32\spool\PRTPROCS\W32X86\filterpipelineprintproc.dll
G:\WINDOWS\system32\SPOOLSS.DLL
G:\WINDOWS\system32\tcpmon.dll
G:\WINDOWS\system32\usbmon.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\win32spl.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\System32\winrnr.dll
G:\WINDOWS\system32\winspool.drv
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WLDAP32.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\system32\wsnmp32.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\WINDOWS\System32\svchost.exe (145)]
G:\Program Files\Bonjour\mdnsNSP.dll
G:\WINDOWS\AppPatch\AcGenral.DLL
g:\windows\pchealth\helpctr\binaries\pchsvc.dll
G:\WINDOWS\System32\ACTIVEDS.dll
G:\WINDOWS\System32\adsldpc.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\Apphelp.dll
g:\windows\system32\ATL.DLL
g:\windows\system32\audiosrv.dll
g:\windows\system32\AUTHZ.dll
g:\windows\system32\browser.dll
G:\WINDOWS\system32\Cabinet.dll
g:\windows\system32\certcli.dll
G:\WINDOWS\System32\CLBCATQ.DLL
G:\WINDOWS\System32\CLUSAPI.DLL
G:\WINDOWS\system32\colbact.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\System32\COMRes.dll
G:\WINDOWS\system32\comsvcs.dll
g:\windows\system32\credui.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\System32\cryptdll.dll
g:\windows\system32\cryptsvc.dll
G:\WINDOWS\system32\CRYPTUI.dll
g:\windows\system32\dhcpcsvc.dll
g:\windows\system32\dmserver.dll
g:\windows\system32\DNSAPI.dll
g:\windows\system32\ersvc.dll
g:\windows\system32\es.dll
g:\windows\system32\ESENT.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\System32\h323.tsp
g:\windows\system32\HID.DLL
G:\WINDOWS\System32\hidphone.tsp
g:\windows\system32\hidserv.dll
G:\WINDOWS\System32\hnetcfg.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\System32\ipconf.tsp
g:\windows\system32\iphlpapi.dll
g:\windows\system32\ipnathlp.dll
G:\WINDOWS\system32\kerberos.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\System32\kmddsp.tsp
G:\WINDOWS\system32\modemui.dll
G:\WINDOWS\system32\MPR.dll
G:\WINDOWS\System32\MPRAPI.dll
G:\WINDOWS\System32\MSACM32.dll
G:\WINDOWS\system32\MSASN1.dll
g:\windows\system32\msi.dll
G:\WINDOWS\System32\MSIDLE.DLL
G:\WINDOWS\system32\msv1_0.dll
g:\windows\system32\MSVCP60.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\mswsock.dll
G:\WINDOWS\system32\MTXCLU.DLL
G:\WINDOWS\system32\NCObjAPI.DLL
G:\WINDOWS\System32\ndptsp.tsp
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\System32\netcfgx.dll
g:\windows\system32\netman.dll
g:\windows\system32\netshell.dll
G:\WINDOWS\system32\ntdll.dll
g:\windows\system32\NTDSAPI.dll
G:\WINDOWS\System32\ntlsapi.dll
G:\WINDOWS\System32\NTMARTA.DLL
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
g:\windows\system32\POWRPROF.dll
g:\windows\system32\PSAPI.DLL
g:\windows\system32\qmgr.dll
G:\WINDOWS\System32\rasadhlp.dll
G:\WINDOWS\System32\RASAPI32.dll
G:\WINDOWS\System32\raschap.dll
G:\WINDOWS\System32\RASDLG.dll
G:\WINDOWS\System32\rasman.dll
G:\WINDOWS\System32\rasmans.dll
G:\WINDOWS\System32\rasppp.dll
G:\WINDOWS\System32\rastapi.dll
G:\WINDOWS\System32\rastls.dll
G:\WINDOWS\System32\RESUTILS.DLL
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\System32\rsaenh.dll
g:\windows\system32\rtutils.dll
G:\WINDOWS\System32\SAMLIB.dll
G:\WINDOWS\System32\SCHANNEL.dll
g:\windows\system32\schedsvc.dll
g:\windows\system32\seclogon.dll
G:\WINDOWS\system32\Secur32.dll
g:\windows\system32\sens.dll
G:\WINDOWS\System32\SETUPAPI.dll
G:\WINDOWS\system32\SHELL32.dll
g:\windows\system32\SHFOLDER.dll
G:\WINDOWS\System32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
g:\windows\system32\shsvcs.dll
g:\windows\system32\srsvc.dll
g:\windows\system32\srvsvc.dll
G:\WINDOWS\System32\SSDPAPI.dll
G:\WINDOWS\System32\SXS.DLL
G:\WINDOWS\System32\TAPI32.dll
g:\windows\system32\tapisrv.dll
g:\windows\system32\trkwks.dll
G:\WINDOWS\System32\unimdm.tsp
G:\WINDOWS\System32\unimdmat.dll
G:\WINDOWS\System32\uniplat.dll
G:\WINDOWS\System32\upnp.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\System32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\VSSAPI.DLL
g:\windows\system32\w32time.dll
G:\WINDOWS\System32\Wbem\esscli.dll
G:\WINDOWS\System32\Wbem\FastProx.dll
G:\WINDOWS\System32\wbem\ncprov.dll
G:\WINDOWS\System32\wbem\repdrvfs.dll
G:\WINDOWS\System32\wbem\wbemcomn.dll
G:\WINDOWS\System32\Wbem\wbemcore.dll
G:\WINDOWS\System32\wbem\wbemess.dll
G:\WINDOWS\System32\wbem\wbemsvc.dll
G:\WINDOWS\System32\wbem\wmiprvsd.dll
g:\windows\system32\wbem\wmisvc.dll
G:\WINDOWS\System32\wbem\wmiutils.dll
g:\windows\system32\WINHTTP.dll
G:\WINDOWS\system32\WININET.dll
G:\WINDOWS\System32\WINIPSEC.DLL
G:\WINDOWS\System32\WINMM.dll
G:\WINDOWS\System32\winrnr.dll
G:\WINDOWS\System32\WinSCard.dll
G:\WINDOWS\System32\WINSTA.dll
G:\WINDOWS\system32\WINTRUST.dll
g:\windows\system32\wkssvc.dll
G:\WINDOWS\system32\WLDAP32.dll
g:\windows\system32\WMI.dll
g:\windows\system32\WS2_32.dll
g:\windows\system32\WS2HELP.dll
g:\windows\system32\wscsvc.dll
G:\WINDOWS\System32\wshtcpip.dll
G:\WINDOWS\system32\WSOCK32.dll
g:\windows\system32\WTSAPI32.dll
G:\WINDOWS\system32\wuapi.dll
g:\windows\system32\WZCSAPI.DLL
g:\windows\system32\wzcsvc.dll
G:\WINDOWS\System32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\WINDOWS\System32\svchost.exe (38)]
G:\WINDOWS\AppPatch\AcGenral.DLL
G:\WINDOWS\System32\actxprxy.dll
G:\WINDOWS\system32\ADVAPI32.dll
g:\windows\system32\CFGMGR32.dll
G:\WINDOWS\System32\CLBCATQ.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\System32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\hpgwiamd.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\System32\MSACM32.dll
G:\WINDOWS\system32\MSASN1.dll
g:\windows\system32\mscms.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\System32\setupapi.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\System32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\System32\sti.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\System32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
g:\windows\system32\wiaservc.dll
G:\WINDOWS\System32\WINMM.dll
g:\windows\system32\WINSPOOL.DRV
g:\windows\system32\WINSTA.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\System32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\WINDOWS\system32\svchost.exe (47)]
G:\WINDOWS\AppPatch\AcGenral.DLL
g:\windows\system32\ACTIVEDS.dll
g:\windows\system32\adsldpc.dll
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\Apphelp.dll
g:\windows\system32\ATL.DLL
g:\windows\system32\AUTHZ.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\comctl32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\GDI32.dll
g:\windows\system32\ICAAPI.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\msi.dll
g:\windows\system32\mstlsapi.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\NTMARTA.DLL
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\REGAPI.dll
G:\WINDOWS\system32\RPCRT4.dll
g:\windows\system32\rpcss.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\SAMLIB.dll
G:\WINDOWS\system32\Secur32.dll
g:\windows\system32\SETUPAPI.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\ShimEng.dll
G:\WINDOWS\system32\SHLWAPI.dll
g:\windows\system32\termsrv.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\UxTheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\WLDAP32.dll
g:\windows\system32\WS2_32.dll
g:\windows\system32\WS2HELP.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\WINDOWS\system32\winlogon.exe (73)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\Apphelp.dll
G:\WINDOWS\system32\AUTHZ.dll
G:\WINDOWS\system32\avgrsstx.dll
G:\WINDOWS\system32\CLBCATQ.DLL
G:\WINDOWS\system32\COMCTL32.dll
G:\WINDOWS\system32\comdlg32.dll
G:\WINDOWS\system32\COMRes.dll
G:\WINDOWS\system32\CRYPT32.dll
G:\WINDOWS\system32\cscdll.dll
G:\WINDOWS\system32\cscui.dll
G:\WINDOWS\system32\DNSAPI.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\IMAGEHLP.dll
G:\WINDOWS\system32\iphlpapi.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\midimap.dll
G:\WINDOWS\system32\MPR.dll
G:\WINDOWS\system32\MSACM32.dll
G:\WINDOWS\system32\msacm32.drv
G:\WINDOWS\system32\MSASN1.dll
G:\WINDOWS\system32\MSGINA.dll
G:\WINDOWS\system32\msv1_0.dll
G:\WINDOWS\system32\MSVCP60.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\NDdeApi.dll
G:\WINDOWS\system32\NETAPI32.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\NTDSAPI.dll
G:\WINDOWS\system32\NTMARTA.DLL
G:\WINDOWS\system32\ODBC32.dll
G:\WINDOWS\system32\odbcint.dll
G:\WINDOWS\system32\ole32.dll
G:\WINDOWS\system32\OLEAUT32.dll
G:\WINDOWS\system32\PROFMAP.dll
G:\WINDOWS\system32\PSAPI.DLL
G:\WINDOWS\system32\RASAPI32.dll
G:\WINDOWS\system32\rasman.dll
G:\WINDOWS\system32\REGAPI.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\rsaenh.dll
G:\WINDOWS\system32\rtutils.dll
G:\WINDOWS\system32\SAMLIB.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SETUPAPI.dll
G:\WINDOWS\system32\sfc.dll
G:\WINDOWS\system32\sfc_os.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\SHSVCS.dll
G:\WINDOWS\system32\sxs.dll
G:\WINDOWS\system32\TAPI32.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\USERENV.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\VERSION.dll
G:\WINDOWS\System32\wbem\fastprox.dll
G:\WINDOWS\System32\wbem\wbemcomn.dll
G:\WINDOWS\System32\wbem\wbemprox.dll
G:\WINDOWS\System32\wbem\wbemsvc.dll
G:\WINDOWS\system32\wdmaud.drv
G:\WINDOWS\system32\WINMM.dll
G:\WINDOWS\system32\WINSCARD.DLL
G:\WINDOWS\system32\WINSPOOL.DRV
G:\WINDOWS\system32\WINSTA.dll
G:\WINDOWS\system32\WINTRUST.dll
G:\WINDOWS\system32\wldap32.dll
G:\WINDOWS\system32\WlNotify.dll
G:\WINDOWS\system32\WS2_32.dll
G:\WINDOWS\system32\WS2HELP.dll
G:\WINDOWS\system32\WTSAPI32.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

[G:\WINDOWS\system32\wscntfy.exe (14)]
G:\WINDOWS\system32\ADVAPI32.dll
G:\WINDOWS\system32\GDI32.dll
G:\WINDOWS\system32\kernel32.dll
G:\WINDOWS\system32\MSCTF.dll
G:\WINDOWS\system32\msvcrt.dll
G:\WINDOWS\system32\ntdll.dll
G:\WINDOWS\system32\RPCRT4.dll
G:\WINDOWS\system32\Secur32.dll
G:\WINDOWS\system32\SHELL32.dll
G:\WINDOWS\system32\SHLWAPI.dll
G:\WINDOWS\system32\USER32.dll
G:\WINDOWS\system32\uxtheme.dll
G:\WINDOWS\system32\xpsp2res.dll
G:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

——————–

Autostart folders:

[Startup (1)]
desktop.ini

[User Startup (1)]
desktop.ini

[Common Startup (7)]
Adobe Gamma Loader.exe.lnk
Adobe Reader Speed Launch.lnk
desktop.ini
GetRight.lnk
HP Digital Imaging Monitor.lnk
InterVideo WinCinema Manager.lnk
Microsoft Office.lnk

[User Common Startup (7)]
Adobe Gamma Loader.exe.lnk
Adobe Reader Speed Launch.lnk
desktop.ini
GetRight.lnk
HP Digital Imaging Monitor.lnk
InterVideo WinCinema Manager.lnk
Microsoft Office.lnk

——————–

Task Scheduler jobs (1):

WGASetup.job

——————–

IniMapping values:

System NT shell = Explorer.exe
User screensaver = G:\WINDOWS\System32\logon.scr

——————–

Autostarting batch files:

[autoexec.nt]
@echo off
lh %SystemRoot%\system32\mscdexnt.exe
lh %SystemRoot%\system32\redir
lh %SystemRoot%\system32\dosx
SET BLASTER=A220 I5 D1 P330 T3

[config.nt]
dos=high, umb
device=%SystemRoot%\system32\himem.sys
files=40

——————–

On-reboot actions:

BootExecute = autocheck autochk *

——————–

Shell commands:

.bat - MS-DOS Batch File - "%1" %*
.cmd - Windows NT Command Script - "%1" %*
.com - MS-DOS Application - "%1" %*
.exe - Application - "%1" %*
.hta - HTML Application - G:\WINDOWS\System32\mshta.exe "%1" %*
.js - JScript Script File - G:\WINDOWS\System32\WScript.exe "%1" %*
.jse - JScript Encoded Script File - G:\WINDOWS\System32\WScript.exe "%1" %*
.pif - Shortcut to MS-DOS Program - "%1" %*
.scr - Screen Saver - "%1" /S
.txt - Text Document - G:\WINDOWS\system32\NOTEPAD.EXE %1
.vbe - VBScript Encoded Script File - G:\WINDOWS\System32\WScript.exe "%1" %*
.vbs - VBScript Script File - G:\WINDOWS\System32\WScript.exe "%1" %*
.wsf - Windows Script File - G:\WINDOWS\System32\WScript.exe "%1" %*
.wsh - Windows Script Host Settings File - G:\WINDOWS\System32\WScript.exe "%1" %*

——————–

Services:

[NT Services (43)]
Apple Mobile Device = "G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"
Background Intelligent Transfer Service = G:\WINDOWS\System32\svchost.exe -k netsvcs
Bonjour Service = "G:\Program Files\Bonjour\mDNSResponder.exe"
Computer Browser = G:\WINDOWS\System32\svchost.exe -k netsvcs
Cryptographic Services = G:\WINDOWS\system32\svchost.exe -k netsvcs
DCOM Server Process Launcher = G:\WINDOWS\system32\svchost -k DcomLaunch
DHCP Client = G:\WINDOWS\System32\svchost.exe -k netsvcs
Distributed Link Tracking Client = G:\WINDOWS\system32\svchost.exe -k netsvcs
DNS Client = G:\WINDOWS\System32\svchost.exe -k NetworkService
Error Reporting Service = G:\WINDOWS\System32\svchost.exe -k netsvcs
Event Log = G:\WINDOWS\system32\services.exe
Help and Support = G:\WINDOWS\System32\svchost.exe -k netsvcs
HID Input Service = G:\WINDOWS\System32\svchost.exe -k netsvcs
IPSEC Services = G:\WINDOWS\System32\lsass.exe
Java Quick Starter = "G:\Program Files\Java\jre6\bin\jqs.exe" -service -config "G:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
Logical Disk Manager = G:\WINDOWS\System32\svchost.exe -k netsvcs
Machine Debug Manager = "G:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"
Plug and Play = G:\WINDOWS\system32\services.exe
Pml Driver HPZ12 = G:\WINDOWS\system32\HPZipm12.exe
Print Spooler = G:\WINDOWS\system32\spoolsv.exe
Protected Storage = G:\WINDOWS\system32\lsass.exe
Remote Procedure Call (RPC) = G:\WINDOWS\system32\svchost -k rpcss
Remote Registry = G:\WINDOWS\system32\svchost.exe -k LocalService
SeaPort = "G:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
Secondary Logon = G:\WINDOWS\System32\svchost.exe -k netsvcs
Security Accounts Manager = G:\WINDOWS\system32\lsass.exe
Security Center = G:\WINDOWS\System32\svchost.exe -k netsvcs
Server = G:\WINDOWS\System32\svchost.exe -k netsvcs
Shell Hardware Detection = G:\WINDOWS\System32\svchost.exe -k netsvcs
System Event Notification = G:\WINDOWS\system32\svchost.exe -k netsvcs
System Restore Service = G:\WINDOWS\System32\svchost.exe -k netsvcs
Task Scheduler = G:\WINDOWS\System32\svchost.exe -k netsvcs
TCP/IP NetBIOS Helper = G:\WINDOWS\System32\svchost.exe -k LocalService
Themes = G:\WINDOWS\System32\svchost.exe -k netsvcs
Viewpoint Manager Service = "G:\Program Files\Viewpoint\Common\ViewpointService.exe"
WebClient = G:\WINDOWS\System32\svchost.exe -k LocalService
Windows Audio = G:\WINDOWS\System32\svchost.exe -k netsvcs
Windows Firewall/Internet Connection Sharing (ICS) = G:\WINDOWS\System32\svchost.exe -k netsvcs
Windows Image Acquisition (WIA) = G:\WINDOWS\System32\svchost.exe -k imgsvc
Windows Management Instrumentation = G:\WINDOWS\system32\svchost.exe -k netsvcs
Windows Time = G:\WINDOWS\System32\svchost.exe -k netsvcs
Wireless Zero Configuration = G:\WINDOWS\System32\svchost.exe -k netsvcs
Workstation = G:\WINDOWS\System32\svchost.exe -k netsvcs

[VxD Services (1)]
JAVASUP = JAVASUP.VXD

[SafeBoot services (Minimal boot)]
* CD-ROM Drive *
{4D36E965-E325-11CE-BFC1-08002BE10318}

* DiskDrive *
{4D36E967-E325-11CE-BFC1-08002BE10318}

* Driver *
dmboot.sys
dmio.sys
dmload.sys
sermouse.sys
vga.sys
vgasave.sys

* Driver Group *
Base
Boot Bus Extender
Boot file system
File system
Filter
PCI Configuration
PNP Filter
Primary disk
SCSI Class
System Bus Extender

* Floppy disk drive *
{4D36E980-E325-11CE-BFC1-08002BE10318}

* FSFilter System Recovery *
sr.sys

* Hdc *
{4D36E96A-E325-11CE-BFC1-08002BE10318}

* Human Interface Devices *
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}

* Keyboard *
{4D36E96B-E325-11CE-BFC1-08002BE10318}

* Mouse *
{4D36E96F-E325-11CE-BFC1-08002BE10318}

* PCMCIA Adapters *
{4D36E977-E325-11CE-BFC1-08002BE10318}

* SCSIAdapter *
{4D36E97B-E325-11CE-BFC1-08002BE10318}

* Service *
AppMgmt
CryptSvc
DcomLaunch
dmadmin
dmserver
EventLog
HelpSvc
Netlogon
PlugPlay
RpcSs
SRService
vds
WinMgmt

* Standard floppy disk controller *
{4D36E969-E325-11CE-BFC1-08002BE10318}

* System *
{4D36E97D-E325-11CE-BFC1-08002BE10318}

* Universal Serial Bus controllers *
{36FC9E60-C465-11CF-8056-444553540000}

* Volume *
{71A27CDD-812A-11D0-BEC7-08002BE2092F}

* Volume shadow copy *
{533C5B84-EC70-11D2-9505-00C04F79DEAF}


[SafeBoot services (Minimal boot + network support)]
* CD-ROM Drive *
{4D36E965-E325-11CE-BFC1-08002BE10318}

* DiskDrive *
{4D36E967-E325-11CE-BFC1-08002BE10318}

* Driver *
dmboot.sys
dmio.sys
dmload.sys
ip6fw.sys
ipnat.sys
rdpcdd.sys
rdpdd.sys
rdpwd.sys
sermouse.sys
tdpipe.sys
tdtcp.sys
vga.sys
vgasave.sys

* Driver Group *
Base
Boot Bus Extender
Boot file system
File system
Filter
NDIS
NDIS Wrapper
NetBIOSGroup
NetDDEGroup
Network
NetworkProvider
PCI Configuration
PNP Filter
PNP_TDI
Primary disk
SCSI Class
Streams Drivers
System Bus Extender
TDI

* Floppy disk drive *
{4D36E980-E325-11CE-BFC1-08002BE10318}

* FSFilter System Recovery *
sr.sys

* Hdc *
{4D36E96A-E325-11CE-BFC1-08002BE10318}

* Human Interface Devices *
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}

* Keyboard *
{4D36E96B-E325-11CE-BFC1-08002BE10318}

* Mouse *
{4D36E96F-E325-11CE-BFC1-08002BE10318}

* Net *
{4D36E972-E325-11CE-BFC1-08002BE10318}

* NetClient *
{4D36E973-E325-11CE-BFC1-08002BE10318}

* NetService *
{4D36E974-E325-11CE-BFC1-08002BE10318}

* NetTrans *
{4D36E975-E325-11CE-BFC1-08002BE10318}

* PCMCIA Adapters *
{4D36E977-E325-11CE-BFC1-08002BE10318}

* SCSIAdapter *
{4D36E97B-E325-11CE-BFC1-08002BE10318}

* Service *
AFD
AppMgmt
Browser
CryptSvc
DcomLaunch
Dhcp
dmadmin
dmserver
DnsCache
EventLog
HelpSvc
LanmanServer
LanmanWorkstation
LmHosts
Messenger
Ndisuio
NetBIOS
NetBT
Netlogon
NetMan
NtLmSsp
PlugPlay
rdsessmgr
RpcSs
sharedaccess
SRService
Tcpip
termservice
UploadMgr
WinMgmt
WZCSVC

* Standard floppy disk controller *
{4D36E969-E325-11CE-BFC1-08002BE10318}

* System *
{4D36E97D-E325-11CE-BFC1-08002BE10318}

* Universal Serial Bus controllers *
{36FC9E60-C465-11CF-8056-444553540000}

* Volume *
{71A27CDD-812A-11D0-BEC7-08002BE2092F}


[SafeBoot: Alternate shell]
cmd.exe (not enabled)

——————–

Driver filters:

[Class filters]
* Disk drives *
- Upper filters
PartMgr.sys

* DVD/CD-ROM drives *
- Upper filters
GEARAspiWDM.sys

- Lower filters
PxHelp20.sys
AFS2K.sys

* Infrared devices *
- Upper filters
IRENUM.sys

* Keyboards *
- Upper filters
kbdclass.sys

* Medium Changers *
- Upper filters
GEARAspiWDM.sys

* Mice and other pointing devices *
- Upper filters
mouclass.sys

* Storage volumes *
- Upper filters
VolSnap.sys

* Tape drives *
- Upper filters
GEARAspiWDM.sys



[Device filters]
* AMD-751 Processor to AGP Controller *
- Upper filters
AMDAGP.sys

* CD-ROM Drive *
- Upper filters
redbook.sys

- Lower filters
imapi.sys

* CD-ROM Drive *
- Upper filters
redbook.sys

* Communications Port *
- Upper filters
serenum.sys

* Compaq Data Fax Modem *
- Lower filters
HCF_MSFT.sys

* Creative SBLive! Gameport *
- Lower filters
ctljystk.sys

* Direct Parallel *
- Lower filters
PtiLink.sys

* Terminal Server Keyboard Driver *
- Upper filters
kbdclass.sys

* Terminal Server Mouse Driver *
- Upper filters
mouclass.sys

* WAN Miniport (IP) *
- Lower filters
NdisTapi.sys

* WAN Miniport (PPPOE) *
- Lower filters
NdisTapi.sys

* WAN Miniport (PPTP) *
- Lower filters
NdisTapi.sys



——————–

Print monitors (8):

BJ Language Monitor - cnbjmon.dll
EPSON V6 2KMonitor - EBPMON24.DLL
HP Standard TCP/IP Port - HpTcpMon.dll
hpzsnt12 - hpzsnt12.dll
Local Port - localspl.dll
PJL Language Monitor - pjlmon.dll
Standard TCP/IP Port - tcpmon.dll
USB Monitor - usbmon.dll

——————–

WinLogon autoruns:

UserInit = G:\WINDOWS\system32\userinit.exe,
VmApplet = rundll32 shell32,Control_RunDLL "sysdm.cpl"

[Notify (10)]
avgrsstarter = avgrsstx.dll
crypt32chain = crypt32.dll
cryptnet = cryptnet.dll
cscdll = cscdll.dll
ScCertProp = wlnotify.dll
Schedule = wlnotify.dll
sclgntfy = sclgntfy.dll
SensLogn = WlNotify.dll
termsrv = wlnotify.dll
wlballoon = wlnotify.dll

[Group policy extensions (11)]
Wireless = gptext.dll
Folder Redirection = fdeploy.dll
Microsoft Disk Quota = dskquota.dll
QoS Packet Scheduler = gptext.dll
Scripts = gptext.dll
Internet Explorer Zonemapping = iedkcs32.dll
Security = scecli.dll
Internet Explorer Branding = iedkcs32.dll
EFS recovery = scecli.dll
Software Installation = appmgmts.dll
IP Security = gptext.dll

——————–

Policies:

[This user]
* Primary policies *
- (4)
EditorPreference = dword: 131072
Send Pictures With Document = dword: 0
HTTP11SAVED = dword: 0
HTTP11SAVED_VAL = dword: 0

* Alternate policies *
- Software\Microsoft\Windows\CurrentVersion\policies\Explorer (2)
NoDriveTypeAutoRun = dword: 255
_NoDriveTypeAutoRun = dword: 145

- (4)
EditorPreference = dword: 131072
Send Pictures With Document = dword: 0
HTTP11SAVED = dword: 0
HTTP11SAVED_VAL = dword: 0



[All users]
* Primary policies *
- Software\Policies\Microsoft\Windows\CurrentVersion\Identities (2)
@ =
Locked Down = dword: 0

- Software\Policies\Microsoft\Windows\Installer (1)
EnableAdminTSRemote = dword: 1

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecFilter{72385235-70fa-11d1-864c-14a300000000} (7)
ClassName = ipsecFilter
description = Matches all ICMP packets between this computer and any other computer.
name = ipsecFilter{72385235-70fa-11d1-864c-14a300000000}
ipsecName = All ICMP Traffic
ipsecID = {72385235-70fa-11d1-864c-14a300000000}
ipsecDataType = dword: 256
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecFilter{7238523a-70fa-11d1-864c-14a300000000} (7)
ClassName = ipsecFilter
description = Matches all IP packets from this computer to any other computer, except broadcast, multicast, Kerberos, RSVP and ISAKMP (IKE).
name = ipsecFilter{7238523a-70fa-11d1-864c-14a300000000}
ipsecName = All IP Traffic
ipsecID = {7238523a-70fa-11d1-864c-14a300000000}
ipsecDataType = dword: 256
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{72385231-70fa-11d1-864c-14a300000000} (5)
ClassName = ipsecISAKMPPolicy
name = ipsecISAKMPPolicy{72385231-70fa-11d1-864c-14a300000000}
ipsecID = {72385231-70fa-11d1-864c-14a300000000}
ipsecDataType = dword: 256
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{72385234-70fa-11d1-864c-14a300000000} (5)
ClassName = ipsecISAKMPPolicy
name = ipsecISAKMPPolicy{72385234-70fa-11d1-864c-14a300000000}
ipsecID = {72385234-70fa-11d1-864c-14a300000000}
ipsecDataType = dword: 256
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{72385237-70fa-11d1-864c-14a300000000} (5)
ClassName = ipsecISAKMPPolicy
name = ipsecISAKMPPolicy{72385237-70fa-11d1-864c-14a300000000}
ipsecID = {72385237-70fa-11d1-864c-14a300000000}
ipsecDataType = dword: 256
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{7238523d-70fa-11d1-864c-14a300000000} (5)
ClassName = ipsecISAKMPPolicy
name = ipsecISAKMPPolicy{7238523d-70fa-11d1-864c-14a300000000}
ipsecID = {7238523d-70fa-11d1-864c-14a300000000}
ipsecDataType = dword: 256
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{613830ba-dd1b-447f-80e6-6d4eaadb1473} (7)
ClassName = ipsecNegotiationPolicy
name = ipsecNegotiationPolicy{613830ba-dd1b-447f-80e6-6d4eaadb1473}
ipsecID = {613830ba-dd1b-447f-80e6-6d4eaadb1473}
ipsecNegotiationPolicyAction = {8a171dd3-77e3-11d1-8659-a04f00000000}
ipsecNegotiationPolicyType = {62f49e13-6c37-11d1-864c-14a300000000}
ipsecDataType = dword: 256
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{72385233-70fa-11d1-864c-14a300000000} (9)
ClassName = ipsecNegotiationPolicy
description = Accepts unsecured communication, but requests clients to establish trust and security methods. Will communicate insecurely to untrusted clients if they do not respond to request.
name = ipsecNegotiationPolicy{72385233-70fa-11d1-864c-14a300000000}
ipsecName = Request Security (Optional)
ipsecID = {72385233-70fa-11d1-864c-14a300000000}
ipsecNegotiationPolicyAction = {3f91a81a-7647-11d1-864d-d46a00000000}
ipsecNegotiationPolicyType = {62f49e10-6c37-11d1-864c-14a300000000}
ipsecDataType = dword: 256
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{7238523b-70fa-11d1-864c-14a300000000} (9)
ClassName = ipsecNegotiationPolicy
description = Permit unsecured IP packets to pass through.
name = ipsecNegotiationPolicy{7238523b-70fa-11d1-864c-14a300000000}
ipsecName = Permit
ipsecID = {7238523b-70fa-11d1-864c-14a300000000}
ipsecNegotiationPolicyAction = {8a171dd2-77e3-11d1-8659-a04f00000000}
ipsecNegotiationPolicyType = {62f49e10-6c37-11d1-864c-14a300000000}
ipsecDataType = dword: 256
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{7238523f-70fa-11d1-864c-14a300000000} (9)
ClassName = ipsecNegotiationPolicy
description = Accepts unsecured communication, but always requires clients to establish trust and security methods. Will NOT communicate with untrusted clients.
name = ipsecNegotiationPolicy{7238523f-70fa-11d1-864c-14a300000000}
ipsecName = Require Security
ipsecID = {7238523f-70fa-11d1-864c-14a300000000}
ipsecNegotiationPolicyAction = {3f91a81a-7647-11d1-864d-d46a00000000}
ipsecNegotiationPolicyType = {62f49e10-6c37-11d1-864c-14a300000000}
ipsecDataType = dword: 256
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{941b28d0-dfa1-46e2-a27d-23ff0ab2c65a} (7)
ClassName = ipsecNegotiationPolicy
name = ipsecNegotiationPolicy{941b28d0-dfa1-46e2-a27d-23ff0ab2c65a}
ipsecID = {941b28d0-dfa1-46e2-a27d-23ff0ab2c65a}
ipsecNegotiationPolicyAction = {8a171dd3-77e3-11d1-8659-a04f00000000}
ipsecNegotiationPolicyType = {62f49e13-6c37-11d1-864c-14a300000000}
ipsecDataType = dword: 256
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{ce6e5a5a-5ba9-45dc-aa15-a5c713dafd99} (7)
ClassName = ipsecNegotiationPolicy
name = ipsecNegotiationPolicy{ce6e5a5a-5ba9-45dc-aa15-a5c713dafd99}
ipsecID = {ce6e5a5a-5ba9-45dc-aa15-a5c713dafd99}
ipsecNegotiationPolicyAction = {8a171dd3-77e3-11d1-8659-a04f00000000}
ipsecNegotiationPolicyType = {62f49e13-6c37-11d1-864c-14a300000000}
ipsecDataType = dword: 256
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{776fa0e5-e901-4862-9799-637e4e4d8a4d} (6)
ClassName = ipsecNFA
name = ipsecNFA{776fa0e5-e901-4862-9799-637e4e4d8a4d}
ipsecID = {776fa0e5-e901-4862-9799-637e4e4d8a4d}
ipsecDataType = dword: 256
ipsecNegotiationPolicyReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{941b28d0-dfa1-46e2-a27d-23ff0ab2c65a}
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{84dd1158-6fdd-4cad-bb0b-5b909e4724c6} (6)
ClassName = ipsecNFA
name = ipsecNFA{84dd1158-6fdd-4cad-bb0b-5b909e4724c6}
ipsecID = {84dd1158-6fdd-4cad-bb0b-5b909e4724c6}
ipsecDataType = dword: 256
ipsecNegotiationPolicyReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{613830ba-dd1b-447f-80e6-6d4eaadb1473}
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{8ab59bc2-f660-4a45-b7cc-2ec5985bfcdc} (8)
ClassName = ipsecNFA
name = ipsecNFA{8ab59bc2-f660-4a45-b7cc-2ec5985bfcdc}
ipsecName = Permit unsecure ICMP packets to pass through.
description = Permit unsecure ICMP packets to pass through.
ipsecID = {8ab59bc2-f660-4a45-b7cc-2ec5985bfcdc}
ipsecDataType = dword: 256
ipsecNegotiationPolicyReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{7238523b-70fa-11d1-864c-14a300000000}
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{af25eebf-4312-4195-8fd5-88a759f5d903} (8)
ClassName = ipsecNFA
name = ipsecNFA{af25eebf-4312-4195-8fd5-88a759f5d903}
ipsecName = Request Security (Optional) Rule
description = For all IP traffic, always request security using Kerberos trust. Allow unsecured communication with clients that do not respond to request.
ipsecID = {af25eebf-4312-4195-8fd5-88a759f5d903}
ipsecDataType = dword: 256
ipsecNegotiationPolicyReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{72385233-70fa-11d1-864c-14a300000000}
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{d70db416-cc8b-461e-8073-d012d3f7f087} (8)
ClassName = ipsecNFA
name = ipsecNFA{d70db416-cc8b-461e-8073-d012d3f7f087}
ipsecName = Permit unsecure ICMP packets to pass through.
description = Permit unsecure ICMP packets to pass through.
ipsecID = {d70db416-cc8b-461e-8073-d012d3f7f087}
ipsecDataType = dword: 256
ipsecNegotiationPolicyReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{7238523b-70fa-11d1-864c-14a300000000}
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{eaccbf88-a8b6-4235-a865-5f5a516e62f9} (6)
ClassName = ipsecNFA
name = ipsecNFA{eaccbf88-a8b6-4235-a865-5f5a516e62f9}
ipsecID = {eaccbf88-a8b6-4235-a865-5f5a516e62f9}
ipsecDataType = dword: 256
ipsecNegotiationPolicyReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{ce6e5a5a-5ba9-45dc-aa15-a5c713dafd99}
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNFA{fc2e4bc5-0fde-462e-8e5e-49129fc730f0} (8)
ClassName = ipsecNFA
name = ipsecNFA{fc2e4bc5-0fde-462e-8e5e-49129fc730f0}
ipsecName = Require Security
description = Accepts unsecured communication, but always requires clients to establish trust and security methods. Will NOT communicate with untrusted clients.
ipsecID = {fc2e4bc5-0fde-462e-8e5e-49129fc730f0}
ipsecDataType = dword: 256
ipsecNegotiationPolicyReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecNegotiationPolicy{7238523f-70fa-11d1-864c-14a300000000}
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecPolicy{72385230-70fa-11d1-864c-14a300000000} (8)
ClassName = ipsecPolicy
description = For all IP traffic, always request security using Kerberos trust. Allow unsecured communication with clients that do not respond to request.
name = ipsecPolicy{72385230-70fa-11d1-864c-14a300000000}
ipsecName = Server (Request Security)
ipsecID = {72385230-70fa-11d1-864c-14a300000000}
ipsecDataType = dword: 256
ipsecISAKMPReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{72385231-70fa-11d1-864c-14a300000000}
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecPolicy{72385236-70fa-11d1-864c-14a300000000} (8)
ClassName = ipsecPolicy
description = Communicate normally (unsecured). Use the default response rule to negotiate with servers that request security. Only the requested protocol and port traffic with that server is secured.
name = ipsecPolicy{72385236-70fa-11d1-864c-14a300000000}
ipsecName = Client (Respond Only)
ipsecID = {72385236-70fa-11d1-864c-14a300000000}
ipsecDataType = dword: 256
ipsecISAKMPReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{72385237-70fa-11d1-864c-14a300000000}
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecPolicy{7238523c-70fa-11d1-864c-14a300000000} (8)
ClassName = ipsecPolicy
description = For all IP traffic, always require security using Kerberos trust. Do NOT allow unsecured communication with untrusted clients.
name = ipsecPolicy{7238523c-70fa-11d1-864c-14a300000000}
ipsecName = Secure Server (Require Security)
ipsecID = {7238523c-70fa-11d1-864c-14a300000000}
ipsecDataType = dword: 256
ipsecISAKMPReference = SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\ipsecISAKMPPolicy{7238523d-70fa-11d1-864c-14a300000000}
whenChanged = dword: 1039388824

- Software\Policies\Microsoft\Windows\RTC\PortRange (1)
Enabled = dword: 0

- Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers (4)
TransparentEnabled = dword: 1
DefaultLevel = dword: 262144
AuthenticodeEnabled = dword: 0
PolicyScope = dword: 0

- Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328} (4)
Description = Stop the download of this file
FriendlyName = Mdac11.cab
SaferFlags = dword: 0
HashAlg = dword: 32771

- Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91} (4)
Description = Stop the download of this file
FriendlyName = mdac20.cab
SaferFlags = dword: 0
HashAlg = dword: 32771

- Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f} (4)
Description = Stop the download of this file
FriendlyName = mdac20_a.cab
SaferFlags = dword: 0
HashAlg = dword: 32771

- Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d} (4)
Description = Stop the download of this file
FriendlyName = _msadc10.cab
SaferFlags = dword: 0
HashAlg = dword: 32771

- Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc} (4)
Description = Stop the download of this file
FriendlyName = msadc11.cab
SaferFlags = dword: 0
HashAlg = dword: 32771

- Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33} (2)
Description =
SaferFlags = dword: 0

* Alternate policies *
- Software\Microsoft\Windows\CurrentVersion\policies\explorer (1)
HonorAutoRunSetting = dword: 1

- Software\Microsoft\Windows\CurrentVersion\policies\NonEnum (3)
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = dword: 1
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} = dword: 1073741857
{0DF44EAA-FF21-4412-828E-260A8728E7F1} = dword: 32

- Software\Microsoft\Windows\CurrentVersion\policies\system (5)
dontdisplaylastusername = dword: 0
legalnoticecaption =
legalnoticetext =
shutdownwithoutlogon = dword: 1
undockwithoutlogon = dword: 1



——————–

Browser Helper Objects (14):

(no name) = {5C255C8A-E604-49b4-9D64-90988571CECB} =
(no name) = {A6ACAE64-F798-4930-AD86-BD3FB32038DB} = G:\Program Files\Video ActiveX Object\isadd.dll
AcroIEHlprObj Class = {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} = G:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
IE to GetRight Helper = {31FF080D-12A3-439A-A2EF-4BA95A3148E8} = G:\Program Files\GetRight\xx2gr.dll
Java™ Plug-In 2 SSV Helper = {DBC80044-A445-435b-BC74-9C25C1C588A9} = G:\Program Files\Java\jre6\bin\jp2ssv.dll
JQSIEStartDetectorImpl = {E7E6F031-17CE-4C07-BC86-EABFE594F69C} = G:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
MSNToolBandBHO = {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} = G:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
Search Helper = {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} = G:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
ST = {9394EDE7-C8B5-483E-8773-474BF36AF6E4} = G:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
UberButton Class = {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} = G:\Program Files\Yahoo!\Common\yiesrvc.dll
Windows Live Sign-in Helper = {9030D464-4C02-4ABF-8ECC-5164760863C6} = G:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
Windows Live Toolbar Helper = {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} = G:\Program Files\Windows Live\Toolbar\wltcore.dll
WormRadar.com IESiteBlocker.NavFilter = {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} = G:\Program Files\AVG\AVG8\avgssie.dll
YahooTaggedBM Class = {65D886A2-7CA7-479B-BB95-14D1EFB7946A} = G:\Program Files\Yahoo!\Common\YIeTagBm.dll

——————–

ActiveX objects (14):

BASEIE40_W2K - {89820200-ECBD-11cf-8B85-00AA005B4383} - G:\WINDOWS\system32\ie4uinit.exe
BRANDING.CAB - {7D4BA2E0-339C-11D3-A3D3-00105A290DEB} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
DOTNETFRAMEWORKS - {89B4C1CD-B018-4511-B0A1-5476DBF70820} - G:\WINDOWS\system32\Rundll32.exe G:\WINDOWS\system32\mscories.dll,Install
IE4Shell_NT - {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
IEACCESS - {26923b43-4d38-484f-9b9e-de460746276c} - G:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigIE
MailNews - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
Messenger - {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection G:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} - rundll32.exe advpack.dll,LaunchINFSection G:\WINDOWS\INF\wmp.inf,PerUserStub
NetMeeting - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection G:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
OEACCESS - {881dd1c5-3dcf-431b-b061-f3f88e8be88a} - G:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE
Theme Component - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - G:\WINDOWS\system32\regsvr32.exe /s /n /i:/UserInstall G:\WINDOWS\system32\themeui.dll
WAB - {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
Windows Marketplace Link - {4b218e3e-bc98-4770-93d3-2731b9329278} - G:\WINDOWS\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 G:\WINDOWS\inf\ie.inf
WMPACCESS - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - G:\WINDOWS\inf\unregmp2.exe /ShowWMP

——————–

Internet Explorer toolbars:

[All users (1)]
0 - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - G:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll

[This user]
* ShellBrowser (4) *
&Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - G:\WINDOWS\System32\browseui.dll
(no name) - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - (no file)
(no name) - {014DA6C9-189F-421A-88CD-07CFE51CFF10} - (no file)
(no name) - {241241DB-B806-40C3-B608-D207CCECC018} - (no file)

* WebBrowser (9) *
&Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - G:\WINDOWS\System32\browseui.dll
&Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - G:\WINDOWS\system32\SHELL32.dll
Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - G:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
(no name) - {241241DB-B806-40C3-B608-D207CCECC018} - (no file)
(no name) - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - (no file)
MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - G:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - G:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
Protection Bar - {84938242-5C5B-4A55-B6B9-A1507543B418} - G:\Program Files\Video ActiveX Object\iesplugin.dll
&Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - G:\Program Files\Windows Live\Toolbar\wltcore.dll


——————–

Internet Explorer buttons/tools (5):

Blog This - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - G:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - G:\Program Files\Yahoo!\Common\yiesrvc.dll
ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - G:\Program Files\ICQLite\ICQLite.exe
Real.com - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - G:\WINDOWS\System32\Shdocvw.dll
Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe

——————–

Internet Explorer menu extensions:

[This user (7)]
&Yahoo! Search - file:///G:\Program Files\Yahoo!\Common/ycsrch.htm
Download with GetRight - G:\Program Files\GetRight\GRdownload.htm
E&xport to Microsoft Excel - res://G:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
Open with GetRight Browser - G:\Program Files\GetRight\GRdownload.htm
Yahoo! &Dictionary - file:///G:\Program Files\Yahoo!\Common/ycdict.htm
Yahoo! &Maps - file:///G:\Program Files\Yahoo!\Common/ycmap.htm
Yahoo! &SMS - file:///G:\Program Files\Yahoo!\Common/ycsms.htm

——————–

Internet Explorer Bands (10):

Search Band - {30D02401-6A81-11d0-8274-00C04FD5AE38} - G:\WINDOWS\System32\browseui.dll
&Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - G:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
&Tip of the Day - {4D5C8C25-D075-11d0-B416-00C04FB90376} - G:\WINDOWS\System32\shdocvw.dll
Protection Bar - {84938242-5C5B-4A55-B6B9-A1507543B418} - G:\Program Files\Video ActiveX Object\iesplugin.dll
&Discuss - {BDEADE7F-C265-11D0-BCED-00A0C90AB50F} - shdocvw.dll
File Search Explorer Band - {C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1} - G:\WINDOWS\system32\SHELL32.dll
Favorites Band - {EFA24E61-B078-11d0-89E4-00C04FC9E26E} - G:\WINDOWS\System32\shdocvw.dll
History Band - {EFA24E62-B078-11d0-89E4-00C04FC9E26E} - G:\WINDOWS\System32\shdocvw.dll
Explorer Band - {EFA24E64-B078-11d0-89E4-00C04FC9E26E} - G:\WINDOWS\System32\shdocvw.dll
Real.com - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - G:\WINDOWS\System32\Shdocvw.dll

——————–

Downloaded Program Files (9):

Microsoft XML Parser for Java - Microsoft XML Parser for Java - (no file) - file://G:\WINDOWS\Java\classes\xmldso.cab
Microsoft Office Template and Media Control - {02BCC737-B171-4746-94C9-0D8A0B2C0089} - G:\WINDOWS\Downloaded Program Files\IEAWSDC.DLL - http://office.microsoft.com/templates/ieawsdc.cab
Shockwave ActiveX Control - {166B1BCA-3F9C-11CF-8075-444553540000} - G:\WINDOWS\system32\Macromed\Director\SwDir.dll - http://download.macromedia.com/pub/shockwa…director/sw.cab
YInstStarter Class - {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - G:\Program Files\Yahoo!\Common\yinsthelper.dll - G:\Program Files\Yahoo!\Common\yinsthelper.dll
Java Runtime Environment 1.6.0 - {8AD9C840-044E-11D1-B3E9-00805F499D93} - G:\Program Files\Java\jre6\bin\jp2iexp.dll - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
(no name) - {9F1C11AA-197B-4942-BA54-47A8489BB47F} - (no file) - http://v4.windowsupdate.microsoft.com/CAB/…7599.4661111111
Java Runtime Environment 1.6.0 - {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - G:\Program Files\Java\jre6\bin\jp2iexp.dll - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
Java Runtime Environment 1.6.0 - {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - G:\Program Files\Java\jre6\bin\npjpi160_14.dll - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
Shockwave Flash Object - {D27CDB6E-AE6D-11CF-96B8-444553540000} - G:\WINDOWS\system32\macromed\flash\Flash.ocx - http://download.macromedia.com/pub/shockwa…ash/swflash.cab

——————–

URL search hooks:

[This user (1)]
Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - G:\WINDOWS\System32\shdocvw.dll

——————–

Explorer clones:

G:\WINDOWS\explorer.exe

——————–

Image File Execution Options (1):

Your Image File Name Here without a path = ntsd -d

——————–

ContextMenuHandlers:

[*]

AVG8 Shell Extension = {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = G:\Program Files\AVG\AVG8\avgse.dll
ICQLiteMenu = {73B24247-042E-4EF5-ADC2-42F62E6FD654} = G:\Program Files\ICQLite\ICQLiteShell.dll
Offline Files = {750fdf0e-2a26-11d1-a3ea-080036587f03} = G:\WINDOWS\System32\cscui.dll
Open With = {09799AFB-AD67-11d1-ABCD-00C04FC30936} = G:\WINDOWS\system32\SHELL32.dll
Open With EncryptionMenu = {A470F8CF-A1E8-4f65-8335-227475AA5C46} = G:\WINDOWS\system32\SHELL32.dll
Start Menu Pin = {a2a9545d-a0c2-42b4-9708-a0b2badd77c8} = G:\WINDOWS\system32\SHELL32.dll
Yahoo! Mail = {5464D816-CF16-4784-B9F3-75C0DB52B499} = G:\PROGRA~1\Yahoo!\Common\ymmapi20041123.dll

[Drive (4)]
Disk Copy Extension = {59099400-57FF-11CE-BD94-0020AF85B590} = diskcopy.dll
Offline Files = {750fdf0e-2a26-11d1-a3ea-080036587f03} = G:\WINDOWS\System32\cscui.dll
Sharing = {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
ShellFolder for CD Burning = {fbeb8a05-beee-4442-804e-409d6c4515e9} = G:\WINDOWS\system32\SHELL32.dll

[Folder (2)]
AVG8 Shell Extension = {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = G:\Program Files\AVG\AVG8\avgse.dll
MBAMShlExt = {57CE581A-0CB6-4266-9CA0-19364C90A0B3} = G:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll

[CompressedFolder (1)]
Compressed (zipped) Folder Context Menu = {b8cdcb65-b1bf-4b42-9428-1dfdb7ee92af} = G:\WINDOWS\System32\zipfldr.dll

[Directory (4)]
EncryptionMenu = {A470F8CF-A1E8-4f65-8335-227475AA5C46} = G:\WINDOWS\system32\SHELL32.dll
ICQLiteMenu = {73B24247-042E-4EF5-ADC2-42F62E6FD654} = G:\Program Files\ICQLite\ICQLiteShell.dll
Offline Files = {750fdf0e-2a26-11d1-a3ea-080036587f03} = G:\WINDOWS\System32\cscui.dll
Sharing = {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll

[Directory\Background (1)]
New = {D969A300-E7FF-11d0-A93B-00A0C90F2719} = G:\WINDOWS\system32\SHELL32.dll

[ChannelShortcut (1)]
Channel Menu Handler Object = {f3da0dc0-9cc8-11d0-a599-00c04fd64437} = G:\WINDOWS\System32\cdfview.dll

[InternetShortcut (1)]
Internet Shortcut = {FBF23B40-E3F0-101B-8488-00AA003E56F8} = shdocvw.dll

[AllFileSystemObjects (2)]
MBAMShlExt = {57CE581A-0CB6-4266-9CA0-19364C90A0B3} = G:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
Send To = {7BA4C740-9E81-11CF-99D3-00AA004AE837} = G:\WINDOWS\system32\SHELL32.dll

——————–

ColumnHandlers (5):

(no name) - {0D2E74C4-3C34-11d2-A27E-00C04FC30871} - G:\WINDOWS\system32\SHELL32.dll
(no name) - {24F14F01-7B1C-11d1-838f-0000F80461CF} - G:\WINDOWS\system32\SHELL32.dll
(no name) - {24F14F02-7B1C-11d1-838f-0000F80461CF} - G:\WINDOWS\system32\SHELL32.dll
(no name) - {66742402-F9B9-11D1-A202-0000F81FEDEE} - G:\WINDOWS\system32\SHELL32.dll
PDF Shell Extension - {F9DB5320-233E-11D1-9F84-707F02C10627} - G:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll

——————–

ShellExecuteHooks (1):

URL Exec Hook = {AEB6717E-7E19-11d0-97EE-00C04FD91972} = shell32.dll

——————–

Approved Shell Extensions:

[All users (195)]
- {00F33137-EE26-412F-8D71-F84E4C2C6625} - G:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
- {06A2568A-CED6-4187-BB20-400B8C02BE5A} -
%DESC_PublishDropTarget% - {60fd46de-f830-4894-a628-6fa81bc0190d} - G:\WINDOWS\System32\photowiz.dll
&Address - {01E04581-4EEE-11d0-BFE9-00AA005B4383} - G:\WINDOWS\System32\browseui.dll
.CAB file viewer - {0CD7A5C0-9F37-11CE-AE65-08002B2E1262} - cabview.dll
Accessible - {7e653215-fa25-46bd-a339-34a2790f3cb7} - G:\WINDOWS\System32\browseui.dll
ActiveX Cache Folder - {88C6C381-2E85-11D0-94DE-444553540000} - G:\WINDOWS\System32\occache.dll
Address Bar Parser - {E0E11A09-5CB8-4B6C-8332-E00720A168F2} - G:\WINDOWS\System32\browseui.dll
Address EditBox - {A08C11D2-A228-11d0-825B-00AA005B4383} - G:\WINDOWS\System32\browseui.dll
Administrative Tools - {D20EA4E1-3957-11d2-A40B-0C5020524153} - G:\WINDOWS\system32\shdocvw.dll
Audio Media Properties Handler - {875CB1A1-0F29-45de-A1AE-CFB4950D0B78} - G:\WINDOWS\System32\shmedia.dll
Augmented Shell Folder - {91EA3F8B-C99B-11d0-9815-00C04FD91972} - G:\WINDOWS\System32\browseui.dll
Augmented Shell Folder 2 - {6413BA2C-B461-11d1-A18A-080036B11A03} - G:\WINDOWS\System32\browseui.dll
Auto Update Property Sheet Extension - {5F327514-6C5E-4d60-8F16-D07FA08A78ED} - G:\WINDOWS\system32\wuaucpl.cpl
AVG8 Find Extension - {9F97547E-460A-42C5-AE0C-81C61FFAEBC3} -
AVG8 Shell Extension - {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} - G:\Program Files\AVG\AVG8\avgse.dll
Avi Properties Handler - {87D62D94-71B3-4b9a-9489-5FE6850DC73E} - G:\WINDOWS\System32\shmedia.dll
BandProxy - {F61FFEC1-754F-11d0-80CA-00AA005B4383} - G:\WINDOWS\System32\browseui.dll
Briefcase - {85BBD920-42A0-1069-A2E4-08002B30309D} - syncui.dll
CDF Extension Copy Hook - {67EA19A0-CCEF-11d0-8024-00C04FD75D13} - G:\WINDOWS\System32\shdocvw.dll
Channel File - {f39a0dc0-9cc8-11d0-a599-00c04fd64433} - G:\WINDOWS\System32\cdfview.dll
Channel Handler Object - {f3ba0dc0-9cc8-11d0-a599-00c04fd64435} - G:\WINDOWS\System32\cdfview.dll
Channel Menu - {f3da0dc0-9cc8-11d0-a599-00c04fd64437} - G:\WINDOWS\System32\cdfview.dll
Channel Properties - {f3ea0dc0-9cc8-11d0-a599-00c04fd64438} - G:\WINDOWS\System32\cdfview.dll
Channel Shortcut - {f3aa0dc0-9cc8-11d0-a599-00c04fd64434} - G:\WINDOWS\System32\cdfview.dll
Code Download Agent - {7D559C10-9FE9-11d0-93F7-00AA0059CE02} - G:\WINDOWS\System32\webcheck.dll
Compatibility Page - {513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8} - SlayerXP.dll
Compressed (zipped) Folder - {E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} - G:\WINDOWS\System32\zipfldr.dll
Compressed (zipped) Folder Right Drag Handler - {BD472F60-27FA-11cf-B8B4-444553540000} - G:\WINDOWS\System32\zipfldr.dll
Compressed (zipped) Folder SendTo Target - {888DCA60-FC0A-11CF-8F0F-00C04FD7D062} - G:\WINDOWS\System32\zipfldr.dll
ConnectionAgent - {E6CC6978-6B6E-11D0-BECA-00C04FD940BE} - G:\WINDOWS\System32\webcheck.dll
Crypto PKO Extension - {7444C717-39BF-11D1-8CD9-00C04FC29D45} - G:\WINDOWS\system32\cryptext.dll
Crypto Sign Extension - {7444C719-39BF-11D1-8CD9-00C04FC29D45} - G:\WINDOWS\system32\cryptext.dll
Custom MRU AutoCompleted List - {6935DB93-21E8-4ccc-BEB9-9FE3C77A297A} - G:\WINDOWS\System32\browseui.dll
Darwin App Publisher - {CFCCC7A0-A282-11D1-9082-006008059382} - G:\WINDOWS\System32\appwiz.cpl
Desktop Explorer - {1CDB2949-8F65-4355-8456-263E7C208A5D} - G:\WINDOWS\System32\nvshell.dll
Desktop Explorer Menu - {1E9B04FB-F9E5-4718-997B-B8DA88302A47} - G:\WINDOWS\System32\nvshell.dll
DfsShell - {ECCDF543-45CC-11CE-B9BF-0080C87CDBA6} - G:\WINDOWS\System32\dfsshlex.dll
Directory Context Menu Verbs - {62AE1F9A-126A-11D0-A14B-0800361B1103} - G:\WINDOWS\System32\dsuiext.dll
Directory Object Find - {163FDC20-2ABC-11d0-88F0-00A024AB2DBB} - G:\WINDOWS\System32\dsquery.dll
Directory Property UI - {0D45D530-764B-11d0-A1CA-00AA00C16E65} - G:\WINDOWS\System32\dsuiext.dll
Directory Query UI - {8A23E65E-31C2-11d0-891C-00A024AB2DBB} - G:\WINDOWS\System32\dsquery.dll
Directory Start/Search Find - {F020E586-5264-11d1-A532-0000F8757D7E} - G:\WINDOWS\System32\dsquery.dll
Disk Copy Extension - {59099400-57FF-11CE-BD94-0020AF85B590} - diskcopy.dll
Disk Quota UI - {7988B573-EC89-11cf-9C00-00AA00A14F56} - dskquoui.dll
Display Adapter CPL Extension - {42071712-76d4-11d1-8b24-00a0c9068ff3} - deskadp.dll
Display Monitor CPL Extension - {42071713-76d4-11d1-8b24-00a0c9068ff3} - deskmon.dll
Display Panning CPL Extension - {42071714-76d4-11d1-8b24-00a0c9068ff3} - deskpan.dll
Display TroubleShoot CPL Extension - {f92e8c40-3d33-11d2-b1aa-080036a75b03} - deskperf.dll
Download Status - {22BF0C20-6DA7-11D0-B373-00A0C9034938} - G:\WINDOWS\System32\browseui.dll
DS Security Page - {4E40F770-369C-11d0-8922-00A024AB2DBB} - dssec.dll
E-mail - {2559a1f5-21d7-11d4-bdaf-00c04f60b9f0} - G:\WINDOWS\system32\shdocvw.dll
Encryption Context Menu - {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} -
Explorer Band - {EFA24E64-B078-11d0-89E4-00C04FC9E26E} - G:\WINDOWS\System32\shdocvw.dll
Extensions Manager Folder - {692F0339-CBAA-47e6-B5B5-3B84DB604E87} - G:\WINDOWS\System32\extmgr.dll
Favorites Band - {EFA24E61-B078-11d0-89E4-00C04FC9E26E} - G:\WINDOWS\System32\shdocvw.dll
Fonts - {BD84B380-8CA2-1069-AB1D-08000948F534} - fontext.dll
Fonts - {D20EA4E1-3957-11d2-A40B-0C5020524152} - G:\WINDOWS\system32\shdocvw.dll
For &People… - {32714800-2E5F-11d0-8B85-00AA0044F941} - G:\Program Files\Outlook Express\wabfind.dll
Free AOL & Unlimited Internet.url - {336B02CE-F88A-4aea-8731-79EF94D3723A} - G:\WINDOWS\aod\aodshext.dll
FTP Folders Webview - {63da6ec0-2e98-11cf-8d82-444553540000} - G:\WINDOWS\System32\msieftp.dll
GDI+ file thumbnail extractor - {3F30C968-480A-4C6C-862D-EFC0897BB84B} - G:\WINDOWS\system32\shimgvw.dll
Get a Passport Wizard - {58f1f272-9240-4f51-b6d4-fd63d1618591} - G:\WINDOWS\System32\netplwiz.dll
Global Folder Settings - {EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} - G:\WINDOWS\System32\browseui.dll
Help and Support - {2559a1f1-21d7-11d4-bdaf-00c04f60b9f0} - G:\WINDOWS\system32\shdocvw.dll
Help and Support - {2559a1f2-21d7-11d4-bdaf-00c04f60b9f0} - G:\WINDOWS\system32\shdocvw.dll
History - {FF393560-C2A7-11CF-BFF4-444553540000} - G:\WINDOWS\System32\shdocvw.dll
HTML Thumbnail Extractor - {EAB841A0-9550-11cf-8C16-00805F1408F3} - G:\WINDOWS\system32\shimgvw.dll
HyperTerminal Icon Ext - {88895560-9AA2-1069-930E-00AA0030EBC8} - G:\WINDOWS\System32\hticons.dll
ICC Profile - {DBCE2480-C732-101B-BE72-BA78E9AD5B27} - G:\WINDOWS\system32\icmui.dll
ICM Monitor Management - {5DB2625A-54DF-11D0-B6C4-0800091AA605} - G:\WINDOWS\System32\icmui.dll
ICM Printer Management - {675F097E-4C4D-11D0-B6C1-0800091AA605} - G:\WINDOWS\system32\icmui.dll
ICM Scanner Management - {176d6597-26d3-11d1-b350-080036a75b03} - icmui.dll
IE4 Suite Splash Screen - {A2B0DD40-CC59-11d0-A3A5-00C04FD706EC} - G:\WINDOWS\System32\shdocvw.dll
In-pane search - {169A0691-8DF9-11d1-A1C4-00C04FD75D13} - G:\WINDOWS\System32\browseui.dll
Installed Apps Enumerator - {0B124F8F-91F0-11D1-B8B5-006008059382} - G:\WINDOWS\System32\appwiz.cpl
Internet - {2559a1f4-21d7-11d4-bdaf-00c04f60b9f0} - G:\WINDOWS\system32\shdocvw.dll
Internet Name Space - {871C5380-42A0-1069-A2EA-08002B30309D} - G:\WINDOWS\System32\shdocvw.dll
InternetShortcut - {FBF23B40-E3F0-101B-8488-00AA003E56F8} - shdocvw.dll
ISFBand OC - {131A6951-7F78-11D0-A979-00C04FD705A2} - G:\WINDOWS\System32\shdocvw.dll
iTunes - {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} - G:\Program Files\iTunes\iTunesMiniPlayer.dll
Media Band - {32683183-48a0-441b-a342-7c2a440a9478} -
Microsoft Agent Character Property Sheet Handler - {143A62C8-C33B-11D1-84FE-00C04FA34A14} - G:\WINDOWS\msagent\agentpsh.dll
Microsoft AutoComplete - {00BB2763-6A77-11D0-A535-00C04FD7D062} - G:\WINDOWS\System32\browseui.dll
Microsoft Browser Architecture - {A5E46E3A-8849-11D1-9D8C-00C04FC99D61} - G:\WINDOWS\System32\shdocvw.dll
Microsoft BrowserBand - {7BA4C742-9E81-11CF-99D3-00AA004AE837} - G:\WINDOWS\System32\browseui.dll
Microsoft Data Link - {2206CDB2-19C1-11D1-89E0-00C04FD7A829} - G:\Program Files\Common Files\System\Ole DB\oledb32.dll
Microsoft DocProp Inplace Calendar Control - {6A205B57-2567-4A2C-B881-F787FAB579A3} - G:\WINDOWS\System32\docprop2.dll
Microsoft DocProp Inplace Droplist Combo Control - {0EEA25CC-4362-4A12-850B-86EE61B0D3EB} - G:\WINDOWS\System32\docprop2.dll
Microsoft DocProp Inplace Edit Box Control - {A9CF0EAE-901A-4739-A481-E35B73E47F6D} - G:\WINDOWS\System32\docprop2.dll
Microsoft DocProp Inplace ML Edit Box Control - {8EE97210-FD1F-4B19-91DA-67914005F020} - G:\WINDOWS\System32\docprop2.dll
Microsoft DocProp Inplace Time Control - {28F8A4AC-BBB3-4D9B-B177-82BFC914FA33} - G:\WINDOWS\System32\docprop2.dll
Microsoft DocProp Shell Ext - {883373C3-BF89-11D1-BE35-080036B11A03} - G:\WINDOWS\System32\docprop2.dll
Microsoft History AutoComplete List - {00BB2764-6A77-11D0-A535-00C04FD7D062} - G:\WINDOWS\System32\browseui.dll
Microsoft Internet Toolbar - {5E6AB780-7743-11CF-A12B-00AA004AE837} - G:\WINDOWS\System32\browseui.dll
Microsoft Multiple AutoComplete List Container - {00BB2765-6A77-11D0-A535-00C04FD7D062} - G:\WINDOWS\System32\browseui.dll
Microsoft Office HTML Icon Handler - {42042206-2D85-11D3-8CFF-005004838597} - G:\Program Files\Microsoft Office\Office10\msohev.dll
Microsoft Outlook Custom Icon Handler - {0006F045-0000-0000-C000-000000000046} - G:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL
Microsoft Shell Folder AutoComplete List - {03C036F1-A186-11D0-824A-00AA005B4383} - G:\WINDOWS\System32\browseui.dll
Microsoft Url History Service - {3C374A40-BAE4-11CF-BF7D-00AA006946EE} - G:\WINDOWS\System32\shdocvw.dll
Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - G:\WINDOWS\System32\shdocvw.dll
Microsoft.XPS.Shell.Metadata.1 - {45670FA8-ED97-4F44-BC93-305082590BFB} - G:\WINDOWS\System32\XPSSHHDR.DLL
Microsoft.XPS.Shell.Thumbnail.1 - {44121072-A222-48f2-A58A-6D9AD51EBBE9} - G:\WINDOWS\System32\XPSSHHDR.DLL
Midi Properties Handler - {A6FD9E45-6E44-43f9-8644-08598F5A74D9} - G:\WINDOWS\System32\shmedia.dll
MMC Icon Handler - {7A80E4A8-8005-11D2-BCF8-00C04F72C717} - G:\WINDOWS\System32\mmcshext.dll
MRU AutoComplete List - {6756A641-DE71-11d0-831B-00AA005B4383} - G:\WINDOWS\System32\browseui.dll
Multimedia File Property Sheet - {00022613-0000-0000-C000-000000000046} - mmsys.cpl
MyDocs Copy Hook - {ECF03A33-103D-11d2-854D-006008059367} - G:\WINDOWS\System32\mydocs.dll
MyDocs Drop Target - {ECF03A32-103D-11d2-854D-006008059367} - G:\WINDOWS\System32\mydocs.dll
MyDocs Properties - {4a7ded0a-ad25-11d0-98a8-0800361b1103} - G:\WINDOWS\System32\mydocs.dll
Network Connections - {7007ACC7-3202-11D1-AAD2-00805FC1270E} - G:\WINDOWS\system32\NETSHELL.dll
Network Connections - {992CFFA0-F557-101A-88EC-00DD010CCC48} - G:\WINDOWS\system32\NETSHELL.dll
NTFS Security Page - {1F2E5C40-9550-11CE-99D2-00AA006E086C} - rshx32.dll
Offline Files Folder - {AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E} - G:\WINDOWS\System32\cscui.dll
Offline Files Folder Options - {10CFC467-4392-11d2-8DB4-00C04FA31A66} - G:\WINDOWS\System32\cscui.dll
Offline Files Menu - {750fdf0e-2a26-11d1-a3ea-080036587f03} - G:\WINDOWS\System32\cscui.dll
OLE Docfile Property Page - {3EA48300-8CF6-101B-84FB-666CCB9BCD32} - docprop.dll
PlusPack CPL Extension - {41E300E0-78B6-11ce-849B-444553540000} - G:\WINDOWS\System32\themeui.dll
PostAgent - {D8BD2030-6FC9-11D0-864F-00AA006809D9} - G:\WINDOWS\System32\webcheck.dll
Previous Versions - {9DB7A13C-F208-4981-8353-73CC61AE2783} - G:\WINDOWS\System32\twext.dll
Previous Versions Property Page - {596AB062-B4D2-4215-9F74-E9109B0A8153} - G:\WINDOWS\System32\twext.dll
Print Ordering via the Web - {add36aa8-751a-4579-a266-d66f5202ccbb} - G:\WINDOWS\System32\netplwiz.dll
Printers Security Page - {F37C5810-4D3F-11d0-B4BF-00AA00BBB723} - rshx32.dll
Registry Tree Options Utility - {AF4F6510-F982-11d0-8595-00AA004CD6D8} - G:\WINDOWS\System32\browseui.dll
Remote Sessions CPL Extension - {F0152790-D56E-4445-850E-4F3117DB740C} - G:\WINDOWS\System32\remotepg.dll
Run… - {2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} - G:\WINDOWS\system32\shdocvw.dll
Scanners & Cameras - {3F953603-1008-4f6e-A73A-04AAC7A992F1} - wiashext.dll
Scanners & Cameras - {83bbcbf3-b28a-4919-a5aa-73027445d672} - wiashext.dll
Scanners & Cameras - {905667aa-acd6-11d2-8080-00805f6596d2} - wiashext.dll
Scanners & Cameras - {E211B736-43FD-11D1-9EFB-0000F8757FCD} - wiashext.dll
Scanners & Cameras - {FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD} - wiashext.dll
Scheduled Tasks - {D6277990-4C6A-11CF-8D87-00AA0060F5BF} - G:\WINDOWS\System32\mstask.dll
Search - {2559a1f0-21d7-11d4-bdaf-00c04f60b9f0} - G:\WINDOWS\system32\shdocvw.dll
Search Assistant OC - {9461b922-3c5a-11d2-bf8b-00c04fb93661} - G:\WINDOWS\System32\shdocvw.dll
Search Band - {30D02401-6A81-11d0-8274-00C04FD5AE38} - G:\WINDOWS\System32\browseui.dll
Sendmail service - {9E56BE60-C50F-11CF-9A2C-00A0C90A90CE} - G:\WINDOWS\System32\sendmail.dll
Sendmail service - {9E56BE61-C50F-11CF-9A2C-00A0C90A90CE} - G:\WINDOWS\System32\sendmail.dll
Set Program Access and Defaults - {2559a1f7-21d7-11d4-bdaf-00c04f60b9f0} - G:\WINDOWS\system32\shdocvw.dll
Shell Application Manager - {352EC2B7-8B9A-11D1-B8AE-006008059382} - G:\WINDOWS\System32\appwiz.cpl
Shell Automation Inproc Service - {0A89A860-D7B1-11CE-8350-444553540000} - G:\WINDOWS\System32\shdocvw.dll
Shell Band Site Menu - {ECD4FC4E-521C-11D0-B792-00A0C90312E1} - G:\WINDOWS\System32\browseui.dll
Shell DeskBar - {ECD4FC4C-521C-11D0-B792-00A0C90312E1} - G:\WINDOWS\System32\browseui.dll
Shell DeskBarApp - {3CCF8A41-5C85-11d0-9796-00AA00B90ADF} - G:\WINDOWS\System32\browseui.dll
Shell DocObject Viewer - {E7E4BC40-E76A-11CE-A9BB-00AA004AE837} - G:\WINDOWS\System32\shdocvw.dll
Shell extensions for file compression - {764BF0E1-F219-11ce-972D-00AA00A14F56} -
Shell extensions for Microsoft Windows Network objects - {59be4990-f85c-11ce-aff7-00aa003ca9f6} - ntlanui2.dll
Shell extensions for sharing - {40dd6e20-7c17-11ce-a804-00aa003ca9f6} - ntshrui.dll
Shell extensions for sharing - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} - ntshrui.dll
Shell extensions for Windows Script Host - {60254CA5-953B-11CF-8C96-00AA00B8708C} - G:\WINDOWS\System32\wshext.dll
Shell Icon Handler for Application References - {E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} - G:\WINDOWS\system32\dfshim.dll
Shell Image Data Factory - {66e4e4fb-f385-4dd0-8d74-a2efd1bc6178} - G:\WINDOWS\system32\shimgvw.dll
Shell Image Property Handler - {eb9b1153-3b57-4e68-959a-a3266bc3d7fe} - G:\WINDOWS\system32\shimgvw.dll
Shell Image Verbs - {e84fda7c-1d6a-45f6-b725-cb260c236066} - G:\WINDOWS\system32\shimgvw.dll
Shell properties for a DS object - {9E51E0D0-6E0F-11d2-9601-00C04FA31A86} - G:\WINDOWS\System32\dsquery.dll
Shell Publishing Wizard Object - {6b33163c-76a5-4b6c-bf21-45de9cd503a1} - G:\WINDOWS\System32\netplwiz.dll
Shell Rebar BandSite - {ECD4FC4D-521C-11D0-B792-00A0C90312E1} - G:\WINDOWS\System32\browseui.dll
Shell Scrap DataHandler - {56117100-C0CD-101B-81E2-00AA004AE837} - shscrap.dll
Shell Search Band - {21569614-B795-46b1-85F4-E737A8DC09AD} - G:\WINDOWS\system32\browseui.dll
ShellLink for Application References - {e82a2d71-5b2f-43a0-97b8-81be15854de8} - G:\WINDOWS\system32\dfshim.dll
Subscription Folder - {F5175861-2688-11d0-9C5E-00AA00A45957} - G:\WINDOWS\System32\webcheck.dll
Subscription Mgr - {ABBE31D0-6DAE-11D0-BECA-00C04FD940BE} - G:\WINDOWS\System32\webcheck.dll
Summary Info Thumbnail handler (DOCFILES) - {9DBD2C50-62AD-11d0-B806-00C04FD706EC} - G:\WINDOWS\system32\shimgvw.dll
Taskbar and Start Menu - {0DF44EAA-FF21-4412-828E-260A8728E7F1} -
Tasks Folder Icon Handler - {DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF} - G:\WINDOWS\System32\mstask.dll
Tasks Folder Shell Extension - {797F1E90-9EDD-11cf-8D8E-00AA0060F5BF} - G:\WINDOWS\System32\mstask.dll
Temporary Internet Files - {7BD29E00-76C1-11CF-9DD0-00A0C9034933} - G:\WINDOWS\System32\shdocvw.dll
Temporary Internet Files - {7BD29E01-76C1-11CF-9DD0-00A0C9034933} - G:\WINDOWS\System32\shdocvw.dll
The Internet - {3DC7A020-0ACD-11CF-A9BB-00AA004AE837} - G:\WINDOWS\System32\shdocvw.dll
Track Popup Bar - {acf35015-526e-4230-9596-becbe19f0ac9} - G:\WINDOWS\System32\browseui.dll
TrayAgent - {E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7} - G:\WINDOWS\System32\webcheck.dll
TridentImageExtractor - {7376D660-C583-11d0-A3A5-00C04FD706EC} - G:\WINDOWS\System32\browseui.dll
User Accounts - {7A9D77BD-5403-11d2-8785-2E0420524153} -
User Assist - {DD313E04-FEFF-11d1-8ECD-0000F87A470C} - G:\WINDOWS\System32\browseui.dll
Video Media Properties Handler - {40C3D757-D6E4-4b49-BB41-0E5BBEA28817} - G:\WINDOWS\System32\shmedia.dll
Video Thumbnail Extractor - {c5a40261-cd64-4ccf-84cb-c394da41d590} - G:\WINDOWS\System32\shmedia.dll
Wav Properties Handler - {E4B29F9D-D390-480b-92FD-7DDB47101D71} - G:\WINDOWS\System32\shmedia.dll
Web Folders - {BDEADF00-C265-11D0-BCED-00A0C90AB50F} - G:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
Web Printer Shell Extension - {77597368-7b15-11d0-a0c2-080036af3f03} - printui.dll
Web Publishing Wizard - {CC6EEFFB-43F6-46c5-9619-51D571967F7D} - G:\WINDOWS\System32\netplwiz.dll
Web Search - {07798131-AF23-11d1-9111-00A0C98BA67D} - G:\WINDOWS\System32\browseui.dll
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - G:\WINDOWS\System32\webcheck.dll
WebCheck SyncMgr Handler - {7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB} - G:\WINDOWS\System32\webcheck.dll
WebCheckChannelAgent - {E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB} - G:\WINDOWS\System32\webcheck.dll
WebCheckWebCrawler - {08165EA0-E946-11CF-9C87-00AA005127ED} - G:\WINDOWS\System32\webcheck.dll
Windows Live Photo Gallery Autoplay Drop Target - {2BE99FD4-A181-4996-BFA9-58C5FFD11F6C} -
Windows Live Photo Gallery Autoplay Drop Target Shim - {00F30F90-3E96-453B-AFCD-D71989ECC2C7} - G:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
Windows Live Photo Gallery Editor Drop Target - {00F374B7-B390-4884-B372-2FC349F2172B} -
Windows Live Photo Gallery Editor Drop Target Shim - {00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} - G:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
Windows Live Photo Gallery Viewer Drop Target - {00F30F64-AC33-42F5-8FD1-5DC2D3FDE06C} -
Windows Live Photo Gallery Viewer Drop Target Shim - {00F346CB-35A4-465B-8B8F-65A29DBAB1F6} - G:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll
Windows Media Player Add to Playlist Context Menu Handler - {F1B9284F-E9DC-4e68-9D7E-42362A59F0FD} - G:\WINDOWS\system32\wmpshell.dll
Windows Media Player Burn Audio CD Context Menu Handler - {CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C} - G:\WINDOWS\system32\wmpshell.dll
Windows Media Player Play as Playlist Context Menu Handler - {8DD448E6-C188-4aed-AF92-44956194EB1F} - G:\WINDOWS\system32\wmpshell.dll
WLMD Message Handler - {0563DB41-F538-4B37-A92D-4659049B7766} - G:\Program Files\Windows Live\Mail\mailcomm.dll
Yahoo! Mail - {5464D816-CF16-4784-B9F3-75C0DB52B499} - G:\PROGRA~1\Yahoo!\Common\ymmapi20041123.dll

——————–

Registry 'Run' keys:

[User Run]
Aim6 =
AROReminder = G:\Program Files\Advanced Registry Optimizer\ARO.exe -rem
ctfmon.exe = G:\WINDOWS\system32\ctfmon.exe
MSMSGS = "G:\Program Files\Messenger\msmsgs.exe" /background
MsnMsgr = "G:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
Weather = G:\Program Files\AWS\WeatherBug\Weather.exe 1
WeatherCast = G:\PROGRA~1\WEATHE~1\Weather.exe /q
Yahoo! Pager = G:\Program Files\Yahoo!\Messenger\ypager.exe -quiet

[User RunOnce]
ICQ Lite = G:\Program Files\ICQLite\ICQLite.exe -trayboot

[System Run]
AltnetPointsManager = c:\program files\altnet\points manager\points manager.exe -s
AVG8_TRAY = G:\PROGRA~1\AVG\AVG8\avgtray.exe
DownloadWare = "G:\Program Files\DownloadWare\dw.exe" /H
DownloadWare Engine = "G:\Program Files\DownloadWare Engine\DWE.EXE" /H
Hotbar = G:\Program Files\Hotbar\bin\4.4.5.0\HbInst.exe /Upgrade
HP Software Update = G:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
HPDJ Taskbar Utility = G:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
HPHmon04 = G:\WINDOWS\System32\hphmon04.exe
HPHUPD04 = "G:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
ICQ Lite = G:\Program Files\ICQLite\ICQLite.exe -minimize
iTunesHelper = "G:\Program Files\iTunes\iTunesHelper.exe"
KAZAA = G:\Program Files\Kazaa\kazaa.exe /SYSTRAY
Microsoft Works Update Detection = G:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
NeroFilterCheck = G:\WINDOWS\system32\NeroCheck.exe
New.net Startup = rundll32 G:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
NvCplDaemon = RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
P2P Networking = G:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
P2P Networking2 = G:\WINDOWS\System32\P2P Networking\P2P Networking2.exe /AUTOSTART
QuickTime Task = "G:\Program Files\QuickTime\qttask.exe" -atboottime
RealTray = G:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
SBHC = G:\Program Files\SuperBar\sbhc.exe
SearchEnhancement = "G:\Program Files\scbar\v1\scbar.exe" /U
Share-to-Web Namespace Daemon = G:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
SunJavaUpdateSched = "G:\Program Files\Java\jre6\bin\jusched.exe"
wcmdmgr = G:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
WeatherOnTray = G:\Program Files\Hotbar\bin\4.4.5.0\WeatherOnTray.exe

——————–

Protocols:

[Pluggable MIME filters (8)]
application/octet-stream = {1E66F26B-79EE-11D2-8710-00C04F79ED0D} = mscoree.dll
application/x-complus = {1E66F26B-79EE-11D2-8710-00C04F79ED0D} = mscoree.dll
application/x-msdownload = {1E66F26B-79EE-11D2-8710-00C04F79ED0D} = mscoree.dll
Class Install Handler = {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} = G:\WINDOWS\system32\urlmon.dll
deflate = {8f6b0360-b80d-11d0-a9b3-006097942311} = G:\WINDOWS\system32\urlmon.dll
gzip = {8f6b0360-b80d-11d0-a9b3-006097942311} = G:\WINDOWS\system32\urlmon.dll
lzdhtml = {8f6b0360-b80d-11d0-a9b3-006097942311} = G:\WINDOWS\system32\urlmon.dll
text/webviewhtml = {733AC4CB-F1A4-11d0-B951-00A0C90312E1} = G:\WINDOWS\system32\SHELL32.dll

[Protocol handlers (28)]
about = {3050F406-98B5-11CF-BB82-00AA00BDCE0B} = G:\WINDOWS\System32\mshtml.dll
cdl = {3dd53d40-7b8b-11D0-b013-00aa0059ce02} = G:\WINDOWS\system32\urlmon.dll
cdo = {CD00020A-8B95-11D1-82DB-00C04FB1625D} = G:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
dvd = {12D51199-0DB5-46FE-A120-47A3D7D937CC} = G:\WINDOWS\system32\msvidctl.dll
file = {79eac9e7-baf9-11ce-8c82-00aa004ba90b} = G:\WINDOWS\system32\urlmon.dll
ftp = {79eac9e3-baf9-11ce-8c82-00aa004ba90b} = G:\WINDOWS\system32\urlmon.dll
gopher = {79eac9e4-baf9-11ce-8c82-00aa004ba90b} = G:\WINDOWS\system32\urlmon.dll
http = {79eac9e2-baf9-11ce-8c82-00aa004ba90b} = G:\WINDOWS\system32\urlmon.dll
https = {79eac9e5-baf9-11ce-8c82-00aa004ba90b} = G:\WINDOWS\system32\urlmon.dll
its = {9D148291-B9C8-11D0-A4CC-0000F80149F6} = G:\WINDOWS\System32\itss.dll
javascript = {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} = G:\WINDOWS\System32\mshtml.dll
lid = {5C135180-9973-46D9-ABF4-148267CBB8BF} = G:\WINDOWS\System32\msvidctl.dll
linkscanner = {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} = G:\Program Files\AVG\AVG8\avgpp.dll
livecall = {828030A1-22C1-4009-854F-8E305202313F} = G:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
local = {79eac9e7-baf9-11ce-8c82-00aa004ba90b} = G:\WINDOWS\system32\urlmon.dll
mailto = {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} = G:\WINDOWS\System32\mshtml.dll
mhtml = {05300401-BCBC-11d0-85E3-00C04FD85AB4} = G:\WINDOWS\System32\inetcomm.dll
mk = {79eac9e6-baf9-11ce-8c82-00aa004ba90b} = G:\WINDOWS\system32\urlmon.dll
ms-its = {9D148291-B9C8-11D0-A4CC-0000F80149F6} = G:\WINDOWS\System32\itss.dll
ms-itss = {0A9007C0-4076-11D3-8789-0000F8105754} = G:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
msnim = {828030A1-22C1-4009-854F-8E305202313F} = G:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
mso-offdap = {3D9F03FA-7A94-11D3-BE81-0050048385D1} = G:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
res = {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} = G:\WINDOWS\System32\mshtml.dll
sysimage = {76E67A63-06E9-11D2-A840-006008059382} = G:\WINDOWS\System32\mshtml.dll
tv = {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} = G:\WINDOWS\system32\msvidctl.dll
vbscript = {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} = G:\WINDOWS\System32\mshtml.dll
wia = {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} = G:\WINDOWS\System32\wiascr.dll
wlmailhtml = {03C514A3-1EFB-4856-9F99-10D7BE1653C0} = G:\Program Files\Windows Live\Mail\mailcomm.dll

——————–

WOW compatibility:

cmdline = G:\WINDOWS\system32\ntvdm.exe
wowcmdline = G:\WINDOWS\system32\ntvdm.exe -a G:\WINDOWS\system32\krnl386

[KnownDlls (16-bit) (40)]
avicap.dll
avifile.dll
comm.drv
commdlg.dll
compobj.dll
ctl3dv2.dll
ddeml.dll
keyboard.drv
lanman.drv
mapi.dll
mciavi.drv
mciseq.drv
mciwave.drv
mmsystem.dll
mouse.drv
msacm.dll
msvideo.dll
netapi.dll
ole2.dll
ole2disp.dll
ole2nls.dll
olecli.dll
olesvr.dll
pmspl.dll
progman.exe
rasapi16.dll
shell.dll
sound.drv
storage.dll
system.drv
timer.drv
toolhelp.dll
typelib.dll
vga.drv
wfwnet.drv
win87em.dll
winoldap.mod
winsock.dll
winspool.exe
wowdeb.exe

[KnownDlls (32-bit) (20)]
advapi32.dll
comdlg32.dll
gdi32.dll
imagehlp.dll
kernel32.dll
lz32.dll
ole32.dll
oleaut32.dll
olecli32.dll
olecnv32.dll
olesvr32.dll
olethk32.dll
rpcrt4.dll
shell32.dll
url.dll
urlmon.dll
user32.dll
version.dll
wininet.dll
wldap32.dll

——————–

ShellServiceObjectDelayLoad:

[All users (4)]
CDBurn = {fbeb8a05-beee-4442-804e-409d6c4515e9} = G:\WINDOWS\system32\SHELL32.dll
PostBootReminder = {7849596a-48ea-486e-8937-a2a3009f31a9} = G:\WINDOWS\system32\SHELL32.dll
SysTray = {35CEC8A3-2BE6-11D2-8773-92E220524153} = G:\WINDOWS\System32\stobject.dll
WebCheck = {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = G:\WINDOWS\System32\webcheck.dll

——————–

SharedTaskScheduler (2):

Browseui preloader = {438755C2-A8BA-11D1-B96B-00A0C90312E1} = G:\WINDOWS\System32\browseui.dll
Component Categories cache daemon = {8C7461EF-2B13-11d2-BE35-3078302C2030} = G:\WINDOWS\System32\browseui.dll

——————–

Winsock LSP:

[Protocols (16)]
MSAFD Tcpip [TCP/IP] - {E70F1AA0-AB8B-11CF-8CA3-00805F48A192} - G:\WINDOWS\system32\mswsock.dll
MSAFD Tcpip [UDP/IP] - {E70F1AA0-AB8B-11CF-8CA3-00805F48A192} - G:\WINDOWS\system32\mswsock.dll
RSVP UDP Service Provider - {9D60A9E0-337A-11D0-BD88-0000C082E69A} - G:\WINDOWS\system32\rsvpsp.dll
RSVP TCP Service Provider - {9D60A9E0-337A-11D0-BD88-0000C082E69A} - G:\WINDOWS\system32\rsvpsp.dll
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7F02BD30-CA4C-4EC7-B69E-A2E9967591CC}] SEQPACKET 0 - {8D5F1830-C273-11CF-95C8-00805F48A192} - G:\WINDOWS\system32\mswsock.dll
MSAFD NetBIOS [\Device\NetBT_Tcpip_{7F02BD30-CA4C-4EC7-B69E-A2E9967591CC}] DATAGRAM 0 - {8D5F1830-C273-11CF-95C8-00805F48A192} - G:\WINDOWS\system32\mswsock.dll
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E586C51C-BB5B-4619-BED3-F76DD9B8F87D}] SEQPACKET 1 - {8D5F1830-C273-11CF-95C8-00805F48A192} - G:\WINDOWS\system32\mswsock.dll
MSAFD NetBIOS [\Device\NetBT_Tcpip_{E586C51C-BB5B-4619-BED3-F76DD9B8F87D}] DATAGRAM 1 - {8D5F1830-C273-11CF-95C8-00805F48A192} - G:\WINDOWS\system32\mswsock.dll
MSAFD NetBIOS [\Device\NetBT_Tcpip_{1B3D9C66-CD3D-42F7-BC54-4343DF81E018}] SEQPACKET 2 - {8D5F1830-C273-11CF-95C8-00805F48A192} - G:\WINDOWS\system32\mswsock.dll
MSAFD NetBIOS [\Device\NetBT_Tcpip_{1B3D9C66-CD3D-42F7-BC54-4343DF81E018}] DATAGRAM 2 - {8D5F1830-C273-11CF-95C8-00805F48A192} - G:\WINDOWS\system32\mswsock.dll
MSAFD NetBIOS [\Device\NetBT_Tcpip_{21AA0696-2981-463E-B869-78C42CE2478B}] SEQPACKET 3 - {8D5F1830-C273-11CF-95C8-00805F48A192} - G:\WINDOWS\system32\mswsock.dll
MSAFD NetBIOS [\Device\NetBT_Tcpip_{21AA0696-2981-463E-B869-78C42CE2478B}] DATAGRAM 3 - {8D5F1830-C273-11CF-95C8-00805F48A192} - G:\WINDOWS\system32\mswsock.dll
MSAFD NetBIOS [\Device\NetBT_Tcpip_{77E77EC8-A26B-4EDE-81E8-D10A9A93C46E}] SEQPACKET 4 - {8D5F1830-C273-11CF-95C8-00805F48A192} - G:\WINDOWS\system32\mswsock.dll
MSAFD NetBIOS [\Device\NetBT_Tcpip_{77E77EC8-A26B-4EDE-81E8-D10A9A93C46E}] DATAGRAM 4 - {8D5F1830-C273-11CF-95C8-00805F48A192} - G:\WINDOWS\system32\mswsock.dll
MSAFD NetBIOS [\Device\NetBT_Tcpip_{834E90FA-F60A-4D80-A495-EA091A51B150}] SEQPACKET 5 - {8D5F1830-C273-11CF-95C8-00805F48A192} - G:\WINDOWS\system32\mswsock.dll
MSAFD NetBIOS [\Device\NetBT_Tcpip_{834E90FA-F60A-4D80-A495-EA091A51B150}] DATAGRAM 5 - {8D5F1830-C273-11CF-95C8-00805F48A192} - G:\WINDOWS\system32\mswsock.dll

[Namespace Providers (4)]
Tcpip - {22059D40-7E9E-11CF-AE5A-00AA00A7112B} - G:\WINDOWS\System32\mswsock.dll
NTDS - {3B2637EE-E580-11CF-A555-00C04FD8D4AC} - G:\WINDOWS\System32\winrnr.dll
Network Location Awareness (NLA) Namespace - {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83} - G:\WINDOWS\System32\mswsock.dll
mdnsNSP - {B600E6E9-553B-4A19-8696-335E5C896153} - G:\Program Files\Bonjour\mdnsNSP.dll

——————–

Hijack points:

[Reset web settings URLs]
SearchAssistant =
CustomizeSearch =
START_PAGE_URL =
SEARCH_PAGE_URL =
MS_START_PAGE_URL =

[Internet Explorer URLs]
* This user *
- Internet Explorer\Main (3)
Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
Start Page = http://www.google.com/

- Internet Explorer\Search (1)
SearchAssistant = http://ie.search.msn.com/en-us/srchasst/srchasst.htm

- Internet Explorer\SearchURL (1)
(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com

- Internet Explorer\Desktop\General (2)
BackupWallpaper = %USERPROFILE%\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
Wallpaper = %USERPROFILE%\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

* All users *
- Internet Explorer\Main (6)
Default_Page_Url = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
Default_Search_Url = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
Local Page = %SystemRoot%\system32\blank.htm
Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
Start Page = http://www.yahoo.com/

- Internet Explorer\Search (2)
CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

- Internet Explorer\AboutURLs (6)
blank = res://mshtml.dll/blank.htm
DesktopItemNavigationFailure = res://shdoclc.dll/navcancl.htm
NavigationCanceled = res://shdoclc.dll/navcancl.htm
NavigationFailure = res://shdoclc.dll/navcancl.htm
OfflineInformation = res://shdoclc.dll/offcancl.htm
PostNotCached = res://mshtml.dll/repost.htm



[Default URL prefixes]
default = http://
ftp = ftp://
gopher = gopher://
home = http://
mosaic = http://
www = http://

[Hosts file location]
DatabasePath = G:\WINDOWS\System32\drivers\etc\hosts

——————–

Protection & disabled items:

[Hosts file (1)]
* 127.0.0.1 *
localhost


[ActiveX killbits (252)]
&Address - {01E04581-4EEE-11d0-BFE9-00AA005B4383} - G:\WINDOWS\System32\browseui.dll
(no name) - {0006f02a-0000-0000-c000-000000000046} - G:\PROGRA~1\MI1933~1\Office10\OUTLLIB.DLL
(no name) - {083863F1-70DE-11d0-BD40-00A0C911CE86} - G:\WINDOWS\System32\devenum.dll
(no name) - {111C85E9-BB62-4528-A806-F0BE908E02F0} - G:\Program Files\MSN Messenger\msgsc.dll
(no name) - {25B0F91C-D23D-11D0-9B85-00C04FC2F51D} - G:\WINDOWS\System32\danim.dll
(no name) - {283807B5-2C60-11D0-A31D-00AA00B92C03} - G:\WINDOWS\System32\danim.dll
(no name) - {283807b8-2c60-11d0-a31d-00aa00b92c03} - G:\WINDOWS\System32\danim.dll
(no name) - {323C0F99-820A-4e0b-B714-57942C6D9678} - G:\PROGRA~1\WINDOW~4\MESSEN~1\MSGSC1~1.DLL
(no name) - {50B4791F-4731-11D0-8912-00C04FC2A0CA} - G:\WINDOWS\System32\danim.dll
(no name) - {542FB453-5003-11CF-92A2-00AA00B8A733} - G:\WINDOWS\System32\danim.dll
(no name) - {5DFB2651-9668-11D0-B17B-00C04FC2A0CA} - G:\WINDOWS\System32\danim.dll
(no name) - {6FBF8DD5-9E03-4af5-B779-FEBEF6754712} - G:\PROGRA~1\WINDOW~4\MESSEN~1\MSGSC1~1.DLL
(no name) - {98cb4060-d3e7-42a1-8d65-949d34ebfe14} - G:\Program Files\Microsoft Office\Office10\SOA.DLL
(no name) - {9CDE7341-3C20-11D0-A330-00AA00B92C03} - G:\WINDOWS\System32\danim.dll
(no name) - {AF868304-AB0B-11D0-876A-00C04FC29D46} - G:\WINDOWS\System32\danim.dll
(no name) - {b4b3aecb-dfd6-11d1-9daa-00805f85cfe3} - G:\WINDOWS\system32\CLBCatQ.DLL
(no name) - {C46C1BC1-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BC4-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BC6-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BC8-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BCA-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BCC-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BCE-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BD0-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BD2-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BD4-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BD6-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BD8-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BDA-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BDC-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BDE-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BE0-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BE2-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BE4-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BE6-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BEC-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BEE-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BF0-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BF2-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {C46C1BF4-3C52-11D0-9200-848C1D000000} - G:\WINDOWS\System32\danim.dll
(no name) - {D17506C3-6B26-11D0-8914-00C04FC2A0CA} - G:\WINDOWS\System32\danim.dll
(no name) - {e846f0a0-d367-11d1-8286-00a0c9231c29} - G:\WINDOWS\System32\clbcatex.dll
(no name) - {F4C30BB5-D7FC-4d60-9D49-7C6B67C3592D} - G:\PROGRA~1\WINDOW~4\MESSEN~1\MSGSC1~1.DLL
(no name) - {f5078f26-c551-11d3-89b9-0000f81fe221} - G:\WINDOWS\System32\msxml2.dll
(no name) - {F5F545A6-39C4-40b5-814D-B45040A89FB5} - G:\PROGRA~1\WINDOW~4\MESSEN~1\MSGSC1~1.DLL
(no name) - {F81CD990-910B-4bbf-9CB3-6A77F3D697B3} - G:\PROGRA~1\WINDOW~4\MESSEN~1\MSGSC1~1.DLL
9x8Resize - {BC0D69A8-0923-4EEE-9375-9239F5A38B92} - G:\Program Files\Movie Maker\wmm2filt.dll
ACM Class Manager - {33d9a761-90c8-11d0-bd43-00a0c911ce86} - G:\WINDOWS\System32\devenum.dll
ADODB.Stream - {00000566-0000-0010-8000-00AA006D2EA4} - G:\Program Files\Common Files\System\ado\msado15.dll
AEPlugIn Class - {E8C31D11-6FD2-4659-AD75-155FA143F42B} - G:\Program Files\Movie Maker\wmm2ae.dll
Allocator Fix - {C0D076C5-E4C6-4561-8BF4-80DA8DB819D7} - G:\Program Files\Movie Maker\wmm2filt.dll
AsyncMHandler Class - {3DA2AA3E-3D96-11D2-9BD2-204C4F4F5020} - G:\WINDOWS\System32\msdxm.ocx
Bitmap - {4F3E50BD-A9D7-4721-B0E1-00CB42A0A747} - G:\Program Files\Movie Maker\wmm2filt.dll
Bln Proxy - {bc5f1e51-5110-11d1-aff5-006097c9a284} - G:\PROGRA~1\MI1933~1\Office10\BLNMGRPS.DLL
BlnMgr Class - {3f8a6c33-e0fd-11d0-8a8c-00a0c90c2bc5} - G:\Program Files\Microsoft Office\Office10\BLNMGR.DLL
BlnMgr Proxy - {F27CE930-4CA3-11D1-AFF2-006097C9A284} - G:\PROGRA~1\MI1933~1\Office10\BLNMGRPS.DLL
Briefcase - {85bbd920-42a0-1069-a2e4-08002b30309d} - syncui.dll
CEnroll Class - {43F8F289-7A20-11D0-8F06-00C04FC295E1} - G:\WINDOWS\system32\xenroll.dll
Certificate Class - {E38FD381-6404-4041-B5E9-B2739258941F} - G:\Program Files\Microsoft CAPICOM 2.1.0.2\Lib\X86\capicom.dll
Certificates Class - {17E3A1C3-EA8A-4970-AF29-7F54610B1D4C} - G:\Program Files\Microsoft CAPICOM 2.1.0.2\Lib\X86\capicom.dll
Certificates Class - {FBAB033B-CDD0-4C5E-81AB-AEA575CD1338} - G:\Program Files\Microsoft CAPICOM 2.1.0.2\Lib\X86\capicom.dll
cfw Class - {ECABAFC0-7F19-11D2-978E-0000F8757E2A} - G:\WINDOWS\system32\comsvcs.dll
Chain Class - {65104D73-BA60-4160-A95A-4B4782E7AA62} - G:\Program Files\Microsoft CAPICOM 2.1.0.2\Lib\X86\capicom.dll
CLSID_ApprenticeICW - {8ee42293-c315-11d0-8d6f-00a0c9a06e1f} - G:\WINDOWS\System32\inetcfg.dll
CLSID_CCommAcctImport - {1aa06ba1-0e88-11d1-8391-00c04fbd7c09} - G:\WINDOWS\System32\msoeacct.dll
CLSID_CDIDeviceActionConfigPage - {18ab439e-fcf4-40d4-90da-f79baa3b0655} - G:\WINDOWS\System32\diactfrm.dll
CommunicationManager - {67dcc487-aa48-11d1-8f4f-00c04fb611c7} - G:\WINDOWS\System32\msdtctm.dll
DirectControl Class - {39A2C2A6-4778-11D2-9BDB-204C4F4F5020} - G:\WINDOWS\System32\msdxm.ocx
DirectX Transform Wrapper Property Page - {1B544C24-FD0B-11CE-8C63-00AA0044B520} - G:\Program Files\Movie Maker\wmm2filt.dll
DiskManagement.Connection - {fd78d554-4c6e-11d0-970d-00a0c9191601} - G:\WINDOWS\System32\dmdskmgr.dll
Dutch_Dutch Stemmer - {860d28d0-8bf4-11ce-be59-00aa0051fe20} - infosoft.dll
English_UK Stemmer - {d99f7670-7f1a-11ce-be57-00aa0051fe20} - infosoft.dll
English_US Stemmer - {eeed4c20-7f1b-11ce-be57-00aa0051fe20} - infosoft.dll
Frame Eater - {6C68955E-F965-4249-8E18-F0977B1D2899} - G:\Program Files\Movie Maker\wmm2filt.dll
Free Threaded XML DOM Document 2.6 - {f5078f1c-c551-11d3-89b9-0000f81fe221} - G:\WINDOWS\System32\msxml2.dll
French_French Stemmer - {2a6eb050-7f1c-11ce-be57-00aa0051fe20} - infosoft.dll
FTP Folder Web View Automation - {210DA8A2-7445-11D1-91F7-006097DF5BD4} - G:\WINDOWS\System32\msieftp.dll
German_German Stemmer - {510a4910-7f1c-11ce-be57-00aa0051fe20} - infosoft.dll
H323MSP Class - {0F1BE7F8-45CA-11D2-831F-00A0244D2298} - G:\WINDOWS\System32\h323msp.dll
Helper Object for Java - {8e26bfc1-afd6-11cf-bffc-00aa003cfdfc} - G:\WINDOWS\System32\vmhelper.dll
HHCtrl Object - {41B23C28-488E-4E5C-ACE2-BB0BBABE99E8} - G:\WINDOWS\system32\hhctrl.ocx
HHCtrl Object - {ADB880A6-D8FF-11CF-9377-00AA003B7A11} - G:\WINDOWS\System32\hhctrl.ocx
HPDevice Class - {60178279-6D62-43AF-A336-77925651A4C6} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPDeviceUtil Class - {DC4F9DA0-DB05-4BB0-8FB2-03A80FE98772} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPFileUtil Class - {CDAF9CEC-F3EC-4B22-ABA3-9726713560F8} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPIniFileUtil Class - {93441C07-E57E-4086-B912-F323D741A9D8} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPLogicalDriveInfo Class - {17E67D4A-23A1-40D8-A049-EE34C0AF756A} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPOperatingSystem Class - {784F2933-6BDD-4E5F-B1BA-A8D99B603649} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPPDriverRead Class - {4774922A-8983-4ECC-94FD-7235F06F53A1} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPPDriversCollection Class - {DE233AFF-8BD5-457E-B7F0-702DBEA5A828} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPPJobRead Class - {E12DA4F2-BDFB-4EAD-B12F-2725251FA6B0} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPPJobsCollection Class - {B9C13CD0-5A97-4C6B-8A50-7638020E2462} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPPMonitorRead Class - {C94188F6-0F9F-46B3-8B78-D71907BD8B77} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPPMonitorsCollection Class - {AB049B11-607B-46C8-BBF7-F4D6AF301046} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPPPortRead Class - {6470DE80-1635-4B5D-93A3-3701CE148A79} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPPPortsCollection Class - {910E7ADE-7F75-402D-A4A6-BB1A82362FCA} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPPProcessorsCollection Class - {42C68651-1700-4750-A81F-A1F5110E0F66} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPPrinterRead Class - {BF931895-AF82-467A-8819-917C6EE2D1F3} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPPrintersCollection Class - {C70D0641-DDE1-4FD7-A4D4-DA187B80741D} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPRegUtil Class - {0C378864-D5C4-4D9C-854C-432E3BEC9CCB} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPSpoolerEnum Class - {CF6866F9-B67C-4B24-9957-F91E91E788DC} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPSpoolerRead Class - {A95845D8-8463-4605-B5FB-4F8CFBAC5C47} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HPSystemBoardInfo Class - {AB237044-8A3B-42BB-9EE1-9BFA6721D9ED} - G:\Program Files\Hewlett-Packard\eSupportDiags\HPeDiag.dll
HTML Inline Movie Control - {8422DAE7-9929-11CF-B8D3-004033373DA8} - G:\Program Files\Microsoft Office\Office10\HTML\HTMLMM.OCX
HTML Inline Sound Control - {8422DAE3-9929-11CF-B8D3-004033373DA8} - G:\Program Files\Microsoft Office\Office10\HTML\HTMLMM.OCX
IAVIStream & IAVIFile Proxy - {0002000D-0000-0000-C000-000000000046} - avifil32.dll
ICM Class Manager - {33d9a760-90c8-11d0-bd43-00a0c911ce86} - G:\WINDOWS\System32\devenum.dll
IndexServer Simple Command Creator - {c7b6c04a-cbb5-11d0-bb4c-00c04fc2f410} - G:\WINDOWS\system32\query.dll
InstallEngineCtl Object - {6E449683-C509-11CF-AAFA-00AA00B6015C} - G:\WINDOWS\System32\asctrls.ocx
IPConfMSP Class - {0F1BE7F7-45CA-11D2-831F-00A0244D2298} - G:\WINDOWS\System32\confmsp.dll
Italian_Italian Stemmer - {6d36ce10-7f1c-11ce-be57-00aa0051fe20} - infosoft.dll
JVIEW Profiler - {03D9F3F2-B0E3-11D2-B081-006008039BF0} - G:\WINDOWS\System32\javaprxy.dll
LexRefBilingualTextContext Class - {75C11604-5C51-48B2-B786-DF5E51D10EC9} - G:\Program Files\Common Files\Microsoft Shared\Translat\FREN\MSB1FREN.DLL
LexRefStEsObject Class - {4CFB5280-800B-4367-848F-5A13EBF27F1D} - G:\Program Files\Common Files\Microsoft Shared\Translat\ESEN\MSB1ESEN.DLL
LexRefStFrObject Class - {B3E0E785-BD78-4366-9560-B7DABE2723BE} - G:\Program Files\Common Files\Microsoft Shared\Translat\FREN\MSB1FREN.DLL
LM Auto Effect Behaivor - {BB339A46-7C49-11d2-9BF3-00C04FA34789} - G:\WINDOWS\System32\lmrt.dll
LM Behavior Factory - {B1549E58-3894-11D2-BB7F-00A0C999C4C1} - G:\WINDOWS\System32\lmrt.dll
LM Runtime Control - {183C259A-0480-11d1-87EA-00C04FC29D46} - G:\WINDOWS\System32\lmrt.dll
Log Sink Class - {DE4735F3-7532-4895-93DC-9A10C4257173} - G:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCORE.DLL
Marquee Control - {250770f3-6af2-11cf-a915-008029e31fcd} - G:\Program Files\Microsoft Office\Office10\HTML\HTMLMARQ.OCX
MarshalableTI Class - {466d66fa-9616-11d2-9342-0000f875ae17} - G:\WINDOWS\System32\msconf.dll
mbcontent Class - {52ca3bcf-3b9b-419e-a3d6-5d28c0b0b50c} - G:\WINDOWS\System32\browsewm.dll
Media Streaming Dynamic Terminal - {AED6483F-3304-11D2-86F1-006008B0E5D2} - G:\WINDOWS\System32\termmgr.dll
MessageMover Class - {ecabb0bf-7f19-11d2-978e-0000f8757e2a} - G:\WINDOWS\system32\comsvcs.dll
Microsoft Agent Control 1.5 - {F5BE8BD2-7DE6-11D0-91FE-00C04FD701A5} - G:\WINDOWS\msagent\agentctl.dll
Microsoft Common Browser Architecture - {AF604EFE-8897-11D1-B944-00A0C90312E1} - G:\WINDOWS\System32\browseui.dll
Microsoft DDS Generic Class - {4faab301-cef6-477c-9f58-f601039e9b78} - G:\Program Files\Common Files\Microsoft Shared\MSDesigners7\msdds.dll
Microsoft DDS Library Shape Control - {ec444cb6-3e7e-4865-b1c3-0de72ef39b3f} - G:\Program Files\Common Files\Microsoft Shared\MSDesigners7\msdds.dll
Microsoft DDS Picture Shape Control - {6cbe0382-a879-4d2a-8ec3-1f2a43611ba8} - G:\Program Files\Common Files\Microsoft Shared\MSDesigners7\msdds.dll
Microsoft DirectAnimation Control - {B6FFC24C-7E13-11D0-9B47-00C04FC2F51D} - G:\WINDOWS\System32\danim.dll
Microsoft DirectAnimation Path - {D7A7D7C3-D47F-11D0-89D3-00A0C90833E6} - G:\WINDOWS\System32\daxctle.ocx
Microsoft DirectAnimation Sequence - {4F241DB1-EE9F-11D0-9824-006097C99E51} - G:\WINDOWS\System32\daxctle.ocx
Microsoft DirectAnimation Sequencer - {B0A6BAE2-AAF0-11D0-A152-00A0C908DB96} - G:\WINDOWS\System32\daxctle.ocx
Microsoft DirectAnimation Sprite - {FD179533-D86E-11D0-89D6-00A0C90833E6} - G:\WINDOWS\System32\daxctle.ocx
Microsoft DirectAnimation Structured Graphics - {369303C2-D7AC-11D0-89D5-00A0C90833E6} - G:\WINDOWS\System32\daxctle.ocx
Microsoft DirectAnimation Windowed Control - {69AD90EF-1C20-11d1-8801-00C04FC29D46} - G:\WINDOWS\System32\danim.dll
Microsoft DocHost User Interface Handler - {7057e952-bd1b-11d1-8919-00c04fc2c836} - G:\WINDOWS\System32\shdocvw.dll
Microsoft HTA Document 6.0 - {3050F5C8-98B5-11CF-BB82-00AA00BDCE0B} - G:\WINDOWS\System32\mshtml.dll
Microsoft Html Document for Popup Window - {3050F67D-98B5-11CF-BB82-00AA00BDCE0B} - G:\WINDOWS\System32\mshtml.dll
Microsoft Html Popup Window - {3050f667-98b5-11cf-bb82-00aa00bdce0b} - G:\WINDOWS\System32\mshtml.dll
Microsoft HTML Window Security Proxy - {3050F391-98B5-11CF-BB82-00AA00BDCE0B} - G:\WINDOWS\System32\mshtml.dll
Microsoft Index Server Scope Administration Object - {3bc4f3a7-652a-11d1-b4d4-00c04fc2db8d} - G:\WINDOWS\system32\ciodm.dll
Microsoft Movie Maker Age Filter - {ADEADEB8-E54B-11D1-9A72-0000F875EADE} - G:\Program Files\Movie Maker\wmm2fxa.dll
Microsoft MovieMaker Fade In Fade Out - {EC85D8F1-1C4E-46E4-A748-7AA04E7C0496} - G:\Program Files\Movie Maker\wmm2fxa.dll
Microsoft MPEG-4 Video Decompressor Property page - {598eba02-b49a-11d2-a1c1-00609778ea66} - G:\WINDOWS\System32\mpg4ds32.ax
Microsoft MS Audio Decompressor Control Property page - {8FE7E181-BB96-11D2-A1CB-00609778EA66} - G:\WINDOWS\System32\msadds32.ax
Microsoft NetShow Player - {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - G:\WINDOWS\system32\wmpdxm.dll
Microsoft Office Chart 9.0 - {0002E500-0000-0000-C000-000000000046} - G:\PROGRA~1\MI1933~1\Office10\MSOWC.DLL
Microsoft Office Data Source Control 9.0 - {0002E530-0000-0000-C000-000000000046} - G:\PROGRA~1\MI1933~1\Office10\MSOWC.DLL
Microsoft Office Free/Busy Registration - {f28d867a-ddb1-11d3-b8e8-00a0c981aeeb} - G:\PROGRA~1\MI1933~1\Office10\MSOSVFBR.DLL
Microsoft Office PivotTable 9.0 - {0002E520-0000-0000-C000-000000000046} - G:\PROGRA~1\MI1933~1\Office10\MSOWC.DLL
Microsoft Office Spreadsheet 9.0 - {0002E510-0000-0000-C000-000000000046} - G:\PROGRA~1\MI1933~1\Office10\MSOWC.DLL
Microsoft Visual Database Tools Database Designer V7.0 - {03cb9467-fd9d-42a8-82f9-8615b4223e6e} - G:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\vdt70.dll
Microsoft Visual Database Tools Query Designer V7.0 - {2c10a98f-d64f-43b4-bed6-dd0e1bf2074c} - G:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\vdt70.dll
Microsoft WBEM Event Subsystem - {5d08b586-343a-11d0-ad46-00c04fd8fdff} - G:\WINDOWS\System32\wbem\wbemess.dll
MidiOut Class Manager - {4efe2452-168a-11d1-bc76-00c04fb9453b} - G:\WINDOWS\System32\devenum.dll
MMStream Class - {49C47CE5-9BA4-11D0-8212-00C04FC32C45} - G:\WINDOWS\System32\amstream.dll
Movie Maker Special Effect 1 Input - {B4DC8DD9-2CC1-4081-9B2B-20D7030234EF} - G:\Program Files\Movie Maker\wmm2fxa.dll
Movie Maker Special Effect 2 Inputs - {C63344D8-70D3-4032-9B32-7A3CAD5091A5} - G:\Program Files\Movie Maker\wmm2fxa.dll
Movie Maker Special Effect Inplace 1 Input - {353359C1-39E1-491b-9951-464FD8AB071C} - G:\Program Files\Movie Maker\wmm2fxa.dll
Movie Maker Video Adjustments - {5A20FD6F-F8FE-4A22-9EE7-307D72D09E6E} - G:\Program Files\Movie Maker\wmm2fxa.dll
MSP Class - {4DDB6D36-3BC1-11D2-86F2-006008B0E5D2} - G:\WINDOWS\System32\wavemsp.dll
MSVDTDDGridCtrl7 Object - {6f9f3481-84dd-4b14-b09c-6b4288eccde8} - G:\Program Files\Common Files\Microsoft Shared\Visual Database Tools\vdt70.dll
MTSEvents Class - {ECABB0AB-7F19-11D2-978E-0000F8757E2A} - G:\WINDOWS\system32\comsvcs.dll
Multimedia File Property Sheet - {00022613-0000-0000-c000-000000000046} - mmsys.cpl
NDFXArtEffects - {E673DCF2-C316-4C6F-AA96-4E4DC6DC291E} - G:\Program Files\Movie Maker\wmm2fxb.dll
Network Connections - {7007acc7-3202-11d1-aad2-00805fc1270e} - G:\WINDOWS\system32\NETSHELL.dll
Network Connections - {992cffa0-f557-101a-88ec-00dd010ccc48} - G:\WINDOWS\system32\NETSHELL.dll
Network Connections Tray - {7007ACCF-3202-11D1-AAD2-00805FC1270E} - G:\WINDOWS\system32\NETSHELL.dll
OpenCable Class - {ABBA001B-3075-11D6-88A4-00B0D0200F88} - G:\WINDOWS\system32\psisdecd.dll
Outlook Express Address Book - {233A9694-667E-11D1-9DFB-006097D50408} - %ProgramFiles%\Outlook Express\msoe.dll
Outlook Progress Ctl - {0006F071-0000-0000-C000-000000000046} - G:\PROGRA~1\MI1933~1\Office10\OUTLLIB.DLL
PostBootReminder object - {7849596a-48ea-486e-8937-a2a3009f31a9} - G:\WINDOWS\system32\SHELL32.dll
PSDispatch - {00020420-0000-0000-c000-000000000046} - oleaut32.dll
PSEnumVariant - {00020421-0000-0000-C000-000000000046} - oleaut32.dll
PSOAInterface - {00020424-0000-0000-c000-000000000046} - oleaut32.dll
PSSupportErrorInfo - {DF0B3D60-548F-101B-8E65-08002B2BD119} - oleaut32.dll
PSTypeComp - {00020425-0000-0000-C000-000000000046} - oleaut32.dll
PSTypeInfo - {00020422-0000-0000-C000-000000000046} - oleaut32.dll
PSTypeLib - {00020423-0000-0000-C000-000000000046} - oleaut32.dll
Queued Components Recorder - {ecabafc2-7f19-11d2-978e-0000f8757e2a} - G:\WINDOWS\system32\comsvcs.dll
Record Queue - {5B4B05EB-1F63-446B-AAD1-E10A34D650E0} - G:\Program Files\Movie Maker\wmm2filt.dll
Redirect - {42B07B28-2280-4937-B035-0293FB812781} - G:\WINDOWS\System32\dxtmsft.dll
RegWizCtrl - {50E5E3D1-C07E-11D0-B9FD-00A0249F6B00} - G:\WINDOWS\System32\regwizc.dll
SafeWia Class - {0DAD5531-BF31-43AC-A513-1F8926BBF5EC} - G:\WINDOWS\System32\wiascr.dll
Script Encoder Object - {32DA2B15-CFED-11D1-B747-00C04FC2B085} - G:\WINDOWS\System32\scrrun.dll
SdpConferenceBlob Class - {9B2719DD-B696-11D0-A489-00C04FD91AC0} - G:\WINDOWS\System32\sdpblb.dll
Search Assistant Control - {47c6c527-6204-4f91-849d-66e234dee015} - g:\windows\srchasst\srchui.dll
ShellFolder for CD Burning - {fbeb8a05-beee-4442-804e-409d6c4515e9} - G:\WINDOWS\system32\SHELL32.dll
Shortcut - {00021401-0000-0000-C000-000000000046} - shell32.dll
ShotDetect - {CFFB1FC7-270D-4986-B299-FECF3F0E42DB} - G:\Program Files\Movie Maker\wmm2filt.dll
Snapshot Viewer Control 10.0 - {F0E42D60-368C-11D0-AD81-00A0C90DC8D9} - G:\Program Files\Common Files\Microsoft Shared\Snapshot Viewer\SNAPVIEW.OCX
Snapshot Viewer General Property Page Object - {F2175210-368C-11D0-AD81-00A0C90DC8D9} - G:\Program Files\Common Files\Microsoft Shared\Snapshot Viewer\SNAPVIEW.OCX
Spanish_Modern Stemmer - {b0516ff0-7f1c-11ce-be57-00aa0051fe20} - infosoft.dll
SpSharedRecoContext Class - {47206204-5ECA-11D2-960F-00C04F8EE628} - G:\Program Files\Common Files\Microsoft Shared\Speech\sapi.dll
SpSharedRecognizer Class - {3BEE4890-4FE9-4A37-8C1E-5E7E12791C1F} - G:\Program Files\Common Files\Microsoft Shared\Speech\sapi.dll
Start Menu - {4622ad11-ff23-11d0-8d34-00a0c90f2719} - G:\WINDOWS\system32\SHELL32.dll
Stetch - {F44BB2D0-F070-463E-9433-B0CCF3CFD627} - G:\Program Files\Movie Maker\wmm2filt.dll
Store Class - {78E61E52-0E57-4456-A2F2-517492BCBF8F} - G:\Program Files\Microsoft CAPICOM 2.1.0.2\Lib\X86\capicom.dll
Swedish_Default Stemmer - {9478f640-7f1c-11ce-be57-00aa0051fe20} - infosoft.dll
System Monitor Source Properties - {0CF32AA1-7571-11D0-93C4-00AA00A3DDEA} - G:\WINDOWS\System32\sysmon.ocx
SysTray - {35cec8a3-2be6-11d2-8773-92e220524153} - G:\WINDOWS\System32\stobject.dll
SysTrayInvoker - {730f6cdc-2c86-11d2-8773-92e220524153} - G:\WINDOWS\System32\stobject.dll
TipGW Init - {F117831B-C052-11d1-B1C0-00C04FC2F3EF} - G:\WINDOWS\System32\msdtctm.dll
Trident HTMLEditor - {3050F4F5-98B5-11CF-BB82-00AA00BDCE0B} - G:\WINDOWS\System32\mshtmled.dll
VFW Capture Class Manager - {860bb310-5d01-11d0-bd3b-00a0c911ce86} - G:\WINDOWS\System32\devenum.dll
Video Effect (1 input) Class Manager - {cc7bfb42-f175-11d1-a392-00e0291f3959} - G:\WINDOWS\System32\qedit.dll
Video Effect (2 input) Class Manager - {cc7bfb43-f175-11d1-a392-00e0291f3959} - G:\WINDOWS\System32\qedit.dll
Video Mixing Renderer 9 - {51B4ABF3-748F-4E3B-A276-C828330E926A} - G:\WINDOWS\system32\quartz.dll
Video Render Dynamic Terminal - {AED6483E-3304-11D2-86F1-006008B0E5D2} - G:\WINDOWS\System32\termmgr.dll
VideoPort Object - {ce292861-fc88-11d0-9e69-00c04fd7c15b} - G:\WINDOWS\System32\qdvd.dll
VMR Allocator Presenter 9 - {2D2E24CB-0CD5-458F-86EA-3E6FA22C8E64} - G:\WINDOWS\system32\quartz.dll
VMR ImageSync 9 - {E4979309-7A32-495E-8A92-7B014AAD4961} - G:\WINDOWS\system32\quartz.dll
WaveIn Class Manager - {33D9A762-90C8-11d0-BD43-00A0C911CE86} - G:\WINDOWS\System32\devenum.dll
WaveOut and DSound Class Manager - {e0f158e1-cb04-11d0-bd4e-00a0c911ce86} - G:\WINDOWS\System32\devenum.dll
Wbem Scripting Object Path - {172BDDF8-CEEA-11D1-8B05-00600806D9B6} - G:\WINDOWS\System32\wbem\wbemdisp.dll
WDM Instance Provider - {d2d588b5-d081-11d0-99e0-00c04fc2f8ec} - G:\WINDOWS\System32\wbem\wmiprov.dll
WIA FileSystem USD - {d2923b86-15f1-46ff-a19a-de825f919576} - G:\WINDOWS\System32\fsusd.dll
WIA Video Preview Class - {457A23DF-6F2A-4684-91D0-317FB768D87C} - G:\WINDOWS\System32\camocx.dll
Windows Media Video Decompressor Property page - {9AADA567-04E0-11D4-9148-00C04F610D24} - G:\WINDOWS\System32\wmv8ds32.ax
WM Color Converter Filter - {CC45B0B0-72D8-4652-AE5F-5E3E266BE7ED} - G:\Program Files\Movie Maker\wmm2filt.dll
WM TV Out Smooth Picture Filter - {41D2B841-7692-4C83-AFD3-F60E845341AF} - G:\Program Files\Movie Maker\wmm2filt.dll
WM VIH2 Fix - {586FB486-5560-4FF3-96DF-1118C96AF456} - G:\Program Files\Movie Maker\wmm2filt.dll
WMI ADSI Extension - {f0975afe-5c7f-11d2-8b74-00104b2afb41} - G:\WINDOWS\System32\wbem\wbemads.dll
WMT Audio Analyzer - {1CB1623E-BBEC-4E8D-B2DF-DC08C6F4627C} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT Black Frame Generator - {2EA10031-0033-450E-8072-E27D9E768142} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT DeInterlace Filter - {C8F209F8-480E-454C-94A4-5392D88EBA0F} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT DeInterlace Prop Page - {A2EDA89A-0966-4B91-9C18-AB69F098187F} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT DirectX Transform Wrapper - {AECF5D2E-7A18-4DD2-BDCD-29B6F615B448} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT DV Extract Filter - {E476CBFF-E229-4524-B6B7-228A3129D1C7} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT FormatConversion - {2D20D4BB-B47E-4FB7-83BD-E3C2EE250D26} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT FormatConversion Prop Page - {E188F7A3-A04E-413E-99D1-D79A45F70305} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT Import Filter - {4D4C9FEF-ED80-47EA-A3FA-3215FDBB33AB} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT Interlacer - {C6CB1FE3-B05E-4F0E-818F-C83ED5A0332F} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT Log Filter - {92883667-E95C-443D-AC96-4CACA27BEB6E} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT MuxDeMux Filter - {01002B17-5D93-4551-81E4-831FEF780A53} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT Sample Info Filter - {7F1232EE-44D7-4494-AB8B-CC61B10E21A5} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT Screen capture Filter - {31087270-d348-432c-899e-2d2f38ff29a0} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT Screen Capture Filter Task Page - {679E132F-561B-42F8-846C-A70DBDC62999} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT Switch Filter - {EF105BC3-C064-45F1-AD53-6D8A8578D01B} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT Virtual Renderer - {930FD02C-BBE7-4EB9-91CF-FC45CC91E3E6} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT Virtual Source - {C44C65C7-FDF1-453D-89A5-BCC28F5D69F9} - G:\Program Files\Movie Maker\wmm2filt.dll
WMT Volume - {EFEE43D6-BFE5-44B0-8063-AC3B2966AB2C} - G:\Program Files\Movie Maker\wmm2filt.dll
XML Data Source Object 2.6 - {f5078f1f-c551-11d3-89b9-0000f81fe221} - G:\WINDOWS\System32\msxml2.dll
XML Document 2.6 - {f5078f22-c551-11d3-89b9-0000f81fe221} - G:\WINDOWS\System32\msxml2.dll
XML Document 2.6 - {f5078f28-c551-11d3-89b9-0000f81fe221} - G:\WINDOWS\System32\msxml2.dll
XML DOM Document 2.6 - {f5078f1b-c551-11d3-89b9-0000f81fe221} - G:\WINDOWS\System32\msxml2.dll
XML HTTP 2.6 - {f5078f1e-c551-11d3-89b9-0000f81fe221} - G:\WINDOWS\System32\msxml2.dll
XML Moniker 2.6 - {f5078f29-c551-11d3-89b9-0000f81fe221} - G:\WINDOWS\System32\msxml2.dll
XML Parser 2.6 - {f5078f20-c551-11d3-89b9-0000f81fe221} - G:\WINDOWS\System32\msxml2.dll
XML Schema Cache 2.6 - {f5078f1d-c551-11d3-89b9-0000f81fe221} - G:\WINDOWS\System32\msxml2.dll
XSL Template 2.6 - {f5078f21-c551-11d3-89b9-0000f81fe221} - G:\WINDOWS\System32\msxml2.dll

[Zones]
* This user *
- Restricted sites (69)
194.187.*.*
195.225.*.*
195.95.*.*
205.177.*.*
205.188.*.*
216.195.*.*
216.239.*.*
66.230.*.*
66.235.*.*
69.31.*.*
69.50.*.*
70.84.*.*
81.9.3.*
81.95.*.*
82.179.*.*
85.255.*.*
accessvid.net
adultan.com
adultfilmsite.com
adultmovieplus.com
adultsper.com
adultzoneworld.com
clubxxxvideo.com
contentlocker.net
cutadult.com
dontgetporn.com
dvdaccess.net
dvds-access.com
funxxxporn.com
galleryclick.net
gallerypictures.net
greatadultvideo.com
hardcorevideosite.com
ispfiltersporn.com
loweradult.com
mega-adult.com
MovieCodec.net
moviesdvds.net
playcodecs.com
playercodec.net
playerscodec.com
playhardmovie.com
playxvideo.com
playxxxvideo.net
pornissex.com
pornxxxfilm.com
site-entrance.net
siteentrances.com
sitesentrance.com
sites-entrance.com
sites-entrance.net
siteticket.net
site-ticket.net
stephieporn.com
superadultfriend.com
superporncity.com
sureadult.com
theadulteye.com
Tvcodec.com
vidaccess.net
videosaccess.net
vids-access.com
Watchfree.net
worldbestadult.com
xxxallvideo.com
xxxmovietour.com
xxxteenfilm.com
xxxzonevideo.com
zcodec.com



[Stopped/disabled NT Services]
* Stopped (44) *
.NET Runtime Optimization Service v2.0.50727_X86 = G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
Application Layer Gateway Service = G:\WINDOWS\System32\alg.exe
Application Management = G:\WINDOWS\system32\svchost.exe -k netsvcs
ASP.NET State Service = G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
Automatic Updates = G:\WINDOWS\system32\svchost.exe -k netsvcs
COM+ Event System = G:\WINDOWS\System32\svchost.exe -k netsvcs
COM+ System Application = G:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Distributed Transaction Coordinator = G:\WINDOWS\System32\msdtc.exe
Fast User Switching Compatibility = G:\WINDOWS\System32\svchost.exe -k netsvcs
HTTP SSL = G:\WINDOWS\System32\svchost.exe -k HTTPFilter
IMAPI CD-Burning COM Service = G:\WINDOWS\System32\imapi.exe
Indexing Service = G:\WINDOWS\System32\cisvc.exe
InstallDriver Table Manager = "G:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"
iPod Service = "G:\Program Files\iPod\bin\iPodService.exe"
Logical Disk Manager Administrative Service = G:\WINDOWS\System32\dmadmin.exe /com
MS Software Shadow Copy Provider = G:\WINDOWS\System32\dllhost.exe /Processid:{36F352CA-F501-4CD8-BAFD-799A08CC6147}
Net Logon = G:\WINDOWS\System32\lsass.exe
NetMeeting Remote Desktop Sharing = G:\WINDOWS\System32\mnmsrvc.exe
Network Connections = G:\WINDOWS\System32\svchost.exe -k netsvcs
Network Location Awareness (NLA) = G:\WINDOWS\System32\svchost.exe -k netsvcs
Network Provisioning Service = G:\WINDOWS\System32\svchost.exe -k netsvcs
NT LM Security Support Provider = G:\WINDOWS\System32\lsass.exe
Performance Logs and Alerts = G:\WINDOWS\system32\smlogsvc.exe
Pml Driver HPH11 = G:\WINDOWS\System32\HPHipm11.exe
Portable Media Serial Number Service = G:\WINDOWS\System32\svchost.exe -k netsvcs
QoS RSVP = G:\WINDOWS\System32\rsvp.exe
Remote Access Auto Connection Manager = G:\WINDOWS\System32\svchost.exe -k netsvcs
Remote Access Connection Manager = G:\WINDOWS\System32\svchost.exe -k netsvcs
Remote Desktop Help Session Manager = G:\WINDOWS\system32\sessmgr.exe
Remote Procedure Call (RPC) Locator = G:\WINDOWS\System32\locator.exe
Removable Storage = G:\WINDOWS\system32\svchost.exe -k netsvcs
Smart Card = G:\WINDOWS\System32\SCardSvr.exe
SSDP Discovery Service = G:\WINDOWS\System32\svchost.exe -k LocalService
Telephony = G:\WINDOWS\System32\svchost.exe -k netsvcs
Telnet = G:\WINDOWS\System32\tlntsvr.exe
Terminal Services = G:\WINDOWS\System32\svchost -k DComLaunch
Uninterruptible Power Supply = G:\WINDOWS\System32\ups.exe
Universal Plug and Play Device Host = G:\WINDOWS\System32\svchost.exe -k LocalService
Volume Shadow Copy = G:\WINDOWS\System32\vssvc.exe
Windows CardSpace = "G:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
Windows Installer = G:\WINDOWS\system32\msiexec.exe /V
Windows Management Instrumentation Driver Extensions = G:\WINDOWS\System32\svchost.exe -k netsvcs
Windows Presentation Foundation Font Cache 3.0.0.0 = G:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
WMI Performance Adapter = G:\WINDOWS\System32\wbem\wmiapsrv.exe

* Stopped & disabled (8) *
Alerter = G:\WINDOWS\System32\svchost.exe -k LocalService
AVG8 WatchDog = G:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
ClipBook = G:\WINDOWS\system32\clipsrv.exe
Messenger = G:\WINDOWS\System32\svchost.exe -k netsvcs
Net.Tcp Port Sharing Service = "G:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"
Network DDE = G:\WINDOWS\system32\netdde.exe
Network DDE DSDM = G:\WINDOWS\system32\netdde.exe
Routing and Remote Access = G:\WINDOWS\System32\svchost.exe -k netsvcs


[Windows XP Security]
* Security Center *
- This user
FirstRun = dword: 1

- All users
AntiVirusDisableNotify = dword: 0
FirewallDisableNotify = dword: 0
UpdatesDisableNotify = dword: 0
AntiVirusOverride = dword: 0
FirewallOverride = dword: 0

* System Restore *
- All users
DisableSR = dword: 0
CreateFirstRunRp = dword: 1
DSMin = dword: 200
DSMax = dword: 400
RPSessionInterval = dword: 0
RPGlobalInterval = dword: 86400
RPLifeInterval = dword: 7776000
CompressionBurst = dword: 60
TimerInterval = dword: 120
DiskPercent = dword: 12
ThawInterval = dword: 900
RestoreDiskSpaceError = dword: 0



==================================================
= Other users on this computer: Default user =
==================================================
——————–

Autostart folders:

[Startup]
desktop.ini
PowerReg SchedulerV2.exe

[User Startup]
desktop.ini

——————–

IniMapping values:

User screensaver = logon.scr

——————–

Policies:

[Alternate policies]
* Software\Microsoft\Windows\CurrentVersion\policies\Explorer (1) *
NoDriveTypeAutoRun = dword: 145


——————–

Protection & disabled items:

[Zones]
* Restricted sites (16) *
194.187.*.*
195.225.*.*
195.95.*.*
205.177.*.*
205.188.*.*
216.195.*.*
216.239.*.*
66.230.*.*
66.235.*.*
69.31.*.*
69.50.*.*
70.84.*.*
81.9.3.*
81.95.*.*
82.179.*.*
85.255.*.*



==================================================
= Other users on this computer: LOCAL SERVICE =
==================================================
——————–

Autostart folders:

[User Startup]
desktop.ini

——————–

IniMapping values:

User screensaver = G:\WINDOWS\System32\logon.scr

——————–

Policies:

[Alternate policies]
* Software\Microsoft\Windows\CurrentVersion\policies\Explorer (1) *
NoDriveTypeAutoRun = dword: 145


——————–

Protection & disabled items:

[Zones]
* Restricted sites (16) *
194.187.*.*
195.225.*.*
195.95.*.*
205.177.*.*
205.188.*.*
216.195.*.*
216.239.*.*
66.230.*.*
66.235.*.*
69.31.*.*
69.50.*.*
70.84.*.*
81.9.3.*
81.95.*.*
82.179.*.*
85.255.*.*



==================================================
= Other users on this computer: NETWORK SERVICE =
==================================================
——————–

Autostart folders:

[User Startup]
desktop.ini

——————–

IniMapping values:

User screensaver = G:\WINDOWS\System32\logon.scr

——————–

Policies:

[Alternate policies]
* Software\Microsoft\Windows\CurrentVersion\policies\Explorer (1) *
NoDriveTypeAutoRun = dword: 145


——————–

Protection & disabled items:

[Zones]
* Restricted sites (16) *
194.187.*.*
195.225.*.*
195.95.*.*
205.177.*.*
205.188.*.*
216.195.*.*
216.239.*.*
66.230.*.*
66.235.*.*
69.31.*.*
69.50.*.*
70.84.*.*
81.9.3.*
81.95.*.*
82.179.*.*
85.255.*.*



==================================================
= Other users on this computer: SYSTEM =
==================================================
——————–

Autostart folders:

[Startup]
desktop.ini
PowerReg SchedulerV2.exe

[User Startup]
desktop.ini

——————–

IniMapping values:

User screensaver = logon.scr

——————–

Policies:

[Alternate policies]
* Software\Microsoft\Windows\CurrentVersion\policies\Explorer (1) *
NoDriveTypeAutoRun = dword: 145


——————–

Protection & disabled items:

[Zones]
* Restricted sites (16) *
194.187.*.*
195.225.*.*
195.95.*.*
205.177.*.*
205.188.*.*
216.195.*.*
216.239.*.*
66.230.*.*
66.235.*.*
69.31.*.*
69.50.*.*
70.84.*.*
81.9.3.*
81.95.*.*
82.179.*.*
85.255.*.*



==================================================
= Other hardware configurations: Last known good =
==================================================
——————–

On-reboot actions:

BootExecute = autocheck autochk *

——————–

Services:

[NT Services (43)]
Apple Mobile Device = "G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"
Background Intelligent Transfer Service = G:\WINDOWS\System32\svchost.exe -k netsvcs
Bonjour Service = "G:\Program Files\Bonjour\mDNSResponder.exe"
Computer Browser = G:\WINDOWS\System32\svchost.exe -k netsvcs
Cryptographic Services = G:\WINDOWS\system32\svchost.exe -k netsvcs
DCOM Server Process Launcher = G:\WINDOWS\system32\svchost -k DcomLaunch
DHCP Client = G:\WINDOWS\System32\svchost.exe -k netsvcs
Distributed Link Tracking Client = G:\WINDOWS\system32\svchost.exe -k netsvcs
DNS Client = G:\WINDOWS\System32\svchost.exe -k NetworkService
Error Reporting Service = G:\WINDOWS\System32\svchost.exe -k netsvcs
Event Log = G:\WINDOWS\system32\services.exe
Help and Support = G:\WINDOWS\System32\svchost.exe -k netsvcs
HID Input Service = G:\WINDOWS\System32\svchost.exe -k netsvcs
IPSEC Services = G:\WINDOWS\System32\lsass.exe
Java Quick Starter = "G:\Program Files\Java\jre6\bin\jqs.exe" -service -config "G:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
Logical Disk Manager = G:\WINDOWS\System32\svchost.exe -k netsvcs
Machine Debug Manager = "G:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"
Plug and Play = G:\WINDOWS\system32\services.exe
Pml Driver HPZ12 = G:\WINDOWS\system32\HPZipm12.exe
Print Spooler = G:\WINDOWS\system32\spoolsv.exe
Protected Storage = G:\WINDOWS\system32\lsass.exe
Remote Procedure Call (RPC) = G:\WINDOWS\system32\svchost -k rpcss
Remote Registry = G:\WINDOWS\system32\svchost.exe -k LocalService
SeaPort = "G:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
Secondary Logon = G:\WINDOWS\System32\svchost.exe -k netsvcs
Security Accounts Manager = G:\WINDOWS\system32\lsass.exe
Security Center = G:\WINDOWS\System32\svchost.exe -k netsvcs
Server = G:\WINDOWS\System32\svchost.exe -k netsvcs
Shell Hardware Detection = G:\WINDOWS\System32\svchost.exe -k netsvcs
System Event Notification = G:\WINDOWS\system32\svchost.exe -k netsvcs
System Restore Service = G:\WINDOWS\System32\svchost.exe -k netsvcs
Task Scheduler = G:\WINDOWS\System32\svchost.exe -k netsvcs
TCP/IP NetBIOS Helper = G:\WINDOWS\System32\svchost.exe -k LocalService
Themes = G:\WINDOWS\System32\svchost.exe -k netsvcs
Viewpoint Manager Service = "G:\Program Files\Viewpoint\Common\ViewpointService.exe"
WebClient = G:\WINDOWS\System32\svchost.exe -k LocalService
Windows Audio = G:\WINDOWS\System32\svchost.exe -k netsvcs
Windows Firewall/Internet Connection Sharing (ICS) = G:\WINDOWS\System32\svchost.exe -k netsvcs
Windows Image Acquisition (WIA) = G:\WINDOWS\System32\svchost.exe -k imgsvc
Windows Management Instrumentation = G:\WINDOWS\system32\svchost.exe -k netsvcs
Windows Time = G:\WINDOWS\System32\svchost.exe -k netsvcs
Wireless Zero Configuration = G:\WINDOWS\System32\svchost.exe -k netsvcs
Workstation = G:\WINDOWS\System32\svchost.exe -k netsvcs

[VxD Services (1)]
JAVASUP = JAVASUP.VXD

[SafeBoot services (Minimal boot)]
* CD-ROM Drive *
{4D36E965-E325-11CE-BFC1-08002BE10318}

* DiskDrive *
{4D36E967-E325-11CE-BFC1-08002BE10318}

* Driver *
dmboot.sys
dmio.sys
dmload.sys
sermouse.sys
vga.sys
vgasave.sys

* Driver Group *
Base
Boot Bus Extender
Boot file system
File system
Filter
PCI Configuration
PNP Filter
Primary disk
SCSI Class
System Bus Extender

* Floppy disk drive *
{4D36E980-E325-11CE-BFC1-08002BE10318}

* FSFilter System Recovery *
sr.sys

* Hdc *
{4D36E96A-E325-11CE-BFC1-08002BE10318}

* Human Interface Devices *
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}

* Keyboard *
{4D36E96B-E325-11CE-BFC1-08002BE10318}

* Mouse *
{4D36E96F-E325-11CE-BFC1-08002BE10318}

* PCMCIA Adapters *
{4D36E977-E325-11CE-BFC1-08002BE10318}

* SCSIAdapter *
{4D36E97B-E325-11CE-BFC1-08002BE10318}

* Service *
AppMgmt
CryptSvc
DcomLaunch
dmadmin
dmserver
EventLog
HelpSvc
Netlogon
PlugPlay
RpcSs
SRService
vds
WinMgmt

* Standard floppy disk controller *
{4D36E969-E325-11CE-BFC1-08002BE10318}

* System *
{4D36E97D-E325-11CE-BFC1-08002BE10318}

* Universal Serial Bus controllers *
{36FC9E60-C465-11CF-8056-444553540000}

* Volume *
{71A27CDD-812A-11D0-BEC7-08002BE2092F}

* Volume shadow copy *
{533C5B84-EC70-11D2-9505-00C04F79DEAF}


[SafeBoot services (Minimal boot + network support)]
* CD-ROM Drive *
{4D36E965-E325-11CE-BFC1-08002BE10318}

* DiskDrive *
{4D36E967-E325-11CE-BFC1-08002BE10318}

* Driver *
dmboot.sys
dmio.sys
dmload.sys
ip6fw.sys
ipnat.sys
rdpcdd.sys
rdpdd.sys
rdpwd.sys
sermouse.sys
tdpipe.sys
tdtcp.sys
vga.sys
vgasave.sys

* Driver Group *
Base
Boot Bus Extender
Boot file system
File system
Filter
NDIS
NDIS Wrapper
NetBIOSGroup
NetDDEGroup
Network
NetworkProvider
PCI Configuration
PNP Filter
PNP_TDI
Primary disk
SCSI Class
Streams Drivers
System Bus Extender
TDI

* Floppy disk drive *
{4D36E980-E325-11CE-BFC1-08002BE10318}

* FSFilter System Recovery *
sr.sys

* Hdc *
{4D36E96A-E325-11CE-BFC1-08002BE10318}

* Human Interface Devices *
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}

* Keyboard *
{4D36E96B-E325-11CE-BFC1-08002BE10318}

* Mouse *
{4D36E96F-E325-11CE-BFC1-08002BE10318}

* Net *
{4D36E972-E325-11CE-BFC1-08002BE10318}

* NetClient *
{4D36E973-E325-11CE-BFC1-08002BE10318}

* NetService *
{4D36E974-E325-11CE-BFC1-08002BE10318}

* NetTrans *
{4D36E975-E325-11CE-BFC1-08002BE10318}

* PCMCIA Adapters *
{4D36E977-E325-11CE-BFC1-08002BE10318}

* SCSIAdapter *
{4D36E97B-E325-11CE-BFC1-08002BE10318}

* Service *
AFD
AppMgmt
Browser
CryptSvc
DcomLaunch
Dhcp
dmadmin
dmserver
DnsCache
EventLog
HelpSvc
LanmanServer
LanmanWorkstation
LmHosts
Messenger
Ndisuio
NetBIOS
NetBT
Netlogon
NetMan
NtLmSsp
PlugPlay
rdsessmgr
RpcSs
sharedaccess
SRService
Tcpip
termservice
UploadMgr
WinMgmt
WZCSVC

* Standard floppy disk controller *
{4D36E969-E325-11CE-BFC1-08002BE10318}

* System *
{4D36E97D-E325-11CE-BFC1-08002BE10318}

* Universal Serial Bus controllers *
{36FC9E60-C465-11CF-8056-444553540000}

* Volume *
{71A27CDD-812A-11D0-BEC7-08002BE2092F}


[SafeBoot: Alternate shell]
cmd.exe (not enabled)

——————–

Driver filters:

[Class filters]
* Infrared devices *
- Upper filters
IRENUM.sys

* Medium Changers *
- Upper filters
GEARAspiWDM.sys

* Storage volumes *
- Upper filters
VolSnap.sys

* Tape drives *
- Upper filters
GEARAspiWDM.sys



[Device filters]
* AMD-751 Processor to AGP Controller *
- Upper filters
AMDAGP.sys

* CD-ROM Drive *
- Upper filters
redbook.sys

- Lower filters
imapi.sys

* CD-ROM Drive *
- Upper filters
redbook.sys

* Communications Port *
- Upper filters
serenum.sys

* Compaq Data Fax Modem *
- Lower filters
HCF_MSFT.sys

* Creative SBLive! Gameport *
- Lower filters
ctljystk.sys

* Direct Parallel *
- Lower filters
PtiLink.sys

* Terminal Server Keyboard Driver *
- Upper filters
kbdclass.sys

* Terminal Server Mouse Driver *
- Upper filters
mouclass.sys

* WAN Miniport (IP) *
- Lower filters
NdisTapi.sys

* WAN Miniport (PPPOE) *
- Lower filters
NdisTapi.sys

* WAN Miniport (PPTP) *
- Lower filters
NdisTapi.sys



——————–

Print monitors (8):

BJ Language Monitor - cnbjmon.dll
EPSON V6 2KMonitor - EBPMON24.DLL
HP Standard TCP/IP Port - HpTcpMon.dll
hpzsnt12 - hpzsnt12.dll
Local Port - localspl.dll
PJL Language Monitor - pjlmon.dll
Standard TCP/IP Port - tcpmon.dll
USB Monitor - usbmon.dll

——————–

WOW compatibility:

cmdline = G:\WINDOWS\system32\ntvdm.exe
wowcmdline = G:\WINDOWS\system32\ntvdm.exe -a G:\WINDOWS\system32\krnl386

[KnownDlls (16-bit) (40)]
avicap.dll
avifile.dll
comm.drv
commdlg.dll
compobj.dll
ctl3dv2.dll
ddeml.dll
keyboard.drv
lanman.drv
mapi.dll
mciavi.drv
mciseq.drv
mciwave.drv
mmsystem.dll
mouse.drv
msacm.dll
msvideo.dll
netapi.dll
ole2.dll
ole2disp.dll
ole2nls.dll
olecli.dll
olesvr.dll
pmspl.dll
progman.exe
rasapi16.dll
shell.dll
sound.drv
storage.dll
system.drv
timer.drv
toolhelp.dll
typelib.dll
vga.drv
wfwnet.drv
win87em.dll
winoldap.mod
winsock.dll
winspool.exe
wowdeb.exe

[KnownDlls (32-bit) (20)]
advapi32.dll
comdlg32.dll
gdi32.dll
imagehlp.dll
kernel32.dll
lz32.dll
ole32.dll
oleaut32.dll
olecli32.dll
olecnv32.dll
olesvr32.dll
olethk32.dll
rpcrt4.dll
shell32.dll
url.dll
urlmon.dll
user32.dll
version.dll
wininet.dll
wldap32.dll


————————————————–
End of report, 205,230 bytes

Commandline options:
/showempty - Show empty sections
/showcmts - Show comments in .bat files
/noshowclsids - Hide class IDs
/noshowprivate - Hide usernames and computer name
/noshowusers - Hide entries from other users
/noshowhardware - Hide entries from other hardware configurations
/showlargehosts - Show hosts file even when more than 1000 lines are in it
/showlargezones - Show Zones even when more than 1000 domains are in them
/autosave - Run hidden, automatically save a report and quit
/autosavepath: - Specify where to save log, when using /autosave.
Use surrounding quotes for paths with spaces.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI