This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Adware tracking cookie

41 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Although your tools did not find those two cookies, my superspyware did find them on almost every reboot recently. see below yourself please: Thanks again!
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/20/2009 at 08:35 PM

Core Rules Database Version : 4113
Trace Rules Database Version: 2053

Scan type : Quick Scan
Total Scan Time : 00:18:16

Memory items scanned : 463
Memory threats detected : 0
Registry items scanned : 752
Registry threats detected : 0
File items scanned : 689
File threats detected : 3

Adware.Tracking Cookie
C:\Documents and Settings\Others\Cookies\[removed][1].txt
C:\Documents and Settings\Others\Cookies\others@atdmt[2].txt
C:\Documents and Settings\Others\Cookies\[removed][2].txt
Tom_q2356,

Perfect. Let's see if we can make them leave.

Please download the OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
    (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Files
    C:\Documents and Settings\Others\Cookies\[removed][1].txt
    C:\Documents and Settings\Others\Cookies\others@atdmt[2].txt
    C:\Documents and Settings\Others\Cookies\[removed][2].txt
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Hi TomK,

It actually took me two scans on OTM.exe because the first time it got frozen, and with two unsuccessful reboots, I had to do it manually each time–shut down and then start again. Anyhow, first thing I noticed from the log is that so much of the FireFox cache and Opera cache got emptied although I have not been using both browsers for a very long time. That tells me that ATF cleaner did not do that job as throughly as OTM.exe did. Can I continue to use OTM.exe for emptying cache in the future?

Secondly, the names of the three cookies–sometimes only show two–are somewhat related to websites I visit regularly, for example, the sznews and hotmail (or windows live) websites. Does that mean I cannot visit these websites again if I don't want to get those cookies? That would be sad for me because they are my daily life thing–I need to read news and check emails. Please give me more advises on this.

Now let me see if those cookies are gone for good or not, this might take me couple of days to find out.

Thanks again,
Tom_q


All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File/Folder C:\Documents and Settings\Others\Cookies\[removed][1].txt not found.
File/Folder C:\Documents and Settings\Others\Cookies\others@atdmt[2].txt not found.
File/Folder C:\Documents and Settings\Others\Cookies\[removed][2].txt not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: All UseZs

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 49286 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Others
File delete failed. C:\Documents and Settings\Others\Local Settings\Temp\Perflib_Perfdata_f58.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Others\Local Settings\Temp\~DF190E.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Others\Local Settings\Temp\~DF4C52.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Others\Local Settings\Temp\~DF8502.tmp scheduled to be deleted on reboot.
->Temp folder emptied: 147637 bytes
File delete failed. C:\Documents and Settings\Others\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 5353399 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 29115838 bytes
->Opera cache emptied: 831257 bytes

User: Tom Q

%systemdrive% .tmp files removed: 0 bytes
C:\WINDOWS\msdownld.tmp folder deleted successfully.
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_130.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ZLT03eec.TMP scheduled to be deleted on reboot.
Windows Temp folder emptied: 19071 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 33.87 mb


OTM by OldTimer - Version 3.0.0.6 log created on 09212009_070333

Files moved on Reboot…
File C:\Documents and Settings\Others\Local Settings\Temp\Perflib_Perfdata_f58.dat not found!
C:\Documents and Settings\Others\Local Settings\Temp\~DF190E.tmp moved successfully.
C:\Documents and Settings\Others\Local Settings\Temp\~DF4C52.tmp moved successfully.
C:\Documents and Settings\Others\Local Settings\Temp\~DF8502.tmp moved successfully.
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_130.dat not found!
File C:\WINDOWS\temp\ZLT03eec.TMP not found!

Registry entries deleted on Reboot…
Tom_q2356,

Unless this was a log from the second run, OTM didn't find those files. The log says they don't exist. :unsure:

Rather than running OTM to delete temp files, here is the stand-alone routine for doing just that.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Does that mean I cannot visit these websites again if I don't want to get those cookies?

Not necessarily. It depends on if those websites "require" them. Now that you require IE to get your permission before installing any cookie, when it asks if it can install them, say no. If the website won't load without them, you will need to consider allowing them. If the page operates correctly without them, you're all good. :)
The hardest thing is that when I open either one of the websites I mentioned earlier on, it will ask me something like "allow cookie…yes or no" many times and each time it has no specified name, at least I did not recognize any of that in the same names of those two cookies.

I will try out your new tool and post a reply later. Thanks.
Hi TomK,

You are so right, I am finally sick and tired of the approval of each cookie and changed that prompt back to allow. So far those two cookies seemed to be gone, but I have to say this, there were times before they seemed to be dead for a while and yet one day all of a sudden they were revived. This could be a tie with the virus found in the computer system and here are the virus found by Avast after a real long scan the whole night last night:

kernel32.dll C:\WINDOWS\system32
winsock.dll C:\WINDOWS\system32
wsock32.dll C:\WINDOWS\system32

And these three are actually the "old force" or old problems. I cought and killed them many many times before and they also pretended to be dead for the last couple of years and now they are back again. As a matter of fact, I remember someone here told me long ago that these are not the virus. However, as far as I am concerned, they are the virus because they have been really slowing down my computer.

So I also hope that you can continue to help me out by getting rid of them or fix them up once and for all.

Thanks a million!
Tom-q
Tom_q2356,

While it is true that there are trojans and worms that mimic those file names, those are actually regitimate Microsoft file names located where they should be. If they are the microsoft files and you remove them, serious problems could ensue.

Let's get some more information:

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
OTL logfile created on: 9/23/2009 9:00:39 AM - Run 1
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\Others\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.98 Mb Total Physical Memory | 583.54 Mb Available Physical Memory | 57.04% Memory free
1.47 Gb Paging File | 1.06 Gb Available in Paging File | 72.03% Paging File free
Paging file location(s): c:\pagefile.sys 576 1152 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 27.91 Gb Total Space | 1.28 Gb Free Space | 4.58% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: Tom_q2356
Current User Name: Others
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2009/08/17 23:58:55 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/07/03 22:49:06 | 01,029,456 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009/08/18 00:07:17 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2002/11/08 12:22:10 | 00,147,456 | —- | M] () – C:\WINDOWS\System32\Ati2evxx.exe
PRC - [2006/06/07 12:46:24 | 00,942,080 | —- | M] (Diskeeper Corporation) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
PRC - [2001/03/29 02:00:00 | 00,102,400 | —- | M] (SEIKO EPSON CORPORATION) – C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
PRC - [2003/07/13 02:49:24 | 00,766,004 | —- | M] () – C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2009/07/15 14:44:03 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/09/10 14:54:02 | 00,269,648 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2003/11/13 16:51:56 | 00,253,952 | —- | M] (Stardock) – C:\Program Files\Common Files\Stardock\SDMCP.exe
PRC - [2008/04/14 08:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2003/12/17 17:43:04 | 00,118,784 | —- | M] (Softarium.com) – C:\Program Files\reliz\akeys.exe
PRC - [2002/11/08 11:00:00 | 00,294,912 | —- | M] (ATI Technologies, Inc.) – C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
PRC - [2005/11/15 13:50:46 | 00,222,784 | —- | M] (BillP Studios) – C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
PRC - [2009/02/15 23:10:22 | 00,981,384 | —- | M] (Check Point Software Technologies LTD) – C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2003/03/01 16:25:28 | 00,138,240 | —- | M] ( ) – C:\Program Files\CursorXP\CursorXP.exe
PRC - [2002/09/12 23:28:14 | 00,024,576 | —- | M] (BVRP Software) – C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2006/03/23 00:13:46 | 01,591,808 | —- | M] (YourWare Solutions ™) – C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
PRC - [2006/07/08 11:36:08 | 00,358,400 | —- | M] (URSoft,Inc) – C:\Program Files\Startup Faster 2004\sfAgent.exe
PRC - [2009/08/18 00:07:01 | 00,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2002/08/29 19:00:00 | 00,016,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wbem\unsecapp.exe
PRC - [2009/02/06 18:10:02 | 00,227,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wbem\wmiprvse.exe
PRC - [2009/08/18 00:04:21 | 00,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2003/08/29 19:05:35 | 00,360,448 | —- | M] () – C:\Program Files\SpywareGuard\sgmain.exe
PRC - [2009/08/18 00:07:23 | 00,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2003/08/29 11:14:56 | 00,233,472 | —- | M] () – C:\Program Files\SpywareGuard\sgbhp.exe
PRC - [2009/09/23 08:55:50 | 00,514,560 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Others\Desktop\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/04/14 08:11:48 | 00,100,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\6to4svc.dll – (6to4 [Auto | Running])
SRV - [2006/01/03 14:59:23 | 00,068,096 | —- | M] () – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe – (Adobe LM Service [On_Demand | Stopped])
SRV - [2008/07/25 11:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2009/08/17 23:58:55 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv [Auto | Running])
SRV - [2002/11/08 12:22:10 | 00,147,456 | —- | M] () – C:\WINDOWS\System32\Ati2evxx.exe – (Ati HotKey Poller [Auto | Running])
SRV - [2009/08/18 00:07:17 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus [Auto | Running])
SRV - [2009/08/18 00:07:01 | 00,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/08/18 00:04:21 | 00,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner [On_Demand | Running])
SRV - [2008/07/25 11:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009/01/09 12:46:24 | 00,410,976 | —- | M] (mst software GmbH, Germany) – C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe – (DfSdkS [On_Demand | Stopped])
SRV - [2006/06/07 12:46:24 | 00,942,080 | —- | M] (Diskeeper Corporation) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe – (Diskeeper [Auto | Running])
SRV - [2001/03/29 02:00:00 | 00,102,400 | —- | M] (SEIKO EPSON CORPORATION) – C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe – (EPSONStatusAgent2 [Auto | Running])
SRV - [2008/07/29 21:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2009/03/03 14:53:08 | 00,033,176 | —- | M] (NOS Microsystems Ltd.) – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe – (getPlus® Helper [Disabled | Stopped])
SRV - [2008/11/21 03:18:52 | 00,136,120 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [On_Demand | Stopped])
SRV - [2008/04/14 08:12:02 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Disabled | Stopped])
SRV - [2007/11/06 21:16:54 | 00,217,088 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll – (hpqcxs08 [On_Demand | Running])
SRV - [2007/11/06 21:16:54 | 00,139,264 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll – (hpqddsvc [Auto | Running])
SRV - [2009/07/08 16:17:50 | 00,397,192 | —- | M] () – C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\IcbcDaemon.exe – (ICBC Daemon Service [Auto | Stopped])
SRV - [2005/04/04 00:41:10 | 00,069,632 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2003/07/13 02:49:24 | 00,766,004 | —- | M] () – C:\Program Files\Ahead\InCD\InCDsrv.exe – (InCDsrv [Auto | Running])
SRV - [2001/10/08 12:59:36 | 00,049,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\Fast.exe – (InteractiveLogon [Auto | Stopped])
SRV - [2008/03/30 10:36:30 | 00,504,104 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Stopped])
SRV - [2009/07/15 14:44:03 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2009/07/03 22:49:06 | 01,029,456 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service [Auto | Running])
SRV - [2009/09/10 14:54:02 | 00,269,648 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService [Auto | Running])
SRV - [2008/07/29 19:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/04/14 08:12:02 | 00,105,472 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\p2pgasvc.dll – (p2pgasvc [On_Demand | Stopped])
SRV - [2009/07/17 11:10:16 | 00,931,080 | —- | M] (Raxco Software, Inc.) – C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe – (PDAgent [On_Demand | Stopped])
SRV - [2009/07/17 11:10:18 | 01,033,480 | —- | M] (Raxco Software, Inc.) – C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe – (PDEngine [On_Demand | Stopped])
SRV - File not found – – (rpcapd [On_Demand | Stopped])
SRV - [2009/02/15 23:10:22 | 02,402,184 | —- | M] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe – (vsmon [Auto | Stopped])
SRV - [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [Disabled | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2009/08/18 00:03:21 | 00,026,944 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys – (Aavmker4 [System | Running])
DRV - [2008/12/07 17:29:59 | 00,021,035 | —- | M] (Meetinghouse Data Communications) – C:\WINDOWS\System32\DRIVERS\AegisP.sys – (AegisP [Auto | Running])
DRV - [2001/04/26 09:04:00 | 00,117,984 | R— | M] (Agilent Technologies) – C:\WINDOWS\System32\DRIVERS\Atusbcam.sys – (AgilentUSBCam [On_Demand | Running])
DRV - [2002/09/04 00:27:16 | 00,005,248 | —- | M] (Acer Laboratories Inc.) – C:\WINDOWS\System32\DRIVERS\aliide.sys – (AliIde [Disabled | Stopped])
DRV - [2008/04/14 02:36:39 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.) – C:\WINDOWS\System32\DRIVERS\amdagp.sys – (amdagp [Disabled | Stopped])
DRV - [2002/09/04 00:27:30 | 00,026,496 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\System32\DRIVERS\asc.sys – (asc [Disabled | Stopped])
DRV - [2002/09/04 00:27:30 | 00,014,848 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\System32\DRIVERS\asc3550.sys – (asc3550 [Disabled | Stopped])
DRV - [1999/09/10 19:06:00 | 00,025,244 | —- | M] (Adaptec) – C:\WINDOWS\System32\drivers\aspi32.sys – (Aspi32 [Auto | Running])
DRV - [2009/08/18 00:05:37 | 00,020,560 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys – (aswFsBlk [Auto | Running])
DRV - [2009/08/18 00:06:43 | 00,094,160 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys – (aswMon2 [Auto | Running])
DRV - [2009/08/18 00:04:29 | 00,023,152 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys – (aswRdr [On_Demand | Running])
DRV - [2009/08/18 00:05:52 | 00,114,768 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys – (aswSP [System | Running])
DRV - [2009/08/18 00:04:40 | 00,051,376 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys – (aswTdi [System | Running])
DRV - [2002/11/08 12:31:36 | 00,539,392 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys – (ati2mtag [On_Demand | Running])
DRV - [2002/12/18 01:36:42 | 00,042,368 | —- | M] (Broadcom Corporation) – C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys – (bcm4sbxp [On_Demand | Running])
DRV - [2007/01/23 22:36:20 | 00,006,016 | —- | M] (Motorola Inc) – C:\WINDOWS\System32\DRIVERS\motfilt.sys – (BTCFilterService [On_Demand | Stopped])
DRV - [2006/05/20 05:16:24 | 00,002,432 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdr4_xp.sys – (Cdr4_xp [System | Running])
DRV - [2006/05/20 05:16:24 | 00,002,560 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdralw2k.sys – (Cdralw2k [System | Running])
DRV - [2006/11/30 16:31:20 | 00,003,038 | —- | M] () – C:\WINDOWS\System32\Drivers\CertClient.dat – (CMB8100 [Auto | Running])
DRV - [2007/01/18 14:28:34 | 00,003,584 | —- | M] () – C:\WINDOWS\System32\Drivers\CMBProtector.dat – (CMBProtector [Auto | Running])
DRV - [2002/09/04 00:29:01 | 00,006,656 | —- | M] (CMD Technology, Inc.) – C:\WINDOWS\System32\DRIVERS\cmdide.sys – (CmdIde [Disabled | Stopped])
DRV - [2002/09/04 00:30:26 | 00,179,584 | —- | M] (Mylex Corporation) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys – (dac2w2k [Disabled | Stopped])
DRV - [2002/07/10 21:13:00 | 00,095,232 | —- | M] (IC Media Corporation) – C:\WINDOWS\System32\Drivers\usbuvt.sys – (DCamUSBUVT [On_Demand | Stopped])
DRV - [2009/06/08 10:00:56 | 00,071,696 | —- | M] (Raxco Software, Inc.) – C:\WINDOWS\System32\drivers\DefragFs.sys – (DefragFS [Auto | Running])
DRV - [2006/04/26 20:12:14 | 00,011,941 | —- | M] (Mjtsai Corp) – C:\WINDOWS\System32\DRIVERS\MotoVisionDP.sys – (DirectDrv [On_Demand | Running])
DRV - [2002/07/02 11:12:42 | 00,002,410 | —- | M] () – C:\Program Files\FreshDevices\FreshDiagnose\FreshIO.sys – (FreshIO [On_Demand | Stopped])
DRV - [2002/09/04 00:31:57 | 00,012,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\fsvga.sys – (FsVga [System | Running])
DRV - [2008/01/29 12:01:28 | 00,016,168 | —- | M] (GEAR Software Inc.) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [1996/04/04 03:33:26 | 00,005,248 | —- | M] () – C:\WINDOWS\system32\giveio.sys – (giveio [Boot | Running])
DRV - [2002/10/18 01:52:44 | 00,159,652 | —- | M] (Conexant Systems) – C:\WINDOWS\System32\DRIVERS\HSFHWICH.sys – (HSFHWICH [On_Demand | Running])
DRV - [2002/10/18 01:50:56 | 01,174,128 | —- | M] (Conexant Systems) – C:\WINDOWS\System32\DRIVERS\HSF_DP.sys – (HSF_DP [On_Demand | Running])
DRV - [2004/08/04 13:29:36 | 00,161,020 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\i81xnt5.sys – (i81x [On_Demand | Stopped])
DRV - [2004/08/04 13:29:37 | 00,012,415 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wADV01nt.sys – (iAimFP0 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:37 | 00,012,127 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wADV02NT.sys – (iAimFP1 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:37 | 00,011,775 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wADV05NT.sys – (iAimFP2 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:47 | 00,012,063 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys – (iAimFP3 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:49 | 00,019,455 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys – (iAimFP4 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:41 | 00,029,311 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wATV01nt.sys – (iAimTV0 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:42 | 00,019,551 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wATV02NT.sys – (iAimTV1 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:43 | 00,033,599 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wATV04nt.sys – (iAimTV3 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:45 | 00,023,615 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys – (iAimTV4 [On_Demand | Stopped])
DRV - [2001/11/05 14:54:38 | 00,014,182 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\DRIVERS\icm10blk.sys – (icm10blk [On_Demand | Stopped])
DRV - [2001/11/05 14:54:14 | 00,420,870 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\Drivers\ICM10USB.sys – (ICM10USB [On_Demand | Stopped])
DRV - [2003/07/13 02:49:24 | 00,085,360 | —- | M] () – C:\WINDOWS\System32\drivers\incdfs.sys – (InCDfs [Disabled | Running])
DRV - [2003/07/13 02:49:24 | 00,026,784 | —- | M] (Ahead Software) – C:\WINDOWS\System32\DRIVERS\InCDPass.sys – (InCDPass [System | Running])
DRV - [2003/07/13 02:49:18 | 00,023,920 | —- | M] (Ahead Software AG) – C:\WINDOWS\System32\drivers\incdrm.sys – (incdrm [System | Running])
DRV - [2009/07/03 22:49:08 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd [Boot | Running])
DRV - [2003/07/03 21:50:12 | 00,045,952 | —- | M] () – C:\Program Files\Everstrike\Lock Folder XP 3.2\UniShieldXP.sys – (lf [Auto | Running])
DRV - [2006/05/23 19:21:02 | 00,004,224 | —- | M] (FSPro Labs) – C:\WINDOWS\System32\drivers\lmpc2.sys – (LMPC2 [On_Demand | Running])
DRV - [2009/09/10 14:53:50 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys – (MBAMProtector [On_Demand | Running])
DRV - [2008/12/07 15:16:57 | 00,015,781 | —- | M] (Meetinghouse Data Communications) – C:\WINDOWS\System32\DRIVERS\mdc8021x.sys – (MDC8021X [Auto | Running])
DRV - [2001/10/23 03:46:42 | 00,009,855 | —- | M] (Conexant) – C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys – (mdmxsdk [Auto | Running])
DRV - [2008/08/21 18:49:22 | 00,018,688 | —- | M] (Motorola) – C:\WINDOWS\System32\DRIVERS\motccgp.sys – (motccgp [On_Demand | Stopped])
DRV - [2008/08/21 18:49:56 | 00,008,320 | —- | M] (Motorola) – C:\WINDOWS\System32\DRIVERS\motccgpfl.sys – (motccgpfl [On_Demand | Stopped])
DRV - [2007/10/10 17:41:50 | 00,042,112 | —- | M] (Motorola Inc) – C:\WINDOWS\System32\DRIVERS\motodrv.sys – (MotDev [On_Demand | Stopped])
DRV - [2007/06/18 20:18:26 | 00,023,680 | —- | M] (Motorola) – C:\WINDOWS\System32\DRIVERS\motmodem.sys – (motmodem [On_Demand | Stopped])
DRV - [2007/11/02 15:51:28 | 00,006,400 | —- | M] (Motorola) – C:\WINDOWS\System32\DRIVERS\motswch.sys – (MotoSwitchService [On_Demand | Stopped])
DRV - [2008/03/03 16:03:10 | 00,023,296 | —- | M] (Motorola) – C:\WINDOWS\System32\DRIVERS\Motousbnet.sys – (Motousbnet [On_Demand | Stopped])
DRV - [2006/04/26 21:37:44 | 00,031,145 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\System32\DRIVERS\motovision.sys – (MOTOVISION [Auto | Running])
DRV - [2007/06/18 15:18:26 | 00,023,680 | —- | M] (Motorola) – C:\WINDOWS\System32\DRIVERS\motport.sys – (motport [On_Demand | Stopped])
DRV - [2002/09/04 00:42:50 | 00,017,280 | —- | M] (American Megatrends Inc.) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys – (mraid35x [Disabled | Stopped])
DRV - [2002/02/09 09:38:06 | 00,024,000 | R— | M] (Samsung Electronics Co., Ltd) – C:\WINDOWS\System32\DRIVERS\NetSecCm.sys – (ndiscm [On_Demand | Stopped])
DRV - [2001/10/31 10:58:34 | 00,161,512 | —- | M] (Efficient Networks, Inc.) – C:\WINDOWS\System32\DRIVERS\ntspppoe.sys – (NTSPPPOE [On_Demand | Stopped])
DRV - [2004/08/04 13:29:54 | 01,897,408 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Stopped])
DRV - [2002/11/09 03:45:06 | 00,017,217 | —- | M] (Dell Computer Corporation) – C:\WINDOWS\System32\DRIVERS\omci.sys – (omci [System | Running])
DRV - [2006/09/28 17:33:08 | 00,040,960 | —- | M] (Motorola Inc) – C:\WINDOWS\System32\DRIVERS\P2k.sys – (P2k [On_Demand | Stopped])
DRV - [2006/05/08 17:26:02 | 00,010,368 | —- | M] (Padus, Inc.) – C:\WINDOWS\System32\drivers\pfc.sys – (pfc [On_Demand | Running])
DRV - [2002/09/04 00:53:10 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2008/11/21 03:19:06 | 00,043,872 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2002/09/04 00:53:20 | 00,040,320 | —- | M] (QLogic Corporation) – C:\WINDOWS\System32\DRIVERS\ql1080.sys – (ql1080 [Disabled | Stopped])
DRV - [2002/09/04 00:53:21 | 00,045,312 | —- | M] (QLogic Corporation) – C:\WINDOWS\System32\DRIVERS\ql12160.sys – (ql12160 [Disabled | Stopped])
DRV - [2002/09/04 00:53:22 | 00,049,024 | —- | M] (QLogic Corporation) – C:\WINDOWS\System32\DRIVERS\ql1280.sys – (ql1280 [Disabled | Stopped])
DRV - [2004/07/29 16:29:58 | 00,211,072 | —- | M] (Ralink Technology Inc.) – C:\WINDOWS\System32\DRIVERS\RT2500.sys – (RT2500 [On_Demand | Stopped])
DRV - [2007/04/23 14:11:54 | 00,224,896 | —- | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\System32\DRIVERS\wg111v3.sys – (RTL8187B [On_Demand | Stopped])
DRV - [2009/07/28 10:53:16 | 00,009,968 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS – (SASDIFSV [System | Running])
DRV - [2009/07/28 10:53:16 | 00,007,408 | R— | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS – (SASENUM [On_Demand | Stopped])
DRV - [2009/07/28 10:53:14 | 00,072,944 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys – (SASKUTIL [System | Running])
DRV - [2007/11/13 18:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2008/04/14 02:36:39 | 00,040,960 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\sisagp.sys – (sisagp [Disabled | Stopped])
DRV - [2001/08/17 13:56:16 | 00,007,552 | —- | M] (Sony Corporation) – C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS – (SONYPVU1 [On_Demand | Stopped])
DRV - [2002/09/04 01:04:10 | 00,019,072 | —- | M] (Adaptec, Inc.) – C:\WINDOWS\System32\DRIVERS\sparrow.sys – (Sparrow [Disabled | Stopped])
DRV - [2005/06/15 22:55:53 | 00,004,096 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\system32\speedfan.sys – (speedfan [Boot | Running])
DRV - [2008/11/17 02:24:00 | 00,051,688 | —- | M] (Check Point Software Technologies LTD) – C:\WINDOWS\system32\ZoneLabs\srescan.sys – (srescan [Boot | Running])
DRV - [2002/11/12 07:57:16 | 00,193,840 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\System32\drivers\STAC97.sys – (STAC97 [On_Demand | Running])
DRV - [2002/10/18 01:54:18 | 00,036,348 | —- | M] (Conexant Systems) – C:\WINDOWS\System32\DRIVERS\strmdisp.sys – (StreamDispatcher [Auto | Running])
DRV - [2002/09/04 01:05:44 | 00,016,256 | —- | M] (Symbios Logic Inc.) – C:\WINDOWS\System32\DRIVERS\symc810.sys – (symc810 [Disabled | Stopped])
DRV - [2002/09/04 01:05:44 | 00,032,640 | —- | M] (LSI Logic) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys – (symc8xx [Disabled | Stopped])
DRV - [2002/09/04 01:05:45 | 00,028,384 | —- | M] (LSI Logic) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys – (sym_hi [Disabled | Stopped])
DRV - [2002/09/04 01:05:45 | 00,030,688 | —- | M] (LSI Logic) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys – (sym_u3 [Disabled | Stopped])
DRV - [2004/05/13 19:19:22 | 00,182,688 | —- | M] (Synaptics, Inc.) – C:\WINDOWS\System32\DRIVERS\SynTP.sys – (SynTP [On_Demand | Running])
DRV - [2008/06/20 19:08:27 | 00,225,856 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\tcpip6.sys – (Tcpip6 [System | Running])
DRV - [2002/09/04 01:07:50 | 00,036,736 | —- | M] (Promise Technology, Inc.) – C:\WINDOWS\System32\DRIVERS\ultra.sys – (ultra [Disabled | Stopped])
DRV - [2002/12/10 09:11:42 | 00,006,852 | —- | M] () – C:\WINDOWS\System32\Drivers\Vcs.sys – (Vcs [Auto | Running])
DRV - [2009/02/15 23:10:26 | 00,353,672 | —- | M] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsdatant.sys – (vsdatant [System | Running])
DRV - [2002/10/18 01:44:46 | 00,602,512 | —- | M] (Conexant Systems) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys – (winachsf [On_Demand | Running])
DRV - [2007/06/25 20:29:50 | 00,500,736 | R— | M] (Atheros Technology Corporation) – C:\WINDOWS\System32\DRIVERS\zd1211Bu.sys – (ZD1211BU(TP-LINK) [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_Url = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.96
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.5
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.2.20080910
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13

FF - user.js..browser.search.openintab: false

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/23 16:16:08 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/15 14:44:10 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2007/02/18 17:41:43 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/24 22:09:36 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/24 22:09:36 | 00,000,000 | —D | M]

[2009/07/30 06:16:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Others\Application Data\mozilla\Extensions
[2008/12/10 15:58:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Others\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/07/30 06:16:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Others\Application Data\mozilla\Extensions\[removed]
[2009/08/24 22:01:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Others\Application Data\mozilla\Firefox\Profiles\8g1iwoqs.default\extensions
[2009/07/03 18:31:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Others\Application Data\mozilla\Firefox\Profiles\8g1iwoqs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/12/08 20:40:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Others\Application Data\mozilla\Firefox\Profiles\8g1iwoqs.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/07/17 11:28:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Others\Application Data\mozilla\Firefox\Profiles\8g1iwoqs.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/08/24 22:01:17 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/08/24 22:09:36 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/07/15 14:45:11 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/08/24 22:09:07 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/24 22:09:07 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/07/15 14:44:07 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009/08/24 22:09:23 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2008/06/02 17:02:48 | 00,200,704 | —- | M] (Pando Networks) – C:\Program Files\mozilla firefox\plugins\npPandoWebInst.dll
[2009/02/27 12:13:42 | 00,103,792 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2006/08/10 14:23:23 | 00,139,305 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2008/06/05 00:16:39 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2008/06/05 00:16:40 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2008/06/05 00:16:40 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2008/06/05 00:16:40 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2008/06/05 00:16:41 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2008/06/05 00:16:41 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2008/06/05 00:16:41 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2006/08/10 14:23:55 | 00,024,621 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprjplug.dll
[2006/08/10 14:22:21 | 00,081,967 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2007/03/10 07:16:44 | 00,189,496 | —- | M] (Yahoo! Inc.) – C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll
[2009/08/24 22:09:28 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/08/24 22:09:28 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/08/24 22:09:28 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/24 22:09:28 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/08/24 22:09:28 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/24 22:09:28 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/08/24 22:09:28 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (931683 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
O1 - Hosts: 127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
O1 - Hosts: 127.0.0.1 phpadsnew.abac.com
O1 - Hosts: 127.0.0.1 a.abnad.net
O1 - Hosts: 127.0.0.1 b.abnad.net
O1 - Hosts: 127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 d.abnad.net
O1 - Hosts: 127.0.0.1 e.abnad.net
O1 - Hosts: 127.0.0.1 t.abnad.net
O1 - Hosts: 127.0.0.1 z.abnad.net
O1 - Hosts: 127.0.0.1 banners.absolpublisher.com
O1 - Hosts: 127.0.0.1 tracking.absolstats.com
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 gtb5.acecounter.com
O1 - Hosts: 127.0.0.1 gtb19.acecounter.com
O1 - Hosts: 27362 more lines…
O2 - BHO: (IE7Pro BHO) - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll (IE7Pro.com)
O2 - BHO: (HelperObject Class) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (bho2gr Class) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (PopKiller Class) - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\SysShield Tools\Internet Eraser\pkext.dll (SysShield Consulting, Inc.)
O2 - BHO: (ICBC Anti-Phishing class) - {BB4491A2-D11A-4c6b-91C0-B53246A3122B} - C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\Icbc_AntiPhishing.dll (??????)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (1-Click Answers) - {7754C418-F62E-44aa-B169-E719E718BCFD} - C:\Program Files\1-Click Answers\IEToolbar\AnswersToolbarU.dll (Answers Corporation)
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (IncrediBar) - {D8073790-84C7-4602-BF77-C6ACBF1612E4} - C:\Program Files\IncrediBar\bin\IBTBar.dll (IncrediBar)
O3 - HKLM\..\Toolbar: (AbsoluteShield) - {EE9DD090-902D-4623-9360-FB7D8666202B} - C:\Program Files\SysShield Tools\Internet Eraser\AbsoluteBar.dll (AbsoluteShield Software)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (IncrediBar) - {D8073790-84C7-4602-BF77-C6ACBF1612E4} - C:\Program Files\IncrediBar\bin\IBTBar.dll (IncrediBar)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (1-Click Answers) - {7754C418-F62E-44AA-B169-E719E718BCFD} - C:\Program Files\1-Click Answers\IEToolbar\AnswersToolbarU.dll (Answers Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (IncrediBar) - {D8073790-84C7-4602-BF77-C6ACBF1612E4} - C:\Program Files\IncrediBar\bin\IBTBar.dll (IncrediBar)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [StartupFaster] C:\Program Files\Startup Faster 2004\StrpFstCfg.exe (URSoft,Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\StartupFaster [2009/09/11 13:28:59 | 00,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Others\Start Menu\Programs\Startup\StartupFaster [2009/08/02 10:26:11 | 00,000,000 | -H-D | M]
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLastUserName = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ShutdownWithoutLogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\PhotoSupport present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInstrumentation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuNetworkPlaces = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoHelp = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMFUprogramsList = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuEjectPC = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSimpleStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDisconnect = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNtSecurity = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: GreyMSIAds = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceMaxRecentDocs = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTips = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LockTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarsOnTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTaskGrouping = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWebServices = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileUrl = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoExpandedNewMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: SpecifyDefaultButtons = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetConnectDisconnect = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoComputersNearMe = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnforceShellExtensionSecurity = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRunasInstallPrompt = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: PromptRunasInstallNetPath = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceCopyAclwithFile = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartRunNoHOMEPATH = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 0? = strpfstcfg.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 1? = newadmin.exe
O8 - Extra context menu item: &Add; animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm ()
O8 - Extra context menu item: &Winamp; Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2007/11/13 20:44:04 | 00,000,000 | —D | M]
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Answers… - C:\Program Files\1-Click Answers\Html\atiemenu.htm ()
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: Logoff - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComLogoff.html ()
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Translate this web page with Babylon - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O8 - Extra context menu item: Translate with Babylon - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2007/11/13 20:44:04 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2007/11/13 20:44:04 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2007/11/13 20:44:04 | 00,000,000 | —D | M]
O9 - Extra Button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll (IE7Pro.com)
O9 - Extra 'Tools' menuitem : IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll (IE7Pro.com)
O9 - Extra Button: IncrediBar - {023FA804-DCE1-4817-94ED-6BA4200F9AF2} - C:\Program Files\IncrediBar\bin\IBTBar.dll (IncrediBar)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe ()
O9 - Extra 'Tools' menuitem : PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe ()
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 72 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: bankofamerica.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: com.cn ([mybank.icbc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: com.cn ([www.icbc] http in Trusted sites)
O15 - HKCU\..Trusted Domains: hotmail.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: live.com ([login] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([v4.Windowsupdate] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([v4.Windowsupdate] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([Windowsupdate] https in Trusted sites)
O15 - HKCU\..Trusted Domains: msn.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: yahoo.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 432 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0D99625B-0619-4420-BB61-82DEE1B91D3A} https://ebank.gdb.com.cn/perbank/js/CertKitAx.cab (BlockHouse Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://download.ewido.net/ewidoOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab (Reg Error: Key error.)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://Tom_q2356.spaces.live.com//PhotoUpload/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} http://us.games2.yimg.com/download.games.y…ctl_0_0_0_1.ocx (ExentInf Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1222675051475 (MUWebControl Class)
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} http://chat.yahoo.com/cab/yacsui.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} http://chat.yahoo.com/cab/yuplapp.cab (Yahoo! Webcam Upload Wrapper)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} https://mybank.icbc.com.cn/icbc/newperbank/…afeControls.cab (AxSubmitControl Class)
O16 - DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE} http://download.yahoo.com/dl/bookmarks/ybconvfav030408.cab (YbUploadFavsCtl Class)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8192.0495138889 (Reg Error: Key error.)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse…pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab (YAddBook Class)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D81CA86B-EF63-42AF-BEE3-4502D9A03C2D} http://wwws.musicmatch.com/graphics/WebPlayer/MMLRadio.cab (MMRadioHostX Class)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.microsoft.com/download/7/E…04/clearadj.cab (CTAdjust Class)
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} http://chat.yahoo.com/cab/yvwrctl.cab (Yahoo! Webcam Viewer Wrapper)
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} http://pccheckup.dellfix.com/rel/35/install/gtdownde.cab (Dell PC Checkup Installer Control)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} http://chat.msn.com/bin/msnchat45.cab (MSN Chat Control 4.5)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Yahoo! MahJong Solitaire http://download.games.yahoo.com/games/clients/y/mjst4_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Pool 2 http://download.games.yahoo.com/games/clients/y/pote_x.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (C:\WINDOWS\system32\logonuiX.exe) - C:\WINDOWS\System32\logonuiX.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\MCPClient: DllName - C:\Program Files\Common Files\Stardock\mcpstub.dll - C:\Program Files\Common Files\Stardock\mcpstub.dll (Stardock)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/05/24 11:42:39 | 00,000,000 | R–D | M] - C:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (PDBoot.exe) - C:\WINDOWS\System32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

File not found – C:\Documents and Settings\Others\Desktop\CAZBDPKE.
[2009/09/23 08:55:42 | 00,514,560 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Others\Desktop\OTL.exe
[2009/09/21 22:51:58 | 10,832,5437 | —- | C] () – C:\Documents and Settings\Others\Desktop\CollegeStudent-xbox.wmv
[2009/09/21 06:28:52 | 00,000,000 | —D | C] – C:\_OTM
[2009/09/21 06:15:22 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/09/20 21:09:09 | 00,000,211 | —- | C] () – C:\Boot.bak
[2009/09/20 21:09:02 | 00,260,272 | —- | C] () – C:\cmldr
[2009/09/20 21:09:00 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/09/20 21:02:52 | 00,229,888 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/09/20 21:02:52 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/09/20 21:02:52 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/09/20 21:02:52 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/09/20 21:02:52 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/09/20 21:02:52 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/09/20 21:02:52 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/09/20 21:02:52 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/09/20 21:02:46 | 00,000,000 | —D | C] – C:\ComboFix
[2009/09/20 21:01:35 | 00,000,000 | —D | C] – C:\Qoobox
[2009/09/19 22:02:52 | 00,032,768 | —- | C] () – C:\Documents and Settings\Others\Desktop\LianQiao.doc
[2009/09/15 12:34:36 | 00,146,475 | —- | C] () – C:\Documents and Settings\Others\Desktop\APAsample.pdf
[2009/09/14 00:33:36 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/09/14 00:29:49 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
[2009/09/14 00:29:21 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2009/09/13 13:18:37 | 00,693,760 | —- | C] () – C:\WINDOWS\is-V9TVU.exe
[2009/09/13 13:18:37 | 00,010,498 | —- | C] () – C:\WINDOWS\is-V9TVU.msg
[2009/09/13 13:18:37 | 00,000,460 | —- | C] () – C:\WINDOWS\is-V9TVU.lst
[2009/09/13 00:03:55 | 00,000,000 | —D | C] – C:\Documents and Settings\Others\Desktop\MeiRECENT
[2009/09/12 16:01:41 | 00,002,688 | —- | C] () – C:\WINDOWS\System32\settings.aaw
[2009/09/12 16:01:40 | 00,000,720 | —- | C] () – C:\WINDOWS\System32\history.aaw
[2009/09/11 13:43:42 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WEBREG
[2009/09/11 13:42:44 | 00,000,000 | —D | C] – C:\Documents and Settings\Others\Application Data\HP
[2009/09/11 13:24:05 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP Product Assistant
[2009/09/11 13:24:05 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP
[2009/09/11 13:23:16 | 00,000,000 | —D | C] – C:\Program Files\Common Files\HP
[2009/09/11 13:21:59 | 00,000,000 | —D | C] – C:\Program Files\HP
[2009/09/11 13:15:02 | 00,157,446 | —- | C] () – C:\WINDOWS\hphins27.dat
[2009/09/11 13:15:02 | 00,000,787 | —- | C] () – C:\WINDOWS\hphmdl27.dat
[2009/09/11 13:14:59 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2009/09/11 13:14:04 | 00,271,704 | R— | C] (Hewlett-Packard) – C:\WINDOWS\System32\hpzids01.dll
[2009/09/11 13:13:56 | 00,117,760 | —- | C] (Hewlett-Packard Company) – C:\WINDOWS\System32\hpzll5mu.dll
[2009/09/10 07:01:54 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009/09/08 22:14:42 | 00,153,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\triedit.dll
[2009/09/07 21:39:58 | 00,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2009/09/04 21:10:28 | 00,000,000 | —D | C] – C:\Program Files\RMVB Converter
[2009/09/03 10:28:06 | 00,000,000 | —D | C] – C:\Documents and Settings\Others\Desktop\HumanBiology
[2009/08/30 16:11:17 | 00,000,000 | —D | C] – C:\Documents and Settings\Others\Desktop\MyMoped
[2009/08/26 07:56:18 | 00,000,000 | —D | C] – C:\Documents and Settings\Others\Desktop\FunSketches
[2009/08/02 10:35:04 | 00,000,028 | —- | C] () – C:\WINDOWS\PIMAREG.INI
[2009/03/30 21:20:41 | 00,389,175 | —- | C] () – C:\WINDOWS\System32\RsaFun.dll
[2009/03/30 21:20:41 | 00,282,734 | —- | C] () – C:\WINDOWS\System32\NPCard.dll
[2009/03/30 21:20:41 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\UnblkPIN.dll
[2009/03/30 21:20:39 | 00,049,152 | —- | C] () – C:\WINDOWS\System32\jcutilTdrUKLCD.dll
[2009/03/30 21:20:38 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\jcutilHUAUK.dll
[2009/03/30 21:20:38 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\jcutilHUAUKLCD.dll
[2009/03/30 21:20:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\jcutilgem101101.dll
[2009/03/30 21:20:36 | 00,027,136 | —- | C] () – C:\WINDOWS\System32\jcinGEM102.dll
[2009/03/30 21:20:34 | 00,023,040 | —- | C] () – C:\WINDOWS\System32\jcidGEM102.dll
[2009/03/30 21:20:33 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\hmukchk.dll
[2009/03/30 21:20:31 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\GEMPIN01.dll
[2009/03/30 21:20:30 | 00,184,320 | —- | C] () – C:\WINDOWS\System32\GdApi.dll
[2008/12/06 17:42:17 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2008/12/06 17:42:17 | 00,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2008/09/14 07:52:41 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\CmbSafeBase.dll
[2008/09/14 07:52:40 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\PBHttpComm.dll
[2006/09/03 19:18:39 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\jcinTHTFUK.dll
[2006/09/03 19:18:38 | 00,073,728 | —- | C] () – C:\WINDOWS\System32\jcidTHTFUK.dll
[2006/09/03 19:18:38 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\jcinpublic.dll
[2006/09/03 19:18:38 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\jcinHUAUK.dll
[2006/09/03 19:18:38 | 00,057,344 | —- | C] () – C:\WINDOWS\System32\jcidHUAUK.dll
[2006/09/03 19:18:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\jcinGEM101.dll
[2006/09/03 19:18:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\jcidGEM101.dll
[2006/09/03 19:18:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\jcidGD84.dll
[2006/09/03 19:18:38 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\jcinGD84.dll
[2006/09/03 19:18:38 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\jcidWATCHK.dll
[2006/09/03 19:18:37 | 00,262,208 | —- | C] () – C:\WINDOWS\System32\GPKPCSC.dll
[2006/09/03 19:18:37 | 00,241,758 | —- | C] () – C:\WINDOWS\System32\GPKPIN.dll
[2006/09/03 19:18:37 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\CEA_Crypt.dll
[2006/09/03 19:18:37 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\ChangPIN.dll
[2006/09/03 19:18:36 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\jcinWATCHK.dll
[2006/09/03 19:18:34 | 00,057,344 | —- | C] () – C:\WINDOWS\System32\USBKey.dll
[2006/08/10 06:58:31 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\70681b24.dll
[2006/08/10 06:58:28 | 00,000,030 | —- | C] () – C:\WINDOWS\System32\68af6bb3.dll
[2006/07/10 18:19:56 | 00,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/04/08 10:11:38 | 00,000,040 | —- | C] () – C:\WINDOWS\powerplayer.ini
[2006/03/22 10:03:02 | 00,000,040 | —- | C] () – C:\WINDOWS\nero.INI
[2006/03/21 19:47:12 | 00,085,360 | —- | C] () – C:\WINDOWS\System32\drivers\incdfs.sys
[2006/02/19 16:25:23 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\SynTPCoI.dll
[2006/02/14 17:25:44 | 00,000,009 | —- | C] () – C:\WINDOWS\winxfigt.sys
[2005/12/25 18:00:36 | 00,001,125 | —- | C] () – C:\WINDOWS\winamp.ini
[2005/11/16 10:40:42 | 00,684,032 | —- | C] () – C:\WINDOWS\libeay32.dll
[2005/11/16 10:40:42 | 00,155,648 | —- | C] () – C:\WINDOWS\ssleay32.dll
[2005/10/19 13:45:34 | 00,014,848 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2005/10/19 12:57:04 | 00,000,027 | —- | C] () – C:\WINDOWS\AdvConfig.ini
[2005/05/15 13:29:59 | 00,163,712 | —- | C] () – C:\WINDOWS\System32\drivers\vidstub.sys
[2005/04/28 13:51:17 | 00,049,152 | —- | C] () – C:\WINDOWS\System32\odlib.dll
[2005/03/28 16:36:38 | 00,000,116 | —- | C] () – C:\WINDOWS\ConverterCore.INI
[2005/02/11 23:36:33 | 00,006,852 | —- | C] () – C:\WINDOWS\System32\drivers\Vcs.sys
[2005/01/21 10:52:56 | 00,010,856 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2005/01/04 12:41:31 | 00,000,214 | —- | C] () – C:\WINDOWS\Gurunet.ini
[2005/01/03 14:25:15 | 00,000,206 | —- | C] () – C:\WINDOWS\EurekaLog.ini
[2004/12/25 10:46:48 | 00,000,064 | —- | C] () – C:\WINDOWS\eFaxView.ini
[2004/12/03 16:54:11 | 00,016,974 | —- | C] () – C:\WINDOWS\ePrompter.ini
[2004/11/06 17:11:28 | 00,000,806 | —- | C] () – C:\WINDOWS\UnitConverter.INI
[2004/10/27 06:39:05 | 03,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/10/08 08:08:11 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\stdsoap2.dll
[2004/08/28 22:33:27 | 00,000,024 | —- | C] () – C:\WINDOWS\LogonStudio.ini
[2004/08/28 22:30:55 | 00,187,392 | —- | C] () – C:\WINDOWS\System32\JPGUtils.dll
[2004/08/16 14:52:06 | 00,397,312 | —- | C] () – C:\WINDOWS\System32\CMBEdit.dll
[2004/07/24 17:44:02 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/07/03 20:32:40 | 00,000,000 | —- | C] () – C:\WINDOWS\audio.INI
[2004/07/03 20:20:24 | 00,000,173 | —- | C] () – C:\WINDOWS\srlink.ini
[2004/07/03 20:20:24 | 00,000,040 | —- | C] () – C:\WINDOWS\System32\sx96.ini
[2004/06/19 12:48:35 | 00,000,067 | —- | C] () – C:\WINDOWS\morphexe.INI
[2004/06/06 13:39:27 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/06/03 22:08:19 | 00,000,478 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/06/03 21:44:16 | 00,000,146 | —- | C] () – C:\WINDOWS\TBPlugin.INI
[2004/06/03 21:44:16 | 00,000,095 | —- | C] () – C:\WINDOWS\avconfig.ini
[2004/05/26 10:30:32 | 00,252,928 | —- | C] () – C:\WINDOWS\System32\astrolib32.dll
[2004/05/25 12:11:43 | 00,000,119 | —- | C] () – C:\WINDOWS\WSST_Screen_Saver.ini
[2004/05/24 09:05:31 | 00,000,227 | —- | C] () – C:\WINDOWS\SIMAQU~1.INI
[2004/04/03 16:53:17 | 00,000,037 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/03/09 14:50:36 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\ICMSetup532.dll
[2004/03/09 14:50:34 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\8532util.dll
[2004/02/03 21:09:07 | 00,000,093 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2003/10/16 10:48:44 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2003/10/14 18:43:32 | 00,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2003/09/05 18:18:30 | 00,000,048 | —- | C] () – C:\WINDOWS\Sierra.ini
[2003/05/27 14:49:00 | 00,041,984 | —- | C] () – C:\WINDOWS\System32\AQalphaGL.dll
[2003/05/14 19:48:08 | 00,000,068 | —- | C] () – C:\WINDOWS\FastAIT.INI
[2003/05/05 10:31:44 | 00,001,663 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/05/01 20:01:48 | 00,000,424 | —- | C] () – C:\WINDOWS\NJCOM.INI
[2003/05/01 12:15:04 | 00,000,023 | —- | C] () – C:\WINDOWS\NtsUninstall.ini
[2003/05/01 11:39:32 | 00,000,068 | —- | C] () – C:\WINDOWS\XDICT.INI
[2003/04/13 17:47:44 | 00,000,095 | —- | C] () – C:\WINDOWS\ntsautodial.ini
[2003/03/19 01:01:19 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/03/19 00:46:32 | 00,000,185 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/03/19 00:46:28 | 00,000,779 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/03/19 00:34:19 | 00,000,892 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/03/19 00:06:10 | 00,000,310 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2002/09/03 22:59:58 | 00,000,999 | —- | C] () – C:\WINDOWS\WIN.INI
[2002/09/03 22:50:58 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2002/03/21 15:39:02 | 00,073,728 | —- | C] () – C:\WINDOWS\System32\UNACEV2.DLL
[2001/10/08 18:59:28 | 00,000,821 | —- | C] () – C:\WINDOWS\txp-lcn.ini
[2001/10/08 13:24:26 | 00,148,544 | —- | C] () – C:\WINDOWS\System32\msvdm.dll
[2001/10/08 12:59:46 | 00,016,960 | —- | C] () – C:\WINDOWS\System32\mag.dll
[2000/11/24 18:05:06 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\Cpuinfo2.dll
[1999/03/16 17:32:33 | 00,000,136 | —- | C] () – C:\WINDOWS\System32\mstraps.dll
[1999/01/22 11:46:56 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1996/04/04 03:33:26 | 00,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys

========== Files - Modified Within 30 Days ==========

File not found – C:\Documents and Settings\Others\Desktop\CAZBDPKE.
[2009/09/23 08:55:50 | 00,514,560 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Others\Desktop\OTL.exe
[2009/09/23 08:45:00 | 00,350,201 | -H– | M] () – C:\WINDOWS\System32\vsconfig.xml
[2009/09/23 08:41:44 | 00,000,024 | —- | M] () – C:\WINDOWS\LogonStudio.ini
[2009/09/23 08:36:06 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/09/23 08:35:51 | 10,727,46496 | -HS- | M] () – C:\hiberfil.sys
[2009/09/22 22:08:00 | 00,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2009/09/22 12:45:28 | 00,055,568 | —- | M] () – C:\Documents and Settings\Others\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/09/22 12:26:16 | 00,200,936 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/09/22 12:22:55 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/09/22 04:29:59 | 00,000,424 | —- | M] () – C:\WINDOWS\NJCOM.INI
[2009/09/21 23:06:48 | 00,190,976 | —- | M] () – C:\Documents and Settings\Others\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/21 23:06:33 | 10,832,5437 | —- | M] () – C:\Documents and Settings\Others\Desktop\CollegeStudent-xbox.wmv
[2009/09/20 21:09:09 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/09/20 16:43:24 | 00,032,768 | —- | M] () – C:\Documents and Settings\Others\Desktop\LianQiao.doc
[2009/09/17 03:53:52 | 29,448,2944 | —- | M] () – C:\Documents and Settings\Others\Desktop\Breaststroke.with.Ed.Moses.and.Peter.Morgan.avi
[2009/09/16 22:40:43 | 00,931,683 | R— | M] () – C:\WINDOWS\System32\drivers\ETC\HOSTS
[2009/09/15 12:36:05 | 00,000,116 | —- | M] () – C:\WINDOWS\ConverterCore.INI
[2009/09/15 12:34:36 | 00,146,475 | —- | M] () – C:\Documents and Settings\Others\Desktop\APAsample.pdf
[2009/09/14 02:12:36 | 00,229,888 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/09/14 00:33:55 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/09/13 13:18:40 | 00,000,482 | —- | M] () – C:\WINDOWS\tasks\Malwarebytes' Scheduled Update for Others.job
[2009/09/13 13:18:37 | 00,693,760 | —- | M] () – C:\WINDOWS\is-V9TVU.exe
[2009/09/13 13:18:37 | 00,010,498 | —- | M] () – C:\WINDOWS\is-V9TVU.msg
[2009/09/13 13:18:37 | 00,000,460 | —- | M] () – C:\WINDOWS\is-V9TVU.lst
[2009/09/12 16:01:41 | 00,002,688 | —- | M] () – C:\WINDOWS\System32\settings.aaw
[2009/09/12 16:01:41 | 00,000,720 | —- | M] () – C:\WINDOWS\System32\history.aaw
[2009/09/11 15:06:17 | 00,157,446 | —- | M] () – C:\WINDOWS\hphins27.dat
[2009/09/11 13:28:35 | 00,000,037 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/09/11 12:53:22 | 60,397,9776 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2009/09/10 14:54:06 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/09/10 14:53:50 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/09/10 06:29:40 | 00,005,134 | —- | M] () – C:\WINDOWS\System32\OEMLOGO.BMP
[2009/09/10 06:29:40 | 00,000,310 | —- | M] () – C:\WINDOWS\System32\oeminfo.ini
[2009/09/09 23:30:20 | 00,930,401 | R— | M] () – C:\WINDOWS\System32\drivers\ETC\hosts.20090916-224043.backup
[2009/09/08 13:32:34 | 00,016,974 | —- | M] () – C:\WINDOWS\ePrompter.ini
[2009/09/05 12:38:07 | 00,928,211 | R— | M] () – C:\WINDOWS\System32\drivers\ETC\hosts.20090909-233020.backup
[2009/08/29 05:38:20 | 24,689,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/08/27 23:06:27 | 00,926,439 | R— | M] () – C:\WINDOWS\System32\drivers\ETC\hosts.20090905-123806.backup

========== Alternate Data Streams ==========

@Alternate Data Stream - 284 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 182 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:28BB1CE8
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
OTL Extras logfile created on: 9/23/2009 9:00:39 AM - Run 1
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\Others\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.98 Mb Total Physical Memory | 583.54 Mb Available Physical Memory | 57.04% Memory free
1.47 Gb Paging File | 1.06 Gb Available in Paging File | 72.03% Paging File free
Paging file location(s): c:\pagefile.sys 576 1152 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 27.91 Gb Total Space | 1.28 Gb Free Space | 4.58% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: Tom_q2356
Current User Name: Others
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
chm.file [open] – "%SYSTEMROOT%\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Directory [ACDBrowse] – "C:\Program Files\ACD Systems\ACDSee\8.0.Pro\ACDSee8Pro.exe" "%1" (ACD Systems Ltd.)
Directory [cmd] – cmd.exe /k "cd %L" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [JPEGScan] – blank File not found
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"25:TCP" = 25:TCP:*:Enabled:File and Printer Sharing
"8529:TCP" = 8529:TCP:*:Enabled:yduq

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe" = C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe:*:Enabled:TrueVector Service – (Check Point Software Technologies LTD)
"C:\Program Files\IncrediMail\bin\IncMail.exe" = C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\bin\IMApp.exe" = C:\Program Files\IncrediMail\bin\IMApp.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\PPLive\PPLive.exe" = C:\Program Files\PPLive\PPLive.exe:*:Enabled:PPLive – ()
"C:\Program Files\IEPro\MiniDM.exe" = C:\Program Files\IEPro\MiniDM.exe:*:Enabled:MiniDM – (IE7Pro.com)
"C:\Program Files\IncrediMail\bin\ImLc.exe" = C:\Program Files\IncrediMail\bin\ImLc.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\bin\ImpCnt.exe" = C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\ICQ6\ICQ.exe" = C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6 – (ICQ, Inc.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)
"C:\Program Files\KWMUSIC\KwMusic.exe" = C:\Program Files\KWMUSIC\KwMusic.exe:*:Enabled:¿áÎÒÒôÀֺР– (????)
"C:\Program Files\KWMUSIC\KwMV.exe" = C:\Program Files\KWMUSIC\KwMV.exe:*:Enabled:¿áÎÒMV´«ÊäÒýÇæ – ()
"C:\Program Files\China Mobile\Fetion\FetionFX.exe" = C:\Program Files\China Mobile\Fetion\FetionFX.exe:*:Enabled:Fetion – (China Mobile)
"C:\Program Files\China Mobile\Fetion\VMDotNet\v2.0.50727\FetionVM.exe" = C:\Program Files\China Mobile\Fetion\VMDotNet\v2.0.50727\FetionVM.exe:*:Enabled:FetionVM – (China Mobile)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Premium
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{0712667C-A171-49AE-A098-4ACDA28625F8}" = Sony Sound Forge 7.0
"{07620C4F-0964-4086-A872-C9C12E418E52}" = DJ_SF_03_D4300_Software
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0F6A7971-0F11-4A79-A0E9-133D0963A570}" = ISO Recorder
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert
"{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}" = QuickTime
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1a8b4ccf-4f49-4210-89e3-4b31141493b0}" = RelevantKnowledge
"{20227921-DB38-4810-9162-DDC6FCA936E7}" = Dell Home Systems Services Agreement
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{24EFA94F-F3D6-4386-8824-B54712C9DC88}" = D4300_Help
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{29D88826-2AB9-11D5-8854-00902761A46D}" = WordPerfect Office 2002
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{387D9916-BD27-480f-8CF0-3228832BBAA2}" = HP Deskjet D4300 Printer Driver Software 10.0 Rel .3
"{38B122B2-3257-4E43-BD51-327599ECBA46}" = 中国工商银行防钓鱼软件
"{395131D0-71C3-4411-8DDD-84E7A4EC8754}" = Intellisync® for Yahoo!
"{3FD3DF65-694C-4F71-97BA-1A70BB2B8B9C}" = ICM532
"{417B79C9-CDB4-477F-952D-840CEFC57A6C}" = AccessDirect
"{42C7C4D8-033E-44F9-BF34-43808A0686CC}" = D4300
"{43FCA273-9534-40DB-B7C5-D7758875616A}" = Dell Support
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{468190DA-FB4C-45BA-8E40-4B165FF1A939}" = BACS
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
"{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}" = NETGEAR WG111v3 wireless USB 2.0 adapter
"{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}" = iTunes
"{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6C31E111-96BB-4ADC-9C81-E6D3EEDDD8D3}" = Powertoys For Windows XP
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7B738CD9-D107-48C7-8E65-2E6639A39C8D}" = PerfectDisk 10 Professional
"{7CF065E2-7816-4440-9019-034A2285F9DF}" = Tweak-XP
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{82C8658D-58A9-4855-ADF2-2448C9410F29}" = Internet PrintWhere 2.6
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B0A7592-2AE0-48EA-A327-6EB7DAB25E4A}" = DJ_SF_03_D4300_Software_Min
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95F62044-BD5E-44DC-928E-8224297E9B4B}" = Lock Folder XP v3.2
"{98B6FB8A-8638-4037-AD44-CF7D0EEAB874}_is1" = TypingMaster TypingTest
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD
"{98FDC595-92B3-48D5-80D6-FE7AABD9191B}_is1" = Weather Watcher Live
"{9BC76CCE-A9EC-4A3A-9B51-D823805E1D1F}" = SolidConverterPDF
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A0B9F8DF-C949-45ed-9808-7DC5C0C19C81}" = Status
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2A60894-E3ED-46FE-9A6A-7CF7A87572A0}" = Opera 9.64
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{A743BBCC-3438-4BB3-8397-6C9D9AC125A6}" = Timershot Powertoy for Windows XP
"{A900E37C-AAE3-44FB-8EE7-7E61F7087CE7}" = SnagIt 8
"{AB18B0BA-A08F-48B8-8D0E-AA9DDDCA22EA}" = CuteFTP 6 Professional
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.3
"{AC76BA86-7AD7-2447-5A64-7E8A45000001}" = Adobe Reader Chinese Simplified Fonts
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{B98B1E3C-B6BE-40C3-993F-B96E4E1D1486}" = ICBC NetBank Client Controls
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}" = Pando
"{C3BDF1C8-66EF-4A0F-B427-A99E39706F45}_is1" = RMVB Converter 1.8
"{C46A5F24-B91F-477C-B634-DB99A7D7792A}" = TablePCRT
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Professional
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{D6B79F07-62D1-46C9-A225-625ACC748144}" = Diskeeper Professional Premier Edition
"{DB6BD5D5-8482-45C0-99CF-745C5B924497}" = WOT for Internet Explorer
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E60A3FF1-856E-4DD2-BFC6-FD9B976FE1C5}" = DJ_SF_03_D4300_ProductContext
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{F99F74B4-972B-4B06-B893-6B3B0DB0128B}" = ACDSee Pro
"1-Click Answers" = 1-Click Answers
"AbsoluteShield File Shredder_is1" = AbsoluteShield File Shredder
"AbsoluteShield Internet Eraser Pro_is1" = AbsoluteShield Internet Eraser Pro
"Ace Utilities_is1" = Ace Utilities 2.4.1
"Active Security Monitor_is1" = Active Security Monitor 1.0.0.315
"Active WebCam" = Active WebCam
"ActiveXControlPad" = Microsoft ActiveX Control Pad
"Ad-Aware" = Ad-Aware
"AddWeb 7 Pro" = AddWeb 7 Pro
"Adobe AIR" = Adobe AIR
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AI RoboForm" = AI RoboForm (All Users)
"AMF Daily Planner and PIM" = AMF Daily Planner and PIM
"AQ3D" = Aquatica 3D
"AqSceneMaker" = Aquatica Scenery Maker
"Aquatica3" = Aquatica 3
"Ashampoo UnInstaller Platinum 2" = Ashampoo UnInstaller Platinum 2
"Ashampoo WinOptimizer 6_is1" = Ashampoo WinOptimizer 6.30
"AskPBar Uninstall" = Ask Toolbar
"ATI Display Driver" = ATI Display Driver
"AV Voice Changer Software 3.0" = AV Voice Changer Software 3.0
"avast!" = avast! Antivirus
"Babylon" = Babylon
"BadCopy Pro" = BadCopy Pro
"BCDP7_is1" = Business Card Designer Plus 7.3.0.0
"Biz-Plan" = Biz-Plan
"BootSkin" = BootSkin
"Camfrog 5.3" = Camfrog Video Chat 5.3
"Camfrog Server 3.2" = Camfrog Server 3.2 (remove only)
"CMBPB40" = ÕÐÐÐרҵ°æ
"CNXT_MODEM_PCI_VEN_8086&DEV_24x6&SUBSYS_542214F1" = Conexant D480 MDC V.92 Modem
"CoffeeCup HTML Editor" = CoffeeCup HTML Editor
"CursorXP" = CursorXP
"Customizer XP_is1" = Customizer XP
"CyberBuddy" = CyberBuddy
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"DesktopX Professional" = DesktopX Professional
"DreamAqua" = Dream Aquarium
"DSBACK1_is1" = Additional Background Pack 1
"DSCLIP1_is1" = Additional Clipart Pack 1
"DSCLIPBW_is1" = Additional Clipart Pack BW
"Easy Video Joiner_is1" = Easy Video Joiner 5.21
"ePrompter" = ePrompter
"EPSON Printer and Utilities" = EPSON Printer Software
"Fetion" = Fetion 2008
"FileSpecs extension for Ad-aware 6" = FileSpecs extension for Ad-aware 6
"Flight Simulator Screensaver" = Flight Simulator Screensaver 0.9
"Free Internet TV_is1" = Free Internet TV v3.5
"FreshDevices - FreshDiagnose_is1" = FreshDiagnose
"FTP Voyager_is1" = FTP Voyager 11.0
"FunPhotor_is1" = FunPhotor 6.0
"GetRight Pro" = GetRight Pro
"Good Sync_is1" = Good Sync version 4.6.10
"HexDump extension for Ad-aware 6" = HexDump extension for Ad-aware 6
"Highway Pursuit_is1" = Highway Pursuit
"HijackThis" = HijackThis 2.0.2
"Holding Pattern" = Holding Pattern Screen Saver
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"IconPackager" = IconPackager
"iDailyDiary_is1" = iDailyDiary 3.52
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"IE7Pro" = IE7Pro
"ie8" = Windows Internet Explorer 8
"imageN 1.4b_is1" = imageN 1.4b
"InCD!UninstallKey" = Ahead InCD
"IncrediBar" = IncrediBar
"IncrediMail" = IncrediMail Xe
"InstallShield_{468190DA-FB4C-45BA-8E40-4B165FF1A939}" = Broadcom Advanced Control Suite
"InstallShield_{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}" = NETGEAR WG111v3 wireless USB 2.0 adapter
"InstallShield_{AB18B0BA-A08F-48B8-8D0E-AA9DDDCA22EA}" = CuteFTP 6 Professional
"Konvertor" = Konvertor
"KwMusic" = Ð¶ÔØ¿áÎÒÒôÀÖºÐ
"LDPD7_is1" = Label Designer Plus DELUXE 7.3.0.0
"LimeWire" = LimeWire PRO 5.2.8
"LogonStudio" = LogonStudio
"LSP Explorer Pluginfor Ad-aware 6" = LSP Explorer Pluginfor Ad-aware 6
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Messenger Control Plugin for Ad-aware" = Messenger Control Plugin for Ad-aware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Mozilla Firefox (3.0.13)" = Mozilla Firefox (3.0.13)
"MRW!UninstallKey" = Ahead InCD EasyWrite Reader
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
"myBabylon_English Toolbar" = myBabylon_English Toolbar
"Nero - Burning Rom!UninstallKey" = Ahead Nero Burning ROM
"Nero BurnRights!UninstallKey" = Ahead Nero BurnRights
"NeroVision!UninstallKey" = Ahead NeroVision Express
"NJStar Communicator" = NJStar Communicator
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NMIX!UninstallKey" = Ahead NeroMIX
"ObjectDock Plus" = ObjectDock Plus
"phoenix.zip" = phoenix.zip
"Picasa 3" = Picasa 3
"PPLive" = PPLive 1.9
"PSN" = Post-it® Software Notes
"RealPlayer 6.0" = RealPlayer
"Registry Mechanic_is1" = Registry Mechanic 8.0
"SereneScreen Marine Aquarium 2_is1" = SereneScreen Marine Aquarium 2
"ShenProfessional 3.0" = ShenProfessional 3.0
"Shop for HP Supplies" = Shop for HP Supplies
"SimAQUARIUM2 Free_is1" = SimAQUARIUM2 Free
"SlimBrowser" = SlimBrowser (remove only)
"SpeedFan" = SpeedFan (remove only)
"SpywareBlaster_is1" = SpywareBlaster 4.2
"SpywareGuard_is1" = SpywareGuard v2.2
"Startup Faster! 2004_is1" = Startup Faster! 2004
"SwitchOff" = Switch Off
"Synacast Plug-in" = Synacast Plug-in [removed]
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Teleport Pro" = Teleport Pro
"TimeLeft 2.16_is1" = TimeLeft FREEWARE edition
"Trash Killer" = Trash Killer 2
"TreeSize Professional_is1" = TreeSize Professional 3.3.3
"Trillian" = Trillian
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"TypingMaster Pro" = TypingMaster Pro
"TZ Connection Booster_is1" = TZ Connection Booster 2.6
"UnixUtils for Yahoo! Widgets" = Unix Utilities for Yahoo! Widgets
"Video Fixer 3.21_is1" = Video Fixer 3.21
"Vital Desktop" = Vital Desktop (remove only)
"Volutive 1" = Volutive 1
"vTuner Plus" = vTuner Plus
"Water Screen Saver" = Water Screen Saver 1.1
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Weather Watcher_is1" = Weather Watcher
"Webshots Desktop_is1" = Webshots Desktop
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar for Internet Explorer
"Windows Live Safety scanner" = Windows Live Safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows Scheduler_is1" = System Scheduler 3.31
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinISO_is1" = WinISO 5.3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinMPG Video Convert 3.1" = WinMPG Video Convert 3.1
"WinPatrol" = WinPatrol
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WinZip Self-Extractor" = WinZip Self-Extractor
"Wisdom-soft ScreenHunter 4.0 Free" = Wisdom-soft ScreenHunter 4.0 Free
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WordPerfect Office 2002" = WordPerfect Office 2002
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"X1 Desktop Search" = X1
"Yahoo! Anti-Spy" = Yahoo! Anti-Spy
"Yahoo! Central" = Yahoo! Central
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Customizations" = Yahoo! Browser Services
"Yahoo! Mail AutoComplete" = Yahoo! Address AutoComplete
"Yahoo! Photos Drag-Drop Uploader 1v7" = Yahoo! Photos Easy Upload Tool 1v7
"Yahoo! Toolbar" = Yahoo! Toolbar
"Yahoo! Widget Engine" = Yahoo! Widgets
"YInstHelper" = Yahoo! Install Manager
"ymb" = Yahoo! Mail Quick Select Tool (PhotoMail)
"ZoneAlarm Pro" = ZoneAlarm Pro

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 12/15/2008 10:26:59 PM | Computer Name = Tom_q2356 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Others\My Documents\My Pictures\DifferentIndividuals\YouYiMeiTian\MayTian@WuTong\AllMeiLan\My
music\Chinese music\??.mp3 failed, 00000005.

Error - 12/15/2008 10:27:13 PM | Computer Name = Tom_q2356 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Others\My Documents\My Pictures\DifferentIndividuals\YouYiMeiTian\MayTian@WuTong\AllMeiLan\My
music\Chinese music\8.mp3 failed, 00000005.

Error - 12/15/2008 10:27:44 PM | Computer Name = Tom_q2356 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Others\My Documents\My Pictures\DifferentIndividuals\YouYiMeiTian\MayTian@WuTong\AllMeiLan\My
music\Chinese music\right here waiting.mp3 failed, 00000005.

Error - 12/15/2008 10:27:58 PM | Computer Name = Tom_q2356 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Others\My Documents\My Pictures\DifferentIndividuals\YouYiMeiTian\MayTian@WuTong\AllMeiLan\My
music\Chinese music\2182c8a9fdcd103e1feee848eb72e49f.mp3 failed, 00000005.

Error - 12/15/2008 10:28:08 PM | Computer Name = Tom_q2356 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Others\My Documents\My Pictures\DifferentIndividuals\YouYiMeiTian\MayTian@WuTong\AllMeiLan\My
music\Chinese music\Elvis Presley - Fever.mp3 failed, 00000005.

Error - 12/15/2008 10:28:22 PM | Computer Name = Tom_q2356 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Others\My Documents\My Pictures\DifferentIndividuals\YouYiMeiTian\MayTian@WuTong\AllMeiLan\My
music\Chinese music\One more time.mp3 failed, 00000005.

Error - 12/15/2008 10:28:32 PM | Computer Name = Tom_q2356 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Others\My Documents\My Pictures\DifferentIndividuals\YouYiMeiTian\MayTian@WuTong\AllMeiLan\My
music\Chinese music\06 Hotel California.wma failed, 00000005.

Error - 12/15/2008 10:28:41 PM | Computer Name = Tom_q2356 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Others\My Documents\My Pictures\DifferentIndividuals\YouYiMeiTian\MayTian@WuTong\AllMeiLan\My
music\Chinese music\WSQSZSQ.mp3 failed, 00000005.

Error - 12/15/2008 10:28:56 PM | Computer Name = Tom_q2356 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Others\My Documents\My Pictures\DifferentIndividuals\YouYiMeiTian\MayTian@WuTong\AllMeiLan\My
music\Chinese music\2006041405.mp3 failed, 00000005.

Error - 12/15/2008 10:29:14 PM | Computer Name = Tom_q2356 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Documents and Settings\Others\My Documents\My Pictures\DifferentIndividuals\YouYiMeiTian\MayTian@WuTong\AllMeiLan\My
music\Chinese music\lan.mp3 failed, 00000005.

[ Application Events ]
Error - 8/9/2009 12:07:42 PM | Computer Name = Tom_q2356 | Source = Application Error | ID = 1000
Description = Faulting application winamp.exe, version 5.5.1.1763, faulting module
oleaut32.dll, version 5.1.2600.5512, fault address 0x00004958.

Error - 8/9/2009 11:55:55 PM | Computer Name = Tom_q2356 | Source = Application Error | ID = 1000
Description = Faulting application spybotsd.exe, version 1.6.2.46, faulting module
spybotsd.exe, version 1.6.2.46, fault address 0x0001eba2.

Error - 8/13/2009 11:35:26 AM | Computer Name = Tom_q2356 | Source = Application Error | ID = 1000
Description = Faulting application camfrog video chat.exe, version 5.3.0.215, faulting
module controls.dll, version 5.3.0.215, fault address 0x0000161a.

Error - 8/29/2009 10:15:11 AM | Computer Name = Tom_q2356 | Source = Application Error | ID = 1000
Description = Faulting application webshots.scr, version 3.1.1.7317, faulting module
mfc42.dll, version 6.2.4131.0, fault address 0x0000497d.

Error - 9/6/2009 12:14:49 PM | Computer Name = Tom_q2356 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 SR-1 Premium – Error 1706. No valid
source could be found for product Microsoft Office 2000 SR-1 Premium. The Windows
installer cannot continue.

Error - 9/7/2009 12:30:27 PM | Computer Name = Tom_q2356 | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x00000000.

Error - 9/11/2009 1:24:38 AM | Computer Name = Tom_q2356 | Source = MsiInstaller | ID = 11904
Description = Product: SolutionCenter – Error 1904. Module C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx
failed to register. HRESULT -2147220473. Contact your support personnel.

Error - 9/13/2009 12:05:21 PM | Computer Name = Tom_q2356 | Source = Application Error | ID = 1000
Description = Faulting application ad-aware.exe, version 7.1.0.12, faulting module
, version 0.0.0.0, fault address 0x00000000.

Error - 9/13/2009 12:06:20 PM | Computer Name = Tom_q2356 | Source = Application Error | ID = 1000
Description = Faulting application ad-aware.exe, version 7.1.0.12, faulting module
ad-aware.exe, version 7.1.0.12, fault address 0x0009659a.

Error - 9/13/2009 12:30:43 PM | Computer Name = Tom_q2356 | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

[ System Events ]
Error - 9/22/2009 8:41:24 PM | Computer Name = Tom_q2356 | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 9/22/2009 8:44:26 PM | Computer Name = Tom_q2356 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 9/22/2009 8:44:26 PM | Computer Name = Tom_q2356 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 9/22/2009 8:44:26 PM | Computer Name = Tom_q2356 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 9/22/2009 8:44:27 PM | Computer Name = Tom_q2356 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 9/22/2009 8:44:27 PM | Computer Name = Tom_q2356 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 9/22/2009 8:44:28 PM | Computer Name = Tom_q2356 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 9/22/2009 8:44:28 PM | Computer Name = Tom_q2356 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 9/22/2009 8:44:28 PM | Computer Name = Tom_q2356 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 9/22/2009 8:45:26 PM | Computer Name = Tom_q2356 | Source = Service Control Manager | ID = 7034
Description = The ICBC Daemon Service service terminated unexpectedly. It has done
this 1 time(s).


< End of report >
Thanks agian TomK,

Yes, Avast has detected and deleted them. However, they should still be in the system, I feel it by experience. If I do one more scan, they will appear in my Avast chest log again for sure. So do you have a way to replace them with the original files from Microsoft? Thanks so much.

Tom_q2356
Tom_q2356,

You've got nothing better to do right now right?

Let's do some more snooping:

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    kernel32.dll 
    winsock.dll 
    wsock32.dll
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
SystemLook v1.0 by jpshortstuff (29.08.09) Log created at 21:45 on 23/09/2009 by Others (Administrator - Elevation successful) ========== filefind ========== Searching for "kernel32.dll " No files found. Searching for "winsock.dll " No files found. Searching for "wsock32.dll" C:\I386\WSOCK32.DLL –a— 21504 bytes [22:23 26/03/2003] [11:00 29/08/2002] 2645B52F630966198317E43BBB1AF102 C:\WINDOWS\$NtServicePackUninstall$\wsock32.dll —–c 22528 bytes [10:20 29/09/2008] [07:56 04/08/2004] 53AF9F2B2CE4B6EFF41C70417359D010 C:\WINDOWS\ServicePackFiles\i386\wsock32.dll —— 22528 bytes [07:56 04/08/2004] [00:12 14/04/2008] 67156D5A9AC356DC99D7BCCB388E3316 C:\WINDOWS\SYSTEM32\wsock32.dll –a— 22528 bytes [17:14 03/09/2002] [00:12 14/04/2008] 67156D5A9AC356DC99D7BCCB388E3316 -=End Of File=-
I feel like you are the one who knows how to deal with this because you have this patience and persistence. Be honest with you, I have never so many people viewing my threads within such a short period of time. It is either they are interested in this topic or attracted by your knowledge. Thanks again TomK for your continuing help and I am proud to be one of the members who is loyal to TomCoyote forum!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI