OTL logfile created on: 9/23/2009 9:00:39 AM - Run 1
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\Others\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.98 Mb Total Physical Memory | 583.54 Mb Available Physical Memory | 57.04% Memory free
1.47 Gb Paging File | 1.06 Gb Available in Paging File | 72.03% Paging File free
Paging file location(s): c:\pagefile.sys 576 1152 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 27.91 Gb Total Space | 1.28 Gb Free Space | 4.58% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: Tom_q2356
Current User Name: Others
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2009/08/17 23:58:55 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/07/03 22:49:06 | 01,029,456 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009/08/18 00:07:17 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2002/11/08 12:22:10 | 00,147,456 | —- | M] () – C:\WINDOWS\System32\Ati2evxx.exe
PRC - [2006/06/07 12:46:24 | 00,942,080 | —- | M] (Diskeeper Corporation) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
PRC - [2001/03/29 02:00:00 | 00,102,400 | —- | M] (SEIKO EPSON CORPORATION) – C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
PRC - [2003/07/13 02:49:24 | 00,766,004 | —- | M] () – C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2009/07/15 14:44:03 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/09/10 14:54:02 | 00,269,648 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2003/11/13 16:51:56 | 00,253,952 | —- | M] (Stardock) – C:\Program Files\Common Files\Stardock\SDMCP.exe
PRC - [2008/04/14 08:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2003/12/17 17:43:04 | 00,118,784 | —- | M] (Softarium.com) – C:\Program Files\reliz\akeys.exe
PRC - [2002/11/08 11:00:00 | 00,294,912 | —- | M] (ATI Technologies, Inc.) – C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
PRC - [2005/11/15 13:50:46 | 00,222,784 | —- | M] (BillP Studios) – C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
PRC - [2009/02/15 23:10:22 | 00,981,384 | —- | M] (Check Point Software Technologies LTD) – C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2003/03/01 16:25:28 | 00,138,240 | —- | M] ( ) – C:\Program Files\CursorXP\CursorXP.exe
PRC - [2002/09/12 23:28:14 | 00,024,576 | —- | M] (BVRP Software) – C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2006/03/23 00:13:46 | 01,591,808 | —- | M] (YourWare Solutions ™) – C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
PRC - [2006/07/08 11:36:08 | 00,358,400 | —- | M] (URSoft,Inc) – C:\Program Files\Startup Faster 2004\sfAgent.exe
PRC - [2009/08/18 00:07:01 | 00,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2002/08/29 19:00:00 | 00,016,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wbem\unsecapp.exe
PRC - [2009/02/06 18:10:02 | 00,227,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wbem\wmiprvse.exe
PRC - [2009/08/18 00:04:21 | 00,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2003/08/29 19:05:35 | 00,360,448 | —- | M] () – C:\Program Files\SpywareGuard\sgmain.exe
PRC - [2009/08/18 00:07:23 | 00,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2003/08/29 11:14:56 | 00,233,472 | —- | M] () – C:\Program Files\SpywareGuard\sgbhp.exe
PRC - [2009/09/23 08:55:50 | 00,514,560 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Others\Desktop\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - [2008/04/14 08:11:48 | 00,100,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\6to4svc.dll – (6to4 [Auto | Running])
SRV - [2006/01/03 14:59:23 | 00,068,096 | —- | M] () – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe – (Adobe LM Service [On_Demand | Stopped])
SRV - [2008/07/25 11:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2009/08/17 23:58:55 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv [Auto | Running])
SRV - [2002/11/08 12:22:10 | 00,147,456 | —- | M] () – C:\WINDOWS\System32\Ati2evxx.exe – (Ati HotKey Poller [Auto | Running])
SRV - [2009/08/18 00:07:17 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus [Auto | Running])
SRV - [2009/08/18 00:07:01 | 00,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/08/18 00:04:21 | 00,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner [On_Demand | Running])
SRV - [2008/07/25 11:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009/01/09 12:46:24 | 00,410,976 | —- | M] (mst software GmbH, Germany) – C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe – (DfSdkS [On_Demand | Stopped])
SRV - [2006/06/07 12:46:24 | 00,942,080 | —- | M] (Diskeeper Corporation) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe – (Diskeeper [Auto | Running])
SRV - [2001/03/29 02:00:00 | 00,102,400 | —- | M] (SEIKO EPSON CORPORATION) – C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe – (EPSONStatusAgent2 [Auto | Running])
SRV - [2008/07/29 21:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2009/03/03 14:53:08 | 00,033,176 | —- | M] (NOS Microsystems Ltd.) – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe – (getPlus® Helper [Disabled | Stopped])
SRV - [2008/11/21 03:18:52 | 00,136,120 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [On_Demand | Stopped])
SRV - [2008/04/14 08:12:02 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Disabled | Stopped])
SRV - [2007/11/06 21:16:54 | 00,217,088 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll – (hpqcxs08 [On_Demand | Running])
SRV - [2007/11/06 21:16:54 | 00,139,264 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll – (hpqddsvc [Auto | Running])
SRV - [2009/07/08 16:17:50 | 00,397,192 | —- | M] () – C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\IcbcDaemon.exe – (ICBC Daemon Service [Auto | Stopped])
SRV - [2005/04/04 00:41:10 | 00,069,632 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2003/07/13 02:49:24 | 00,766,004 | —- | M] () – C:\Program Files\Ahead\InCD\InCDsrv.exe – (InCDsrv [Auto | Running])
SRV - [2001/10/08 12:59:36 | 00,049,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\Fast.exe – (InteractiveLogon [Auto | Stopped])
SRV - [2008/03/30 10:36:30 | 00,504,104 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Stopped])
SRV - [2009/07/15 14:44:03 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2009/07/03 22:49:06 | 01,029,456 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service [Auto | Running])
SRV - [2009/09/10 14:54:02 | 00,269,648 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService [Auto | Running])
SRV - [2008/07/29 19:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/04/14 08:12:02 | 00,105,472 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\p2pgasvc.dll – (p2pgasvc [On_Demand | Stopped])
SRV - [2009/07/17 11:10:16 | 00,931,080 | —- | M] (Raxco Software, Inc.) – C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe – (PDAgent [On_Demand | Stopped])
SRV - [2009/07/17 11:10:18 | 01,033,480 | —- | M] (Raxco Software, Inc.) – C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe – (PDEngine [On_Demand | Stopped])
SRV - File not found – – (rpcapd [On_Demand | Stopped])
SRV - [2009/02/15 23:10:22 | 02,402,184 | —- | M] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe – (vsmon [Auto | Stopped])
SRV - [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [Disabled | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2009/08/18 00:03:21 | 00,026,944 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys – (Aavmker4 [System | Running])
DRV - [2008/12/07 17:29:59 | 00,021,035 | —- | M] (Meetinghouse Data Communications) – C:\WINDOWS\System32\DRIVERS\AegisP.sys – (AegisP [Auto | Running])
DRV - [2001/04/26 09:04:00 | 00,117,984 | R— | M] (Agilent Technologies) – C:\WINDOWS\System32\DRIVERS\Atusbcam.sys – (AgilentUSBCam [On_Demand | Running])
DRV - [2002/09/04 00:27:16 | 00,005,248 | —- | M] (Acer Laboratories Inc.) – C:\WINDOWS\System32\DRIVERS\aliide.sys – (AliIde [Disabled | Stopped])
DRV - [2008/04/14 02:36:39 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.) – C:\WINDOWS\System32\DRIVERS\amdagp.sys – (amdagp [Disabled | Stopped])
DRV - [2002/09/04 00:27:30 | 00,026,496 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\System32\DRIVERS\asc.sys – (asc [Disabled | Stopped])
DRV - [2002/09/04 00:27:30 | 00,014,848 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\System32\DRIVERS\asc3550.sys – (asc3550 [Disabled | Stopped])
DRV - [1999/09/10 19:06:00 | 00,025,244 | —- | M] (Adaptec) – C:\WINDOWS\System32\drivers\aspi32.sys – (Aspi32 [Auto | Running])
DRV - [2009/08/18 00:05:37 | 00,020,560 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys – (aswFsBlk [Auto | Running])
DRV - [2009/08/18 00:06:43 | 00,094,160 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys – (aswMon2 [Auto | Running])
DRV - [2009/08/18 00:04:29 | 00,023,152 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys – (aswRdr [On_Demand | Running])
DRV - [2009/08/18 00:05:52 | 00,114,768 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys – (aswSP [System | Running])
DRV - [2009/08/18 00:04:40 | 00,051,376 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys – (aswTdi [System | Running])
DRV - [2002/11/08 12:31:36 | 00,539,392 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys – (ati2mtag [On_Demand | Running])
DRV - [2002/12/18 01:36:42 | 00,042,368 | —- | M] (Broadcom Corporation) – C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys – (bcm4sbxp [On_Demand | Running])
DRV - [2007/01/23 22:36:20 | 00,006,016 | —- | M] (Motorola Inc) – C:\WINDOWS\System32\DRIVERS\motfilt.sys – (BTCFilterService [On_Demand | Stopped])
DRV - [2006/05/20 05:16:24 | 00,002,432 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdr4_xp.sys – (Cdr4_xp [System | Running])
DRV - [2006/05/20 05:16:24 | 00,002,560 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdralw2k.sys – (Cdralw2k [System | Running])
DRV - [2006/11/30 16:31:20 | 00,003,038 | —- | M] () – C:\WINDOWS\System32\Drivers\CertClient.dat – (CMB8100 [Auto | Running])
DRV - [2007/01/18 14:28:34 | 00,003,584 | —- | M] () – C:\WINDOWS\System32\Drivers\CMBProtector.dat – (CMBProtector [Auto | Running])
DRV - [2002/09/04 00:29:01 | 00,006,656 | —- | M] (CMD Technology, Inc.) – C:\WINDOWS\System32\DRIVERS\cmdide.sys – (CmdIde [Disabled | Stopped])
DRV - [2002/09/04 00:30:26 | 00,179,584 | —- | M] (Mylex Corporation) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys – (dac2w2k [Disabled | Stopped])
DRV - [2002/07/10 21:13:00 | 00,095,232 | —- | M] (IC Media Corporation) – C:\WINDOWS\System32\Drivers\usbuvt.sys – (DCamUSBUVT [On_Demand | Stopped])
DRV - [2009/06/08 10:00:56 | 00,071,696 | —- | M] (Raxco Software, Inc.) – C:\WINDOWS\System32\drivers\DefragFs.sys – (DefragFS [Auto | Running])
DRV - [2006/04/26 20:12:14 | 00,011,941 | —- | M] (Mjtsai Corp) – C:\WINDOWS\System32\DRIVERS\MotoVisionDP.sys – (DirectDrv [On_Demand | Running])
DRV - [2002/07/02 11:12:42 | 00,002,410 | —- | M] () – C:\Program Files\FreshDevices\FreshDiagnose\FreshIO.sys – (FreshIO [On_Demand | Stopped])
DRV - [2002/09/04 00:31:57 | 00,012,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\fsvga.sys – (FsVga [System | Running])
DRV - [2008/01/29 12:01:28 | 00,016,168 | —- | M] (GEAR Software Inc.) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [1996/04/04 03:33:26 | 00,005,248 | —- | M] () – C:\WINDOWS\system32\giveio.sys – (giveio [Boot | Running])
DRV - [2002/10/18 01:52:44 | 00,159,652 | —- | M] (Conexant Systems) – C:\WINDOWS\System32\DRIVERS\HSFHWICH.sys – (HSFHWICH [On_Demand | Running])
DRV - [2002/10/18 01:50:56 | 01,174,128 | —- | M] (Conexant Systems) – C:\WINDOWS\System32\DRIVERS\HSF_DP.sys – (HSF_DP [On_Demand | Running])
DRV - [2004/08/04 13:29:36 | 00,161,020 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\i81xnt5.sys – (i81x [On_Demand | Stopped])
DRV - [2004/08/04 13:29:37 | 00,012,415 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wADV01nt.sys – (iAimFP0 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:37 | 00,012,127 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wADV02NT.sys – (iAimFP1 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:37 | 00,011,775 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wADV05NT.sys – (iAimFP2 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:47 | 00,012,063 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys – (iAimFP3 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:49 | 00,019,455 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys – (iAimFP4 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:41 | 00,029,311 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wATV01nt.sys – (iAimTV0 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:42 | 00,019,551 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wATV02NT.sys – (iAimTV1 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:43 | 00,033,599 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wATV04nt.sys – (iAimTV3 [On_Demand | Stopped])
DRV - [2004/08/04 13:29:45 | 00,023,615 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys – (iAimTV4 [On_Demand | Stopped])
DRV - [2001/11/05 14:54:38 | 00,014,182 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\DRIVERS\icm10blk.sys – (icm10blk [On_Demand | Stopped])
DRV - [2001/11/05 14:54:14 | 00,420,870 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\Drivers\ICM10USB.sys – (ICM10USB [On_Demand | Stopped])
DRV - [2003/07/13 02:49:24 | 00,085,360 | —- | M] () – C:\WINDOWS\System32\drivers\incdfs.sys – (InCDfs [Disabled | Running])
DRV - [2003/07/13 02:49:24 | 00,026,784 | —- | M] (Ahead Software) – C:\WINDOWS\System32\DRIVERS\InCDPass.sys – (InCDPass [System | Running])
DRV - [2003/07/13 02:49:18 | 00,023,920 | —- | M] (Ahead Software AG) – C:\WINDOWS\System32\drivers\incdrm.sys – (incdrm [System | Running])
DRV - [2009/07/03 22:49:08 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd [Boot | Running])
DRV - [2003/07/03 21:50:12 | 00,045,952 | —- | M] () – C:\Program Files\Everstrike\Lock Folder XP 3.2\UniShieldXP.sys – (lf [Auto | Running])
DRV - [2006/05/23 19:21:02 | 00,004,224 | —- | M] (FSPro Labs) – C:\WINDOWS\System32\drivers\lmpc2.sys – (LMPC2 [On_Demand | Running])
DRV - [2009/09/10 14:53:50 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys – (MBAMProtector [On_Demand | Running])
DRV - [2008/12/07 15:16:57 | 00,015,781 | —- | M] (Meetinghouse Data Communications) – C:\WINDOWS\System32\DRIVERS\mdc8021x.sys – (MDC8021X [Auto | Running])
DRV - [2001/10/23 03:46:42 | 00,009,855 | —- | M] (Conexant) – C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys – (mdmxsdk [Auto | Running])
DRV - [2008/08/21 18:49:22 | 00,018,688 | —- | M] (Motorola) – C:\WINDOWS\System32\DRIVERS\motccgp.sys – (motccgp [On_Demand | Stopped])
DRV - [2008/08/21 18:49:56 | 00,008,320 | —- | M] (Motorola) – C:\WINDOWS\System32\DRIVERS\motccgpfl.sys – (motccgpfl [On_Demand | Stopped])
DRV - [2007/10/10 17:41:50 | 00,042,112 | —- | M] (Motorola Inc) – C:\WINDOWS\System32\DRIVERS\motodrv.sys – (MotDev [On_Demand | Stopped])
DRV - [2007/06/18 20:18:26 | 00,023,680 | —- | M] (Motorola) – C:\WINDOWS\System32\DRIVERS\motmodem.sys – (motmodem [On_Demand | Stopped])
DRV - [2007/11/02 15:51:28 | 00,006,400 | —- | M] (Motorola) – C:\WINDOWS\System32\DRIVERS\motswch.sys – (MotoSwitchService [On_Demand | Stopped])
DRV - [2008/03/03 16:03:10 | 00,023,296 | —- | M] (Motorola) – C:\WINDOWS\System32\DRIVERS\Motousbnet.sys – (Motousbnet [On_Demand | Stopped])
DRV - [2006/04/26 21:37:44 | 00,031,145 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\System32\DRIVERS\motovision.sys – (MOTOVISION [Auto | Running])
DRV - [2007/06/18 15:18:26 | 00,023,680 | —- | M] (Motorola) – C:\WINDOWS\System32\DRIVERS\motport.sys – (motport [On_Demand | Stopped])
DRV - [2002/09/04 00:42:50 | 00,017,280 | —- | M] (American Megatrends Inc.) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys – (mraid35x [Disabled | Stopped])
DRV - [2002/02/09 09:38:06 | 00,024,000 | R— | M] (Samsung Electronics Co., Ltd) – C:\WINDOWS\System32\DRIVERS\NetSecCm.sys – (ndiscm [On_Demand | Stopped])
DRV - [2001/10/31 10:58:34 | 00,161,512 | —- | M] (Efficient Networks, Inc.) – C:\WINDOWS\System32\DRIVERS\ntspppoe.sys – (NTSPPPOE [On_Demand | Stopped])
DRV - [2004/08/04 13:29:54 | 01,897,408 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Stopped])
DRV - [2002/11/09 03:45:06 | 00,017,217 | —- | M] (Dell Computer Corporation) – C:\WINDOWS\System32\DRIVERS\omci.sys – (omci [System | Running])
DRV - [2006/09/28 17:33:08 | 00,040,960 | —- | M] (Motorola Inc) – C:\WINDOWS\System32\DRIVERS\P2k.sys – (P2k [On_Demand | Stopped])
DRV - [2006/05/08 17:26:02 | 00,010,368 | —- | M] (Padus, Inc.) – C:\WINDOWS\System32\drivers\pfc.sys – (pfc [On_Demand | Running])
DRV - [2002/09/04 00:53:10 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2008/11/21 03:19:06 | 00,043,872 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2002/09/04 00:53:20 | 00,040,320 | —- | M] (QLogic Corporation) – C:\WINDOWS\System32\DRIVERS\ql1080.sys – (ql1080 [Disabled | Stopped])
DRV - [2002/09/04 00:53:21 | 00,045,312 | —- | M] (QLogic Corporation) – C:\WINDOWS\System32\DRIVERS\ql12160.sys – (ql12160 [Disabled | Stopped])
DRV - [2002/09/04 00:53:22 | 00,049,024 | —- | M] (QLogic Corporation) – C:\WINDOWS\System32\DRIVERS\ql1280.sys – (ql1280 [Disabled | Stopped])
DRV - [2004/07/29 16:29:58 | 00,211,072 | —- | M] (Ralink Technology Inc.) – C:\WINDOWS\System32\DRIVERS\RT2500.sys – (RT2500 [On_Demand | Stopped])
DRV - [2007/04/23 14:11:54 | 00,224,896 | —- | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\System32\DRIVERS\wg111v3.sys – (RTL8187B [On_Demand | Stopped])
DRV - [2009/07/28 10:53:16 | 00,009,968 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS – (SASDIFSV [System | Running])
DRV - [2009/07/28 10:53:16 | 00,007,408 | R— | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS – (SASENUM [On_Demand | Stopped])
DRV - [2009/07/28 10:53:14 | 00,072,944 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys – (SASKUTIL [System | Running])
DRV - [2007/11/13 18:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2008/04/14 02:36:39 | 00,040,960 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\sisagp.sys – (sisagp [Disabled | Stopped])
DRV - [2001/08/17 13:56:16 | 00,007,552 | —- | M] (Sony Corporation) – C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS – (SONYPVU1 [On_Demand | Stopped])
DRV - [2002/09/04 01:04:10 | 00,019,072 | —- | M] (Adaptec, Inc.) – C:\WINDOWS\System32\DRIVERS\sparrow.sys – (Sparrow [Disabled | Stopped])
DRV - [2005/06/15 22:55:53 | 00,004,096 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\system32\speedfan.sys – (speedfan [Boot | Running])
DRV - [2008/11/17 02:24:00 | 00,051,688 | —- | M] (Check Point Software Technologies LTD) – C:\WINDOWS\system32\ZoneLabs\srescan.sys – (srescan [Boot | Running])
DRV - [2002/11/12 07:57:16 | 00,193,840 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\System32\drivers\STAC97.sys – (STAC97 [On_Demand | Running])
DRV - [2002/10/18 01:54:18 | 00,036,348 | —- | M] (Conexant Systems) – C:\WINDOWS\System32\DRIVERS\strmdisp.sys – (StreamDispatcher [Auto | Running])
DRV - [2002/09/04 01:05:44 | 00,016,256 | —- | M] (Symbios Logic Inc.) – C:\WINDOWS\System32\DRIVERS\symc810.sys – (symc810 [Disabled | Stopped])
DRV - [2002/09/04 01:05:44 | 00,032,640 | —- | M] (LSI Logic) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys – (symc8xx [Disabled | Stopped])
DRV - [2002/09/04 01:05:45 | 00,028,384 | —- | M] (LSI Logic) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys – (sym_hi [Disabled | Stopped])
DRV - [2002/09/04 01:05:45 | 00,030,688 | —- | M] (LSI Logic) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys – (sym_u3 [Disabled | Stopped])
DRV - [2004/05/13 19:19:22 | 00,182,688 | —- | M] (Synaptics, Inc.) – C:\WINDOWS\System32\DRIVERS\SynTP.sys – (SynTP [On_Demand | Running])
DRV - [2008/06/20 19:08:27 | 00,225,856 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\tcpip6.sys – (Tcpip6 [System | Running])
DRV - [2002/09/04 01:07:50 | 00,036,736 | —- | M] (Promise Technology, Inc.) – C:\WINDOWS\System32\DRIVERS\ultra.sys – (ultra [Disabled | Stopped])
DRV - [2002/12/10 09:11:42 | 00,006,852 | —- | M] () – C:\WINDOWS\System32\Drivers\Vcs.sys – (Vcs [Auto | Running])
DRV - [2009/02/15 23:10:26 | 00,353,672 | —- | M] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsdatant.sys – (vsdatant [System | Running])
DRV - [2002/10/18 01:44:46 | 00,602,512 | —- | M] (Conexant Systems) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys – (winachsf [On_Demand | Running])
DRV - [2007/06/25 20:29:50 | 00,500,736 | R— | M] (Atheros Technology Corporation) – C:\WINDOWS\System32\DRIVERS\zd1211Bu.sys – (ZD1211BU(TP-LINK) [On_Demand | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_Url =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page =
http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.96
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.5
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.2.20080910
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13
FF - user.js..browser.search.openintab: false
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/23 16:16:08 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/15 14:44:10 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2007/02/18 17:41:43 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/24 22:09:36 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/24 22:09:36 | 00,000,000 | —D | M]
[2009/07/30 06:16:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Others\Application Data\mozilla\Extensions
[2008/12/10 15:58:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Others\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/07/30 06:16:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Others\Application Data\mozilla\Extensions\[removed]
[2009/08/24 22:01:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Others\Application Data\mozilla\Firefox\Profiles\8g1iwoqs.default\extensions
[2009/07/03 18:31:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Others\Application Data\mozilla\Firefox\Profiles\8g1iwoqs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/12/08 20:40:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Others\Application Data\mozilla\Firefox\Profiles\8g1iwoqs.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/07/17 11:28:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Others\Application Data\mozilla\Firefox\Profiles\8g1iwoqs.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/08/24 22:01:17 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/08/24 22:09:36 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/07/15 14:45:11 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/08/24 22:09:07 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/24 22:09:07 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/07/15 14:44:07 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009/08/24 22:09:23 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2008/06/02 17:02:48 | 00,200,704 | —- | M] (Pando Networks) – C:\Program Files\mozilla firefox\plugins\npPandoWebInst.dll
[2009/02/27 12:13:42 | 00,103,792 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2006/08/10 14:23:23 | 00,139,305 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2008/06/05 00:16:39 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2008/06/05 00:16:40 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2008/06/05 00:16:40 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2008/06/05 00:16:40 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2008/06/05 00:16:41 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2008/06/05 00:16:41 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2008/06/05 00:16:41 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2006/08/10 14:23:55 | 00,024,621 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprjplug.dll
[2006/08/10 14:22:21 | 00,081,967 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2007/03/10 07:16:44 | 00,189,496 | —- | M] (Yahoo! Inc.) – C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll
[2009/08/24 22:09:28 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/08/24 22:09:28 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/08/24 22:09:28 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/24 22:09:28 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/08/24 22:09:28 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/24 22:09:28 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/08/24 22:09:28 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (931683 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
O1 - Hosts: 127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
O1 - Hosts: 127.0.0.1 phpadsnew.abac.com
O1 - Hosts: 127.0.0.1 a.abnad.net
O1 - Hosts: 127.0.0.1 b.abnad.net
O1 - Hosts: 127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 d.abnad.net
O1 - Hosts: 127.0.0.1 e.abnad.net
O1 - Hosts: 127.0.0.1 t.abnad.net
O1 - Hosts: 127.0.0.1 z.abnad.net
O1 - Hosts: 127.0.0.1 banners.absolpublisher.com
O1 - Hosts: 127.0.0.1 tracking.absolstats.com
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 gtb5.acecounter.com
O1 - Hosts: 127.0.0.1 gtb19.acecounter.com
O1 - Hosts: 27362 more lines…
O2 - BHO: (IE7Pro BHO) - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll (IE7Pro.com)
O2 - BHO: (HelperObject Class) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (bho2gr Class) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (PopKiller Class) - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\SysShield Tools\Internet Eraser\pkext.dll (SysShield Consulting, Inc.)
O2 - BHO: (ICBC Anti-Phishing class) - {BB4491A2-D11A-4c6b-91C0-B53246A3122B} - C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\Icbc_AntiPhishing.dll (??????)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (1-Click Answers) - {7754C418-F62E-44aa-B169-E719E718BCFD} - C:\Program Files\1-Click Answers\IEToolbar\AnswersToolbarU.dll (Answers Corporation)
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (IncrediBar) - {D8073790-84C7-4602-BF77-C6ACBF1612E4} - C:\Program Files\IncrediBar\bin\IBTBar.dll (IncrediBar)
O3 - HKLM\..\Toolbar: (AbsoluteShield) - {EE9DD090-902D-4623-9360-FB7D8666202B} - C:\Program Files\SysShield Tools\Internet Eraser\AbsoluteBar.dll (AbsoluteShield Software)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (IncrediBar) - {D8073790-84C7-4602-BF77-C6ACBF1612E4} - C:\Program Files\IncrediBar\bin\IBTBar.dll (IncrediBar)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (1-Click Answers) - {7754C418-F62E-44AA-B169-E719E718BCFD} - C:\Program Files\1-Click Answers\IEToolbar\AnswersToolbarU.dll (Answers Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (IncrediBar) - {D8073790-84C7-4602-BF77-C6ACBF1612E4} - C:\Program Files\IncrediBar\bin\IBTBar.dll (IncrediBar)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [StartupFaster] C:\Program Files\Startup Faster 2004\StrpFstCfg.exe (URSoft,Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\StartupFaster [2009/09/11 13:28:59 | 00,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Others\Start Menu\Programs\Startup\StartupFaster [2009/08/02 10:26:11 | 00,000,000 | -H-D | M]
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLastUserName = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ShutdownWithoutLogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\PhotoSupport present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInstrumentation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuNetworkPlaces = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoHelp = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMFUprogramsList = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuEjectPC = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSimpleStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDisconnect = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNtSecurity = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: GreyMSIAds = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceMaxRecentDocs = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTips = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LockTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarsOnTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTaskGrouping = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWebServices = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileUrl = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoExpandedNewMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: SpecifyDefaultButtons = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetConnectDisconnect = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoComputersNearMe = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnforceShellExtensionSecurity = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRunasInstallPrompt = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: PromptRunasInstallNetPath = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceCopyAclwithFile = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartRunNoHOMEPATH = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 0? = strpfstcfg.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun: 1? = newadmin.exe
O8 - Extra context menu item: &Add; animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm ()
O8 - Extra context menu item: &Winamp; Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2007/11/13 20:44:04 | 00,000,000 | —D | M]
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Answers… - C:\Program Files\1-Click Answers\Html\atiemenu.htm ()
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: Logoff - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComLogoff.html ()
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Translate this web page with Babylon - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O8 - Extra context menu item: Translate with Babylon - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2007/11/13 20:44:04 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2007/11/13 20:44:04 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2007/11/13 20:44:04 | 00,000,000 | —D | M]
O9 - Extra Button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll (IE7Pro.com)
O9 - Extra 'Tools' menuitem : IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll (IE7Pro.com)
O9 - Extra Button: IncrediBar - {023FA804-DCE1-4817-94ED-6BA4200F9AF2} - C:\Program Files\IncrediBar\bin\IBTBar.dll (IncrediBar)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe ()
O9 - Extra 'Tools' menuitem : PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe ()
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 72 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: bankofamerica.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: com.cn ([mybank.icbc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: com.cn ([www.icbc] http in Trusted sites)
O15 - HKCU\..Trusted Domains: hotmail.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: live.com ([login] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([v4.Windowsupdate] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([v4.Windowsupdate] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([Windowsupdate] https in Trusted sites)
O15 - HKCU\..Trusted Domains: msn.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: yahoo.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 432 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0D99625B-0619-4420-BB61-82DEE1B91D3A}
https://ebank.gdb.com.cn/perbank/js/CertKitAx.cab (BlockHouse Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://download.ewido.net/ewidoOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab (Reg Error: Key error.)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://Tom_q2356.spaces.live.com//PhotoUpload/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455}
http://us.games2.yimg.com/download.games.y…ctl_0_0_0_1.ocx (ExentInf Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1222675051475 (MUWebControl Class)
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} http://chat.yahoo.com/cab/yacsui.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} http://chat.yahoo.com/cab/yuplapp.cab (Yahoo! Webcam Upload Wrapper)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2}
https://mybank.icbc.com.cn/icbc/newperbank/…afeControls.cab (AxSubmitControl Class)
O16 - DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE}
http://download.yahoo.com/dl/bookmarks/ybconvfav030408.cab (YbUploadFavsCtl Class)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
http://v4.windowsupdate.microsoft.com/CAB/…8192.0495138889 (Reg Error: Key error.)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse…pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab (YAddBook Class)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D81CA86B-EF63-42AF-BEE3-4502D9A03C2D}
http://wwws.musicmatch.com/graphics/WebPlayer/MMLRadio.cab (MMRadioHostX Class)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7}
http://download.microsoft.com/download/7/E…04/clearadj.cab (CTAdjust Class)
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} http://chat.yahoo.com/cab/yvwrctl.cab (Yahoo! Webcam Viewer Wrapper)
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667}
http://pccheckup.dellfix.com/rel/35/install/gtdownde.cab (Dell PC Checkup Installer Control)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} http://chat.msn.com/bin/msnchat45.cab (MSN Chat Control 4.5)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Yahoo! MahJong Solitaire
http://download.games.yahoo.com/games/clients/y/mjst4_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Pool 2
http://download.games.yahoo.com/games/clients/y/pote_x.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (C:\WINDOWS\system32\logonuiX.exe) - C:\WINDOWS\System32\logonuiX.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\MCPClient: DllName - C:\Program Files\Common Files\Stardock\mcpstub.dll - C:\Program Files\Common Files\Stardock\mcpstub.dll (Stardock)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/05/24 11:42:39 | 00,000,000 | R–D | M] - C:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (PDBoot.exe) - C:\WINDOWS\System32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
File not found – C:\Documents and Settings\Others\Desktop\CAZBDPKE.
[2009/09/23 08:55:42 | 00,514,560 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Others\Desktop\OTL.exe
[2009/09/21 22:51:58 | 10,832,5437 | —- | C] () – C:\Documents and Settings\Others\Desktop\CollegeStudent-xbox.wmv
[2009/09/21 06:28:52 | 00,000,000 | —D | C] – C:\_OTM
[2009/09/21 06:15:22 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/09/20 21:09:09 | 00,000,211 | —- | C] () – C:\Boot.bak
[2009/09/20 21:09:02 | 00,260,272 | —- | C] () – C:\cmldr
[2009/09/20 21:09:00 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/09/20 21:02:52 | 00,229,888 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/09/20 21:02:52 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/09/20 21:02:52 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/09/20 21:02:52 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/09/20 21:02:52 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/09/20 21:02:52 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/09/20 21:02:52 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/09/20 21:02:52 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/09/20 21:02:46 | 00,000,000 | —D | C] – C:\ComboFix
[2009/09/20 21:01:35 | 00,000,000 | —D | C] – C:\Qoobox
[2009/09/19 22:02:52 | 00,032,768 | —- | C] () – C:\Documents and Settings\Others\Desktop\LianQiao.doc
[2009/09/15 12:34:36 | 00,146,475 | —- | C] () – C:\Documents and Settings\Others\Desktop\APAsample.pdf
[2009/09/14 00:33:36 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/09/14 00:29:49 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
[2009/09/14 00:29:21 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2009/09/13 13:18:37 | 00,693,760 | —- | C] () – C:\WINDOWS\is-V9TVU.exe
[2009/09/13 13:18:37 | 00,010,498 | —- | C] () – C:\WINDOWS\is-V9TVU.msg
[2009/09/13 13:18:37 | 00,000,460 | —- | C] () – C:\WINDOWS\is-V9TVU.lst
[2009/09/13 00:03:55 | 00,000,000 | —D | C] – C:\Documents and Settings\Others\Desktop\MeiRECENT
[2009/09/12 16:01:41 | 00,002,688 | —- | C] () – C:\WINDOWS\System32\settings.aaw
[2009/09/12 16:01:40 | 00,000,720 | —- | C] () – C:\WINDOWS\System32\history.aaw
[2009/09/11 13:43:42 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WEBREG
[2009/09/11 13:42:44 | 00,000,000 | —D | C] – C:\Documents and Settings\Others\Application Data\HP
[2009/09/11 13:24:05 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP Product Assistant
[2009/09/11 13:24:05 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP
[2009/09/11 13:23:16 | 00,000,000 | —D | C] – C:\Program Files\Common Files\HP
[2009/09/11 13:21:59 | 00,000,000 | —D | C] – C:\Program Files\HP
[2009/09/11 13:15:02 | 00,157,446 | —- | C] () – C:\WINDOWS\hphins27.dat
[2009/09/11 13:15:02 | 00,000,787 | —- | C] () – C:\WINDOWS\hphmdl27.dat
[2009/09/11 13:14:59 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2009/09/11 13:14:04 | 00,271,704 | R— | C] (Hewlett-Packard) – C:\WINDOWS\System32\hpzids01.dll
[2009/09/11 13:13:56 | 00,117,760 | —- | C] (Hewlett-Packard Company) – C:\WINDOWS\System32\hpzll5mu.dll
[2009/09/10 07:01:54 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009/09/08 22:14:42 | 00,153,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\triedit.dll
[2009/09/07 21:39:58 | 00,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2009/09/04 21:10:28 | 00,000,000 | —D | C] – C:\Program Files\RMVB Converter
[2009/09/03 10:28:06 | 00,000,000 | —D | C] – C:\Documents and Settings\Others\Desktop\HumanBiology
[2009/08/30 16:11:17 | 00,000,000 | —D | C] – C:\Documents and Settings\Others\Desktop\MyMoped
[2009/08/26 07:56:18 | 00,000,000 | —D | C] – C:\Documents and Settings\Others\Desktop\FunSketches
[2009/08/02 10:35:04 | 00,000,028 | —- | C] () – C:\WINDOWS\PIMAREG.INI
[2009/03/30 21:20:41 | 00,389,175 | —- | C] () – C:\WINDOWS\System32\RsaFun.dll
[2009/03/30 21:20:41 | 00,282,734 | —- | C] () – C:\WINDOWS\System32\NPCard.dll
[2009/03/30 21:20:41 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\UnblkPIN.dll
[2009/03/30 21:20:39 | 00,049,152 | —- | C] () – C:\WINDOWS\System32\jcutilTdrUKLCD.dll
[2009/03/30 21:20:38 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\jcutilHUAUK.dll
[2009/03/30 21:20:38 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\jcutilHUAUKLCD.dll
[2009/03/30 21:20:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\jcutilgem101101.dll
[2009/03/30 21:20:36 | 00,027,136 | —- | C] () – C:\WINDOWS\System32\jcinGEM102.dll
[2009/03/30 21:20:34 | 00,023,040 | —- | C] () – C:\WINDOWS\System32\jcidGEM102.dll
[2009/03/30 21:20:33 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\hmukchk.dll
[2009/03/30 21:20:31 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\GEMPIN01.dll
[2009/03/30 21:20:30 | 00,184,320 | —- | C] () – C:\WINDOWS\System32\GdApi.dll
[2008/12/06 17:42:17 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2008/12/06 17:42:17 | 00,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2008/09/14 07:52:41 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\CmbSafeBase.dll
[2008/09/14 07:52:40 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\PBHttpComm.dll
[2006/09/03 19:18:39 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\jcinTHTFUK.dll
[2006/09/03 19:18:38 | 00,073,728 | —- | C] () – C:\WINDOWS\System32\jcidTHTFUK.dll
[2006/09/03 19:18:38 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\jcinpublic.dll
[2006/09/03 19:18:38 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\jcinHUAUK.dll
[2006/09/03 19:18:38 | 00,057,344 | —- | C] () – C:\WINDOWS\System32\jcidHUAUK.dll
[2006/09/03 19:18:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\jcinGEM101.dll
[2006/09/03 19:18:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\jcidGEM101.dll
[2006/09/03 19:18:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\jcidGD84.dll
[2006/09/03 19:18:38 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\jcinGD84.dll
[2006/09/03 19:18:38 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\jcidWATCHK.dll
[2006/09/03 19:18:37 | 00,262,208 | —- | C] () – C:\WINDOWS\System32\GPKPCSC.dll
[2006/09/03 19:18:37 | 00,241,758 | —- | C] () – C:\WINDOWS\System32\GPKPIN.dll
[2006/09/03 19:18:37 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\CEA_Crypt.dll
[2006/09/03 19:18:37 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\ChangPIN.dll
[2006/09/03 19:18:36 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\jcinWATCHK.dll
[2006/09/03 19:18:34 | 00,057,344 | —- | C] () – C:\WINDOWS\System32\USBKey.dll
[2006/08/10 06:58:31 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\70681b24.dll
[2006/08/10 06:58:28 | 00,000,030 | —- | C] () – C:\WINDOWS\System32\68af6bb3.dll
[2006/07/10 18:19:56 | 00,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/04/08 10:11:38 | 00,000,040 | —- | C] () – C:\WINDOWS\powerplayer.ini
[2006/03/22 10:03:02 | 00,000,040 | —- | C] () – C:\WINDOWS\nero.INI
[2006/03/21 19:47:12 | 00,085,360 | —- | C] () – C:\WINDOWS\System32\drivers\incdfs.sys
[2006/02/19 16:25:23 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\SynTPCoI.dll
[2006/02/14 17:25:44 | 00,000,009 | —- | C] () – C:\WINDOWS\winxfigt.sys
[2005/12/25 18:00:36 | 00,001,125 | —- | C] () – C:\WINDOWS\winamp.ini
[2005/11/16 10:40:42 | 00,684,032 | —- | C] () – C:\WINDOWS\libeay32.dll
[2005/11/16 10:40:42 | 00,155,648 | —- | C] () – C:\WINDOWS\ssleay32.dll
[2005/10/19 13:45:34 | 00,014,848 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2005/10/19 12:57:04 | 00,000,027 | —- | C] () – C:\WINDOWS\AdvConfig.ini
[2005/05/15 13:29:59 | 00,163,712 | —- | C] () – C:\WINDOWS\System32\drivers\vidstub.sys
[2005/04/28 13:51:17 | 00,049,152 | —- | C] () – C:\WINDOWS\System32\odlib.dll
[2005/03/28 16:36:38 | 00,000,116 | —- | C] () – C:\WINDOWS\ConverterCore.INI
[2005/02/11 23:36:33 | 00,006,852 | —- | C] () – C:\WINDOWS\System32\drivers\Vcs.sys
[2005/01/21 10:52:56 | 00,010,856 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2005/01/04 12:41:31 | 00,000,214 | —- | C] () – C:\WINDOWS\Gurunet.ini
[2005/01/03 14:25:15 | 00,000,206 | —- | C] () – C:\WINDOWS\EurekaLog.ini
[2004/12/25 10:46:48 | 00,000,064 | —- | C] () – C:\WINDOWS\eFaxView.ini
[2004/12/03 16:54:11 | 00,016,974 | —- | C] () – C:\WINDOWS\ePrompter.ini
[2004/11/06 17:11:28 | 00,000,806 | —- | C] () – C:\WINDOWS\UnitConverter.INI
[2004/10/27 06:39:05 | 03,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/10/08 08:08:11 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\stdsoap2.dll
[2004/08/28 22:33:27 | 00,000,024 | —- | C] () – C:\WINDOWS\LogonStudio.ini
[2004/08/28 22:30:55 | 00,187,392 | —- | C] () – C:\WINDOWS\System32\JPGUtils.dll
[2004/08/16 14:52:06 | 00,397,312 | —- | C] () – C:\WINDOWS\System32\CMBEdit.dll
[2004/07/24 17:44:02 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/07/03 20:32:40 | 00,000,000 | —- | C] () – C:\WINDOWS\audio.INI
[2004/07/03 20:20:24 | 00,000,173 | —- | C] () – C:\WINDOWS\srlink.ini
[2004/07/03 20:20:24 | 00,000,040 | —- | C] () – C:\WINDOWS\System32\sx96.ini
[2004/06/19 12:48:35 | 00,000,067 | —- | C] () – C:\WINDOWS\morphexe.INI
[2004/06/06 13:39:27 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/06/03 22:08:19 | 00,000,478 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/06/03 21:44:16 | 00,000,146 | —- | C] () – C:\WINDOWS\TBPlugin.INI
[2004/06/03 21:44:16 | 00,000,095 | —- | C] () – C:\WINDOWS\avconfig.ini
[2004/05/26 10:30:32 | 00,252,928 | —- | C] () – C:\WINDOWS\System32\astrolib32.dll
[2004/05/25 12:11:43 | 00,000,119 | —- | C] () – C:\WINDOWS\WSST_Screen_Saver.ini
[2004/05/24 09:05:31 | 00,000,227 | —- | C] () – C:\WINDOWS\SIMAQU~1.INI
[2004/04/03 16:53:17 | 00,000,037 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/03/09 14:50:36 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\ICMSetup532.dll
[2004/03/09 14:50:34 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\8532util.dll
[2004/02/03 21:09:07 | 00,000,093 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2003/10/16 10:48:44 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2003/10/14 18:43:32 | 00,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2003/09/05 18:18:30 | 00,000,048 | —- | C] () – C:\WINDOWS\Sierra.ini
[2003/05/27 14:49:00 | 00,041,984 | —- | C] () – C:\WINDOWS\System32\AQalphaGL.dll
[2003/05/14 19:48:08 | 00,000,068 | —- | C] () – C:\WINDOWS\FastAIT.INI
[2003/05/05 10:31:44 | 00,001,663 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/05/01 20:01:48 | 00,000,424 | —- | C] () – C:\WINDOWS\NJCOM.INI
[2003/05/01 12:15:04 | 00,000,023 | —- | C] () – C:\WINDOWS\NtsUninstall.ini
[2003/05/01 11:39:32 | 00,000,068 | —- | C] () – C:\WINDOWS\XDICT.INI
[2003/04/13 17:47:44 | 00,000,095 | —- | C] () – C:\WINDOWS\ntsautodial.ini
[2003/03/19 01:01:19 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/03/19 00:46:32 | 00,000,185 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/03/19 00:46:28 | 00,000,779 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/03/19 00:34:19 | 00,000,892 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/03/19 00:06:10 | 00,000,310 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2002/09/03 22:59:58 | 00,000,999 | —- | C] () – C:\WINDOWS\WIN.INI
[2002/09/03 22:50:58 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2002/03/21 15:39:02 | 00,073,728 | —- | C] () – C:\WINDOWS\System32\UNACEV2.DLL
[2001/10/08 18:59:28 | 00,000,821 | —- | C] () – C:\WINDOWS\txp-lcn.ini
[2001/10/08 13:24:26 | 00,148,544 | —- | C] () – C:\WINDOWS\System32\msvdm.dll
[2001/10/08 12:59:46 | 00,016,960 | —- | C] () – C:\WINDOWS\System32\mag.dll
[2000/11/24 18:05:06 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\Cpuinfo2.dll
[1999/03/16 17:32:33 | 00,000,136 | —- | C] () – C:\WINDOWS\System32\mstraps.dll
[1999/01/22 11:46:56 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1996/04/04 03:33:26 | 00,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys
========== Files - Modified Within 30 Days ==========
File not found – C:\Documents and Settings\Others\Desktop\CAZBDPKE.
[2009/09/23 08:55:50 | 00,514,560 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Others\Desktop\OTL.exe
[2009/09/23 08:45:00 | 00,350,201 | -H– | M] () – C:\WINDOWS\System32\vsconfig.xml
[2009/09/23 08:41:44 | 00,000,024 | —- | M] () – C:\WINDOWS\LogonStudio.ini
[2009/09/23 08:36:06 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/09/23 08:35:51 | 10,727,46496 | -HS- | M] () – C:\hiberfil.sys
[2009/09/22 22:08:00 | 00,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2009/09/22 12:45:28 | 00,055,568 | —- | M] () – C:\Documents and Settings\Others\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/09/22 12:26:16 | 00,200,936 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/09/22 12:22:55 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/09/22 04:29:59 | 00,000,424 | —- | M] () – C:\WINDOWS\NJCOM.INI
[2009/09/21 23:06:48 | 00,190,976 | —- | M] () – C:\Documents and Settings\Others\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/21 23:06:33 | 10,832,5437 | —- | M] () – C:\Documents and Settings\Others\Desktop\CollegeStudent-xbox.wmv
[2009/09/20 21:09:09 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/09/20 16:43:24 | 00,032,768 | —- | M] () – C:\Documents and Settings\Others\Desktop\LianQiao.doc
[2009/09/17 03:53:52 | 29,448,2944 | —- | M] () – C:\Documents and Settings\Others\Desktop\Breaststroke.with.Ed.Moses.and.Peter.Morgan.avi
[2009/09/16 22:40:43 | 00,931,683 | R— | M] () – C:\WINDOWS\System32\drivers\ETC\HOSTS
[2009/09/15 12:36:05 | 00,000,116 | —- | M] () – C:\WINDOWS\ConverterCore.INI
[2009/09/15 12:34:36 | 00,146,475 | —- | M] () – C:\Documents and Settings\Others\Desktop\APAsample.pdf
[2009/09/14 02:12:36 | 00,229,888 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/09/14 00:33:55 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/09/13 13:18:40 | 00,000,482 | —- | M] () – C:\WINDOWS\tasks\Malwarebytes' Scheduled Update for Others.job
[2009/09/13 13:18:37 | 00,693,760 | —- | M] () – C:\WINDOWS\is-V9TVU.exe
[2009/09/13 13:18:37 | 00,010,498 | —- | M] () – C:\WINDOWS\is-V9TVU.msg
[2009/09/13 13:18:37 | 00,000,460 | —- | M] () – C:\WINDOWS\is-V9TVU.lst
[2009/09/12 16:01:41 | 00,002,688 | —- | M] () – C:\WINDOWS\System32\settings.aaw
[2009/09/12 16:01:41 | 00,000,720 | —- | M] () – C:\WINDOWS\System32\history.aaw
[2009/09/11 15:06:17 | 00,157,446 | —- | M] () – C:\WINDOWS\hphins27.dat
[2009/09/11 13:28:35 | 00,000,037 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/09/11 12:53:22 | 60,397,9776 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2009/09/10 14:54:06 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/09/10 14:53:50 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/09/10 06:29:40 | 00,005,134 | —- | M] () – C:\WINDOWS\System32\OEMLOGO.BMP
[2009/09/10 06:29:40 | 00,000,310 | —- | M] () – C:\WINDOWS\System32\oeminfo.ini
[2009/09/09 23:30:20 | 00,930,401 | R— | M] () – C:\WINDOWS\System32\drivers\ETC\hosts.20090916-224043.backup
[2009/09/08 13:32:34 | 00,016,974 | —- | M] () – C:\WINDOWS\ePrompter.ini
[2009/09/05 12:38:07 | 00,928,211 | R— | M] () – C:\WINDOWS\System32\drivers\ETC\hosts.20090909-233020.backup
[2009/08/29 05:38:20 | 24,689,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/08/27 23:06:27 | 00,926,439 | R— | M] () – C:\WINDOWS\System32\drivers\ETC\hosts.20090905-123806.backup
========== Alternate Data Streams ==========
@Alternate Data Stream - 284 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 182 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:28BB1CE8
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >