This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE pages keep poping up & cant access any drive from my computer p

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:32:34, on 13/6/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17023)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIFI_LINK\WL_Utility\srvany.exe
C:\Program Files\WIFI_LINK\WL_Utility\ZyDummyZD11B-BG.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\ZSSnp211.exe
C:\WINDOWS\Domino.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\WIFI_LINK\WL_Utility\ZDWlan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.2.7.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Windows Live ?n﹑J﹑p??﹑ - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [kava] C:\WINDOWS\system32\kavo.exe
O4 - HKCU\..\Run: [tava] C:\WINDOWS\system32\tavo.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.3\IExifMap.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Open with KUSO EXIF Viewer - C:\Program Files\KUSO EXIF Viewer\EXIF.htm
O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.3\IExifCom.htm
O8 - Extra context menu item: 使用光影編輯和美化 - C:\Program Files\nEO iMAGING\NeoOpenNeo.htm
O8 - Extra context menu item: 匯出至 Microsoft Excel(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 轉換為 Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: 轉換連結目標到現有 PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: 轉換連結目標為 Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: 轉換選定的連結到現有 PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: 轉換選定的連結為 Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: 轉換選擇內容到現有 PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: 轉換選擇內容為 Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: 附加至現有 PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java 主控台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: ?????豌????R… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://aux1.jp.canon.com
O15 - Trusted Zone: http://mytv.tvb.com
O15 - Trusted Zone: http://www.youtube.com
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {3AC7F64E-6154-47B0-82B5-764ED4077F77} (DataStorage Class) - http://txn.hkjc.com/BetSlip/object/HKJCSecKey.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1210948029250
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{08EB659D-7F07-478B-9FD5-8D932DDA96F3}: NameServer = 218.102.32.208 205.252.144.126
O17 - HKLM\System\CCS\Services\Tcpip\..\{3F1E0D7C-7661-4125-8948-8D047928623E}: NameServer = 192.168.0.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{08EB659D-7F07-478B-9FD5-8D932DDA96F3}: NameServer = 218.102.32.208 205.252.144.126
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour ?A?? (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod ?A?? (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: ZyDAS1211BBG - Unknown owner - C:\Program Files\WIFI_LINK\WL_Utility\srvany.exe

–
End of file - 14595 bytes
Hello there, vonnielui

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. :)
Hi,

You are infected with a backdoor trojan/password stealer

We recommend, you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or it if it contains any other sensitive information, please get to a known clean computer and change all passwords where applicable, Pin numbers, credit card numbers, account numbers, etc. should all be changed immediately, and it would be wise to contact those same financial institutions to advise them of your situation. This infection that you have will attract others, keep it offline except when we are troubleshooting.

Trojans attempt to steal passwords, as well as logging keypresses and open a window periodically sends the collected information. Even if we clean the malware off your system, We can't guarantee that your system will be clean afterwards. Also, we cannot guarantee to repair all the damage it caused.

Should you have decided to do a re-format of your system or wish to continue, please let me know.

Please read this :
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud

When should I re-format? How should I reinstall

===================================================

You have ( BitComet ), a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.internetworldstats.com/articles…cles/art053.htm
See Clean/Infected P2P Programs here

I would recommend that you uninstall it, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


===================================================

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

On your next reply please post :
OTL log
GMER log

Good Day!
OTL.txt

OTL logfile created on: 14/6/2010 0:12:49 - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\edwinlee\桌面
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C04 | Country: 香港特別行政區 | Language: ZHH | Date Format: d/M/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.45 Gb Total Space | 18.71 Gb Free Space | 25.14% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 298.09 Gb Total Space | 8.55 Gb Free Space | 2.87% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME
Current User Name: edwinlee
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\edwinlee\桌面\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\system32\drivers\CDAC11BA.EXE (Macrovision)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE (Symantec Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\ZSSnp211.EXE (Vimicro)
PRC - C:\WINDOWS\Domino.EXE ()
PRC - C:\Program Files\WIFI_LINK\WL_Utility\ZDWlan.exe ()
PRC - C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE (Symantec Corporation)
PRC - C:\Program Files\WIFI_LINK\WL_Utility\ZyDummyZD11B-BG.exe ()
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE (Symantec Corporation)
PRC - C:\Program Files\Norton Internet Security\ISSVC.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe ()
PRC - C:\Program Files\WIFI_LINK\WL_Utility\srvany.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\edwinlee\桌面\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\MSVCR71.DLL (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\Common Files\Symantec Shared\AntiSpam\ASOEHOOK.DLL (Symantec Corporation)


========== Win32 Services (SafeList) ==========

SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (C-DillaCdaC11BA) – C:\WINDOWS\system32\drivers\CDAC11BA.EXE (Macrovision)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (ccProxy) – C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (SBService) – C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBSERV.EXE (Symantec Corporation)
SRV - (navapsvc) – C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (Symantec Corporation)
SRV - (ISSVC) – C:\Program Files\Norton Internet Security\ISSVC.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SAVScan) – C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe (Symantec Corporation)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (ZyDAS1211BBG) – C:\Program Files\WIFI_LINK\WL_Utility\srvany.exe ()


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100609.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100609.003\NAVENG.SYS (Symantec Corporation)
DRV - (Alidevice) – C:\WINDOWS\system32\drivers\alidevice.sys (alipay.com)
DRV - (CdaC15BA) – C:\WINDOWS\system32\drivers\CDAC15BA.SYS (Macrovision Europe Ltd)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (SYMIDSCO) – C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20080221.003\SymIDSCo.sys (Symantec Corporation)
DRV - (slabser) – C:\WINDOWS\system32\drivers\slabser.sys (MCCI Corporation)
DRV - (slabbus) CP210x USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\slabbus.sys (MCCI Corporation)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (ZSMC211) USB PC Camera (ZS0211) – C:\WINDOWS\system32\drivers\ZS211.sys (ZSMC Corporation)
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (ZD1211BU(MAYFLASH)) WIFI LINK IEEE 802.11 b+g Wireless LAN Driver (USB)(MAYFLASH) – C:\WINDOWS\system32\drivers\ZD1211BU.sys (ZyDAS Technology Corporation)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (BRGSp50) – C:\WINDOWS\system32\drivers\BRGSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (WmBEnum) – C:\WINDOWS\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmVirHid) – C:\WINDOWS\system32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmXlCore) – C:\WINDOWS\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMDNS) – C:\WINDOWS\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (SAVRTPEL) – C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS (Symantec Corporation)
DRV - (k750obex) – C:\WINDOWS\system32\drivers\k750obex.sys (MCCI)
DRV - (k750mgmt) – C:\WINDOWS\system32\drivers\k750mgmt.sys (MCCI)
DRV - (k750mdm) – C:\WINDOWS\system32\drivers\k750mdm.sys (MCCI)
DRV - (k750mdfl) – C:\WINDOWS\system32\drivers\k750mdfl.sys (MCCI)
DRV - (k750bus) Sony Ericsson 750 driver (WDM) – C:\WINDOWS\system32\drivers\k750bus.sys (MCCI)
DRV - (NAL) – C:\WINDOWS\system32\drivers\iqvw32.sys (Intel Corporation )
DRV - (ZDPSp50) – C:\WINDOWS\system32\drivers\ZDPSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (FsVga) – C:\WINDOWS\system32\drivers\fsvga.sys (Microsoft Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (FileDisk) – C:\WINDOWS\system32\drivers\filedisk.sys (Bo Brantén)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://google.icq.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll (ICQ Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2009/06/29 21:53:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/08 23:56:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/08 23:56:05 | 000,000,000 | —D | M]

[2008/07/30 23:17:44 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\Mozilla\Extensions
[2008/07/30 23:17:44 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\Mozilla\Firefox\Profiles\x1qhf3lr.default\extensions
[2008/07/30 23:17:11 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/02/28 16:39:48 | 000,002,310 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\findbook-zh-TW.xml
[2010/02/28 16:39:48 | 000,001,222 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-zh-TW.xml
[2010/02/28 16:39:48 | 000,001,350 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-answer-zh-TW.xml
[2010/02/28 16:39:48 | 000,000,834 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-bid-zh-TW.xml
[2010/02/28 16:39:48 | 000,000,843 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-zh-TW.xml

O1 HOSTS File: ([2004/08/12 12:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (bho2gr Class) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.2.7.dll (BitComet)
O2 - BHO: (Megaupload Toolbar) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll (MEGAUPLOAD)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (CNisExtBho Class) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (CNavExtBho Class) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Internet Security) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Megaupload Toolbar) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll (MEGAUPLOAD)
O3 - HKLM\..\Toolbar: (ICQ Toolbar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll (ICQ Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL (Symantec Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Internet Security) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Megaupload Toolbar) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll (MEGAUPLOAD)
O3 - HKCU\..\Toolbar\WebBrowser: (ICQ Toolbar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll (ICQ Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Domino] C:\WINDOWS\Domino.EXE ()
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe ()
O4 - HKLM..\Run: [Symantec NetDriver Monitor] C:\Program Files\SymNetDrv\SNDMon.exe (Symantec Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.EXE (Vimicro)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
O4 - HKCU..\Run: [kava] C:\WINDOWS\system32\kavo.exe ()
O4 - HKCU..\Run: [tava] C:\WINDOWS\system32\tavo.exe ()
O4 - Startup: C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\WL Utility.lnk = C:\Program Files\WIFI_LINK\WL_Utility\ZDWlan.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &ICQ Toolbar Search - C:\Program Files\ICQToolbar\toolbaru.dll (ICQ Inc.)
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRDownload.htm ()
O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.3\IExifMap.htm ()
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRBrowse.htm ()
O8 - Extra context menu item: Open with KUSO EXIF Viewer - C:\Program Files\KUSO EXIF Viewer\EXIF.htm ()
O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.3\IExifCom.htm ()
O8 - Extra context menu item: ェ・[ヲワイ{ヲウェコ PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: ツ犇ォウsオイ・リシミャー Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: ツ犇ォウsオイ・リシミヲワイ{ヲウ PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: ツ犇ォソ・wェコウsオイャー Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: ツ犇ォソ・wェコウsオイヲワイ{ヲウ PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: ツ犇ォソ・ワ、コョeャー Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: ツ犇ォソ・ワ、コョeヲワイ{ヲウ PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: ツ犇ォャー Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: 使用光影編輯和美化 - C:\Program Files\nEO iMAGING\NeoOpenNeo.htm ()
O8 - Extra context menu item: 附加至現有 PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: 匯出至 Microsoft Excel(&X) - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: 轉換為 Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: 轉換連結目標到現有 PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: 轉換連結目標為 Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: 轉換選定的連結到現有 PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: 轉換選定的連結為 Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: 轉換選擇內容到現有 PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: 轉換選擇內容為 Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra 'Tools' menuitem : Sun Java 主控台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : ォリ・゚ヲ豌ハウフキR… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (ICQ Ltd.)
O9 - Extra 'Tools' menuitem : ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (ICQ Ltd.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: canon.com ([aux1.jp] http in 信任的網站)
O15 - HKCU\..Trusted Domains: tvb.com ([mytv] http in 信任的網站)
O15 - HKCU\..Trusted Domains: youtube.com ([www] http in 信任的網站)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {3AC7F64E-6154-47B0-82B5-764ED4077F77} http://txn.hkjc.com/BetSlip/object/HKJCSecKey.cab (DataStorage Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1210948029250 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (目前的首頁) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\edwinlee\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\edwinlee\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/09/07 11:10:30 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/09/25 20:26:57 | 000,000,649 | RHS- | M] () - C:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2009/02/11 23:02:02 | 000,002,584 | —- | M] () - C:\autorun.PNF – [ NTFS ]
O33 - MountPoints2\{6068cdf8-37b7-11da-807b-00123fa23e89}\Shell\AutoRun\command - "" = H:\qkarc.exe – File not found
O33 - MountPoints2\{6068cdf8-37b7-11da-807b-00123fa23e89}\Shell\explore\Command - "" = H:\qkarc.exe – File not found
O33 - MountPoints2\{6068cdf8-37b7-11da-807b-00123fa23e89}\Shell\open\Command - "" = H:\qkarc.exe – File not found
O33 - MountPoints2\{8c1846bb-63a9-11da-8092-00123fa23e89}\Shell\sorthb\command - "" = C:\Program Files\PSP Brew\PSPbrew.exe – [2006/10/27 17:22:26 | 002,121,728 | —- | M] (Stefano Russello (www.StefanoRussello.it))
O33 - MountPoints2\{b3874e2c-d44f-11de-9e46-00123fa23e89}\Shell\AutoRun\command - "" = r3fhr.exe
O33 - MountPoints2\{b3874e2c-d44f-11de-9e46-00123fa23e89}\Shell\open\Command - "" = r3fhr.exe
O33 - MountPoints2\{f74f4a92-4c38-11dd-9bd1-00123fa23e89}\Shell\AutoRun\command - "" = abqk2c3i.bat
O33 - MountPoints2\{f74f4a92-4c38-11dd-9bd1-00123fa23e89}\Shell\explore\Command - "" = abqk2c3i.bat
O33 - MountPoints2\{f74f4a92-4c38-11dd-9bd1-00123fa23e89}\Shell\open\Command - "" = abqk2c3i.bat
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2004/09/07 10:58:02 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/06/14 00:11:17 | 000,572,416 | —- | C] (OldTimer Tools) – C:\Documents and Settings\edwinlee\桌面\OTL.exe
[2010/06/13 00:30:34 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/06/12 23:17:41 | 000,000,000 | —D | C] – C:\Program Files\StreamTorrent 1.0
[2010/06/12 23:17:41 | 000,000,000 | —D | C] – C:\Documents and Settings\edwinlee\Application Data\StreamTorrent
[2010/06/12 02:10:31 | 000,000,000 | —D | C] – C:\Program Files\szPlayer
[2010/06/06 17:17:09 | 000,000,000 | —D | C] – C:\Documents and Settings\edwinlee\桌面\SAVEDATA
[2010/05/30 11:51:26 | 000,013,312 | —- | C] (Hilgraeve, Inc.) – C:\WINDOWS\System32\dllcache\htrn_jis.dll
[2010/05/29 14:30:04 | 000,258,048 | —- | C] (Peter Wimmer, Gabest) – C:\WINDOWS\System32\GplMpgDec.ax
[2010/05/29 14:30:00 | 000,000,000 | —D | C] – C:\Program Files\Ultra MP4 Video Converter
[2010/05/23 13:04:16 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2010/05/23 02:25:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PPLiveNetwork
[2010/05/23 02:23:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PPLiveVA
[2010/05/23 02:22:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PPLive
[4 C:\Documents and Settings\edwinlee\桌面\*.tmp files -> C:\Documents and Settings\edwinlee\桌面\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/14 00:11:28 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Documents and Settings\edwinlee\桌面\OTL.exe
[2010/06/13 23:49:03 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/06/13 23:48:19 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/13 23:46:02 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/13 23:45:40 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/13 23:45:31 | 1608,667,136 | -HS- | M] () – C:\hiberfil.sys
[2010/06/13 23:45:31 | 000,211,288 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/13 23:44:31 | 017,301,504 | -H– | M] () – C:\Documents and Settings\edwinlee\NTUSER.DAT
[2010/06/13 23:44:31 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\edwinlee\ntuser.ini
[2010/06/13 13:41:59 | 000,006,089 | —- | M] () – C:\Documents and Settings\edwinlee\桌面\Ec screen.JPG
[2010/06/13 12:41:59 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/06/13 00:30:45 | 000,002,453 | —- | M] () – C:\Documents and Settings\edwinlee\桌面\HiJackThis.lnk
[2010/06/12 23:17:41 | 000,000,792 | —- | M] () – C:\Documents and Settings\edwinlee\桌面\StreamTorrent 1.0.lnk
[2010/06/12 02:10:39 | 000,000,138 | —- | M] () – C:\WINDOWS\powerplayer.ini
[2010/06/12 02:10:39 | 000,000,017 | —- | M] () – C:\WINDOWS\psnetwork.ini
[2010/06/12 01:31:44 | 000,031,744 | —- | M] () – C:\Documents and Settings\edwinlee\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/07 17:34:13 | 000,033,280 | —- | M] () – C:\Documents and Settings\edwinlee\桌面\portfolio.xls
[2010/06/07 17:30:24 | 000,093,184 | —- | M] () – C:\Documents and Settings\edwinlee\桌面\Lens.xls
[2010/06/07 16:51:12 | 031,499,845 | —- | M] () – C:\Documents and Settings\edwinlee\My Documents\8411954_mp4_h264_aac[1].mp4
[2010/06/07 16:27:38 | 032,283,941 | —- | M] () – C:\Documents and Settings\edwinlee\My Documents\smile[1].flv
[2010/06/07 16:21:47 | 023,463,534 | —- | M] () – C:\Documents and Settings\edwinlee\My Documents\videoplayback[6].flv
[2010/06/06 14:14:35 | 000,075,703 | —- | M] () – C:\Documents and Settings\edwinlee\桌面\Laptop Warranty.pdf
[2010/06/05 00:17:53 | 000,058,568 | —- | M] () – C:\Documents and Settings\edwinlee\Application Data\GDIPFONTCACHEV1.DAT
[2010/06/04 20:10:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/06/03 22:59:03 | 000,106,496 | —- | M] () – C:\Documents and Settings\edwinlee\桌面\Record.XLS
[2010/06/01 22:02:28 | 000,000,554 | —- | M] () – C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - edwinlee.job
[2010/05/30 11:51:58 | 001,260,120 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/05/30 11:51:58 | 000,491,232 | —- | M] () – C:\WINDOWS\System32\prfh0404.dat
[2010/05/30 11:51:58 | 000,407,652 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/05/30 11:51:58 | 000,271,188 | —- | M] () – C:\WINDOWS\System32\prfc0404.dat
[2010/05/30 11:51:58 | 000,064,434 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/05/28 17:38:58 | 000,000,057 | —- | M] () – C:\WINDOWS\System32\mapisvc.inf
[2010/05/28 17:34:24 | 000,097,412 | —- | M] () – C:\Documents and Settings\edwinlee\Favorites.rar
[2010/05/28 13:28:52 | 069,688,304 | —- | M] () – C:\Documents and Settings\edwinlee\My Documents\4777[1].flv
[2010/05/28 13:15:39 | 098,463,128 | —- | M] () – C:\Documents and Settings\edwinlee\My Documents\20100513Sp1eBAnw[1].flv
[4 C:\Documents and Settings\edwinlee\桌面\*.tmp files -> C:\Documents and Settings\edwinlee\桌面\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/13 13:41:59 | 000,006,089 | —- | C] () – C:\Documents and Settings\edwinlee\桌面\Ec screen.JPG
[2010/06/13 00:30:34 | 000,002,453 | —- | C] () – C:\Documents and Settings\edwinlee\桌面\HiJackThis.lnk
[2010/06/12 23:17:41 | 000,000,792 | —- | C] () – C:\Documents and Settings\edwinlee\桌面\StreamTorrent 1.0.lnk
[2010/06/12 02:10:39 | 000,000,017 | —- | C] () – C:\WINDOWS\psnetwork.ini
[2010/06/07 16:52:35 | 031,499,845 | —- | C] () – C:\Documents and Settings\edwinlee\My Documents\8411954_mp4_h264_aac[1].mp4
[2010/06/07 16:52:35 | 023,463,534 | —- | C] () – C:\Documents and Settings\edwinlee\My Documents\videoplayback[6].flv
[2010/06/07 16:52:21 | 032,283,941 | —- | C] () – C:\Documents and Settings\edwinlee\My Documents\smile[1].flv
[2010/06/06 14:14:36 | 000,075,703 | —- | C] () – C:\Documents and Settings\edwinlee\桌面\Laptop Warranty.pdf
[2010/05/30 11:51:18 | 000,065,954 | —- | C] () – C:\WINDOWS\Prairie Wind.bmp
[2010/05/30 11:51:18 | 000,065,832 | —- | C] () – C:\WINDOWS\Santa Fe Stucco.bmp
[2010/05/30 11:51:18 | 000,026,680 | —- | C] () – C:\WINDOWS\River Sumida.bmp
[2010/05/30 11:51:18 | 000,026,582 | —- | C] () – C:\WINDOWS\Greenstone.bmp
[2010/05/30 11:51:18 | 000,017,362 | —- | C] () – C:\WINDOWS\Rhododendron.bmp
[2010/05/30 11:51:18 | 000,009,522 | —- | C] () – C:\WINDOWS\Zapotec.bmp
[2010/05/30 11:51:17 | 000,065,978 | —- | C] () – C:\WINDOWS\Soap Bubbles.bmp
[2010/05/30 11:51:17 | 000,017,336 | —- | C] () – C:\WINDOWS\Gone Fishing.bmp
[2010/05/30 11:51:17 | 000,017,062 | —- | C] () – C:\WINDOWS\Coffee Bean.bmp
[2010/05/30 11:51:17 | 000,016,730 | —- | C] () – C:\WINDOWS\FeatherTexture.bmp
[2010/05/30 11:51:17 | 000,001,272 | —- | C] () – C:\WINDOWS\Blue Lace 16.bmp
[2010/05/29 14:30:03 | 000,129,024 | —- | C] () – C:\WINDOWS\System32\AVERM.dll
[2010/05/29 14:30:03 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\AVEQT.dll
[2010/05/28 17:34:22 | 000,097,412 | —- | C] () – C:\Documents and Settings\edwinlee\Favorites.rar
[2010/05/28 13:32:56 | 069,688,304 | —- | C] () – C:\Documents and Settings\edwinlee\My Documents\4777[1].flv
[2010/05/28 13:17:48 | 098,463,128 | —- | C] () – C:\Documents and Settings\edwinlee\My Documents\20100513Sp1eBAnw[1].flv
[2008/09/24 21:20:41 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\tavo0.dll
[2008/09/24 19:59:35 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\tavo1.dll
[2008/09/22 23:37:50 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\kavo1.dll
[2008/09/22 23:36:22 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\kavo0.dll
[2008/04/05 00:54:41 | 000,000,036 | —- | C] () – C:\WINDOWS\webica.ini
[2008/03/30 21:05:58 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\QCKEY32.DLL
[2007/04/14 20:13:48 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2007/04/14 20:13:48 | 000,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2007/03/21 19:56:24 | 000,646,392 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2006/10/28 20:33:24 | 000,000,476 | —- | C] () – C:\WINDOWS\WebEye.ini
[2006/10/28 20:32:15 | 000,002,508 | —- | C] () – C:\WINDOWS\unvpeye.ini
[2006/10/22 16:12:41 | 000,015,360 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2006/09/13 19:06:10 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\gtapi.dll
[2006/06/20 23:41:59 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\cutemon2k.dll
[2006/06/10 21:10:33 | 000,000,057 | —- | C] () – C:\WINDOWS\System32\peer.ini
[2006/05/01 01:06:28 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/01/25 02:08:29 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2005/10/16 19:36:17 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS3y.DLL
[2005/10/03 22:22:12 | 000,000,138 | —- | C] () – C:\WINDOWS\powerplayer.ini
[2005/09/26 23:50:06 | 000,000,379 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/09/21 00:39:37 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/09/21 00:36:39 | 000,000,460 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/09/21 00:15:30 | 000,000,408 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/13 05:57:09 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/06/22 13:37:46 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2002/05/28 09:52:36 | 000,106,496 | —- | C] () – C:\WINDOWS\japi.dll
[2002/03/21 15:39:02 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\UNACEV2.DLL
[2001/06/24 17:32:44 | 000,172,032 | —- | C] () – C:\WINDOWS\japi2.dll

========== LOP Check ==========

[2006/10/22 15:59:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ACD Systems
[2008/08/29 21:15:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2010/06/12 23:27:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PPLive
[2010/05/23 02:23:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PPLiveVA
[2009/09/26 01:37:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Storm
[2009/06/28 13:52:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2006/10/22 16:13:18 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\ACD Systems
[2008/08/29 21:20:04 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\Autodesk
[2007/07/08 11:16:13 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\BitTorrent
[2007/12/01 22:39:38 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\Canon
[2010/05/12 00:41:17 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\Geniesoft
[2008/04/05 00:53:54 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\ICAClient
[2005/10/14 22:15:02 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\ICQLite
[2005/12/03 11:30:18 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\Leadertech
[2010/01/07 00:46:15 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\MegauploadToolbar
[2009/12/18 22:14:49 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\Oasys
[2005/10/15 23:32:45 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\ppStream
[2010/06/12 23:17:41 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\StreamTorrent
[2008/05/08 01:17:42 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\Thinstall
[2008/11/02 14:27:57 | 000,000,000 | —D | M] – C:\Documents and Settings\edwinlee\Application Data\Tilted Mill
[2010/06/13 23:49:03 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2007/01/23 23:55:50 | 000,000,000 | —- | M] () – C:\atixhwug.exe
[2007/01/23 23:55:43 | 000,000,000 | —- | M] () – C:\bxaee.exe
[2007/01/23 23:55:39 | 000,000,000 | —- | M] () – C:\dbjjaf.exe
[2007/01/23 23:55:48 | 000,000,000 | —- | M] () – C:\ivmwn.exe
[2007/01/23 23:55:52 | 000,000,000 | —- | M] () – C:\nqmer.exe
[2007/01/23 23:55:41 | 000,000,000 | —- | M] () – C:\sesul.exe
[2007/01/23 23:55:45 | 000,000,000 | —- | M] () – C:\uqlsgwsn.exe
[2007/01/23 23:55:36 | 000,000,000 | —- | M] () – C:\xpioo.exe


< MD5 for: AGP440.SYS >
[2004/08/12 12:00:00 | 018,907,918 | —- | M] () .cab file – C:\i386\sp2.cab:AGP440.sys
[2004/08/12 12:00:00 | 018,907,918 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/10/27 21:52:11 | 024,342,908 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/10/27 21:52:11 | 024,342,908 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/14 02:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/14 02:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\i386\AGP440.SYS
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/12 12:00:00 | 018,907,918 | —- | M] () .cab file – C:\i386\sp2.cab:atapi.sys
[2004/08/12 12:00:00 | 018,907,918 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/10/27 21:52:11 | 024,342,908 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/10/27 21:52:11 | 024,342,908 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/14 02:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/14 02:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0011\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/15 18:54:31 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=0A9FB6653A8AC115B5110C0A5C263952 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/15 18:54:31 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=0A9FB6653A8AC115B5110C0A5C263952 – C:\WINDOWS\system32\eventlog.dll
[2004/08/12 12:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=D33069982F8DCCA36BA9B5E64188BA48 – C:\i386\eventlog.dll
[2004/08/12 12:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=D33069982F8DCCA36BA9B5E64188BA48 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2009/02/07 02:46:14 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=20F21AFD8FDA3826BFBAEA5D12AEC7B9 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/07 02:46:14 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=20F21AFD8FDA3826BFBAEA5D12AEC7B9 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2008/04/15 18:54:35 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=380F657700A117DA25AB6E4713EB8E08 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/15 18:54:35 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=380F657700A117DA25AB6E4713EB8E08 – C:\WINDOWS\system32\netlogon.dll
[2004/08/12 12:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=E1E2BA80D8CFC0C6814E5774E42B53D9 – C:\i386\netlogon.dll
[2004/08/12 12:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=E1E2BA80D8CFC0C6814E5774E42B53D9 – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2008/04/15 18:54:37 | 000,172,544 | —- | M] (Microsoft Corporation) MD5=011B5C1D7D51291041B4574CD423253C – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/15 18:54:37 | 000,172,544 | —- | M] (Microsoft Corporation) MD5=011B5C1D7D51291041B4574CD423253C – C:\WINDOWS\system32\scecli.dll
[2004/08/12 12:00:00 | 000,171,520 | —- | M] (Microsoft Corporation) MD5=3294F364BA88EDA4A296A7FDD55653E9 – C:\i386\scecli.dll
[2004/08/12 12:00:00 | 000,171,520 | —- | M] (Microsoft Corporation) MD5=3294F364BA88EDA4A296A7FDD55653E9 – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2010/05/05 01:14:10 | 000,347,136 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtmsft.dll
[2010/05/05 01:14:10 | 000,214,528 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtrans.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2007/03/21 19:56:24 | 000,646,392 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2004/09/07 11:02:00 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/09/07 11:02:00 | 000,622,592 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/09/07 11:02:00 | 000,405,504 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >

========== Files - Unicode (All) ==========
[2010/05/12 00:41:03 | 000,002,339 | —- | M] ()(C:\Documents and Settings\edwinlee\桌面\OVERTU~3.0?c?驂Overture 4.0 ?c?鬢﹑﹑??.lnk) – C:\Documents and Settings\edwinlee\桌面\OVERTU~3.0チcナ驂Overture 4.0 チcナ鬢、、蟐ゥ.lnk
[2010/05/12 00:40:28 | 000,002,339 | —- | C] ()(C:\Documents and Settings\edwinlee\桌面\OVERTU~3.0?c?驂Overture 4.0 ?c?鬢﹑﹑??.lnk) – C:\Documents and Settings\edwinlee\桌面\OVERTU~3.0チcナ驂Overture 4.0 チcナ鬢、、蟐ゥ.lnk
[2009/09/16 23:37:47 | 000,000,912 | —- | M] ()(C:\Documents and Settings\edwinlee\My Documents\?????@???????.lnk) – C:\Documents and Settings\edwinlee\My Documents\ァレェコヲ@・ホク・ニァィ.lnk
[2009/09/16 23:37:47 | 000,000,912 | —- | C] ()(C:\Documents and Settings\edwinlee\My Documents\?????@???????.lnk) – C:\Documents and Settings\edwinlee\My Documents\ァレェコヲ@・ホク・ニァィ.lnk
< End of report >
Extra.txt

OTL Extras logfile created on: 14/6/2010 0:12:49 - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\edwinlee\桌面
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C04 | Country: 香港特別行政區 | Language: ZHH | Date Format: d/M/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.45 Gb Total Space | 18.71 Gb Free Space | 25.14% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 298.09 Gb Total Space | 8.55 Gb Free Space | 2.87% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME
Current User Name: edwinlee
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\Program Files\ACD Systems\ACDSee\8.0\ACDSee8.exe" "%1" (ACD Systems Ltd.)
Directory [Digital Photo Professional] – C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"38350:TCP" = 38350:TCP:*:Enabled:ppLive
"45706:UDP" = 45706:UDP:*:Enabled:ppLive
"13659:TCP" = 13659:TCP:*:Enabled:BitComet 13659 TCP
"13659:UDP" = 13659:UDP:*:Enabled:BitComet 13659 UDP
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\ICQLite\ICQLite.exe" = C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite – (ICQ Ltd.)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – File not found
"C:\Program Files\PPLive\PPlive.exe" = C:\Program Files\PPLive\PPlive.exe:*:Enabled:PPLive – File not found
"C:\Program Files\TVAnts\Tvants.exe" = C:\Program Files\TVAnts\Tvants.exe:*:Enabled:TVAnts – (Zhejiang University)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\uusee\UUSeePlayer.exe" = C:\Program Files\uusee\UUSeePlayer.exe:*:Enabled:UUSEE – File not found
"C:\game\Pro Evolution Soccer 2009\pes2009.exe" = C:\game\Pro Evolution Soccer 2009\pes2009.exe:*:Enabled:Pro Evolution Soccer 2009 – File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\PPLive\PPTV\PPLive.exe" = C:\Program Files\PPLive\PPTV\PPLive.exe:*:Enabled:PPLive – File not found
"C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe" = C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe:*:Enabled:PPLive – File not found
"C:\Program Files\PPLive\PPTV\PPLiveU.exe" = C:\Program Files\PPLive\PPTV\PPLiveU.exe:*:Enabled:PPLiveU – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03B20126-F3C2-11D5-A6D2-00C026001DCA}" = WebEye
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0C9B0475-F65F-45AB-8D88-2AE7C195E907}" = Microsoft .NET Framework 1.1 Chinese (Traditional) Lang. Pack
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{12E2B9E9-05B1-407d-B0FD-B5F350535125}" = Norton Internet Security
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live 、Wク・uィ
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}" = SymNet
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{350C97B6-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36BD0774-6CD6-4FF9-A148-83CA09AC123E}" = Intel® PROSafe for Wired Connections
"{394BE3D9-7F57-4638-A8D1-1D88671913B7}" = Microsoft AppLocale
"{3B29A786-5803-4e9e-9B58-3014A5B4E519}" = Norton AntiSpam
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D5E5C0A-5B36-4F98-99A7-287F7DBDCE03}" = Skype Plugin Manager
"{403EF592-953B-4794-BCEF-ECAB835C2095}" = Intel® PROSafe for Wired Connections
"{41E496B5-47F4-11D6-9BBB-00E0987BB2CD}" = VIMICRO USB PC Camera(ZC0301PL)
"{449F3A9E-9903-4a0d-A209-08030D45A935}" = Norton Internet Security
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{48185814-A224-447a-81DA-71BD20580E1B}" = Norton Internet Security
"{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant
"{4E4F8EE0-43EC-4AB9-9A04-702F2AE7E229}" = Windows Live オn、J、pター、
"{50ADDF79-3249-4679-B527-3FB8C5EA99E5}" = Overture 4.0 チcナ鬢、、蟐ゥ
"{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F}" = Norton Internet Security
"{5677563D-0CB1-485f-9E18-C5025306BB3F}" = Norton AntiSpam
"{577CD3CD-8820-47D7-96DB-C43692ADE8A5}" = Microsoft ActiveSync
"{5783F2D7-0201-0409-0002-0060B0CE6BBA}" = AutoCAD 2004
"{581CE7EA-A30D-0000-1211-088635773309}" = WIFI LINK IEEE 802.11 b+g Wireless LAN - USB
"{5D601655-6D54-4384-B52C-17EC5385FBBD}" = iTunes
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.5
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75D3FF08-4838-4E47-BAE2-DF1BD866B630}" = Travel Recorder PC Utility
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{8355F970-601D-442D-A79B-1D7DB4F24CAD}" = Apple Mobile Device Support
"{851F09E3-6F23-46DB-A67D-BA1B0CF308F1}" = ArcSoft Panorama Maker 3
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{91120C04-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Standard
"{9465CD4C-1CE3-47EB-896C-C17C02BEA48C}" = Windows Live Call
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B63540D-D942-4C38-B42E-A48AE0145970}" = Virtua Tennis 3
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A93C9E60-29B6-49da-BA21-F70AC6AADE20}" = Norton Internet Security
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio module
"{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}" = Dell Media Experience
"{AC76BA86-1028-0000-7760-000000000003}" = Adobe Acrobat Professional 8 - ChineseT
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AC76BA86-7AD7-2447-5A64-7E8A45000001}" = Adobe Reader Chinese Simplified Fonts
"{AC76BA86-7AD7-2448-0000-900000000003}" = Chinese Traditional Fonts Support For Adobe Reader 9
"{AC76BA86-7AD7-5A76-5A64-7E8A45000001}" = Adobe Reader Japanese Fonts
"{AE156750-B9B5-4063-84F7-22FF638AF350}" = Windows Live Messenger
"{AE80641A-0C8D-4670-A518-B4EC154B1027}" = ACDSee 8
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7C61755-DB48-4003-948F-3D34DB8EAF69}" = MSRedist
"{BA12FD6C-169A-11D7-A6A9-00C026281E5A}" = USB Vibration Joystick
"{C037D08B-4883-491D-9329-DC5ACA90F797}" = Sony Ericsson PC Suite
"{C6F5B6CF-609C-428E-876F-CA83176C021B}" = Norton AntiVirus 2005
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CA0A1E54-CE0F-4366-B09C-A87B61DC5633}" = Symantec Network Drivers Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC23FF9A-989C-4DEB-8970-50E6E4862315}" = EOSInfo
"{D327AFC9-7BAA-473A-8319-6EB7A0D40138}" = Symantec Script Blocking Installer
"{DA42FDCA-7C5A-43EF-9A05-CCE148ADF919}" = CC_ccProxyExt
"{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}" = ccCommon
"{DE7ED7D4-B603-4678-8CFD-09BD55C2A736}" = Windows Live オ{ヲ。カー
"{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb" = Microsoft Windows Application Compatibility Database
"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}" = Norton Internet Security
"{E5EE9939-259F-4DE2-8023-5C49E16A4F43}" = Norton Internet Security
"{E85FA9A1-C241-4698-893B-DD99509B8DB0}" = Norton WMI Update
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F64306A5-4C32-41bb-B153-53986527FAB4}" = Norton WMI Update
"{F90592EC-5E58-4EE6-A333-EC05ED57ACF4}" = XLink Kai Evolution 7
"{FC08587A-4F01-4188-819F-F55880022917}" = ccPxyCore
"{FC2C0536-583C-46c0-844A-62CECAE01F22}" = Norton Internet Security
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Acrobat Professional 8 - ChineseT" = Adobe Acrobat Professional 8 - ChineseT
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player
"AdobeESD" = Adobe Download Manager 2.0 (僅供移除)
"Alipay security control_is1" = Alipay security control 2,1,2,5
"ATI Display Driver" = ATI Display Driver
"Autodesk Express Viewer" = Autodesk Express Viewer
"BitComet" = BitComet 0.84
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"CANONBJ_Deinstall_CNMCP3y.DLL" = Canon S200SP
"CdaC13Ba" = SafeCast Shared Components
"CSCLIB" = Canon Camera Support Core Library
"CutePDF Port Monitor" = CutePDF Printer Setup
"DPP" = Canon Utilities Digital Photo Professional 3.8
"EOS Utility" = Canon Utilities EOS Utility
"Flv Audio Extractor_is1" = Flv Audio Extractor 1.04
"FLV Player" = FLV Player 2.0, build 24
"G6 U-DISK Manager" = G6 U-DISK Manager Uninstall
"GetRight" = GetRight
"GoldWave v5.14" = GoldWave v5.14
"HiCalc version 1.8" = HiCalc version 1.8
"HijackThis" = HijackThis 2.0.2
"ICQLite" = ICQ 5.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"KUSO EXIF Viewer" = KUSO EXIF Viewer
"KUSO EXIF Viewer2.0" = KUSO EXIF Viewer
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 3.0 (Symantec Corporation)
"M3 GAME Manager" = M3 GAME Manager Uninstall
"MapAsia" = MapAsia
"MegauploadToolbar" = Megaupload Toolbar
"MetaFrame Presentation Server Web Client for Win32" = MetaFrame Presentation Server Web Client for Win32
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MovieSplitter" = Movie Splitter
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"ODSK" = Canon Utilities Original Data Security Tools
"OfflineList" = OfflineList 0.7.2a
"Okoker DVD Ripper_is1" = Okoker DVD Ripper 1.5
"Opanda IExif_is1" = Opanda IExif 2.3
"Opanda PowerExif Professional Trial_is1" = Opanda PowerExif 1.2 Professional Trial
"PhotoStitch" = Canon Utilities PhotoStitch
"Picture Style Editor" = Canon Utilities Picture Style Editor
"PocketAxe" = PocketAxe
"PROSetDX" = Intel® PRO Network Connections 軟體 v9.2.4.11
"PSP Brew_is1" = PSP Brew 0.91
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 6.0" = RealPlayer
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"Resco Explorer" = Resco Explorer
"Rockstar Custom Tracks" = Rockstar Custom Tracks 1.0
"Skype_is1" = Skype 3.1
"SLABCOMM&10C4&EA60" = Silicon Laboratories CP210x USB to UART Bridge (Driver Removal)
"StreamTorrent 1.0" = StreamTorrent 1.0
"Super Card_is1" = SC Ver 2.58
"SymSetup.{A93C9E60-29B6-49da-BA21-F70AC6AADE20}" = Norton Internet Security 2005 (Symantec Corporation)
"Synacast Plug-in" = Synacast Plug-in [removed]
"szPlayer" = szPlayer [removed]
"ToolbarICQToolbar.ICQToolbarObjectIEToolbar" = ICQ Toolbar
"TVAnts 1.0" = TVAnts 1.0
"Ultra MP4 Video Converter_is1" = Ultra MP4 Video Converter 5.3.0402
"WFTK" = Canon Utilities WFT-E1/E2/E3 Utility
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows Mobile Device Handbook" = Windows Mobile® 裝置手冊
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live オ{ヲ。カー
"WinRAR archiver" = WinRAR archiver
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"光影魔術手_is1" = 光影魔術手 3.01

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/6/2010 23:26:24 | Computer Name = HOME | Source = Application Error | ID = 1000
Description = 失敗的應用程式 drwtsn32.exe,版本 5.1.2600.0,失敗的模組 dbghelp.dll,版本 5.1.2600.5512,錯誤位址
0x0001295d。

Error - 7/6/2010 23:26:43 | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = 無回應的應用程式 iexplore.exe,版本 7.0.6000.17023。無回應的模組 hungapp 版本 0.0.0.0。無回應的位址
0x00000000。

Error - 7/6/2010 23:42:08 | Computer Name = HOME | Source = Microsoft Office 10 | ID = 1000
Description = Faulting application winword.exe, version 10.0.2627.0, faulting module
winword.exe, version 10.0.2627.0, fault address 0x0002644f.

Error - 7/6/2010 23:42:16 | Computer Name = HOME | Source = Microsoft Office 10 | ID = 1000
Description = Faulting application winword.exe, version 10.0.2627.0, faulting module
winword.exe, version 10.0.2627.0, fault address 0x0002644f.

Error - 7/6/2010 23:42:38 | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = 無回應的應用程式 WINWORD.EXE,版本 10.0.2627.0。無回應的模組 hungapp 版本 0.0.0.0。無回應的位址
0x00000000。

Error - 7/6/2010 23:42:41 | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = 無回應的應用程式 WINWORD.EXE,版本 10.0.2627.0。無回應的模組 hungapp 版本 0.0.0.0。無回應的位址
0x00000000。

Error - 10/6/2010 8:43:10 | Computer Name = HOME | Source = Application Error | ID = 1000
Description = 失敗的應用程式 iexplore.exe,版本 7.0.6000.17023,失敗的模組 unknown,版本 0.0.0.0,錯誤位址
0x052e0f50。

Error - 12/6/2010 3:13:38 | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = 無回應的應用程式 explorer.exe,版本 6.0.2900.5512。無回應的模組 hungapp 版本 0.0.0.0。無回應的位址
0x00000000。

Error - 12/6/2010 3:13:38 | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = 無回應的應用程式 explorer.exe,版本 6.0.2900.5512。無回應的模組 hungapp 版本 0.0.0.0。無回應的位址
0x00000000。

Error - 13/6/2010 0:31:39 | Computer Name = HOME | Source = HotFixInstaller | ID = 5000
Description = EventType visualstudio8setup, P1 microsoft .net framework 2.0-kb953300,
P2 1028, P3 1605, P4 msi, P5 f, P6 9.0.40302.0, P7 install, P8 x86, P9 xp, P10
0.

[ System Events ]
Error - 12/6/2010 14:04:57 | Computer Name = HOME | Source = BROWSER | ID = 8032
Description = 瀏覽器服務已太多次無法在 \Device\NetBT_Tcpip_{BBC0DAE8-D86D-41D2-BED3-7E1015B25061}
傳輸上擷取備份清單。 備份瀏覽器已經停止。

Error - 12/6/2010 14:05:23 | Computer Name = HOME | Source = ipnathlp | ID = 31008
Description = DNS proxy 代理程式無法從登錄讀取名稱解析伺服器 的本機清單。 資料是錯誤碼。

Error - 12/6/2010 14:33:27 | Computer Name = HOME | Source = DCOM | ID = 10010
Description = 伺服器 {F3A614DC-ABE0-11D2-A441-00C04F795683} 沒有在指定的等候逾時內登錄 DCOM。

Error - 12/6/2010 16:29:40 | Computer Name = HOME | Source = ipnathlp | ID = 31008
Description = DNS proxy 代理程式無法從登錄讀取名稱解析伺服器 的本機清單。 資料是錯誤碼。

Error - 12/6/2010 16:29:55 | Computer Name = HOME | Source = ipnathlp | ID = 31008
Description = DNS proxy 代理程式無法從登錄讀取名稱解析伺服器 的本機清單。 資料是錯誤碼。

Error - 13/6/2010 0:31:47 | Computer Name = HOME | Source = Windows Update Agent | ID = 20
Description = 安裝失敗: Windows 無法安裝下列更新,錯誤 0x80070643: KB953300:Windows 2000、Windows
Server 2003 與 Windows XP 的 Microsoft .NET Framework 2.0 Service Pack 1 安全性更新。

Error - 13/6/2010 0:41:53 | Computer Name = HOME | Source = Windows Update Agent | ID = 20
Description = 安裝失敗: Windows 無法安裝下列更新,錯誤 0x80070643: KB979906:Windows 2000 與 Windows
XP 的 Microsoft .NET Framework 1.1 SP1 安全性更新。

Error - 13/6/2010 11:30:09 | Computer Name = HOME | Source = ipnathlp | ID = 31008
Description = DNS proxy 代理程式無法從登錄讀取名稱解析伺服器 的本機清單。 資料是錯誤碼。

Error - 13/6/2010 11:31:14 | Computer Name = HOME | Source = BROWSER | ID = 8032
Description = 瀏覽器服務已太多次無法在 \Device\NetBT_Tcpip_{BBC0DAE8-D86D-41D2-BED3-7E1015B25061}
傳輸上擷取備份清單。 備份瀏覽器已經停止。

Error - 13/6/2010 11:59:42 | Computer Name = HOME | Source = ipnathlp | ID = 31008
Description = DNS proxy 代理程式無法從登錄讀取名稱解析伺服器 的本機清單。 資料是錯誤碼。


< End of report >
Hi,

The GMER scan time period varies from computer to computer, some take longer time and some shorter.

If you have any questions, please ask. :)

Please disable three security programs as below and try to run GMER again. If this fails, please go to Plan B

Disabling Windows Defender
  • Click Start > Programs > Windows Defender or launch from the system tray icon.
  • Click on Tools & Settings > Options.
  • Under Real-time protection options, uncheck the "Real-time protection" check box.
  • Click Save.
  • Go to Start > Control Panel > Security > Windows Defender, at the bottom of the Window Defenders page uncheck under Administrator Options "use Windows Defender" and then Save.
  • (When we are done, you can re-enable Defender using the same steps but this time place a check next to "Turn on real-time protection" check box.)

===================================================

NORTON ANTIVIRUS
Please navigate to the system tray on the bottom right hand corner and look for a [external image: Posted Image] sign.
  • right-click it -> chose "Disable Auto-Protect."
  • select a duration of 5 hours (this assures no interference with the cleanup of your pc)
  • click "Ok."
  • a popup will warn that protection will now be disabled and the sign will now look like this: [external image: Posted Image]
You succesfully disabled the Norton Antivirus Guard.

===================================================

Norton Internet Security
  • Please have a look at this link and follow its instructions.
  • Protection will now be disabled.
You succesfully disabled the Norton Internet Security Guard.

===================================================

Plan B

Reboot your computer in Safe Mode
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.

Then try to run GMER again and post back the results.

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI