This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Spyware.AdaEbook, AdWare.Cydoor, Adware.Clicker [Solved]

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've used avira for a long time. I found that the program cannot perform automatic updates few months ago.
So I uninstall the avira and install a new copy of avira free antivirus. The program still fail to update automatically.
I came across a post in a forum saying that infection with malwares could be the cause.
So I run a scan with malwarebytes Anti-malware and fix some problem with the log below.

Malwarebytes Anti-Malware (Trial) 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.27.03

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Kenneth :: COMP1 [administrator]

Protection: Enabled

28/1/2012 0:29:12
mbam-log-2012-01-28 (00-29-12).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 314144
Time elapsed: 1 hour(s), 55 minute(s), 8 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 3
HKCR\CLSID\{E8CFC029-8420-4EAE-ADEF-915BDC77E1DC} (Spyware.AdaEbook) -> Quarantined and deleted successfully.
HKCR\褚澄:褚氏遺書.MyNSHandler (Spyware.AdaEbook) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\YingSoft (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 1
C:\WINDOWS\system32\AdCache (AdWare.Cydoor) -> Quarantined and deleted successfully.

Files Detected: 1
C:\Program Files\Unlocker\eBay_shortcuts_1016.exe (Adware.Clicker) -> Quarantined and deleted successfully.

(end)

After that, avira still fail to update automatically.

So I am looking for help in this forum to see if my computer is infected by anything.

I ran otl with the logs below:

otl.txt
OTL logfile created on: 29/1/2012 1:31:23 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Kenneth\桌面
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C04 | Country: 香港特別行政區 | Language: ZHH | Date Format: d/M/yyyy

501.92 Mb Total Physical Memory | 97.70 Mb Available Physical Memory | 19.46% Memory free
1.20 Gb Paging File | 0.49 Gb Available in Paging File | 41.42% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.70 Gb Total Space | 4.90 Gb Free Space | 8.79% Space Free | Partition Type: NTFS
Drive D: | 56.09 Gb Total Space | 41.54 Gb Free Space | 74.06% Space Free | Partition Type: NTFS

Computer Name: COMP1 | User Name: Kenneth | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Kenneth\桌面\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\SugarSync\SugarSyncManager.exe (SugarSync, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\OrangeHRM\2.6.12.1\apache\bin\httpd.exe (Apache Software Foundation)
PRC - C:\Program Files\OrangeHRM\2.6.12.1\mysql\bin\mysqld.exe ()
PRC - C:\Program Files\SafeNet\Authentication\SAC\x32\SACSrv.exe (SafeNet, Inc.)
PRC - C:\Program Files\FlashGet Network\FlashGet 3\mxhelper.exe ()
PRC - C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe (PC Tools)
PRC - C:\Program Files\PC Tools Firewall Plus\FWService.exe (PC Tools)
PRC - C:\Program Files\CachemanXP\CachemanXP.exe (Outertech)
PRC - C:\WINDOWS\system32\slserv.exe (Smart Link)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Softex\OmniPass\OmniServ.exe (Softex Inc.)
PRC - C:\Program Files\Softex\OmniPass\OPXPApp.exe ()
PRC - C:\WINDOWS\system32\o2flash.exe (O2Micro International)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Program Files\SugarSync\QtGui4.dll ()
MOD - C:\Program Files\SugarSync\QtCore4.dll ()
MOD - C:\Program Files\SugarSync\QtNetwork4.dll ()
MOD - C:\Program Files\SugarSync\QtXml4.dll ()
MOD - C:\Program Files\OrangeHRM\2.6.12.1\apache\bin\zlib1.dll ()
MOD - C:\Program Files\OrangeHRM\2.6.12.1\mysql\bin\mysqld.exe ()
MOD - C:\Program Files\FlashGet Network\FlashGet 3\mxhelper.exe ()
MOD - C:\Program Files\Unlocker\UnlockerCOM.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\IntStngs.dll ()
MOD - C:\Program Files\Softex\OmniPass\hdddrv.dll ()
MOD - C:\Program Files\Softex\OmniPass\userdata.dll ()
MOD - C:\Program Files\Softex\OmniPass\autheng.dll ()
MOD - C:\Program Files\Softex\OmniPass\storeng.dll ()
MOD - C:\Program Files\Softex\OmniPass\OPXPGina.dll ()
MOD - C:\Program Files\Softex\OmniPass\OPXPApp.exe ()
MOD - C:\Program Files\Softex\OmniPass\ginastub.dll ()
MOD - C:\Program Files\Softex\OmniPass\opfsdll.dll ()
MOD - C:\Program Files\Softex\OmniPass\cryptodll.dll ()
MOD - C:\Program Files\Softex\OmniPass\SSPLogon.dll ()
MOD - C:\Program Files\Softex\OmniPass\sftxtgp.dll ()
MOD - C:\WINDOWS\system32\TosBtHcrpAPI.dll ()


========== Win32 Services (SafeList) ==========

SRV - (ioloSystemService) – File not found
SRV - (ioloFileInfoList) – File not found
SRV - (HidServ) – File not found
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (wampmysqld) – c:\wamp\bin\mysql\mysql5.5.16\bin\mysqld.exe ()
SRV - (wampapache) – c:\wamp\bin\apache\apache2.2.21\bin\httpd.exe (Apache Software Foundation)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (Apache2.2) – C:\Program Files\OrangeHRM\2.6.12.1\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (mysql) – C:\Program Files\OrangeHRM\2.6.12.1\mysql\bin\mysqld.exe ()
SRV - (SACSrv) – C:\Program Files\SafeNet\Authentication\SAC\x32\SACSrv.exe (SafeNet, Inc.)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (PCToolsFirewallPlus) – C:\Program Files\PC Tools Firewall Plus\FWService.exe (PC Tools)
SRV - (CachemanXPService) – C:\Program Files\CachemanXP\CachemanXP.exe (Outertech)
SRV - (SLService) – C:\WINDOWS\System32\slserv.exe (Smart Link)
SRV - (omniserv) – C:\Program Files\Softex\OmniPass\OmniServ.exe (Softex Inc.)
SRV - (O2Flash) – C:\WINDOWS\system32\o2flash.exe (O2Micro International)


========== Driver Services (SafeList) ==========

DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (dgderdrv) – C:\WINDOWS\system32\drivers\dgderdrv.sys (Devguru Co., Ltd)
DRV - (ssudmdm) SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.) – C:\WINDOWS\system32\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.) – C:\WINDOWS\system32\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avkmgr) – C:\WINDOWS\system32\drivers\avkmgr.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (BootScreen) – C:\WINDOWS\System32\drivers\vidstub.sys ()
DRV - (RnbToken) – C:\WINDOWS\system32\drivers\RNBTOKEN.SYS (SafeNet, Inc.)
DRV - (iKeyIFD) – C:\WINDOWS\system32\drivers\IKEYIFD.SYS (SafeNet, Inc.)
DRV - (iKeyEnum) – C:\WINDOWS\system32\drivers\IKEYENUM.SYS (SafeNet, Inc.)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (pctplfw) – C:\WINDOWS\system32\drivers\pctplfw.sys (PC Tools)
DRV - (PCTFW-PacketFilter) – C:\WINDOWS\system32\drivers\pctNdis-PacketFilter.sys (PC Tools)
DRV - (pctNDIS) – C:\WINDOWS\system32\drivers\pctNdis.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (PCTAppEvent) – C:\WINDOWS\system32\drivers\PCTAppEvent.sys (PC Tools)
DRV - (PCTFW-DNS) – C:\WINDOWS\system32\drivers\pctNdis-DNS.sys (PC Tools)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (AKSIFDH) – C:\WINDOWS\system32\drivers\aksifdh.sys (Aladdin Knowledge Systems, Ltd.)
DRV - (FJGSDisk) – C:\WINDOWS\system32\DRIVERS\FJGSDisk.sys (FUJITSU LIMITED)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (ATSWPDRV) AuthenTec TruePrint USB Driver (AES2500) – C:\WINDOWS\system32\drivers\atswpdrv.sys (AuthenTec, Inc.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (O2MDRDR) – C:\WINDOWS\system32\DRIVERS\o2media.sys (O2Micro )
DRV - (Tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (Tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (TosRfSnd) Bluetooth Audio Device (WDM) – C:\WINDOWS\system32\drivers\tosrfsnd.sys (TOSHIBA Corporation)
DRV - (BtnHnd) – C:\Program Files\Fujitsu\BtnHnd\BtnHnd.sys (FUJITSU LIMITED)
DRV - (O2SDRDR) – C:\WINDOWS\system32\DRIVERS\o2sd.sys (O2Micro )
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (FlashDrv) – C:\Program Files\Fujitsu\FlashAid\FlashDrv.sys (FUJITSU LIMITED)
DRV - (toshidpt) – C:\WINDOWS\system32\drivers\toshidpt.sys (TOSHIBA Corporation.)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (FUJ02E1) – C:\WINDOWS\system32\drivers\FUJ02E1.sys (Fujitsu Limited)
DRV - (FsVga) – C:\WINDOWS\system32\drivers\fsvga.sys (Microsoft Corporation)
DRV - (SlNtHal) – C:\WINDOWS\system32\drivers\slnthal.sys (Smart Link)
DRV - (SlWdmSup) – C:\WINDOWS\system32\drivers\slwdmsup.sys (Smart Link)
DRV - (Slnt7554) – C:\WINDOWS\system32\drivers\slnt7554.sys (Smart Link)
DRV - (NtMtlFax) – C:\WINDOWS\system32\drivers\ntmtlfax.sys (Smart Link)
DRV - (Mtlmnt5) – C:\WINDOWS\system32\drivers\mtlmnt5.sys (Smart Link)
DRV - (RecAgent) – C:\WINDOWS\system32\DRIVERS\RecAgent.sys (Smart Link)
DRV - (Mtlstrm) – C:\WINDOWS\system32\drivers\mtlstrm.sys (Smart Link)
DRV - (FUJ02E3) – C:\WINDOWS\system32\drivers\fuj02e3.sys (FUJITSU LIMITED)
DRV - (vcdrom) – C:\WINDOWS\system32\VCdRom.sys (Microsoft Corporation)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMC)
DRV - (FUJ02B1) – C:\WINDOWS\system32\drivers\fuj02b1.sys (FUJITSU LIMITED)
DRV - (ADVNTDRV) – C:\WINDOWS\System32\drivers\ADVNTDRV.SYS (FUJITSU LIMITED.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@safenet-inc.com/NpDkSig,version=,ISign: C:\Program Files\SafeNet\Authentication\SAC\x32\BSecClient\npDkSig.dll ()
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll File not found
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Logia\eSnipsDownloader\ext

[2009/11/09 02:35:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kenneth\Application Data\Mozilla\Extensions
[2009/11/09 01:54:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kenneth\Application Data\Mozilla\Extensions\MediaCoder
[2009/11/09 02:35:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kenneth\Application Data\Mozilla\Extensions\MediaCoder-Setup-Wizard

O1 HOSTS File: ([2010/05/21 22:47:08 | 000,000,767 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 sams.nikonimaging.com
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll (BitComet)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (FlashGetBHO) - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Documents and Settings\Kenneth\Application Data\FlashGetBHO\FlashGetBHO3.dll (Trend Media Group)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [00PCTFW] C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe (PC Tools)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [FlashGetBHO] C:\Program Files\FlashGet Network\FlashGet 3\mxhelper.exe ()
O4 - HKCU..\Run: [SugarSync] C:\Program Files\SugarSync\SugarSyncManager.exe (SugarSync, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O8 - Extra context menu item: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D&ownload all video with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: UseFlashGet - Reg Error: Value error. File not found
O8 - Extra context menu item: UseFlashGetDownloadAllLink - Reg Error: Value error. File not found
O8 - Extra context menu item: 使用快車3下載 - C:\Documents and Settings\Kenneth\Application Data\FlashGetBHO\GetUrl.htm ()
O8 - Extra context menu item: 使用快車3下載全部鏈結 - C:\Documents and Settings\Kenneth\Application Data\FlashGetBHO\GetAllUrl.htm ()
O8 - Extra context menu item: 透過Mipony下載 - C:\Program Files\MiPony\Browser\IEContext.htm ()
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll (BitComet)
O9 - Extra Button: PDFill PDF Editor - {FB858B22-55E2-413f-87F5-30ADC5552151} - C:\Program Files\PlotSoft\PDFill\DownloadPDF.exe (PlotSoft LLC)
O15 - HKCU\..Trusted Domains: samsung.com ([www] http in Trusted sites)
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} http://skqsweb.lib.cuhk.edu.hk.easyaccess1…ptX/ScriptX.cab (MeadCo ScriptX)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {31EE92CA-C0F5-48F7-AE60-B54CDF3BB76C} http://219.105.35.37/player/AcqVPlayerX_2_0_2_21.cab (AcqVPlayer Control)
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} http://picasaweb.google.com/s/v/56.20/uploader2.cab (UploadListView Class)
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} http://picasaweb.google.com.hk/s/v/33.06/uploader2.cab (UploadListView Class)
O16 - DPF: {47F7AB40-86FD-4385-991D-895E2E3E1255} http://2008.i-cable.com/webapps/live_video/p2pactx.cab (p2pactx Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1229527811437 (WUWebControl Class)
O16 - DPF: {65F928C4-032E-42DD-AB17-CBD334D4CC54} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1257695678024 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{63B5314A-DF72-4EF3-92A4-DC00975FE503}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\Userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (C:\WINDOWS\Resources\Logon\Ubuntu LogonUI\logonui.exe) -C:\WINDOWS\Resources\Logon\Ubuntu LogonUI\logonui.exe (Microsoft Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - (C:\Program Files\Softex\OmniPass\opxpgina.dll) - C:\Program Files\Softex\OmniPass\OPXPGina.dll ()
O24 - Desktop Components:0 (目前的首頁) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2006/08/03 23:38:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: ("autocheck autochk *")
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = ExeFile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: EventSystem - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.alf2cd - C:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ffdshow.ax ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: wave2 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave3 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave4 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/01/29 01:28:54 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Kenneth\桌面\OTL.exe
[2012/01/28 00:25:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Kenneth\Application Data\Malwarebytes
[2012/01/28 00:25:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\「開始」功能表\程式集\Malwarebytes' Anti-Malware
[2012/01/28 00:25:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/01/28 00:25:22 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/01/28 00:25:22 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/01/28 00:24:02 | 010,847,608 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Kenneth\桌面\mbam-setup-1.60.0.1800.exe
[2012/01/27 19:03:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Kenneth\Application Data\YCanPDF
[2012/01/27 19:03:58 | 000,000,000 | —D | C] – C:\tmp
[2012/01/27 18:52:57 | 004,578,837 | —- | C] (http://www.PDFExcelConverter.com ) – C:\Documents and Settings\Kenneth\桌面\pdf2excel.exe
[2012/01/21 00:52:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Kenneth\桌面\usbcleaner20101017
[2012/01/16 23:19:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Kenneth\桌面\time
[2012/01/16 01:41:59 | 000,000,000 | —D | C] – C:\Program Files\OrangeHRM
[2012/01/15 22:36:43 | 000,000,000 | —D | C] – C:\WINDOWS\Downloaded Installations
[2012/01/15 21:36:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Kenneth\「開始」功能表\程式集\Revo Uninstaller
[2012/01/15 13:58:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Kenneth\「開始」功能表\程式集\Accessories
[2012/01/15 13:52:27 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2012/01/15 13:47:02 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2012/01/15 13:47:02 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2012/01/15 13:46:59 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2012/01/15 03:28:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Kenneth\桌面\timeclock
[2012/01/15 03:18:14 | 000,000,000 | —D | C] – D:\My Documents\gegl-0.0
[2012/01/15 03:01:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\「開始」功能表\程式集\WampServer
[2012/01/15 03:00:15 | 000,000,000 | —D | C] – C:\wamp
[2012/01/15 01:18:25 | 000,000,000 | —D | C] – C:\Program Files\Xpress Software
[2012/01/03 00:23:22 | 000,720,896 | —- | C] (SECUi.COM) – C:\WINDOWS\System32\SecuiSEC.dll
[2012/01/03 00:23:22 | 000,102,400 | —- | C] (SECUi.COM) – C:\WINDOWS\System32\SecuiSECJsa.dll
[2004/11/25 02:25:52 | 000,335,872 | —- | C] ( ) – C:\WINDOWS\System32\drvc.dll
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/29 01:28:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kenneth\桌面\OTL.exe
[2012/01/29 01:24:50 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/01/29 01:05:53 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/01/28 00:24:02 | 010,847,608 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Kenneth\桌面\mbam-setup-1.60.0.1800.exe
[2012/01/27 19:28:19 | 000,002,095 | —- | M] () – C:\Documents and Settings\All Users\桌面\ONE-POS V3.lnk
[2012/01/27 19:01:18 | 000,024,959 | —- | M] () – C:\Documents and Settings\Kenneth\桌面\temp1.pdf
[2012/01/27 18:52:57 | 004,578,837 | —- | M] (http://www.PDFExcelConverter.com ) – C:\Documents and Settings\Kenneth\桌面\pdf2excel.exe
[2012/01/21 00:51:23 | 003,737,753 | —- | M] () – C:\Documents and Settings\Kenneth\桌面\usbcleaner20101017.zip
[2012/01/21 00:48:52 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2012/01/19 01:00:46 | 000,001,474 | —- | M] () – C:\Documents and Settings\Kenneth\.recently-used.xbel
[2012/01/19 00:48:37 | 006,475,520 | —- | M] () – C:\Documents and Settings\Kenneth\桌面\AdobeICCProfilesCS4Win_end-user.zip
[2012/01/18 23:47:51 | 000,273,073 | —- | M] () – C:\Documents and Settings\Kenneth\桌面\separate+-0.5.8.zip
[2012/01/18 23:44:44 | 000,035,695 | —- | M] () – C:\Documents and Settings\Kenneth\桌面\temp.xcf
[2012/01/15 22:37:42 | 000,000,035 | —- | M] () – C:\WINDOWS\markosoft.ini
[2012/01/15 13:58:15 | 000,000,815 | —- | M] () – C:\Documents and Settings\Kenneth\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/01/15 13:55:26 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/01/08 14:32:31 | 000,003,908 | —- | M] () – C:\Documents and Settings\Kenneth\桌面\ksmanage.htm
[2012/01/08 14:31:50 | 000,003,896 | —- | M] () – C:\Documents and Settings\Kenneth\桌面\rvd.htm
[2012/01/05 01:28:32 | 000,413,791 | —- | M] () – C:\Documents and Settings\Kenneth\桌面\hk1p.pdf
[2012/01/03 01:42:03 | 000,262,962 | —- | M] () – C:\Documents and Settings\Kenneth\桌面\NoteECsample.pdf
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/27 18:59:25 | 000,024,959 | —- | C] () – C:\Documents and Settings\Kenneth\桌面\temp1.pdf
[2012/01/21 00:51:20 | 003,737,753 | —- | C] () – C:\Documents and Settings\Kenneth\桌面\usbcleaner20101017.zip
[2012/01/19 01:00:46 | 000,001,474 | —- | C] () – C:\Documents and Settings\Kenneth\.recently-used.xbel
[2012/01/19 00:48:34 | 006,475,520 | —- | C] () – C:\Documents and Settings\Kenneth\桌面\AdobeICCProfilesCS4Win_end-user.zip
[2012/01/18 23:47:49 | 000,273,073 | —- | C] () – C:\Documents and Settings\Kenneth\桌面\separate+-0.5.8.zip
[2012/01/18 23:44:44 | 000,035,695 | —- | C] () – C:\Documents and Settings\Kenneth\桌面\temp.xcf
[2012/01/15 22:37:42 | 000,000,035 | —- | C] () – C:\WINDOWS\markosoft.ini
[2012/01/15 13:58:15 | 000,000,815 | —- | C] () – C:\Documents and Settings\Kenneth\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/01/08 14:32:31 | 000,003,908 | —- | C] () – C:\Documents and Settings\Kenneth\桌面\ksmanage.htm
[2012/01/08 14:31:50 | 000,003,896 | —- | C] () – C:\Documents and Settings\Kenneth\桌面\rvd.htm
[2012/01/05 01:28:32 | 000,413,791 | —- | C] () – C:\Documents and Settings\Kenneth\桌面\hk1p.pdf
[2012/01/03 01:42:03 | 000,262,962 | —- | C] () – C:\Documents and Settings\Kenneth\桌面\NoteECsample.pdf
[2012/01/03 00:23:22 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\SecuiSecIE.dll
[2011/12/13 02:05:55 | 000,107,480 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/10/31 11:22:42 | 000,030,568 | —- | C] () – C:\WINDOWS\MusiccityDownload.exe
[2011/10/31 11:22:40 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2011/10/31 11:22:40 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2011/10/31 11:22:40 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\issacapi_se-2.3.dll
[2011/10/31 11:22:38 | 000,974,848 | —- | C] () – C:\WINDOWS\System32\cis-2.4.dll
[2011/05/04 00:11:25 | 000,019,288 | —- | C] () – C:\Documents and Settings\Kenneth\Application Data\.cmyktool_errorlog
[2011/02/10 01:52:58 | 000,000,556 | —- | C] () – C:\WINDOWS\System32\secustat.dat
[2011/02/10 00:22:56 | 000,002,356 | —- | C] () – C:\WINDOWS\System32\secushr.dat
[2011/02/10 00:22:10 | 000,000,025 | —- | C] () – C:\WINDOWS\libem.INI
[2010/10/30 22:25:53 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/07/27 19:56:30 | 000,434,376 | —- | C] () – C:\WINDOWS\System32\DkIdentrus.dll
[2010/06/15 23:34:50 | 000,000,000 | –S- | C] () – C:\WINDOWS\System32\ONEPOSv3.ini
[2010/05/30 01:18:54 | 000,163,712 | —- | C] () – C:\WINDOWS\System32\drivers\vidstub.sys
[2010/05/21 22:38:15 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\PPD Plugins
[2010/05/21 22:38:15 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Kenneth\Application Data\Organic
[2010/05/16 06:30:31 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLbx.DAT
[2010/05/06 12:31:19 | 000,175,075 | —- | C] () – C:\WINDOWS\hphins25.dat
[2010/05/06 12:31:19 | 000,000,795 | —- | C] () – C:\WINDOWS\hphmdl25.dat
[2010/01/28 06:59:14 | 000,856,064 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2009/12/10 23:47:27 | 000,126,451 | —- | C] () – C:\WINDOWS\HPHins15.dat
[2009/12/10 23:47:27 | 000,002,885 | —- | C] () – C:\WINDOWS\hphmdl15.dat
[2009/11/14 01:30:21 | 000,000,067 | —- | C] () – C:\WINDOWS\Easy Avi Divx Xvid to DVD Burner.INI
[2009/11/12 03:42:23 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/05/22 22:57:47 | 000,000,272 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2008/11/16 23:08:16 | 000,003,216 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2008/11/02 00:58:01 | 000,002,528 | —- | C] () – C:\Documents and Settings\Kenneth\Application Data\$_hpcst$.hpc
[2008/10/19 23:29:43 | 000,000,131 | —- | C] () – C:\WINDOWS\CRC.INI
[2008/09/13 02:09:52 | 000,000,297 | —- | C] () – C:\WINDOWS\System32\admshare.dat
[2008/09/01 00:34:29 | 000,000,098 | —- | C] () – C:\WINDOWS\WirelessFTP.INI
[2008/07/25 22:29:13 | 000,000,038 | —- | C] () – C:\WINDOWS\AviSplitter.INI
[2008/07/16 21:16:17 | 000,074,703 | —- | C] () – C:\WINDOWS\System32\mfc45.dll
[2008/07/14 22:28:24 | 000,000,158 | —- | C] () – C:\WINDOWS\ncpro5.ini
[2008/07/05 18:14:48 | 000,456,192 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2008/07/05 18:14:44 | 003,591,168 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2008/07/05 18:13:16 | 000,708,096 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2008/06/23 00:34:00 | 000,177,664 | —- | C] () – C:\WINDOWS\System32\ff_theora.dll
[2008/06/13 18:39:38 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2008/06/13 01:36:38 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/06/09 10:59:52 | 000,000,000 | —- | C] () – C:\Documents and Settings\Kenneth\Application Data\AVSDVDPlayer.m3u
[2008/06/09 10:46:26 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/06/09 10:46:26 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/05/20 21:20:43 | 000,010,752 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2008/05/20 19:35:40 | 000,000,817 | —- | C] () – C:\WINDOWS\AZPR3.INI
[2008/05/18 02:03:01 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS52.DLL
[2008/05/15 20:16:06 | 000,023,040 | —- | C] () – C:\Documents and Settings\Kenneth\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/05/15 00:44:00 | 000,000,000 | —- | C] () – C:\WINDOWS\tosOBEX.INI
[2008/05/13 21:33:57 | 000,001,169 | —- | C] () – C:\WINDOWS\mozver.dat
[2008/05/12 13:33:14 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/05/12 12:42:33 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2008/05/12 11:01:32 | 000,040,960 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe
[2008/05/12 11:01:31 | 000,135,168 | R— | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2008/05/12 10:53:18 | 000,000,130 | —- | C] () – C:\Documents and Settings\Kenneth\Local Settings\Application Data\fusioncache.dat
[2008/05/12 10:50:55 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/03/28 09:01:34 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\tsclib.dll
[2006/11/02 23:10:16 | 000,080,912 | —- | C] () – C:\WINDOWS\System32\sherlock2.exe
[2006/08/25 17:18:23 | 000,003,111 | —- | C] () – C:\WINDOWS\System32\FJSaver.ini
[2006/08/03 23:40:46 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/08/03 23:36:37 | 000,021,456 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/08/03 23:35:00 | 000,004,205 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/08/03 23:33:32 | 000,247,136 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/08/03 15:02:51 | 000,000,720 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/08/03 15:02:32 | 000,328,454 | —- | C] () – C:\WINDOWS\System32\prfh0404.dat
[2006/08/03 15:02:32 | 000,113,902 | —- | C] () – C:\WINDOWS\System32\prfc0404.dat
[2006/08/03 15:02:32 | 000,112,200 | —- | C] () – C:\WINDOWS\System32\prfi0404.dat
[2006/08/03 15:02:32 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\prfd0404.dat
[2006/08/03 15:02:26 | 000,261,056 | —- | C] () – C:\WINDOWS\winhelp.exe
[2006/08/03 15:02:18 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/08/03 15:02:16 | 000,445,704 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/08/03 15:02:16 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/08/03 15:02:16 | 000,072,910 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/08/03 15:02:16 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/08/03 15:02:14 | 000,004,555 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/08/03 15:02:13 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/08/03 15:02:12 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/08/03 15:02:06 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/08/03 15:02:06 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/08/03 15:02:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/08/03 15:01:54 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/04/13 19:55:53 | 000,000,013 | -H– | C] () – C:\Program Files\IMAGE.DAT
[2006/03/07 22:43:58 | 000,013,312 | —- | C] () – C:\WINDOWS\System32\RMDevice.dll
[2005/09/02 14:44:08 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\TosBtAcc.dll
[2005/07/22 21:30:20 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\TosCommAPI.dll
[2004/10/06 06:37:20 | 000,258,048 | —- | C] () – C:\WINDOWS\System32\Manipulate.dll
[2004/10/04 00:50:54 | 000,129,024 | —- | C] () – C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004/07/20 17:04:02 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/15 14:43:28 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\TBTMonUI.dll
[2003/08/08 03:01:50 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll

========== LOP Check ==========

[2010/05/21 22:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Applause and Laugher
[2010/03/04 01:56:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010/05/16 06:30:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2010/05/30 01:24:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IconTweaker
[2008/10/17 09:33:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2008/05/13 19:19:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2010/07/10 21:58:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nokia
[2010/07/10 21:17:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache
[2010/07/10 21:56:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/11/09 23:52:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlotSoft
[2011/12/09 00:58:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2008/12/05 23:26:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2010/05/30 00:43:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Stardock
[2008/05/15 21:24:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Storm
[2012/01/29 01:32:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/05/16 06:30:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2008/08/06 13:30:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{E0FD8DB4-0B1B-427B-B11A-E920A60A344E}
[2011/05/04 00:11:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\.config
[2008/10/16 12:04:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\abcMultiactive
[2010/04/30 01:47:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\adma
[2009/11/22 04:53:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\Audacity
[2009/11/29 13:23:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\avidemux
[2009/11/14 01:28:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\AviDvdBurner
[2011/08/18 08:57:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\BITS
[2009/11/29 13:31:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\Broad Intelligence
[2010/01/02 07:24:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\CoreFTP
[2010/03/04 02:01:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\DAEMON Tools Lite
[2008/06/06 19:44:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\FileSubmit
[2011/02/10 00:21:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\FlashGet
[2011/02/10 00:21:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\FlashGetBHO
[2011/02/10 00:20:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\FlashgetSetup
[2009/11/01 23:20:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\FLV Extract
[2009/11/03 00:01:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\Founder
[2010/05/21 00:03:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\FUJIFILM
[2009/10/26 02:28:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\Geniesoft
[2011/02/15 20:27:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\GetRightToGo
[2009/01/04 16:49:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\GrabPro
[2012/01/18 23:44:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\gtk-2.0
[2009/11/09 02:34:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\iRehearse
[2008/12/12 00:35:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\Jeyo
[2010/04/14 02:33:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\Logia
[2008/12/06 01:04:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\Micro-Sys
[2011/12/19 01:17:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\Mipony
[2010/05/21 22:38:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\Nikon
[2012/01/15 00:01:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\Nokia
[2010/03/11 15:28:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\Orbit
[2010/07/10 21:57:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\PC Suite
[2009/10/11 22:13:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\PCToolsFirewallPlus
[2011/12/09 01:02:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\Samsung
[2008/08/06 13:29:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\Seven Zip
[2009/02/26 23:41:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\SlySoft
[2008/12/06 00:41:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\Sprite Software
[2008/05/15 21:26:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\StromII
[2010/04/18 15:03:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\uTorrent
[2012/01/27 19:03:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Kenneth\Application Data\YCanPDF

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/04/29 16:17:44 | 000,000,130 | —- | M] () – C:\acqv_conn.log
[2006/08/03 23:38:29 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/05/28 09:06:24 | 000,000,211 | —- | M] () – C:\boot.bak
[2011/12/18 23:41:19 | 000,000,211 | —- | M] () – C:\boot.ini
[2010/05/28 09:06:24 | 000,000,211 | —- | M] () – C:\boot.lgb
[2010/05/31 00:04:11 | 000,000,441 | —- | M] () – C:\bootbak.bat
[2004/08/12 20:00:00 | 000,213,830 | RHS- | M] () – C:\bootfont.bin
[2006/08/03 23:38:29 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/06/19 01:35:17 | 000,000,182 | —- | M] () – C:\drwtsn32.log
[2008/09/18 00:26:16 | 000,000,024 | R— | M] () – C:\endor.t
[2006/08/03 23:38:29 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/09/18 00:26:16 | 000,000,029 | R— | M] () – C:\m1.p
[2006/08/03 23:38:29 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/12 20:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/10/07 13:56:52 | 000,257,728 | RHS- | M] () – C:\ntldr
[2012/01/29 01:05:51 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
[2008/06/08 02:40:03 | 000,002,858 | —- | M] () – C:\rollback.ini
[2008/05/20 20:08:38 | 000,000,006 | —- | M] () – C:\sysnt_32.ini
[2010/08/26 11:58:35 | 000,000,084 | —- | M] () – C:\tcsftp.dat
[2010/08/26 11:57:38 | 000,000,000 | —- | M] () – C:\tcsftp.exe

< %systemroot%\Fonts\*.com >
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/08/03 23:38:04 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/11/30 05:00:00 | 000,020,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD52.DLL
[2005/11/30 05:00:00 | 000,059,392 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP52.DLL
[2008/07/06 20:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/03/28 13:57:34 | 000,274,944 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5ha.dll
[2007/10/20 18:21:50 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2008/07/06 18:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/09/03 22:43:41 | 000,001,762 | -H– | M] () – C:\Documents and Settings\Kenneth\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2008/05/12 11:01:43 | 000,000,206 | —- | M] () – C:\Program Files\Audio.log
[2008/05/12 11:03:35 | 000,000,297 | —- | M] () – C:\Program Files\DisplayManager.log
[2008/05/12 11:03:31 | 000,000,327 | —- | M] () – C:\Program Files\FlashAid.log
[2008/05/12 11:03:22 | 000,000,354 | —- | M] () – C:\Program Files\HotkeyUtility.log
[2006/01/08 02:09:42 | 000,000,013 | -H– | M] () – C:\Program Files\IMAGE.DAT
[2008/05/12 11:00:31 | 000,000,182 | —- | M] () – C:\Program Files\Mouse.log
[2008/05/12 11:03:06 | 000,000,163 | —- | M] () – C:\Program Files\NaviSetup.log
[2008/05/12 11:02:58 | 000,000,161 | —- | M] () – C:\Program Files\Omnipass.log
[2008/05/12 11:03:41 | 000,000,348 | —- | M] () – C:\Program Files\RadioControl.log
[2008/05/12 11:03:32 | 000,000,160 | —- | M] () – C:\Program Files\SetupAP.log
[2008/05/12 11:03:33 | 000,000,165 | —- | M] () – C:\Program Files\SetupFA.log
[2008/05/12 11:03:41 | 000,000,032 | —- | M] () – C:\Program Files\SetupFDM4.0.log
[2008/05/12 11:03:23 | 000,000,179 | —- | M] () – C:\Program Files\SetupHK.log
[2008/05/12 11:03:42 | 000,000,187 | —- | M] () – C:\Program Files\SetupRC.log
[2008/05/12 11:03:19 | 000,000,164 | —- | M] () – C:\Program Files\SetupSEU.log
[2008/05/12 11:03:17 | 000,000,379 | —- | M] () – C:\Program Files\SEU.log
[2008/05/12 11:03:26 | 000,000,345 | —- | M] () – C:\Program Files\TouchButton.log
[2008/05/12 11:02:29 | 000,000,260 | —- | M] () – C:\Program Files\Video.log

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/08/04 07:33:15 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2006/08/04 07:33:15 | 000,647,168 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2006/08/04 07:33:15 | 000,438,272 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2006/01/17 02:57:56 | 000,005,120 | -HS- | M] () – C:\WINDOWS\system32\Thumbs.db
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/10/07 14:15:38 | 000,000,112 | -HS- | M] () – C:\Documents and Settings\Kenneth\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/08/03 23:42:03 | 000,000,079 | —- | M] () – C:\Documents and Settings\Kenneth\Application Data\Microsoft\Internet Explorer\Quick Launch\顯示桌面.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >
[2003/06/13 17:23:00 | 000,004,304 | —- | M] () – C:\WINDOWS\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoRebootWithLoggedOnUsers" = 0

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< >

========== Files - Unicode (All) ==========
[2011/09/08 19:50:38 | 000,002,407 | —- | M] ()(C:\Documents and Settings\Kenneth\桌面\十二生肖?灸?法.txt) – C:\Documents and Settings\Kenneth\桌面\十二生肖针灸疗法.txt
[2011/09/08 19:50:38 | 000,002,407 | —- | C] ()(C:\Documents and Settings\Kenneth\桌面\十二生肖?灸?法.txt) – C:\Documents and Settings\Kenneth\桌面\十二生肖针灸疗法.txt

========== Alternate Data Streams ==========

@Alternate Data Stream - 24 bytes -> C:\WINDOWS:82E271A46B3DC674
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C31F31E6

< End of report >


extras.txt
OTL Extras logfile created on: 29/1/2012 1:31:24 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Kenneth\桌面
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C04 | Country: 香港特別行政區 | Language: ZHH | Date Format: d/M/yyyy

501.92 Mb Total Physical Memory | 97.70 Mb Available Physical Memory | 19.46% Memory free
1.20 Gb Paging File | 0.49 Gb Available in Paging File | 41.42% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.70 Gb Total Space | 4.90 Gb Free Space | 8.79% Space Free | Partition Type: NTFS
Drive D: | 56.09 Gb Total Space | 41.54 Gb Free Space | 74.06% Space Free | Partition Type: NTFS

Computer Name: COMP1 | User Name: Kenneth | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [FinePix] – "C:\Program Files\FinePixViewer\FinePixViewer.exe" "%1" (FUJIFILM Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"22902:TCP" = 22902:TCP:*:Enabled:BitComet 22902 TCP
"22902:UDP" = 22902:UDP:*:Enabled:BitComet 22902 UDP
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"8080:TCP" = 8080:TCP:*:Enabled:BitComet 8080 TCP
"8080:UDP" = 8080:UDP:*:Enabled:BitComet 8080 UDP
"26901:TCP" = 26901:TCP:*:Enabled:BitComet 26901 TCP
"26901:UDP" = 26901:UDP:*:Enabled:BitComet 26901 UDP
"500:TCP" = 500:TCP:*:Enabled:BitComet 500 TCP
"500:UDP" = 500:UDP:*:Enabled:BitComet 500 UDP
"20503:TCP" = 20503:TCP:*:Enabled:BitComet 20503 TCP
"20503:UDP" = 20503:UDP:*:Enabled:BitComet 20503 UDP
"11126:TCP" = 11126:TCP:*:Enabled:BitComet 11126 TCP
"11126:UDP" = 11126:UDP:*:Enabled:BitComet 11126 UDP
"60000:TCP" = 60000:TCP:*:Enabled:BitComet 60000 TCP
"60000:UDP" = 60000:UDP:*:Enabled:BitComet 60000 UDP
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:μTorrent – (BitTorrent, Inc.)
"C:\WINDOWS\system32\fxsclnt.exe" = C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console – (Microsoft Corporation)
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\BitComet\BitComet.exe" = C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client – (www.BitComet.com)
"C:\Downloads\flashget_6268_1.exe" = C:\Downloads\flashget_6268_1.exe:*:Enabled:fg_ol_setup
"C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe" = C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3 – (Trend Media Corporation Limited)
"C:\WINDOWS\system32\muzapp.exe" = C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player – (Musiccity Co.Ltd.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0AC9EC4C-7DEB-4B5C-A4FE-766B581F404E}" = 漢王OCR 5.0 增強版
"{0C07CBAC-F2DF-4849-A284-E4255A2F9464}" = SafeNet Authentication Client 8.0
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{130A7A12-4F90-439C-AB47-0DCF3C808176}" = Fujitsu System Extension Utility
"{1CC79857-A9CE-4130-8FAC-D4CC8BAE1C73}" = ONE-POS FREE POS System
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{232FDC0C-12DE-41F2-9701-27EFCA18BEF9}" = MediaJoin
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.5.5
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java™ 6 Update 29
"{2753C1D6-270D-49A8-BC18-97BE21BC8BBC}" = Fujitsu Display Manager
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{29A725D7-50B6-33D5-8FAC-239EFC439C96}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - CHT
"{29F563F4-8807-4496-8463-441EAA0E96AB}" = PC Connectivity Solution
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B6-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{394BE3D9-7F57-4638-A8D1-1D88671913B7}" = Microsoft AppLocale
"{3C3758FA-C2DF-4E10-9D29-0CC28DA9214A}" = FlashAid
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{577CD3CD-8820-47D7-96DB-C43692ADE8A5}" = Microsoft ActiveSync
"{5B09BD67-4C99-46A1-8161-B7208CE18121}" = QuickTime
"{6257E290-5E8E-11D4-9B8D-00D0B72459DD}" = SafeNet iKey Driver v4.1.1.5
"{6BFDC0CD-ADF5-49F6-8A47-3177EF2AE6D2}" = Google Book Downloader
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{70B6A483-F815-4879-9AA4-3DCE9BCC61A0}" = Shock Sensor Utility
"{7236B969-6A18-42DD-ADE4-BBA2604F34C8}" = DJ_SF_03_D2500_Software_Min
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{75C22B40-6D12-4439-80DC-CAB3313EADA5}" = dj_sf_software_req
"{7C05EEDD-E565-4E2B-ADE4-0C784C17311C}" = Crystal Reports for .NET Framework 2.0 (x86)
"{7CBD8A89-45F4-4203-9923-673F72603747}" = Adobe Photoshop Lightroom 2.3
"{7E20EFE6-E604-48C6-8B39-BA4742F2CDB4}" = Zune Desktop Theme
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8B993121-CF5C-43C0-9296-0C1B7F515B27}" = O2Micro Smartcard Driver
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{90120000-0010-0404-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Chinese (Traditional)) 12
"{90120000-0015-0000-0000-0000000FF1CE}" = Microsoft Office Access 2007
"{90120000-0015-0404-0000-0000000FF1CE}" = Microsoft Office Access MUI (Chinese (Traditional)) 2007
"{90120000-0016-0000-0000-0000000FF1CE}" = Microsoft Office Excel 2007
"{90120000-0016-0404-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Chinese (Traditional)) 2007
"{90120000-0018-0000-0000-0000000FF1CE}" = Microsoft Office PowerPoint 2007
"{90120000-0018-0404-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Chinese (Traditional)) 2007
"{90120000-001A-0000-0000-0000000FF1CE}" = Microsoft Office Outlook 2007
"{90120000-001A-0404-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Chinese (Traditional)) 2007
"{90120000-001B-0000-0000-0000000FF1CE}" = Microsoft Office Word 2007
"{90120000-001B-0404-0000-0000000FF1CE}" = Microsoft Office Word MUI (Chinese (Traditional)) 2007
"{90120000-001F-0404-0000-0000000FF1CE}" = Microsoft Office Proof (Chinese (Traditional)) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-0028-0404-0000-0000000FF1CE}" = Microsoft Office IME (Chinese (Traditional)) 2007
"{90120000-002C-0404-0000-0000000FF1CE}" = Microsoft Office Proofing (Chinese (Traditional)) 2007
"{90120000-006E-0404-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Chinese (Traditional)) 2007
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{90CC4231-94AC-45CD-991A-0253BFAC0650}" = mDrWiFi
"{92354E91-92E0-3C7D-A030-936F88E75451}" = Microsoft .NET Framework 3.5 Language Pack SP1 - cht
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98736A65-3C79-49EC-B7E9-A3C77774B0E6}" = Google SketchUp 6
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{A0377175-5908-42CB-9D01-DD9FFFC88539}" = Application Suite
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1028-7B44-A83000000003}" = Adobe Reader 8.3.1 - Chinese Traditional
"{AC76BA86-7AD7-2447-0000-800000000003}" = Chinese Simplified Fonts Support For Adobe Reader 8
"{AC76BA86-7AD7-5760-0000-800000000003}" = Japanese Fonts Support For Adobe Reader 8
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B223DB66-E5EC-4F19-B8C8-274EB876094C}" = O2Micro Flash Memory Card Windows Driver
"{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}" = Google SketchUp 6
"{B41D74C6-886C-4406-AE27-241590A6C433}" = Fujitsu Radio Control
"{B44529FF-501E-47CD-A06D-223C161BE058}" = FinePixViewer Resource
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCEFF8D8-A712-4C04-8F37-D1C2E6731BE0}" = FortuneMaker
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D10AB8DE-0ED1-4152-A247-FB89CF1435D5}" = HP Deskjet D2500 Printer Driver Software 11.0 Rel .3
"{D1399216-81B2-457C-A0F7-73B9A2EF6902}" = PDFill PDF Editor with FREE Writer and FREE Tools
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D4276E73-31BE-495D-AE16-7022EC9D398E}" = TrustNet Web ToolKit For SEC
"{D7017D91-E22E-480D-B9A8-A3BC12425156}" = LifeBook Application Panel
"{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb" = Microsoft Windows Application Compatibility Database
"{E0C18BB0-32CA-4679-B422-9B9FA825378F}" = HP Deskjet Printer Driver Software 9.0
"{E0FAA0BA-874E-47C8-9ECA-BB333006CF16}" = Update Navi
"{E3B3AB03-8ABC-46CF-8CA9-DB5581E1F368}" = FinePix Studio
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{E96B0085-6659-486b-A221-5042A042728D}" = Toolbox
"{EDFE2E1D-FF41-369C-9F54-86EFA9DB8833}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - CHT
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E2B312-D7FD-4349-A9B6-E90B36DB1BD0}" = Paint.NET v3.5.5
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4E57F49-84B4-4CF2-B0A1-8CA1752BDF7E}" = OmniPass
"{F64394E6-46D6-48F3-9701-3629D6CDD092}" = Fingerprint Sensor Minimum Install
"{F7B0E599-C114-4493-BC4D-D8FC7CBBABBB}" = 32 Bit HP CIO Components Installer
"{FB0BBE4E-6D4D-47A7-A015-7F1C154A66A3}" = Fujitsu Hotkey Utility
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"504244733D18C8F63FF584AEB290E3904E791693" = Windows 驅動程式封裝 - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Access" = Microsoft Office Access 2007
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Avira AntiVir Desktop" = Avira Free Antivirus
"BitComet" = BitComet 1.01
"BootSkin" = BootSkin
"C5A76DC11BABDA0A881E7BE8DDEB641365A77FFD" = Windows 驅動程式封裝 - Nokia Modem (05/22/2008 3.8)
"Capture NX 2" = Capture NX 2
"CDex" = CDex extraction audio
"Core FTP LE 2.1" = Core FTP LE 2.1
"DAB436C4031D4395E5025EEF529E9B04643E6900" = Windows 驅動程式封裝 - Hewlett-Packard hp scanjet 3600 series (01/17/2007 8.1.0.77)
"EXCEL" = Microsoft Office Excel 2007
"IconTweaker" = IconTweaker
"ie8" = Windows Internet Explorer 8
"ImagePrinter" = ImagePrinter 1.5.5
"InstallShield_{2753C1D6-270D-49A8-BC18-97BE21BC8BBC}" = Fujitsu Display Manager
"InstallShield_{70B6A483-F815-4879-9AA4-3DCE9BCC61A0}" = Shock Sensor Utility
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{8B993121-CF5C-43C0-9296-0C1B7F515B27}" = O2Micro Smartcard Driver
"InstallShield_{B223DB66-E5EC-4F19-B8C8-274EB876094C}" = O2Micro Flash Memory Card Windows Driver
"IrfanView" = IrfanView (remove only)
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - cht" = Microsoft .NET Framework 3.5 粂ē甅ン SP1 - 羉砰いゅ
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"MiPony" = MiPony 1.5.0
"MSHKSCS2001" = MS HKSCS-2001 Support
"OrangeHRM" = OrangeHRM - Opensource HR management
"Orbit_is1" = Orbit Downloader
"OUTLOOK" = Microsoft Office Outlook 2007
"PC Tools Firewall Plus" = PC Tools Firewall Plus 6.0
"pdfFactory Pro" = pdfFactory Pro
"Picasa 3" = Picasa 3
"POWERPOINT" = Microsoft Office PowerPoint 2007
"ProInst" = Intel® PROSet/無線軟體
"Revo Uninstaller" = Revo Uninstaller 1.93
"SwitchOff" = Switch Off
"SyncBack_is1" = SyncBack
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TagScanner_is1" = TagScanner 5.0 build 525
"Unlocker" = Unlocker 1.8.7
"WampServer 2_is1" = WampServer 2.2
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR 壓縮工具
"WMFDist11" = Windows Media Format 11 runtime
"WORD" = Microsoft Office Word 2007
"Wudf01009" = Microsoft User-Mode Driver Framework Feature Pack 1.9
"XP Codec Pack" = XP Codec Pack
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"快車(FlashGet)3.5" = 快車(FlashGet)3.5 正式版

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SugarSync" = SugarSync Manager
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 19/1/2012 14:10:54 | Computer Name = COMP1 | Source = Microsoft Office 12 | ID = 1000
Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028,
faulting module hpz3r5ha.dll, version 61.71.246.0, stamp 460a27bd, debug? 0, fault
address 0x000467e8.

Error - 20/1/2012 12:21:45 | Computer Name = COMP1 | Source = Microsoft Office 12 | ID = 1000
Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028,
faulting module hpz3r5ha.dll, version 61.71.246.0, stamp 460a27bd, debug? 0, fault
address 0x000467e8.

Error - 27/1/2012 7:04:03 | Computer Name = COMP1 | Source = Application Error | ID = 1000
Description = 失敗的應用程式 pdf2excel.exe,版本 3.0.0.2,失敗的模組 pdftox.dll,版本 1.2.0.0,錯誤位址
0x00004360。

Error - 27/1/2012 7:04:48 | Computer Name = COMP1 | Source = Application Error | ID = 1000
Description = 失敗的應用程式 pdf2excel.exe,版本 3.0.0.2,失敗的模組 pdftox.dll,版本 1.2.0.0,錯誤位址
0x00004360。

Error - 27/1/2012 12:10:12 | Computer Name = COMP1 | Source = EventSystem | ID = 4609
Description = COM+ 事件系統在內部處理時偵測到錯誤的傳回碼。HRESULT 是 80070424,來自 d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp
的行 44。請與 Microsoft 產品支援服務聯絡,以報告這個錯誤

Error - 27/1/2012 12:10:12 | Computer Name = COMP1 | Source = VSS | ID = 8193
Description = 磁碟區陰影複製服務錯誤: 呼叫常式 CoCreateInstance 時發生意外錯誤。 hr = 0x80040206。

Error - 27/1/2012 17:32:16 | Computer Name = COMP1 | Source = EventSystem | ID = 4609
Description = COM+ 事件系統在內部處理時偵測到錯誤的傳回碼。HRESULT 是 80070424,來自 d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp
的行 44。請與 Microsoft 產品支援服務聯絡,以報告這個錯誤

Error - 27/1/2012 17:32:16 | Computer Name = COMP1 | Source = VSS | ID = 8193
Description = 磁碟區陰影複製服務錯誤: 呼叫常式 CoCreateInstance 時發生意外錯誤。 hr = 0x80040206。

Error - 28/1/2012 13:06:19 | Computer Name = COMP1 | Source = EventSystem | ID = 4609
Description = COM+ 事件系統在內部處理時偵測到錯誤的傳回碼。HRESULT 是 80070424,來自 d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp
的行 44。請與 Microsoft 產品支援服務聯絡,以報告這個錯誤

Error - 28/1/2012 13:06:19 | Computer Name = COMP1 | Source = VSS | ID = 8193
Description = 磁碟區陰影複製服務錯誤: 呼叫常式 CoCreateInstance 時發生意外錯誤。 hr = 0x80040206。

[ OSession Events ]
Error - 28/4/2010 14:57:47 | Computer Name = YOUR-B910977560 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 18221 seconds with 780 seconds of active time. This session ended with a
crash.

Error - 3/5/2010 13:21:09 | Computer Name = YOUR-B910977560 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 13688 seconds with 4260 seconds of active time. This session ended with
a crash.

Error - 25/5/2010 15:14:50 | Computer Name = YOUR-B910977560 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 19954 seconds with 4920 seconds of active time. This session ended with
a crash.

Error - 25/5/2010 15:15:34 | Computer Name = YOUR-B910977560 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 22 seconds with 0 seconds of active time. This session ended with a crash.

Error - 25/5/2010 15:16:47 | Computer Name = YOUR-B910977560 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 67 seconds with 60 seconds of active time. This session ended with a crash.

Error - 26/5/2010 13:12:42 | Computer Name = YOUR-B910977560 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 4181 seconds with 3240 seconds of active time. This session ended with a
crash.

Error - 26/5/2010 15:26:20 | Computer Name = YOUR-B910977560 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session
lasted 8008 seconds with 3660 seconds of active time. This session ended with a
crash.

Error - 12/6/2010 13:08:01 | Computer Name = YOUR-B910977560 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 8527
seconds with 5520 seconds of active time. This session ended with a crash.

Error - 10/7/2010 13:34:55 | Computer Name = YOUR-B910977560 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 10118
seconds with 4020 seconds of active time. This session ended with a crash.

Error - 12/11/2010 13:38:27 | Computer Name = COMP1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 4611
seconds with 1860 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 27/1/2012 12:10:45 | Computer Name = COMP1 | Source = Service Control Manager | ID = 7000
Description = iolo FileInfoList Service 服務無法啟動,因為發生下列錯誤: %%2

Error - 27/1/2012 12:10:45 | Computer Name = COMP1 | Source = Service Control Manager | ID = 7000
Description = iolo System Service 服務無法啟動,因為發生下列錯誤: %%2

Error - 27/1/2012 12:10:45 | Computer Name = COMP1 | Source = Service Control Manager | ID = 7003
Description = System Event Notification 服務依存於下列不存在的服務: EventSystem

Error - 27/1/2012 17:32:18 | Computer Name = COMP1 | Source = sr | ID = 1
Description = 系統還原篩選器在磁碟區 HarddiskVolume1 處理檔案 時遇到意外錯誤 0xC0000001。系統還原已經停止監視磁碟區。

Error - 27/1/2012 17:32:27 | Computer Name = COMP1 | Source = Service Control Manager | ID = 7000
Description = iolo FileInfoList Service 服務無法啟動,因為發生下列錯誤: %%2

Error - 27/1/2012 17:32:27 | Computer Name = COMP1 | Source = Service Control Manager | ID = 7000
Description = iolo System Service 服務無法啟動,因為發生下列錯誤: %%2

Error - 27/1/2012 17:32:27 | Computer Name = COMP1 | Source = Service Control Manager | ID = 7003
Description = System Event Notification 服務依存於下列不存在的服務: EventSystem

Error - 28/1/2012 13:06:34 | Computer Name = COMP1 | Source = Service Control Manager | ID = 7000
Description = iolo FileInfoList Service 服務無法啟動,因為發生下列錯誤: %%2

Error - 28/1/2012 13:06:34 | Computer Name = COMP1 | Source = Service Control Manager | ID = 7000
Description = iolo System Service 服務無法啟動,因為發生下列錯誤: %%2

Error - 28/1/2012 13:06:34 | Computer Name = COMP1 | Source = Service Control Manager | ID = 7003
Description = System Event Notification 服務依存於下列不存在的服務: EventSystem


< End of report >
Hi camelpig and welcome to WhatTheTech forums!
I'm Sunyata and I will be helping you with your computer problems.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts before I post them. This is to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my very best to keep it as short as possible.

Please read the following guidelines which will help to make cleaning your machine easier:

  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • The fixes I will give you are specific to your problem and should only be used for this issue on this machine.
  • Please make sure to carefully read any instructions posted. If you're not sure, please stop and ask!
  • Please stay with this thread until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that all malware is gone.
  • PLEASE DO NOT install/uninstall any programs unless asked to.
  • PLEASE DO NOT run any malware scans other than those requested.
  • Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
  • I will reply back shortly with instructions

Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
Thanks for your attention. I am quite sure that there must be some backdoors in my comp. My avira detect the TR/Trash.Gen' [trojan] recently. Avira log as follows: The file 'C:\System Volume Information\_restore{C9E5CCB0-79D6-4912-A295-161EB9450D98}\RP900\A0188615.exe' contained a virus or unwanted program 'TR/Trash.Gen' [trojan] Action(s) taken: The file was moved to the quarantine directory under the name '4d816858.qua'.
Hello camelpig

Please download aswMBR to your desktop.
  • Double click the aswMBR icon to run it.

    Vista and Windows 7 users right click the icon and choose "Run as administrator".

  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]

Thanks. aswMBR log as follows: aswMBR version 0.9.9.1532 Copyright© 2011 AVAST Software Run date: 2012-01-30 23:31:07 —————————– 23:31:07.531 OS Version: Windows 5.1.2600 Service Pack 3 23:31:07.531 Number of processors: 2 586 0xF06 23:31:07.531 ComputerName: COMP1 UserName: 23:31:10.656 Initialize success 23:33:46.609 AVAST engine defs: 12013000 23:34:40.187 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 23:34:40.187 Disk 0 Vendor: FUJITSU_ 0000 Size: 114473MB BusType: 3 23:34:40.203 Disk 0 MBR read successfully 23:34:40.203 Disk 0 MBR scan 23:34:41.312 Disk 0 Windows XP default MBR code 23:34:41.328 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 57035 MB offset 63 23:34:41.953 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 57435 MB offset 116808615 23:34:42.140 Disk 0 scanning sectors +234436545 23:34:42.468 Disk 0 scanning C:\WINDOWS\system32\drivers 23:35:17.765 Service scanning 23:35:19.984 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32 23:35:20.843 Modules scanning 23:35:33.562 Disk 0 trace - called modules: 23:35:33.578 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll iaStor.sys spwg.sys >>UNKNOWN [0x8317b938]<< 23:35:33.578 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x830e2750] 23:35:33.593 3 CLASSPNP.SYS[f86a5fd7] -> nt!IofCallDriver -> \Device\000000a9[0x830e7700] 23:35:33.593 5 ACPI.sys[f83d9620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x82b89030] 23:35:36.031 AVAST engine scan C:\ 00:01:52.859 File: C:\Documents and Settings\Kenneth\桌面\my usb backup\USBCleaner6.0\UPDATE.Exe **INFECTED** Win32:Malware-gen 00:30:47.875 File: C:\System Volume Information\_restore{C9E5CCB0-79D6-4912-A295-161EB9450D98}\RP896\A0188016.exe **INFECTED** Win32:Malware-gen 00:53:02.765 Scan finished successfully 00:57:55.656 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Kenneth\桌面\MBR.dat" 00:57:55.687 The log file has been saved successfully to "C:\Documents and Settings\Kenneth\桌面\aswMBR.txt" Also avira detects few trojans in my comp. Very terrible!
Hello camelpig

Next, we need to run an OTL Fix

  • Please reopen [external image: Posted Image].
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    
    :OTL
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: File not found
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
    FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll File not found
    O4 - HKLM..\Run: [] File not found
    O8 - Extra context menu item: UseFlashGet - Reg Error: Value error. File not found
    O8 - Extra context menu item: UseFlashGetDownloadAllLink - Reg Error: Value error. File not found
    O16 - DPF: {65F928C4-032E-42DD-AB17-CBD334D4CC54} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    [2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    @Alternate Data Stream - 24 bytes -> C:\WINDOWS:82E271A46B3DC674
    
    :Files
    C:\Documents and Settings\Kenneth\桌面\my usb backup\USBCleaner6.0\UPDATE.Exe
    
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [Reboot]

  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
How is the machine behaving now? What are the issues?
Thanks for your help. The first time I ran the fix, otl crash with the malwarebyte and the system hung up. Next time, I switched off the malwarebyte before running the fix, the system still hung up. OTL created a _otl folder under c: with one subfolder "MoveFiles" with nothings inside. So what should I do next? Actually the system still functions except it is a bit slow with frequent detection of torjan activities by avira.
Hello camelpig

Let's see if we can eliminate any malware stopping us from running OTL…

Download RogueKiller to your desktop

  • Quit all running programs
  • For Vista/Seven, right click -> run as administrator, for XP simply run RogueKiller.exe
  • When prompted, type 2 and validate
  • The RKreport.txt shall be generated next to the executable.
  • If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
Please post the contents of the RKreport.txt in your next Reply

Next, try the OTL Fix again

  • Please reopen [external image: Posted Image].
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    
    :OTL
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: File not found
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
    FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll File not found
    O4 - HKLM..\Run: [] File not found
    O8 - Extra context menu item: UseFlashGet - Reg Error: Value error. File not found
    O8 - Extra context menu item: UseFlashGetDownloadAllLink - Reg Error: Value error. File not found
    O16 - DPF: {65F928C4-032E-42DD-AB17-CBD334D4CC54} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    [2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    @Alternate Data Stream - 24 bytes -> C:\WINDOWS:82E271A46B3DC674
    
    :Files
    C:\Documents and Settings\Kenneth\桌面\my usb backup\USBCleaner6.0\UPDATE.Exe
    
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [Reboot]

  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
How is the machine behaving now? Is it running any faster?
After running rougekiller, everytime running the otl fix, the system hung.

The log of rougekiller:
RogueKiller V7.0.2 [01/30/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Kenneth [Admin rights]
Mode: Remove – Date : 02/01/2012 22:53:31

??? Bad processes: 0 中?

??? Registry Entries: 5 中?
[PROXY IE] HKCU\[…]\Internet Settings : ProxyServer (:) -> NOT REMOVED, USE PROXYFIX
[DNS] HKLM\[…]\ControlSet001\Parameters\Interfaces\{9E41DFA5-D923-4060-9BAD-786FE136A536} : NameServer (218.102.62.71,203.198.23.208) -> NOT REMOVED, USE DNSFIX
[HJ] HKCU\[…]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> REPLACED (1)
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[FILEASSO] HKCR\.exe : (ExeFile) -> REPLACED (exefile)

??? Particular Files / Folders: ???

??? Driver: [LOADED] 中?

中?Infection : Rogue.AntiSpy-AH 中?

??? HOSTS File: ???
127.0.0.1 localhost
127.0.0.1 sams.nikonimaging.com


??? MBR Check: ???

+++++ PhysicalDrive0: FUJITSU MHV2120BH PL +++++
— User —
[MBR] d7f51dffe5d649a5aecec77154b56b27
[BSP] cc772a30909d0ec311973f06dd75b94b : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 57035 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 116808615 | Size: 57435 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt

Does it matter that my comp is a Chinese version system and it conflicts with otl or otl customs fix code does not support chinese character?
Hello camelpig

Does it matter that my comp is a Chinese version system and it conflicts with otl or otl customs fix code does not support chinese character?

Our scanning tools, like OTL and ComboFix below, should have no problems with Chinese characters.


Please read through these instructions to familarize yourself with what to expect when this tool runs

Please download ComboFix from one of the following locations:
  • LINK 1
  • LINK 2
**IMPORTANT! Save ComboFix to your Desktop. Read the following thoroughly
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link :How to Disable your Security Programs
  • Double click on 'ComboFix.exe' & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message box:



[external image: Posted Image]


Click on 'Yes', to continue scanning for malware.

When finished, it will produce a log for you.
Please include the contents of C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making Internet Explorer the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please let me know.
5. ComboFix disconnects your machine from the internet. The connection is automatically restored before ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

In your next reply please post the log created by ComboFix.
As I can't shut down avira so i first uninstall it before running the combo fix.

Log:
ComboFix 12-02-02.01 - Kenneth 2/2012 Fri 0:00.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.[removed].18.502.73 [GMT 8:00]
執行位置: c:\documents and settings\Kenneth\桌面\ComboFix.exe
AV: Avira Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: PC Tools Firewall Plus *Disabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
* 成功創造新還原點
.
Error: Cfiles.dat
ADS - WINDOWS: deleted 24 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( 被刪除的檔案 )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Storm
c:\documents and settings\All Users\Application Data\Storm\Update\aac_ps.ax
c:\documents and settings\All Users\Application Data\Storm\update\aasc32.dll
c:\documents and settings\All Users\Application Data\Storm\Update\ac3filter.ax
c:\documents and settings\All Users\Application Data\Storm\update\asusasv1.dll
c:\documents and settings\All Users\Application Data\Storm\Update\asusasv2.dll
c:\documents and settings\All Users\Application Data\Storm\update\atidvdv.ax
c:\documents and settings\All Users\Application Data\Storm\update\ativcr2.dll
c:\documents and settings\All Users\Application Data\Storm\update\avidavicodec.dll
c:\documents and settings\All Users\Application Data\Storm\update\binkw32.dll
c:\documents and settings\All Users\Application Data\Storm\update\cddareader.ax
c:\documents and settings\All Users\Application Data\Storm\update\cdxareader.ax
c:\documents and settings\All Users\Application Data\Storm\update\CLRVIDDC.DLL
c:\documents and settings\All Users\Application Data\Storm\update\clrviddd.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Codec\RadGtSplitter.ax
c:\documents and settings\All Users\Application Data\Storm\update\com.apple.QuickTime.plist
c:\documents and settings\All Users\Application Data\Storm\update\CoreAVC.ax
c:\documents and settings\All Users\Application Data\Storm\update\DECVW_32.DLL
c:\documents and settings\All Users\Application Data\Storm\Update\DmoDec.dll
c:\documents and settings\All Users\Application Data\Storm\update\dxr.dll
c:\documents and settings\All Users\Application Data\Storm\Update\ff_kerneldeint.dll
c:\documents and settings\All Users\Application Data\Storm\Update\ff_liba52.dll
c:\documents and settings\All Users\Application Data\Storm\update\ff_libdts.dll
c:\documents and settings\All Users\Application Data\Storm\Update\ff_realaac.dll
c:\documents and settings\All Users\Application Data\Storm\Update\ff_samplerate.dll
c:\documents and settings\All Users\Application Data\Storm\Update\ff_tremor.dll
c:\documents and settings\All Users\Application Data\Storm\Update\ff_vfw.dll
c:\documents and settings\All Users\Application Data\Storm\update\ff_vfw.dll.manifest
c:\documents and settings\All Users\Application Data\Storm\update\ffdshow.ax
c:\documents and settings\All Users\Application Data\Storm\Update\ffdshow.ax.manifest
c:\documents and settings\All Users\Application Data\Storm\update\FLAC.ax
c:\documents and settings\All Users\Application Data\Storm\update\FLVSplitter.ax
c:\documents and settings\All Users\Application Data\Storm\update\frapsvid.dll
c:\documents and settings\All Users\Application Data\Storm\update\i263_32.drv
c:\documents and settings\All Users\Application Data\Storm\Update\icmw_32.dll
c:\documents and settings\All Users\Application Data\Storm\update\keys.dat
c:\documents and settings\All Users\Application Data\Storm\Update\l3codeca.acm
c:\documents and settings\All Users\Application Data\Storm\Update\l3codecp.acm
c:\documents and settings\All Users\Application Data\Storm\update\l3codecx.ax
c:\documents and settings\All Users\Application Data\Storm\update\languages\ffdshow.1033.en
c:\documents and settings\All Users\Application Data\Storm\update\languages\ffdshow.2052.sc
c:\documents and settings\All Users\Application Data\Storm\Update\LCodcCMP.dll
c:\documents and settings\All Users\Application Data\Storm\Update\libavcodec.dll
c:\documents and settings\All Users\Application Data\Storm\Update\libmplayer.dll
c:\documents and settings\All Users\Application Data\Storm\update\lsvxdec.dll
c:\documents and settings\All Users\Application Data\Storm\update\MACDec.dll
c:\documents and settings\All Users\Application Data\Storm\Update\MASource.ax
c:\documents and settings\All Users\Application Data\Storm\update\mkunicode.dll
c:\documents and settings\All Users\Application Data\Storm\update\mkx.dll
c:\documents and settings\All Users\Application Data\Storm\update\mkzlib.dll
c:\documents and settings\All Users\Application Data\Storm\update\mp4.dll
c:\documents and settings\All Users\Application Data\Storm\Update\MP4Splitter.ax
c:\documents and settings\All Users\Application Data\Storm\Update\MpegSplitter.ax
c:\documents and settings\All Users\Application Data\Storm\update\mpg2splt.ax
c:\documents and settings\All Users\Application Data\Storm\update\msvcr71.dll
c:\documents and settings\All Users\Application Data\Storm\update\MZP4_DEC.DLL
c:\documents and settings\All Users\Application Data\Storm\update\ogm.dll
c:\documents and settings\All Users\Application Data\Storm\update\Plugins\nppl3260.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Plugins\nppl3260.xpt
c:\documents and settings\All Users\Application Data\Storm\Update\Plugins\npqtplugin.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Plugins\nprpjplug.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Plugins\nsIQTScriptablePlugin.xpt
c:\documents and settings\All Users\Application Data\Storm\Update\Plugins\nsJSRealPlayerPlugin.xpt
c:\documents and settings\All Users\Application Data\Storm\Update\Plugins\QuickTimePlugin.class
c:\documents and settings\All Users\Application Data\Storm\update\PmpSplt.ax
c:\documents and settings\All Users\Application Data\Storm\update\pncrt.dll
c:\documents and settings\All Users\Application Data\Storm\update\pndx5016.dll
c:\documents and settings\All Users\Application Data\Storm\update\pndx5032.dll
c:\documents and settings\All Users\Application Data\Storm\Update\qt.p2p
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\CFCharacterSetBitmaps.bitmap
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\CoreVideo.qtx
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\CoreVideo.Resources\CoreVideo.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\CoreVideo.Resources\en.lproj\CoreVideoLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\CoreVideo.Resources\zh_CN.lproj\CoreVideoLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QTCheck.ocx
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QTPlugin.ocx
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTime.cpl
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTime.qts
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTime.Resources\en.lproj\QuickTimeLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTime.Resources\en.lproj\QuickTimeLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTime.Resources\QuickTime.dll
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTime.Resources\QuickTime.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTime.Resources\zh_CN.lproj\QuickTimeLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTime.Resources\zh_CN.lproj\QuickTimeLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTime3GPP.qtx
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTime3GPP.Resources\en.lproj\QuickTime3GPPLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTime3GPP.Resources\QuickTime3GPP.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTime3GPP.Resources\zh_CN.lproj\QuickTime3GPPLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeAudioSupport.qtx
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeAudioSupport.Resources\en.lproj\QuickTimeAudioSupportLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeAudioSupport.Resources\en.lproj\QuickTimeAudioSupportLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeAudioSupport.Resources\QuickTimeAudioSupport.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeAudioSupport.Resources\zh_CN.lproj\QuickTimeAudioSupportLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeAudioSupport.Resources\zh_CN.lproj\QuickTimeAudioSupportLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeEssentials.qtx
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeEssentials.Resources\en.lproj\QuickTimeEssentialsLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeEssentials.Resources\QuickTimeEssentials.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeEssentials.Resources\zh_CN.lproj\QuickTimeEssentialsLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeH264.qtx
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeH264.Resources\en.lproj\QuickTimeH264Localized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeH264.Resources\QuickTimeH264.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeH264.Resources\zh_CN.lproj\QuickTimeH264Localized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeInternetExtras.qtx
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeInternetExtras.Resources\en.lproj\QuickTimeInternetExtrasLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeInternetExtras.Resources\QuickTimeInternetExtras.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeInternetExtras.Resources\zh_CN.lproj\QuickTimeInternetExtrasLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeMPEG4.qtx
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeMPEG4.Resources\en.lproj\QuickTimeMPEG4Localized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeMPEG4.Resources\QuickTimeMPEG4.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeMPEG4.Resources\zh_CN.lproj\QuickTimeMPEG4Localized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeStreaming.qtx
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeStreaming.Resources\en.lproj\QuickTimeStreamingLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeStreaming.Resources\en.lproj\QuickTimeStreamingLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeStreaming.Resources\QuickTimeStreaming.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeStreaming.Resources\zh_CN.lproj\QuickTimeStreamingLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeStreaming.Resources\zh_CN.lproj\QuickTimeStreamingLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeStreamingExtras.qtx
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeStreamingExtras.Resources\en.lproj\QuickTimeStreamingExtrasLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeStreamingExtras.Resources\QuickTimeStreamingExtras.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeStreamingExtras.Resources\zh_CN.lproj\QuickTimeStreamingExtrasLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeVR.qtx
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeVR.Resources\en.lproj\QuickTimeVRLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeVR.Resources\QuickTimeVR.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeVR.Resources\zh_CN.lproj\QuickTimeVRLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeWebHelper.qtx
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeWebHelper.Resources\en.lproj\QuickTimeWebHelperLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeWebHelper.Resources\en.lproj\QuickTimeWebHelperLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeWebHelper.Resources\QuickTimeWebHelper.dll
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeWebHelper.Resources\QuickTimeWebHelper.qtr
c:\documents and settings\All Users\Application Data\Storm\update\QTSystem\QuickTimeWebHelper.Resources\zh_CN.lproj\QuickTimeWebHelperLocalized.dll
c:\documents and settings\All Users\Application Data\Storm\Update\QTSystem\QuickTimeWebHelper.Resources\zh_CN.lproj\QuickTimeWebHelperLocalized.qtr
c:\documents and settings\All Users\Application Data\Storm\Update\QuickTime.qts
c:\documents and settings\All Users\Application Data\Storm\update\QuickTimeVR.qtx
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\14_43260.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\28_83260.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\atrc.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\cook.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\ddnt3260.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\dnet3260.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\drv1.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\drv2.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\drvc.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\hxltcolor.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\raac.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\ralf.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\rv10.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\rv20.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\rv30.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Codecs\rv40.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Codecs\sipr.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Common\objb3201.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Common\pnen3260.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Common\pngu3267.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Common\pnrs3260.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Common\rppr3260.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\audplin.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\authmgr.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\clbascauth.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\clntxres.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\ExtResources\coreres.xrs
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\fpsechnd.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\httpfsys.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\hxsdp.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\hxxml.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\imgrender.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\memfsys.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\mp3fformat.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\mp3render.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\mp4arender.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\ntlmauth.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\oggfformat.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\pacplin.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\plusplin.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\pxcb3210.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\ramfformat.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\ramrender.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\rarender.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\rmfformat.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\rmxfpln.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\rmxrend.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\rn5auth.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\rtfformat.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\rtrender.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\rvrender.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\sdpplin.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\security.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\smlfformat.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\smlrender.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\smmrender.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\smplfsys.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\stubdrm.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\tfilesys.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\vidplin.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\vidsite.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\Plugins\vorbisrend.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\Plugins\vsrlocal.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\rpplugins\cn\embed_cn.dll
c:\documents and settings\All Users\Application Data\Storm\Update\Real\rpplugins\cn\rpclsvc_cn.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\rpplugins\embd3260.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\rpplugins\rpcl3260.dll
c:\documents and settings\All Users\Application Data\Storm\update\Real\rpplugins\rput3260.dll
c:\documents and settings\All Users\Application Data\Storm\Update\RLMPCDec.ax
c:\documents and settings\All Users\Application Data\Storm\Update\rmoc3260.dll
c:\documents and settings\All Users\Application Data\Storm\update\RMSplt.ax
c:\documents and settings\All Users\Application Data\Storm\update\scsource.ax
c:\documents and settings\All Users\Application Data\Storm\update\SHNTrans.ax
c:\documents and settings\All Users\Application Data\Storm\Update\smackw32.dll
c:\documents and settings\All Users\Application Data\Storm\update\splitter.ax
c:\documents and settings\All Users\Application Data\Storm\Update\tomsmocomp_ff.dll
c:\documents and settings\All Users\Application Data\Storm\Update\ts.dll
c:\documents and settings\All Users\Application Data\Storm\update\tsccvid.dll
c:\documents and settings\All Users\Application Data\Storm\Update\TTASplt.ax
c:\documents and settings\All Users\Application Data\Storm\Update\TTL2Dec.dll
c:\documents and settings\All Users\Application Data\Storm\Update\v2k2_dec.dll
c:\documents and settings\All Users\Application Data\Storm\update\v2kdspde.dll
c:\documents and settings\All Users\Application Data\Storm\Update\VDODEC32.dll
c:\documents and settings\All Users\Application Data\Storm\update\vdowave.drv
c:\documents and settings\All Users\Application Data\Storm\Update\VgmAudio.ax
c:\documents and settings\All Users\Application Data\Storm\update\vgmbgr.ax
c:\documents and settings\All Users\Application Data\Storm\Update\VgmSplt.ax
c:\documents and settings\All Users\Application Data\Storm\Update\vgmv2k2.ax
c:\documents and settings\All Users\Application Data\Storm\Update\Vid1Dec.dll
c:\documents and settings\All Users\Application Data\Storm\update\vmnc.dll
c:\documents and settings\All Users\Application Data\Storm\update\vp6vfw.dll
c:\documents and settings\All Users\Application Data\Storm\update\vp7vfw.dll
c:\documents and settings\All Users\Application Data\Storm\Update\VSFilter.dll
c:\documents and settings\All Users\Application Data\Storm\update\xvid.ax
c:\documents and settings\All Users\Application Data\Storm\update\xvidcore.dll
c:\documents and settings\All Users\Application Data\Storm\Update\xvidvfw.dll
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Kenneth\com_securenetasia_p11wrapper3_cbs.bochk.com.dll
c:\documents and settings\Kenneth\Local Settings\Application Data\assembly\tmp
c:\documents and settings\Kenneth\Local Settings\Application Data\assembly\tmp\2CLU3CKT\__AssemblyInfo__.ini
c:\documents and settings\Kenneth\Local Settings\Application Data\assembly\tmp\9MV4DLV3\__AssemblyInfo__.ini
c:\documents and settings\Kenneth\Local Settings\Application Data\assembly\tmp\S4DMV4DM\__AssemblyInfo__.ini
c:\documents and settings\Kenneth\Local Settings\Application Data\assembly\tmp\U6FNX5EN\__AssemblyInfo__.ini
c:\documents and settings\Kenneth\Local Settings\Application Data\assembly\tmp\V7GPX6FO\__AssemblyInfo__.ini
c:\windows\msmqinst.log
c:\windows\setupapi.log
c:\windows\system32\system32
c:\windows\system32\system32\3DAudio.ax
c:\windows\system32\system32\avrt.dll
c:\windows\system32\system32\cis-2.4.dll
c:\windows\system32\system32\issacapi_bs-2.3.dll
c:\windows\system32\system32\issacapi_pe-2.3.dll
c:\windows\system32\system32\issacapi_se-2.3.dll
c:\windows\system32\system32\MACXMLProto.dll
c:\windows\system32\system32\MaDRM.dll
c:\windows\system32\system32\MaJGUILib.dll
c:\windows\system32\system32\MAMACExtract.dll
c:\windows\system32\system32\MASetupCleaner.exe
c:\windows\system32\system32\MaXMLProto.dll
c:\windows\system32\system32\mfplat.dll
c:\windows\system32\system32\MK_Lyric.dll
c:\windows\system32\system32\MSCLib.dll
c:\windows\system32\system32\MSFLib.dll
c:\windows\system32\system32\MSLUR71.dll
c:\windows\system32\system32\msvcp60.dll
c:\windows\system32\system32\MTTELECHIP.dll
c:\windows\system32\system32\MTXSYNCICON.dll
c:\windows\system32\system32\muzaf1.dll
c:\windows\system32\system32\muzapp.dll
c:\windows\system32\system32\muzapp.exe
c:\windows\system32\system32\muzdecode.ax
c:\windows\system32\system32\muzeffect.ax
c:\windows\system32\system32\muzmp4sp.ax
c:\windows\system32\system32\muzmpgsp.ax
c:\windows\system32\system32\muzoggsp.ax
c:\windows\system32\system32\muzwmts.dll
c:\windows\system32\system32\psapi.dll
c:\windows\system32\YingInstall
c:\windows\system32\YingInstall\409.ini
.
發現受感染 c:\windows\system32\Drivers\atapi.sys 並且成功解毒
從 - c:\windows\ServicePackFiles\i386\atapi.sys 恢復原來檔案
.
.
((((((((((((((((((((((((( 2012-01-02 至 2012-02-02 的新的檔案 )))))))))))))))))))))))))))))))
.
.
2012-01-31 14:49 . 2012-01-31 14:49 ——– d—–w- C:\_OTL
2012-01-27 16:25 . 2012-01-27 16:25 ——– d—–w- c:\documents and settings\Kenneth\Application Data\Malwarebytes
2012-01-27 16:25 . 2012-01-27 16:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-01-27 16:25 . 2012-01-27 16:25 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-01-27 16:25 . 2011-12-10 07:24 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-01-27 11:03 . 2012-01-27 11:03 ——– d—–w- c:\documents and settings\Kenneth\Application Data\YCanPDF
2012-01-27 11:03 . 2012-01-27 11:04 ——– d—–w- C:\tmp
2012-01-15 17:41 . 2011-01-26 03:43 ——– d—–w- c:\program files\OrangeHRM
2012-01-15 14:36 . 2012-01-15 14:36 ——– d—–w- c:\windows\Downloaded Installations
2012-01-15 05:52 . 2012-01-15 05:53 ——– dc-h–w- c:\windows\ie8
2012-01-15 05:47 . 2011-11-04 19:13 55296 ——w- c:\windows\system32\dllcache\msfeedsbs.dll
2012-01-15 05:47 . 2011-11-04 19:13 602112 ——w- c:\windows\system32\dllcache\msfeeds.dll
2012-01-15 05:46 . 2011-11-04 19:13 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2012-01-14 19:00 . 2012-01-14 19:20 ——– d—–w- C:\wamp
2012-01-14 17:18 . 2012-01-14 19:14 ——– d—–w- c:\program files\Xpress Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-14 16:14 . 2011-06-02 18:16 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-04 19:13 . 2006-08-03 07:02 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:13 . 2006-08-03 07:02 43520 ——w- c:\windows\system32\licmgr10.dll
2011-11-04 19:13 . 2006-08-03 07:02 1469440 ——w- c:\windows\system32\inetcpl.cpl
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-09-16 . 8E036EEC565910417EA020CE0962AA24 . 361344 . . [5.1.2600.5512] . . c:\windows\system32\drivers\TCPIP.SYS
[-] 2009-09-16 . 8E036EEC565910417EA020CE0962AA24 . 361344 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\TCPIP.SYS
[-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\bd142275395b2b38d513ff6a92b5d2fa\sp3qfe\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\bd142275395b2b38d513ff6a92b5d2fa\sp3gdr\tcpip.sys
[-] 2008-05-14 . BA57942C0029B0878AFBA052A3E33689 . 359808 . . [5.1.2600.2892] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\TCPIP.SYS
[-] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[-] 2006-01-13 . 5562CC0A47B2AEF06D3417B733F3C195 . 360448 . . [5.1.2600.2827] . . c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[-] 2005-05-25 . 63FDFEA54EB53DE2D863EE454937CE1E . 359936 . . [5.1.2600.2685] . . c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2011-12-22 12:52 323584 —-a-w- c:\program files\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2011-12-22 12:52 323584 —-a-w- c:\program files\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2011-12-22 12:52 323584 —-a-w- c:\program files\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2011-12-22 12:52 323584 —-a-w- c:\program files\SugarSync\SugarSyncShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1280808]
"FlashGetBHO"="c:\program files\FlashGet Network\FlashGet 3\mxhelper.exe" [2010-05-18 108080]
"SugarSync"="c:\program files\SugarSync\SugarSyncManager.exe" [2011-12-22 12214272]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-12 208952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-31 761946]
"AGRSMMSG"="AGRSMMSG.exe" [2006-03-17 89541]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-02 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-02 118784]
"00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2010-01-19 3168216]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-10-19 286720]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\Resources\Logon\Ubuntu LogonUI\logonui.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2006-06-10 09:02 49152 —-a-w- c:\program files\Softex\OmniPass\OPXPGina.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^「開始」功能表^程式集^啟動^Bluetooth Manager.lnk]
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^「開始」功能表^程式集^啟動^ExifLauncher2.lnk]
path=c:\documents and settings\All Users\「開始」功能表\程式集\啟動\ExifLauncher2.lnk
backup=c:\windows\pss\ExifLauncher2.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Kenneth^「開始」功能表^程式集^啟動^BitComet.lnk]
path=c:\documents and settings\Kenneth\「開始」功能表\程式集\啟動\BitComet.lnk
backup=c:\windows\pss\BitComet.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATSwpNav
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-29 13:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-08-31 01:57 40368 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
2008-05-05 09:02 2334520 —-a-w- c:\program files\BitComet\BitComet.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FJUPDNV_Chitose]
2006-02-21 07:00 331776 —-a-w- c:\program files\Fujitsu\updnavi\updnavi.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 07:01 1280808 —-a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndicatorUtility]
2006-03-15 09:12 90112 —-a-w- c:\program files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
2006-08-01 16:32 696320 —-a-w- c:\program files\Intel\Wireless\Bin\iFrmewrk.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
2006-08-01 16:38 802816 —-a-w- c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]
2011-12-08 01:33 935824 —-a-w- c:\program files\Samsung\Kies\KiesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
2011-12-08 01:33 21392 —-a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
2011-12-08 01:33 3508624 —-a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LoadBtnHnd]
2005-10-05 10:53 61440 —-a-w- c:\program files\Fujitsu\BtnHnd\BtnHnd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LoadFUJ02E3]
2006-01-27 13:17 73728 —-a-w- c:\program files\Fujitsu\FUJ02E3\FUJ02E3.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LoadFujitsuQuickTouch]
2005-10-05 10:58 253952 —-a-w- c:\program files\Fujitsu\Application Panel\QuickTouch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
2005-05-18 07:57 188416 ——w- c:\program files\ltmoh\ltmoh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmniPass]
2006-06-10 09:24 1966080 —-a-w- c:\program files\Softex\OmniPass\scureapp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2007-10-19 12:16 286720 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2006-03-07 19:54 16010240 ——r- c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SafeNetCertMngr]
2010-07-27 11:51 1024200 —-a-w- c:\program files\SafeNet\Authentication\SAC\x32\SACMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSUtility]
2006-07-22 02:10 233472 —-a-r- c:\program files\Fujitsu\SSUtility\FJSSDMN.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 05:06 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TvOutSwitch]
2006-04-19 10:45 81920 —-a-w- c:\program files\Fujitsu\DispSwitch\DispSwitchLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2010-03-25 09:49 319792 —-a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"BITS"=3 (0x3)
"AntiVirService"=2 (0x2)
"AntiVirSchedulerService"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\FlashGet Network\\FlashGet 3\\FlashGet3.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"22902:TCP"= 22902:TCP:BitComet 22902 TCP
"22902:UDP"= 22902:UDP:BitComet 22902 UDP
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"8080:TCP"= 8080:TCP:BitComet 8080 TCP
"8080:UDP"= 8080:UDP:BitComet 8080 UDP
"26901:TCP"= 26901:TCP:BitComet 26901 TCP
"26901:UDP"= 26901:UDP:BitComet 26901 UDP
"500:TCP"= 500:TCP:BitComet 500 TCP
"500:UDP"= 500:UDP:BitComet 500 UDP
"20503:TCP"= 20503:TCP:BitComet 20503 TCP
"20503:UDP"= 20503:UDP:BitComet 20503 UDP
"11126:TCP"= 11126:TCP:BitComet 11126 TCP
"11126:UDP"= 11126:UDP:BitComet 11126 UDP
"60000:TCP"= 60000:TCP:BitComet 60000 TCP
"60000:UDP"= 60000:UDP:BitComet 60000 UDP
.
R0 FJGSDisk;G-Sensor Application Filter Driver;c:\windows\system32\drivers\FJGSDisk.sys [12/5/2008 11:03 7168]
R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [21/2/2006 15:05 36352]
R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [23/9/2005 7:48 28544]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/3/2010 1:57 691696]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [11/10/2009 22:10 233136]
R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\VCdRom.sys [9/6/2008 10:23 8576]
R2 Apache2.2;Apache2.2;c:\program files\OrangeHRM\2.6.12.1\apache\bin\httpd.exe [25/3/2011 13:55 20549]
R2 CachemanXPService;CachemanXP;c:\progra~1\CACHEM~1\CachemanXP.exe [2/8/2008 0:24 243200]
R2 FlashDrv;FlashDrv;c:\progra~1\Fujitsu\FlashAid\FlashDrv.sys [12/5/2008 11:03 7196]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [28/1/2012 0:25 652872]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [11/10/2009 22:10 88040]
R2 SACSrv;SACSrv;c:\program files\SafeNet\Authentication\SAC\x32\SACSrv.exe [27/7/2010 19:51 8392]
R3 FUJ02E1;%FUJ02E1.DeviceDesc%;c:\windows\system32\drivers\FUJ02E1.sys [3/8/2006 15:02 5632]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;c:\windows\system32\drivers\fuj02e3.sys [12/5/2008 11:17 4864]
R3 iKeyEnum;Rainbow iKey Enumerator;c:\windows\system32\drivers\IKEYENUM.SYS [1/12/2011 23:47 11616]
R3 iKeyIFD;Rainbow iKey Virtual Reader;c:\windows\system32\drivers\IKEYIFD.SYS [1/12/2011 23:47 18080]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [28/1/2012 0:25 20464]
R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [11/10/2009 22:09 70664]
R3 pctNDIS;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [11/10/2009 22:09 58816]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [11/10/2009 22:09 115216]
S2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe –> c:\program files\iolo\common\lib\ioloServiceManager.exe [?]
S2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe –> c:\program files\iolo\common\lib\ioloServiceManager.exe [?]
S3 ADVNTDRV;ADVNTDRV;c:\windows\system32\drivers\ADVNTDRV.SYS [18/11/1999 17:20 3872]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [9/12/2011 1:13 78136]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [9/12/2011 0:56 20032]
S3 PCTFW-DNS;PCTools Firewall - DNS driver;c:\windows\system32\drivers\pctNdis-DNS.sys [11/10/2009 22:09 32680]
S3 RnbToken;Rainbow iKey Token Service;c:\windows\system32\drivers\RNBTOKEN.SYS [1/12/2011 23:47 21472]
S3 Slnt7554;USB Soft Modem Driver;c:\windows\system32\drivers\slnt7554.sys [7/10/2008 13:36 129535]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [9/12/2011 1:13 181432]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
.
——- 而外的掃描 ——-
.
uStart Page = about:blank
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: UseFlashGet
IE: UseFlashGetDownloadAllLink
IE: 使用快車3下載 - c:\documents and settings\Kenneth\Application Data\FlashGetBHO\GetUrl.htm
IE: 使用快車3下載全部鏈結 - c:\documents and settings\Kenneth\Application Data\FlashGetBHO\GetAllUrl.htm
IE: 匯出至 Microsoft Excel(&X) - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: 透過Mipony下載 - file://c:\program files\MiPony\Browser\IEContext.htm
Trusted Zone: samsung.com\www
TCP: DhcpNameServer = 192.168.1.1
DPF: {31EE92CA-C0F5-48F7-AE60-B54CDF3BB76C} - hxxp://219.105.35.37/player/AcqVPlayerX_2_0_2_21.cab
DPF: {47F7AB40-86FD-4385-991D-895E2E3E1255} - hxxp://2008.i-cable.com/webapps/live_video/p2pactx.cab
.
.
——- 文件類型 ——-
.
.
- - - - ORPHANS REMOVED - - - -
.
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-Akamai NetSession Interface - c:\documents and settings\Kenneth\Local Settings\Application Data\Akamai\netsession_win.exe
MSConfigStartUp-CloneCDTray - c:\program files\SlySoft\CloneCD\CloneCDTray.exe
MSConfigStartUp-eSnips_Downloader - c:\program files\Logia\eSnipsDownloader\eSnips_Downloader.exe
MSConfigStartUp-Google Update - c:\documents and settings\Kenneth\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
MSConfigStartUp-MSMSGS - c:\program files\Messenger\msmsgs.exe
MSConfigStartUp-NokiaOviSuite2 - c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
MSConfigStartUp-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-03 00:21
Windows 5.1.2600 Service Pack 3 NTFS
.
掃描被隱藏的進程 …
.
掃描被隱藏的啟動組 …
.
掃描被隱藏的文件 …
.
掃描完成
被隱藏的檔案: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mysql]
"ImagePath"="\"c:\program files\OrangeHRM\2.6.12.1\mysql\bin\mysqld\" –defaults-file=\"c:\program files\OrangeHRM\2.6.12.1\mysql\bin\my.ini\" mysql"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2655231707-597013420-2883546955-1005\Software\Microsoft\Internet Explorer\MenuExt\O(u螒?3* N 㒖
@="c:\\Documents and Settings\\Kenneth\\Application Data\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-2655231707-597013420-2883546955-1005\Software\Microsoft\Internet Explorer\MenuExt\O(u螒?3* N 祘Q??P}]
@="c:\\Documents and Settings\\Kenneth\\Application Data\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_USERS\S-1-5-21-1123561945-162531612-725345543-500_Classes\O*v*e*r*t*u*r*e* *>?w\DefaultIcon]
@=expand:"%APPDATA%\\Microsoft\\Installer\\{50ADDF79-3249-4679-B527-3FB8C5EA99E5}\\_294823.exe,0"
.
[HKEY_USERS\S-1-5-21-1123561945-162531612-725345543-500_Classes\O*v*e*r*t*u*r*e* *>?w\shell]
@="open"
.
[HKEY_USERS\S-1-5-21-1123561945-162531612-725345543-500_Classes\O*v*e*r*t*u*r*e* *>?w\shell\open]
@="??(&O)"
.
[HKEY_USERS\S-1-5-21-1123561945-162531612-725345543-500_Classes\O*v*e*r*t*u*r*e* *>?w\shell\open\command]
@="\"c:\\Program Files\\Overture 4.0\\Overture.exe\" \"%1\""
"command"=multi:"%_(xAdi9`=RGK6dXKNlr>?%)duR)D9Xu~OSIW`PT- \"%1\"\00\00"
.
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ譸\CLSID]
@="{809B6661-94C4-49E6-B6EC-3F0F862215AA}"
.
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ譸\CurVer]
@="BDATuner.元件.1"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Unimodem\DeviceSpecific\j *3*3*6*0*0* *b*p*s* *xe焺_j:*:*(*jxe焺_j^?W)*:*:*M*i*c*r*o*s*o*f*t*\Responses]
""=hex:01,00,00,00,00,00,00,00,00,00
""=hex:01,00,00,00,00,00,00,00,00,00
"OK"=hex:00,00,00,00,00,00,00,00,00,00
"RING"=hex:08,00,00,00,00,00,00,00,00,00
"NO CARRIER"=hex:04,00,00,00,00,00,00,00,00,00
"ERROR"=hex:03,00,00,00,00,00,00,00,00,00
"NO DIALTONE"=hex:05,00,00,00,00,00,00,00,00,00
"BUSY"=hex:06,00,00,00,00,00,00,00,00,00
"NO ANSWER"=hex:07,00,00,00,00,00,00,00,00,00
"CONNECT"=hex:02,00,00,00,00,00,00,00,00,00
"0"=hex:00,00,00,00,00,00,00,00,00,00
"2"=hex:08,00,00,00,00,00,00,00,00,00
"3"=hex:04,00,00,00,00,00,00,00,00,00
"4"=hex:03,00,00,00,00,00,00,00,00,00
"6"=hex:05,00,00,00,00,00,00,00,00,00
"7"=hex:06,00,00,00,00,00,00,00,00,00
"8"=hex:07,00,00,00,00,00,00,00,00,00
"OK"=hex:00,00,00,00,00,00,00,00,00,00
"RING"=hex:08,00,00,00,00,00,00,00,00,00
"NO CARRIER"=hex:04,00,00,00,00,00,00,00,00,00
"ERROR"=hex:03,00,00,00,00,00,00,00,00,00
"NO DIALTONE"=hex:05,00,00,00,00,00,00,00,00,00
"NO DIAL TONE"=hex:05,00,00,00,00,00,00,00,00,00
"BUSY"=hex:06,00,00,00,00,00,00,00,00,00
"NO ANSWER"=hex:07,00,00,00,00,00,00,00,00,00
"FAX"=hex:03,00,00,00,00,00,00,00,00,00
"DATA"=hex:03,00,00,00,00,00,00,00,00,00
"VOICE"=hex:03,00,00,00,00,00,00,00,00,00
"RINGING"=hex:01,00,00,00,00,00,00,00,00,00
"DIALING"=hex:01,00,00,00,00,00,00,00,00,00
"RRING"=hex:01,00,00,00,00,00,00,00,00,00
"DELAYED"=hex:1d,00,00,00,00,00,00,00,00,00
"BLACKLISTED"=hex:1c,00,00,00,00,00,00,00,00,00
"+FCERROR"=hex:03,00,00,00,00,00,00,00,00,00
"CONNECT"=hex:02,00,00,00,00,00,00,00,00,00
"CONNECT/ARQ"=hex:02,02,00,00,00,00,00,00,00,00
"CONNECT/REL"=hex:02,02,00,00,00,00,00,00,00,00
"CONNECT/MNP"=hex:02,02,00,00,00,00,00,00,00,00
"CONNECT/LAP-M"=hex:02,02,00,00,00,00,00,00,00,00
"CONNECT/V42BIS"=hex:02,03,00,00,00,00,00,00,00,00
"CONNECT/V42b"=hex:02,03,00,00,00,00,00,00,00,00
"CONNECT 300"=hex:02,00,2c,01,00,00,00,00,00,00
"CONNECT 300/ARQ"=hex:02,02,2c,01,00,00,00,00,00,00
"CONNECT 300/REL"=hex:02,02,2c,01,00,00,00,00,00,00
"CONNECT 300/MNP"=hex:02,02,2c,01,00,00,00,00,00,00
"CONNECT 300/LAP-M"=hex:02,02,2c,01,00,00,00,00,00,00
"CONNECT 300/V42BIS"=hex:02,03,2c,01,00,00,00,00,00,00
"CONNECT 300/V42b"=hex:02,03,2c,01,00,00,00,00,00,00
"CONNECT 600"=hex:02,00,58,02,00,00,00,00,00,00
"CONNECT 600/ARQ"=hex:02,02,58,02,00,00,00,00,00,00
"CONNECT 600/REL"=hex:02,02,58,02,00,00,00,00,00,00
"CONNECT 600/MNP"=hex:02,02,58,02,00,00,00,00,00,00
"CONNECT 600/LAP-M"=hex:02,02,58,02,00,00,00,00,00,00
"CONNECT 600/V42BIS"=hex:02,03,58,02,00,00,00,00,00,00
"CONNECT 600/V42b"=hex:02,03,58,02,00,00,00,00,00,00
"CONNECT 0600"=hex:02,00,58,02,00,00,00,00,00,00
"CONNECT 0600/ARQ"=hex:02,02,58,02,00,00,00,00,00,00
"CONNECT 0600/REL"=hex:02,02,58,02,00,00,00,00,00,00
"CONNECT 0600/MNP"=hex:02,02,58,02,00,00,00,00,00,00
"CONNECT 0600/LAP-M"=hex:02,02,58,02,00,00,00,00,00,00
"CONNECT 0600/V42BIS"=hex:02,03,58,02,00,00,00,00,00,00
"CONNECT 0600/V42b"=hex:02,03,58,02,00,00,00,00,00,00
"CONNECT 1200"=hex:02,00,b0,04,00,00,00,00,00,00
"CONNECT 1200/ARQ"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 1200/REL"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 1200/MNP"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 1200/LAP-M"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 1200/V42BIS"=hex:02,03,b0,04,00,00,00,00,00,00
"CONNECT 1200/V42b"=hex:02,03,b0,04,00,00,00,00,00,00
"CONNECT 1200/75"=hex:02,00,b0,04,00,00,00,00,00,00
"CONNECT 1200/75/ARQ"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 1200/75/REL"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 1200/75/MNP"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 1200/75/LAP-M"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 1200/75/V42BIS"=hex:02,03,b0,04,00,00,00,00,00,00
"CONNECT 1200/75/V42b"=hex:02,03,b0,04,00,00,00,00,00,00
"CONNECT 1200TX/75RX"=hex:02,00,b0,04,00,00,00,00,00,00
"CONNECT 1200TX/75RX/ARQ"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 1200TX/75RX/REL"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 1200TX/75RX/MNP"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 1200TX/75RX/LAP-M"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 1200TX/75RX/V42BIS"=hex:02,03,b0,04,00,00,00,00,00,00
"CONNECT 1200TX/75RX/V42b"=hex:02,03,b0,04,00,00,00,00,00,00
"CONNECT 75/1200"=hex:02,00,b0,04,00,00,00,00,00,00
"CONNECT 75/1200/ARQ"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 75/1200/REL"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 75/1200/MNP"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 75/1200/LAP-M"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 75/1200/V42BIS"=hex:02,03,b0,04,00,00,00,00,00,00
"CONNECT 75/1200/V42b"=hex:02,03,b0,04,00,00,00,00,00,00
"CONNECT 75TX/1200RX"=hex:02,00,b0,04,00,00,00,00,00,00
"CONNECT 75TX/1200RX/ARQ"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 75TX/1200RX/REL"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 75TX/1200RX/MNP"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 75TX/1200RX/LAP-M"=hex:02,02,b0,04,00,00,00,00,00,00
"CONNECT 75TX/1200RX/V42BIS"=hex:02,03,b0,04,00,00,00,00,00,00
"CONNECT 75TX/1200RX/V42b"=hex:02,03,b0,04,00,00,00,00,00,00
"CONNECT 2400"=hex:02,00,60,09,00,00,00,00,00,00
"CONNECT 2400/ARQ"=hex:02,02,60,09,00,00,00,00,00,00
"CONNECT 2400/REL"=hex:02,02,60,09,00,00,00,00,00,00
"CONNECT 2400/MNP"=hex:02,02,60,09,00,00,00,00,00,00
"CONNECT 2400/LAP-M"=hex:02,02,60,09,00,00,00,00,00,00
"CONNECT 2400/V42BIS"=hex:02,03,60,09,00,00,00,00,00,00
"CONNECT 2400/V42b"=hex:02,03,60,09,00,00,00,00,00,00
"CONNECT 4800"=hex:02,00,c0,12,00,00,00,00,00,00
"CONNECT 4800/ARQ"=hex:02,02,c0,12,00,00,00,00,00,00
"CONNECT 4800/REL"=hex:02,02,c0,12,00,00,00,00,00,00
"CONNECT 4800/MNP"=hex:02,02,c0,12,00,00,00,00,00,00
"CONNECT 4800/LAP-M"=hex:02,02,c0,12,00,00,00,00,00,00
"CONNECT 4800/V42BIS"=hex:02,03,c0,12,00,00,00,00,00,00
"CONNECT 4800/V42b"=hex:02,03,c0,12,00,00,00,00,00,00
"CONNECT 7200"=hex:02,00,20,1c,00,00,00,00,00,00
"CONNECT 7200/ARQ"=hex:02,02,20,1c,00,00,00,00,00,00
"CONNECT 7200/REL"=hex:02,02,20,1c,00,00,00,00,00,00
"CONNECT 7200/MNP"=hex:02,02,20,1c,00,00,00,00,00,00
"CONNECT 7200/LAP-M"=hex:02,02,20,1c,00,00,00,00,00,00
"CONNECT 7200/V42BIS"=hex:02,03,20,1c,00,00,00,00,00,00
"CONNECT 7200/V42b"=hex:02,03,20,1c,00,00,00,00,00,00
"CONNECT 9600"=hex:02,00,80,25,00,00,00,00,00,00
"CONNECT 9600/ARQ"=hex:02,02,80,25,00,00,00,00,00,00
"CONNECT 9600/REL"=hex:02,02,80,25,00,00,00,00,00,00
"CONNECT 9600/MNP"=hex:02,02,80,25,00,00,00,00,00,00
"CONNECT 9600/LAP-M"=hex:02,02,80,25,00,00,00,00,00,00
"CONNECT 9600/V42BIS"=hex:02,03,80,25,00,00,00,00,00,00
"CONNECT 9600/V42b"=hex:02,03,80,25,00,00,00,00,00,00
"CONNECT 12000"=hex:02,00,e0,2e,00,00,00,00,00,00
"CONNECT 12000/ARQ"=hex:02,02,e0,2e,00,00,00,00,00,00
"CONNECT 12000/REL"=hex:02,02,e0,2e,00,00,00,00,00,00
"CONNECT 12000/MNP"=hex:02,02,e0,2e,00,00,00,00,00,00
"CONNECT 12000/LAP-M"=hex:02,02,e0,2e,00,00,00,00,00,00
"CONNECT 12000/V42BIS"=hex:02,03,e0,2e,00,00,00,00,00,00
"CONNECT 12000/V42b"=hex:02,03,e0,2e,00,00,00,00,00,00
"CONNECT 14400"=hex:02,00,40,38,00,00,00,00,00,00
"CONNECT 14400/ARQ"=hex:02,02,40,38,00,00,00,00,00,00
"CONNECT 14400/REL"=hex:02,02,40,38,00,00,00,00,00,00
"CONNECT 14400/MNP"=hex:02,02,40,38,00,00,00,00,00,00
"CONNECT 14400/LAP-M"=hex:02,02,40,38,00,00,00,00,00,00
"CONNECT 14400/V42BIS"=hex:02,03,40,38,00,00,00,00,00,00
"CONNECT 14400/V42b"=hex:02,03,40,38,00,00,00,00,00,00
"CONNECT 16800"=hex:02,00,a0,41,00,00,00,00,00,00
"CONNECT 16800/ARQ"=hex:02,02,a0,41,00,00,00,00,00,00
"CONNECT 16800/REL"=hex:02,02,a0,41,00,00,00,00,00,00
"CONNECT 16800/MNP"=hex:02,02,a0,41,00,00,00,00,00,00
"CONNECT 16800/LAP-M"=hex:02,02,a0,41,00,00,00,00,00,00
"CONNECT 16800/V42BIS"=hex:02,03,a0,41,00,00,00,00,00,00
"CONNECT 16800/V42b"=hex:02,03,a0,41,00,00,00,00,00,00
"CONNECT 19200"=hex:02,00,00,4b,00,00,00,00,00,00
"CONNECT 19200/ARQ"=hex:02,02,00,4b,00,00,00,00,00,00
"CONNECT 19200/REL"=hex:02,02,00,4b,00,00,00,00,00,00
"CONNECT 19200/MNP"=hex:02,02,00,4b,00,00,00,00,00,00
"CONNECT 19200/LAP-M"=hex:02,02,00,4b,00,00,00,00,00,00
"CONNECT 19200/V42BIS"=hex:02,03,00,4b,00,00,00,00,00,00
"CONNECT 19200/V42b"=hex:02,03,00,4b,00,00,00,00,00,00
"CONNECT 21600"=hex:02,00,60,54,00,00,00,00,00,00
"CONNECT 21600/ARQ"=hex:02,02,60,54,00,00,00,00,00,00
"CONNECT 21600/REL"=hex:02,02,60,54,00,00,00,00,00,00
"CONNECT 21600/MNP"=hex:02,02,60,54,00,00,00,00,00,00
"CONNECT 21600/LAP-M"=hex:02,02,60,54,00,00,00,00,00,00
"CONNECT 21600/V42BIS"=hex:02,03,60,54,00,00,00,00,00,00
"CONNECT 21600/V42b"=hex:02,03,60,54,00,00,00,00,00,00
"CONNECT 24000"=hex:02,00,c0,5d,00,00,00,00,00,00
"CONNECT 24000/ARQ"=hex:02,02,c0,5d,00,00,00,00,00,00
"CONNECT 24000/REL"=hex:02,02,c0,5d,00,00,00,00,00,00
"CONNECT 24000/MNP"=hex:02,02,c0,5d,00,00,00,00,00,00
"CONNECT 24000/LAP-M"=hex:02,02,c0,5d,00,00,00,00,00,00
"CONNECT 24000/V42BIS"=hex:02,03,c0,5d,00,00,00,00,00,00
"CONNECT 24000/V42b"=hex:02,03,c0,5d,00,00,00,00,00,00
"CONNECT 26400"=hex:02,00,20,67,00,00,00,00,00,00
"CONNECT 26400/ARQ"=hex:02,02,20,67,00,00,00,00,00,00
"CONNECT 26400/REL"=hex:02,02,20,67,00,00,00,00,00,00
"CONNECT 26400/MNP"=hex:02,02,20,67,00,00,00,00,00,00
"CONNECT 26400/LAP-M"=hex:02,02,20,67,00,00,00,00,00,00
"CONNECT 26400/V42BIS"=hex:02,03,20,67,00,00,00,00,00,00
"CONNECT 26400/V42b"=hex:02,03,20,67,00,00,00,00,00,00
"CONNECT 28800"=hex:02,00,80,70,00,00,00,00,00,00
"CONNECT 28800/ARQ"=hex:02,02,80,70,00,00,00,00,00,00
"CONNECT 28800/REL"=hex:02,02,80,70,00,00,00,00,00,00
"CONNECT 28800/MNP"=hex:02,02,80,70,00,00,00,00,00,00
"CONNECT 28800/LAP-M"=hex:02,02,80,70,00,00,00,00,00,00
"CONNECT 28800/V42BIS"=hex:02,03,80,70,00,00,00,00,00,00
"CONNECT 28800/V42b"=hex:02,03,80,70,00,00,00,00,00,00
"CONNECT 38400"=hex:02,00,00,00,00,00,00,96,00,00
"CONNECT 38400/ARQ"=hex:02,02,00,00,00,00,00,96,00,00
"CONNECT 38400/REL"=hex:02,02,00,00,00,00,00,96,00,00
"CONNECT 38400/MNP"=hex:02,02,00,00,00,00,00,96,00,00
"CONNECT 38400/LAP-M"=hex:02,02,00,00,00,00,00,96,00,00
"CONNECT 38400/V42BIS"=hex:02,03,00,00,00,00,00,96,00,00
"CONNECT 38400/V42b"=hex:02,03,00,00,00,00,00,96,00,00
"CONNECT 57600"=hex:02,00,00,00,00,00,00,e1,00,00
"CONNECT 57600/ARQ"=hex:02,02,00,00,00,00,00,e1,00,00
"CONNECT 57600/REL"=hex:02,02,00,00,00,00,00,e1,00,00
"CONNECT 57600/MNP"=hex:02,02,00,00,00,00,00,e1,00,00
"CONNECT 57600/LAP-M"=hex:02,02,00,00,00,00,00,e1,00,00
"CONNECT 57600/V42BIS"=hex:02,03,00,00,00,00,00,e1,00,00
"CONNECT 57600/V42b"=hex:02,03,00,00,00,00,00,e1,00,00
"CONNECT 115200"=hex:02,00,00,00,00,00,00,c2,01,00
"CONNECT 115200/ARQ"=hex:02,02,00,00,00,00,00,c2,01,00
"CONNECT 115200/REL"=hex:02,02,00,00,00,00,00,c2,01,00
"CONNECT 115200/MNP"=hex:02,02,00,00,00,00,00,c2,01,00
"CONNECT 115200/LAP-M"=hex:02,02,00,00,00,00,00,c2,01,00
"CONNECT 115200/V42BIS"=hex:02,03,00,00,00,00,00,c2,01,00
"CONNECT 115200/V42b"=hex:02,03,00,00,00,00,00,c2,01,00
"CONNECT 115,200"=hex:02,00,00,00,00,00,00,c2,01,00
"CONNECT 115,200/ARQ"=hex:02,02,00,00,00,00,00,c2,01,00
"CONNECT 115,200/REL"=hex:02,02,00,00,00,00,00,c2,01,00
"CONNECT 115,200/MNP"=hex:02,02,00,00,00,00,00,c2,01,00
"CONNECT 115,200/LAP-M"=hex:02,02,00,00,00,00,00,c2,01,00
"CONNECT 115,200/V42BIS"=hex:02,03,00,00,00,00,00,c2,01,00
"CONNECT 115,200/V42b"=hex:02,03,00,00,00,00,00,c2,01,00
"CONNECT 230400"=hex:02,00,00,00,00,00,00,84,03,00
"CONNECT 230400/ARQ"=hex:02,02,00,00,00,00,00,84,03,00
"CONNECT 230400/REL"=hex:02,02,00,00,00,00,00,84,03,00
"CONNECT 230400/MNP"=hex:02,02,00,00,00,00,00,84,03,00
"CONNECT 230400/LAP-M"=hex:02,02,00,00,00,00,00,84,03,00
"CONNECT 230400/V42BIS"=hex:02,03,00,00,00,00,00,84,03,00
"CONNECT 230400/V42b"=hex:02,03,00,00,00,00,00,84,03,00
"CARRIER 300"=hex:01,00,2c,01,00,00,00,00,00,00
"CARRIER 1200"=hex:01,00,b0,04,00,00,00,00,00,00
"CARRIER 1200/75"=hex:01,00,b0,04,00,00,00,00,00,00
"CARRIER 75/1200"=hex:01,00,b0,04,00,00,00,00,00,00
"CARRIER 2400"=hex:01,00,60,09,00,00,00,00,00,00
"CARRIER 4800"=hex:01,00,c0,12,00,00,00,00,00,00
"CARRIER 7200"=hex:01,00,20,1c,00,00,00,00,00,00
"CARRIER 9600"=hex:01,00,80,25,00,00,00,00,00,00
"CARRIER 12000"=hex:01,00,e0,2e,00,00,00,00,00,00
"CARRIER 14400"=hex:01,00,40,38,00,00,00,00,00,00
"CARRIER 16800"=hex:01,00,a0,41,00,00,00,00,00,00
"CARRIER 19200"=hex:01,00,00,4b,00,00,00,00,00,00
"CARRIER 21600"=hex:01,00,60,54,00,00,00,00,00,00
"CARRIER 24000"=hex:01,00,c0,5d,00,00,00,00,00,00
"CARRIER 26400"=hex:01,00,20,67,00,00,00,00,00,00
"CARRIER 28800"=hex:01,00,80,70,00,00,00,00,00,00
"COMPRESSION: CLASS 5"=hex:01,03,00,00,00,00,00,00,00,00
"COMPRESSION: MNP5"=hex:01,03,00,00,00,00,00,00,00,00
"COMPRESSION: V.42BIS"=hex:01,03,00,00,00,00,00,00,00,00
"COMPRESSION: V.42 BIS"=hex:01,03,00,00,00,00,00,00,00,00
"COMPRESSION: ADC"=hex:01,01,00,00,00,00,00,00,00,00
"COMPRESSION: NONE"=hex:01,00,00,00,00,00,00,00,00,00
"PROTOCOL: NONE"=hex:01,00,00,00,00,00,00,00,00,00
"PROTOCOL: ERROR-CONTROL/LAPB"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: ERROR-CONTROL/LAPB/HDX"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: ERROR-CONTROL/LAPB/AFT"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: X.25/LAPB"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: X.25/LAPB/HDX"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: X.25/LAPB/AFT"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: LAPM"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: LAP-M"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: LAPM/HDX"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: LAP-M/HDX"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: LAPM/AFT"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: LAP-M/AFT"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: ALT"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: ALT-CELLULAR"=hex:01,0a,00,00,00,00,00,00,00,00
"PROTOCOL: MNP"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: MNP2"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: MNP3"=hex:01,02,00,00,00,00,00,00,00,00
"PROTOCOL: MNP4"=hex:01,02,00,00,00,00,00,00,00,00
"AUTOSTREAM: LEVEL 1"=hex:01,00,00,00,00,00,00,00,00,00
"AUTOSTREAM: LEVEL 2"=hex:01,00,00,00,00,00,00,00,00,00
"AUTOSTREAM: LEVEL 3"=hex:01,00,00,00,00,00,00,00,00,00
"CARRIER 31200 V.23"=hex:01,00,e0,79,00,00,00,00,00,00
"CARRIER 31200"=hex:01,00,e0,79,00,00,00,00,00,00
"CARRIER 31200/VFC"=hex:01,00,e0,79,00,00,00,00,00,00
"CARRIER 33600 V.23"=hex:01,00,40,83,00,00,00,00,00,00
"CARRIER 33600"=hex:01,00,40,83,00,00,00,00,00,00
"CARRIER 33600/VFC"=hex:01,00,40,83,00,00,00,00,00,00
"CONNECT 31200 EC"=hex:02,02,e0,79,00,00,00,00,00,00
"CONNECT 31200 EC/V42"=hex:02,02,e0,79,00,00,00,00,00,00
"CONNECT 31200 EC/V42BIS"=hex:02,03,e0,79,00,00,00,00,00,00
"CONNECT 31200 REL"=hex:02,02,e0,79,00,00,00,00,00,00
"CONNECT 31200 REL/MNP5"=hex:02,03,e0,79,00,00,00,00,00,00
"CONNECT 31200 REL/V42"=hex:02,02,e0,79,00,00,00,00,00,00
"CONNECT 31200 REL/V42BIS"=hex:02,03,e0,79,00,00,00,00,00,00
"CONNECT 31200"=hex:02,00,e0,79,00,00,00,00,00,00
"CONNECT 31200/ARQ"=hex:02,02,e0,79,00,00,00,00,00,00
"CONNECT 31200/LAP-M"=hex:02,02,e0,79,00,00,00,00,00,00
"CONNECT 31200/MNP"=hex:02,02,e0,79,00,00,00,00,00,00
"CONNECT 31200/REL"=hex:02,02,e0,79,00,00,00,00,00,00
"CONNECT 31200/REL-LAPM V.42 BIS"=hex:02,03,e0,79,00,00,00,00,00,00
"CONNECT 31200/REL-LAPM"=hex:02,02,e0,79,00,00,00,00,00,00
"CONNECT 31200/V42B"=hex:02,03,e0,79,00,00,00,00,00,00
"CONNECT 31200/V42BIS"=hex:02,03,e0,79,00,00,00,00,00,00
"CONNECT 33600 EC"=hex:02,02,40,83,00,00,00,00,00,00
"CONNECT 33600 EC/V42"=hex:02,02,40,83,00,00,00,00,00,00
"CONNECT 33600 EC/V42BIS"=hex:02,03,40,83,00,00,00,00,00,00
"CONNECT 33600 REL"=hex:02,02,40,83,00,00,00,00,00,00
"CONNECT 33600 REL/MNP5"=hex:02,03,40,83,00,00,00,00,00,00
"CONNECT 33600 REL/V42"=hex:02,02,40,83,00,00,00,00,00,00
"CONNECT 33600 REL/V42BIS"=hex:02,03,40,83,00,00,00,00,00,00
"CONNECT 33600"=hex:02,00,40,83,00,00,00,00,00,00
"CONNECT 33600/ARQ"=hex:02,02,40,83,00,00,00,00,00,00
"CONNECT 33600/LAP-M"=hex:02,02,40,83,00,00,00,00,00,00
"CONNECT 33600/MNP"=hex:02,02,40,83,00,00,00,00,00,00
"CONNECT 33600/REL"=hex:02,02,40,83,00,00,00,00,00,00
"CONNECT 33600/REL-LAPM V.42 BIS"=hex:02,03,40,83,00,00,00,00,00,00
"CONNECT 33600/REL-LAPM"=hex:02,02,40,83,00,00,00,00,00,00
"CONNECT 33600/V42B"=hex:02,03,40,83,00,00,00,00,00,00
"CONNECT 33600/V42BIS"=hex:02,03,40,83,00,00,00,00,00,00
"CONNECT 31200/REL-MNP"=hex:02,02,e0,79,00,00,00,00,00,00
"CONNECT 33600/REL-MNP"=hex:02,02,40,83,00,00,00,00,00,00
"1"=hex:02,00,2c,01,00,00,00,00,00,00
"5"=hex:02,00,b0,04,00,00,00,00,00,00
"NO DIAL TONE"=hex:05,00,00,00,00,00,00,00,00,00
"RINGING"=hex:01,00,00,00,00,00,00,00,00,00
"VOICE"=hex:03,00,00,00,00,00,00,00,00,00
"CONNECT 57333/ARQ/x2/MNP/MNP5"=hex:02,03,f5,df,00,00,00,00,00,
00
"CONNECT 57333/ARQ/x2/LAPM/V42BIS"=hex:02,03,f5,df,00,00,00,00,
00,00
"CONNECT 57333/ARQ/x2/LAPM/MNP5"=hex:02,03,f5,df,00,00,00,00,
00,00
"CONNECT 57333/ARQ/x2/MNP"=hex:02,02,f5,df,00,00,00,00,00,00
"CONNECT 57333/ARQ/x2/LAPM"=hex:02,02,f5,df,00,00,00,00,00,00
"CONNECT 57333/x2/NONE"=hex:02,00,f5,df,00,00,00,00,00,00
"CONNECT 56000/ARQ/x2/MNP/MNP5"=hex:02,03,c0,da,00,00,00,00,00,
00
"CONNECT 56000/ARQ/x2/LAPM/V42BIS"=hex:02,03,c0,da,00,00,00,00,
00,00
"CONNECT 56000/ARQ/x2/LAPM/MNP5"=hex:02,03,c0,da,00,00,00,00,
00,00
"CONNECT 56000/ARQ/x2/MNP"=hex:02,02,c0,da,00,00,00,00,00,00
"CONNECT 56000/ARQ/x2/LAPM"=hex:02,02,c0,da,00,00,00,00,00,00
"CONNECT 56000/x2/NONE"=hex:02,00,c0,da,00,00,00,00,00,00
"CONNECT 54666/ARQ/x2/MNP/MNP5"=hex:02,03,8a,d5,00,00,00,00,00,
00
"CONNECT 54666/ARQ/x2/LAPM/V42BIS"=hex:02,03,8a,d5,00,00,00,00,
00,00
"CONNECT 54666/ARQ/x2/LAPM/MNP5"=hex:02,03,8a,d5,00,00,00,00,
00,00
"CONNECT 54666/ARQ/x2/MNP"=hex:02,02,8a,d5,00,00,00,00,00,00
"CONNECT 54666/ARQ/x2/LAPM"=hex:02,02,8a,d5,00,00,00,00,00,00
"CONNECT 54666/x2/NONE"=hex:02,00,8a,d5,00,00,00,00,00,00
"CONNECT 53333/ARQ/x2/MNP/MNP5"=hex:02,03,55,d0,00,00,00,00,00,
00
"CONNECT 53333/ARQ/x2/LAPM/V42BIS"=hex:02,03,55,d0,00,00,00,00,
00,00
"CONNECT 53333/ARQ/x2/LAPM/MNP5"=hex:02,03,55,d0,00,00,00,00,
00,00
"CONNECT 53333/ARQ/x2/MNP"=hex:02,02,55,d0,00,00,00,00,00,00
"CONNECT 53333/ARQ/x2/LAPM"=hex:02,02,55,d0,00,00,00,00,00,00
"CONNECT 53333/x2/NONE"=hex:02,00,55,d0,00,00,00,00,00,00
"CONNECT 52000/ARQ/x2/MNP/MNP5"=hex:02,03,20,cb,00,00,00,00,00,
00
"CONNECT 52000/ARQ/x2/LAPM/V42BIS"=hex:02,03,20,cb,00,00,00,00,
00,00
"CONNECT 52000/ARQ/x2/LAPM/MNP5"=hex:02,03,20,cb,00,00,00,00,
00,00
"CONNECT 52000/ARQ/x2/MNP"=hex:02,02,20,cb,00,00,00,00,00,00
"CONNECT 52000/ARQ/x2/LAPM"=hex:02,02,20,cb,00,00,00,00,00,00
"CONNECT 52000/x2/NONE"=hex:02,00,20,cb,00,00,00,00,00,00
"CONNECT 50666/ARQ/x2/MNP/MNP5"=hex:02,03,ea,c5,00,00,00,00,00,
00
"CONNECT 50666/ARQ/x2/LAPM/V42BIS"=hex:02,03,ea,c5,00,00,00,00,
00,00
"CONNECT 50666/ARQ/x2/LAPM/MNP5"=hex:02,03,ea,c5,00,00,00,00,
00,00
"CONNECT 50666/ARQ/x2/MNP"=hex:02,02,ea,c5,00,00,00,00,00,00
"CONNECT 50666/ARQ/x2/LAPM"=hex:02,02,ea,c5,00,00,00,00,00,00
"CONNECT 50666/x2/NONE"=hex:02,00,ea,c5,00,00,00,00,00,00
"CONNECT 49333/ARQ/x2/MNP/MNP5"=hex:02,03,b5,c0,00,00,00,00,00,
00
"CONNECT 49333/ARQ/x2/LAPM/V42BIS"=hex:02,03,b5,c0,00,00,00,00,
00,00
"CONNECT 49333/ARQ/x2/LAPM/MNP5"=hex:02,03,b5,c0,00,00,00,00,
00,00
"CONNECT 49333/ARQ/x2/MNP"=hex:02,02,b5,c0,00,00,00,00,00,00
"CONNECT 49333/ARQ/x2/LAPM"=hex:02,02,b5,c0,00,00,00,00,00,00
"CONNECT 49333/x2/NONE"=hex:02,00,b5,c0,00,00,00,00,00,00
"CONNECT 48000/ARQ/x2/MNP/MNP5"=hex:02,03,80,bb,00,00,00,00,00,
00
"CONNECT 48000/ARQ/x2/LAPM/V42BIS"=hex:02,03,80,bb,00,00,00,00,
00,00
"CONNECT 48000/ARQ/x2/LAPM/MNP5"=hex:02,03,80,bb,00,00,00,00,
00,00
"CONNECT 48000/ARQ/x2/MNP"=hex:02,02,80,bb,00,00,00,00,00,00
"CONNECT 48000/ARQ/x2/LAPM"=hex:02,02,80,bb,00,00,00,00,00,00
"CONNECT 48000/x2/NONE"=hex:02,00,80,bb,00,00,00,00,00,00
"CONNECT 46666/ARQ/x2/MNP/MNP5"=hex:02,03,4a,b6,00,00,00,00,00,
00
"CONNECT 46666/ARQ/x2/LAPM/V42BIS"=hex:02,03,4a,b6,00,00,00,00,
00,00
"CONNECT 46666/ARQ/x2/LAPM/MNP5"=hex:02,03,4a,b6,00,00,00,00,
00,00
"CONNECT 46666/ARQ/x2/MNP"=hex:02,02,4a,b6,00,00,00,00,00,00
"CONNECT 46666/ARQ/x2/LAPM"=hex:02,02,4a,b6,00,00,00,00,00,00
"CONNECT 46666/x2/NONE"=hex:02,00,4a,b6,00,00,00,00,00,00
"CONNECT 45333/ARQ/x2/MNP/MNP5"=hex:02,03,15,b1,00,00,00,00,00,
00
"CONNECT 45333/ARQ/x2/LAPM/V42BIS"=hex:02,03,15,b1,00,00,00,00,
00,00
"CONNECT 45333/ARQ/x2/LAPM/MNP5"=hex:02,03,15,b1,00,00,00,00,
00,00
"CONNECT 45333/ARQ/x2/MNP"=hex:02,02,15,b1,00,00,00,00,00,00
"CONNECT 45333/ARQ/x2/LAPM"=hex:02,02,15,b1,00,00,00,00,00,00
"CONNECT 45333/x2/NONE"=hex:02,00,15,b1,00,00,00,00,00,00
"CONNECT 44000/ARQ/x2/MNP/MNP5"=hex:02,03,e0,ab,00,00,00,00,00,
00
"CONNECT 44000/ARQ/x2/LAPM/V42BIS"=hex:02,03,e0,ab,00,00,00,00,
00,00
"CONNECT 44000/ARQ/x2/LAPM/MNP5"=hex:02,03,e0,ab,00,00,00,00,
00,00
"CONNECT 44000/ARQ/x2/MNP"=hex:02,02,e0,ab,00,00,00,00,00,00
"CONNECT 44000/ARQ/x2/LAPM"=hex:02,02,e0,ab,00,00,00,00,00,00
"CONNECT 44000/x2/NONE"=hex:02,00,e0,ab,00,00,00,00,00,00
"CONNECT 42666/ARQ/x2/MNP/MNP5"=hex:02,03,aa,a6,00,00,00,00,00,
00
"CONNECT 42666/ARQ/x2/LAPM/V42BIS"=hex:02,03,aa,a6,00,00,00,00,
00,00
"CONNECT 42666/ARQ/x2/LAPM/MNP5"=hex:02,03,aa,a6,00,00,00,00,
00,00
"CONNECT 42666/ARQ/x2/MNP"=hex:02,02,aa,a6,00,00,00,00,00,00
"CONNECT 42666/ARQ/x2/LAPM"=hex:02,02,aa,a6,00,00,00,00,00,00
"CONNECT 42666/x2/NONE"=hex:02,00,aa,a6,00,00,00,00,00,00
"CONNECT 41333/ARQ/x2/MNP/MNP5"=hex:02,03,75,a1,00,00,00,00,00,
00
"CONNECT 41333/ARQ/x2/LAPM/V42BIS"=hex:02,03,75,a1,00,00,00,00,
00,00
"CONNECT 41333/ARQ/x2/LAPM/MNP5"=hex:02,03,75,a1,00,00,00,00,
00,00
"CONNECT 41333/ARQ/x2/MNP"=hex:02,02,75,a1,00,00,00,00,00,00
"CONNECT 41333/ARQ/x2/LAPM"=hex:02,02,75,a1,00,00,00,00,00,00
"CONNECT 41333/x2/NONE"=hex:02,00,75,a1,00,00,00,00,00,00
"CONNECT 37333/ARQ/x2/MNP/MNP5"=hex:02,03,d5,91,00,00,00,00,00,
00
"CONNECT 37333/ARQ/x2/LAPM/V42BIS"=hex:02,03,d5,91,00,00,00,00,
00,00
"CONNECT 37333/ARQ/x2/LAPM/MNP5"=hex:02,03,d5,91,00,00,00,00,
00,00
"CONNECT 37333/ARQ/x2/MNP"=hex:02,02,d5,91,00,00,00,00,00,00
"CONNECT 37333/ARQ/x2/LAPM"=hex:02,02,d5,91,00,00,00,00,00,00
"CONNECT 37333/x2/NONE"=hex:02,00,d5,91,00,00,00,00,00,00
.
——————— 運行進程下的動態鏈接庫 ———————
.
- - - - - - - > 'winlogon.exe'(1848)
c:\program files\Softex\OmniPass\opxpgina.dll
.
- - - - - - - > 'explorer.exe'(4068)
c:\windows\system32\WININET.dll
c:\program files\SugarSync\SugarSyncShellExt.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— 其他運行進程 ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\OrangeHRM\2.6.12.1\mysql\bin\mysqld.exe
c:\windows\system32\o2flash.exe
c:\program files\Softex\OmniPass\Omniserv.exe
c:\program files\PC Tools Firewall Plus\FWService.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Softex\OmniPass\OPXPApp.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\conime.exe
c:\windows\AGRSMMSG.exe
c:\progra~1\MICROS~4\rapimgr.exe
.
**************************************************************************
.
完成時間: 2012-02-03 00:28:53 - 電腦已重新啟動
ComboFix-quarantined-files.txt 2012-02-02 16:28
.
Pre-Run: 4,895,342,592 位元組可用
Post-Run: 6,943,248,384 位元組可用
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CHT.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 588B8D81F6B1F18754820B5AB03BA757

After running combofix , i reinstall avira.
Should i run otl once again ?
Hello camelpig

Scan For Malware:

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.



Do An Online Scan For Viruses:

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
In your next reply please post the logs created by Malwarebytes and the ESET Online Scan.

How is your system is running now?
Both results is negative. Eset online scan didn't any log. mbam log: Malwarebytes Anti-Malware (Trial) 1.60.1.1000 www.malwarebytes.org Database version: v2012.02.03.06 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Kenneth :: COMP1 [administrator] Protection: Disabled 3/2/2012 23:00:45 mbam-log-2012-02-03 (23-00-45).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 189070 Time elapsed: 10 minute(s), 3 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Hello camelpig

Eset online scan didn't any log.

Did you Push [external image: Posted Image], and save the file to your desktop?


And please tell us…

How is your system is running now?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI