Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
 
Closed TopicStart new topic
Infected with Trojan.Vundo.H [Closed], Computer slows, malawarebytes shows repeated infection with TVH.
little_angel
post Sep 18 2009, 04:25 PM
Post #1


New Member
*
Posts: 8
OS: windows xp



Hello,
I've noticed my computer to be excessively slow for about 1 month or so. When I ran Malawarebytes, it showed I was infected with Trojan.Vundo.H., and prompted me to reboot computer to fix. After being "fixed", my computer runs a bit faster, however, after 5 minutes of connecting to the internet, without surfing or even opening Internet explorer, my computer would become sluggish and Malawarebytes would show that i have at least 5 infections with of the same Trojan.
When I surf for instruction on removal of TVH, just about any website I clicked on would be redirected to somewhere else. Sometimes, I even get redirected when trying to go to www.mail.yahoo.com.
I'm not sure if this is related, but about a month or so, I have not been able to open the Add/Remove programs option in my COntrol Panel to remove unwanted program, no matter what I do.
Below is my most recent Malawarebytes scan and HJT log
Thank you for all your help.


Malwarebytes' Anti-Malware 1.41
Database version: 2819
Windows 5.1.2600 Service Pack 3

9/18/2009 1:35:51 PM
mbam-log-2009-09-18 (13-35-51).txt

Scan type: Full Scan (C:\|)
Objects scanned: 217185
Time elapsed: 1 hour(s), 38 minute(s), 55 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\SYSTEM32\ablvzzxf.dll (Trojan.Vundo.H) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01f97b14-a066-42fa-80b9-5f112a423743} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{01f97b14-a066-42fa-80b9-5f112a423743} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{01f97b14-a066-42fa-80b9-5f112a423743} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\SYSTEM32\ablvzzxf.dll (Trojan.Vundo.H) -> Delete on reboot.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:14:48 PM, on 9/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O1 - Hosts: ::1 localhost
O1 - Hosts: ??????????????? browser-security.microsoft.com
O1 - Hosts: ??????????????? spywareprotector-2009.com
O1 - Hosts: ??????????????? www.spywareprotector-2009.com
O1 - Hosts: ??????????????? secure.spywareprotector-2009.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {2EB5C6DF-DBF6-4E3F-A81A-FABABBCB693B} - c:\windows\system32\ojxhfcz.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [hpppt] /ICON
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.imageservr.com (HKLM)
O16 - DPF: Yahoo! Go - http://download.games.yahoo.com/games/clients/y/gt2_x.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase9563.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1173831454421
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033...all/xscan53.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8646A6AF-0AE4-4BF8-B716-DB1513803972} (SFImageUpload1_8.ImageUpload) - http://riteaid.storefront.com/images/globa...geUpload1_8.CAB
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://www.imgag.com/cp/install/Crusher.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem...GameManager.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac...ta/SymAData.dll
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p...obat/nos/gp.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac.../ActiveData.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca04.rightnowtech.com/7020-b369...l/java/RntX.cab
O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugi...NetOpPlugin.ocx
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: karna.dat
O20 - Winlogon Notify: bbddqbke - C:\WINDOWS\SYSTEM32\ojxhfcz.dll
O20 - Winlogon Notify: mljigfg - mljigfg.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\SYSTEM32\IcdSptSv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Protected Storage (ProtectedStorage) - Unknown owner - C:\WINDOWS\system32\lsassnexe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 9582 bytes
Go to the top of the page
 
+Quote Post
NeonFx
post Sep 18 2009, 04:44 PM
Post #2


Malware Removal Dude
Group Icon
Posts: 1,350
From: California
OS: XP / Vista



Hello there cool.gif Welcome to the GeeksToGo forums.
My name is NeonFx. I'll be glad to help you with your computer problems. Logs can take some time to research, so please be patient with me. I am still a student here, and as such I will have to have all my responses checked by a malware removal expert before I post them here.

Please note the following:
  • The fixes are specific to your problem and should only be used on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that the system is completely clean.
  • It's often worth reading through these instructions and printing them for ease of reference. I may ask you to boot into Safe Mode where you will be unable to follow my instructions online.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


Note: Disabling any security programs you have running will significantly decrease the time it takes to run most of the programs I ask you run. Please disable them before performing any of my steps. For instructions, if needed, see HERE

Step 1

Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.

Start the Sysprot.exe program.

  • Click on the Log tab.
  • In the Write to log box select all items.
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new Window should appear.
  • Make sure Scan all drives is selected and click on the Start button.
    (Unless you have a floppy drive. In this case, please use "Scan Root Drive Only" and press Start)
  • When it is complete a new Window will appear to indicate that the scan is finished.
  • The log will be created and saved automatically in the same folder. Open the text file and copy/paste the log here.


Step 2

Download AVZ and save it to your Desktop by right clicking HERE , selecting "Save Link As" or "Save Target As" and browsing to your desktop on the window that pops up before you click on the Save button.

Right click on avz4.zip and select "Extract All..." from the selection. Extract it to a new folder on your desktop and open this folder. If you used the default settings, this folder will be called "avz4."

  1. Double click on AVZ.exe
  2. Click File > Custom scripts
  3. Copy & paste the contents of the following codebox into the new "Run A Script" window that opened up. (start with begin and end with end.)
    To copy and paste you need to click and drag your mouse to select all the text, right click on it and select "Copy". Then right click where you wish to paste it and select "Paste"

    CODE
    begin
    if ExecuteAVUpdate then
      AddLineToTxtFile(GetAVZDirectory + '\LOG\History.txt', DateTimeToStr(Now)+': Update Completed')
    else
      AddLineToTxtFile(GetAVZDirectory + '\LOG\History.txt', DateTimeToStr(Now)+': Error Updating');
    if ExecuteStdScr(3) then
      AddLineToTxtFile(GetAVZDirectory + '\LOG\History.txt', DateTimeToStr(Now)+': System Analysis with MRM enabled was run successfully');
    SetAVZPMStatus(True);
    RebootWindows(true);
    end.
  4. Click the "Check Syntax" button
  5. If you get an error when clicking "Check Syntax" make sure you copy and pasted the entire code over correctly.
  6. If it says "Syntax is Correct" with a green check, click on the Run button to start the script.
    Note: When you run the script, your PC will be restarted.


STEP 3
After your computer Restarts:

  1. Double click on AVZ.exe
  2. Click File > Custom scripts
  3. Copy & paste the contents of the following codebox into the new "Run A Script" window that opened up. (start with begin and end with end.)
    To copy and paste you need to click and drag your mouse to select all the text, right click on it and select "Copy". Then right click where you wish to paste it and select "Paste"

    CODE
    begin
    if GetAVZPMStatus then
      AddLineToTxtFile(GetAVZDirectory + '\LOG\History.txt', DateTimeToStr(Now)+': AVZPM is active')
    else
      AddLineToTxtFile(GetAVZDirectory + '\LOG\History.txt', DateTimeToStr(Now)+': AVZPM is not active');
    if ExecuteStdScr(2) then
      AddLineToTxtFile(GetAVZDirectory + '\LOG\History.txt', DateTimeToStr(Now)+': System Analysis was run successfully');
    RebootWindows(true);
    end.
  4. Click the "Check Syntax" button
  5. If you get an error when clicking "Check Syntax" make sure you copy and pasted the entire code over correctly.
  6. If it says "Syntax is Correct" with a green check, click on the Run button to start the script.
    Note: When you run the script, your PC will be restarted.


AVZ saves its logs as .zip files in the LOG folder within the AVZ4 folder from which AVZ.exe was run.
Please attach both virusinfo_syscure.zip and virusinfo_syscheck.zip to your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on to insert the attachment into your post


In the LOG folder you will also see a file called "History.txt". Please double click on it to open it in Notepad, and copy and paste the contents of that file here.


Step 4

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Under the Extra Registry box change it to Use SafeList if it is not selected.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.txt and Extras.Txt. These are saved in the same location as OTL.exe.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.



In your next reply, please include
  • The results from the SysProt scan
  • The two attached zip files from the AVZ scans
  • The contents of the History.txt file in AVZ's LOG folder.
  • The results from the OTL scans (OTL.txt , Extras.txt)
Go to the top of the page
 
+Quote Post
little_angel
post Sep 18 2009, 06:07 PM
Post #3


New Member
*
Posts: 8
OS: windows xp



SysProt AntiRootkit v1.0.1.0
by swatkat

******************************************************************************************
******************************************************************************************

Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No

Name: System
PID: 4
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\smss.exe
PID: 408
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\csrss.exe
PID: 464
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\winlogon.exe
PID: 488
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\services.exe
PID: 532
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\lsass.exe
PID: 544
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 700
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 764
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 800
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 844
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 876
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\LEXBCES.EXE
PID: 1096
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\spoolsv.exe
PID: 1120
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\LEXPPS.EXE
PID: 1128
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 1252
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PID: 1280
Hidden: No
Window Visible: No

Name: C:\Program Files\Bonjour\mDNSResponder.exe
PID: 1316
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE
PID: 1328
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\svchost.exe
PID: 1420
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\wdfmgr.exe
PID: 1460
Hidden: No
Window Visible: No

Name: C:\Program Files\Viewpoint\Common\ViewpointService.exe
PID: 1492
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\alg.exe
PID: 128
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\wscntfy.exe
PID: 1068
Hidden: No
Window Visible: No

Name: C:\WINDOWS\explorer.exe
PID: 1996
Hidden: No
Window Visible: No

Name: C:\WINDOWS\SYSTEM32\hkcmd.exe
PID: 2488
Hidden: No
Window Visible: No

Name: C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
PID: 2504
Hidden: No
Window Visible: No

Name: C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
PID: 2516
Hidden: No
Window Visible: No

Name: C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
PID: 2524
Hidden: No
Window Visible: No

Name: C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
PID: 2552
Hidden: No
Window Visible: No

Name: C:\Program Files\iTunes\iTunesHelper.exe
PID: 2572
Hidden: No
Window Visible: No

Name: C:\Program Files\QuickTime\QTTask.exe
PID: 2600
Hidden: No
Window Visible: No

Name: C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
PID: 2632
Hidden: No
Window Visible: No

Name: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PID: 2644
Hidden: No
Window Visible: No

Name: C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
PID: 2672
Hidden: No
Window Visible: No

Name: C:\Program Files\Digital Line Detect\DLG.exe
PID: 2696
Hidden: No
Window Visible: No

Name: C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
PID: 2720
Hidden: No
Window Visible: No

Name: C:\Program Files\Internet Explorer\iexplore.exe
PID: 2752
Hidden: No
Window Visible: No

Name: C:\Program Files\iPod\bin\iPodService.exe
PID: 2868
Hidden: No
Window Visible: No

Name: C:\Documents and Settings\TuongVy\Desktop\SysProt\SysProt\SysProt.exe
PID: 304
Hidden: No
Window Visible: Yes

******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \??\C:\Documents and Settings\TuongVy\Desktop\SysProt\SysProt\SysProtDrv.sys
Service Name: SysProtDrv.sys
Module Base: EFAAB000
Module End: EFAB6000
Hidden: No

Module Name: \WINDOWS\system32\ntoskrnl.exe
Service Name: ---
Module Base: 804D7000
Module End: 806ED700
Hidden: No

Module Name: \WINDOWS\system32\hal.dll
Service Name: ---
Module Base: 806EE000
Module End: 8070E300
Hidden: No

Module Name: \WINDOWS\system32\KDCOM.DLL
Service Name: ---
Module Base: F9762000
Module End: F9764000
Hidden: No

Module Name: \WINDOWS\system32\BOOTVID.dll
Service Name: ---
Module Base: F9672000
Module End: F9675000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\ACPI.sys
Service Name: ACPI
Module Base: F9213000
Module End: F9241000
Hidden: No

Module Name: \WINDOWS\System32\DRIVERS\WMILIB.SYS
Service Name: ---
Module Base: F9764000
Module End: F9766000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\pci.sys
Service Name: PCI
Module Base: F9202000
Module End: F9213000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\isapnp.sys
Service Name: isapnp
Module Base: F9262000
Module End: F926C000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\lpjoofsn.sys
Service Name: lpjoofsn
Module Base: F94E2000
Module End: F94E8000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\pciide.sys
Service Name: PCIIde
Module Base: F982A000
Module End: F982B000
Hidden: No

Module Name: \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
Service Name: ---
Module Base: F94EA000
Module End: F94F1000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys
Service Name: MountMgr
Module Base: F9272000
Module End: F927D000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys
Service Name: Disk
Module Base: F91E3000
Module End: F9202000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\dmio.sys
Service Name: dmio
Module Base: F91BD000
Module End: F91E3000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys
Service Name: PartMgr
Module Base: F94F2000
Module End: F94F7000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys
Service Name: VolSnap
Module Base: F9282000
Module End: F928F000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\atapi.sys
Service Name: atapi
Module Base: F91A5000
Module End: F91BD000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\disk.sys
Service Name: ---
Module Base: F9292000
Module End: F929B000
Hidden: No

Module Name: \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
Service Name: ---
Module Base: F92A2000
Module End: F92AF000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\sr.sys
Service Name: sr
Module Base: F9173000
Module End: F9185000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\PxHelp20.sys
Service Name: PxHelp20
Module Base: F92B2000
Module End: F92BB000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys
Service Name: KSecDD
Module Base: F915C000
Module End: F9173000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys
Service Name: Ntfs
Module Base: F90CF000
Module End: F915C000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\NDIS.sys
Service Name: NDIS
Module Base: F90A2000
Module End: F90CF000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\Mup.sys
Service Name: Mup
Module Base: F9088000
Module End: F90A2000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\intelppm.sys
Service Name: intelppm
Module Base: F92F2000
Module End: F92FB000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ialmnt5.sys
Service Name: ialm
Module Base: F9018000
Module End: F902F000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\VIDEOPRT.SYS
Service Name: ---
Module Base: F9004000
Module End: F9018000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\usbuhci.sys
Service Name: usbuhci
Module Base: F95AA000
Module End: F95B0000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\USBPORT.SYS
Service Name: ---
Module Base: F8FE0000
Module End: F9004000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\usbehci.sys
Service Name: usbehci
Module Base: F95B2000
Module End: F95BA000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys
Service Name: HSFHWBS2
Module Base: F8FB9000
Module End: F8FE0000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\HSF_DP.sys
Service Name: HSF_DP
Module Base: F8EAE000
Module End: F8FB9000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys
Service Name: winachsf
Module Base: F8E22000
Module End: F8EAE000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Modem.SYS
Service Name: Modem
Module Base: F95BA000
Module End: F95C2000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\P16X.sys
Service Name: P16X
Module Base: F8CE6000
Module End: F8E22000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\ks.sys
Service Name: ---
Module Base: F8CC3000
Module End: F8CE6000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\portcls.sys
Service Name: ---
Module Base: F8C9F000
Module End: F8CC3000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\drmk.sys
Service Name: ---
Module Base: F9302000
Module End: F9311000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\gameenum.sys
Service Name: gameenum
Module Base: F9742000
Module End: F9745000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\i8042prt.sys
Service Name: i8042prt
Module Base: F9312000
Module End: F931F000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\kbdclass.sys
Service Name: Kbdclass
Module Base: F95CA000
Module End: F95D0000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\mouclass.sys
Service Name: Mouclass
Module Base: F95D2000
Module End: F95D8000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\serial.sys
Service Name: Serial
Module Base: F9322000
Module End: F9332000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\serenum.sys
Service Name: serenum
Module Base: F9746000
Module End: F974A000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\parport.sys
Service Name: Parport
Module Base: F8C8B000
Module End: F8C9F000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\imapi.sys
Service Name: Imapi
Module Base: F9332000
Module End: F933D000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\MxlW2k.SYS
Service Name: MxlW2k
Module Base: F95DA000
Module End: F95E1000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Service Name: Cdrom
Module Base: F9342000
Module End: F9352000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\redbook.sys
Service Name: redbook
Module Base: F9352000
Module End: F9361000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\pwd_2k.SYS
Service Name: pwd_2k
Module Base: F8C6C000
Module End: F8C8B000
Hidden: No

Module Name: C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
Service Name: GEARAspiWDM
Module Base: F9362000
Module End: F936C000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\audstub.sys
Service Name: audstub
Module Base: F9972000
Module End: F9973000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\rasl2tp.sys
Service Name: Rasl2tp
Module Base: F9372000
Module End: F937F000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ndistapi.sys
Service Name: NdisTapi
Module Base: F974E000
Module End: F9751000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ndiswan.sys
Service Name: NdisWan
Module Base: F8C55000
Module End: F8C6C000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\raspppoe.sys
Service Name: RasPppoe
Module Base: F9382000
Module End: F938D000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\raspptp.sys
Service Name: PptpMiniport
Module Base: F9392000
Module End: F939E000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\TDI.SYS
Service Name: ---
Module Base: F95E2000
Module End: F95E7000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\psched.sys
Service Name: PSched
Module Base: F8C44000
Module End: F8C55000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\msgpc.sys
Service Name: Gpc
Module Base: F93A2000
Module End: F93AB000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ptilink.sys
Service Name: Ptilink
Module Base: F95F2000
Module End: F95F7000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\raspti.sys
Service Name: Raspti
Module Base: F95FA000
Module End: F95FF000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\rdpdr.sys
Service Name: rdpdr
Module Base: F8C14000
Module End: F8C44000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\termdd.sys
Service Name: TermDD
Module Base: F93B2000
Module End: F93BC000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\swenum.sys
Service Name: swenum
Module Base: F979C000
Module End: F979E000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\update.sys
Service Name: Update
Module Base: F8B8E000
Module End: F8BEC000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\omci.sys
Service Name: omci
Module Base: F9602000
Module End: F9607000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\mssmbios.sys
Service Name: mssmbios
Module Base: F9047000
Module End: F904B000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\ialmkchw.sys
Service Name: {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}
Module Base: F0AFA000
Module End: F0B0E000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\ialmsbw.sys
Service Name: {6080A529-897E-4629-A488-ABA0C29B635E}
Module Base: F0ADE000
Module End: F0AFA000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\mmc_2K.SYS
Service Name: mmc_2K
Module Base: F960A000
Module End: F9610000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Service Name: NDProxy
Module Base: F93D2000
Module End: F93DC000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\usbhub.sys
Service Name: usbhub
Module Base: F93E2000
Module End: F93F1000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\USBD.SYS
Service Name: ---
Module Base: F97A0000
Module End: F97A2000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\flpydisk.sys
Service Name: Flpydisk
Module Base: F9612000
Module End: F9617000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\i2omgmt.SYS
Service Name: i2omgmt
Module Base: F9712000
Module End: F9715000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Cdr4_xp.SYS
Service Name: Cdr4_xp
Module Base: F9876000
Module End: F9877000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Cdralw2k.SYS
Service Name: Cdralw2k
Module Base: F9877000
Module End: F9878000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\ATMhelpr.SYS
Service Name: ATMhelpr
Module Base: F9879000
Module End: F987A000
Hidden: No

Module Name: C:\WINDOWS\System32\drivers\vga.sys
Service Name: VgaSave
Module Base: F9622000
Module End: F9628000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Service Name: mnmdd
Module Base: F97A6000
Module End: F97A8000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Service Name: RDPCDD
Module Base: F97A8000
Module End: F97AA000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\cdudf_xp.SYS
Service Name: cdudf_xp
Module Base: F0976000
Module End: F09B1000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS
Service Name: Npfs
Module Base: F9632000
Module End: F963A000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\UdfReadr_xp.SYS
Service Name: UdfReadr_xp
Module Base: F0931000
Module End: F0964000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\rasacd.sys
Service Name: RasAcd
Module Base: F972A000
Module End: F972D000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\NDISRD.SYS
Service Name: NDISRD
Module Base: F963A000
Module End: F9640000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ipsec.sys
Service Name: IPSec
Module Base: F08E4000
Module End: F08F7000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\tcpip.sys
Service Name: Tcpip
Module Base: F088B000
Module End: F08E4000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\netbt.sys
Service Name: NetBT
Module Base: F0863000
Module End: F088B000
Hidden: No

Module Name: C:\WINDOWS\System32\drivers\ws2ifsl.sys
Service Name: WS2IFSL
Module Base: F9732000
Module End: F9735000
Hidden: No

Module Name: C:\WINDOWS\System32\drivers\afd.sys
Service Name: AFD
Module Base: F0841000
Module End: F0863000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\netbios.sys
Service Name: NetBIOS
Module Base: F9422000
Module End: F942B000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\rdbss.sys
Service Name: Rdbss
Module Base: F0816000
Module End: F0841000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\mrxsmb.sys
Service Name: MRxSmb
Module Base: F07A6000
Module End: F0816000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS
Service Name: Fips
Module Base: F9452000
Module End: F945D000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ipnat.sys
Service Name: IpNat
Module Base: F0780000
Module End: F07A6000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\wanarp.sys
Service Name: Wanarp
Module Base: F9462000
Module End: F946B000
Hidden: No

Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: F0740000
Module End: F0758000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: F97AE000
Module End: F97B0000
Hidden: Yes

Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys
Service Name: ---
Module Base: F0A26000
Module End: F0A29000
Hidden: No

Module Name: C:\WINDOWS\System32\watchdog.sys
Service Name: ---
Module Base: F964A000
Module End: F964F000
Hidden: No

Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys
Service Name: ---
Module Base: F9920000
Module End: F9921000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ndisuio.sys
Service Name: Ndisuio
Module Base: F0605000
Module End: F0609000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\mrxdav.sys
Service Name: MRxDAV
Module Base: F0390000
Module End: F03BD000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys
Service Name: mdmxsdk
Module Base: F0471000
Module End: F0474000
Hidden: No

Module Name: \??\C:\WINDOWS\System32\PfModNT.sys
Service Name: PfModNT
Module Base: F97AC000
Module End: F97AE000
Hidden: No

Module Name: \??\C:\WINDOWS\System32\Drivers\SbcpHid.sys
Service Name: SbcpHid
Module Base: F056D000
Module End: F0577000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\srv.sys
Service Name: Srv
Module Base: F010E000
Module End: F0160000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys
Service Name: wdmaud
Module Base: EFE01000
Module End: EFE16000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys
Service Name: sysaudio
Module Base: F0026000
Module End: F0035000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Service Name: Cdfs
Module Base: EFDA3000
Module End: EFDB3000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\HTTP.sys
Service Name: HTTP
Module Base: EF9F7000
Module End: EFA38000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys
Service Name: bcm4sbxp
Module Base: EF8FF000
Module End: EF90A000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\dmload.sys
Service Name: dmload
Module Base: F9766000
Module End: F9768000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\fdc.sys
Service Name: Fdc
Module Base: F95C2000
Module End: F95C9000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\ParVdm.SYS
Service Name: ParVdm
Module Base: F9798000
Module End: F979A000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Null.SYS
Service Name: Null
Module Base: F9878000
Module End: F9879000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS
Service Name: Msfs
Module Base: F962A000
Module End: F962F000
Hidden: No

******************************************************************************************
******************************************************************************************
No SSDT Hooks found

******************************************************************************************
******************************************************************************************
No Kernel Hooks found

******************************************************************************************
******************************************************************************************
No IRP Hooks found

******************************************************************************************
******************************************************************************************
Ports:
Local Address: D7SDGB31.MYHOME.WESTELL.COM:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING

Local Address: D7SDGB31:27015
Remote Address: LOCALHOST:1041
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: ESTABLISHED

Local Address: D7SDGB31:27015
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: LISTENING

Local Address: D7SDGB31:5354
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: LISTENING

Local Address: D7SDGB31:1041
Remote Address: LOCALHOST:27015
Type: TCP
Process: C:\Program Files\iTunes\iTunesHelper.exe
State: ESTABLISHED

Local Address: D7SDGB31:1028
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\SYSTEM32\alg.exe
State: LISTENING

Local Address: D7SDGB31:1025
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\SYSTEM32\LEXPPS.EXE
State: LISTENING

Local Address: D7SDGB31:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING

Local Address: D7SDGB31:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\SYSTEM32\svchost.exe
State: LISTENING

Local Address: D7SDGB31.MYHOME.WESTELL.COM:5353
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA

Local Address: D7SDGB31.MYHOME.WESTELL.COM:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\SYSTEM32\svchost.exe
State: NA

Local Address: D7SDGB31.MYHOME.WESTELL.COM:138
Remote Address: NA
Type: UDP
Process: System
State: NA

Local Address: D7SDGB31.MYHOME.WESTELL.COM:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA

Local Address: D7SDGB31.MYHOME.WESTELL.COM:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\SYSTEM32\svchost.exe
State: NA

Local Address: D7SDGB31:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\SYSTEM32\svchost.exe
State: NA

Local Address: D7SDGB31:1052
Remote Address: NA
Type: UDP
Process: C:\Program Files\Internet Explorer\iexplore.exe
State: NA

Local Address: D7SDGB31:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\SYSTEM32\svchost.exe
State: NA

Local Address: D7SDGB31:58182
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA

Local Address: D7SDGB31:4500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\SYSTEM32\lsass.exe
State: NA

Local Address: D7SDGB31:1026
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA

Local Address: D7SDGB31:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\SYSTEM32\lsass.exe
State: NA

Local Address: D7SDGB31:MICROSOFT-DS
Remote Address: NA
Type: UDP
Process: System
State: NA

******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\Documents and Settings\TuongVy\Application Data\Microsoft\Office\Recent\Nam Bính Tu?t.LNK
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Application Data\Microsoft\Office\Recent\Quę Huong B? L?i.LNK
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Application Data\Microsoft\Office\Recent\Đęm Đông.LNK
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\click2,060qAO2MCQAqYioAAAAAANMQDAAAAAAAAgD4AQYAAAAAAP8AAAAHEHe2DwAAAAAAuB4RAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F33%2F15%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\click2,060qAO2MCQB5tR8AAAAAAHnnCgAAAAAAAgEAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAACGjg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAA[2].com%2Fno_bra%2F3%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAGMAAYAAAAAAAUACQAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F81%2F01%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAcABAAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F35%2F06%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\click2,060qAO2MCQDKCS0AAAAAAMIhDQAAAAAAAgDcAAYAAAAAAP8AAAABAXa2DwAAAAAA6JcSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\main_2;sz=300x250;mpvid=AARzbqbF2fYfzT4t;!c=2;k2=211;k3=211;klg=en;kvid=Uhdajt0C1sE;ctb=1;kr=A;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=Uhdajt0C1sE_2;kg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\main_2;sz=450x60;mpvid=AARzbaZ8Rpgm-jnR;!c=2;k2=211;k3=211;klg=en;kvid=oqGnsP4wOf0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=oqGnsP4wOf0_2;kgg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\main_2;sz=480x70,480x360;mpvid=AARzbHogfYeijH0I;!c=2;k2=593;k3=593;klg=en;kvid=j5Cvq416zuQ;ctb=1;kr=F;kt=K;ko=p;kpid=2;afc=1;kga=-1;shortform=1;u=j5Cvq416z
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\main_2;sz=480x70,480x360;mpvid=AARzbIqhklLpg1Q8;!c=2;k2=618;k3=618;klg=en;kvid=1nV_p6cvr2A;ctb=1;kr=F;khd=0;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=1nV_p6cv
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\main_2;sz=480x70;mpvid=AARzbAO1ptvzrNXu;!c=2;k2=211;k3=211;klg=en;kvid=Jdvmw4FRzQ8;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=Jdvmw4FRzQ8_2;kgg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\main_9440;sz=480x70;mpvid=AARzbaSST1aBdfx7;!c=9440;k2=184;k2=507;k3=184;klg=en;kvid=-37F6MmAYD4;kpu=LittleMissSunshine87;kr=F;kt=K;ko=c;kpid=9440;afc=1;kga
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAIAAgAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AA[2].com%2F7th_period_is_a_secret%2F2%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAE8AAYAAAAAAAcACgAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F83%2F09%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH0AAIAAAAAAAMACQAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F84%2F09%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH4AQIAAAAAAAYAAgAHD3e2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F30%2F13%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\click2,5jBaAP4SCACOAi0AAAAAAFCTCgAAAAAAAwANaAoAAAAAAP8AAAAHEvdBCwAAAAAAtxMPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAABJIQIAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\default;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=pocahontas+if+i+never+knew+you+with+lyrics;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=3
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\main_2;sz=300x60,300x250;mpvid=AARza6Z4w1zIt1i7;!c=2;k2=584;k2=617;k3=584;klg=en;kvid=ljdodmEly6A;ctb=1;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=ljdodmE
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\main_2;sz=450x60;mpvid=AARzbIqhklLpg1Q8;!c=2;k2=618;k3=618;klg=en;kvid=1nV_p6cvr2A;ctb=1;kr=F;khd=0;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=1nV_p6cvr2A_2;kg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\main_2;sz=450x60;mpvid=AARzbZa60_ywl0tx;!c=2;k2=211;k3=211;klg=en;kvid=oqGnsP4wOf0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=oqGnsP4wOf0_2;kgg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\main_5703;sz=300x250;mpvid=AARzbGIAgfphbzHA;!c=5703;k2=3;k2=23;k3=3;klg=en;kvid=YRi20cWMYOM;ctb=1;kr=F;kt=K;ko=c;kpid=5703;afc=1;kga=-1;shortform=1;u=YRi20
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\click2,060qAO2MCQAIBi0AAAAAABrVDAAAAAAAAgH4AQIAAAAAAP8AAAAHEPgSEAAAAAAA9ngNAAAAAADkKBIAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAA[2].com%2Fgintama%2F33%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAIABgAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAA[2].com%2Fno_bra%2F1%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\click2,060qAO2MCQDDOC0AAAAAAHPiDAAAAAAAAAEAAAIAAAAAAAoAAQAHFHa2DwAAAAAAjjsSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\click2,060qAO2MCQDDOC0AAAAAAHPiDAAAAAAAAgH4AQIAAAAAAP8AAAAHE3e2DwAAAAAAjjsSAAAAAAAAAAAAAAAAAAAAAAAAA[1].com%2Fsuperior%2F21%2F01%2F,;dcopt=rcl;mtfIFPath=no
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\main_2;sz=300x250;mpvid=AARza3NwqFsWxDrN;!c=2;k2=211;k3=211;klg=en;kvid=9I9hVzqTbn0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;k1=rock;u=9I9hVzqTbn0_2;kgg=-1
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\main_2;sz=300x60,300x250;mpvid=AARzbBPWz9fDIPli;!c=2;k2=35;k3=35;klg=en;kvid=APnO_I4idsY;ctb=1;kr=F;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=APnO_I4idsY_2;kg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\main_2;sz=300x60,300x250;mpvid=AARzbYcYcW0k9V-w;!c=2;k2=211;k3=211;klg=en;kvid=uD7HfOX9i64;kpu=sonybmg;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=uD7HfOX9
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\main_2;sz=450x60;mpvid=AARzbBPWz9fDIPli;!c=2;k2=35;k3=35;klg=en;kvid=APnO_I4idsY;ctb=1;kr=F;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=APnO_I4idsY_2;kgg=-1;kcr
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\main_2;sz=480x70;mpvid=AARzbaZ8Rpgm-jnR;!c=2;k2=211;k3=211;klg=en;kvid=oqGnsP4wOf0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=oqGnsP4wOf0_2;kgg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\81AVWX2F\click2,060qAO2MCQADHScAAAAAAHnnCgAAAAAAAgEAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAACGjg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAA[2].com%2Fno_bra%2F17%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\81AVWX2F\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAYABwAHD3a2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F30%2F11%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\81AVWX2F\click2,060qAO2MCQDh8BIAAAAAAN63BQAAAAAAAACEAQYAAAAAAAAAAgAHDfgSEAAAAAAAGEIOAAAAAADLiggAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\81AVWX2F\main_2;sz=450x60;mpvid=AARza3NwqFsWxDrN;!c=2;k2=211;k3=211;klg=en;kvid=9I9hVzqTbn0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;k1=rock;u=9I9hVzqTbn0_2;kgg=-1;
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\81AVWX2F\main_2;sz=450x60;mpvid=AARzbYcYcW0k9V-w;!c=2;k2=211;k3=211;klg=en;kvid=uD7HfOX9i64;kpu=sonybmg;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=uD7HfOX9i64_2;kg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\81AVWX2F\main_2;sz=480x70,480x360;mpvid=AARzbXu50EmUJgRF;!c=2;k2=617;k3=617;klg=en;kvid=WZiQdM7ih5Q;ctb=1;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=WZiQdM7ih5Q_2;
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\81AVWX2F\main_2;sz=480x70;mpvid=AARza2HRcvJHpj0e;!c=2;k2=184;k2=617;k3=184;klg=en;kvid=W2uHW1h5uWY;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=W2uHW1h5uW
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAEABQAHEHe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F35%2F07%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\click2,060qAO2MCQDh8BIAAAAAAN63BQAAAAAAAAB8AQYAAAAAAAEAAQAHDfgSEAAAAAAAGEIOAAAAAADLiggAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAGEAAIAAAAAAAkABgAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F83%2F17%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH4AQIAAAAAAAcABQAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F34%2F20%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\click2,060qAO2MCQDuvBsAAAAAAHnnCgAAAAAAAgEAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAACGjg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAA[2].com%2Fno_bra%2F2%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\main_2;sz=300x250;mpvid=AARzbZa60_ywl0tx;!c=2;k2=211;k3=211;klg=en;kvid=oqGnsP4wOf0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=oqGnsP4wOf0_2;kg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\main_2;sz=450x60;mpvid=AARza6Z4w1zIt1i7;!c=2;k2=584;k2=617;k3=584;klg=en;kvid=ljdodmEly6A;ctb=1;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=ljdodmEly6A_2;k
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\main_2;sz=450x60;mpvid=AARzbWi9jfofJKb7;!c=2;k2=35;k2=299;k3=35;klg=en;kvid=sjbDuXZ8gTo;ctb=1;kr=A;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=sjbDuXZ8gTo_
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\music_jazzrb;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=i+swear+boyz+2+men+official+video;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=20067
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\click2,060qAO2MCQD1WCkAAAAAAMzyCwAAAAAAAgAAAAIAAAAAAP8AAAAHFNL5DgAAAAAAiYILAAAAAADk9xAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\click2,060qAO2MCQD5kigAAAAAADPPCwAAAAAAAgH4AQIAAAAAAP8AAAAHENL5DgAAAAAAiYILAAAAAACQyBAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\click2,060qAO2MCQDh8BIAAAAAAN63BQAAAAAAAABMAQYAAAAAAAEAAgABAfgSEAAAAAAAGEIOAAAAAADLiggAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAGUAAIAAAAAAAAABwAHDXe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F83%2F18-19%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH4AQIAAAAAAAEABAAHEHe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F33%2F04%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAHEAQIAAAAAAAIABQAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F82%2F15%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\click2,VaUDABPCCQCbcCkAAAAAAHzOCwAAAAAAAgACcgYAAAAAAP8AAAAHDoyuAQAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2
].php%3Fen%3Dcp1252,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\default;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=pocahontas+if+i+never+knew+you;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=3911049755233
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\main_2;sz=300x250;mpvid=AARza2HRcvJHpj0e;!c=2;k2=184;k2=617;k3=184;klg=en;kvid=W2uHW1h5uWY;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=W2uHW1h5u
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\main_2;sz=450x60;mpvid=AARza2HRcvJHpj0e;!c=2;k2=184;k2=617;k3=184;klg=en;kvid=W2uHW1h5uWY;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=W2uHW1h5uW
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\main_2;sz=480x70,480x360;mpvid=AARza6Z4w1zIt1i7;!c=2;k2=584;k2=617;k3=584;klg=en;kvid=ljdodmEly6A;ctb=1;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=ljdodmE
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\main_2;sz=480x70;mpvid=AARza5Cb1vshxS96;!c=2;k2=211;k3=211;klg=en;kvid=_EOWfvX2czw;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=_EOWfvX2czw_2;kgg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\main_5703;sz=480x70;mpvid=AARzbGIAgfphbzHA;!c=5703;k2=3;k2=23;k3=3;klg=en;kvid=YRi20cWMYOM;ctb=1;kr=F;kt=K;ko=c;kpid=5703;afc=1;kga=-1;shortform=1;u=YRi20c
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\music_rockpop;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=j+lo+waiting+for+tonight;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=1760630316801
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\1252822631&ga_sid=1252822631&ga_hid=1241134712&ga_fc=0&u_tz=-300&u_his=8&u_java=1&u_h=768&u_w=1024&u_ah=740&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&biw=300&b
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\52820350&ga_sid=1252820350&ga_hid=942050748&ga_fc=0&u_tz=-300&u_his=27&u_java=1&u_h=768&u_w=1024&u_ah=740&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&biw=300&bih
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\booksliterature;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=savage+garden+i+knew+i+loved+you;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=887
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\click2,060qAO2MCQBe2SoAAAAAAMxsDAAAAAAAAgHwAQIAAAAAAP8AAAAHDfgSEAAAAAAA9ngNAAAAAADOlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAA[2].com%2Fbloody_monday%2F82%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAG4AAIAAAAAAAAACAAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F84%2F01%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH4AQIAAAAAAAcABAAHEHe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F31%2F08%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH4AQIAAAAAAAMAAgAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F33%2F03%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\click2,VaUDABDCCQAjGCoAAAAAALgLDAAAAAAAAgAOcg8AAAAAAP8AAAAHDoyuAQAAAAAA6hcRAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2
].php%3Fen%3Dcp1252,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\main_2;sz=300x250;mpvid=AARzbAO1ptvzrNXu;!c=2;k2=211;k3=211;klg=en;kvid=Jdvmw4FRzQ8;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=Jdvmw4FRzQ8_2;kg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\main_2;sz=300x250;mpvid=AARzbaZ8Rpgm-jnR;!c=2;k2=211;k3=211;klg=en;kvid=oqGnsP4wOf0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=oqGnsP4wOf0_2;kg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\main_2;sz=450x60;mpvid=AARzbHogfYeijH0I;!c=2;k2=593;k3=593;klg=en;kvid=j5Cvq416zuQ;ctb=1;kr=F;kt=K;ko=p;kpid=2;afc=1;kga=-1;shortform=1;u=j5Cvq416zuQ_2;kgg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\music_rockpop;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=savage+garden+santa+monica;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=62450298846
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQAGICEAAAAAAHnnCgAAAAAAAgEAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAACGjg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAA[2].com%2Fno_bra%2F2%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQBe2SoAAAAAAM5sDAAAAAAAAgEAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AA[2].com%2F7th_period_is_a_secret%2F3%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEEAAYAAAAAAAkABQAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAA[2].com%2Fno_bra%2F1%2F00-co
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAUAAgAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F33%2F18%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAgH4AQYAAAAAAP8AAAAHEHe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F33%2F13%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQDh8BIAAAAAAN63BQAAAAAAAgA0AQYAAAAAAP8AAAABAfgSEAAAAAAAGEIOAAAAAADLiggAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAgH4AQIAAAAAAP8AAAAHEHe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F33%2F01%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQDKCS0AAAAAAMIhDQAAAAAAAADkAAYAAAAAAAEAAQABAXa2DwAAAAAA6JcSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\main_2;sz=300x60,300x250;mpvid=AARzbHogfYeijH0I;!c=2;k2=593;k3=593;klg=en;kvid=j5Cvq416zuQ;ctb=1;kr=F;kt=K;ko=p;kpid=2;afc=1;kga=-1;shortform=1;u=j5Cvq416z
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\main_2;sz=480x70,480x360;mpvid=AARzbYcYcW0k9V-w;!c=2;k2=211;k3=211;klg=en;kvid=uD7HfOX9i64;kpu=sonybmg;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=uD7HfOX9
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\music_jazzrb;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=i+swear+boyz+2+men+official+video;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=75553
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,060qAO2MCQBe2SoAAAAAAM5sDAAAAAAAAAEAAAIAAAAAAAAAAQAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AA[2].com%2F7th_period_is_a_secret%2F3%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAgEAAAYAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AA[2].com%2F7th_period_is_a_secret%2F1%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAEoAAYAAAAAAAgACgAHDXe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F83%2F07%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAGMAAYAAAAAAAgACwAHDXe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F83%2F18-19%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,060qAO2MCQCHjRkAAAAAADY2BgAAAAAAAgD4AQYAAAAAAP8AAAAHEPgSEAAAAAAA9ngNAAAAAABcSQkAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAA[2].com%2Fgintama%2F34%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,RwQAAMqTCQD9-CoAAAAAAM2ZCgAAAAAAAgAAAAYAAAAAAP8AAAAHDHe2DwAAAAAAzRsDAAAAAABdHQ8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F80%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,VaUDABDCCQAjGCoAAAAAALgLDAAAAAAAAgAGcg8AAAAAAP8AAAAHFoyuAQAAAAAA6hcRAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2
].php%3Fen%3Dcp1252,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,VaUDABDCCQDivSwAAAAAAP3DDAAAAAAAAgAKcg8AAAAAAP8AAAAHDoyuAQAAAAAADRISAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACwJAIAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\main_2;sz=300x60,300x250;mpvid=AARzbIqhklLpg1Q8;!c=2;k2=618;k3=618;klg=en;kvid=1nV_p6cvr2A;ctb=1;kr=F;khd=0;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=1nV_p6cv
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\main_2;sz=480x70,480x360;mpvid=AARzbBPWz9fDIPli;!c=2;k2=35;k3=35;klg=en;kvid=APnO_I4idsY;ctb=1;kr=F;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=APnO_I4idsY_2;kg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\main_2;sz=480x70;mpvid=AARza3NwqFsWxDrN;!c=2;k2=211;k3=211;klg=en;kvid=9I9hVzqTbn0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;k1=rock;u=9I9hVzqTbn0_2;kgg=-1;
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\main_2;sz=480x70;mpvid=AARzbZa60_ywl0tx;!c=2;k2=211;k3=211;klg=en;kvid=oqGnsP4wOf0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=oqGnsP4wOf0_2;kgg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\main_9440;sz=300x250;mpvid=AARzbaSST1aBdfx7;!c=9440;k2=184;k2=507;k3=184;klg=en;kvid=-37F6MmAYD4;kpu=LittleMissSunshine87;kr=F;kt=K;ko=c;kpid=9440;afc=1;kg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXI74TQB\click2,060qAO2MCQDh8BIAAAAAAN63BQAAAAAAAABEAQYAAAAAAAcAAQABAfgSEAAAAAAAGEIOAAAAAADLiggAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXI74TQB\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH4AQIAAAAAAAIABQAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F31%2F12%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXI74TQB\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAgH4AQIAAAAAAP8AAAAHD3e2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F30%2F08%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXI74TQB\click2,VaUDABDCCQCXGCkAAAAAAJoCDAAAAAAAAgEWcg8AAAAAAP8AAAAHDoyuAQAAAAAAfAwRAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2
].php%3Fen%3Dcp1252,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXI74TQB\main_2;sz=450x60;mpvid=AARza5Cb1vshxS96;!c=2;k2=211;k3=211;klg=en;kvid=_EOWfvX2czw;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=_EOWfvX2czw_2;kgg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXI74TQB\main_2;sz=480x70;mpvid=AARzbqbF2fYfzT4t;!c=2;k2=211;k3=211;klg=en;kvid=Uhdajt0C1sE;ctb=1;kr=A;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=Uhdajt0C1sE_2;kgg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXI74TQB\music;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=savage+garden+truly+madly+deeply;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=9597733392601
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\OPQRGHER\click2,060qAO2MCQBkoCgAAAAAAHnnCgAAAAAAAgHcAAIAAAAAAP8AAAAHDfgSEAAAAAAA9ngNAAAAAACGjg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAA[2].com%2Fbloody_monday%2F84%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\OPQRGHER\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAYABAAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AA[2].com%2F7th_period_is_a_secret%2F3%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\OPQRGHER\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAUABgAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F35%2F15%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\OPQRGHER\click2,060qAO2MCQD1WCkAAAAAAMzyCwAAAAAAAgCsAAIAAAAAAP8AAAAHDdL5DgAAAAAAiYILAAAAAADk9xAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\OPQRGHER\ethnicidentitygroups_indigenouspeoples;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=pocahontas+colors+of+the+wind;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\OPQRGHER\main_2;sz=300x250;mpvid=AARza5Cb1vshxS96;!c=2;k2=211;k3=211;klg=en;kvid=_EOWfvX2czw;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=_EOWfvX2czw_2;kg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\OPQRGHER\main_5703;sz=450x60;mpvid=AARzbGIAgfphbzHA;!c=5703;k2=3;k2=23;k3=3;klg=en;kvid=YRi20cWMYOM;ctb=1;kr=F;kt=K;ko=c;kpid=5703;afc=1;kga=-1;shortform=1;u=YRi20c
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQBEixkAAAAAADY2BgAAAAAAAgAAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAABcSQkAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AA[2].com%2F7th_period_is_a_secret%2F2%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAUABgAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAA[2].com%2Fno_bra%2F1%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAYAAQAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AA[2].com%2F7th_period_is_a_secret%2F2%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAGkAAYAAAAAAAEACwAHDXe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F83%2Fcredits%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAYACAAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F30%2F18%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAHcAQYAAAAAAAMABAAHD3e2DwAAAAAAyccQAAAAAAAAAAAAAAAA[2].com%2Fkaichou_wa_maid-sama%2F41%2F04%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQDDOC0AAAAAAHPiDAAAAAAAAgH4AQIAAAAAAP8AAAAHEHa2DwAAAAAAjjsSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQDKCS0AAAAAAMIhDQAAAAAAAADsAAYAAAAAAAAAAgABAXe2DwAAAAAA6JcSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,Bi4DAFheCgDK8ScAAAAAAH-JCwAAAAAAAgEsAAIAAAAAAP8AAAABASndEQAAAAAA7wAOAAAAAADKahAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPSgU
AAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\main_2;sz=480x70;mpvid=AARzbWi9jfofJKb7;!c=2;k2=35;k2=299;k3=35;klg=en;kvid=sjbDuXZ8gTo;ctb=1;kr=A;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=sjbDuXZ8gTo_
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAG8AQYAAAAAAAsAAgAHD3a2DwAAAAAAyccQAAAAAAAAA[2].com%2Fkaichou_wa_maid-sama%2F41%2F00-cover3%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAcACQAHEHe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F32%2F15%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\click2,060qAO2MCQDh8BIAAAAAAN63BQAAAAAAAgB0AQYAAAAAAP8AAAAHDfgSEAAAAAAAGEIOAAAAAADLiggAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAGsAQIAAAAAAAIABAAHDXe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F82%2F14%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH4AQIAAAAAAAMABgAHEHe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F31%2F18%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAgHoAAIAAAAAAP8AAAAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F81%2F11%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\default;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=beauty+and+the+beast+celine+dion;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=77610877460
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\main_2;sz=450x60;mpvid=AARzbXu50EmUJgRF;!c=2;k2=617;k3=617;klg=en;kvid=WZiQdM7ih5Q;ctb=1;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=WZiQdM7ih5Q_2;kgg=-1;k
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\main_9440;sz=450x60;mpvid=AARzbaSST1aBdfx7;!c=9440;k2=184;k2=507;k3=184;klg=en;kvid=-37F6MmAYD4;kpu=LittleMissSunshine87;kr=F;kt=K;ko=c;kpid=9440;afc=1;kga
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAEoAQYAAAAAAAUACQAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F81%2F20%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAFQAAYAAAAAAA8ACAAHDHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F80%2F14%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAQACAAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F31%2F05%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\click2,060qAO2MCQDUOhkAAAAAAHnnCgAAAAAAAgEAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAACGjg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AA[2].com%2F7th_period_is_a_secret%2F1%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\click2,060qAPCMCQAO-SoAAAAAAM2ZCgAAAAAAAgBwAQoAAAAAAP8AAAAHDvgSEAAAAAAAElUNAAAAAABdHQ8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AA[2].com%2Frec
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\click2,VaUDABDCCQAjGCoAAAAAALgLDAAAAAAAAAAecg8AAAAAAAoAAgAHD4yuAQAAAAAA6hcRAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2
].php%3Fen%3Dcp1252,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\click2,VaUDABPCCQCbcCkAAAAAAHzOCwAAAAAAAAAOcgYAAAAAAAYAAgAHDoyuAQAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2
].php%3Fen%3Dcp1252,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\main_2;sz=450x60;mpvid=AARzbAO1ptvzrNXu;!c=2;k2=211;k3=211;klg=en;kvid=Jdvmw4FRzQ8;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=Jdvmw4FRzQ8_2;kgg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\main_2;sz=450x60;mpvid=AARzbqbF2fYfzT4t;!c=2;k2=211;k3=211;klg=en;kvid=Uhdajt0C1sE;ctb=1;kr=A;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=Uhdajt0C1sE_2;kgg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\music_rockpop;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=savage+garden+santa+monica;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=41555346255
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\W9AFCXQ7\click2,060qAO2MCQA1SysAAAAAAOmDDAAAAAAAAgEAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAAAquBEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAA[2].com%2Fzero_in%2F30%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\W9AFCXQ7\click2,060qAO2MCQBe2SoAAAAAAM5sDAAAAAAAAAEAAAIAAAAAAAUAAgAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AA[2].com%2F7th_period_is_a_secret%2F3%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\W9AFCXQ7\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAMABQAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AA[2].com%2F7th_period_is_a_secret%2F3%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\W9AFCXQ7\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAYABwAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAA[2].com%2Fno_bra%2F2%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\W9AFCXQ7\click2,060qAOuMCQBPBC0AAAAAAOrIDAAAAAAAAgEAAAoAAAAAAP8AAAAHFPgSEAAAAAAAGEIOAAAAAAAvGRIAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACg1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\W9AFCXQ7\main_2;sz=300x250;mpvid=AARzbqbF2fYfzT4t;!c=2;k2=211;k3=211;klg=en;kvid=Uhdajt0C1sE;ctb=1;kr=A;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=Uhdajt0C1sE_2;kg
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQBISysAAAAAAOmDDAAAAAAAAgH4AQYAAAAAAP8AAAAHEPgSEAAAAAAA9ngNAAAAAAAquBEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAA[2].com%2Fgintama%2F36%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQBmZSoAAAAAAHkvDAAAAAAAAgD4AQYAAAAAAP8AAAAHEPgSEAAAAAAA9ngNAAAAAADxQxEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAA[2].com%2Fgintama%2F34%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAAAAwAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AA[2].com%2F7th_period_is_a_secret%2F2%2
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAcABgAHD3e2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F30%2F06%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAHQAAYAAAAAAAYACQAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F81%2F09%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQDDOC0AAAAAAHPiDAAAAAAAAgH4AQIAAAAAAP8AAAAHE3e2DwAAAAAAjjsSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAGsAAIAAAAAAAEACAAHDXe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F83%2Fcredits%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAGYAQIAAAAAAAcAAgAHDXe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F82%2F12%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAOuMCQCtYyoAAAAAABeyCwAAAAAAAgCUAAoAAAAAAP8AAAABAXe2DwAAAAAAOKEQAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fdirectory%2Ffantasy%2F,;dcopt=rcl;mtfIFPath
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,VaUDABDCCQAk3x0AAAAAAHqYCQAAAAAAAgACcg8AAAAAAP8AAAAHDoyuAQAAAAAAL7sNAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAA[1].php%3Fen%3D
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\default;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=beauty+and+the+beast+celine+dion;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=75066161379
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\main_2;sz=300x250;mpvid=AARzbWi9jfofJKb7;!c=2;k2=35;k2=299;k3=35;klg=en;kvid=sjbDuXZ8gTo;ctb=1;kr=A;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=sjbDuXZ8gTo
Status: Hidden

Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\main_2;sz=300x60,300x250;mpvid=AARzbXu50EmUJgRF;!c=2;k2=617;k3=617;klg=en;kvid=WZiQdM7ih5Q;ctb=1;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=WZiQdM7ih5Q_2;
Status: Hidden

Object: C:\Documents and Settings\TuongVy\My Documents\Music\hai kich\Hai Kich 2\Hŕi K?ch Ngŕy Xuân Vui Cu?i - Hoŕi Linh.MP3
Status: Hidden

Object: C:\Documents and Settings\TuongVy\My Documents\Music\hai kich\Hŕi K?ch - Ngŕy Xuân Vui Cu?i - Hoŕi Linh.MP3
Status: Hidden


From the AVZ4 History
9/18/2009 7:14:29 PM: System Analysis with MRM enabled was run successfully
9/18/2009 7:31:13 PM: AVZPM is active
9/18/2009 7:34:28 PM: System Analysis was run successfully

From OLT file
OTL logfile created on: 9/18/2009 7:47:48 PM - Run 1
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\TuongVy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

254.00 Mb Total Physical Memory | 103.18 Mb Available Physical Memory | 40.62% Memory free
1002.93 Mb Paging File | 770.68 Mb Available in Paging File | 76.84% Paging File free
Paging file location(s): C:\pagefile.sys 762 1000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 10.15 Gb Free Space | 26.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D7SDGB31
Current User Name: TuongVy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\System32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\System32\CTsvcCDA.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
PRC - C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe (Dell Computer Corporation)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Dell AIO Printer A940\dlbabmon.exe (Dell Computer Corporation)
PRC - C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe (Creative Technology Ltd)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
PRC - C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe (Panicware, Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe (Musicmatch, Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe (Musicmatch, Inc.)
PRC - C:\Documents and Settings\TuongVy\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (auguamcv [Auto | Running]) -- C:\WINDOWS\System32\ojxhfcz.dll ()
SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (Creative Service for CDROM Access [Auto | Running]) -- C:\WINDOWS\System32\CTsvcCDA.exe (Creative Technology Ltd)
SRV - (getPlus® Helper [On_Demand | Stopped]) -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (ICDSPTSV [On_Demand | Stopped]) -- C:\WINDOWS\System32\IcdSptSv.exe (Sony Corporation)
SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (LexBceS [Auto | Running]) -- C:\WINDOWS\System32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (ProtectedStorage [Auto | Stopped]) -- File not found
SRV - (UMWdf [Auto | Running]) -- C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Running]) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ATMhelpr [System | Running]) -- C:\WINDOWS\System32\drivers\ATMHELPR.SYS (Adobe Systems Incorporated)
DRV - (bcm4sbxp [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (bvrp_pci [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\bvrp_pci.sys ()
DRV - (Cdr4_xp [System | Running]) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (Cdralw2k [System | Running]) -- C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (cdudf_xp [System | Running]) -- C:\WINDOWS\System32\drivers\cdudf_xp.sys (Roxio)
DRV - (CmdIde [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DCamUSBVeo532 [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\ubVeo532.sys (IC Media Corporation)
DRV - (dvd_2K [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\Dvd_2k.sys (Roxio)
DRV - (EL90XBC [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\el90xbc5.sys (3Com Corporation)
DRV - (epstw2k [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\epstw2k.sys (Microsoft Corporation)
DRV - (gameenum [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (hamachi [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\hamachi.sys (Applied Networking Inc.)
DRV - (HSFHWBS2 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys (Conexant Systems)
DRV - (HSF_DP [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_DP.sys (Conexant Systems)
DRV - (i81x [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wADV01nt.sys (Intel® Corporation)
DRV - (iAimFP1 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wADV02NT.sys (Intel® Corporation)
DRV - (iAimFP2 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wADV05NT.sys (Intel® Corporation)
DRV - (iAimFP3 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys (Intel® Corporation)
DRV - (iAimFP4 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys (Intel® Corporation)
DRV - (iAimTV0 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wATV01nt.sys (Intel® Corporation)
DRV - (iAimTV1 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wATV02NT.sys (Intel® Corporation)
DRV - (iAimTV3 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wATV04nt.sys (Intel® Corporation)
DRV - (iAimTV4 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys (Intel® Corporation)
DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (lpjoofsn [Boot | Running]) -- C:\WINDOWS\system32\drivers\lpjoofsn.sys (Intel® Corporation)
DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mmc_2K [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\Mmc_2k.sys (Roxio)
DRV - (mraid35x [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (MxlW2k [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (NPPTNT2 [On_Demand | Stopped]) -- C:\WINDOWS\System32\npptNT2.sys (INCA Internet Co., Ltd.)
DRV - (nv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) -- C:\WINDOWS\System32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (P16X [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\P16X.sys (Creative Technology Ltd.)
DRV - (PCTINDIS5 [On_Demand | Stopped]) -- C:\WINDOWS\System32\PCTINDIS5.SYS (PCTEL Inc.)
DRV - (PfModNT [Auto | Running]) -- C:\WINDOWS\System32\PfModNT.sys (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (pwd_2k [System | Running]) -- C:\WINDOWS\System32\drivers\pwd_2K.sys (Roxio)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (SbcpHid [Auto | Running]) -- C:\WINDOWS\System32\Drivers\SbcpHid.sys ()
DRV - (scsiscan [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\scsiscan.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (slabbus [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\slabbus.sys (MCCI)
DRV - (slabser [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\slabser.sys (MCCI)
DRV - (Sparrow [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (symc810 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (SysProtDrv.sys [On_Demand | Stopped]) -- C:\Documents and Settings\TuongVy\Desktop\SysProt\SysProt\SysProtDrv.sys ()
DRV - (UdfReadr_xp [System | Running]) -- C:\WINDOWS\System32\drivers\udfreadr_xp.sys (Roxio)
DRV - (ultra [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (USBMSD [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\USBMSD.SYS (Generic)
DRV - (uzi0odaz [System | Running]) -- C:\WINDOWS\System32\Drivers\uzi0odaz.sys ()
DRV - (w550bus [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\w550bus.sys (MCCI)
DRV - (w550mdfl [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\w550mdfl.sys (MCCI)
DRV - (w550mdm [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\w550mdm.sys (MCCI)
DRV - (w550mgmt [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\w550mgmt.sys (MCCI)
DRV - (w550obex [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\w550obex.sys (MCCI)
DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default = CE 89 47 DF 36 72 B7 40 BF 6C D1 0F 8F 35 36 04 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 14 7B F9 01 66 A0 FA 42 80 B9 5F 11 2A 42 37 43 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\System32\shdocvw.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {736fca60-00ae-431c-93b9-f4c01470e8cc}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/08 17:37:58 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/30 09:19:48 | 00,000,000 | ---D | M]

[2009/04/12 10:29:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\mozilla\Extensions
[2009/01/13 15:52:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/12 10:29:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\mozilla\Extensions\mozswing@mozswing.org
[2009/09/17 17:03:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\mozilla\Firefox\Profiles\2e2g8oi8.default\extensions
[2009/09/18 19:41:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\mozilla\Firefox\Profiles\2e2g8oi8.default\extensions\{736fca60-00ae-431c-93b9-f4c01470e8cc}
[2009/09/17 17:03:08 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/08/30 09:19:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/02/06 15:26:19 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/03/09 11:08:17 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2009/08/30 09:19:13 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/30 09:19:14 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/06/18 01:43:04 | 00,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2006/01/12 17:28:26 | 00,086,016 | ---- | M] (DivX, Inc) -- C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2005/11/10 19:21:00 | 01,499,136 | ---- | M] (LizardTech) -- C:\Program Files\mozilla firefox\plugins\npdjvu.dll
[2009/08/30 09:19:31 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/04/30 07:15:11 | 00,239,432 | ---- | M] (Pando Networks) -- C:\Program Files\mozilla firefox\plugins\npPandoWebInst.dll
[2009/02/18 10:56:23 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/02/18 10:56:24 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/02/18 10:56:25 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/02/18 10:56:25 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/02/18 10:56:26 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/02/18 10:56:27 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/02/18 10:56:27 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2007/11/20 16:52:00 | 02,884,992 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\NPSWF32.dll
[2007/04/16 12:07:12 | 00,180,293 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2009/08/30 09:19:37 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/08/30 09:19:37 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/08/30 09:19:37 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/30 09:19:37 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/08/30 09:19:37 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/30 09:19:37 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/08/30 09:19:37 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (224 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: ??????????????? browser-security.microsoft.com
O1 - Hosts: ??????????????? spywareprotector-2009.com
O1 - Hosts: ??????????????? www.spywareprotector-2009.com
O1 - Hosts: ??????????????? secure.spywareprotector-2009.com
O2 - BHO: (no name) - {01F97B14-A066-42FA-80B9-5F112A423743} - C:\WINDOWS\System32\ablvzzxf.dll ()
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: () - {2EB5C6DF-DBF6-4E3F-A81A-FABABBCB693B} - C:\WINDOWS\System32\ojxhfcz.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Dell AIO Printer A940] C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe (Dell Computer Corporation)
O4 - HKLM..\Run: [diagent] C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [hpppt] File not found
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKCU..\Run: [Aim6] File not found
O4 - HKCU..\Run: [PopUpStopperFreeEdition] C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe (Panicware, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: &AIM Search - Reg Error: Value error. File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: imageservr.com ([]* in Trusted sites)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKLM\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/...lscbase9563.cab (Windows Live Safety Center Base Module)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo...otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1173831454421 (MUWebControl Class)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} http://a840.g.akamai.net/7/840/537/2004033...all/xscan53.cab (HouseCall Control)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://www.nick.com/common/groove/gx/GrooveAX27.cab (Groove Control)
O16 - DPF: {8646A6AF-0AE4-4BF8-B716-DB1513803972} http://riteaid.storefront.com/images/globa...geUpload1_8.CAB (SFImageUpload1_8.ImageUpload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/...tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} http://www.imgag.com/cp/install/Crusher.cab (Creative Toolbox Plug-in)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} https://disney.go.com/games/downloads/gamem...GameManager.cab (CGameManagerCtrl Object)
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} https://www-secure.symantec.com/techsupp/ac...ta/SymAData.dll (ActiveDataInfo Class)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p...obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} https://www-secure.symantec.com/techsupp/ac.../ActiveData.cab (ActiveDataObj Class)
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} http://liveca04.rightnowtech.com/7020-b369...l/java/RntX.cab (Live Collaboration)
O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} http://apps.corel.com/nos_dl_manager/plugi...NetOpPlugin.ocx (Get_ActiveX Control)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Go http://download.games.yahoo.com/games/clients/y/gt2_x.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\System32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\System32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - AppInit_DLLs: (karna.datS\System3) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\bbddqbke: DllName - ojxhfcz.dll - C:\WINDOWS\System32\ojxhfcz.dll ()
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\System32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\mljigfg: DllName - mljigfg.dll - File not found
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\WlNotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\System32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\System32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\System32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 13:36:02 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{1418bd52-13bb-11dc-866a-000bdbb6960d}\Shell - "" = AutoRun
O33 - MountPoints2\{1418bd52-13bb-11dc-866a-000bdbb6960d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1418bd52-13bb-11dc-866a-000bdbb6960d}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
O33 - MountPoints2\{eb0477f2-215f-11dd-882b-000bdbb6960d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{eb0477f2-215f-11dd-882b-000bdbb6960d}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\Shell32.DLL -- [2008/06/17 14:02:19 | 08,461,312 | ---- | M] (Microsoft Corporation)
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[9 C:\Documents and Settings\TuongVy\Desktop\*.tmp files]
[2009/09/18 19:14:29 | 00,011,264 | ---- | C] () -- C:\WINDOWS\System32\drivers\uzi0odaz.sys
[2009/09/18 18:53:53 | 00,037,376 | ---- | C] () -- C:\Documents and Settings\TuongVy\Desktop\trojan remove.doc
[2009/09/18 18:52:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TuongVy\Desktop\avz4
[2009/09/18 18:52:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TuongVy\Desktop\SysProt
[2009/09/18 18:48:23 | 00,514,560 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\TuongVy\Desktop\OTL.exe
[2009/09/18 18:14:32 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\TuongVy\Desktop\HijackThis.lnk
[2009/09/18 18:14:32 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/09/18 01:11:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TuongVy\Local Settings\Application Data\kfogetgj
[2009/09/18 01:11:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TuongVy\Application Data\kfogetgj
[2009/09/09 21:17:22 | 00,001,986 | ---- | C] () -- C:\Documents and Settings\TuongVy\My Documents\ROFLMAO.html
[2009/08/29 08:26:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TuongVy\My Documents\My Library
[2009/08/29 08:26:43 | 00,001,552 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Reader.lnk
[2009/08/29 08:26:14 | 00,057,436 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\DASShp.dll
[2009/08/29 08:26:14 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Reader
[2009/08/28 21:41:06 | 00,000,000 | -HSD | C] -- C:\found.005
[2009/03/08 22:10:30 | 00,595,160 | ---- | C] () -- C:\WINDOWS\System32\wodCertificate.dll
[2009/03/08 22:10:25 | 00,589,960 | ---- | C] () -- C:\WINDOWS\System32\brgrt.dll
[2008/12/12 03:08:52 | 00,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2007/08/20 19:26:52 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2007/08/20 19:26:52 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2007/05/24 13:23:22 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007/05/16 21:41:03 | 01,458,950 | -HS- | C] () -- C:\WINDOWS\System32\eaqmsnqr.ini
[2007/01/31 13:20:15 | 00,000,168 | RHS- | C] () -- C:\WINDOWS\System32\A228C0DDBC.sys
[2007/01/23 15:20:21 | 00,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2006/11/16 03:07:17 | 00,000,000 | ---- | C] () -- C:\WINDOWS\DVEdit.INI
[2006/11/16 03:02:59 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\dsp_trc.dll
[2006/11/16 03:02:59 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\IcdSptSvps.dll
[2006/03/18 15:42:04 | 00,000,012 | ---- | C] () -- C:\WINDOWS\dirsaver.ini
[2006/03/18 15:41:30 | 00,028,672 | ---- | C] () -- C:\WINDOWS\gscr.dll
[2006/02/12 13:23:04 | 00,000,061 | ---- | C] () -- C:\WINDOWS\einit.ini
[2006/02/04 02:12:49 | 00,000,032 | ---- | C] () -- C:\WINDOWS\AMPlayer.INI
[2006/02/02 21:12:21 | 00,000,056 | ---- | C] () -- C:\WINDOWS\System32\BCDDC028A2.sys
[2006/01/30 19:18:46 | 00,000,192 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2006/01/30 11:03:45 | 00,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/01/30 09:44:15 | 00,000,061 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/01/24 13:08:29 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2005/12/09 21:29:36 | 00,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2005/10/04 20:39:37 | 00,000,000 | ---- | C] () -- C:\WINDOWS\server32.INI
[2005/10/04 20:28:21 | 00,000,026 | ---- | C] () -- C:\WINDOWS\chscg.ini
[2005/08/12 16:57:09 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/05/15 10:27:21 | 00,000,650 | ---- | C] () -- C:\WINDOWS\DELLSTAT.INI
[2005/03/29 22:56:29 | 00,000,074 | ---- | C] () -- C:\WINDOWS\hpsjbmgr.ini
[2005/03/29 22:39:47 | 00,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
[2005/03/29 07:08:46 | 00,000,021 | ---- | C] () -- C:\WINDOWS\THUMBV~1.INI
[2005/03/29 06:47:18 | 00,000,458 | ---- | C] () -- C:\WINDOWS\icompose.INI
[2005/03/29 06:43:04 | 00,000,140 | ---- | C] () -- C:\WINDOWS\VWORK32.INI
[2004/08/05 18:02:21 | 00,000,073 | ---- | C] () -- C:\WINDOWS\PUZZLES.INI
[2004/07/29 10:47:10 | 00,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2004/06/16 19:14:10 | 00,000,019 | ---- | C] () -- C:\WINDOWS\KNP.INI
[2004/06/15 22:08:25 | 00,001,251 | ---- | C] () -- C:\WINDOWS\Things.ini
[2004/05/05 16:40:23 | 00,000,040 | ---- | C] () -- C:\WINDOWS\TSC.INI
[2004/05/05 16:36:55 | 00,000,170 | ---- | C] () -- C:\WINDOWS\GetServer.ini
[2004/02/29 22:03:57 | 00,004,239 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2004/02/22 11:33:52 | 00,000,018 | ---- | C] () -- C:\WINDOWS\Epson777.ini
[2004/02/07 21:54:53 | 00,002,397 | ---- | C] () -- C:\WINDOWS\System32\drivers\symlcbrd.sys
[2004/01/18 00:00:15 | 00,004,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2004/01/05 00:24:27 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\VeoSetup532.dll
[2004/01/05 00:24:26 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\Veo532ut.dll
[2003/12/21 07:38:57 | 00,004,094 | ---- | C] () -- C:\WINDOWS\System32\rtcsses.dll
[2003/12/21 07:38:57 | 00,004,094 | ---- | C] () -- C:\WINDOWS\System32\dimces.dll
[2003/12/15 08:42:41 | 00,000,035 | ---- | C] () -- C:\WINDOWS\ERegClnt.INI
[2003/08/24 16:05:57 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2003/08/24 15:57:28 | 00,000,784 | ---- | C] () -- C:\WINDOWS\lrun32.ini
[2003/08/24 15:55:37 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003/08/24 15:51:38 | 00,000,231 | ---- | C] () -- C:\WINDOWS\AC3API.INI
[2003/08/24 15:51:08 | 00,039,936 | ---- | C] () -- C:\WINDOWS\System32\P16X.dll
[2003/08/24 15:51:08 | 00,002,092 | ---- | C] () -- C:\WINDOWS\System32\P16X.ini
[2003/08/24 15:51:08 | 00,000,026 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2003/08/24 15:51:07 | 00,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\A3d.dll
[2003/08/24 15:51:07 | 00,006,175 | ---- | C] () -- C:\WINDOWS\MIXDEF.INI
[2003/08/24 15:51:07 | 00,005,917 | ---- | C] () -- C:\WINDOWS\SBMIXDEF.INI
[2003/08/24 15:51:07 | 00,000,064 | ---- | C] () -- C:\WINDOWS\P16x.ini
[2003/08/24 15:50:21 | 00,000,245 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2003/08/24 15:44:39 | 00,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2003/08/24 15:22:53 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/08/24 15:04:14 | 00,000,550 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2003/02/17 17:00:42 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbavs.dll
[2003/02/17 17:00:36 | 00,000,177 | ---- | C] () -- C:\WINDOWS\System32\dlbacoin.ini
[2003/02/05 11:11:12 | 00,000,126 | ---- | C] () -- C:\WINDOWS\System32\DLBAPLC.INI
[2002/11/01 16:17:50 | 00,000,256 | ---- | C] () -- C:\WINDOWS\aucfg.ini
[2002/09/03 13:36:02 | 00,000,784 | ---- | C] () -- C:\WINDOWS\WIN.INI
[2002/09/03 13:26:32 | 00,000,292 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI
[2002/08/29 05:00:00 | 00,147,968 | ---- | C] () -- C:\WINDOWS\System32\lvmcyiat.dll
[2002/08/29 05:00:00 | 00,147,968 | ---- | C] () -- C:\WINDOWS\System32\ablvzzxf.dll
[2002/08/29 05:00:00 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\ojxhfcz.dll
[2002/08/29 05:00:00 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\euqdegy.dll
[2002/07/04 15:05:34 | 00,000,269 | ---- | C] () -- C:\WINDOWS\tmupdate.ini
[2001/12/14 13:34:46 | 00,164,864 | ---- | C] () -- C:\WINDOWS\patchw32.dll
[2001/04/23 13:00:44 | 00,037,408 | ---- | C] () -- C:\WINDOWS\System32\drivers\SbcpHid.sys

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[9 C:\Documents and Settings\TuongVy\Desktop\*.tmp files]
[2009/09/18 19:39:28 | 00,001,170 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2009/09/18 19:36:21 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/09/18 19:36:17 | 00,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2009/09/18 19:36:14 | 26,640,7936 | -HS- | M] () -- C:\hiberfil.sys
[2009/09/18 19:14:29 | 00,011,264 | ---- | M] () -- C:\WINDOWS\System32\drivers\uzi0odaz.sys
[2009/09/18 18:53:54 | 00,037,376 | ---- | M] () -- C:\Documents and Settings\TuongVy\Desktop\trojan remove.doc
[2009/09/18 18:48:27 | 00,514,560 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\TuongVy\Desktop\OTL.exe
[2009/09/18 18:14:33 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\TuongVy\Desktop\HijackThis.lnk
[2009/09/18 15:00:07 | 00,000,412 | ---- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for TuongVy.job
[2009/09/18 13:37:13 | 00,000,434 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2009/09/18 07:00:32 | 00,000,650 | ---- | M] () -- C:\WINDOWS\DELLSTAT.INI
[2009/09/16 05:20:32 | 00,131,304 | ---- | M] () -- C:\Documents and Settings\TuongVy\Application Data\GDIPFONTCACHEV1.DAT
[2009/09/14 20:19:39 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/09/10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/09/10 14:53:50 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/09/09 21:17:22 | 00,001,986 | ---- | M] () -- C:\Documents and Settings\TuongVy\My Documents\ROFLMAO.html
[2009/08/29 10:20:10 | 00,508,688 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/29 08:26:43 | 00,001,552 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Reader.lnk
[2009/08/28 16:38:20 | 24,689,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe

========== LOP Check ==========

[2009/08/10 11:22:09 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/05/15 01:01:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/01/11 11:28:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avg7
[2006/02/27 02:22:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2005/05/29 09:03:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Dell
[2006/01/29 20:40:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Motive
[2006/01/29 20:42:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSN6
[2008/12/18 18:39:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2004/07/27 14:49:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2003/08/24 15:46:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI
[2006/07/05 20:06:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Teleca
[2008/11/25 19:42:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2004/09/23 16:37:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia
[2008/04/29 16:22:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/09/18 01:11:32 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\TuongVy\Application Data
[2007/01/23 15:27:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\acccore
[2007/01/23 15:36:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Aim
[2007/04/29 09:25:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Chessmaster Challenge
[2006/02/02 21:06:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Corel
[2007/12/12 17:16:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\dvdcss
[2009/03/31 20:57:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Hamachi
[2003/12/16 06:17:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Jasc
[2009/09/18 01:11:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\kfogetgj
[2006/08/27 17:25:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Leadertech
[2009/01/23 17:42:09 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\TuongVy\Application Data\Move Networks
[2004/10/19 22:12:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\MSN6
[2006/01/29 20:49:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\MSNInstaller
[2006/01/30 20:10:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Musicmatch
[2008/03/10 14:09:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Nexon
[2006/04/29 10:12:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Opera
[2007/08/14 20:36:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Printer Info Cache
[2004/01/11 16:01:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Roxio
[2006/07/05 20:13:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Teleca
[2009/06/17 10:53:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Tutor
[2009/09/06 04:00:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\U3
[2007/01/13 18:44:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Viewpoint
[2005/12/07 00:41:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\WeatherBug
[2008/01/19 01:24:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Winff
[2009/09/14 20:19:39 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/09/18 13:37:13 | 00,000,434 | ---- | M] () -- C:\WINDOWS\Tasks\At1.job
[2002/08/29 05:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\DESKTOP.INI
[2009/09/18 15:00:07 | 00,000,412 | ---- | M] () -- C:\WINDOWS\Tasks\Norton Security Scan for TuongVy.job
[2009/09/18 19:36:21 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >

OTL Extras logfile created on: 9/18/2009 7:47:48 PM - Run 1
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\TuongVy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

254.00 Mb Total Physical Memory | 103.18 Mb Available Physical Memory | 40.62% Memory free
1002.93 Mb Paging File | 770.68 Mb Available in Paging File | 76.84% Paging File free
Paging file location(s): C:\pagefile.sys 762 1000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 10.15 Gb Free Space | 26.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D7SDGB31
Current User Name: TuongVy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.hta [@ = htafile] -- Reg Error: Key error. File not found
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htafile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" "%1" (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" "%1" (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" "%1" (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"57983:TCP" = 57983:TCP:*:Enabled:Pando Media Booster
"57983:UDP" = 57983:UDP:*:Enabled:Pando Media Booster
"57658:TCP" = 57658:TCP:*:Enabled:Pando Media Booster
"57658:UDP" = 57658:UDP:*:Enabled:Pando Media Booster

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\Yahoo!\Messenger\YPager.exe" = C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Disabled:Yahoo! Messenger -- File not found
"C:\Program Files\Internet Explorer\iexplore.exe" = C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer -- (Microsoft Corporation)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC)
"C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC -- (mIRC Co. Ltd.)
"C:\Program Files\YVD\n00b-IRC.exe" = C:\Program Files\YVD\n00b-IRC.exe:*:Disabled:n00b-IRC -- File not found
"C:\Program Files\YVD\YGO Virtual Desktop V086.exe" = C:\Program Files\YVD\YGO Virtual Desktop V086.exe:*:Enabled:YGO Virtual Desktop Executable -- File not found
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Program Files\BitLord\BitLord.exe" = C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord -- (www.BitLord.com)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\WINDOWS\SYSTEM32\fxsclnt.exe" = C:\WINDOWS\SYSTEM32\fxsclnt.exe:*:Enabled:Microsoft Fax Console -- (Microsoft Corporation)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM -- (AOL LLC)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Grisoft\MapleStory.exe" = C:\Program Files\Grisoft\MapleStory.exe:*:Disabled:MapleStory -- File not found
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player -- ()
"C:\Program Files\Common Files\aol\Loader\aolload.exe" = C:\Program Files\Common Files\aol\Loader\aolload.exe:*:Enabled:AOL Loader -- (AOL LLC)
"C:\WINDOWS\SYSTEM32\DRIVERS\svchost.exe" = C:\WINDOWS\SYSTEM32\DRIVERS\svchost.exe:*:Disabled:Vvjbjmor Ewetyty -- File not found
"C:\Program Files\Yugioh Virtual Dueling\Yugioh Virtual Desktop 9.exe" = C:\Program Files\Yugioh Virtual Dueling\Yugioh Virtual Desktop 9.exe:*:Enabled:YGO Virtual Desktop Executable -- File not found
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- File not found
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program Files\USMLE\2009FredV2Step1\FredV2Orient.exe" = C:\Program Files\USMLE\2009FredV2Step1\FredV2Orient.exe:*:Enabled:FredV2Orient -- ()
"C:\Program Files\USMLE\2009FredV2Step1\NED.exe" = C:\Program Files\USMLE\2009FredV2Step1\NED.exe:*:Enabled:NBME Exam Driver -- (NBME)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{099B096F-A916-4ECE-8EF2-A6E5F7C4D113}" = Veo Connect
"{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = Lizardtech DjVu Control
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert
"{15CCBC5D-66A7-4131-8D36-E05F27B0E68F}" = Sibelius Scorch (ActiveX Only)
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{25EF00BE-F17B-11D6-88EA-000476CD2443}" = Verizon Online
"{29FA18EE-BDA4-40DF-99A5-42A7D8CF6746}" = FRED
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{4468EF97-A253-4699-9E1C-88CAE2C6832D}" = ABBYY FineReader 5.0 Sprint
"{44CDBD1B-89FB-4E02-8319-2A4C550F664A}" = RTC Client API v1.2
"{45AEEA61-04F8-11D6-8B35-0080C8F5C4AA}" = Veo Digital Studio
"{47813E93-F2A0-484A-838E-47EC1B28D190}" = Adobe Stock Photos 1.0
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{5E977DEC-5BB4-44C7-9FE5-9357D2DB4FCB}" = Disc2Phone
"{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes
"{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
"{64116298-93C5-401D-B06C-39D8E3338508}" = DAO
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A136B9A-1895-436F-83F8-30D9C68BB6EA}" = Rhapsody Player Engine
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7B98B956-EF9E-4801-BAC5-AC55546139EE}" = Sony Ericsson Communication Center
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91130409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Small Business
"{96E16100-A77F-4B31-B9AD-FFBA040EE1BD}" = Sound Blaster Live!
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9D98F245-3010-43C6-B3B0-67A464DA298E}" = ELNKInst
"{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8
"{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{B7EF4BD8-CA13-11D5-AE3D-005004B8E30C}" = Digital Photo Navigator 1.0
"{BC019EBE-613F-491F-9A83-08E3E8A74CE6}" = EarthLink Free Trial
"{C8E8D623-B163-48F7-9150-F824C8DCF064}" = 2009FredV2Step1
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools
"{F478DA38-C1D7-4A71-A690-8DEFA4EC5BCC}" = USB Mass Storage Package for Windows 2000-XP
"{FADE1A2A-CF22-4E4D-A0E0-1187C24405B9}" = Sony Ericsson PC Suite 1.10.61
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"3DGroove" = 3D Groove Playback Engine
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe Type Manager 4.0" = Adobe Type Manager 4.0
"AdobeESD" = Adobe Download Manager 2.0 (Remove Only)
"AIM_6" = AIM 6
"BitLord" = BitLord 1.1
"BREE5" = Brownstone Equation Editor 5
"CNXT_MODEM_PCI_VEN_14F1&DEV_2702" = Conexant SmartHSFi V92 56K DF PCI Modem
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Dell AIO Printer A940" = Dell AIO Printer A940
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"DellSupport" = Dell Support 5.0.0 (766)
"EPSON Printer and Utilities" = EPSON Printer Software
"HF_screensaver" = HF_screensaver
"HijackThis" = HijackThis 2.0.2
"Hijackthis_is1" = Hijackthis 1.99.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"InstallShield_{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs
"InstallShield_{9D98F245-3010-43C6-B3B0-67A464DA298E}" = Earthlink Installer - uninstall 'Earthlink 5.0' entry first if present
"kuririn_ss01_is1" = kuririn_ss01
"LimeWire" = LimeWire 4.18.8
"littletwinstar_is1" = littletwinstar
"Looney Tunes - Speedy" = Looney Tunes - Speedy Screen Saver
"Looney Tunes Valentines Day" = Looney Tunes Valentines Day Screen Saver
"lt_dvd_ssaver1_post1028" = lt_dvd_ssaver1_post1028 Screen Saver
"lt_dvd_ssaver2_post1028" = lt_dvd_ssaver2_post1028 Screen Saver
"lt_vday_saver" = lt_vday_saver Screen Saver
"LT_xmas_A_v2" = LT_xmas_A_v2 Screen Saver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft Press Interactive Training" = Microsoft Interactive Training
"mIRC" = mIRC
"mm_saver.scr" = mm_saver ScreenSaver
"Modem User Guide" = Modem User Guide
"Mozilla Firefox (3.0.13)" = Mozilla Firefox (3.0.13)
"Musicnotes Player_is1" = Musicnotes Player V1.23.1 and Viewer
"MWSnap 3" = MWSnap 3
"My Melody Screensaver_is1" = My Melody Screensaver
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"pochacco_is1" = pochacco
"Pop-Up Stopper Free Edition" = Pop-Up Stopper Free Edition
"Scooby Doo Loch Ness" = Scooby Doo Loch Ness Screen Saver
"ScoobyDooScreenSaver" = ScoobyDooScreenSaver Screen Saver
"screen_gossomer" = screen_gossomer Screen Saver
"Shockwave" = Shockwave
"Tutor" = Tutor
"USBCOMM&10AB&10C5" = USB Data Cable
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6d
"Winamp" = Winamp (remove only)
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinFF_is1" = WinFF 0.33
"WinRAR archiver" = WinRAR archiver
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Usmleworld Sim Exam V2" = Usmleworld Sim Exam V2
"Usmleworld Step1 QBank V2" = Usmleworld Step1 QBank V2

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/13/2009 10:54:57 AM | Computer Name = D7SDGB31 | Source = ESENT | ID = 474
Description = wuauclt (3744) The database page read from the file "C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb"
at offset 17764352 (0x00000000010f1000) for 4096 (0x00001000) bytes failed verification
due to a page checksum mismatch. The expected checksum was 2899087093 (0xaccc8ef5)
and the actual checksum was 2894892789 (0xac8c8ef5). The read operation will fail
with error -1018 (0xfffffc06). If this condition persists then please restore
the database from a previous backup.

Error - 9/14/2009 1:08:11 PM | Computer Name = D7SDGB31 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module mshtml.dll, version 6.0.2900.5848, fault address 0x0012403c.

Error - 9/14/2009 4:18:17 PM | Computer Name = D7SDGB31 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x0001168b.

Error - 9/14/2009 5:59:00 PM | Computer Name = D7SDGB31 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.

Error - 9/14/2009 9:08:25 PM | Computer Name = D7SDGB31 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3498, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/16/2009 9:13:28 AM | Computer Name = D7SDGB31 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module jscript.dll, version 5.7.6002.22145, fault address 0x0001c20c.

Error - 9/16/2009 1:26:38 PM | Computer Name = D7SDGB31 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module mshtml.dll, version 6.0.2900.5848, fault address 0x001fd3f3.

Error - 9/16/2009 7:34:14 PM | Computer Name = D7SDGB31 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module flash9f.ocx, version 9.0.124.0, fault address 0x001b5ada.

Error - 9/17/2009 6:19:16 AM | Computer Name = D7SDGB31 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000100e8.

Error - 9/18/2009 3:10:26 AM | Computer Name = D7SDGB31 | Source = Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 10.0.6854.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 9/18/2009 8:36:32 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000
Description = The Protected Storage service failed to start due to the following
error: %%2

Error - 9/18/2009 8:36:38 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Beep

Error - 9/18/2009 8:38:03 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000
Description = The Protected Storage service failed to start due to the following
error: %%2

Error - 9/18/2009 8:38:03 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000
Description = The Protected Storage service failed to start due to the following
error: %%2

Error - 9/18/2009 8:41:17 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000
Description = The Protected Storage service failed to start due to the following
error: %%2

Error - 9/18/2009 8:41:17 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000
Description = The Protected Storage service failed to start due to the following
error: %%2

Error - 9/18/2009 8:41:17 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000
Description = The Protected Storage service failed to start due to the following
error: %%2

Error - 9/18/2009 8:41:17 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000
Description = The Protected Storage service failed to start due to the following
error: %%2

Error - 9/18/2009 8:43:34 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000
Description = The Protected Storage service failed to start due to the following
error: %%2

Error - 9/18/2009 8:43:34 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000
Description = The Protected Storage service failed to start due to the following
error: %%2


< End of report >



Attached File(s)
Attached File  virusinfo_syscheck.zip ( 34.32K ) Number of downloads: 7
Attached File  virusinfo_syscure.zip ( 34.82K ) Number of downloads: 13
 
Go to the top of the page
 
+Quote Post
NeonFx
post Sep 19 2009, 11:21 AM
Post #4


Malware Removal Dude
Group Icon
Posts: 1,350
From: California
OS: XP / Vista



Thank you for that smile.gif Please do the following now:

STEP 1

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    CODE
    :OTL
    SRV - (auguamcv [Auto | Running]) -- C:\WINDOWS\System32\ojxhfcz.dll ()
    FF - prefs.js..extensions.enabledItems: {736fca60-00ae-431c-93b9-f4c01470e8cc}:1.0
    [2009/09/18 19:41:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\mozilla\Firefox\Profiles\2e2g8oi8.default\extensions\{736fca60-00ae-431c-93b9-f4c01470e8cc}
    O2 - BHO: (no name) - {01F97B14-A066-42FA-80B9-5F112A423743} - C:\WINDOWS\System32\ablvzzxf.dll ()
    O2 - BHO: () - {2EB5C6DF-DBF6-4E3F-A81A-FABABBCB693B} - C:\WINDOWS\System32\ojxhfcz.dll ()
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O20 - AppInit_DLLs: (karna.datS\System3) - File not found
    O20 - Winlogon\Notify\bbddqbke: DllName - ojxhfcz.dll - C:\WINDOWS\System32\ojxhfcz.dll ()
    O20 - Winlogon\Notify\mljigfg: DllName - mljigfg.dll - File not found
    [2009/09/18 01:11:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TuongVy\Local Settings\Application Data\kfogetgj
    [2009/09/18 01:11:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TuongVy\Application Data\kfogetgj
    [2002/08/29 05:00:00 | 00,147,968 | ---- | C] () -- C:\WINDOWS\System32\lvmcyiat.dll
    [2002/08/29 05:00:00 | 00,147,968 | ---- | C] () -- C:\WINDOWS\System32\ablvzzxf.dll
    [2002/08/29 05:00:00 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\ojxhfcz.dll
    [2002/08/29 05:00:00 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\euqdegy.dll

    :Services

    :Reg

    :Files
    C:\WINDOWS\tasks\At*.job

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • This will create a log in C:\_OTL\MovedFiles\<date>_<time>.txt where date and time are those of when the fix was run. Open it from there if it does not appear automatically on reboot. Please copy and paste the contents of that file here.


STEP 2

Open MalwareBytes AntiMalware
  • Update your version of MalwareBytes by clicking on the update tab at the top and using the button.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • Select all your harddrives and click on "Scan Now"
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy & Paste the entire report in your next reply.


Please restart your computer again.

STEP 3

After rebooting, run OTL again and click on the Quick Scan button at the top. Copy and Paste the results of this scan in your next reply.


STEP 4

How's the computer running? Are you experiencing any symptoms? If you are still being redirected on the internet, do you get the same symptoms while using Internet Explorer instead of Firefox?
Go to the top of the page
 
+Quote Post
little_angel
post Sep 19 2009, 08:29 PM
Post #5


New Member
*
Posts: 8
OS: windows xp



I tried running olt fix but my computer keeps on stalling/freezing. the last try took over 10 hours with a blank white box that was olt and my desktop background on the back. I couldn't shut off the computer, and had to turn off then on electricity to restart the computer. After the computer restarted, there are a lot of new icons/items on the desktop that were not there before with names of different files. I tried going into Drive C looking for olt folder to see what is reported but there is nothing in the subfolders.
what should i do now? do i try to rerun the olt again or go to malawarebytes?
Go to the top of the page
 
+Quote Post
NeonFx
post Sep 20 2009, 09:59 AM
Post #6


Malware Removal Dude
Group Icon
Posts: 1,350
From: California
OS: XP / Vista



That's alright, let's try to get it with the other tool you downloaded.

STEP 1

Close all your programs and disable all your security programs before proceeding.

  1. Double click on AVZ.exe
  2. Click File > Custom scripts
  3. Copy & paste the contents of the following codebox into the new "Run A Script" window that opened up. (start with begin and end with end.)
    To copy and paste you need to click and drag your mouse to select all the text, right click on it and select "Copy". Then right click where you wish to paste it and select "Paste"

    CODE
    begin
    SearchRootkit(true, true);
    SetAVZGuardStatus(True);
    StopService('auguamcv');
    DeleteService('auguamcv', true);
    DelCLSID('01F97B14-A066-42FA-80B9-5F112A423743');
    DelCLSID('2EB5C6DF-DBF6-4E3F-A81A-FABABBCB693B');
    RegKeyStrParamWrite('HKLM','SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows','AppInit_DLLs', '');
    DelWinlogonNotifyByFileName('ojxhfcz.dll');
    DelWinlogonNotifyByFileName('mljigfg.dll');
    DeleteFileMask('C:\Documents and Settings\TuongVy\Local Settings\Application Data\kfogetgj', '*.*', true);
    DeleteFileMask('C:\Documents and Settings\TuongVy\Application Data\kfogetgj', '*.*', true);
    DeleteFileMask('C:\WINDOWS\tasks', 'At*.job', false);
    DeleteFile('C:\WINDOWS\System32\lvmcyiat.dll');
    DeleteFile('C:\WINDOWS\System32\ablvzzxf.dll');
    DeleteFile('C:\WINDOWS\System32\ojxhfcz.dll');
    DeleteFile('C:\WINDOWS\System32\euqdegy.dll');
    DeleteFile('C:\WINDOWS\System32\mljigfg.dll');
    DeleteFile('C:\WINDOWS\System32\karna.dat');
    BC_ImportAll;
    ExecuteSysClean;
    ExecuteRepair(6);
    ExecuteRepair(13);
    BC_Activate;
    RebootWindows(true);
    end.
  4. Click the "Check Syntax" button
  5. If you get an error when clicking "Check Syntax" make sure you copy and pasted the entire code over correctly.
  6. If it says "Syntax is Correct" with a green check, click on the Run button to start the script.
    Note: When you run the script, your PC will be restarted.


STEP 2

Open MalwareBytes AntiMalware
  • Update your version of MalwareBytes by clicking on the update tab at the top and using the button.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • Select all your harddrives and click on "Scan Now"
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy & Paste the entire report in your next reply.


Please restart your computer again.

STEP 3

After rebooting, run OTL.exe and click on the Quick Scan button at the top. Copy and Paste the results of this scan in your next reply.


STEP 4

How's the computer running? Are you experiencing any symptoms? If you are still being redirected on the internet, do you get the same symptoms while using Internet Explorer instead of Firefox?

This post has been edited by NeonFx: Sep 20 2009, 10:01 AM
Go to the top of the page
 
+Quote Post
little_angel
post Sep 20 2009, 07:15 PM
Post #7


New Member
*
Posts: 8
OS: windows xp



I ran avz as instructed and restarted my computer. When my computer restarted, a box that says "found new hardware wizard" showed up asking me to connect to windows update to serach for software. when i clicked cancel to go to my desktop, i have a box that says "malwarebytes' anti-malware"- "run-time error '372': failed to load control 'vbalGrid' from vbalsgrid6.ocx. your version may be outdated. make sure you are using the version of control that was provided with your application." My desktop background days "active desktop recovery", to restore active desktop, click on the restore active desktop bar.
When I tried to connect to the internet with my internet connection setting, there were none there. before, there were LAN connection option, now there is nothing there. I restarted my computer again, and was told the same thing, except this time there is no start-up tab at the lower left corner, or any taskbar at all. for me to restart the computer, i have to manually cut off the electricity. also, i couldn't open any files or restore my active desktop.
There are also shaded files on my desktop from the runs with OTL. what should i do with those? is it ok for me to delete them?
Go to the top of the page
 
+Quote Post
NeonFx
post Sep 20 2009, 07:32 PM
Post #8


Malware Removal Dude
Group Icon
Posts: 1,350
From: California
OS: XP / Vista



Hi little_angel. I'm sorry to hear this has happened, there must be an infection on your system that I either missed, or cannot see, that is actively defending itself and the other infections on your system. Nothing in the fix I gave you can cause any of that. I will go over your logs once again and consult with my teacher about this.

My teacher has left for the day so I will have a new fix for you sometime tomorrow morning my time. In the meantime, could you attempt to boot into safemode and let me know if you can see your taskbar and run programs in that mode?

To boot into SafeMode you need to repeatedly press the F8 key on your keyboard as soon as you press the power button until a black and white menu comes up. Use your arrows and enter key to select SafeMode. Once it loads, log into your account and click on Yes when prompted if you wish to enter Safe Mode.

Apart from that, try to leave the computer alone while I decide on our next move.

This post has been edited by NeonFx: Sep 20 2009, 07:39 PM
Go to the top of the page
 
+Quote Post
little_angel
post Sep 20 2009, 08:00 PM
Post #9


New Member
*
Posts: 8
OS: windows xp



When I entered into safemode, there is still the box that says "FOUND NEW HARDWARE WIZARD"-Welcome to the Found New HArdware Wizard......
Even in safemode, i still cannot find my Taskbar, still had the malwarebyte' run-time error '372'. still can't connect to the internet. when i clicked on the ie icon, it opens up but showed that it cannot connect to ms n homepage because it is not connected to the internet. When it was not in safemode, i got the error box telling me to report problem to microsoft. still can't connect to the internet.
is it possible to revert back to the state my computer was in prior to running the last avz fix?
Go to the top of the page
 
+Quote Post
NeonFx
post Sep 21 2009, 01:49 PM
Post #10


Malware Removal Dude
Group Icon
Posts: 1,350
From: California
OS: XP / Vista



Hi again little_angel. Thank you for your patience. Let's try to recover your computer to an earlier state as you suggested.

The easiest way to do this is:
  • Boot your computer into Safe Mode
  • Log into your account
  • At the prompt asking you if you wish to continue into Safe Mode select "No" to open the System Restore applet.
  • Follow the prompts to restore your computer to an earlier date. To ensure that everything works properly, you should select the very last time a system restore was made.
  • This will begin the restore process and will reboot your machine when it is done.


If you cannot get the System Restore applet to run, use your keyboard to open it by holding down the Windows Key and pressing "R".
This will open a run dialog where you should type in the following:
C:\windows\system32\restore\rstrui.exe
And press Enter to run the applet.

If that doesn't work, try restoring to an even earlier time.

When your computer restarts, and if this solved our problem, please:

Open OTL.exe and run a scan by clicking on the Quick Scan button at the top. Copy and Paste the results of this scan here.


Also, I will need to know the exact Make and Model for your system. We may have to obtain the necessary drivers to reinstall your network device.
The "Found New Hardware" wizard is probably attempting to reinstall your networking device. Let it attempt to automatically find the drivers for the device the next time you see it. If it is not able to we will have to do so manually.
Go to the top of the page
 
+Quote Post
little_angel
post Sep 21 2009, 04:03 PM
Post #11


New Member
*
Posts: 8
OS: windows xp



Hi,
I tried to turn on my computer but instead of turning on, there's this eeeeeeeeeee sound coming from the machine and nothing comes up.
the computer is a Dell 2400.
Go to the top of the page
 
+Quote Post
little_angel
post Sep 21 2009, 04:14 PM
Post #12


New Member
*
Posts: 8
OS: windows xp



I got the computer to power up. however, it won't let me go to safemode option when i pressed f8. instead, it goes directly to the desktop. the found new hardware box popped up. i chose the "find hardware this time" option. It found a hardware "UNKNOWN" and asks me to install the CD that comes with the drive but i'm not sure what that is.
Go to the top of the page
 
+Quote Post
little_angel
post Sep 21 2009, 08:43 PM
Post #13


New Member
*
Posts: 8
OS: windows xp



I was able to get my computer into safemode, but when i chose to run system restore instead of safemode, it tells me to restart my computer and says that restore will not protect my computer.
btw, my computer is a Dell Dimension 2400, running on XP pro service pack 3
I've been trying to run system restore, but either in safemode or normal, i keep getting a box saying "system restore is not able to protect your computer. Please restart your computer, and then run system restore again."

This post has been edited by little_angel: Sep 21 2009, 08:47 PM
Go to the top of the page
 
+Quote Post
NeonFx
post Sep 22 2009, 12:00 PM
Post #14


Malware Removal Dude
Group Icon
Posts: 1,350
From: California
OS: XP / Vista



I'm very sorry to say this little_angel, but what you are describing, especially the continuous beeping sound when you turn your computer on, is a definite sign of a hardware malfunction that actually has nothing to with malware. You computer must have been right on the edge of its life when we started treating this as a virus problem, and will probably fail soon regardless of what we do.

I strongly suggest that you take your computer into a shop as there is nothing else I can do to troubleshoot your situation. Hardware issues such as the one you describe are extremely difficult to troubleshoot over the internet as they require opening up your computer and replacing/testing different parts of it.

If after taking it to the shop and getting the hardware problem fixed, you wish to continue analyzing your computer for malware, feel free to send me a private message to reopen this topic once it's closed.
Go to the top of the page
 
+Quote Post
Essexboy
post Sep 26 2009, 06:55 AM
Post #15


GeekU Moderator
Group Icon
Posts: 19,166
From: Darkest Cornwall
OS: Vista Ultimate & Windows 7



Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 21st November 2009 - 09:24 AM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising