Infected with Trojan.Vundo.H [Closed], Computer slows, malawarebytes shows repeated infection with TVH. |
![]() ![]() |
Infected with Trojan.Vundo.H [Closed], Computer slows, malawarebytes shows repeated infection with TVH. |
Sep 18 2009, 04:25 PM
Post
#1
|
|
|
New Member ![]() Posts: 8 OS: windows xp |
Hello,
I've noticed my computer to be excessively slow for about 1 month or so. When I ran Malawarebytes, it showed I was infected with Trojan.Vundo.H., and prompted me to reboot computer to fix. After being "fixed", my computer runs a bit faster, however, after 5 minutes of connecting to the internet, without surfing or even opening Internet explorer, my computer would become sluggish and Malawarebytes would show that i have at least 5 infections with of the same Trojan. When I surf for instruction on removal of TVH, just about any website I clicked on would be redirected to somewhere else. Sometimes, I even get redirected when trying to go to www.mail.yahoo.com. I'm not sure if this is related, but about a month or so, I have not been able to open the Add/Remove programs option in my COntrol Panel to remove unwanted program, no matter what I do. Below is my most recent Malawarebytes scan and HJT log Thank you for all your help. Malwarebytes' Anti-Malware 1.41 Database version: 2819 Windows 5.1.2600 Service Pack 3 9/18/2009 1:35:51 PM mbam-log-2009-09-18 (13-35-51).txt Scan type: Full Scan (C:\|) Objects scanned: 217185 Time elapsed: 1 hour(s), 38 minute(s), 55 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\SYSTEM32\ablvzzxf.dll (Trojan.Vundo.H) -> Delete on reboot. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01f97b14-a066-42fa-80b9-5f112a423743} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{01f97b14-a066-42fa-80b9-5f112a423743} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{01f97b14-a066-42fa-80b9-5f112a423743} (Trojan.Vundo.H) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\SYSTEM32\ablvzzxf.dll (Trojan.Vundo.H) -> Delete on reboot. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:14:48 PM, on 9/18/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wdfmgr.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\hkcmd.exe C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe C:\Program Files\Dell AIO Printer A940\dlbabmon.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\system32\wbem\wmiprvse.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank O1 - Hosts: ::1 localhost O1 - Hosts: ??????????????? browser-security.microsoft.com O1 - Hosts: ??????????????? spywareprotector-2009.com O1 - Hosts: ??????????????? www.spywareprotector-2009.com O1 - Hosts: ??????????????? secure.spywareprotector-2009.com O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: (no name) - {2EB5C6DF-DBF6-4E3F-A81A-FABABBCB693B} - c:\windows\system32\ojxhfcz.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [hpppt] /ICON O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe" O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p (User 'Default user') O4 - Global Startup: Digital Line Detect.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: *.imageservr.com (HKLM) O16 - DPF: Yahoo! Go - http://download.games.yahoo.com/games/clients/y/gt2_x.cab O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase9563.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1173831454421 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033...all/xscan53.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab O16 - DPF: {8646A6AF-0AE4-4BF8-B716-DB1513803972} (SFImageUpload1_8.ImageUpload) - http://riteaid.storefront.com/images/globa...geUpload1_8.CAB O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://www.imgag.com/cp/install/Crusher.cab O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem...GameManager.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac...ta/SymAData.dll O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p...obat/nos/gp.cab O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac.../ActiveData.cab O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca04.rightnowtech.com/7020-b369...l/java/RntX.cab O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugi...NetOpPlugin.ocx O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll O20 - AppInit_DLLs: karna.dat O20 - Winlogon Notify: bbddqbke - C:\WINDOWS\SYSTEM32\ojxhfcz.dll O20 - Winlogon Notify: mljigfg - mljigfg.dll (file missing) O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\SYSTEM32\IcdSptSv.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Protected Storage (ProtectedStorage) - Unknown owner - C:\WINDOWS\system32\lsassnexe (file missing) O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe -- End of file - 9582 bytes |
|
|
Sep 18 2009, 04:44 PM
Post
#2
|
|
![]() Malware Removal Dude Posts: 1,350 From: California OS: XP / Vista |
Hello there
My name is NeonFx. I'll be glad to help you with your computer problems. Logs can take some time to research, so please be patient with me. I am still a student here, and as such I will have to have all my responses checked by a malware removal expert before I post them here. Please note the following:
Note: Disabling any security programs you have running will significantly decrease the time it takes to run most of the programs I ask you run. Please disable them before performing any of my steps. For instructions, if needed, see HERE Step 1 Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors). http://sites.google.com/site/sysprotantirootkit/ Unzip it into a folder on your desktop. Start the Sysprot.exe program.
Step 2 Download AVZ and save it to your Desktop by right clicking HERE , selecting "Save Link As" or "Save Target As" and browsing to your desktop on the window that pops up before you click on the Save button. Right click on avz4.zip and select "Extract All..." from the selection. Extract it to a new folder on your desktop and open this folder. If you used the default settings, this folder will be called "avz4."
STEP 3 After your computer Restarts:
AVZ saves its logs as .zip files in the LOG folder within the AVZ4 folder from which AVZ.exe was run. Please attach both virusinfo_syscure.zip and virusinfo_syscheck.zip to your next post. To attach a file, do the following:
In the LOG folder you will also see a file called "History.txt". Please double click on it to open it in Notepad, and copy and paste the contents of that file here. Step 4
In your next reply, please include
|
|
|
Sep 18 2009, 06:07 PM
Post
#3
|
|
|
New Member ![]() Posts: 8 OS: windows xp |
SysProt AntiRootkit v1.0.1.0
by swatkat ****************************************************************************************** ****************************************************************************************** Process: Name: [System Idle Process] PID: 0 Hidden: No Window Visible: No Name: System PID: 4 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\smss.exe PID: 408 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\csrss.exe PID: 464 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\winlogon.exe PID: 488 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\services.exe PID: 532 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\lsass.exe PID: 544 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\svchost.exe PID: 700 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\svchost.exe PID: 764 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\svchost.exe PID: 800 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\svchost.exe PID: 844 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\svchost.exe PID: 876 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\LEXBCES.EXE PID: 1096 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\spoolsv.exe PID: 1120 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\LEXPPS.EXE PID: 1128 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\svchost.exe PID: 1252 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe PID: 1280 Hidden: No Window Visible: No Name: C:\Program Files\Bonjour\mDNSResponder.exe PID: 1316 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE PID: 1328 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\svchost.exe PID: 1420 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\wdfmgr.exe PID: 1460 Hidden: No Window Visible: No Name: C:\Program Files\Viewpoint\Common\ViewpointService.exe PID: 1492 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\alg.exe PID: 128 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\wscntfy.exe PID: 1068 Hidden: No Window Visible: No Name: C:\WINDOWS\explorer.exe PID: 1996 Hidden: No Window Visible: No Name: C:\WINDOWS\SYSTEM32\hkcmd.exe PID: 2488 Hidden: No Window Visible: No Name: C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe PID: 2504 Hidden: No Window Visible: No Name: C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe PID: 2516 Hidden: No Window Visible: No Name: C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe PID: 2524 Hidden: No Window Visible: No Name: C:\Program Files\Dell AIO Printer A940\dlbabmon.exe PID: 2552 Hidden: No Window Visible: No Name: C:\Program Files\iTunes\iTunesHelper.exe PID: 2572 Hidden: No Window Visible: No Name: C:\Program Files\QuickTime\QTTask.exe PID: 2600 Hidden: No Window Visible: No Name: C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe PID: 2632 Hidden: No Window Visible: No Name: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe PID: 2644 Hidden: No Window Visible: No Name: C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe PID: 2672 Hidden: No Window Visible: No Name: C:\Program Files\Digital Line Detect\DLG.exe PID: 2696 Hidden: No Window Visible: No Name: C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe PID: 2720 Hidden: No Window Visible: No Name: C:\Program Files\Internet Explorer\iexplore.exe PID: 2752 Hidden: No Window Visible: No Name: C:\Program Files\iPod\bin\iPodService.exe PID: 2868 Hidden: No Window Visible: No Name: C:\Documents and Settings\TuongVy\Desktop\SysProt\SysProt\SysProt.exe PID: 304 Hidden: No Window Visible: Yes ****************************************************************************************** ****************************************************************************************** Kernel Modules: Module Name: \??\C:\Documents and Settings\TuongVy\Desktop\SysProt\SysProt\SysProtDrv.sys Service Name: SysProtDrv.sys Module Base: EFAAB000 Module End: EFAB6000 Hidden: No Module Name: \WINDOWS\system32\ntoskrnl.exe Service Name: --- Module Base: 804D7000 Module End: 806ED700 Hidden: No Module Name: \WINDOWS\system32\hal.dll Service Name: --- Module Base: 806EE000 Module End: 8070E300 Hidden: No Module Name: \WINDOWS\system32\KDCOM.DLL Service Name: --- Module Base: F9762000 Module End: F9764000 Hidden: No Module Name: \WINDOWS\system32\BOOTVID.dll Service Name: --- Module Base: F9672000 Module End: F9675000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ACPI.sys Service Name: ACPI Module Base: F9213000 Module End: F9241000 Hidden: No Module Name: \WINDOWS\System32\DRIVERS\WMILIB.SYS Service Name: --- Module Base: F9764000 Module End: F9766000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\pci.sys Service Name: PCI Module Base: F9202000 Module End: F9213000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\isapnp.sys Service Name: isapnp Module Base: F9262000 Module End: F926C000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\lpjoofsn.sys Service Name: lpjoofsn Module Base: F94E2000 Module End: F94E8000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\pciide.sys Service Name: PCIIde Module Base: F982A000 Module End: F982B000 Hidden: No Module Name: \WINDOWS\System32\DRIVERS\PCIIDEX.SYS Service Name: --- Module Base: F94EA000 Module End: F94F1000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys Service Name: MountMgr Module Base: F9272000 Module End: F927D000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys Service Name: Disk Module Base: F91E3000 Module End: F9202000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\dmio.sys Service Name: dmio Module Base: F91BD000 Module End: F91E3000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys Service Name: PartMgr Module Base: F94F2000 Module End: F94F7000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys Service Name: VolSnap Module Base: F9282000 Module End: F928F000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\atapi.sys Service Name: atapi Module Base: F91A5000 Module End: F91BD000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\disk.sys Service Name: --- Module Base: F9292000 Module End: F929B000 Hidden: No Module Name: \WINDOWS\System32\DRIVERS\CLASSPNP.SYS Service Name: --- Module Base: F92A2000 Module End: F92AF000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\sr.sys Service Name: sr Module Base: F9173000 Module End: F9185000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\PxHelp20.sys Service Name: PxHelp20 Module Base: F92B2000 Module End: F92BB000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys Service Name: KSecDD Module Base: F915C000 Module End: F9173000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys Service Name: Ntfs Module Base: F90CF000 Module End: F915C000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\NDIS.sys Service Name: NDIS Module Base: F90A2000 Module End: F90CF000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\Mup.sys Service Name: Mup Module Base: F9088000 Module End: F90A2000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\intelppm.sys Service Name: intelppm Module Base: F92F2000 Module End: F92FB000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ialmnt5.sys Service Name: ialm Module Base: F9018000 Module End: F902F000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\VIDEOPRT.SYS Service Name: --- Module Base: F9004000 Module End: F9018000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\usbuhci.sys Service Name: usbuhci Module Base: F95AA000 Module End: F95B0000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\USBPORT.SYS Service Name: --- Module Base: F8FE0000 Module End: F9004000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\usbehci.sys Service Name: usbehci Module Base: F95B2000 Module End: F95BA000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys Service Name: HSFHWBS2 Module Base: F8FB9000 Module End: F8FE0000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\HSF_DP.sys Service Name: HSF_DP Module Base: F8EAE000 Module End: F8FB9000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys Service Name: winachsf Module Base: F8E22000 Module End: F8EAE000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Modem.SYS Service Name: Modem Module Base: F95BA000 Module End: F95C2000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\P16X.sys Service Name: P16X Module Base: F8CE6000 Module End: F8E22000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ks.sys Service Name: --- Module Base: F8CC3000 Module End: F8CE6000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\portcls.sys Service Name: --- Module Base: F8C9F000 Module End: F8CC3000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\drmk.sys Service Name: --- Module Base: F9302000 Module End: F9311000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\gameenum.sys Service Name: gameenum Module Base: F9742000 Module End: F9745000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\i8042prt.sys Service Name: i8042prt Module Base: F9312000 Module End: F931F000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\kbdclass.sys Service Name: Kbdclass Module Base: F95CA000 Module End: F95D0000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\mouclass.sys Service Name: Mouclass Module Base: F95D2000 Module End: F95D8000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\serial.sys Service Name: Serial Module Base: F9322000 Module End: F9332000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\serenum.sys Service Name: serenum Module Base: F9746000 Module End: F974A000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\parport.sys Service Name: Parport Module Base: F8C8B000 Module End: F8C9F000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\imapi.sys Service Name: Imapi Module Base: F9332000 Module End: F933D000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\MxlW2k.SYS Service Name: MxlW2k Module Base: F95DA000 Module End: F95E1000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\cdrom.sys Service Name: Cdrom Module Base: F9342000 Module End: F9352000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\redbook.sys Service Name: redbook Module Base: F9352000 Module End: F9361000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\pwd_2k.SYS Service Name: pwd_2k Module Base: F8C6C000 Module End: F8C8B000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys Service Name: GEARAspiWDM Module Base: F9362000 Module End: F936C000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\audstub.sys Service Name: audstub Module Base: F9972000 Module End: F9973000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\rasl2tp.sys Service Name: Rasl2tp Module Base: F9372000 Module End: F937F000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ndistapi.sys Service Name: NdisTapi Module Base: F974E000 Module End: F9751000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ndiswan.sys Service Name: NdisWan Module Base: F8C55000 Module End: F8C6C000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\raspppoe.sys Service Name: RasPppoe Module Base: F9382000 Module End: F938D000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\raspptp.sys Service Name: PptpMiniport Module Base: F9392000 Module End: F939E000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\TDI.SYS Service Name: --- Module Base: F95E2000 Module End: F95E7000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\psched.sys Service Name: PSched Module Base: F8C44000 Module End: F8C55000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\msgpc.sys Service Name: Gpc Module Base: F93A2000 Module End: F93AB000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ptilink.sys Service Name: Ptilink Module Base: F95F2000 Module End: F95F7000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\raspti.sys Service Name: Raspti Module Base: F95FA000 Module End: F95FF000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\rdpdr.sys Service Name: rdpdr Module Base: F8C14000 Module End: F8C44000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\termdd.sys Service Name: TermDD Module Base: F93B2000 Module End: F93BC000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\swenum.sys Service Name: swenum Module Base: F979C000 Module End: F979E000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\update.sys Service Name: Update Module Base: F8B8E000 Module End: F8BEC000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\omci.sys Service Name: omci Module Base: F9602000 Module End: F9607000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\mssmbios.sys Service Name: mssmbios Module Base: F9047000 Module End: F904B000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ialmkchw.sys Service Name: {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} Module Base: F0AFA000 Module End: F0B0E000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ialmsbw.sys Service Name: {6080A529-897E-4629-A488-ABA0C29B635E} Module Base: F0ADE000 Module End: F0AFA000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\mmc_2K.SYS Service Name: mmc_2K Module Base: F960A000 Module End: F9610000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS Service Name: NDProxy Module Base: F93D2000 Module End: F93DC000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\usbhub.sys Service Name: usbhub Module Base: F93E2000 Module End: F93F1000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\USBD.SYS Service Name: --- Module Base: F97A0000 Module End: F97A2000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\flpydisk.sys Service Name: Flpydisk Module Base: F9612000 Module End: F9617000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\i2omgmt.SYS Service Name: i2omgmt Module Base: F9712000 Module End: F9715000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Cdr4_xp.SYS Service Name: Cdr4_xp Module Base: F9876000 Module End: F9877000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Cdralw2k.SYS Service Name: Cdralw2k Module Base: F9877000 Module End: F9878000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\ATMhelpr.SYS Service Name: ATMhelpr Module Base: F9879000 Module End: F987A000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\vga.sys Service Name: VgaSave Module Base: F9622000 Module End: F9628000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS Service Name: mnmdd Module Base: F97A6000 Module End: F97A8000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys Service Name: RDPCDD Module Base: F97A8000 Module End: F97AA000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\cdudf_xp.SYS Service Name: cdudf_xp Module Base: F0976000 Module End: F09B1000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS Service Name: Npfs Module Base: F9632000 Module End: F963A000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\UdfReadr_xp.SYS Service Name: UdfReadr_xp Module Base: F0931000 Module End: F0964000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\rasacd.sys Service Name: RasAcd Module Base: F972A000 Module End: F972D000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\NDISRD.SYS Service Name: NDISRD Module Base: F963A000 Module End: F9640000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ipsec.sys Service Name: IPSec Module Base: F08E4000 Module End: F08F7000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\tcpip.sys Service Name: Tcpip Module Base: F088B000 Module End: F08E4000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\netbt.sys Service Name: NetBT Module Base: F0863000 Module End: F088B000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\ws2ifsl.sys Service Name: WS2IFSL Module Base: F9732000 Module End: F9735000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\afd.sys Service Name: AFD Module Base: F0841000 Module End: F0863000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\netbios.sys Service Name: NetBIOS Module Base: F9422000 Module End: F942B000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\rdbss.sys Service Name: Rdbss Module Base: F0816000 Module End: F0841000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\mrxsmb.sys Service Name: MRxSmb Module Base: F07A6000 Module End: F0816000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS Service Name: Fips Module Base: F9452000 Module End: F945D000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ipnat.sys Service Name: IpNat Module Base: F0780000 Module End: F07A6000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\wanarp.sys Service Name: Wanarp Module Base: F9462000 Module End: F946B000 Hidden: No Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys Service Name: --- Module Base: F0740000 Module End: F0758000 Hidden: Yes Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS Service Name: --- Module Base: F97AE000 Module End: F97B0000 Hidden: Yes Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys Service Name: --- Module Base: F0A26000 Module End: F0A29000 Hidden: No Module Name: C:\WINDOWS\System32\watchdog.sys Service Name: --- Module Base: F964A000 Module End: F964F000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys Service Name: --- Module Base: F9920000 Module End: F9921000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\ndisuio.sys Service Name: Ndisuio Module Base: F0605000 Module End: F0609000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\mrxdav.sys Service Name: MRxDAV Module Base: F0390000 Module End: F03BD000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys Service Name: mdmxsdk Module Base: F0471000 Module End: F0474000 Hidden: No Module Name: \??\C:\WINDOWS\System32\PfModNT.sys Service Name: PfModNT Module Base: F97AC000 Module End: F97AE000 Hidden: No Module Name: \??\C:\WINDOWS\System32\Drivers\SbcpHid.sys Service Name: SbcpHid Module Base: F056D000 Module End: F0577000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\srv.sys Service Name: Srv Module Base: F010E000 Module End: F0160000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys Service Name: wdmaud Module Base: EFE01000 Module End: EFE16000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys Service Name: sysaudio Module Base: F0026000 Module End: F0035000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Cdfs.SYS Service Name: Cdfs Module Base: EFDA3000 Module End: EFDB3000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\HTTP.sys Service Name: HTTP Module Base: EF9F7000 Module End: EFA38000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys Service Name: bcm4sbxp Module Base: EF8FF000 Module End: EF90A000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\dmload.sys Service Name: dmload Module Base: F9766000 Module End: F9768000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\fdc.sys Service Name: Fdc Module Base: F95C2000 Module End: F95C9000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\ParVdm.SYS Service Name: ParVdm Module Base: F9798000 Module End: F979A000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Null.SYS Service Name: Null Module Base: F9878000 Module End: F9879000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS Service Name: Msfs Module Base: F962A000 Module End: F962F000 Hidden: No ****************************************************************************************** ****************************************************************************************** No SSDT Hooks found ****************************************************************************************** ****************************************************************************************** No Kernel Hooks found ****************************************************************************************** ****************************************************************************************** No IRP Hooks found ****************************************************************************************** ****************************************************************************************** Ports: Local Address: D7SDGB31.MYHOME.WESTELL.COM:NETBIOS-SSN Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: D7SDGB31:27015 Remote Address: LOCALHOST:1041 Type: TCP Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe State: ESTABLISHED Local Address: D7SDGB31:27015 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe State: LISTENING Local Address: D7SDGB31:5354 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: LISTENING Local Address: D7SDGB31:1041 Remote Address: LOCALHOST:27015 Type: TCP Process: C:\Program Files\iTunes\iTunesHelper.exe State: ESTABLISHED Local Address: D7SDGB31:1028 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\SYSTEM32\alg.exe State: LISTENING Local Address: D7SDGB31:1025 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\SYSTEM32\LEXPPS.EXE State: LISTENING Local Address: D7SDGB31:MICROSOFT-DS Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: D7SDGB31:EPMAP Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\SYSTEM32\svchost.exe State: LISTENING Local Address: D7SDGB31.MYHOME.WESTELL.COM:5353 Remote Address: NA Type: UDP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: NA Local Address: D7SDGB31.MYHOME.WESTELL.COM:1900 Remote Address: NA Type: UDP Process: C:\WINDOWS\SYSTEM32\svchost.exe State: NA Local Address: D7SDGB31.MYHOME.WESTELL.COM:138 Remote Address: NA Type: UDP Process: System State: NA Local Address: D7SDGB31.MYHOME.WESTELL.COM:NETBIOS-NS Remote Address: NA Type: UDP Process: System State: NA Local Address: D7SDGB31.MYHOME.WESTELL.COM:123 Remote Address: NA Type: UDP Process: C:\WINDOWS\SYSTEM32\svchost.exe State: NA Local Address: D7SDGB31:1900 Remote Address: NA Type: UDP Process: C:\WINDOWS\SYSTEM32\svchost.exe State: NA Local Address: D7SDGB31:1052 Remote Address: NA Type: UDP Process: C:\Program Files\Internet Explorer\iexplore.exe State: NA Local Address: D7SDGB31:123 Remote Address: NA Type: UDP Process: C:\WINDOWS\SYSTEM32\svchost.exe State: NA Local Address: D7SDGB31:58182 Remote Address: NA Type: UDP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: NA Local Address: D7SDGB31:4500 Remote Address: NA Type: UDP Process: C:\WINDOWS\SYSTEM32\lsass.exe State: NA Local Address: D7SDGB31:1026 Remote Address: NA Type: UDP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: NA Local Address: D7SDGB31:500 Remote Address: NA Type: UDP Process: C:\WINDOWS\SYSTEM32\lsass.exe State: NA Local Address: D7SDGB31:MICROSOFT-DS Remote Address: NA Type: UDP Process: System State: NA ****************************************************************************************** ****************************************************************************************** Hidden files/folders: Object: C:\Documents and Settings\TuongVy\Application Data\Microsoft\Office\Recent\Nam Bính Tu?t.LNK Status: Hidden Object: C:\Documents and Settings\TuongVy\Application Data\Microsoft\Office\Recent\Quę Huong B? L?i.LNK Status: Hidden Object: C:\Documents and Settings\TuongVy\Application Data\Microsoft\Office\Recent\Đęm Đông.LNK Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\click2,060qAO2MCQAqYioAAAAAANMQDAAAAAAAAgD4AQYAAAAAAP8AAAAHEHe2DwAAAAAAuB4RAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F33%2F15%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\click2,060qAO2MCQB5tR8AAAAAAHnnCgAAAAAAAgEAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAACGjg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAA[2].com%2Fno_bra%2F3%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAGMAAYAAAAAAAUACQAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F81%2F01%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAcABAAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F35%2F06%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\click2,060qAO2MCQDKCS0AAAAAAMIhDQAAAAAAAgDcAAYAAAAAAP8AAAABAXa2DwAAAAAA6JcSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\main_2;sz=300x250;mpvid=AARzbqbF2fYfzT4t;!c=2;k2=211;k3=211;klg=en;kvid=Uhdajt0C1sE;ctb=1;kr=A;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=Uhdajt0C1sE_2;kg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\main_2;sz=450x60;mpvid=AARzbaZ8Rpgm-jnR;!c=2;k2=211;k3=211;klg=en;kvid=oqGnsP4wOf0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=oqGnsP4wOf0_2;kgg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\main_2;sz=480x70,480x360;mpvid=AARzbHogfYeijH0I;!c=2;k2=593;k3=593;klg=en;kvid=j5Cvq416zuQ;ctb=1;kr=F;kt=K;ko=p;kpid=2;afc=1;kga=-1;shortform=1;u=j5Cvq416z Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\main_2;sz=480x70,480x360;mpvid=AARzbIqhklLpg1Q8;!c=2;k2=618;k3=618;klg=en;kvid=1nV_p6cvr2A;ctb=1;kr=F;khd=0;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=1nV_p6cv Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\main_2;sz=480x70;mpvid=AARzbAO1ptvzrNXu;!c=2;k2=211;k3=211;klg=en;kvid=Jdvmw4FRzQ8;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=Jdvmw4FRzQ8_2;kgg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\09KDYNKP\main_9440;sz=480x70;mpvid=AARzbaSST1aBdfx7;!c=9440;k2=184;k2=507;k3=184;klg=en;kvid=-37F6MmAYD4;kpu=LittleMissSunshine87;kr=F;kt=K;ko=c;kpid=9440;afc=1;kga Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAIAAgAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AA[2].com%2F7th_period_is_a_secret%2F2%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAE8AAYAAAAAAAcACgAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F83%2F09%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH0AAIAAAAAAAMACQAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F84%2F09%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH4AQIAAAAAAAYAAgAHD3e2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F30%2F13%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\click2,5jBaAP4SCACOAi0AAAAAAFCTCgAAAAAAAwANaAoAAAAAAP8AAAAHEvdBCwAAAAAAtxMPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAABJIQIAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\default;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=pocahontas+if+i+never+knew+you+with+lyrics;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=3 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\main_2;sz=300x60,300x250;mpvid=AARza6Z4w1zIt1i7;!c=2;k2=584;k2=617;k3=584;klg=en;kvid=ljdodmEly6A;ctb=1;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=ljdodmE Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\main_2;sz=450x60;mpvid=AARzbIqhklLpg1Q8;!c=2;k2=618;k3=618;klg=en;kvid=1nV_p6cvr2A;ctb=1;kr=F;khd=0;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=1nV_p6cvr2A_2;kg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\main_2;sz=450x60;mpvid=AARzbZa60_ywl0tx;!c=2;k2=211;k3=211;klg=en;kvid=oqGnsP4wOf0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=oqGnsP4wOf0_2;kgg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DQV05E3\main_5703;sz=300x250;mpvid=AARzbGIAgfphbzHA;!c=5703;k2=3;k2=23;k3=3;klg=en;kvid=YRi20cWMYOM;ctb=1;kr=F;kt=K;ko=c;kpid=5703;afc=1;kga=-1;shortform=1;u=YRi20 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\click2,060qAO2MCQAIBi0AAAAAABrVDAAAAAAAAgH4AQIAAAAAAP8AAAAHEPgSEAAAAAAA9ngNAAAAAADkKBIAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAA[2].com%2Fgintama%2F33%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAIABgAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAA[2].com%2Fno_bra%2F1%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\click2,060qAO2MCQDDOC0AAAAAAHPiDAAAAAAAAAEAAAIAAAAAAAoAAQAHFHa2DwAAAAAAjjsSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\click2,060qAO2MCQDDOC0AAAAAAHPiDAAAAAAAAgH4AQIAAAAAAP8AAAAHE3e2DwAAAAAAjjsSAAAAAAAAAAAAAAAAAAAAAAAAA[1].com%2Fsuperior%2F21%2F01%2F,;dcopt=rcl;mtfIFPath=no Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\main_2;sz=300x250;mpvid=AARza3NwqFsWxDrN;!c=2;k2=211;k3=211;klg=en;kvid=9I9hVzqTbn0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;k1=rock;u=9I9hVzqTbn0_2;kgg=-1 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\main_2;sz=300x60,300x250;mpvid=AARzbBPWz9fDIPli;!c=2;k2=35;k3=35;klg=en;kvid=APnO_I4idsY;ctb=1;kr=F;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=APnO_I4idsY_2;kg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\main_2;sz=300x60,300x250;mpvid=AARzbYcYcW0k9V-w;!c=2;k2=211;k3=211;klg=en;kvid=uD7HfOX9i64;kpu=sonybmg;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=uD7HfOX9 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\main_2;sz=450x60;mpvid=AARzbBPWz9fDIPli;!c=2;k2=35;k3=35;klg=en;kvid=APnO_I4idsY;ctb=1;kr=F;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=APnO_I4idsY_2;kgg=-1;kcr Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\6P4FE501\main_2;sz=480x70;mpvid=AARzbaZ8Rpgm-jnR;!c=2;k2=211;k3=211;klg=en;kvid=oqGnsP4wOf0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=oqGnsP4wOf0_2;kgg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\81AVWX2F\click2,060qAO2MCQADHScAAAAAAHnnCgAAAAAAAgEAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAACGjg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAA[2].com%2Fno_bra%2F17%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\81AVWX2F\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAYABwAHD3a2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F30%2F11%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\81AVWX2F\click2,060qAO2MCQDh8BIAAAAAAN63BQAAAAAAAACEAQYAAAAAAAAAAgAHDfgSEAAAAAAAGEIOAAAAAADLiggAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\81AVWX2F\main_2;sz=450x60;mpvid=AARza3NwqFsWxDrN;!c=2;k2=211;k3=211;klg=en;kvid=9I9hVzqTbn0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;k1=rock;u=9I9hVzqTbn0_2;kgg=-1; Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\81AVWX2F\main_2;sz=450x60;mpvid=AARzbYcYcW0k9V-w;!c=2;k2=211;k3=211;klg=en;kvid=uD7HfOX9i64;kpu=sonybmg;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=uD7HfOX9i64_2;kg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\81AVWX2F\main_2;sz=480x70,480x360;mpvid=AARzbXu50EmUJgRF;!c=2;k2=617;k3=617;klg=en;kvid=WZiQdM7ih5Q;ctb=1;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=WZiQdM7ih5Q_2; Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\81AVWX2F\main_2;sz=480x70;mpvid=AARza2HRcvJHpj0e;!c=2;k2=184;k2=617;k3=184;klg=en;kvid=W2uHW1h5uWY;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=W2uHW1h5uW Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAEABQAHEHe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F35%2F07%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\click2,060qAO2MCQDh8BIAAAAAAN63BQAAAAAAAAB8AQYAAAAAAAEAAQAHDfgSEAAAAAAAGEIOAAAAAADLiggAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAGEAAIAAAAAAAkABgAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F83%2F17%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH4AQIAAAAAAAcABQAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F34%2F20%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\click2,060qAO2MCQDuvBsAAAAAAHnnCgAAAAAAAgEAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAACGjg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAA[2].com%2Fno_bra%2F2%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\main_2;sz=300x250;mpvid=AARzbZa60_ywl0tx;!c=2;k2=211;k3=211;klg=en;kvid=oqGnsP4wOf0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=oqGnsP4wOf0_2;kg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\main_2;sz=450x60;mpvid=AARza6Z4w1zIt1i7;!c=2;k2=584;k2=617;k3=584;klg=en;kvid=ljdodmEly6A;ctb=1;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=ljdodmEly6A_2;k Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\main_2;sz=450x60;mpvid=AARzbWi9jfofJKb7;!c=2;k2=35;k2=299;k3=35;klg=en;kvid=sjbDuXZ8gTo;ctb=1;kr=A;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=sjbDuXZ8gTo_ Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8HI709YF\music_jazzrb;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=i+swear+boyz+2+men+official+video;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=20067 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\click2,060qAO2MCQD1WCkAAAAAAMzyCwAAAAAAAgAAAAIAAAAAAP8AAAAHFNL5DgAAAAAAiYILAAAAAADk9xAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\click2,060qAO2MCQD5kigAAAAAADPPCwAAAAAAAgH4AQIAAAAAAP8AAAAHENL5DgAAAAAAiYILAAAAAACQyBAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\click2,060qAO2MCQDh8BIAAAAAAN63BQAAAAAAAABMAQYAAAAAAAEAAgABAfgSEAAAAAAAGEIOAAAAAADLiggAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAGUAAIAAAAAAAAABwAHDXe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F83%2F18-19%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH4AQIAAAAAAAEABAAHEHe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F33%2F04%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAHEAQIAAAAAAAIABQAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F82%2F15%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\click2,VaUDABPCCQCbcCkAAAAAAHzOCwAAAAAAAgACcgYAAAAAAP8AAAAHDoyuAQAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2 ].php%3Fen%3Dcp1252,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\default;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=pocahontas+if+i+never+knew+you;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=3911049755233 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\main_2;sz=300x250;mpvid=AARza2HRcvJHpj0e;!c=2;k2=184;k2=617;k3=184;klg=en;kvid=W2uHW1h5uWY;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=W2uHW1h5u Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\main_2;sz=450x60;mpvid=AARza2HRcvJHpj0e;!c=2;k2=184;k2=617;k3=184;klg=en;kvid=W2uHW1h5uWY;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=W2uHW1h5uW Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\main_2;sz=480x70,480x360;mpvid=AARza6Z4w1zIt1i7;!c=2;k2=584;k2=617;k3=584;klg=en;kvid=ljdodmEly6A;ctb=1;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=ljdodmE Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\main_2;sz=480x70;mpvid=AARza5Cb1vshxS96;!c=2;k2=211;k3=211;klg=en;kvid=_EOWfvX2czw;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=_EOWfvX2czw_2;kgg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\main_5703;sz=480x70;mpvid=AARzbGIAgfphbzHA;!c=5703;k2=3;k2=23;k3=3;klg=en;kvid=YRi20cWMYOM;ctb=1;kr=F;kt=K;ko=c;kpid=5703;afc=1;kga=-1;shortform=1;u=YRi20c Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\8RLNIIBT\music_rockpop;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=j+lo+waiting+for+tonight;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=1760630316801 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\1252822631&ga_sid=1252822631&ga_hid=1241134712&ga_fc=0&u_tz=-300&u_his=8&u_java=1&u_h=768&u_w=1024&u_ah=740&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&biw=300&b Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\52820350&ga_sid=1252820350&ga_hid=942050748&ga_fc=0&u_tz=-300&u_his=27&u_java=1&u_h=768&u_w=1024&u_ah=740&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&biw=300&bih Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\booksliterature;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=savage+garden+i+knew+i+loved+you;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=887 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\click2,060qAO2MCQBe2SoAAAAAAMxsDAAAAAAAAgHwAQIAAAAAAP8AAAAHDfgSEAAAAAAA9ngNAAAAAADOlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAA[2].com%2Fbloody_monday%2F82%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAG4AAIAAAAAAAAACAAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F84%2F01%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH4AQIAAAAAAAcABAAHEHe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F31%2F08%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH4AQIAAAAAAAMAAgAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F33%2F03%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\click2,VaUDABDCCQAjGCoAAAAAALgLDAAAAAAAAgAOcg8AAAAAAP8AAAAHDoyuAQAAAAAA6hcRAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2 ].php%3Fen%3Dcp1252,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\main_2;sz=300x250;mpvid=AARzbAO1ptvzrNXu;!c=2;k2=211;k3=211;klg=en;kvid=Jdvmw4FRzQ8;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=Jdvmw4FRzQ8_2;kg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\main_2;sz=300x250;mpvid=AARzbaZ8Rpgm-jnR;!c=2;k2=211;k3=211;klg=en;kvid=oqGnsP4wOf0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=oqGnsP4wOf0_2;kg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\main_2;sz=450x60;mpvid=AARzbHogfYeijH0I;!c=2;k2=593;k3=593;klg=en;kvid=j5Cvq416zuQ;ctb=1;kr=F;kt=K;ko=p;kpid=2;afc=1;kga=-1;shortform=1;u=j5Cvq416zuQ_2;kgg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\C3JFEGPL\music_rockpop;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=savage+garden+santa+monica;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=62450298846 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQAGICEAAAAAAHnnCgAAAAAAAgEAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAACGjg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAA[2].com%2Fno_bra%2F2%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQBe2SoAAAAAAM5sDAAAAAAAAgEAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AA[2].com%2F7th_period_is_a_secret%2F3%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEEAAYAAAAAAAkABQAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAA[2].com%2Fno_bra%2F1%2F00-co Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAUAAgAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F33%2F18%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAgH4AQYAAAAAAP8AAAAHEHe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F33%2F13%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQDh8BIAAAAAAN63BQAAAAAAAgA0AQYAAAAAAP8AAAABAfgSEAAAAAAAGEIOAAAAAADLiggAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAgH4AQIAAAAAAP8AAAAHEHe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F33%2F01%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\click2,060qAO2MCQDKCS0AAAAAAMIhDQAAAAAAAADkAAYAAAAAAAEAAQABAXa2DwAAAAAA6JcSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\main_2;sz=300x60,300x250;mpvid=AARzbHogfYeijH0I;!c=2;k2=593;k3=593;klg=en;kvid=j5Cvq416zuQ;ctb=1;kr=F;kt=K;ko=p;kpid=2;afc=1;kga=-1;shortform=1;u=j5Cvq416z Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\main_2;sz=480x70,480x360;mpvid=AARzbYcYcW0k9V-w;!c=2;k2=211;k3=211;klg=en;kvid=uD7HfOX9i64;kpu=sonybmg;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=uD7HfOX9 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\E6T6OLUB\music_jazzrb;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=i+swear+boyz+2+men+official+video;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=75553 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,060qAO2MCQBe2SoAAAAAAM5sDAAAAAAAAAEAAAIAAAAAAAAAAQAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AA[2].com%2F7th_period_is_a_secret%2F3%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAgEAAAYAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AA[2].com%2F7th_period_is_a_secret%2F1%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAEoAAYAAAAAAAgACgAHDXe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F83%2F07%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAGMAAYAAAAAAAgACwAHDXe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F83%2F18-19%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,060qAO2MCQCHjRkAAAAAADY2BgAAAAAAAgD4AQYAAAAAAP8AAAAHEPgSEAAAAAAA9ngNAAAAAABcSQkAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAA[2].com%2Fgintama%2F34%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,RwQAAMqTCQD9-CoAAAAAAM2ZCgAAAAAAAgAAAAYAAAAAAP8AAAAHDHe2DwAAAAAAzRsDAAAAAABdHQ8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F80%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,VaUDABDCCQAjGCoAAAAAALgLDAAAAAAAAgAGcg8AAAAAAP8AAAAHFoyuAQAAAAAA6hcRAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2 ].php%3Fen%3Dcp1252,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\click2,VaUDABDCCQDivSwAAAAAAP3DDAAAAAAAAgAKcg8AAAAAAP8AAAAHDoyuAQAAAAAADRISAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACwJAIAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\main_2;sz=300x60,300x250;mpvid=AARzbIqhklLpg1Q8;!c=2;k2=618;k3=618;klg=en;kvid=1nV_p6cvr2A;ctb=1;kr=F;khd=0;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=1nV_p6cv Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\main_2;sz=480x70,480x360;mpvid=AARzbBPWz9fDIPli;!c=2;k2=35;k3=35;klg=en;kvid=APnO_I4idsY;ctb=1;kr=F;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=APnO_I4idsY_2;kg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\main_2;sz=480x70;mpvid=AARza3NwqFsWxDrN;!c=2;k2=211;k3=211;klg=en;kvid=9I9hVzqTbn0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;k1=rock;u=9I9hVzqTbn0_2;kgg=-1; Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\main_2;sz=480x70;mpvid=AARzbZa60_ywl0tx;!c=2;k2=211;k3=211;klg=en;kvid=oqGnsP4wOf0;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=oqGnsP4wOf0_2;kgg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\GWSS5705\main_9440;sz=300x250;mpvid=AARzbaSST1aBdfx7;!c=9440;k2=184;k2=507;k3=184;klg=en;kvid=-37F6MmAYD4;kpu=LittleMissSunshine87;kr=F;kt=K;ko=c;kpid=9440;afc=1;kg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXI74TQB\click2,060qAO2MCQDh8BIAAAAAAN63BQAAAAAAAABEAQYAAAAAAAcAAQABAfgSEAAAAAAAGEIOAAAAAADLiggAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXI74TQB\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH4AQIAAAAAAAIABQAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F31%2F12%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXI74TQB\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAgH4AQIAAAAAAP8AAAAHD3e2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F30%2F08%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXI74TQB\click2,VaUDABDCCQCXGCkAAAAAAJoCDAAAAAAAAgEWcg8AAAAAAP8AAAAHDoyuAQAAAAAAfAwRAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2 ].php%3Fen%3Dcp1252,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXI74TQB\main_2;sz=450x60;mpvid=AARza5Cb1vshxS96;!c=2;k2=211;k3=211;klg=en;kvid=_EOWfvX2czw;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=_EOWfvX2czw_2;kgg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXI74TQB\main_2;sz=480x70;mpvid=AARzbqbF2fYfzT4t;!c=2;k2=211;k3=211;klg=en;kvid=Uhdajt0C1sE;ctb=1;kr=A;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=Uhdajt0C1sE_2;kgg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXI74TQB\music;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=savage+garden+truly+madly+deeply;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=9597733392601 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\OPQRGHER\click2,060qAO2MCQBkoCgAAAAAAHnnCgAAAAAAAgHcAAIAAAAAAP8AAAAHDfgSEAAAAAAA9ngNAAAAAACGjg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAA[2].com%2Fbloody_monday%2F84%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\OPQRGHER\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAYABAAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AA[2].com%2F7th_period_is_a_secret%2F3%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\OPQRGHER\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAUABgAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F35%2F15%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\OPQRGHER\click2,060qAO2MCQD1WCkAAAAAAMzyCwAAAAAAAgCsAAIAAAAAAP8AAAAHDdL5DgAAAAAAiYILAAAAAADk9xAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\OPQRGHER\ethnicidentitygroups_indigenouspeoples;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=pocahontas+colors+of+the+wind;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\OPQRGHER\main_2;sz=300x250;mpvid=AARza5Cb1vshxS96;!c=2;k2=211;k3=211;klg=en;kvid=_EOWfvX2czw;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=_EOWfvX2czw_2;kg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\OPQRGHER\main_5703;sz=450x60;mpvid=AARzbGIAgfphbzHA;!c=5703;k2=3;k2=23;k3=3;klg=en;kvid=YRi20cWMYOM;ctb=1;kr=F;kt=K;ko=c;kpid=5703;afc=1;kga=-1;shortform=1;u=YRi20c Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQBEixkAAAAAADY2BgAAAAAAAgAAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAABcSQkAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AA[2].com%2F7th_period_is_a_secret%2F2%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAUABgAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAA[2].com%2Fno_bra%2F1%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAYAAQAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AA[2].com%2F7th_period_is_a_secret%2F2%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAGkAAYAAAAAAAEACwAHDXe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F83%2Fcredits%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAYACAAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F30%2F18%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAHcAQYAAAAAAAMABAAHD3e2DwAAAAAAyccQAAAAAAAAAAAAAAAA[2].com%2Fkaichou_wa_maid-sama%2F41%2F04%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQDDOC0AAAAAAHPiDAAAAAAAAgH4AQIAAAAAAP8AAAAHEHa2DwAAAAAAjjsSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,060qAO2MCQDKCS0AAAAAAMIhDQAAAAAAAADsAAYAAAAAAAAAAgABAXe2DwAAAAAA6JcSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\click2,Bi4DAFheCgDK8ScAAAAAAH-JCwAAAAAAAgEsAAIAAAAAAP8AAAABASndEQAAAAAA7wAOAAAAAADKahAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPSgU AAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q3NQNEDB\main_2;sz=480x70;mpvid=AARzbWi9jfofJKb7;!c=2;k2=35;k2=299;k3=35;klg=en;kvid=sjbDuXZ8gTo;ctb=1;kr=A;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=sjbDuXZ8gTo_ Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAG8AQYAAAAAAAsAAgAHD3a2DwAAAAAAyccQAAAAAAAAA[2].com%2Fkaichou_wa_maid-sama%2F41%2F00-cover3%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAcACQAHEHe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F32%2F15%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\click2,060qAO2MCQDh8BIAAAAAAN63BQAAAAAAAgB0AQYAAAAAAP8AAAAHDfgSEAAAAAAAGEIOAAAAAADLiggAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAGsAQIAAAAAAAIABAAHDXe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F82%2F14%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAH4AQIAAAAAAAMABgAHEHe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F31%2F18%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAgHoAAIAAAAAAP8AAAAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F81%2F11%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\default;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=beauty+and+the+beast+celine+dion;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=77610877460 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\main_2;sz=450x60;mpvid=AARzbXu50EmUJgRF;!c=2;k2=617;k3=617;klg=en;kvid=WZiQdM7ih5Q;ctb=1;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=WZiQdM7ih5Q_2;kgg=-1;k Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\QTXI7A9S\main_9440;sz=450x60;mpvid=AARzbaSST1aBdfx7;!c=9440;k2=184;k2=507;k3=184;klg=en;kvid=-37F6MmAYD4;kpu=LittleMissSunshine87;kr=F;kt=K;ko=c;kpid=9440;afc=1;kga Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAEoAQYAAAAAAAUACQAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F81%2F20%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAFQAAYAAAAAAA8ACAAHDHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F80%2F14%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAQACAAHEHa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F31%2F05%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\click2,060qAO2MCQDUOhkAAAAAAHnnCgAAAAAAAgEAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAACGjg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AA[2].com%2F7th_period_is_a_secret%2F1%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\click2,060qAPCMCQAO-SoAAAAAAM2ZCgAAAAAAAgBwAQoAAAAAAP8AAAAHDvgSEAAAAAAAElUNAAAAAABdHQ8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AA[2].com%2Frec Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\click2,VaUDABDCCQAjGCoAAAAAALgLDAAAAAAAAAAecg8AAAAAAAoAAgAHD4yuAQAAAAAA6hcRAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2 ].php%3Fen%3Dcp1252,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\click2,VaUDABPCCQCbcCkAAAAAAHzOCwAAAAAAAAAOcgYAAAAAAAYAAgAHDoyuAQAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2 ].php%3Fen%3Dcp1252,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\main_2;sz=450x60;mpvid=AARzbAO1ptvzrNXu;!c=2;k2=211;k3=211;klg=en;kvid=Jdvmw4FRzQ8;ctb=1;kr=F;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=Jdvmw4FRzQ8_2;kgg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\main_2;sz=450x60;mpvid=AARzbqbF2fYfzT4t;!c=2;k2=211;k3=211;klg=en;kvid=Uhdajt0C1sE;ctb=1;kr=A;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=Uhdajt0C1sE_2;kgg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\VJ9NV9GO\music_rockpop;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=savage+garden+santa+monica;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=41555346255 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\W9AFCXQ7\click2,060qAO2MCQA1SysAAAAAAOmDDAAAAAAAAgEAAAIAAAAAAP8AAAAHFPgSEAAAAAAA9ngNAAAAAAAquBEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAA[2].com%2Fzero_in%2F30%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\W9AFCXQ7\click2,060qAO2MCQBe2SoAAAAAAM5sDAAAAAAAAAEAAAIAAAAAAAUAAgAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AA[2].com%2F7th_period_is_a_secret%2F3%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\W9AFCXQ7\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAMABQAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AA[2].com%2F7th_period_is_a_secret%2F3%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\W9AFCXQ7\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAYABwAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAA[2].com%2Fno_bra%2F2%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\W9AFCXQ7\click2,060qAOuMCQBPBC0AAAAAAOrIDAAAAAAAAgEAAAoAAAAAAP8AAAAHFPgSEAAAAAAAGEIOAAAAAAAvGRIAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACg1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\W9AFCXQ7\main_2;sz=300x250;mpvid=AARzbqbF2fYfzT4t;!c=2;k2=211;k3=211;klg=en;kvid=Uhdajt0C1sE;ctb=1;kr=A;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=Uhdajt0C1sE_2;kg Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQBISysAAAAAAOmDDAAAAAAAAgH4AQYAAAAAAP8AAAAHEPgSEAAAAAAA9ngNAAAAAAAquBEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAA[2].com%2Fgintama%2F36%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQBmZSoAAAAAAHkvDAAAAAAAAgD4AQYAAAAAAP8AAAAHEPgSEAAAAAAA9ngNAAAAAADxQxEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAA[2].com%2Fgintama%2F34%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQBu2SoAAAAAAM5sDAAAAAAAAAEAAAYAAAAAAAAAAwAHFPgSEAAAAAAA9ngNAAAAAADSlhEAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AA[2].com%2F7th_period_is_a_secret%2F2%2 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAH4AQYAAAAAAAcABgAHD3e2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fgintama%2F30%2F06%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQCbcCkAAAAAAHzOCwAAAAAAAAHQAAYAAAAAAAYACQAHDXa2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F81%2F09%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQDDOC0AAAAAAHPiDAAAAAAAAgH4AQIAAAAAAP8AAAAHE3e2DwAAAAAAjjsSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAACi1AQAAAAA Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAGsAAIAAAAAAAEACAAHDXe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F83%2Fcredits%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAO2MCQDhcCkAAAAAAHzOCwAAAAAAAAGYAQIAAAAAAAcAAgAHDXe2DwAAAAAAyccQAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fbloody_monday%2F82%2F12%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,060qAOuMCQCtYyoAAAAAABeyCwAAAAAAAgCUAAoAAAAAAP8AAAABAXe2DwAAAAAAOKEQAAAAAAAAAAAAAAAAAAAAAAAAAAA[2].com%2Fdirectory%2Ffantasy%2F,;dcopt=rcl;mtfIFPath Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\click2,VaUDABDCCQAk3x0AAAAAAHqYCQAAAAAAAgACcg8AAAAAAP8AAAAHDoyuAQAAAAAAL7sNAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAA[1].php%3Fen%3D Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\default;sz=300x250;klg=en;kt=K;kga=-1;kr=F;kw=beauty+and+the+beast+celine+dion;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=75066161379 Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\main_2;sz=300x250;mpvid=AARzbWi9jfofJKb7;!c=2;k2=35;k2=299;k3=35;klg=en;kvid=sjbDuXZ8gTo;ctb=1;kr=A;kt=K;ko=c;kpid=2;afc=1;kga=-1;shortform=1;u=sjbDuXZ8gTo Status: Hidden Object: C:\Documents and Settings\TuongVy\Local Settings\Temp\Temporary Internet Files\Content.IE5\XZNZ1X8E\main_2;sz=300x60,300x250;mpvid=AARzbXu50EmUJgRF;!c=2;k2=617;k3=617;klg=en;kvid=WZiQdM7ih5Q;ctb=1;kr=A;kt=K;ko=p;kpid=2;afc=1;kga=-1;k1=pop;u=WZiQdM7ih5Q_2; Status: Hidden Object: C:\Documents and Settings\TuongVy\My Documents\Music\hai kich\Hai Kich 2\Hŕi K?ch Ngŕy Xuân Vui Cu?i - Hoŕi Linh.MP3 Status: Hidden Object: C:\Documents and Settings\TuongVy\My Documents\Music\hai kich\Hŕi K?ch - Ngŕy Xuân Vui Cu?i - Hoŕi Linh.MP3 Status: Hidden From the AVZ4 History 9/18/2009 7:14:29 PM: System Analysis with MRM enabled was run successfully 9/18/2009 7:31:13 PM: AVZPM is active 9/18/2009 7:34:28 PM: System Analysis was run successfully From OLT file OTL logfile created on: 9/18/2009 7:47:48 PM - Run 1 OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\TuongVy\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 254.00 Mb Total Physical Memory | 103.18 Mb Available Physical Memory | 40.62% Memory free 1002.93 Mb Paging File | 770.68 Mb Available in Paging File | 76.84% Paging File free Paging file location(s): C:\pagefile.sys 762 1000 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 38.25 Gb Total Space | 10.15 Gb Free Space | 26.53% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: D7SDGB31 Current User Name: TuongVy Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\WINDOWS\System32\LEXBCES.EXE (Lexmark International, Inc.) PRC - C:\WINDOWS\System32\LEXPPS.EXE (Lexmark International, Inc.) PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.) PRC - C:\WINDOWS\System32\CTsvcCDA.exe (Creative Technology Ltd) PRC - C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation) PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation) PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation) PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation) PRC - C:\WINDOWS\System32\hkcmd.exe (Intel Corporation) PRC - C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe (Dell Computer Corporation) PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated) PRC - C:\Program Files\Dell AIO Printer A940\dlbabmon.exe (Dell Computer Corporation) PRC - C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe (Creative Technology Ltd) PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.) PRC - C:\Program Files\QuickTime\qttask.exe (Apple Inc.) PRC - C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe (Panicware, Inc.) PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software) PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe (Musicmatch, Inc.) PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe (Musicmatch, Inc.) PRC - C:\Documents and Settings\TuongVy\Desktop\OTL.exe (OldTimer Tools) ========== Win32 Services (SafeList) ========== SRV - (Adobe LM Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems) SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation) SRV - (auguamcv [Auto | Running]) -- C:\WINDOWS\System32\ojxhfcz.dll () SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.) SRV - (Creative Service for CDROM Access [Auto | Running]) -- C:\WINDOWS\System32\CTsvcCDA.exe (Creative Technology Ltd) SRV - (getPlus® Helper [On_Demand | Stopped]) -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.) SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google) SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) SRV - (ICDSPTSV [On_Demand | Stopped]) -- C:\WINDOWS\System32\IcdSptSv.exe (Sony Corporation) SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) SRV - (LexBceS [Auto | Running]) -- C:\WINDOWS\System32\LEXBCES.EXE (Lexmark International, Inc.) SRV - (ProtectedStorage [Auto | Stopped]) -- File not found SRV - (UMWdf [Auto | Running]) -- C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation) SRV - (Viewpoint Manager Service [Auto | Running]) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation) ========== Driver Services (SafeList) ========== DRV - (AliIde [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.) DRV - (amdagp [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.) DRV - (asc [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.) DRV - (asc3550 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.) DRV - (ATMhelpr [System | Running]) -- C:\WINDOWS\System32\drivers\ATMHELPR.SYS (Adobe Systems Incorporated) DRV - (bcm4sbxp [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation) DRV - (bvrp_pci [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\bvrp_pci.sys () DRV - (Cdr4_xp [System | Running]) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions) DRV - (Cdralw2k [System | Running]) -- C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions) DRV - (cdudf_xp [System | Running]) -- C:\WINDOWS\System32\drivers\cdudf_xp.sys (Roxio) DRV - (CmdIde [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.) DRV - (dac2w2k [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation) DRV - (DCamUSBVeo532 [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\ubVeo532.sys (IC Media Corporation) DRV - (dvd_2K [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\Dvd_2k.sys (Roxio) DRV - (EL90XBC [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\el90xbc5.sys (3Com Corporation) DRV - (epstw2k [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\epstw2k.sys (Microsoft Corporation) DRV - (gameenum [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation) DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.) DRV - (hamachi [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\hamachi.sys (Applied Networking Inc.) DRV - (HSFHWBS2 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys (Conexant Systems) DRV - (HSF_DP [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_DP.sys (Conexant Systems) DRV - (i81x [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\i81xnt5.sys (Intel® Corporation) DRV - (iAimFP0 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wADV01nt.sys (Intel® Corporation) DRV - (iAimFP1 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wADV02NT.sys (Intel® Corporation) DRV - (iAimFP2 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wADV05NT.sys (Intel® Corporation) DRV - (iAimFP3 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys (Intel® Corporation) DRV - (iAimFP4 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys (Intel® Corporation) DRV - (iAimTV0 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wATV01nt.sys (Intel® Corporation) DRV - (iAimTV1 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wATV02NT.sys (Intel® Corporation) DRV - (iAimTV3 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wATV04nt.sys (Intel® Corporation) DRV - (iAimTV4 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys (Intel® Corporation) DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation) DRV - (lpjoofsn [Boot | Running]) -- C:\WINDOWS\system32\drivers\lpjoofsn.sys (Intel® Corporation) DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant) DRV - (mmc_2K [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\Mmc_2k.sys (Roxio) DRV - (mraid35x [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.) DRV - (MxlW2k [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\MxlW2k.sys (MusicMatch, Inc.) DRV - (NPPTNT2 [On_Demand | Stopped]) -- C:\WINDOWS\System32\npptNT2.sys (INCA Internet Co., Ltd.) DRV - (nv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation) DRV - (omci [System | Running]) -- C:\WINDOWS\System32\DRIVERS\omci.sys (Dell Computer Corporation) DRV - (P16X [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\P16X.sys (Creative Technology Ltd.) DRV - (PCTINDIS5 [On_Demand | Stopped]) -- C:\WINDOWS\System32\PCTINDIS5.SYS (PCTEL Inc.) DRV - (PfModNT [Auto | Running]) -- C:\WINDOWS\System32\PfModNT.sys (Creative Technology Ltd.) DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.) DRV - (pwd_2k [System | Running]) -- C:\WINDOWS\System32\drivers\pwd_2K.sys (Roxio) DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions) DRV - (ql1080 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation) DRV - (ql12160 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation) DRV - (ql1280 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation) DRV - (SbcpHid [Auto | Running]) -- C:\WINDOWS\System32\Drivers\SbcpHid.sys () DRV - (scsiscan [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\scsiscan.sys (Microsoft Corporation) DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (sisagp [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation) DRV - (slabbus [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\slabbus.sys (MCCI) DRV - (slabser [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\slabser.sys (MCCI) DRV - (Sparrow [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.) DRV - (symc810 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.) DRV - (symc8xx [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic) DRV - (sym_hi [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic) DRV - (sym_u3 [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic) DRV - (SysProtDrv.sys [On_Demand | Stopped]) -- C:\Documents and Settings\TuongVy\Desktop\SysProt\SysProt\SysProtDrv.sys () DRV - (UdfReadr_xp [System | Running]) -- C:\WINDOWS\System32\drivers\udfreadr_xp.sys (Roxio) DRV - (ultra [Disabled | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.) DRV - (USBMSD [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\USBMSD.SYS (Generic) DRV - (uzi0odaz [System | Running]) -- C:\WINDOWS\System32\Drivers\uzi0odaz.sys () DRV - (w550bus [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\w550bus.sys (MCCI) DRV - (w550mdfl [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\w550mdfl.sys (MCCI) DRV - (w550mdm [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\w550mdm.sys (MCCI) DRV - (w550mgmt [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\w550mgmt.sys (MCCI) DRV - (w550obex [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\w550obex.sys (MCCI) DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems) DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation) DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation) ========== Standard Registry (All) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/...rch/search.html IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default = CE 89 47 DF 36 72 B7 40 BF 6C D1 0F 8F 35 36 04 [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm...tf8&oe=utf8 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 14 7B F9 01 66 A0 FA 42 80 B9 5F 11 2A 42 37 43 [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\System32\shdocvw.dll (Microsoft Corporation) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05 FF - prefs.js..extensions.enabledItems: {736fca60-00ae-431c-93b9-f4c01470e8cc}:1.0 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13 FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/08 17:37:58 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/30 09:19:48 | 00,000,000 | ---D | M] [2009/04/12 10:29:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\mozilla\Extensions [2009/01/13 15:52:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/04/12 10:29:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\mozilla\Extensions\mozswing@mozswing.org [2009/09/17 17:03:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\mozilla\Firefox\Profiles\2e2g8oi8.default\extensions [2009/09/18 19:41:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\mozilla\Firefox\Profiles\2e2g8oi8.default\extensions\{736fca60-00ae-431c-93b9-f4c01470e8cc} [2009/09/17 17:03:08 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2009/08/30 09:19:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2008/02/06 15:26:19 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [2008/03/09 11:08:17 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [2009/08/30 09:19:13 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/08/30 09:19:14 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2008/06/18 01:43:04 | 00,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll [2006/01/12 17:28:26 | 00,086,016 | ---- | M] (DivX, Inc) -- C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll [2005/11/10 19:21:00 | 01,499,136 | ---- | M] (LizardTech) -- C:\Program Files\mozilla firefox\plugins\npdjvu.dll [2009/08/30 09:19:31 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll [2009/04/30 07:15:11 | 00,239,432 | ---- | M] (Pando Networks) -- C:\Program Files\mozilla firefox\plugins\npPandoWebInst.dll [2009/02/18 10:56:23 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2009/02/18 10:56:24 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2009/02/18 10:56:25 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2009/02/18 10:56:25 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2009/02/18 10:56:26 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2009/02/18 10:56:27 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2009/02/18 10:56:27 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2007/11/20 16:52:00 | 02,884,992 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\NPSWF32.dll [2007/04/16 12:07:12 | 00,180,293 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npViewpoint.dll [2009/08/30 09:19:37 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2009/08/30 09:19:37 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2009/08/30 09:19:37 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2009/08/30 09:19:37 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2009/08/30 09:19:37 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2009/08/30 09:19:37 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml [2009/08/30 09:19:37 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (224 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O1 - Hosts: ??????????????? browser-security.microsoft.com O1 - Hosts: ??????????????? spywareprotector-2009.com O1 - Hosts: ??????????????? www.spywareprotector-2009.com O1 - Hosts: ??????????????? secure.spywareprotector-2009.com O2 - BHO: (no name) - {01F97B14-A066-42FA-80B9-5F112A423743} - C:\WINDOWS\System32\ablvzzxf.dll () O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. O2 - BHO: () - {2EB5C6DF-DBF6-4E3F-A81A-FABABBCB693B} - C:\WINDOWS\System32\ojxhfcz.dll () O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll (Google Inc.) O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\ShellBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.) O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Dell AIO Printer A940] C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe (Dell Computer Corporation) O4 - HKLM..\Run: [diagent] C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe (Creative Technology Ltd) O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation) O4 - HKLM..\Run: [hpppt] File not found O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation) O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.) O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe (Musicmatch, Inc.) O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.) O4 - HKCU..\Run: [Aim6] File not found O4 - HKCU..\Run: [PopUpStopperFreeEdition] C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe (Panicware, Inc.) O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data] O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1 O8 - Extra context menu item: &AIM Search - Reg Error: Value error. File not found O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.) O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\System32\winrnr.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation) O15 - HKLM\..Trusted Domains: imageservr.com ([]* in Trusted sites) O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites) O15 - HKLM\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class) O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control) O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock...director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool) O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB (Reg Error: Key error.) O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class) O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/...lscbase9563.cab (Windows Live Safety Center Base Module) O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo...otoUploader.cab (Facebook Photo Uploader Control) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1173831454421 (MUWebControl Class) O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} http://a840.g.akamai.net/7/840/537/2004033...all/xscan53.cab (HouseCall Control) O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://www.nick.com/common/groove/gx/GrooveAX27.cab (Groove Control) O16 - DPF: {8646A6AF-0AE4-4BF8-B716-DB1513803972} http://riteaid.storefront.com/images/globa...geUpload1_8.CAB (SFImageUpload1_8.ImageUpload) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/...tiveXPlugin.cab (ScorchPlugin Class) O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} http://www.imgag.com/cp/install/Crusher.cab (Creative Toolbox Plug-in) O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_02) O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_10) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} https://disney.go.com/games/downloads/gamem...GameManager.cab (CGameManagerCtrl Object) O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} https://www-secure.symantec.com/techsupp/ac...ta/SymAData.dll (ActiveDataInfo Class) O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p...obat/nos/gp.cab (get_atlcom Class) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa...ash/swflash.cab (Shockwave Flash Object) O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} https://www-secure.symantec.com/techsupp/ac.../ActiveData.cab (ActiveDataObj Class) O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} http://liveca04.rightnowtech.com/7020-b369...l/java/RntX.cab (Live Collaboration) O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} http://apps.corel.com/nos_dl_manager/plugi...NetOpPlugin.ocx (Get_ActiveX Control) O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.) O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.) O16 - DPF: Yahoo! Go http://download.games.yahoo.com/games/clients/y/gt2_x.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\System32\msvidctl.dll (Microsoft Corporation) O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll (Microsoft Corporation) O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll (Microsoft Corporation) O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\System32\msvidctl.dll (Microsoft Corporation) O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll (Microsoft Corporation) O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Filter: - deflate - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Filter: - gzip - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation) O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation) O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.) O20 - AppInit_DLLs: (karna.datS\System3) - File not found O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation) O20 - Winlogon\Notify\bbddqbke: DllName - ojxhfcz.dll - C:\WINDOWS\System32\ojxhfcz.dll () O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation) O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation) O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation) O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\System32\dimsntfy.dll (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation) O20 - Winlogon\Notify\mljigfg: DllName - mljigfg.dll - File not found O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation) O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation) O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation) O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\WlNotify.dll (Microsoft Corporation) O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation) O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation) O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation) O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation) O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation) O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\System32\stobject.dll (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\System32\webcheck.dll (Microsoft Corporation) O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation) O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation) O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\System32\ntsd.exe (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation) O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation) O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation) O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation) O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation) O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation) O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation) O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation) O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation) O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2002/09/03 13:36:02 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{1418bd52-13bb-11dc-866a-000bdbb6960d}\Shell - "" = AutoRun O33 - MountPoints2\{1418bd52-13bb-11dc-866a-000bdbb6960d}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{1418bd52-13bb-11dc-866a-000bdbb6960d}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found O33 - MountPoints2\{eb0477f2-215f-11dd-882b-000bdbb6960d}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{eb0477f2-215f-11dd-882b-000bdbb6960d}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\Shell32.DLL -- [2008/06/17 14:02:19 | 08,461,312 | ---- | M] (Microsoft Corporation) O33 - MountPoints2\E\Shell - "" = AutoRun O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found ========== Files/Folders - Created Within 30 Days ========== [1 C:\*.tmp files] [9 C:\Documents and Settings\TuongVy\Desktop\*.tmp files] [2009/09/18 19:14:29 | 00,011,264 | ---- | C] () -- C:\WINDOWS\System32\drivers\uzi0odaz.sys [2009/09/18 18:53:53 | 00,037,376 | ---- | C] () -- C:\Documents and Settings\TuongVy\Desktop\trojan remove.doc [2009/09/18 18:52:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TuongVy\Desktop\avz4 [2009/09/18 18:52:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TuongVy\Desktop\SysProt [2009/09/18 18:48:23 | 00,514,560 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\TuongVy\Desktop\OTL.exe [2009/09/18 18:14:32 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\TuongVy\Desktop\HijackThis.lnk [2009/09/18 18:14:32 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro [2009/09/18 01:11:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TuongVy\Local Settings\Application Data\kfogetgj [2009/09/18 01:11:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TuongVy\Application Data\kfogetgj [2009/09/09 21:17:22 | 00,001,986 | ---- | C] () -- C:\Documents and Settings\TuongVy\My Documents\ROFLMAO.html [2009/08/29 08:26:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\TuongVy\My Documents\My Library [2009/08/29 08:26:43 | 00,001,552 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Reader.lnk [2009/08/29 08:26:14 | 00,057,436 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\DASShp.dll [2009/08/29 08:26:14 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Reader [2009/08/28 21:41:06 | 00,000,000 | -HSD | C] -- C:\found.005 [2009/03/08 22:10:30 | 00,595,160 | ---- | C] () -- C:\WINDOWS\System32\wodCertificate.dll [2009/03/08 22:10:25 | 00,589,960 | ---- | C] () -- C:\WINDOWS\System32\brgrt.dll [2008/12/12 03:08:52 | 00,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI [2007/08/20 19:26:52 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest [2007/08/20 19:26:52 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest [2007/05/24 13:23:22 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2007/05/16 21:41:03 | 01,458,950 | -HS- | C] () -- C:\WINDOWS\System32\eaqmsnqr.ini [2007/01/31 13:20:15 | 00,000,168 | RHS- | C] () -- C:\WINDOWS\System32\A228C0DDBC.sys [2007/01/23 15:20:21 | 00,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini [2006/11/16 03:07:17 | 00,000,000 | ---- | C] () -- C:\WINDOWS\DVEdit.INI [2006/11/16 03:02:59 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\dsp_trc.dll [2006/11/16 03:02:59 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\IcdSptSvps.dll [2006/03/18 15:42:04 | 00,000,012 | ---- | C] () -- C:\WINDOWS\dirsaver.ini [2006/03/18 15:41:30 | 00,028,672 | ---- | C] () -- C:\WINDOWS\gscr.dll [2006/02/12 13:23:04 | 00,000,061 | ---- | C] () -- C:\WINDOWS\einit.ini [2006/02/04 02:12:49 | 00,000,032 | ---- | C] () -- C:\WINDOWS\AMPlayer.INI [2006/02/02 21:12:21 | 00,000,056 | ---- | C] () -- C:\WINDOWS\System32\BCDDC028A2.sys [2006/01/30 19:18:46 | 00,000,192 | ---- | C] () -- C:\WINDOWS\winamp.ini [2006/01/30 11:03:45 | 00,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini [2006/01/30 09:44:15 | 00,000,061 | ---- | C] () -- C:\WINDOWS\wininit.ini [2006/01/24 13:08:29 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll [2005/12/09 21:29:36 | 00,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI [2005/10/04 20:39:37 | 00,000,000 | ---- | C] () -- C:\WINDOWS\server32.INI [2005/10/04 20:28:21 | 00,000,026 | ---- | C] () -- C:\WINDOWS\chscg.ini [2005/08/12 16:57:09 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2005/05/15 10:27:21 | 00,000,650 | ---- | C] () -- C:\WINDOWS\DELLSTAT.INI [2005/03/29 22:56:29 | 00,000,074 | ---- | C] () -- C:\WINDOWS\hpsjbmgr.ini [2005/03/29 22:39:47 | 00,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL [2005/03/29 07:08:46 | 00,000,021 | ---- | C] () -- C:\WINDOWS\THUMBV~1.INI [2005/03/29 06:47:18 | 00,000,458 | ---- | C] () -- C:\WINDOWS\icompose.INI [2005/03/29 06:43:04 | 00,000,140 | ---- | C] () -- C:\WINDOWS\VWORK32.INI [2004/08/05 18:02:21 | 00,000,073 | ---- | C] () -- C:\WINDOWS\PUZZLES.INI [2004/07/29 10:47:10 | 00,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll [2004/06/16 19:14:10 | 00,000,019 | ---- | C] () -- C:\WINDOWS\KNP.INI [2004/06/15 22:08:25 | 00,001,251 | ---- | C] () -- C:\WINDOWS\Things.ini [2004/05/05 16:40:23 | 00,000,040 | ---- | C] () -- C:\WINDOWS\TSC.INI [2004/05/05 16:36:55 | 00,000,170 | ---- | C] () -- C:\WINDOWS\GetServer.ini [2004/02/29 22:03:57 | 00,004,239 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini [2004/02/22 11:33:52 | 00,000,018 | ---- | C] () -- C:\WINDOWS\Epson777.ini [2004/02/07 21:54:53 | 00,002,397 | ---- | C] () -- C:\WINDOWS\System32\drivers\symlcbrd.sys [2004/01/18 00:00:15 | 00,004,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\bvrp_pci.sys [2004/01/05 00:24:27 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\VeoSetup532.dll [2004/01/05 00:24:26 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\Veo532ut.dll [2003/12/21 07:38:57 | 00,004,094 | ---- | C] () -- C:\WINDOWS\System32\rtcsses.dll [2003/12/21 07:38:57 | 00,004,094 | ---- | C] () -- C:\WINDOWS\System32\dimces.dll [2003/12/15 08:42:41 | 00,000,035 | ---- | C] () -- C:\WINDOWS\ERegClnt.INI [2003/08/24 16:05:57 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini [2003/08/24 15:57:28 | 00,000,784 | ---- | C] () -- C:\WINDOWS\lrun32.ini [2003/08/24 15:55:37 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2003/08/24 15:51:38 | 00,000,231 | ---- | C] () -- C:\WINDOWS\AC3API.INI [2003/08/24 15:51:08 | 00,039,936 | ---- | C] () -- C:\WINDOWS\System32\P16X.dll [2003/08/24 15:51:08 | 00,002,092 | ---- | C] () -- C:\WINDOWS\System32\P16X.ini [2003/08/24 15:51:08 | 00,000,026 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini [2003/08/24 15:51:07 | 00,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\A3d.dll [2003/08/24 15:51:07 | 00,006,175 | ---- | C] () -- C:\WINDOWS\MIXDEF.INI [2003/08/24 15:51:07 | 00,005,917 | ---- | C] () -- C:\WINDOWS\SBMIXDEF.INI [2003/08/24 15:51:07 | 00,000,064 | ---- | C] () -- C:\WINDOWS\P16x.ini [2003/08/24 15:50:21 | 00,000,245 | ---- | C] () -- C:\WINDOWS\SBWIN.INI [2003/08/24 15:44:39 | 00,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini [2003/08/24 15:22:53 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini [2003/08/24 15:04:14 | 00,000,550 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI [2003/02/17 17:00:42 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbavs.dll [2003/02/17 17:00:36 | 00,000,177 | ---- | C] () -- C:\WINDOWS\System32\dlbacoin.ini [2003/02/05 11:11:12 | 00,000,126 | ---- | C] () -- C:\WINDOWS\System32\DLBAPLC.INI [2002/11/01 16:17:50 | 00,000,256 | ---- | C] () -- C:\WINDOWS\aucfg.ini [2002/09/03 13:36:02 | 00,000,784 | ---- | C] () -- C:\WINDOWS\WIN.INI [2002/09/03 13:26:32 | 00,000,292 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI [2002/08/29 05:00:00 | 00,147,968 | ---- | C] () -- C:\WINDOWS\System32\lvmcyiat.dll [2002/08/29 05:00:00 | 00,147,968 | ---- | C] () -- C:\WINDOWS\System32\ablvzzxf.dll [2002/08/29 05:00:00 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\ojxhfcz.dll [2002/08/29 05:00:00 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\euqdegy.dll [2002/07/04 15:05:34 | 00,000,269 | ---- | C] () -- C:\WINDOWS\tmupdate.ini [2001/12/14 13:34:46 | 00,164,864 | ---- | C] () -- C:\WINDOWS\patchw32.dll [2001/04/23 13:00:44 | 00,037,408 | ---- | C] () -- C:\WINDOWS\System32\drivers\SbcpHid.sys ========== Files - Modified Within 30 Days ========== [1 C:\*.tmp files] [1 C:\WINDOWS\System32\*.tmp files] [4 C:\WINDOWS\*.tmp files] [9 C:\Documents and Settings\TuongVy\Desktop\*.tmp files] [2009/09/18 19:39:28 | 00,001,170 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL [2009/09/18 19:36:21 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009/09/18 19:36:17 | 00,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT [2009/09/18 19:36:14 | 26,640,7936 | -HS- | M] () -- C:\hiberfil.sys [2009/09/18 19:14:29 | 00,011,264 | ---- | M] () -- C:\WINDOWS\System32\drivers\uzi0odaz.sys [2009/09/18 18:53:54 | 00,037,376 | ---- | M] () -- C:\Documents and Settings\TuongVy\Desktop\trojan remove.doc [2009/09/18 18:48:27 | 00,514,560 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\TuongVy\Desktop\OTL.exe [2009/09/18 18:14:33 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\TuongVy\Desktop\HijackThis.lnk [2009/09/18 15:00:07 | 00,000,412 | ---- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for TuongVy.job [2009/09/18 13:37:13 | 00,000,434 | ---- | M] () -- C:\WINDOWS\tasks\At1.job [2009/09/18 07:00:32 | 00,000,650 | ---- | M] () -- C:\WINDOWS\DELLSTAT.INI [2009/09/16 05:20:32 | 00,131,304 | ---- | M] () -- C:\Documents and Settings\TuongVy\Application Data\GDIPFONTCACHEV1.DAT [2009/09/14 20:19:39 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2009/09/10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009/09/10 14:53:50 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2009/09/09 21:17:22 | 00,001,986 | ---- | M] () -- C:\Documents and Settings\TuongVy\My Documents\ROFLMAO.html [2009/08/29 10:20:10 | 00,508,688 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009/08/29 08:26:43 | 00,001,552 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Reader.lnk [2009/08/28 16:38:20 | 24,689,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe ========== LOP Check ========== [2009/08/10 11:22:09 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data [2009/05/15 01:01:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} [2009/01/11 11:28:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avg7 [2006/02/27 02:22:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software [2005/05/29 09:03:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Dell [2006/01/29 20:40:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Motive [2006/01/29 20:42:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSN6 [2008/12/18 18:39:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files [2004/07/27 14:49:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap [2003/08/24 15:46:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI [2006/07/05 20:06:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Teleca [2008/11/25 19:42:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP [2004/09/23 16:37:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia [2008/04/29 16:22:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint [2009/09/18 01:11:32 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\TuongVy\Application Data [2007/01/23 15:27:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\acccore [2007/01/23 15:36:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Aim [2007/04/29 09:25:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Chessmaster Challenge [2006/02/02 21:06:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Corel [2007/12/12 17:16:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\dvdcss [2009/03/31 20:57:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Hamachi [2003/12/16 06:17:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Jasc [2009/09/18 01:11:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\kfogetgj [2006/08/27 17:25:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Leadertech [2009/01/23 17:42:09 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\TuongVy\Application Data\Move Networks [2004/10/19 22:12:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\MSN6 [2006/01/29 20:49:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\MSNInstaller [2006/01/30 20:10:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Musicmatch [2008/03/10 14:09:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Nexon [2006/04/29 10:12:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Opera [2007/08/14 20:36:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Printer Info Cache [2004/01/11 16:01:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Roxio [2006/07/05 20:13:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Teleca [2009/06/17 10:53:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Tutor [2009/09/06 04:00:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\U3 [2007/01/13 18:44:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Viewpoint [2005/12/07 00:41:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\WeatherBug [2008/01/19 01:24:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\TuongVy\Application Data\Winff [2009/09/14 20:19:39 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job [2009/09/18 13:37:13 | 00,000,434 | ---- | M] () -- C:\WINDOWS\Tasks\At1.job [2002/08/29 05:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\DESKTOP.INI [2009/09/18 15:00:07 | 00,000,412 | ---- | M] () -- C:\WINDOWS\Tasks\Norton Security Scan for TuongVy.job [2009/09/18 19:36:21 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 < End of report > OTL Extras logfile created on: 9/18/2009 7:47:48 PM - Run 1 OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\TuongVy\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 254.00 Mb Total Physical Memory | 103.18 Mb Available Physical Memory | 40.62% Memory free 1002.93 Mb Paging File | 770.68 Mb Available in Paging File | 76.84% Paging File free Paging file location(s): C:\pagefile.sys 762 1000 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 38.25 Gb Total Space | 10.15 Gb Free Space | 26.53% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: D7SDGB31 Current User Name: TuongVy Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation) .hta [@ = htafile] -- Reg Error: Key error. File not found .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found chm.file [open] -- "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found htafile [open] -- Reg Error: Key error. htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" "%1" (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" "%1" (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft) Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" "%1" (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "57983:TCP" = 57983:TCP:*:Enabled:Pando Media Booster "57983:UDP" = 57983:UDP:*:Enabled:Pando Media Booster "57658:TCP" = 57658:TCP:*:Enabled:Pando Media Booster "57658:UDP" = 57658:UDP:*:Enabled:Pando Media Booster ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) "C:\Program Files\Yahoo!\Messenger\YPager.exe" = C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Disabled:Yahoo! Messenger -- File not found "C:\Program Files\Internet Explorer\iexplore.exe" = C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer -- (Microsoft Corporation) "C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC) "C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC -- (mIRC Co. Ltd.) "C:\Program Files\YVD\n00b-IRC.exe" = C:\Program Files\YVD\n00b-IRC.exe:*:Disabled:n00b-IRC -- File not found "C:\Program Files\YVD\YGO Virtual Desktop V086.exe" = C:\Program Files\YVD\YGO Virtual Desktop V086.exe:*:Enabled:YGO Virtual Desktop Executable -- File not found "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.) "C:\Program Files\BitLord\BitLord.exe" = C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord -- (www.BitLord.com) "C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation) "C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation) "C:\WINDOWS\SYSTEM32\fxsclnt.exe" = C:\WINDOWS\SYSTEM32\fxsclnt.exe:*:Enabled:Microsoft Fax Console -- (Microsoft Corporation) "C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM -- (AOL LLC) "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) "C:\Program Files\Grisoft\MapleStory.exe" = C:\Program Files\Grisoft\MapleStory.exe:*:Disabled:MapleStory -- File not found "C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player -- () "C:\Program Files\Common Files\aol\Loader\aolload.exe" = C:\Program Files\Common Files\aol\Loader\aolload.exe:*:Enabled:AOL Loader -- (AOL LLC) "C:\WINDOWS\SYSTEM32\DRIVERS\svchost.exe" = C:\WINDOWS\SYSTEM32\DRIVERS\svchost.exe:*:Disabled:Vvjbjmor Ewetyty -- File not found "C:\Program Files\Yugioh Virtual Dueling\Yugioh Virtual Desktop 9.exe" = C:\Program Files\Yugioh Virtual Dueling\Yugioh Virtual Desktop 9.exe:*:Enabled:YGO Virtual Desktop Executable -- File not found "C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- File not found "C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.) "C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.) "C:\Program Files\USMLE\2009FredV2Step1\FredV2Orient.exe" = C:\Program Files\USMLE\2009FredV2Step1\FredV2Orient.exe:*:Enabled:FredV2Orient -- () "C:\Program Files\USMLE\2009FredV2Step1\NED.exe" = C:\Program Files\USMLE\2009FredV2Step1\NED.exe:*:Enabled:NBME Exam Driver -- (NBME) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour "{099B096F-A916-4ECE-8EF2-A6E5F7C4D113}" = Veo Connect "{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = Lizardtech DjVu Control "{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center "{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert "{15CCBC5D-66A7-4131-8D36-E05F27B0E68F}" = Sibelius Scorch (ActiveX Only) "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{25EF00BE-F17B-11D6-88EA-000476CD2443}" = Verizon Online "{29FA18EE-BDA4-40DF-99A5-42A7D8CF6746}" = FRED "{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2 "{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10 "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3 "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java 6 Update 5 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting "{4468EF97-A253-4699-9E1C-88CAE2C6832D}" = ABBYY FineReader 5.0 Sprint "{44CDBD1B-89FB-4E02-8319-2A4C550F664A}" = RTC Client API v1.2 "{45AEEA61-04F8-11D6-8B35-0080C8F5C4AA}" = Veo Digital Studio "{47813E93-F2A0-484A-838E-47EC1B28D190}" = Adobe Stock Photos 1.0 "{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0 "{5E977DEC-5BB4-44C7-9FE5-9357D2DB4FCB}" = Disc2Phone "{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes "{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic "{64116298-93C5-401D-B06C-39D8E3338508}" = DAO "{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{6A136B9A-1895-436F-83F8-30D9C68BB6EA}" = Rhapsody Player Engine "{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0 "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX "{7B98B956-EF9E-4801-BAC5-AC55546139EE}" = Sony Ericsson Communication Center "{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper "{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox "{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage "{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content "{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization "{91130409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Small Business "{96E16100-A77F-4B31-B9AD-FFBA040EE1BD}" = Sound Blaster Live! "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9D98F245-3010-43C6-B3B0-67A464DA298E}" = ELNKInst "{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8 "{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support "{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader "{B7EF4BD8-CA13-11D5-AE3D-005004B8E30C}" = Digital Photo Navigator 1.0 "{BC019EBE-613F-491F-9A83-08E3E8A74CE6}" = EarthLink Free Trial "{C8E8D623-B163-48F7-9150-F824C8DCF064}" = 2009FredV2Step1 "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe "{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect "{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin "{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools "{F478DA38-C1D7-4A71-A690-8DEFA4EC5BCC}" = USB Mass Storage Package for Windows 2000-XP "{FADE1A2A-CF22-4E4D-A0E0-1187C24405B9}" = Sony Ericsson PC Suite 1.10.61 "{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement "3DGroove" = 3D Groove Playback Engine "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Shockwave Player" = Adobe Shockwave Player 11.5 "Adobe Type Manager 4.0" = Adobe Type Manager 4.0 "AdobeESD" = Adobe Download Manager 2.0 (Remove Only) "AIM_6" = AIM 6 "BitLord" = BitLord 1.1 "BREE5" = Brownstone Equation Editor 5 "CNXT_MODEM_PCI_VEN_14F1&DEV_2702" = Conexant SmartHSFi V92 56K DF PCI Modem "Coupon Printer for Windows4.0" = Coupon Printer for Windows "Dell AIO Printer A940" = Dell AIO Printer A940 "Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver "DellSupport" = Dell Support 5.0.0 (766) "EPSON Printer and Utilities" = EPSON Printer Software "HF_screensaver" = HF_screensaver "HijackThis" = HijackThis 2.0.2 "Hijackthis_is1" = Hijackthis 1.99.1 "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "InstallShield_{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs "InstallShield_{9D98F245-3010-43C6-B3B0-67A464DA298E}" = Earthlink Installer - uninstall 'Earthlink 5.0' entry first if present "kuririn_ss01_is1" = kuririn_ss01 "LimeWire" = LimeWire 4.18.8 "littletwinstar_is1" = littletwinstar "Looney Tunes - Speedy" = Looney Tunes - Speedy Screen Saver "Looney Tunes Valentines Day" = Looney Tunes Valentines Day Screen Saver "lt_dvd_ssaver1_post1028" = lt_dvd_ssaver1_post1028 Screen Saver "lt_dvd_ssaver2_post1028" = lt_dvd_ssaver2_post1028 Screen Saver "lt_vday_saver" = lt_vday_saver Screen Saver "LT_xmas_A_v2" = LT_xmas_A_v2 Screen Saver "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft Press Interactive Training" = Microsoft Interactive Training "mIRC" = mIRC "mm_saver.scr" = mm_saver ScreenSaver "Modem User Guide" = Modem User Guide "Mozilla Firefox (3.0.13)" = Mozilla Firefox (3.0.13) "Musicnotes Player_is1" = Musicnotes Player V1.23.1 and Viewer "MWSnap 3" = MWSnap 3 "My Melody Screensaver_is1" = My Melody Screensaver "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "pochacco_is1" = pochacco "Pop-Up Stopper Free Edition" = Pop-Up Stopper Free Edition "Scooby Doo Loch Ness" = Scooby Doo Loch Ness Screen Saver "ScoobyDooScreenSaver" = ScoobyDooScreenSaver Screen Saver "screen_gossomer" = screen_gossomer Screen Saver "Shockwave" = Shockwave "Tutor" = Tutor "USBCOMM&10AB&10C5" = USB Data Cable "Viewpoint Manager" = Viewpoint Manager (Remove Only) "ViewpointMediaPlayer" = Viewpoint Media Player "VLC media player" = VideoLAN VLC media player 0.8.6d "Winamp" = Winamp (remove only) "Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner "Windows Media Format Runtime" = Windows Media Format Runtime "Windows Media Player" = Windows Media Player 10 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinFF_is1" = WinFF 0.33 "WinRAR archiver" = WinRAR archiver "Yahoo! Messenger" = Yahoo! Messenger ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Move Networks Player - IE" = Move Networks Media Player for Internet Explorer "Usmleworld Sim Exam V2" = Usmleworld Sim Exam V2 "Usmleworld Step1 QBank V2" = Usmleworld Step1 QBank V2 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 9/13/2009 10:54:57 AM | Computer Name = D7SDGB31 | Source = ESENT | ID = 474 Description = wuauclt (3744) The database page read from the file "C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb" at offset 17764352 (0x00000000010f1000) for 4096 (0x00001000) bytes failed verification due to a page checksum mismatch. The expected checksum was 2899087093 (0xaccc8ef5) and the actual checksum was 2894892789 (0xac8c8ef5). The read operation will fail with error -1018 (0xfffffc06). If this condition persists then please restore the database from a previous backup. Error - 9/14/2009 1:08:11 PM | Computer Name = D7SDGB31 | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting module mshtml.dll, version 6.0.2900.5848, fault address 0x0012403c. Error - 9/14/2009 4:18:17 PM | Computer Name = D7SDGB31 | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting module ntdll.dll, version 5.1.2600.5755, fault address 0x0001168b. Error - 9/14/2009 5:59:00 PM | Computer Name = D7SDGB31 | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3. Error - 9/14/2009 9:08:25 PM | Computer Name = D7SDGB31 | Source = Application Hang | ID = 1002 Description = Hanging application firefox.exe, version 1.9.0.3498, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 9/16/2009 9:13:28 AM | Computer Name = D7SDGB31 | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting module jscript.dll, version 5.7.6002.22145, fault address 0x0001c20c. Error - 9/16/2009 1:26:38 PM | Computer Name = D7SDGB31 | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting module mshtml.dll, version 6.0.2900.5848, fault address 0x001fd3f3. Error - 9/16/2009 7:34:14 PM | Computer Name = D7SDGB31 | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting module flash9f.ocx, version 9.0.124.0, fault address 0x001b5ada. Error - 9/17/2009 6:19:16 AM | Computer Name = D7SDGB31 | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting module ntdll.dll, version 5.1.2600.5755, fault address 0x000100e8. Error - 9/18/2009 3:10:26 AM | Computer Name = D7SDGB31 | Source = Application Hang | ID = 1002 Description = Hanging application WINWORD.EXE, version 10.0.6854.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. [ System Events ] Error - 9/18/2009 8:36:32 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000 Description = The Protected Storage service failed to start due to the following error: %%2 Error - 9/18/2009 8:36:38 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7026 Description = The following boot-start or system-start driver(s) failed to load: Beep Error - 9/18/2009 8:38:03 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000 Description = The Protected Storage service failed to start due to the following error: %%2 Error - 9/18/2009 8:38:03 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000 Description = The Protected Storage service failed to start due to the following error: %%2 Error - 9/18/2009 8:41:17 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000 Description = The Protected Storage service failed to start due to the following error: %%2 Error - 9/18/2009 8:41:17 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000 Description = The Protected Storage service failed to start due to the following error: %%2 Error - 9/18/2009 8:41:17 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000 Description = The Protected Storage service failed to start due to the following error: %%2 Error - 9/18/2009 8:41:17 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000 Description = The Protected Storage service failed to start due to the following error: %%2 Error - 9/18/2009 8:43:34 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000 Description = The Protected Storage service failed to start due to the following error: %%2 Error - 9/18/2009 8:43:34 PM | Computer Name = D7SDGB31 | Source = Service Control Manager | ID = 7000 Description = The Protected Storage service failed to start due to the following error: %%2 < End of report >
Attached File(s)
virusinfo_syscheck.zip ( 34.32K )
Number of downloads: 7
virusinfo_syscure.zip ( 34.82K )
Number of downloads: 13 |
|
|
Sep 19 2009, 11:21 AM
Post
#4
|
|
![]() Malware Removal Dude Posts: 1,350 From: California OS: XP / Vista |
Thank you for that
STEP 1 Run OTL
STEP 2
Please restart your computer again. STEP 3 After rebooting, run OTL again and click on the Quick Scan button at the top. Copy and Paste the results of this scan in your next reply. STEP 4 How's the computer running? Are you experiencing any symptoms? If you are still being redirected on the internet, do you get the same symptoms while using Internet Explorer instead of Firefox? |
|
|
Sep 19 2009, 08:29 PM
Post
#5
|
|
|
New Member ![]() Posts: 8 OS: windows xp |
I tried running olt fix but my computer keeps on stalling/freezing. the last try took over 10 hours with a blank white box that was olt and my desktop background on the back. I couldn't shut off the computer, and had to turn off then on electricity to restart the computer. After the computer restarted, there are a lot of new icons/items on the desktop that were not there before with names of different files. I tried going into Drive C looking for olt folder to see what is reported but there is nothing in the subfolders.
what should i do now? do i try to rerun the olt again or go to malawarebytes? |
|
|
Sep 20 2009, 09:59 AM
Post
#6
|
|
![]() Malware Removal Dude Posts: 1,350 From: California OS: XP / Vista |
That's alright, let's try to get it with the other tool you downloaded.
STEP 1 Close all your programs and disable all your security programs before proceeding.
STEP 2
Please restart your computer again. STEP 3 After rebooting, run OTL.exe and click on the Quick Scan button at the top. Copy and Paste the results of this scan in your next reply. STEP 4 How's the computer running? Are you experiencing any symptoms? If you are still being redirected on the internet, do you get the same symptoms while using Internet Explorer instead of Firefox? This post has been edited by NeonFx: Sep 20 2009, 10:01 AM |
|
|
Sep 20 2009, 07:15 PM
Post
#7
|
|
|
New Member ![]() Posts: 8 OS: windows xp |
I ran avz as instructed and restarted my computer. When my computer restarted, a box that says "found new hardware wizard" showed up asking me to connect to windows update to serach for software. when i clicked cancel to go to my desktop, i have a box that says "malwarebytes' anti-malware"- "run-time error '372': failed to load control 'vbalGrid' from vbalsgrid6.ocx. your version may be outdated. make sure you are using the version of control that was provided with your application." My desktop background days "active desktop recovery", to restore active desktop, click on the restore active desktop bar.
When I tried to connect to the internet with my internet connection setting, there were none there. before, there were LAN connection option, now there is nothing there. I restarted my computer again, and was told the same thing, except this time there is no start-up tab at the lower left corner, or any taskbar at all. for me to restart the computer, i have to manually cut off the electricity. also, i couldn't open any files or restore my active desktop. There are also shaded files on my desktop from the runs with OTL. what should i do with those? is it ok for me to delete them? |
|
|
Sep 20 2009, 07:32 PM
Post
#8
|
|
![]() Malware Removal Dude Posts: 1,350 From: California OS: XP / Vista |
Hi little_angel. I'm sorry to hear this has happened, there must be an infection on your system that I either missed, or cannot see, that is actively defending itself and the other infections on your system. Nothing in the fix I gave you can cause any of that. I will go over your logs once again and consult with my teacher about this.
My teacher has left for the day so I will have a new fix for you sometime tomorrow morning my time. In the meantime, could you attempt to boot into safemode and let me know if you can see your taskbar and run programs in that mode? To boot into SafeMode you need to repeatedly press the F8 key on your keyboard as soon as you press the power button until a black and white menu comes up. Use your arrows and enter key to select SafeMode. Once it loads, log into your account and click on Yes when prompted if you wish to enter Safe Mode. Apart from that, try to leave the computer alone while I decide on our next move. This post has been edited by NeonFx: Sep 20 2009, 07:39 PM |
|
|
Sep 20 2009, 08:00 PM
Post
#9
|
|
|
New Member ![]() Posts: 8 OS: windows xp |
When I entered into safemode, there is still the box that says "FOUND NEW HARDWARE WIZARD"-Welcome to the Found New HArdware Wizard......
Even in safemode, i still cannot find my Taskbar, still had the malwarebyte' run-time error '372'. still can't connect to the internet. when i clicked on the ie icon, it opens up but showed that it cannot connect to ms n homepage because it is not connected to the internet. When it was not in safemode, i got the error box telling me to report problem to microsoft. still can't connect to the internet. is it possible to revert back to the state my computer was in prior to running the last avz fix? |
|
|
Sep 21 2009, 01:49 PM
Post
#10
|
|
![]() Malware Removal Dude Posts: 1,350 From: California OS: XP / Vista |
Hi again little_angel. Thank you for your patience. Let's try to recover your computer to an earlier state as you suggested.
The easiest way to do this is:
If you cannot get the System Restore applet to run, use your keyboard to open it by holding down the Windows Key and pressing "R". This will open a run dialog where you should type in the following: C:\windows\system32\restore\rstrui.exe And press Enter to run the applet. If that doesn't work, try restoring to an even earlier time. When your computer restarts, and if this solved our problem, please: Open OTL.exe and run a scan by clicking on the Quick Scan button at the top. Copy and Paste the results of this scan here. Also, I will need to know the exact Make and Model for your system. We may have to obtain the necessary drivers to reinstall your network device. The "Found New Hardware" wizard is probably attempting to reinstall your networking device. Let it attempt to automatically find the drivers for the device the next time you see it. If it is not able to we will have to do so manually. |
|
|
Sep 21 2009, 04:03 PM
Post
#11
|
|
|
New Member ![]() Posts: 8 OS: windows xp |
Hi,
I tried to turn on my computer but instead of turning on, there's this eeeeeeeeeee sound coming from the machine and nothing comes up. the computer is a Dell 2400. |
|
|
Sep 21 2009, 04:14 PM
Post
#12
|
|
|
New Member ![]() Posts: 8 OS: windows xp |
I got the computer to power up. however, it won't let me go to safemode option when i pressed f8. instead, it goes directly to the desktop. the found new hardware box popped up. i chose the "find hardware this time" option. It found a hardware "UNKNOWN" and asks me to install the CD that comes with the drive but i'm not sure what that is.
|
|
|
Sep 21 2009, 08:43 PM
Post
#13
|
|
|
New Member ![]() Posts: 8 OS: windows xp |
I was able to get my computer into safemode, but when i chose to run system restore instead of safemode, it tells me to restart my computer and says that restore will not protect my computer.
btw, my computer is a Dell Dimension 2400, running on XP pro service pack 3 I've been trying to run system restore, but either in safemode or normal, i keep getting a box saying "system restore is not able to protect your computer. Please restart your computer, and then run system restore again." This post has been edited by little_angel: Sep 21 2009, 08:47 PM |
|
|
Sep 22 2009, 12:00 PM
Post
#14
|
|
![]() Malware Removal Dude Posts: 1,350 From: California OS: XP / Vista |
I'm very sorry to say this little_angel, but what you are describing, especially the continuous beeping sound when you turn your computer on, is a definite sign of a hardware malfunction that actually has nothing to with malware. You computer must have been right on the edge of its life when we started treating this as a virus problem, and will probably fail soon regardless of what we do.
I strongly suggest that you take your computer into a shop as there is nothing else I can do to troubleshoot your situation. Hardware issues such as the one you describe are extremely difficult to troubleshoot over the internet as they require opening up your computer and replacing/testing different parts of it. If after taking it to the shop and getting the hardware problem fixed, you wish to continue analyzing your computer for malware, feel free to send me a private message to reopen this topic once it's closed. |
|
|
Sep 26 2009, 06:55 AM
Post
#15
|
|
![]() GeekU Moderator Posts: 19,166 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
6 / 223 | 18th December 2005 - 01:06 PM derdy started - last by Excal |
|||||
![]() |
3 / 116 | 3rd May 2009 - 04:40 PM chitown4lyfe started - last by fenzodahl512 |
|||||
![]() |
11 / 341 | 2nd May 2009 - 01:52 AM Cougar1966 started - last by fenzodahl512 |
|||||
![]() |
15 / 306 | 7th October 2009 - 12:40 PM BuzzBoy22 started - last by hammerman |
|||||
|
Time is now: 21st November 2009 - 09:24 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising