Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
2 Pages V   1 2 >  
Closed TopicStart new topic
Rtvscan.exe uses 100% CPU and infected with Trojan.Vundo [Solved]
BuzzBoy22
post Sep 27 2009, 11:16 PM
Post #1


New Member
*
Posts: 9
OS: XP



Thank you for your help! I seem to have a cascading problem that is resulting in a constant 100% CPU usage and repeated infection with Trojan.Vundo.

Rtvscan.exe loads immediately upon boot and consumes between 50-100% of the CPU.

I have run MBAM, Symantec AV, SpyBot Search & Destroy repeatedly. MBAM continues to find multiple instances of Trojan Vundo, but it reappears after rebooting. Symantec Quick Scan finds "tenedefi.dll" and attempts to remove it every time I reboot, bu it reappears.

I have completed the Malware and Spyware Cleaning Guide. I could not run RootRepeal. When I try to run it I get an initialization screen and nothing else. It does not open no matter how long I wait.

Here are the OTL and MBAM log files.

------------------------------------------------------------------------------------

OTL logfile created on: 9/27/2009 6:12:36 PM - Run 1
OTL by OldTimer - Version 3.0.16.0 Folder = C:\Documents and Settings\JD\My Documents\JD's Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.41 Gb Available Physical Memory | 27.07% Memory free
2.11 Gb Paging File | 1.21 Gb Available in Paging File | 57.35% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 180.00 Gb Total Space | 34.27 Gb Free Space | 19.04% Space Free | Partition Type: NTFS
Drive D: | 6.29 Gb Total Space | 1.12 Gb Free Space | 17.85% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DESKTOP
Current User Name: JD
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2004/11/03 21:38:10 | 00,413,696 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe
PRC - [2005/01/03 06:40:42 | 00,854,528 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2006/03/07 13:03:02 | 00,169,632 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PRC - [2004/11/03 21:38:10 | 00,413,696 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe
PRC - [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2006/03/07 13:02:34 | 00,192,160 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PRC - [2009/01/29 15:40:22 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe
PRC - [2009/06/30 09:11:00 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
PRC - [2008/09/16 12:03:18 | 00,169,312 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
PRC - [2009/05/29 13:41:26 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2006/02/23 11:41:02 | 00,100,032 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2006/03/17 06:34:12 | 00,030,448 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe
PRC - [2008/04/13 14:12:18 | 00,084,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehSched.exe
PRC - [2009/05/01 14:35:54 | 00,181,544 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
PRC - [2005/02/02 16:44:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\HP\KBD\KBD.EXE
PRC - [2004/11/03 21:10:00 | 00,344,064 | ---- | M] (ATI Technologies, Inc.) -- C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
PRC - [2003/08/14 14:11:32 | 00,139,264 | ---- | M] (Alcor Micro, Corp.) -- C:\Program Files\Multimedia Card Reader\shwicon2k.exe
PRC - [2003/05/23 00:55:38 | 00,483,328 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\System32\hphmon05.exe
PRC - [2005/01/12 09:54:58 | 00,241,664 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
PRC - [2004/07/29 02:53:58 | 00,053,248 | ---- | M] (GEAR Software) -- C:\WINDOWS\System32\GEARSec.exe
PRC - [2002/10/07 05:23:20 | 00,090,112 | ---- | M] () -- C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
PRC - [2006/03/17 06:34:30 | 00,124,656 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\VPTray.exe
PRC - [2004/11/22 17:20:54 | 01,126,400 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe
PRC - [2006/03/07 13:02:14 | 00,053,408 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2000/09/22 10:13:40 | 00,227,328 | ---- | M] (Visioneer Inc.) -- C:\Program Files\Visioneer\PaperPort\FBDirect.exe
PRC - [2006/07/07 13:14:38 | 00,576,320 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliType Pro\itype.exe
PRC - [2006/03/17 06:34:12 | 00,024,816 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DoScan.exe
PRC - [2006/07/07 13:15:07 | 00,600,896 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliPoint\ipoint.exe
PRC - [2008/11/24 22:31:10 | 29,263,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
PRC - [2002/08/28 15:39:50 | 00,455,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE
PRC - [2009/05/01 14:35:10 | 00,185,640 | ---- | M] (Seagate LLC) -- C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
PRC - [2009/09/08 21:09:42 | 00,305,440 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2007/09/26 23:23:28 | 02,211,840 | ---- | M] (Ziff-Davis Media, Inc.) -- C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe
PRC - [2009/03/05 16:07:20 | 02,260,480 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/13 21:10:40 | 00,342,848 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\DNA\btdna.exe
PRC - [2007/03/11 21:26:24 | 00,210,520 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PRC - [2008/05/26 22:19:14 | 00,123,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\WindowsSearch.exe
PRC - [2009/02/16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2005/08/07 18:54:00 | 00,167,936 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe
PRC - [2008/11/24 22:31:08 | 00,239,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
PRC - [2008/11/24 22:31:12 | 00,087,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2006/03/17 06:34:20 | 01,799,408 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe
PRC - [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe
PRC - [2009/02/16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe
PRC - [2001/05/01 17:06:22 | 00,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MsPMSPSv.exe
PRC - [2004/11/22 17:04:14 | 01,273,856 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
PRC - [2009/09/08 21:09:30 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2008/04/13 14:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wscntfy.exe
PRC - [2009/09/09 19:15:54 | 00,908,280 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2004/10/08 11:52:32 | 00,221,184 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\System32\LVComsX.exe
PRC - [2009/09/27 18:09:56 | 00,518,144 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\JD\My Documents\JD's Downloads\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/09/16 12:03:18 | 00,169,312 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor7.0 [Auto | Running])
SRV - [2009/05/29 13:41:26 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2004/11/03 21:38:10 | 00,413,696 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])
SRV - [2004/11/03 21:10:00 | 00,516,096 | ---- | M] () -- C:\WINDOWS\System32\ati2sgag.exe -- (ATI Smart [Auto | Stopped])
SRV - [2006/02/23 11:41:02 | 00,100,032 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler [Auto | Running])
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2006/03/07 13:02:34 | 00,192,160 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr [Auto | Running])
SRV - [2006/03/07 13:03:02 | 00,169,632 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr [Auto | Running])
SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2006/03/17 06:34:12 | 00,030,448 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch [Auto | Running])
SRV - [2008/04/13 14:12:18 | 00,084,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehSched.exe -- (ehSched [Auto | Running])
SRV - [2008/10/16 21:11:00 | 00,651,720 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service [On_Demand | Stopped])
SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2009/05/01 14:35:54 | 00,181,544 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe -- (FreeAgentGoNext Service [Auto | Running])
SRV - [2004/07/29 02:53:58 | 00,053,248 | ---- | M] (GEAR Software) -- C:\WINDOWS\System32\GEARSec.exe -- (GEARSecurity [Auto | Running])
SRV - [2009/08/07 12:44:18 | 00,045,816 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper [On_Demand | Stopped])
SRV - [2009/01/29 15:40:22 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1c9827bbeb07656 [Auto | Stopped])
SRV - [2007/01/03 15:40:21 | 00,136,120 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2008/04/13 14:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2007/05/16 22:13:44 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -- (hpqcxs08 [On_Demand | Running])
SRV - [2007/05/16 22:13:44 | 00,131,072 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -- (hpqddsvc [Auto | Running])
SRV - [2007/05/16 22:13:08 | 00,602,112 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL -- (HPSLPSVC [Auto | Running])
SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2005/01/03 06:40:42 | 00,854,528 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv [Auto | Running])
SRV - [2008/10/10 05:45:26 | 00,013,088 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService [Auto | Stopped])
SRV - [2009/09/08 21:09:30 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2009/09/27 10:42:25 | 01,028,432 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service [On_Demand | Stopped])
SRV - [2006/02/23 11:41:02 | 02,045,632 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE -- (LiveUpdate [On_Demand | Stopped])
SRV - [2008/11/24 22:31:10 | 29,263,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$SQLEXPRESS [Auto | Running])
SRV - [2008/11/24 22:31:08 | 00,045,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper [Disabled | Stopped])
SRV - [2006/10/31 13:56:24 | 00,043,520 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\System32\HPZinw12.dll -- (Net Driver HPZ12 [Auto | Running])
SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2004/11/22 17:04:14 | 01,273,856 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe -- (Norton Ghost [Auto | Running])
SRV - [2008/11/04 01:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2006/10/31 13:56:28 | 00,052,736 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\System32\HPZipm12.dll -- (Pml Driver HPZ12 [Auto | Running])
SRV - [2005/08/07 18:54:00 | 00,167,936 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe -- (RichVideo [Auto | Running])
SRV - [2006/03/17 06:34:24 | 00,115,952 | ---- | M] (symantec) -- C:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam [On_Demand | Stopped])
SRV - [2006/01/24 20:06:58 | 00,214,720 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc [On_Demand | Stopped])
SRV - [2006/02/06 12:50:24 | 01,160,848 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc [On_Demand | Stopped])
SRV - [2008/11/24 22:31:08 | 00,239,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser [Auto | Running])
SRV - [2008/11/24 22:31:12 | 00,087,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter [Auto | Running])
SRV - [2006/03/17 06:34:20 | 01,799,408 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus [Auto | Running])
SRV - [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running])
SRV - [2009/02/16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon [Auto | Running])
SRV - [2001/05/01 17:06:22 | 00,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MsPMSPSv.exe -- (WMDM PMSP Service [Auto | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 41
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.96
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.32.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: statusbar@toodledo.com:1.60
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/24 03:04:09 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2009/09/08 10:18:41 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/09 19:16:03 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/09/09 19:16:03 | 00,000,000 | ---D | M]

[2008/06/18 18:29:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Extensions
[2008/06/18 18:29:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/09/27 11:31:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions
[2008/04/20 09:59:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{1AF3FC34-0725-4485-A939-6B40EB7CA96A}
[2009/06/26 19:17:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/05/02 11:19:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2009/08/16 20:53:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2009/03/20 17:12:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\statusbar@toodledo.com
[2008/10/12 18:10:36 | 00,000,276 | ---- | M] () -- C:\Documents and Settings\JD\Application Data\Mozilla\FireFox\Profiles\v2nyddyy.default\searchplugins\search.xml
[2009/09/27 11:31:13 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/09/09 19:16:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/12/11 19:32:04 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2009/09/09 19:15:53 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/09/09 19:15:53 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/03/19 19:23:20 | 00,114,688 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2008/09/03 14:11:24 | 00,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\mozilla firefox\plugins\npbittorrent.dll
[2008/06/17 20:43:04 | 00,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2007/10/11 14:17:50 | 01,435,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/09/09 19:15:56 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2007/05/10 22:52:34 | 00,095,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2006/09/07 10:08:58 | 00,618,496 | ---- | M] (Pixami) -- C:\Program Files\mozilla firefox\plugins\NPPxIm.dll
[2006/09/07 10:08:58 | 00,819,200 | ---- | M] (Pixami) -- C:\Program Files\mozilla firefox\plugins\NPPxPrn.dll
[2009/09/09 19:02:21 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/09/09 19:02:21 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2007/12/25 00:02:38 | 00,024,673 | ---- | M] (Check Point Software Technologies Ltd.) -- C:\Program Files\mozilla firefox\plugins\NPZoneSB.dll
[2009/08/07 12:44:18 | 00,030,400 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\mozilla firefox\plugins\np_gp.dll
[2009/08/15 07:48:37 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/08/15 07:48:37 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/08/15 07:48:37 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/15 07:48:37 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/08/15 07:48:37 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/15 07:48:37 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/08/15 07:48:37 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (319151 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10945 more lines...
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SpywareBlock Class) - {0A87E45F-537A-40B4-B812-E2544C21A09F} - Reg Error: Value error. File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe ()
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HP Component Manager] C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [KBD] C:\HP\KBD\KBD.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [Norton Ghost 9.0] C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PP7600usb] C:\Program Files\Visioneer\PaperPort\FBDirect.exe (Visioneer Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE ()
O4 - HKLM..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Startup Cop Pro Startup Launcher] C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe (Ziff-Davis Media, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Zone Labs Security.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - Startup: C:\Documents and Settings\JD\Start Menu\Programs\Startup\TempClean.bat ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: &Translate English Word - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate Page into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll (Google Inc.)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: PokerTime.net Poker - {E28AB5C9-B58F-4512-AF80-29001BC5A29D} - C:\Program Files\PokerTimeGuestMPP\MPPoker.exe (Microgaming)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: 69 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://activation.rr.com/install/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {1B9935E4-8A50-4DD8-BD09-A7518723BF97} https://quicken.ehosts.net/netagent/objects/custappx3.CAB (eAssist NetAgent Customer ActiveX Control version 3)
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab (LSSupCtl Class)
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} http://asp.mathxl.com/wizmodules/testgen/i...GenXInstall.cab (TTestGenXInstallObject)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://spaces.msn.com//PhotoUpload/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1231725258781 (MUWebControl Class)
O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll (InstallHelper Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll (There Voice Trainer)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab (Pearson Installation Assistant 2)
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} http://download.zonelabs.com/bin/promotion...ctor/WebSWK.cab (WebSpyWareKiller Class)
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} http://download.zonelabs.com/bin/promotion...ctor/WebAAS.cab (Anonymizer Anti-Spyware Scanner)
O16 - DPF: {AAF421E6-7914-430A-9981-72B31AFF3BF4} file://c:\Program Files\There\ThereClient\ThereLauncher.dll (There Launcher)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse...pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} https://www-secure.symantec.com/techsupp/asa/SymAData.cab (ActiveDataInfo Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D44C75D8-C827-473E-8F68-A77E42500782} http://www.samsphotoclub.com/upload/WebUploadClient.cab (Uploader Class)
O16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} http://asp.mathxl.com/books/_Players/EconPlayer.cab (Pearson MyEconLab Player Control)
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} http://216.249.24.60/code/iPIX-ImageWell-ipix.cab (iPIX Media Send Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.25.227.55 209.18.47.61 24.25.227.53
O18 - Protocol\Handler\bw+0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw+0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\offline-8876480 {9EB19210-0033-48C0-94F0-164D35CB93DB} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\windows\system32\gisisema.dll) - C:\WINDOWS\System32\gisisema.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\) - C:\WINDOWS\System32 [2009/09/27 17:57:52 | 00,000,000 | ---D | M]
O20 - AppInit_DLLs: (c:\windows\system32\yudegoku.dll) - C:\WINDOWS\System32\yudegoku.dll File not found
O20 - AppInit_DLLs: (tenedefi.dll) - C:\WINDOWS\System32\tenedefi.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\System32\NavLogon.dll (Symantec Corporation)
O21 - SSODL: ganokiboy - {324fc3bb-4f3e-4c51-84b7-1689cfe42ed0} - C:\WINDOWS\System32\yudegoku.dll File not found
O21 - SSODL: kawuhesud - {de4e9e38-28ca-4548-8ac1-ad002276dd90} - C:\WINDOWS\System32\gisisema.dll File not found
O22 - SharedTaskScheduler: {324fc3bb-4f3e-4c51-84b7-1689cfe42ed0} - tokatiluy - C:\WINDOWS\System32\yudegoku.dll File not found
O22 - SharedTaskScheduler: {de4e9e38-28ca-4548-8ac1-ad002276dd90} - tokatiluy - C:\WINDOWS\System32\gisisema.dll File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/12/16 19:45:52 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2002/09/11 03:02:32 | 00,000,045 | -HS- | M] () - D:\Autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{391dd251-46bc-11dd-b7f4-000ea6c3bfc8}\Shell\AutoRun\command - "" = .\Encryption Tool\MaxtorEncryption.exe
O33 - MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\AutoRun\command - "" = F:\PortableRoboForm.exe -- File not found
O33 - MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\RoboForm2Go\command - "" = F:\PortableRoboForm.exe -- File not found
O33 - MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\AutoRun\command - "" = J:\Autorun.exe -- File not found
O33 - MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell00\Command - "" = J:\Autorun.exe -- File not found
O33 - MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell01\Command - "" = J:\Autorun.exe -- File not found
O33 - MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell02\Command - "" = J:\Autorun.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)

========== Files/Folders - Created Within 14 Days ==========

[2009/09/27 17:57:55 | 16,099,45088 | -HS- | C] () -- C:\hiberfil.sys
[2009/09/27 15:47:27 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2009/09/27 14:20:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/09/27 14:19:31 | 00,000,622 | ---- | C] () -- C:\Documents and Settings\JD\Desktop\NTREGOPT.lnk
[2009/09/27 14:19:31 | 00,000,603 | ---- | C] () -- C:\Documents and Settings\JD\Desktop\ERUNT.lnk
[2009/09/27 14:19:29 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/09/27 13:10:24 | 00,000,000 | ---D | C] -- C:\VundoFix Backups
[2009/09/27 13:02:28 | 00,001,559 | ---- | C] () -- C:\Documents and Settings\JD\Desktop\CCleaner.lnk
[2009/09/27 13:02:26 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009/09/27 11:24:43 | 03,550,592 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\JD\Desktop\iexplore.exe
[2009/09/25 05:56:21 | 00,000,095 | ---- | C] () -- C:\WINDOWS\wininit.ini

========== Files - Modified Within 14 Days ==========

[2009/09/27 18:18:09 | 00,011,168 | -H-- | M] () -- C:\WINDOWS\System32\mehudebe
[2009/09/27 18:17:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/09/27 18:04:46 | 00,350,197 | -H-- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2009/09/27 17:58:44 | 00,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/09/27 17:58:43 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/09/27 17:58:00 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/09/27 17:57:55 | 16,099,45088 | -HS- | M] () -- C:\hiberfil.sys
[2009/09/27 17:56:38 | 04,401,936 | -H-- | M] () -- C:\Documents and Settings\JD\Local Settings\Application Data\IconCache.db
[2009/09/27 16:30:01 | 00,000,966 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006UA.job
[2009/09/27 15:16:16 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/09/27 14:19:31 | 00,000,622 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\NTREGOPT.lnk
[2009/09/27 14:19:31 | 00,000,603 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\ERUNT.lnk
[2009/09/27 13:02:28 | 00,001,559 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\CCleaner.lnk
[2009/09/27 11:24:48 | 03,550,592 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\JD\Desktop\iexplore.exe
[2009/09/27 10:43:19 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/09/27 09:30:00 | 00,000,914 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006Core.job
[2009/09/27 04:00:15 | 00,000,804 | ---- | M] () -- C:\WINDOWS\tasks\Incremental Backup.job
[2009/09/25 16:58:50 | 00,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/09/25 05:56:21 | 00,000,095 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2009/09/22 09:15:28 | 00,000,768 | ---- | M] () -- C:\WINDOWS\tasks\Media Backup Schedule.job
[2009/09/18 15:35:23 | 00,002,272 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\Google Chrome.lnk
[2009/09/14 15:27:52 | 00,000,832 | ---- | M] () -- C:\WINDOWS\tasks\Full Backups.job

========== LOP Check ==========

[2009/09/27 11:42:58 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/03/27 19:12:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/02/03 23:42:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/09/09 19:25:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/01/25 10:40:14 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/04/09 19:04:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2005/04/10 06:27:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{A695AD8D-651B-4C8A-91DF-51F853449A57}
[2004/12/29 19:20:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ahead
[2008/04/20 14:23:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink
[2007/12/31 14:24:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2008/10/17 18:50:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\espionServerData
[2008/10/17 17:36:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2009/01/24 17:26:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intuit
[2007/10/01 16:43:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2003/12/16 23:06:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Motive
[2006/01/05 10:18:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PureEdge
[2005/03/10 15:28:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RoboForm
[2003/12/16 19:51:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI
[2009/09/01 22:35:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2005/09/19 20:49:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Support.com
[2008/10/13 08:54:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/12/30 22:23:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tenebril
[2005/11/26 13:07:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia
[2004/12/30 14:55:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/11/14 22:02:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/06/08 17:58:13 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\JD\Application Data
[2007/12/31 15:31:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\2K Games
[2007/12/30 22:11:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\AccurateRip
[2004/12/29 19:49:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Ahead
[2007/12/01 14:33:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Amazon
[2009/01/17 16:22:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Any Video Converter
[2004/12/29 16:44:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\ArcSoft
[2009/08/02 20:43:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\BitTorrent
[2007/12/28 15:35:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\BookmarkBridge
[2004/11/14 11:07:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Common Files
[2008/04/20 14:23:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\CyberLink
[2009/09/27 18:11:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\DNA
[2009/08/03 05:11:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\DVD Flick
[2009/06/11 19:56:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\dvdcss
[2004/11/02 15:30:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\EuroTalk
[2005/08/21 11:48:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\FotoWire
[2008/06/29 19:22:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\gtk-2.0
[2007/11/25 15:09:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\interMute
[2004/09/10 15:48:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\InterVideo
[2008/07/22 18:02:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Intuit
[2009/02/07 20:01:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\IObit
[2008/01/05 15:59:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\iPhoneRingToneMaker
[2004/11/02 12:45:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\IsolatedStorage
[2006/10/14 20:15:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\LaCie
[2007/01/26 17:21:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Leadertech
[2008/12/16 20:26:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\LimeWire
[2005/12/22 12:17:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Microgaming
[2004/08/24 14:37:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Motive
[2005/08/27 06:44:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Musicmatch
[2007/07/27 22:45:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\NGC_IKTS
[2005/12/24 11:01:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\OLYMPUS
[2009/01/16 09:56:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\PC Magazine Utilities
[2008/10/17 18:52:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.1
[2006/05/28 08:05:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Premiere
[2006/01/05 10:18:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\PureEdge
[2007/12/13 22:26:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Roxio
[2003/12/16 23:23:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\SampleView
[2004/12/05 13:02:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\spweng
[2007/12/30 22:23:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Tenebril
[2009/09/21 21:20:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\U3
[2004/12/30 15:27:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Ulead Systems
[2008/11/14 22:03:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Viewpoint
[2009/05/13 06:36:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Windows Desktop Search
[2009/06/08 17:58:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Windows Search
[2009/09/27 10:43:19 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/09/10 18:03:04 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2003/07/30 09:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/09/14 15:27:52 | 00,000,832 | ---- | M] () -- C:\WINDOWS\Tasks\Full Backups.job
[2009/09/27 17:58:44 | 00,000,882 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2009/09/27 18:17:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2009/09/27 09:30:00 | 00,000,914 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006Core.job
[2009/09/27 16:30:01 | 00,000,966 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006UA.job
[2009/09/27 04:00:15 | 00,000,804 | ---- | M] () -- C:\WINDOWS\Tasks\Incremental Backup.job
[2009/09/22 09:15:28 | 00,000,768 | ---- | M] () -- C:\WINDOWS\Tasks\Media Backup Schedule.job
[2009/09/27 17:58:43 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

< %systemroot%\system32\eventlog.dll >
[2008/04/13 14:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\eventlog.dll

< %systemroot%\system32\scecli.dll >
[2008/04/13 14:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\scecli.dll

< %systemroot%\netlogon.dll >

< %systemroot%\system32\cngaudit.dll >

< %systemroot%\system32\sceclt.dll >

< %systemroot%\ntelogon.dll >

< %systemroot%\system32\logevent.dll >

========== Alternate Data Streams ==========

@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:825D5945
< End of report >
-----------------------------------------------------------------------------------

OTL Extras logfile created on: 9/27/2009 6:12:36 PM - Run 1
OTL by OldTimer - Version 3.0.16.0 Folder = C:\Documents and Settings\JD\My Documents\JD's Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.41 Gb Available Physical Memory | 27.07% Memory free
2.11 Gb Paging File | 1.21 Gb Available in Paging File | 57.35% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 180.00 Gb Total Space | 34.27 Gb Free Space | 19.04% Space Free | Partition Type: NTFS
Drive D: | 6.29 Gb Total Space | 1.12 Gb Free Space | 17.85% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DESKTOP
Current User Name: JD
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde File not found
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" %* File not found
txtfile [edit] -- Reg Error: Key error.
Directory [AddToPlaylistVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger -- (Logitech)
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger -- (Logitech)
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 -- (Microsoft Corporation)
"C:\WINDOWS\pchealth\helpctr\Binaries\helpctr.exe" = C:\WINDOWS\pchealth\helpctr\Binaries\helpctr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice -- (Microsoft Corporation)
"C:\Program Files\TurboTax\Premier 2006\32bit\ttax.exe" = C:\Program Files\TurboTax\Premier 2006\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax -- (Intuit, Inc.)
"C:\Program Files\TurboTax\Premier 2006\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Premier 2006\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager -- (Intuit, Inc.)
"E:\setup\HPZNUI01.EXE" = E:\setup\HPZNUI01.EXE:*:Enabled:hpznui01.exe -- File not found
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe -- ()
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe -- ()
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe -- (Hewlett-Packard Co.)
"C:\WINDOWS\system32\hpzipm12.exe" = C:\WINDOWS\system32\hpzipm12.exe:*:Enabled:hpzipm12 -- (HP)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- File not found
"C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Civilization4.exe" = C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4 Gold -- (Firaxis Games)
"C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Warlords\Civ4Warlords.exe" = C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Warlords\Civ4Warlords.exe:*:Enabled:Sid Meier's Civilization 4: Warlords -- (Firaxis Games)
"C:\Program Files\TurboTax\Premier 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Premier 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax -- (Intuit, Inc.)
"C:\Program Files\TurboTax\Premier 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Premier 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager -- (Intuit, Inc.)
"C:\Program Files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe" = C:\Program Files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe:*:Disabled:Adobe Photoshop Elements Media Server -- (Adobe Systems Incorporated)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA -- (BitTorrent, Inc.)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server -- (Intuit Inc.)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe" = C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe:*:Enabled:StartupCopPro -- (Ziff-Davis Media, Inc.)
"C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" = C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe:*:Enabled:zlclient -- (Check Point Software Technologies LTD)
"C:\WINDOWS\system32\wscntfy.exe" = C:\WINDOWS\system32\wscntfy.exe:*:Enabled:wscntfy -- (Microsoft Corporation)
"C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe" = C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe:*:Enabled:16496404 -- File not found
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer -- (Microsoft Corporation)
"C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe" = C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe:*:Enabled:14267034 -- File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{086E6C0B-627B-4CC0-A87B-A0166260B15D}" = Business, Investment and Growth 2.0
"{092eeeee-9fdd-4895-a568-0818c96beb6c}" = AiO_Scan
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{0D2E80C8-0875-43EB-9623-47118E2DFBCA}" = Quicken 2007
"{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{145CACAF-9B34-41FC-BE49-7D510A253E78}" = Multimedia Card Reader
"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1F51A0CA-2BDD-474E-BB90-C7FA8EA78F52}" = ImageMixer VCD/DVD2 for OLYMPUS
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{21DAFB84-2421-488F-B17D-102FF53396AA}" = Ulead DVD Player
"{231A1A09-FDF2-45F2-B3D1-964CECE372BC}" = Seagate Manager Installer
"{2583DCD3-7A78-4F88-8F91-BBA5C7EB5444}" = Microsoft Broadband Networking
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{2A267BC6-F77F-4DD4-825F-7AEB1F68B4B1}" = HpSdpAppCoreApp
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{2E132061-C78A-48D4-A899-1D13B9D189FA}" = Memories Disc Creator 2.0
"{2E7595EC-4FB1-4E29-93D4-9083C8A9B107}" = TurboTax ItsDeductible 2005
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{3207208B-A2E1-4326-95E8-6642443B1DD2}" = MUSICMATCH Media Center
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{324CEC09-007A-48eb-90E0-9D42D4D5EB0A}" = NetDeviceManager
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36495C59-089C-49D1-BD15-9E5BD86DC9A1}" = ItsDeductible Express
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{3C759736-8347-4031-BB9C-D75ADFE6B101}" = Norton Ghost 9.0
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth
"{405ABBEB-8DF1-4174-86C0-DCB5E1C78F14}" = NetDeviceManager
"{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing
"{4394DC3A-5DAC-4C80-A86E-FF462D0AD653}" = Windows 7 Upgrade Advisor Beta
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{44B2E182-DD85-45FC-9F51-326B81D7C7F1}" = Fax
"{45B6180B-DCAB-4093-8EE8-6164457517F0}" = Photosmart 140,240,7200,7600,7700,7900 Series
"{46DDF76F-ACD4-42BC-B48F-B89C4EE2E1A9}" = Easy CD & DVD Creator 6
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{4FB6F304-A91D-4919-98E5-D96E074EA9E5}" = SkinsHP1
"{53EF7D4D-374D-4E39-9859-5504A5352BD7}" = MCESleepTimerV2.0
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{54e854d5-d5d4-452d-9c75-b39f5625b5fb}" = Readme
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{5AA18C57-381C-4C99-8FE6-5EB1CB0A5BC0}" = ImageMixer
"{5ADF6293-D60F-4425-AFA7-CEB820DB872B}" = QuickProjects
"{5D7F0A0E-369E-46C0-9F99-FAB21A064781}" = HP Photo and Imaging 2.0 - Photosmart Cameras
"{6179550A-3E7C-499E-BCC9-9E8113E0A285}" = LG ODD Auto Firmware Update
"{64FC0C98-B035-4530-B15D-3D30610B6DF1}" = HP Software Update
"{66C018BD-6F16-4B32-B4CD-1DC1B21FBDFF}" = Zone Deluxe Games
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6C117F31-28A8-4477-BE91-64AC0A2204AD}" = Microsoft IntelliPoint 6.01
"{6DD9963C-271A-4A14-82B0-4DC148C52E58}" = LaCie Backup Software v1.5.2042
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{730837D4-FF5E-48DB-BA49-33E732DFF0B3}" = PanoStandAlone
"{745A92AF-53B4-41A7-91C3-9B026B1D5897}" = InstantShare
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{757AD3D4-036B-42FA-B0A4-96BD6F4605A0}" = Ulead VideoStudio 7 SE DVD
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}" = overland
"{791B20D4-AE59-4DE9-B45F-BA01F3D0A493}" = ArcSoft ShowBiz 2
"{7A1F1E81-A017-43EE-8A24-E88878164C91}" = SeaWorld Adventure Parks Tycoon 3D
"{7BBD57D6-09B1-4CC3-9664-A0D53EE25247}" = PSShortcutsP
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{88F93347-0F9B-4FED-BA71-6C2A4CDFE61D}" = Ulead DVD MovieFactory 2 SE
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8BABDC16-04D1-4263-B3E7-A9E5F33A5969}" = NGC: Investor's Key To Real Estate
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}" = Musicmatch® Jukebox
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90AD8C11-ED4A-4AE7-BB70-7740C452C999}" = Visual J# .NET Redistributable Package
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD Player
"{93F54611-2701-454e-94AB-623F458D9E6B}" = DeviceDiscovery
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = RecordNow!
"{961D35E8-D426-3E2E-8222-F4FFD9E104FD}" = Google Gears
"{96976098-9527-41E4-837E-EAA1DBEADB54}" = TurboTax 2008 whiiper
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{9F4EEA0C-7174-4BD3-89AF-7AB2F9F6AEDD}" = hpmdtab
"{A011A1DC-7F1D-4EA8-BD11-0C5F9718E428}" = Symantec AntiVirus
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A1960A82-DB70-474D-A86B-FA74466103C6}" = Drivers Install For Linksys Easylink Advisor
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A363B66C-1547-47bf-90F0-3834E70A841A}" = CreativeProjects
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A53A1A49-C3EA-406c-B87C-8E02B622D605}" = C7200_doccd
"{A9212616-FCA2-4173-BD99-5C741EB3A068}" = Ulead DVD PictureShow 2 SE
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AD13BFB0-FDD2-4AFA-A8AF-9F4A950D56B7}" = ArcSoft Camera Suite 1.3
"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{AFBBF30D-ADA9-4313-464E-14458B6BE034}" = PhotoshopdotcomInspirationBrowser
"{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}" = TurboTax ItsDeductible 2006
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B34E4B72-37C6-4f79-A5B3-008EEFC6EA8B}" = PS_AIO_02_Software_min
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B46AC30C-22D2-4610-B041-1DA7BB29EB57}" = HP Photosmart All-In-One Software 9.0
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{B7E5D642-E74E-40a4-B5C7-6AB6EE916814}" = PS_AIO_02_ProductContext
"{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BC10649A-983B-494e-AD1F-DE0BF717D701}" = PS_AIO_02_Software
"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
"{BD57EA4D-026E-4F08-9B93-080E282B81FE}" = iPod for Windows 2006-06-28
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{BD76AF27-5CD9-4848-87FC-12285A90AE6A}" = c7200_Help
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{c330461f-c4a9-4fc7-af5d-c158e0b56aa7}" = AiOSoftware
"{C38BC5B7-62D3-4880-82DD-A4803FD81921}" = PhotoGallery
"{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Logitech QuickCam Software
"{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}" = Microsoft Plus! Digital Media Edition
"{C9618743-1A5C-461E-91C4-E013A3D70F3C}" = Adobe® Photoshop® Album Starter Edition 3.0.1
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB6075D9-F912-40AE-BEA6-E590DA24F16B}" = Adobe Photoshop Elements 7.0
"{CDF64407-E968-4AC8-8323-A1DDBE5A8D72}" = Quicken Home Inventory Manager
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}" = MSN Messenger 7.5
"{CECEB0FF-5C45-4b50-9A00-C596E36D88F4}" = C7200
"{CFD1B282-555D-494d-8231-4175C2AF08C2}" = PrintScreen
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D545BB81-DEB0-49f7-BE26-197BC31AAF57}" = SkinsHP2
"{D75915D3-6CFF-445F-A346-18ED6EF2F618}" = Microsoft IntelliType Pro 6.01
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E0000600-0600-0600-0600-000000000600}" = ICS Viewer 6.0
"{E031338C-839D-4EDD-9537-99B653C39D81}" = Autodesk MapGuide® Viewer ActiveX Control Release 6.5
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{E2750613-73F1-43B9-9B0B-387E5543971F}" = CD LabelMaker 5
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E4ABB302-9D82-4D18-83D5-AD1DFE786AA8}" = Unload
"{E56D39F8-2A9F-44B4-B068-A72E45A073E6}" = Safari
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"{EC2A8F27-4FBF-4E41-B27B-FE822511B761}" = iTunes
"{ec7d7a6a-31cb-4810-826f-74171bef44f1}" = AIOMinimal
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F247869D-3643-4A9F-821B-3534145928E3}" = HPIZ311
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}" = HP PSC & OfficeJet 3.0
"{F419D20A-7719-4639-8E30-C073A040D878}" = HP Deskjet Preloaded Printer Drivers
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status
"36317AE4-57EC-4F3E-B828-009A3DD96BE8" = Polar Bowler from Hewlett-Packard Desktops (remove only)
"62067F4C-84A9-45B9-8573-B90468B0A3EF" = Orbital from Hewlett-Packard Desktops (remove only)
"Abacast Client" = Abacast Client
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 7" = Adobe Photoshop Elements 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"Age of Empires 2.0" = Microsoft Age of Empires II
"All ATI Software" = ATI - Software Uninstall Utility
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"Any Video Converter_is1" = Any Video Converter 2.6.7
"ATI Display Driver" = ATI Display Driver
"Audacity_is1" = Audacity 1.2.6
"Avi2Dvd" = Avi2Dvd 0.4.5 beta
"Avidemux 2.4" = Avidemux 2.4
"AviSynth" = AviSynth 2.5
"BackWeb-137903 Uninstaller" = Updates from HP
"Bookmarkbridge" = BookmarkBridge 0.76
"CCleaner" = CCleaner (remove only)
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"dBpoweramp AAC Encoder" = dBpoweramp AAC Encoder
"dBpoweramp m4a Codec" = dBpoweramp m4a Codec
"dBpoweramp m4a Utilities" = dBpoweramp m4a Utilities
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"DHCP Convertor" = DHCP Convertor
"DVD Flick_is1" = DVD Flick
"DVD Shrink_is1" = DVD Shrink 3.2
"EasyLinkAdvisor" = Linksys EasyLink Advisor 1.6 (0032)
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"EuroTalk Talk Now Plus!" = EuroTalk Talk Now Plus!
"exPressit S.E. 3.0" = exPressit S.E. 3.0
"Free Video to iPhone Converter_is1" = Free Video to iPhone Converter version 2.1
"Guild Wars" = Guild Wars
"HandBrake" = HandBrake 0.9.3
"HD Tune_is1" = HD Tune 2.55
"HP Imaging Device Functions" = HP Imaging Device Functions 9.0
"HP Instant Support" = HP Instant Support
"HP Photo & Imaging" = HP Photo & Imaging 3.1
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0
"HPExtendedCapabilities" = HP Customer Participation Program 9.0
"HPOCR" = HP OCR Software 9.0
"HPTOOLKIT" = toolkit
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"iGolfNeo" = iGolf Neo Sync Application
"iLyrics" = iTunes Lyrics Importer
"InCD!UninstallKey" = InCD
"InstallShield_{145CACAF-9B34-41FC-BE49-7D510A253E78}" = Multimedia Card Reader
"InstallShield_{231A1A09-FDF2-45F2-B3D1-964CECE372BC}" = Seagate Manager Installer
"InstallShield_{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"InstallShield_{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"InstallShield_{BD57EA4D-026E-4F08-9B93-080E282B81FE}" = iPod for Windows 2006-06-28
"InterActual Player" = InterActual Player
"IrfanView" = IrfanView (remove only)
"ItsDeductible7" = ItsDeductible7
"JDiskReport 1.2.1" = JGoodies JDiskReport 1.2.1
"LaCie Device Updater" = LaCie Device Updater
"LiveUpdate" = LiveUpdate 3.0 (Symantec Corporation)
"Logitech Print Service" = Logitech Print Service
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3)
"MSN Music Assistant" = MSN Music Assistant
"MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
"MUSICMATCH Radio" = MUSICMATCH® MX Web Player
"MWASPI" = MicroStaff WINASPI
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NeroVision!UninstallKey" = NeroVision Express 3
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NMIX!UninstallKey" = NeroMIX
"NMPUninstallKey" = Nero Media Player
"NVEContent!UninstallKey" = NeroVision Express Content
"NVIDIA" =
"Paint Shop Pro 6.0" = Paint Shop Pro 6.0 (ESD)
"Paint Shop Pro 6.02 Patch" = Paint Shop Pro 6.02 Patch
"PC Magazine Defrag-A-File 2_is1" = PC Magazine Defrag-A-File 2.0.2
"PC Magazine Folders 2_is1" = PC Magazine Folders 2
"Pcsx2_is1" = Pcsx2 0.9.4 Watermoose
"PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.1" = Adobe Photoshop.com Inspiration Browser
"Picasa2" = Picasa 2
"PokerTime.net Poker" = PokerTime.net Poker
"PS2" = PS2
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"Python 2.2.1" = Python 2.2.1
"QcDrv" = Logitech® Camera Driver
"Quicken Legal Business Pro 2007" = Quicken Legal Business Pro 2007
"Railroad Tycoon II" = Railroad Tycoon II
"RealAlt_is1" = Real Alternative 1.23
"Rosetta Stone 2.1.5.0A" = Rosetta Stone 2.1.5.0A
"SereneScene Marine Aquarium 2" = SereneScene Marine Aquarium 2
"Sid Meier's Alpha Centauri" = Sid Meier's Alpha Centauri
"SimCity 3000" = SimCity 3000
"SPSS for Windows Student Version 11.0" = SPSS 11.0 for Windows Student Version
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"Startup Cop Pro_is1" = Startup Cop Pro 3.0
"TurboTax 2008" = TurboTax 2008
"TurboTax Premier 2003" = TurboTax Premier 2003
"TurboTax Premier 2004" = TurboTax Premier 2004
"TurboTax Premier 2005" = TurboTax Premier 2005
"TurboTax Premier 2007" = TurboTax Premier 2007
"TurboTax Premier Investments 2006" = TurboTax Premier Investments 2006
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"Uninstall_is1" = Uninstall 1.0.0.1
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"Visioneer 7600 Scanner Driver" = Visioneer 7600 Scanner Driver
"Visioneer PaperPort 6.1" = Visioneer PaperPort 6.1
"VLC media player" = VLC media player 0.9.8a
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"Xfire" = Xfire (remove only)
"ZoneAlarm" = ZoneAlarm
"ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{55502C49-F061-428C-BF26-06ECDFB3AC29}" = Sid Meier's Civilization 4 Gold
"AI RoboForm" = AI RoboForm
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/27/2009 8:02:08 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Risk: Trojan.Vundo in File: Unavailable by: Invalid
: (15) scan. Action: Delete failed. Action Description: The file was left unchanged.



Error - 9/27/2009 10:06:35 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Risk: Trojan.Vundo in File: Unavailable by: Invalid
: (15) scan. Action: Delete failed. Action Description: The file was left unchanged.



Error - 9/27/2009 10:06:36 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685
Description = Risk Found!Risk: Trojan.Vundo in File: c:\windows\system32\noyusoda.dll
by: Invalid : (15) scan. Action: Delete succeeded. Action Description: The file
was deleted successfully.

Error - 9/27/2009 10:06:43 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Risk: Trojan.Vundo in File: Unavailable by: Invalid
: (15) scan. Action: Delete failed : Leave Alone failed. Action Description:


Error - 9/27/2009 10:07:05 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Risk: Trojan.Vundo in File: Unavailable by: Invalid
: (15) scan. Action: Delete failed. Action Description: The file was left unchanged.



Error - 9/27/2009 10:07:06 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685
Description = Risk Found!Risk: Trojan.Vundo in File: c:\windows\system32\noyusoda.dll
by: Invalid : (15) scan. Action: Delete succeeded. Action Description: The file
was deleted successfully.

Error - 9/27/2009 10:07:06 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685
Description = Risk Found!Risk: Trojan.Vundo in File: c:\windows\system32\kesibahi.dll
by: Invalid : (15) scan. Action: Delete succeeded. Action Description: The file
was deleted successfully.

Error - 9/27/2009 10:37:58 AM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\rundll32.exe
by: Invalid : (15) scan. Action: Delete failed. Action Description: The file
was left unchanged.

Error - 9/27/2009 2:44:24 PM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Risk: Trojan.Vundo in File: Unavailable by: Invalid
: (15) scan. Action: Delete failed. Action Description: The file was left unchanged.



Error - 9/27/2009 2:44:24 PM | Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685
Description = Risk Found!Risk: Trojan.Vundo in File: c:\windows\system32\noyusoda.dll
by: Invalid : (15) scan. Action: Delete succeeded. Action Description: The file
was deleted successfully.

[ System Events ]
Error - 8/23/2009 1:56:01 PM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000
Description = The TrueVector Internet Monitor service failed to start due to the
following error: %%1053

Error - 8/24/2009 11:24:31 PM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor
service to connect.

Error - 8/24/2009 11:24:31 PM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000
Description = The TrueVector Internet Monitor service failed to start due to the
following error: %%1053

Error - 8/27/2009 1:27:18 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor
service to connect.

Error - 8/27/2009 1:27:18 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000
Description = The TrueVector Internet Monitor service failed to start due to the
following error: %%1053

Error - 8/30/2009 12:43:18 AM | Computer Name = DESKTOP | Source = LDMS | ID = 16780230
Description = Unhandled exception, exception code=6B

Error - 8/30/2009 1:19:10 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor
service to connect.

Error - 8/30/2009 1:19:10 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000
Description = The TrueVector Internet Monitor service failed to start due to the
following error: %%1053

Error - 8/30/2009 1:42:42 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor
service to connect.

Error - 8/30/2009 1:42:43 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000
Description = The TrueVector Internet Monitor service failed to start due to the
following error: %%1053


< End of report >

------------------------------------------------------------------------------------

Malwarebytes' Anti-Malware 1.41
Database version: 2866
Windows 5.1.2600 Service Pack 3

9/27/2009 3:09:18 PM
mbam-log-2009-09-27 (15-09-18).txt

Scan type: Quick Scan
Objects scanned: 139641
Time elapsed: 33 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 1
Registry Values Infected: 4
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\WINDOWS\system32\borababu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\tenedefi.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\derupili.dll (Trojan.Vundo) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{c3314a31-d91d-4cfb-9056-9f8e13893e00} (Trojan.Vundo.H) -> Delete on reboot.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wefowuwus (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{c3314a31-d91d-4cfb-9056-9f8e13893e00} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\juhovidag (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\10990154 (Rogue.Multiple) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\borababu.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\borababu.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\borababu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\tenedefi.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\derupili.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\reforola.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sepoyije.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tijawani.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tupemawu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

-------------------------------
Thanks again for your help.
BuzzBoy

Go to the top of the page
 
+Quote Post
hammerman
post Oct 3 2009, 10:21 AM
Post #2


Trusted Helper
Group Icon
Posts: 1,499
From: UK
OS: XP



Hello BuzzBoy22 and welcome to GeeksToGo smile.gif
I'm hammerman and I'm going to help you fix your problem.

Sorry for the delay in replying.

Before we begin, here are some guidelines which will help us both in fixing your problem.
  • I suggest you print or save any instructions I give you for easy reference. We may be using Safe mode and you will not always be able to access this thread. You can copy and paste these instructions into Notepad and then save the text file to your Desktop. If you need any help with this or further clarification, please let me know.
  • Please do no attach logs or post them in Quote/Code boxes unless requested.
  • When posting logs, please ensure Word Wrap is turned off in Notepad. Open Notepad, select Format on the menu bar and make sure that Word Wrap is unchecked.
  • Please follow the steps exactly in the same order posted. If you can't perform a certain step, or you're unsure on what to do, please stop and let me know.
  • If in doubt about anything, please ask.


As it's been a while since you posted your logs, let's get some fresh ones.

Please follow these steps.

-- Step 1 --

Run Malwarebytes' Anti-Malware.
  • Select the Update tab and then click Check for Updates. If an update is found, it will download and install the latest version.
  • Select the Scanner tab, select "Perform quick scan", then click Scan
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

-- Step 2 --

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTS to your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Under Additional Scans check the following:
    • Reg - Shell Spawning
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EvtViewer (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.

Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on to insert the attachment into your post


-- Step 3 --

Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.

Start the Sysprot.exe program.
  • Click on the Log tab.
  • In the Write to log box select all items.
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new Window should appear.
  • Make sure Scan all drives is selected and click on the Start button.
  • When it is complete a new Window will appear to indicate that the scan is finished.
  • The log will be created and saved automatically in the same folder. Open the text file and copy/paste the log here.


Go to the top of the page
 
+Quote Post
BuzzBoy22
post Oct 3 2009, 05:00 PM
Post #3


New Member
*
Posts: 9
OS: XP



hammerman,

Thanks for helping me out. I ran MBAM, OTS and SysProt, but SysProt did not appear to run correctly. After about 8 minutes of scanning, the system clock hung up, and the scan never gave me a "completed" message. I waited an hour for the scan to complete, but after that time there was no disk drive activity and the rest of the computer had hung up. There was a text file in the SysProt folder, and I have included it below, but I'm not confident in its completeness. Here are the log files:

Malwarebytes' Anti-Malware 1.41
Database version: 2900
Windows 5.1.2600 Service Pack 3

10/3/2009 10:17:49 AM
mbam-log-2009-10-03 (10-17-49).txt

Scan type: Quick Scan
Objects scanned: 140681
Time elapsed: 25 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 1
Registry Values Infected: 4
Registry Data Items Infected: 3
Folders Infected: 3
Files Infected: 22

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\tehunevo.dll (Trojan.Vundo) -> Delete on reboot.
c:\WINDOWS\system32\wobihasa.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\fedoniko.dll (Trojan.Vundo) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{d045846b-9cd4-48bf-b327-b0f6757c4d5f} (Trojan.Vundo.H) -> Delete on reboot.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wefowuwus (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{d045846b-9cd4-48bf-b327-b0f6757c4d5f} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\sebugeban (Trojan.Vundo.H) -> Delete on reboot.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\install (Rogue.SecurityTool) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\wobihasa.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\wobihasa.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Documents and Settings\All Users\Application Data\15637184 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\17270004 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\JD\Application Data\6802223407 (Rogue.SecurityTool) -> Quarantined and deleted successfully.

Files Infected:
c:\WINDOWS\system32\wobihasa.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\tehunevo.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\fedoniko.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\buloboti.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\derupili.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\foweriyo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hizudenu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lahozunu.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nawodope.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nukatojo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pobefoli.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\setevari.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tenedefi.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tigahifa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wowuneha.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yetogusu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yolefode.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\15637184\15637184 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\17270004\17270004 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\JD\Application Data\6802223407\6802223407.bat (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\Documents and Settings\JD\Application Data\6802223407\6802223407.cfg (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\Documents and Settings\JD\Application Data\6802223407\6802223407.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.

--------------------------------------------------------------------------------
Attached File  OTS.Txt ( 240.79K ) Number of downloads: 7


--------------------------------------------------------------------------------

SysProt AntiRootkit v1.0.1.0
by swatkat

******************************************************************************************
******************************************************************************************

Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No

Name: System
PID: 4
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\smss.exe
PID: 760
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\csrss.exe
PID: 888
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\winlogon.exe
PID: 912
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\services.exe
PID: 964
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\lsass.exe
PID: 976
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\ati2evxx.exe
PID: 1152
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1180
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1244
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1360
Hidden: No
Window Visible: No

Name: C:\Program Files\Ahead\InCD\InCDsrv.exe
PID: 1388
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1568
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1648
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
PID: 1704
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
PID: 1984
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\spoolsv.exe
PID: 316
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 552
Hidden: No
Window Visible: No

Name: C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
PID: 584
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PID: 620
Hidden: No
Window Visible: No

Name: C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PID: 848
Hidden: No
Window Visible: No

Name: C:\Program Files\Bonjour\mDNSResponder.exe
PID: 200
Hidden: No
Window Visible: No

Name: C:\Program Files\Symantec AntiVirus\DefWatch.exe
PID: 1332
Hidden: No
Window Visible: No

Name: C:\WINDOWS\eHome\ehsched.exe
PID: 1540
Hidden: No
Window Visible: No

Name: C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
PID: 1588
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\gearsec.exe
PID: 1760
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1836
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1888
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PID: 1960
Hidden: No
Window Visible: No

Name: C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
PID: 2072
Hidden: No
Window Visible: No

Name: C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
PID: 2200
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 2384
Hidden: No
Window Visible: No

Name: C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
PID: 2424
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 2532
Hidden: No
Window Visible: No

Name: C:\Program Files\CyberLink\Shared Files\RichVideo.exe
PID: 2644
Hidden: No
Window Visible: No

Name: C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
PID: 2740
Hidden: No
Window Visible: No

Name: C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PID: 2804
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 2860
Hidden: No
Window Visible: No

Name: C:\Program Files\Symantec AntiVirus\Rtvscan.exe
PID: 2952
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\wdfmgr.exe
PID: 3072
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\MsPMSPSv.exe
PID: 3332
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\searchindexer.exe
PID: 3368
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\alg.exe
PID: 3752
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\ati2evxx.exe
PID: 2380
Hidden: No
Window Visible: No

Name: C:\WINDOWS\explorer.exe
PID: 2888
Hidden: No
Window Visible: No

Name: C:\hp\KBD\kbd.exe
PID: 3632
Hidden: No
Window Visible: No

Name: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
PID: 1444
Hidden: No
Window Visible: No

Name: C:\Program Files\Multimedia Card Reader\shwicon2k.exe
PID: 3444
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\hphmon05.exe
PID: 1396
Hidden: No
Window Visible: No

Name: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
PID: 1628
Hidden: No
Window Visible: No

Name: C:\Program Files\HP\Digital Imaging\Unload\HpqCmon.exe
PID: 2216
Hidden: No
Window Visible: No

Name: C:\PROGRA~1\SYMANT~1\VPTray.exe
PID: 2116
Hidden: No
Window Visible: No

Name: C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe
PID: 2332
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE
PID: 1380
Hidden: No
Window Visible: No

Name: C:\PROGRA~1\VISION~1\PAPERP~1\FBDirect.exe
PID: 2464
Hidden: No
Window Visible: No

Name: C:\Program Files\Microsoft IntelliType Pro\itype.exe
PID: 2636
Hidden: No
Window Visible: No

Name: C:\Program Files\Microsoft IntelliPoint\ipoint.exe
PID: 2724
Hidden: No
Window Visible: No

Name: C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
PID: 2716
Hidden: No
Window Visible: No

Name: C:\Program Files\iTunes\iTunesHelper.exe
PID: 3512
Hidden: No
Window Visible: No

Name: C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe
PID: 3248
Hidden: No
Window Visible: No

Name: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PID: 864
Hidden: No
Window Visible: No

Name: C:\Program Files\DNA\btdna.exe
PID: 2060
Hidden: No
Window Visible: No

Name: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PID: 4196
Hidden: No
Window Visible: No

Name: C:\Program Files\Windows Desktop Search\WindowsSearch.exe
PID: 4204
Hidden: No
Window Visible: No

Name: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PID: 4224
Hidden: No
Window Visible: No

Name: C:\Program Files\Symantec AntiVirus\DoScan.exe
PID: 4412
Hidden: No
Window Visible: No

Name: C:\Program Files\iPod\bin\iPodService.exe
PID: 5212
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\ZoneLabs\vsmon.exe
PID: 5368
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 6140
Hidden: No
Window Visible: No

Name: C:\Documents and Settings\JD\Desktop\SysProt\SysProt\SysProt.exe
PID: 4360
Hidden: No
Window Visible: Yes

******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \??\C:\Documents and Settings\JD\Desktop\SysProt\SysProt\SysProtDrv.sys
Service Name: SysProtDrv.sys
Module Base: AB29E000
Module End: AB2A9000
Hidden: No

Module Name: \WINDOWS\system32\ntoskrnl.exe
Service Name: ---
Module Base: 804D7000
Module End: 806FF000
Hidden: No

Module Name: \WINDOWS\system32\hal.dll
Service Name: ---
Module Base: 806FF000
Module End: 8071FD00
Hidden: No

Module Name: \WINDOWS\system32\KDCOM.DLL
Service Name: ---
Module Base: F7987000
Module End: F7989000
Hidden: No

Module Name: \WINDOWS\system32\BOOTVID.dll
Service Name: ---
Module Base: F7897000
Module End: F789A000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\ACPI.sys
Service Name: ACPI
Module Base: F75A8000
Module End: F75D6000
Hidden: No

Module Name: \WINDOWS\System32\DRIVERS\WMILIB.SYS
Service Name: ---
Module Base: F7989000
Module End: F798B000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\pci.sys
Service Name: PCI
Module Base: F7597000
Module End: F75A8000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\isapnp.sys
Service Name: isapnp
Module Base: F75F7000
Module End: F7601000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\pciide.sys
Service Name: PCIIde
Module Base: F7A4F000
Module End: F7A50000
Hidden: No

Module Name: \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
Service Name: ---
Module Base: F7707000
Module End: F770E000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys
Service Name: MountMgr
Module Base: F7607000
Module End: F7612000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys
Service Name: Disk
Module Base: F74D8000
Module End: F74F7000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\dmload.sys
Service Name: dmload
Module Base: F798B000
Module End: F798D000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\dmio.sys
Service Name: dmio
Module Base: F74B2000
Module End: F74D8000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys
Service Name: PartMgr
Module Base: F770F000
Module End: F7714000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys
Service Name: VolSnap
Module Base: F7617000
Module End: F7624000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\atapi.sys
Service Name: atapi
Module Base: F749A000
Module End: F74B2000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\disk.sys
Service Name: ---
Module Base: F7627000
Module End: F7630000
Hidden: No

Module Name: \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
Service Name: ---
Module Base: F7637000
Module End: F7644000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\fltmgr.sys
Service Name: FltMgr
Module Base: F747A000
Module End: F749A000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\sr.sys
Service Name: sr
Module Base: F7468000
Module End: F747A000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\Lbd.sys
Service Name: Lbd
Module Base: F7647000
Module End: F7656000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\PxHelp20.sys
Service Name: PxHelp20
Module Base: F7657000
Module End: F7660000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\PQV2i.sys
Service Name: PQV2i
Module Base: F7452000
Module End: F7468000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys
Service Name: KSecDD
Module Base: F743B000
Module End: F7452000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys
Service Name: Ntfs
Module Base: F7B52000
Module End: F7BDF000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\NDIS.sys
Service Name: NDIS
Module Base: F740E000
Module End: F743B000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\ppsio2.sys
Service Name: ppsio2
Module Base: F789B000
Module End: F789E000
Hidden: No

Module Name: srescan.sys
Service Name: srescan
Module Base: F7883000
Module End: F7897000
Hidden: Yes

Module Name: C:\WINDOWS\system32\drivers\sbp2port.sys
Service Name: sbp2port
Module Base: F7667000
Module End: F7672000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\ohci1394.sys
Service Name: ohci1394
Module Base: F7677000
Module End: F7687000
Hidden: No

Module Name: \WINDOWS\System32\DRIVERS\1394BUS.SYS
Service Name: ---
Module Base: F7687000
Module End: F7695000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\Mup.sys
Service Name: Mup
Module Base: BAF46000
Module End: BAF60000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\agp440.sys
Service Name: agp440
Module Base: F7697000
Module End: F76A2000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\intelppm.sys
Service Name: intelppm
Module Base: BAF90000
Module End: BAF99000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ati2mtag.sys
Service Name: ati2mtag
Module Base: BA026000
Module End: BA0FB000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\VIDEOPRT.SYS
Service Name: ---
Module Base: BA012000
Module End: BA026000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\usbuhci.sys
Service Name: usbuhci
Module Base: F7757000
Module End: F775D000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\USBPORT.SYS
Service Name: ---
Module Base: B9FEE000
Module End: BA012000
Hidden: No

Module Name: C:\WINDOWS\system32\DRIVERS\LaCieUSBFilter.sys
Service Name: LaCieUSBFilter
Module Base: BAF80000
Module End: BAF89000
Hidden: No

Module Name: C:\WINDOWS\system32\DRIVERS\USBD.SYS
Service Name: ---
Module Base: F79BB000
Module End: F79BD000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\usbehci.sys
Service Name: usbehci
Module Base: F775F000
Module End: F7767000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\cx88vid.sys
Service Name: CX23880
Module Base: B9FBE000
Module End: B9FEE000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\STREAM.SYS
Service Name: ---
Module Base: BAF60000
Module End: BAF6D000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\ks.sys
Service Name: ---
Module Base: B9F9B000
Module End: B9FBE000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\cx88enc.sys
Service Name: CX88ENC
Module Base: B9F52000
Module End: B9F9B000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys
Service Name: ltmodem5
Module Base: B9EB7000
Module End: B9F52000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Modem.SYS
Service Name: Modem
Module Base: F7767000
Module End: F776F000
Hidden: No

Module Name: C:\WINDOWS\system32\DRIVERS\LaCieFWFilter.sys
Service Name: LaCieFWFilter
Module Base: F776F000
Module End: F7777000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\R8139n51.SYS
Service Name: rtl8139
Module Base: BA9CA000
Module End: BA9D6000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\serial.sys
Service Name: Serial
Module Base: BA9BA000
Module End: BA9CA000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\serenum.sys
Service Name: serenum
Module Base: BAED2000
Module End: BAED6000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\fdc.sys
Service Name: Fdc
Module Base: F7777000
Module End: F777E000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\parport.sys
Service Name: Parport
Module Base: B9EA3000
Module End: B9EB7000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\imapi.sys
Service Name: Imapi
Module Base: BA9AA000
Module End: BA9B5000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\cdrbsdrv.SYS
Service Name: cdrbsdrv
Module Base: BAECE000
Module End: BAED2000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\AFS2K.SYS
Service Name: AFS2K
Module Base: BA99A000
Module End: BA9A4000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\pfc.sys
Service Name: pfc
Module Base: BAECA000
Module End: BAECD000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Service Name: Cdrom
Module Base: BA98A000
Module End: BA99A000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\redbook.sys
Service Name: redbook
Module Base: BA97A000
Module End: BA989000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\InCDPass.sys
Service Name: InCDPass
Module Base: F777F000
Module End: F7787000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\incdrm.SYS
Service Name: incdrm
Module Base: F7787000
Module End: F778E000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\pwd_2k.SYS
Service Name: pwd_2k
Module Base: B9E86000
Module End: B9EA3000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys
Service Name: GEARAspiWDM
Module Base: F77AF000
Module End: F77B5000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\ALCXWDM.SYS
Service Name: ALCXWDM
Module Base: B9C59000
Module End: B9E86000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\portcls.sys
Service Name: ---
Module Base: B9C35000
Module End: B9C59000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\drmk.sys
Service Name: ---
Module Base: BA95A000
Module End: BA969000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\serscan.sys
Service Name: StillCam
Module Base: F79BD000
Module End: F79BF000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\audstub.sys
Service Name: audstub
Module Base: F7A9E000
Module End: F7A9F000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\rasl2tp.sys
Service Name: Rasl2tp
Module Base: F7577000
Module End: F7584000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ndistapi.sys
Service Name: NdisTapi
Module Base: BAEB6000
Module End: BAEB9000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ndiswan.sys
Service Name: NdisWan
Module Base: B9C1E000
Module End: B9C35000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\raspppoe.sys
Service Name: RasPppoe
Module Base: F7567000
Module End: F7572000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\raspptp.sys
Service Name: PptpMiniport
Module Base: F7557000
Module End: F7563000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\TDI.SYS
Service Name: ---
Module Base: BA37B000
Module End: BA380000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\psched.sys
Service Name: PSched
Module Base: B9C0D000
Module End: B9C1E000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\msgpc.sys
Service Name: Gpc
Module Base: F7547000
Module End: F7550000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ptilink.sys
Service Name: Ptilink
Module Base: BA373000
Module End: BA378000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\raspti.sys
Service Name: Raspti
Module Base: BA36B000
Module End: BA370000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\rdpdr.sys
Service Name: rdpdr
Module Base: B9BB5000
Module End: B9BE5000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\termdd.sys
Service Name: TermDD
Module Base: F7537000
Module End: F7541000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\kbdclass.sys
Service Name: Kbdclass
Module Base: BA363000
Module End: BA369000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\mouclass.sys
Service Name: Mouclass
Module Base: BA35B000
Module End: BA361000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\swenum.sys
Service Name: swenum
Module Base: F79BF000
Module End: F79C1000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\update.sys
Service Name: Update
Module Base: B9AB7000
Module End: B9B15000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\mssmbios.sys
Service Name: mssmbios
Module Base: BAE9A000
Module End: BAE9E000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\dvd_2K.SYS
Service Name: dvd_2K
Module Base: BA353000
Module End: BA359000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Service Name: NDProxy
Module Base: BAFF0000
Module End: BAFFA000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\usbhub.sys
Service Name: usbhub
Module Base: BAFB0000
Module End: BAFBF000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\CX88TUNE.sys
Service Name: CXTUNE
Module Base: BA34B000
Module End: BA353000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\CX88XBARDUAL.sys
Service Name: CX88XBAR
Module Base: F79C5000
Module End: F79C7000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\nic1394.sys
Service Name: NIC1394
Module Base: F76C7000
Module End: F76D7000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\flpydisk.sys
Service Name: Flpydisk
Module Base: BA343000
Module End: BA348000
Hidden: No

Module Name: \??\C:\Program Files\Symantec AntiVirus\savrt.sys
Service Name: SAVRT
Module Base: AEE69000
Module End: AEEC1000
Hidden: No

Module Name: \??\C:\Program Files\Symantec\SYMEVENT.SYS
Service Name: SymEvent
Module Base: AEE47000
Module End: AEE69000
Hidden: No

Module Name: \??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys
Service Name: SAVRTPEL
Module Base: AEE33000
Module End: AEE47000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\IrBus.sys
Service Name: IrBus
Module Base: BA94A000
Module End: BA956000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\usbccgp.sys
Service Name: usbccgp
Module Base: BA33B000
Module End: BA343000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\hidusb.sys
Service Name: HidUsb
Module Base: BAEDE000
Module End: BAEE1000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\HIDCLASS.SYS
Service Name: ---
Module Base: BA93A000
Module End: BA943000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\HIDPARSE.SYS
Service Name: ---
Module Base: BA333000
Module End: BA33A000
Hidden: No

Module Name: \??\C:\WINDOWS\System32\Drivers\sunkfilt.sys
Service Name: SunkFilt
Module Base: F77DF000
Module End: F77E6000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS
Service Name: USBSTOR
Module Base: F778F000
Module End: F7796000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\hidir.sys
Service Name: HidIr
Module Base: F779F000
Module End: F77A4000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\kbdhid.sys
Service Name: kbdhid
Module Base: BAEDA000
Module End: BAEDE000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\mouhid.sys
Service Name: mouhid
Module Base: BAED6000
Module End: BAED9000
Hidden: No

Module Name: C:\WINDOWS\system32\DRIVERS\NuidFltr.sys
Service Name: NuidFltr
Module Base: F77A7000
Module End: F77AE000
Hidden: No

Module Name: C:\WINDOWS\system32\DRIVERS\WDFLDR.SYS
Service Name: ---
Module Base: F76D7000
Module End: F76E4000
Hidden: No

Module Name: C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
Service Name: Wdf01000
Module Base: AED68000
Module End: AEDE3000
Hidden: No

Module Name: C:\WINDOWS\system32\DRIVERS\point32.sys
Service Name: Point32
Module Base: F77B7000
Module End: F77BD000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Cdr4_xp.SYS
Service Name: Cdr4_xp
Module Base: F7A59000
Module End: F7A5A000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Cdralw2k.SYS
Service Name: Cdralw2k
Module Base: F7A58000
Module End: F7A59000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Service Name: Fs_Rec
Module Base: F79D9000
Module End: F79DB000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Null.SYS
Service Name: Null
Module Base: BAB19000
Module End: BAB1A000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Beep.SYS
Service Name: Beep
Module Base: F79DB000
Module End: F79DD000
Hidden: No

Module Name: C:\WINDOWS\System32\drivers\vga.sys
Service Name: VgaSave
Module Base: F77CF000
Module End: F77D5000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Service Name: mnmdd
Module Base: F79DD000
Module End: F79DF000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Service Name: RDPCDD
Module Base: F79DF000
Module End: F79E1000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\cdudf_xp.SYS
Service Name: cdudf_xp
Module Base: AEBB2000
Module End: AEBF2000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\InCDrec.SYS
Service Name: InCDrec
Module Base: B9BE5000
Module End: B9BE8000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\InCDfs.SYS
Service Name: InCDfs
Module Base: AEB5F000
Module End: AEB78000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS
Service Name: Msfs
Module Base: F77D7000
Module End: F77DC000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS
Service Name: Npfs
Module Base: F77E7000
Module End: F77EF000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\UdfReadr_xp.SYS
Service Name: UdfReadr_xp
Module Base: AEB2A000
Module End: AEB5F000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\rasacd.sys
Service Name: RasAcd
Module Base: B8FB5000
Module End: B8FB8000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ipsec.sys
Service Name: IPSec
Module Base: AEADD000
Module End: AEAF0000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\tcpip.sys
Service Name: Tcpip
Module Base: AEA84000
Module End: AEADD000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ipnat.sys
Service Name: IpNat
Module Base: AEA5E000
Module End: AEA84000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\SYMTDI.SYS
Service Name: SYMTDI
Module Base: AEA23000
Module End: AEA5E000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\arp1394.sys
Service Name: Arp1394
Module Base: F76F7000
Module End: F7706000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\netbt.sys
Service Name: NetBT
Module Base: AE9FB000
Module End: AEA23000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\wanarp.sys
Service Name: Wanarp
Module Base: F7587000
Module End: F7590000
Hidden: No

Module Name: C:\WINDOWS\System32\vsdatant.sys
Service Name: vsdatant
Module Base: AE990000
Module End: AE9FB000
Hidden: No

Module Name: C:\WINDOWS\System32\drivers\ws2ifsl.sys
Service Name: WS2IFSL
Module Base: AEED9000
Module End: AEEDC000
Hidden: No

Module Name: C:\WINDOWS\System32\drivers\afd.sys
Service Name: AFD
Module Base: AE96E000
Module End: AE990000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\netbios.sys
Service Name: NetBIOS
Module Base: B9BA5000
Module End: B9BAE000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\rdbss.sys
Service Name: Rdbss
Module Base: AE943000
Module End: AE96E000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\PQIMount.SYS
Service Name: PQIMount
Module Base: B9B85000
Module End: B9B8E000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\mrxsmb.sys
Service Name: MRxSmb
Module Base: AE883000
Module End: AE8F3000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS
Service Name: Fips
Module Base: B9B75000
Module End: B9B80000
Hidden: No

Module Name: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
Service Name: eeCtrl
Module Base: AE825000
Module End: AE883000
Hidden: No

Module Name: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
Service Name: EraserUtilRebootDrv
Module Base: AE808000
Module End: AE825000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Service Name: Fastfat
Module Base: AE76C000
Module End: AE790000
Hidden: No

Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys
Service Name: ---
Module Base: AE7BC000
Module End: AE7BF000
Hidden: No

Module Name: C:\WINDOWS\System32\watchdog.sys
Service Name: ---
Module Base: F77F7000
Module End: F77FC000
Hidden: No

Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys
Service Name: ---
Module Base: BA0FC000
Module End: BA0FD000
Hidden: No

Module Name: C:\WINDOWS\system32\DRIVERS\elagopro.sys
Service Name: elagopro
Module Base: F780F000
Module End: F7816000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\ndisuio.sys
Service Name: Ndisuio
Module Base: AC568000
Module End: AC56C000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\mrxdav.sys
Service Name: MRxDAV
Module Base: AC19F000
Module End: AC1CC000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\ParVdm.SYS
Service Name: ParVdm
Module Base: F79E9000
Module End: F79EB000
Hidden: No

Module Name: C:\WINDOWS\system32\DRIVERS\elaunidr.sys
Service Name: elaunidr
Module Base: F798D000
Module End: F798F000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\MASPINT.SYS
Service Name: MASPINT
Module Base: F79A9000
Module End: F79AB000
Hidden: No

Module Name: C:\WINDOWS\System32\DRIVERS\srv.sys
Service Name: Srv
Module Base: ABD29000
Module End: ABD7B000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Service Name: Cdfs
Module Base: ABA57000
Module End: ABA67000
Hidden: No

Module Name: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20091002.003\navex15.sys
Service Name: NAVEX15
Module Base: AB60D000
Module End: AB74F000
Hidden: No

Module Name: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20091002.003\naveng.sys
Service Name: NAVENG
Module Base: AB5F9000
Module End: AB60D000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys
Service Name: wdmaud
Module Base: AB42C000
Module End: AB441000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys
Service Name: sysaudio
Module Base: ABB47000
Module End: ABB56000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\DMusic.sys
Service Name: DMusic
Module Base: AB4F9000
Module End: AB506000
Hidden: Yes

Module Name: C:\WINDOWS\system32\drivers\kmixer.sys
Service Name: kmixer
Module Base: AB3DE000
Module End: AB409000
Hidden: No

Module Name: C:\WINDOWS\system32\drivers\drmkaud.sys
Service Name: drmkaud
Module Base: F7AA6000
Module End: F7AA7000
Hidden: Yes

Module Name: C:\WINDOWS\System32\Drivers\HTTP.sys
Service Name: HTTP
Module Base: AB09D000
Module End: AB0DE000
Hidden: No

Module Name: C:\WINDOWS\System32\Drivers\SYMREDRV.SYS
Service Name: SYMREDRV
Module Base: AAD7D000
Module End: AAD87000
Hidden: No

******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwConnectPort
Address: AE9B1FC0
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwCreateFile
Address: AE9AEC80
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwCreateKey
Address: AE9C9170
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwCreatePort
Address: AE9B2580
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwCreateProcess
Address: AE9C6900
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwCreateProcessEx
Address: AE9C6B10
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwCreateSection
Address: AE9CAB10
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwCreateWaitablePort
Address: AE9B2670
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwDeleteFile
Address: AE9AF210
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwDeleteKey
Address: AE9C99F0
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwDeleteValueKey
Address: AEE5ACB0
Driver Base: AEE47000
Driver End: AEE69000
Driver Name: \??\C:\Program Files\Symantec\SYMEVENT.SYS

Function Name: ZwDuplicateObject
Address: AE9C6280
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwLoadKey
Address: AE9C9F10
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwLoadKey2
Address: AE9C9F90
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwOpenFile
Address: AE9AF070
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwOpenProcess
Address: AE9C8180
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwOpenThread
Address: AE9C7F40
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwRenameKey
Address: AE9CA6F0
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwReplaceKey
Address: AE9CA150
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwRequestWaitReplyPort
Address: AE9B1BE0
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwRestoreKey
Address: AE9CA540
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwSecureConnectPort
Address: AE9B2190
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwSetInformationFile
Address: AE9AF440
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwSetValueKey
Address: AEE5AF10
Driver Base: AEE47000
Driver End: AEE69000
Driver Name: \??\C:\Program Files\Symantec\SYMEVENT.SYS

Function Name: ZwSystemDebugControl
Address: AE9C7200
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

Function Name: ZwTerminateProcess
Address: AE9C7080
Driver Base: AE990000
Driver End: AE9FB000
Driver Name: \SystemRoot\System32\vsdatant.sys

******************************************************************************************
******************************************************************************************
Kernel Hooks:
Hooked Function: PsGetProcessWin32WindowStation
At Address: 804F41EC
Jump To: FD806070
Module Name: _unknown_

Hooked Function: PsGetProcessJob
At Address: 804F41EC
Jump To: FD806070
Module Name: _unknown_

******************************************************************************************
******************************************************************************************
IRP Hooks:
Hooked Module: C:\WINDOWS\System32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: AE9D6880
Hooking Module: C:\WINDOWS\System32\vsdatant.sys

Hooked Module: C:\WINDOWS\System32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: AE9D6880
Hooking Module: C:\WINDOWS\System32\vsdatant.sys

Hooked Module: C:\WINDOWS\System32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: AE9D6880
Hooking Module: C:\WINDOWS\System32\vsdatant.sys

Hooked Module: C:\WINDOWS\System32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: AE9D6880
Hooking Module: C:\WINDOWS\System32\vsdatant.sys

Hooked Module: C:\WINDOWS\System32\DRIVERS\tcpip.sys
Hooked IRP: IRP_MJ_CLEANUP
Jump To: AE9D6880
Hooking Module: C:\WINDOWS\System32\vsdatant.sys

******************************************************************************************
******************************************************************************************
Ports:
Local Address: DESKTOP.HAWAII.RR.COM:139
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING

Local Address: DESKTOP:27015
Remote Address: LOCALHOST:1041
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: ESTABLISHED

Local Address: DESKTOP:27015
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: LISTENING

Local Address: DESKTOP:5354
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: LISTENING

Local Address: DESKTOP:1041
Remote Address: LOCALHOST:27015
Type: TCP
Process: C:\Program Files\iTunes\iTunesHelper.exe
State: ESTABLISHED

Local Address: DESKTOP:1039
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE
State: LISTENING

Local Address: DESKTOP:1027
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\alg.exe
State: LISTENING

Local Address: DESKTOP:14375
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\DNA\btdna.exe
State: LISTENING

Local Address: DESKTOP:2869
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING

Local Address: DESKTOP:445
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING

Local Address: DESKTOP:135
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING

Local Address: DESKTOP.HAWAII.RR.COM:5353
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA

Local Address: DESKTOP.HAWAII.RR.COM:1900
Remote Address: NA
Type: UDP
Process: C:\Program Files\DNA\btdna.exe
State: NA

Local Address: DESKTOP.HAWAII.RR.COM:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA

Local Address: DESKTOP.HAWAII.RR.COM:138
Remote Address: NA
Type: UDP
Process: System
State: NA

Local Address: DESKTOP.HAWAII.RR.COM:137
Remote Address: NA
Type: UDP
Process: System
State: NA

Local Address: DESKTOP.HAWAII.RR.COM:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA

Local Address: DESKTOP:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA

Local Address: DESKTOP:1053
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA

Local Address: DESKTOP:1052
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\explorer.exe
State: NA

Local Address: DESKTOP:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA

Local Address: DESKTOP:51082
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA

Local Address: DESKTOP:14375
Remote Address: NA
Type: UDP
Process: C:\Program Files\DNA\btdna.exe
State: NA

Local Address: DESKTOP:4500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA

Local Address: DESKTOP:1434
Remote Address: NA
Type: UDP
Process: C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
State: NA

Local Address: DESKTOP:1025
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA

Local Address: DESKTOP:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA

Local Address: DESKTOP:445
Remote Address: NA
Type: UDP
Process: System
State: NA

******************************************************************************************
******************************************************************************************
Go to the top of the page
 
+Quote Post
hammerman
post Oct 3 2009, 08:48 PM
Post #4


Trusted Helper
Group Icon
Posts: 1,499
From: UK
OS: XP



Hello,

Please follow these steps.

-- Step 1 --

I notice you are running one or more Peer-to-Peer (P2P) programs. The files shared by P2P programs are often infected with viruses and malware, even though they may appear to be legitimate. For this reason, I would recommend you uninstall them. If you decide to keep them, I ask that you do not use them while we are fixing your problem.

An article indicating the Dangers of P2P can be found here

-- Step 2 --

While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent malware removal tools from fixing certain things.
Please disable TeaTimer for now until you are clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click "Advanced mode" if not already selected.
  • Choose "Yes" at the Warning prompt.
  • Expand the "Tools" menu.
  • Click "Resident".
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • In the File menu click "Exit" to exit Spybot Search & Destroy.


-- Step 3 --

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

QUOTE
[Kill All Processes]
[Unregister Dlls]
[Registry - Safe List]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {0A87E45F-537A-40B4-B812-E2544C21A09F} [HKLM] -> Reg Error: Value error. [SpywareBlock Class]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> "" [HKLM] -> Reg Error: Key error. [Reg Error: Value error.]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YY -> "wefowuwus" -> C:\WINDOWS\System32\wobihasa.DLL [Rundll32.exe "c:\windows\system32\wobihasa.dll",a]
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{A75C6120-9B36-11d4-A3F0-009027427750}" [HKLM] -> [Reg Error: Key error.]
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls
YY -> c:\windows\system32\gisisema.dll -> C:\WINDOWS\System32\gisisema.dll
YY -> c:\windows\system32\yudegoku.dll -> C:\WINDOWS\System32\yudegoku.dll
YY -> tehunevo.dll -> C:\WINDOWS\System32\tehunevo.dll
YY -> c:\windows\system32\wobihasa.dll -> C:\WINDOWS\System32\wobihasa.dll
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
YN -> "{324fc3bb-4f3e-4c51-84b7-1689cfe42ed0}" [HKLM] -> C:\WINDOWS\System32\yudegoku.dll [ganokiboy]
YN -> "{de4e9e38-28ca-4548-8ac1-ad002276dd90}" [HKLM] -> C:\WINDOWS\System32\gisisema.dll [kawuhesud]
YY -> "{d045846b-9cd4-48bf-b327-b0f6757c4d5f}" [HKLM] -> C:\WINDOWS\System32\wobihasa.dll [sebugeban]
< SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
YN -> "{324fc3bb-4f3e-4c51-84b7-1689cfe42ed0}" [HKLM] -> C:\WINDOWS\System32\yudegoku.dll [tokatiluy]
YY -> "{d045846b-9cd4-48bf-b327-b0f6757c4d5f}" [HKLM] -> C:\WINDOWS\System32\wobihasa.dll [mujuzedij]
YN -> "{de4e9e38-28ca-4548-8ac1-ad002276dd90}" [HKLM] -> C:\WINDOWS\System32\gisisema.dll [tokatiluy]
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
YN -> "C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe" -> C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe [C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe:*:Enabled:14267034]
YN -> "C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe" -> C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe [C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe:*:Enabled:16496404]
YN -> "C:\Program Files\LimeWire\LimeWire.exe" -> C:\Program Files\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire]
YN -> "E:\setup\HPZNUI01.EXE" -> E:\setup\HPZNUI01.EXE [E:\setup\HPZNUI01.EXE:*:Enabled:hpznui01.exe]
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8} ->
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\AutoRun\command ->
YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\AutoRun\command\\"" -> J:\Autorun.exe [J:\Autorun.exe /run]
YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8} ->
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell00\Command ->
YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell00\Command\\"" -> J:\Autorun.exe [J:\Autorun.exe /run]
YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8} ->
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell01\Command ->
YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell01\Command\\"" -> J:\Autorun.exe [J:\Autorun.exe /action]
YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8} ->
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell02\Command ->
YN -> \{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell02\Command\\"" -> J:\Autorun.exe [J:\Autorun.exe /uninstall]
[Files/Folders - Modified Within 30 Days]
NY -> mehudebe -> C:\WINDOWS\System32\mehudebe
NY -> wobihasa.dll -> C:\WINDOWS\System32\wobihasa.dll
NY -> vokafifu.dll -> C:\WINDOWS\System32\vokafifu.dll
NY -> famatoge.dll -> C:\WINDOWS\System32\famatoge.dll
NY -> wayolelu.dll -> C:\WINDOWS\System32\wayolelu.dll
[Files - No Company Name]
NY -> wobihasa.dll -> C:\WINDOWS\System32\wobihasa.dll
NY -> tehunevo.dll -> C:\WINDOWS\System32\tehunevo.dll
NY -> fedoniko.dll -> C:\WINDOWS\System32\fedoniko.dll
NY -> vokafifu.dll -> C:\WINDOWS\System32\vokafifu.dll
NY -> famatoge.dll -> C:\WINDOWS\System32\famatoge.dll
NY -> wayolelu.dll -> C:\WINDOWS\System32\wayolelu.dll
[Custom Items]
:files
C:\Documents and Settings\All Users\Application Data\14267034
C:\Documents and Settings\All Users\Application Data\16496404
:end
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.

-- Step 4 --

Run Malwarebytes' Anti-Malware.
  • Select the Update tab and then click Check for Updates. If an update is found, it will download and install the latest version.
  • Select the Scanner tab, select "Perform full scan", then click Scan
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

-- Step 5 --

Run OTL and select Minimal Output. Use the Quick Scan button to start a scan.
Please post the OTL report in your reply.

-- Step 6 --

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<--- ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.

Do you recognise this file?

C:\Documents and Settings\JD\Start Menu\Programs\Startup\TempClean.bat

Go to the top of the page
 
+Quote Post
BuzzBoy22
post Oct 4 2009, 08:18 AM
Post #5


New Member
*
Posts: 9
OS: XP



hammerman,

For some reason Spybot Search and Destroy would hang ever time I clicked the "Resident" button, so I manually terminated TeaTimer after each reboot.

The TempClean.bat file is a batch file I created a long time ago to delete temp files.

Here are the log files:

CODE
OTS logfile created on: 10/3/2009 10:34:25 AM - Run 1
OTS by OldTimer - Version 3.0.20.1     Folder = C:\Documents and Settings\JD\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.49 Gb Available Physical Memory | 32.45% Memory free
2.11 Gb Paging File | 1.28 Gb Available in Paging File | 60.66% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 180.00 Gb Total Space | 33.56 Gb Free Space | 18.65% Space Free | Partition Type: NTFS
Drive D: | 6.29 Gb Total Space | 1.12 Gb Free Space | 17.85% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DESKTOP
Current User Name: JD
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days

[Processes - Safe List]
aluschedulersvc.exe -> C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -> [2006/02/23 11:41:02 | 00,100,032 | ---- | M] (Symantec Corporation)
applemobiledeviceservice.exe -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/05/29 13:41:26 | 00,144,712 | ---- | M] (Apple Inc.)
ati2evxx.exe -> C:\WINDOWS\System32\Ati2evxx.exe -> [2004/11/03 21:38:10 | 00,413,696 | ---- | M] (ATI Technologies Inc.)
ati2evxx.exe -> C:\WINDOWS\System32\Ati2evxx.exe -> [2004/11/03 21:38:10 | 00,413,696 | ---- | M] (ATI Technologies Inc.)
atiptaxx.exe -> C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe -> [2004/11/03 21:10:00 | 00,344,064 | ---- | M] (ATI Technologies, Inc.)
btdna.exe -> C:\Program Files\DNA\btdna.exe -> [2009/01/13 21:10:40 | 00,342,848 | ---- | M] (BitTorrent, Inc.)
ccapp.exe -> C:\Program Files\Common Files\Symantec Shared\ccApp.exe -> [2006/03/07 13:02:14 | 00,053,408 | ---- | M] (Symantec Corporation)
ccevtmgr.exe -> C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -> [2006/03/07 13:02:34 | 00,192,160 | ---- | M] (Symantec Corporation)
ccsetmgr.exe -> C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -> [2006/03/07 13:03:02 | 00,169,632 | ---- | M] (Symantec Corporation)
defwatch.exe -> C:\Program Files\Symantec AntiVirus\DefWatch.exe -> [2006/03/17 06:34:12 | 00,030,448 | ---- | M] (Symantec Corporation)
doscan.exe -> C:\Program Files\Symantec AntiVirus\DoScan.exe -> [2006/03/17 06:34:12 | 00,024,816 | ---- | M] (Symantec Corporation)
ehsched.exe -> C:\WINDOWS\ehome\ehSched.exe -> [2008/04/13 14:12:18 | 00,084,992 | ---- | M] (Microsoft Corporation)
explorer.exe -> C:\WINDOWS\Explorer.EXE -> [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
fbdirect.exe -> C:\Program Files\Visioneer\PaperPort\FBDirect.exe -> [2000/09/22 10:13:40 | 00,227,328 | ---- | M] (Visioneer Inc.)
freeagentservice.exe -> C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe -> [2009/05/01 14:35:54 | 00,181,544 | ---- | M] (Seagate Technology LLC)
gearsec.exe -> C:\WINDOWS\System32\GEARSec.exe -> [2004/07/29 02:53:58 | 00,053,248 | ---- | M] (GEAR Software)
googlecrashhandler.exe -> C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe -> [2009/06/30 09:11:00 | 00,133,104 | ---- | M] (Google Inc.)
hpcmpmgr.exe -> C:\Program Files\HP\hpcoretech\hpcmpmgr.exe -> [2005/01/12 09:54:58 | 00,241,664 | ---- | M] (Hewlett-Packard Company)
hphmon05.exe -> C:\WINDOWS\System32\hphmon05.exe -> [2003/05/23 00:55:38 | 00,483,328 | ---- | M] (Hewlett-Packard)
hpqcmon.exe -> C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe -> [2002/10/07 05:23:20 | 00,090,112 | ---- | M] ()
hpqtra08.exe -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe -> [2007/03/11 21:26:24 | 00,210,520 | ---- | M] (Hewlett-Packard Co.)
incdsrv.exe -> C:\Program Files\Ahead\InCD\InCDsrv.exe -> [2005/01/03 06:40:42 | 00,854,528 | ---- | M] (Nero AG)
intuitupdateservice.exe -> C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -> [2008/10/10 05:45:26 | 00,013,088 | ---- | M] (Intuit Inc.)
ipodservice.exe -> C:\Program Files\iPod\bin\iPodService.exe -> [2009/09/08 21:09:30 | 00,545,568 | ---- | M] (Apple Inc.)
ipoint.exe -> C:\Program Files\Microsoft IntelliPoint\ipoint.exe -> [2006/07/07 13:15:07 | 00,600,896 | ---- | M] (Microsoft Corporation)
ituneshelper.exe -> C:\Program Files\iTunes\iTunesHelper.exe -> [2009/09/08 21:09:42 | 00,305,440 | ---- | M] (Apple Inc.)
itype.exe -> C:\Program Files\Microsoft IntelliType Pro\itype.exe -> [2006/07/07 13:14:38 | 00,576,320 | ---- | M] (Microsoft Corporation)
kbd.exe -> C:\HP\KBD\KBD.EXE -> [2005/02/02 16:44:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company)
mdnsresponder.exe -> C:\Program Files\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.)
mspmspsv.exe -> C:\WINDOWS\System32\MsPMSPSv.exe -> [2001/05/01 17:06:22 | 00,053,248 | ---- | M] (Microsoft Corporation)
ots.exe -> C:\Documents and Settings\JD\Desktop\OTS.exe -> [2009/10/03 10:31:02 | 00,519,680 | ---- | M] (OldTimer Tools)
photoshopelementsfileagent.exe -> C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -> [2008/09/16 12:03:18 | 00,169,312 | ---- | M] (Adobe Systems Incorporated)
pqv2isvc.exe -> C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe -> [2004/11/22 17:04:14 | 01,273,856 | ---- | M] (Symantec Corporation)
richvideo.exe -> C:\Program Files\CyberLink\Shared Files\RichVideo.exe -> [2005/08/07 18:54:00 | 00,167,936 | ---- | M] ()
rtvscan.exe -> C:\Program Files\Symantec AntiVirus\Rtvscan.exe -> [2006/03/17 06:34:20 | 01,799,408 | ---- | M] (Symantec Corporation)
shwicon2k.exe -> C:\Program Files\Multimedia Card Reader\shwicon2k.exe -> [2003/08/14 14:11:32 | 00,139,264 | ---- | M] (Alcor Micro, Corp.)
sqlbrowser.exe -> C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -> [2008/11/24 22:31:08 | 00,239,968 | ---- | M] (Microsoft Corporation)
sqlservr.exe -> C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -> [2008/11/24 22:31:10 | 29,263,712 | ---- | M] (Microsoft Corporation)
sqlwriter.exe -> C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -> [2008/11/24 22:31:12 | 00,087,904 | ---- | M] (Microsoft Corporation)
startupcoppro.exe -> C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe -> [2007/09/26 23:23:28 | 02,211,840 | ---- | M] (Ziff-Davis Media, Inc.)
stxmenumgr.exe -> C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe -> [2009/05/01 14:35:10 | 00,185,640 | ---- | M] (Seagate LLC)
teatimer.exe -> C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe -> [2009/03/05 16:07:20 | 02,260,480 | ---- | M] (Safer-Networking Ltd.)
tintsetp.exe -> C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE -> [2002/08/28 15:39:50 | 00,455,168 | ---- | M] (Microsoft Corporation)
vptray.exe -> C:\Program Files\Symantec AntiVirus\VPTray.exe -> [2006/03/17 06:34:30 | 00,124,656 | ---- | M] (Symantec Corporation)
vsmon.exe -> C:\WINDOWS\System32\ZoneLabs\vsmon.exe -> [2009/02/16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD)
wdfmgr.exe -> C:\WINDOWS\System32\wdfmgr.exe -> [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation)
windowssearch.exe -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe -> [2008/05/26 22:19:14 | 00,123,904 | ---- | M] (Microsoft Corporation)
wscntfy.exe -> C:\WINDOWS\System32\wscntfy.exe -> [2008/04/13 14:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation)
zlclient.exe -> C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe -> [2009/02/16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD)

[Win32 Services - Safe List]
(AdobeActiveFileMonitor7.0) Adobe Active File Monitor V7 [Win32_Own | Auto | Running] -> C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -> [2008/09/16 12:03:18 | 00,169,312 | ---- | M] (Adobe Systems Incorporated)
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/05/29 13:41:26 | 00,144,712 | ---- | M] (Apple Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation)
(Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\Ati2evxx.exe -> [2004/11/03 21:38:10 | 00,413,696 | ---- | M] (ATI Technologies Inc.)
(ATI Smart) ATI Smart [Win32_Own | Auto | Stopped] -> C:\WINDOWS\System32\ati2sgag.exe -> [2004/11/03 21:10:00 | 00,516,096 | ---- | M] ()
(Automatic LiveUpdate Scheduler) Automatic LiveUpdate Scheduler [Win32_Own | Auto | Running] -> C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -> [2006/02/23 11:41:02 | 00,100,032 | ---- | M] (Symantec Corporation)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> C:\Program Files\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.)
(ccEvtMgr) Symantec Event Manager [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -> [2006/03/07 13:02:34 | 00,192,160 | ---- | M] (Symantec Corporation)
(ccSetMgr) Symantec Settings Manager [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -> [2006/03/07 13:03:02 | 00,169,632 | ---- | M] (Symantec Corporation)
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation)
(DefWatch) Symantec AntiVirus Definition Watcher [Win32_Own | Auto | Running] -> C:\Program Files\Symantec AntiVirus\DefWatch.exe -> [2006/03/17 06:34:12 | 00,030,448 | ---- | M] (Symantec Corporation)
(ehSched) Media Center Scheduler Service [Win32_Own | Auto | Running] -> C:\WINDOWS\ehome\ehSched.exe -> [2008/04/13 14:12:18 | 00,084,992 | ---- | M] (Microsoft Corporation)
(FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> [2008/10/16 21:11:00 | 00,651,720 | ---- | M] (Macrovision Europe Ltd.)
(FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -> [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation)
(FreeAgentGoNext Service) Seagate Service [Win32_Own | Auto | Running] -> C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe -> [2009/05/01 14:35:54 | 00,181,544 | ---- | M] (Seagate Technology LLC)
(GEARSecurity) GEARSecurity [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\GEARSec.exe -> [2004/07/29 02:53:58 | 00,053,248 | ---- | M] (GEAR Software)
(getPlusHelper) getPlus(R) Helper [Win32_Own | On_Demand | Stopped] -> C:\Program Files\NOS\bin\getPlus_Helper.dll -> [2009/08/07 12:44:18 | 00,045,816 | ---- | M] (NOS Microsystems Ltd.)
(gupdate1c9827bbeb07656) Google Update Service (gupdate1c9827bbeb07656) [Win32_Own | Auto | Stopped] -> C:\Program Files\Google\Update\GoogleUpdate.exe -> [2009/01/29 15:40:22 | 00,133,104 | ---- | M] (Google Inc.)
(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2007/01/03 15:40:21 | 00,136,120 | ---- | M] (Google)
(helpsvc) Help and Support [Win32_Shared | Auto | Running] -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/13 14:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation)
(hpqcxs08) hpqcxs08 [Win32_Shared | On_Demand | Running] -> C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -> [2007/05/16 22:13:44 | 00,217,088 | ---- | M] (Hewlett-Packard Co.)
(hpqddsvc) HP CUE DeviceDiscovery Service [Win32_Shared | Auto | Running] -> C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -> [2007/05/16 22:13:44 | 00,131,072 | ---- | M] (Hewlett-Packard Co.)
(HPSLPSVC) HP Network Devices Support [Win32_Shared | Auto | Running] -> C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL -> [2007/05/16 22:13:08 | 00,602,112 | ---- | M] (Hewlett-Packard Co.)
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -> [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation)
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation)
(InCDsrv) InCD Helper [Win32_Own | Auto | Running] -> C:\Program Files\Ahead\InCD\InCDsrv.exe -> [2005/01/03 06:40:42 | 00,854,528 | ---- | M] (Nero AG)
(IntuitUpdateService) Intuit Update Service [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -> [2008/10/10 05:45:26 | 00,013,088 | ---- | M] (Intuit Inc.)
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> C:\Program Files\iPod\bin\iPodService.exe -> [2009/09/08 21:09:30 | 00,545,568 | ---- | M] (Apple Inc.)
(Lavasoft Ad-Aware Service) Lavasoft Ad-Aware Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -> [2009/09/27 10:42:25 | 01,028,432 | ---- | M] (Lavasoft)
(LiveUpdate) LiveUpdate [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE -> [2006/02/23 11:41:02 | 02,045,632 | ---- | M] (Symantec Corporation)
(MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) [Win32_Own | Auto | Running] -> C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -> [2008/11/24 22:31:10 | 29,263,712 | ---- | M] (Microsoft Corporation)
(MSSQLServerADHelper) SQL Server Active Directory Helper [Win32_Own | Disabled | Stopped] -> C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -> [2008/11/24 22:31:08 | 00,045,408 | ---- | M] (Microsoft Corporation)
(Net Driver HPZ12) Net Driver HPZ12 [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\HPZinw12.dll -> [2006/10/31 13:56:24 | 00,043,520 | ---- | M] (Hewlett-Packard)
(NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation)
(Norton Ghost) Norton Ghost [Win32_Own | Auto | Running] -> C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe -> [2004/11/22 17:04:14 | 01,273,856 | ---- | M] (Symantec Corporation)
(odserv) Microsoft Office Diagnostics Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -> [2008/11/04 01:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -> [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation)
(Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\HPZipm12.dll -> [2006/10/31 13:56:28 | 00,052,736 | ---- | M] (Hewlett-Packard)
(RichVideo) Cyberlink RichVideo Service(CRVS) [Win32_Own | Auto | Running] -> C:\Program Files\CyberLink\Shared Files\RichVideo.exe -> [2005/08/07 18:54:00 | 00,167,936 | ---- | M] ()
(SavRoam) SavRoam [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Symantec AntiVirus\SavRoam.exe -> [2006/03/17 06:34:24 | 00,115,952 | ---- | M] (symantec)
(SNDSrvc) Symantec Network Drivers Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -> [2006/01/24 20:06:58 | 00,214,720 | ---- | M] (Symantec Corporation)
(SPBBCSvc) Symantec SPBBCSvc [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -> [2006/02/06 12:50:24 | 01,160,848 | ---- | M] (Symantec Corporation)
(SQLBrowser) SQL Server Browser [Win32_Own | Auto | Running] -> C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -> [2008/11/24 22:31:08 | 00,239,968 | ---- | M] (Microsoft Corporation)
(SQLWriter) SQL Server VSS Writer [Win32_Own | Auto | Running] -> C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -> [2008/11/24 22:31:12 | 00,087,904 | ---- | M] (Microsoft Corporation)
(Symantec AntiVirus) Symantec AntiVirus [Win32_Own | Auto | Running] -> C:\Program Files\Symantec AntiVirus\Rtvscan.exe -> [2006/03/17 06:34:20 | 01,799,408 | ---- | M] (Symantec Corporation)
(UMWdf) Windows User Mode Driver Framework [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\wdfmgr.exe -> [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation)
(vsmon) TrueVector Internet Monitor [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\ZoneLabs\vsmon.exe -> [2009/02/16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD)
(WMDM PMSP Service) WMDM PMSP Service [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\MsPMSPSv.exe -> [2001/05/01 17:06:22 | 00,053,248 | ---- | M] (Microsoft Corporation)

[Driver Services - Safe List]
(61883) 61883 Unit Device [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\61883.sys -> [2008/04/13 08:46:20 | 00,048,128 | ---- | M] (Microsoft Corporation)
(AFS2K) AFS2K [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\AFS2K.SYS -> [2004/08/04 15:49:09 | 00,043,672 | ---- | M] (Oak Technology Inc.)
(ALCXSENS) Service for WDM 3D Audio Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\ALCXSENS.SYS -> [2004/02/17 00:49:14 | 00,391,424 | ---- | M] (Sensaura Ltd)
(ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\ALCXWDM.SYS -> [2004/10/01 05:24:02 | 02,279,424 | ---- | M] (Realtek Semiconductor Corp.)
(ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -> [2004/11/03 21:40:04 | 00,821,248 | ---- | M] (ATI Technologies Inc.)
(Avc) AVC Device [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\avc.sys -> [2008/04/13 08:46:20 | 00,038,912 | ---- | M] (Microsoft Corporation)
(Cdr4_xp) Cdr4_xp [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\cdr4_xp.sys -> [2006/10/04 16:42:42 | 00,002,432 | ---- | M] (Sonic Solutions)
(Cdralw2k) Cdralw2k [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\cdralw2k.sys -> [2006/10/04 16:42:42 | 00,002,560 | ---- | M] (Sonic Solutions)
(cdrbsdrv) cdrbsdrv [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\CDRBSDRV.SYS -> [2004/03/08 12:55:50 | 00,013,567 | ---- | M] (B.H.A Corporation)
(cdudf_xp) cdudf_xp [File_System | System | Running] -> C:\WINDOWS\System32\drivers\Cdudf_xp.sys -> [2006/11/12 15:44:37 | 00,259,456 | ---- | M] (Roxio)
(CX23880) Conexant 23880 Video Capture [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\cx88vid.sys -> [2003/12/10 18:40:06 | 00,193,408 | ---- | M] (Conexant Systems, Inc.)
(CX88ENC) Conexant 2388x MPEG Encoder [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\cx88enc.sys -> [2003/12/10 18:40:02 | 00,295,552 | ---- | M] (Conexant Systems, Inc.)
(CX88XBAR) Conexant 2388x Crossbar Dual Input [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\CX88XBARDUAL.sys -> [2003/12/10 18:40:08 | 00,007,040 | ---- | M] (Conexant Systems, Inc.)
(CXTUNE) Conexant 2388x Tuner [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\CX88TUNE.sys -> [2003/12/10 18:40:04 | 00,030,080 | ---- | M] (Conexant Systems, Inc.)
(dvd_2K) dvd_2K [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\Dvd_2k.sys -> [2003/07/18 17:25:16 | 00,021,993 | ---- | M] (Roxio)
(eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -> [2009/08/26 22:00:00 | 00,371,248 | ---- | M] (Symantec Corporation)
(elagopro) GoProto Protocol Driver for LELA [Kernel | Auto | Running] -> C:\WINDOWS\System32\DRIVERS\elagopro.sys -> [2007/03/22 12:57:14 | 00,028,672 | --S- | M] (Gteko Ltd.)
(elaunidr) UniDriver for LELA [Kernel | Auto | Running] -> C:\WINDOWS\System32\DRIVERS\elaunidr.sys -> [2007/03/22 12:57:14 | 00,005,376 | --S- | M] (Gteko Ltd.)
(EraserUtilRebootDrv) EraserUtilRebootDrv [Kernel | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -> [2009/08/26 22:00:00 | 00,102,448 | ---- | M] (Symantec Corporation)
(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys -> [2009/05/18 14:17:00 | 00,026,600 | ---- | M] (GEAR Software Inc.)
(ialm) ialm [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\ialmnt5.sys -> [2003/10/08 16:11:20 | 00,093,979 | ---- | M] (Intel Corporation)
(InCDfs) InCD File System [File_System | Disabled | Running] -> C:\WINDOWS\System32\drivers\InCDfs.sys -> [2005/01/03 06:33:44 | 00,099,456 | ---- | M] (Nero AG)
(InCDPass) InCDPass [Kernel | System | Running] -> C:\WINDOWS\System32\DRIVERS\InCDPass.sys -> [2005/01/03 06:33:24 | 00,028,928 | ---- | M] (Nero AG)
(incdrm) InCD Reader [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\InCDrm.sys -> [2005/01/03 06:33:18 | 00,027,776 | ---- | M] (Nero AG)
(IrBus) Infrared bus filter driver for eHome remote controls [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\IrBus.sys -> [2008/04/13 08:45:34 | 00,046,592 | ---- | M] (Microsoft Corporation)
(LaCieFWFilter) Silver 1394 Filter (1394 BUS Filter Driver) [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\LaCieFWFilter.sys -> [2005/10/18 07:28:08 | 00,014,848 | ---- | M] (LaCie Group S.A.)
(LaCieUSBFilter) Silver USB Filter (USB BUS Filter Driver) [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\LaCieUSBFilter.sys -> [2005/10/19 08:34:02 | 00,015,872 | ---- | M] (LaCie Group)
(Lbd) Lbd [File_System | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\Lbd.sys -> [2009/01/25 10:41:57 | 00,064,160 | ---- | M] (Lavasoft AB)
(ltmodem5) Agere Modem Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys -> [2003/07/01 21:33:00 | 00,652,497 | ---- | M] (Agere Systems)
(LVUSBSta) Logitech USB Monitor Filter [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\lvusbsta.sys -> [2005/01/31 00:12:46 | 00,022,016 | R--- | M] (Logitech Inc.)
(MASPINT) MASPINT [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\MASPINT.SYS -> [2000/03/29 12:11:20 | 00,008,096 | ---- | M] (MicroStaff Co.,Ltd.)
(mmc_2K) mmc_2K [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\Mmc_2k.sys -> [2003/07/18 17:25:14 | 00,022,745 | ---- | M] (Roxio)
(MN710-51) Microsoft(R) Wireless USB 2.0 Adapter [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\MN710-51.sys -> [2004/01/07 10:04:00 | 00,339,520 | ---- | M] (GlobespanVirata, Inc.)
(MSDV) Microsoft DV Camera and VCR [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\msdv.sys -> [2008/04/13 08:46:09 | 00,051,200 | ---- | M] (Microsoft Corporation)
(NAVENG) NAVENG [Kernel | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\VirusDefs\20091002.003\NAVENG.SYS -> [2009/08/26 22:00:00 | 00,084,912 | ---- | M] (Symantec Corporation)
(NAVEX15) NAVEX15 [Kernel | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\VirusDefs\20091002.003\NAVEX15.SYS -> [2009/08/26 22:00:00 | 01,323,568 | ---- | M] (Symantec Corporation)
(NuidFltr) NUID filter driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\NuidFltr.sys -> [2009/05/09 01:14:20 | 00,014,736 | ---- | M] (Microsoft Corporation)
(nv) nv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -> [2004/08/03 19:29:54 | 01,897,408 | ---- | M] (NVIDIA Corporation)
(pepifilter) Volume Adapter [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\lv302af.sys -> [2005/01/31 00:19:20 | 00,007,104 | R--- | M] (Logitech Inc.)
(pfc) Padus ASPI Shell [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\pfc.sys -> [2002/10/01 04:22:32 | 00,009,856 | ---- | M] (Padus, Inc.)
(PID_08A0) QuickCam IM(PID_08A0) [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\LV302AV.SYS -> [2005/01/31 00:26:06 | 00,912,768 | R--- | M] (Logitech Inc.)
(PIXMCV) JVC Communication PIX-MCV Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\pixmcvc.sys -> [2002/09/28 04:08:08 | 00,032,000 | R--- | M] (Pixela)
(PIXMCVA) JVC PIX-MCV Audio Capture [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\pixmcva.sys -> [2002/10/03 18:53:22 | 00,028,057 | R--- | M] (Pixela)
(PIXMCVV) JVC PIX-MCV Video Capture [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\pixmcvv.sys -> [2002/11/28 00:16:36 | 00,021,081 | R--- | M] (Pixela)
(Point32) Microsoft IntelliPoint Filter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\point32.sys -> [2006/06/29 22:51:21 | 00,021,760 | ---- | M] (Microsoft Corporation)
(PQIMount) PQIMount [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\PQIMount.sys -> [2004/11/22 17:08:54 | 00,046,800 | ---- | M] (PowerQuest Corporation)
(PQV2i) PQV2i [File_System | Boot | Running] -> C:\WINDOWS\System32\drivers\PQV2i.sys -> [2004/11/22 16:51:58 | 00,138,801 | ---- | M] (StorageCraft)
(Ps2) Ps2 [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\PS2.sys -> [2005/12/12 17:27:00 | 00,019,072 | ---- | M] (Hewlett-Packard Company)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ptilink.sys -> [2003/07/30 02:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.)
(pwd_2k) pwd_2k [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\pwd_2K.sys -> [2003/07/18 17:25:10 | 00,118,409 | ---- | M] (Roxio)
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> C:\WINDOWS\System32\DRIVERS\PxHelp20.sys -> [2008/10/16 21:05:04 | 00,043,528 | ---- | M] (Sonic Solutions)
(rtl8139) Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\R8139n51.SYS -> [2002/10/04 15:04:10 | 00,046,976 | ---- | M] (Realtek Semiconductor Corporation       )
(SAVRT) SAVRT [Kernel | System | Running] -> C:\Program Files\Symantec AntiVirus\savrt.sys -> [2005/12/19 20:41:56 | 00,337,592 | ---- | M] (Symantec Corporation)
(SAVRTPEL) SAVRTPEL [Kernel | System | Running] -> C:\Program Files\Symantec AntiVirus\Savrtpel.sys -> [2005/12/19 20:41:58 | 00,054,968 | ---- | M] (Symantec Corporation)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\secdrv.sys -> [2007/11/13 00:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(Ser2pl) Prolific2 Serial port driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\ser2pl.sys -> [2005/07/25 10:04:08 | 00,048,640 | ---- | M] (Prolific Technology Inc.)
(SPBBCDrv) SPBBCDrv [Kernel | On_Demand | Stopped] -> C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -> [2006/02/06 12:50:22 | 00,389,776 | ---- | M] (Symantec Corporation)
(srescan) srescan [Kernel | Boot | Running] -> C:\WINDOWS\system32\ZoneLabs\srescan.sys -> [2008/11/17 02:24:00 | 00,051,688 | ---- | M] (Check Point Software Technologies LTD)
(StillCam) Still Serial Digital Camera Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\serscan.sys -> [2001/08/17 13:53:32 | 00,006,784 | ---- | M] (Microsoft Corporation)
(SunkFilt) Alcor Micro Corp - 9360 [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\sunkfilt.sys -> [2003/08/13 15:50:36 | 00,039,648 | ---- | M] (Alcor Micro Corp.)
(SymEvent) SymEvent [Kernel | Disabled | Running] -> C:\Program Files\Symantec\SYMEVENT.SYS -> [2006/01/31 13:29:20 | 00,107,696 | ---- | M] (Symantec Corporation)
(SYMREDRV) SYMREDRV [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -> [2006/01/24 20:06:32 | 00,024,768 | ---- | M] (Symantec Corporation)
(SYMTDI) SYMTDI [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\SYMTDI.SYS -> [2006/01/24 20:06:36 | 00,195,776 | ---- | M] (Symantec Corporation)
(UdfReadr_xp) UdfReadr_xp [File_System | System | Running] -> C:\WINDOWS\System32\drivers\UdfReadr_xp.sys -> [2003/07/18 17:22:06 | 00,213,120 | ---- | M] (Roxio)
(USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\usbaapl.sys -> [2009/08/28 19:42:52 | 00,040,448 | ---- | M] (Apple, Inc.)
(usbaudio) USB Audio Driver (WDM) [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\usbaudio.sys -> [2008/04/13 08:45:12 | 00,060,032 | ---- | M] (Microsoft Corporation)
(vsdatant) vsdatant [Kernel | System | Running] -> C:\WINDOWS\System32\vsdatant.sys -> [2009/02/16 00:10:26 | 00,353,672 | ---- | M] (Check Point Software Technologies LTD)
({6080A529-897E-4629-A488-ABA0C29B635E}) Intel(R) Graphics Platform (SoftBIOS) Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\ialmsbw.sys -> [2003/10/08 16:12:24 | 00,120,830 | ---- | M] (Intel Corporation)
({D31A0762-0CEB-444e-ACFF-B049A1F6FE91}) Intel(R) Graphics Chipset (KCH) Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\ialmkchw.sys -> [2003/10/08 16:12:16 | 00,098,842 | ---- | M] (Intel Corporation)

[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" ->  [binary data] ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://www.google.com/ie ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: Main\\"Default_Page_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome ->
HKEY_USERS\.DEFAULT\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\.DEFAULT\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\.DEFAULT\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ ->
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: Main\\"Default_Page_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome ->
HKEY_USERS\S-1-5-18\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-18\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-18\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ ->
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
HKEY_USERS\S-1-5-19\: Main\\"Default_Page_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome ->
HKEY_USERS\S-1-5-19\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-19\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-19\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ ->
HKEY_USERS\S-1-5-19\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
HKEY_USERS\S-1-5-20\: Main\\"Default_Page_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome ->
HKEY_USERS\S-1-5-20\: Main\\"Default_Search_URL" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-20\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-20\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ ->
HKEY_USERS\S-1-5-20\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> ->
HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: Main\\"Search Page" -> http://www.google.com ->
HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: Main\\"SearchMigratedDefaultName" -> Google ->
HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: Main\\"SearchMigratedDefaultURL" -> http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 ->
HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: Main\\"Start Page" -> http://www.rr.com/ ->
HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: SearchURL\\"" -> http://www.google.com/keyword/%s ->
HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: "ProxyEnable" -> 0 ->
HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\: "ProxyOverride" -> localhost;*.local ->
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\JD\Application Data\Mozilla\FireFox\Profiles\v2nyddyy.default\prefs.js ->
browser.startup.homepage -> "http://www.google.com/" ->
extensions.enabledItems -> {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1 ->
extensions.enabledItems -> 6 ->
extensions.enabledItems -> 2 ->
extensions.enabledItems -> 41 ->
extensions.enabledItems -> {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.96 ->
extensions.enabledItems -> {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5 ->
extensions.enabledItems -> {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.32.0 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 ->
extensions.enabledItems -> {20a82645-c095-46ed-80e3-08825760534b}:1.1 ->
extensions.enabledItems -> statusbar@toodledo.com:1.60 ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions ->  ->
HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/06/24 03:04:09 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8} -> C:\PROGRAM FILES\GOOGLE\GOOGLE GEARS\FIREFOX [C:\PROGRAM FILES\GOOGLE\GOOGLE GEARS\FIREFOX\] -> [2009/09/08 10:18:41 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions ->  ->
HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components -> C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/09/09 19:16:03 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins -> C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/09/09 19:16:03 | 00,000,000 | ---D | M]
< FireFox Extensions [User Folders] > ->
-> C:\Documents and Settings\JD\Application Data\mozilla\Extensions -> [2008/06/18 18:29:12 | 00,000,000 | ---D | M]
-> C:\Documents and Settings\JD\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2008/06/18 18:29:12 | 00,000,000 | ---D | M]
-> C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions -> [2009/09/09 19:18:33 | 00,103,106 | ---- | M] ()
-> C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{1AF3FC34-0725-4485-A939-6B40EB7CA96A} -> [2009/09/09 19:18:33 | 00,103,106 | ---- | M] ()
-> C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} -> [2009/09/09 19:18:33 | 00,103,106 | ---- | M] ()
-> C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} -> [2009/09/09 19:18:33 | 00,103,106 | ---- | M] ()
-> C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} -> [2009/09/09 19:18:33 | 00,103,106 | ---- | M] ()
-> C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\statusbar@toodledo.com -> [2009/09/09 19:18:33 | 00,103,106 | ---- | M] ()
< FireFox SearchPlugins [User Folders] > ->
C:\Documents and Settings\JD\Application Data\Mozilla\FireFox\Profiles\v2nyddyy.default\searchplugins\ -> C:\Documents and Settings\JD\Application Data\Mozilla\FireFox\Profiles\v2nyddyy.default\searchplugins -> [2008/10/12 18:10:36 | 00,000,000 | ---D | M]
search.xml -> C:\Documents and Settings\JD\Application Data\Mozilla\FireFox\Profiles\v2nyddyy.default\searchplugins\search.xml -> [2008/10/12 18:10:36 | 00,000,276 | ---- | M] ()
< FireFox Extensions [Program Folders] > ->
-> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions -> [2009/09/09 19:16:03 | 10,776,568 | ---- | M] (Mozilla Foundation)
-> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} -> [2009/09/09 19:16:03 | 10,776,568 | ---- | M] (Mozilla Foundation)
-> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} -> [2009/09/09 19:16:03 | 10,776,568 | ---- | M] (Mozilla Foundation)
< FireFox Components [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX\components\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\components -> [2009/09/09 19:16:03 | 00,000,000 | ---D | M]
browserdirprovider.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\browserdirprovider.dll -> [2009/09/09 19:15:53 | 00,023,544 | ---- | M] (Mozilla Foundation)
brwsrcmp.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\brwsrcmp.dll -> [2009/09/09 19:15:53 | 00,137,208 | ---- | M] (Mozilla Foundation)
< FireFox Plugins [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins -> [2009/09/09 19:16:03 | 00,000,000 | ---D | M]
np32dsw.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\np32dsw.dll -> [2008/03/19 19:23:20 | 00,114,688 | ---- | M] (Adobe Systems, Inc.)
npbittorrent.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npbittorrent.dll -> [2008/09/03 14:11:24 | 00,054,600 | ---- | M] (BitTorrent, Inc.)
npCouponPrinter.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npCouponPrinter.dll -> [2008/06/17 20:43:04 | 00,086,016 | ---- | M] (Coupons, Inc.)
npLegitCheckPlugin.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npLegitCheckPlugin.dll -> [2007/10/11 14:17:50 | 01,435,688 | ---- | M] (Microsoft Corporation)
npnul32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npnul32.dll -> [2009/09/09 19:15:56 | 00,065,016 | ---- | M] (mozilla.org)
NPOFF12.DLL -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\NPOFF12.DLL -> [2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation)
nppdf32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\nppdf32.dll -> [2007/05/10 22:52:34 | 00,095,864 | ---- | M] (Adobe Systems Inc.)
NPPxIm.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\NPPxIm.dll -> [2006/09/07 10:08:58 | 00,618,496 | ---- | M] (Pixami)
NPPxPrn.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\NPPxPrn.dll -> [2006/09/07 10:08:58 | 00,819,200 | ---- | M] (Pixami)
npqtplugin.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin.dll -> [2009/09/09 19:02:21 | 00,159,744 | ---- | M] (Apple Inc.)
npqtplugin2.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin2.dll -> [2009/09/09 19:02:21 | 00,159,744 | ---- | M] (Apple Inc.)
npqtplugin3.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin3.dll -> [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.)
npqtplugin4.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin4.dll -> [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.)
npqtplugin5.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin5.dll -> [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.)
npqtplugin6.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin6.dll -> [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.)
npqtplugin7.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npqtplugin7.dll -> [2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.)
NPZoneSB.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\NPZoneSB.dll -> [2007/12/25 00:02:38 | 00,024,673 | ---- | M] (Check Point Software Technologies Ltd.)
np_gp.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\np_gp.dll -> [2009/08/07 12:44:18 | 00,030,400 | ---- | M] (NOS Microsystems Ltd.)
nsIQTScriptablePlugin.xpt -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\nsIQTScriptablePlugin.xpt -> [2007/05/22 18:16:49 | 00,002,394 | ---- | M] ()
QuickTimePlugin.class -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\QuickTimePlugin.cla -> [2009/09/09 19:02:21 | 00,004,208 | ---- | M] ()
ShockwavePlugin.class -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\ShockwavePlugin.cla -> [2008/03/19 18:33:36 | 00,001,144 | ---- | M] ()
< FireFox SearchPlugins [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins -> [2009/08/15 07:48:45 | 00,000,000 | ---D | M]
amazondotcom.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\amazondotcom.xml -> [2009/08/15 07:48:37 | 00,001,394 | ---- | M] ()
answers.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\answers.xml -> [2009/08/15 07:48:37 | 00,002,193 | ---- | M] ()
creativecommons.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\creativecommons.xml -> [2009/08/15 07:48:37 | 00,001,534 | ---- | M] ()
eBay.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\eBay.xml -> [2009/08/15 07:48:37 | 00,002,344 | ---- | M] ()
google.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\google.xml -> [2009/08/15 07:48:37 | 00,002,371 | ---- | M] ()
wikipedia.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\wikipedia.xml -> [2009/08/15 07:48:37 | 00,001,178 | ---- | M] ()
yahoo.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\yahoo.xml -> [2009/08/15 07:48:37 | 00,000,792 | ---- | M] ()
< HOSTS File > (319151 bytes and 10989 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
First 25 entries...
Reset Hosts
127.0.0.1    localhost
127.0.0.1    www.007guard.com
127.0.0.1    007guard.com
127.0.0.1    008i.com
127.0.0.1    www.008k.com
127.0.0.1    008k.com
127.0.0.1    www.00hq.com
127.0.0.1    00hq.com
127.0.0.1    010402.com
127.0.0.1    www.032439.com
127.0.0.1    032439.com
127.0.0.1    www.0scan.com
127.0.0.1    0scan.com
127.0.0.1    www.1000gratisproben.com
127.0.0.1    1000gratisproben.com
127.0.0.1    www.1001namen.com
127.0.0.1    1001namen.com
127.0.0.1    100888290cs.com
127.0.0.1    www.100888290cs.com
127.0.0.1    100sexlinks.com
127.0.0.1    www.100sexlinks.com
127.0.0.1    10sek.com
127.0.0.1    www.10sek.com
127.0.0.1    www.1-2005-search.com
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{0347C33E-8762-4905-BF09-768834316C61} [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [HP Print Enhancer] -> [2007/03/02 16:52:24 | 01,298,024 | R--- | M] (Hewlett-Packard Co.)
{053F9267-DC04-4294-A72C-58F732D338C0} [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [HP Print Clips] -> [2007/03/02 16:52:08 | 00,177,768 | R--- | M] (Hewlett-Packard Co.)
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/22 23:08:42 | 00,062,080 | ---- | M] (Adobe Systems Incorporated)
{0A87E45F-537A-40B4-B812-E2544C21A09F} [HKLM] -> Reg Error: Value error. [SpywareBlock Class] -> File not found
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> [2008/09/15 14:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited)
{724d43a9-0d85-11d4-9908-00400523e39a} [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll [Reg Error: Value error.] -> [2009/08/15 07:56:19 | 05,960,520 | ---- | M] (Siber Systems Inc.)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [SSVHelper Class] -> [2007/09/25 01:11:33 | 00,501,136 | ---- | M] (Sun Microsystems, Inc.)
{E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} [HKLM] -> C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll [Google Gears Helper] -> [2009/08/21 13:49:42 | 02,097,152 | ---- | M] (Google Inc.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"" [HKLM] -> Reg Error: Key error. [Reg Error: Value error.] -> File not found
"{724d43a0-0d85-11d4-9908-00400523e39a}" [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll [&RoboForm] -> [2009/08/15 07:56:19 | 05,960,520 | ---- | M] (Siber Systems Inc.)
"{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}" [HKLM] -> c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll [HP View] -> [2003/09/03 16:42:14 | 00,098,304 | ---- | M] (Hewlett-Packard Company)
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
ShellBrowser\\"{724D43A0-0D85-11D4-9908-00400523E39A}" [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll [&RoboForm] -> [2009/08/15 07:56:19 | 05,960,520 | ---- | M] (Siber Systems Inc.)
ShellBrowser\\"{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}" [HKLM] -> c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll [HP View] -> [2003/09/03 16:42:14 | 00,098,304 | ---- | M] (Hewlett-Packard Company)
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> c:\program files\google\googletoolbar1.dll [&Google] -> [2006/02/14 20:05:30 | 01,191,424 | ---- | M] (Google Inc.)
WebBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
WebBrowser\\"{724D43A0-0D85-11D4-9908-00400523E39A}" [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll [&RoboForm] -> [2009/08/15 07:56:19 | 05,960,520 | ---- | M] (Siber Systems Inc.)
WebBrowser\\"{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}" [HKLM] -> c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll [HP View] -> [2003/09/03 16:42:14 | 00,098,304 | ---- | M] (Hewlett-Packard Company)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"AppleSyncNotifier" -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe] -> [2009/08/13 15:51:42 | 00,177,440 | ---- | M] (Apple Inc.)
"ATIPTA" -> C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe] -> [2004/11/03 21:10:00 | 00,344,064 | ---- | M] (ATI Technologies, Inc.)
"CamMonitor" -> c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe ["c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe"] -> [2002/10/07 05:23:20 | 00,090,112 | ---- | M] ()
"ccApp" -> C:\Program Files\Common Files\Symantec Shared\ccApp.exe ["C:\Program Files\Common Files\Symantec Shared\ccApp.exe"] -> [2006/03/07 13:02:14 | 00,053,408 | ---- | M] (Symantec Corporation)
"HP Component Manager" -> C:\Program Files\HP\hpcoretech\hpcmpmgr.exe ["C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"] -> [2005/01/12 09:54:58 | 00,241,664 | ---- | M] (Hewlett-Packard Company)
"HPHmon05" -> C:\WINDOWS\System32\hphmon05.exe [C:\WINDOWS\System32\hphmon05.exe] -> [2003/05/23 00:55:38 | 00,483,328 | ---- | M] (Hewlett-Packard)
"hpqSRMon" -> C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe] -> [2007/08/22 16:31:16 | 00,080,896 | ---- | M] (Hewlett-Packard)
"IMEKRMIG6.1" -> C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE [C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE] -> [2003/07/30 09:00:00 | 00,044,032 | ---- | M] (Microsoft Corporation)
"IMJPMIG8.1" -> C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE ["C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32] -> [2004/08/03 19:31:59 | 00,208,952 | ---- | M] (Microsoft Corporation)
"IntelliPoint" -> C:\Program Files\Microsoft IntelliPoint\ipoint.exe ["C:\Program Files\Microsoft IntelliPoint\ipoint.exe"] -> [2006/07/07 13:15:07 | 00,600,896 | ---- | M] (Microsoft Corporation)
"iTunesHelper" -> C:\Program Files\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2009/09/08 21:09:42 | 00,305,440 | ---- | M] (Apple Inc.)
"itype" -> C:\Program Files\Microsoft IntelliType Pro\itype.exe ["C:\Program Files\Microsoft IntelliType Pro\itype.exe"] -> [2006/07/07 13:14:38 | 00,576,320 | ---- | M] (Microsoft Corporation)
"KBD" -> C:\HP\KBD\KBD.EXE [C:\HP\KBD\KBD.EXE] -> [2005/02/02 16:44:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company)
"Malwarebytes Anti-Malware (reboot)" -> C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe ["C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript] -> [2009/09/10 14:53:56 | 01,312,080 | ---- | M] (Malwarebytes Corporation)
"MaxMenuMgr" -> C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe ["C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"] -> [2009/05/01 14:35:10 | 00,185,640 | ---- | M] (Seagate LLC)
"MSPY2002" -> C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe [C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC] -> [2002/08/28 15:39:06 | 00,059,392 | ---- | M] ()
"Norton Ghost 9.0" -> C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe ["C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe"] -> [2004/11/22 17:20:54 | 01,126,400 | ---- | M] (Symantec Corporation)
"PHIME2002A" -> C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName] -> [2002/08/28 15:39:50 | 00,455,168 | ---- | M] (Microsoft Corporation)
"PHIME2002ASync" -> C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC] -> [2002/08/28 15:39:50 | 00,455,168 | ---- | M] (Microsoft Corporation)
"PP7600usb" -> C:\Program Files\Visioneer\PaperPort\FBDirect.exe [C:\PROGRA~1\VISION~1\PAPERP~1\FBDirect.exe] -> [2000/09/22 10:13:40 | 00,227,328 | ---- | M] (Visioneer Inc.)
"Recguard" -> C:\WINDOWS\SMINST\RECGUARD.EXE [C:\WINDOWS\SMINST\RECGUARD.EXE] -> [2002/09/13 19:42:26 | 00,212,992 | ---- | M] ()
"Sunkist2k" -> C:\Program Files\Multimedia Card Reader\shwicon2k.exe ["C:\Program Files\Multimedia Card Reader\shwicon2k.exe"] -> [2003/08/14 14:11:32 | 00,139,264 | ---- | M] (Alcor Micro, Corp.)
"vptray" -> C:\Program Files\Symantec AntiVirus\VPTray.exe [C:\PROGRA~1\SYMANT~1\VPTray.exe] -> [2006/03/17 06:34:30 | 00,124,656 | ---- | M] (Symantec Corporation)
"wefowuwus" -> C:\WINDOWS\System32\wobihasa.DLL [Rundll32.exe "c:\windows\system32\wobihasa.dll",a] -> [2009/10/03 05:21:32 | 00,091,136 | ---- | M] ()
"ZoneAlarm Client" -> C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe ["C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"] -> [2009/02/16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD)
< Run [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"BitTorrent DNA" -> C:\Program Files\DNA\btdna.exe ["C:\Program Files\DNA\btdna.exe"] -> [2009/01/13 21:10:40 | 00,342,848 | ---- | M] (BitTorrent, Inc.)
"SpybotSD TeaTimer" -> C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe] -> [2009/03/05 16:07:20 | 02,260,480 | ---- | M] (Safer-Networking Ltd.)
"Startup Cop Pro Startup Launcher" -> C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe ["C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe" /startup] -> [2007/09/26 23:23:28 | 02,211,840 | ---- | M] (Ziff-Davis Media, Inc.)
< Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup ->
< Aimee Startup Folder > -> C:\Documents and Settings\Aimee\Start Menu\Programs\Startup ->
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe -> [2007/03/11 21:26:24 | 00,210,520 | ---- | M] (Hewlett-Packard Co.)
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe -> [2008/05/26 22:19:14 | 00,123,904 | ---- | M] (Microsoft Corporation)
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Zone Labs Security.lnk -> C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe -> [2009/02/16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD)
< Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup ->
-> C:\Documents and Settings\Default User\Start Menu\Programs\Startup\AutoTBar.exe -> [2003/06/18 17:19:08 | 00,053,248 | ---- | M] ()
< JD Startup Folder > -> C:\Documents and Settings\JD\Start Menu\Programs\Startup ->
-> C:\Documents and Settings\JD\Start Menu\Programs\Startup\TempClean.bat -> [2005/11/25 11:11:20 | 00,000,030 | ---- | M] ()
< Kids Startup Folder > -> C:\Documents and Settings\Kids\Start Menu\Programs\Startup ->
< Software Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions
\Infodelivery\Restrictions\\"NoUpdateCheck" ->  [1] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main
\Main\\"DisableFirstRunCustomize" ->  [1] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoCDBurning" ->  [0] -> File not found
\\"LinkResolveIgnoreLinkInfo" ->  [0] -> File not found
\\"NoResolveSearch" ->  [1] -> File not found
\\"HonorAutoRunSetting" ->  [1] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
\\"DisableTaskMgr" ->  [0] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [149] -> File not found
\\"CDRAutoRun" ->  [0] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [149] -> File not found
\\"CDRAutoRun" ->  [0] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [149] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [149] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [149] -> File not found
\\"LinkResolveIgnoreLinkInfo" ->  [0] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"DisableTaskMgr" ->  [0] -> File not found
< Internet Explorer Menu Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport to Microsoft Excel -> C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE [res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000] -> File not found
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport to Microsoft Excel -> C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE [res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000] -> File not found
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\Software\Microsoft\Internet Explorer\MenuExt\ ->
&Google Search -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html] -> [2006/02/14 20:05:30 | 01,191,424 | ---- | M] (Google Inc.)
&Translate English Word -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html] -> [2006/02/14 20:05:30 | 01,191,424 | ---- | M] (Google Inc.)
Backward Links -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html] -> [2006/02/14 20:05:30 | 01,191,424 | ---- | M] (Google Inc.)
Cached Snapshot of Page -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html] -> [2006/02/14 20:05:30 | 01,191,424 | ---- | M] (Google Inc.)
Customize Menu -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html [file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html] -> [2009/08/15 07:56:51 | 00,000,212 | ---- | M] ()
E&xport to Microsoft Excel -> C:\Program Files\Microsoft Office\Office12\EXCEL.EXE [res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000] -> [2009/05/04 08:40:04 | 18,333,536 | ---- | M] (Microsoft Corporation)
Fill Forms -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html [file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html] -> [2009/08/15 07:56:51 | 00,000,206 | ---- | M] ()
Save Forms -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html [file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html] -> [2009/08/15 07:56:51 | 00,000,205 | ---- | M] ()
Similar Pages -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html] -> [2006/02/14 20:05:30 | 01,191,424 | ---- | M] (Google Inc.)
Translate Page into English -> C:\Program Files\Google\GoogleToolbar1.dll [res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html] -> [2006/02/14 20:05:30 | 01,191,424 | ---- | M] (Google Inc.)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} [HKLM] -> C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll [Menu: Sun Java Console] -> [2007/09/25 01:11:34 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
{09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5}:{0B4350D1-055F-47A3-B112-5F2F2B0D6F08} [HKLM] -> C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll [Menu: &Gears Settings] -> [2009/08/21 13:49:42 | 02,097,152 | ---- | M] (Google Inc.)
{320AF880-6646-11D3-ABEE-C5DBF3571F46}:file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html [Button: Fill Forms] -> [2009/08/15 07:56:51 | 00,000,206 | ---- | M] ()
{320AF880-6646-11D3-ABEE-C5DBF3571F46}:file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html [Menu: Fill Forms] -> [2009/08/15 07:56:51 | 00,000,206 | ---- | M] ()
{320AF880-6646-11D3-ABEE-C5DBF3571F49}:file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html [Button: Save] -> [2009/08/15 07:56:51 | 00,000,205 | ---- | M] ()
{320AF880-6646-11D3-ABEE-C5DBF3571F49}:file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html [Menu: Save Forms] -> [2009/08/15 07:56:51 | 00,000,205 | ---- | M] ()
{58ECB495-38F0-49cb-A538-10282ABF65E7}:{E763472E-A716-4CD9-89BD-DBDA6122F741} [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll [Button: HP Clipbook] -> [2007/03/02 16:53:20 | 00,153,192 | R--- | M] (Hewlett-Packard Co.)
{700259D7-1666-479a-93B1-3250410481E8}:{A93C41D8-01F8-4F8B-B14C-DE20B117E636} [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll [Button: HP Smart Select] -> [2007/03/02 16:53:20 | 00,153,192 | R--- | M] (Hewlett-Packard Co.)
{724d43aa-0d85-11d4-9908-00400523e39a}:file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html [Button: RoboForm] -> [2009/08/15 07:56:51 | 00,000,208 | ---- | M] ()
{724d43aa-0d85-11d4-9908-00400523e39a}:file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html [HKLM] -> C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html [Menu: RoboForm Toolbar] -> [2009/08/15 07:56:51 | 00,000,208 | ---- | M] ()
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL [Button: Research] -> [2009/03/06 04:04:56 | 00,039,464 | ---- | M] (Microsoft Corporation)
{d81ca86b-ef63-42af-bee3-4502d9a03c2d}:http://wwws.musicmatch.com/mmz/openWebRadio.html [HKLM] ->  [Button: MUSICMATCH MX Web Player] -> File not found
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [Menu: Spybot - Search & Destroy Configuration] -> [2008/09/15 14:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited)
{E28AB5C9-B58F-4512-AF80-29001BC5A29D}:Exec [HKLM] -> C:\Program Files\PokerTimeGuestMPP\MPPoker.exe [Button: PokerTime.net Poker] -> [2005/10/07 14:38:16 | 00,049,213 | ---- | M] (Microgaming)
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008/04/13 08:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/13 14:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/13 14:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> [2007/09/25 01:11:34 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\"{320AF880-6646-11D3-ABEE-C5DBF3571F46}" [HKLM] ->  [Fill Forms] -> File not found
CmdMapping\\"{320AF880-6646-11D3-ABEE-C5DBF3571F49}" [HKLM] ->  [Save] -> File not found
CmdMapping\\"{724d43aa-0d85-11d4-9908-00400523e39a}" [HKLM] ->  [RoboForm] -> File not found
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL [Research] -> [2009/03/06 04:04:56 | 00,039,464 | ---- | M] (Microsoft Corporation)
CmdMapping\\"{d81ca86b-ef63-42af-bee3-4502d9a03c2d}" [HKLM] -> C:\Program Files\MUSICMATCH\MUSICMATCH Media Center\MMRadioHostX.dll [MMRadioHostX Class] -> [2003/07/24 01:08:00 | 00,430,080 | ---- | M] (MUSICMATCH Inc)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 14:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> [2007/09/25 01:11:34 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\"{320AF880-6646-11D3-ABEE-C5DBF3571F46}" [HKLM] ->  [Fill Forms] -> File not found
CmdMapping\\"{320AF880-6646-11D3-ABEE-C5DBF3571F49}" [HKLM] ->  [Save] -> File not found
CmdMapping\\"{724d43aa-0d85-11d4-9908-00400523e39a}" [HKLM] ->  [RoboForm] -> File not found
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL [Research] -> [2009/03/06 04:04:56 | 00,039,464 | ---- | M] (Microsoft Corporation)
CmdMapping\\"{d81ca86b-ef63-42af-bee3-4502d9a03c2d}" [HKLM] -> C:\Program Files\MUSICMATCH\MUSICMATCH Media Center\MMRadioHostX.dll [MMRadioHostX Class] -> [2003/07/24 01:08:00 | 00,430,080 | ---- | M] (MUSICMATCH Inc)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 14:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> [2007/09/25 01:11:34 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\"{320AF880-6646-11D3-ABEE-C5DBF3571F46}" [HKLM] ->  [Fill Forms] -> File not found
CmdMapping\\"{320AF880-6646-11D3-ABEE-C5DBF3571F49}" [HKLM] ->  [Save] -> File not found
CmdMapping\\"{58ECB495-38F0-49cb-A538-10282ABF65E7}" [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll [HP Clipbook] -> [2007/03/02 16:53:20 | 00,153,192 | R--- | M] (Hewlett-Packard Co.)
CmdMapping\\"{700259D7-1666-479a-93B1-3250410481E8}" [HKLM] -> C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll [HP Smart Select] -> [2007/03/02 16:53:20 | 00,153,192 | R--- | M] (Hewlett-Packard Co.)
CmdMapping\\"{724d43aa-0d85-11d4-9908-00400523e39a}" [HKLM] ->  [RoboForm] -> File not found
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL [Research] -> [2009/03/06 04:04:56 | 00,039,464 | ---- | M] (Microsoft Corporation)
CmdMapping\\"{A75C6120-9B36-11d4-A3F0-009027427750}" [HKLM] ->  [Reg Error: Key error.] -> File not found
CmdMapping\\"{d81ca86b-ef63-42af-bee3-4502d9a03c2d}" [HKLM] -> C:\Program Files\MUSICMATCH\MUSICMATCH Media Center\MMRadioHostX.dll [MMRadioHostX Class] -> [2003/07/24 01:08:00 | 00,430,080 | ---- | M] (MUSICMATCH Inc)
CmdMapping\\"{E28AB5C9-B58F-4512-AF80-29001BC5A29D}" [HKLM] -> C:\Program Files\PokerTimeGuestMPP\MPPoker.exe [PokerTime.net Poker] -> [2005/10/07 14:38:16 | 00,049,213 | ---- | M] (Microgaming)
CmdMapping\\"{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}" [HKLM] ->  [Messenger Class] -> File not found
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 14:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5692 domain(s) found. ->
58 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5691 domain(s) found. ->
57 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 66 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5691 domain(s) found. ->
57 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 66 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 30 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 30 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5837 domain(s) found. ->
turbotax.com .[https] -> Trusted sites ->
69 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\] > -> HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-4249377541-764714509-3756006734-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 66 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{01113300-3E00-11D2-8470-0060089874ED} [HKLM] -> http://activation.rr.com/install/download/tgctlcm.cab [Support.com Configuration Class] ->
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} [HKLM] -> http://www.apple.com/qtactivex/qtplugin.cab [QuickTime Object] ->
{1B9935E4-8A50-4DD8-BD09-A7518723BF97} [HKLM] -> https://quicken.ehosts.net/netagent/objects/custappx3.CAB [eAssist NetAgent Customer ActiveX Control version 3] ->
{1F2F4C9E-6F09-47BC-970D-3C54734667FE} [HKLM] -> https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab [LSSupCtl Class] ->
{37A273C2-5129-11D5-BF37-00A0CCE8754B} [HKLM] -> http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab [TTestGenXInstallObject] ->
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} [HKLM] -> http://office.microsoft.com/officeupdate/content/opuc.cab [Office Update Installation Engine] ->
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} [HKLM] -> http://spaces.msn.com//PhotoUpload/MsnPUpld.cab [MSN Photo Upload Tool] ->
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [HKLM] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231725258781 [MUWebControl Class] ->
{88D8E8B7-A33B-4417-A385-8373484D43ED} [HKLM] -> file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll [InstallHelper Class] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab [Java Plug-in 1.6.0_03] ->
{8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} [HKLM] -> file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll [There Voice Trainer] ->
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab [Reg Error: Key error.] ->
{95D88B35-A521-472B-A182-BB1A98356421} [HKLM] -> http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab [Pearson Installation Assistant 2] ->
{99B6E512-3893-4155-9964-8EB8E06099CB} [HKLM] -> http://download.zonelabs.com/bin/promotions/spywaredetector/WebSWK.cab [WebSpyWareKiller Class] ->
{9B03C5F1-F5AB-47EE-937D-A8EDA626F876} [HKLM] -> http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab [Anonymizer Anti-Spyware Scanner] ->
{AAF421E6-7914-430A-9981-72B31AFF3BF4} [HKLM] -> file://c:\Program Files\There\ThereClient\ThereLauncher.dll [There Launcher] ->
{B38870E4-7ECB-40DA-8C6A-595F0A5519FF} [HKLM] -> http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab [MsnMessengerSetupDownloadControl Class] ->
{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab [Java Plug-in 1.4.2] ->
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab [Java Plug-in 1.6.0_03] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab [Java Plug-in 1.6.0_03] ->
{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} [HKLM] -> https://www-secure.symantec.com/techsupp/asa/SymAData.cab [ActiveDataInfo Class] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] ->
{D44C75D8-C827-473E-8F68-A77E42500782} [HKLM] -> http://www.samsphotoclub.com/upload/WebUploadClient.cab [Uploader Class] ->
{EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} [HKLM] -> http://asp.mathxl.com/books/_Players/EconPlayer.cab [Pearson MyEconLab Player Control] ->
{F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} [HKLM] -> http://216.249.24.60/code/iPIX-ImageWell-ipix.cab [iPIX Media Send Class] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 24.25.227.55 209.18.47.61 24.25.227.53 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{1EA86FCF-F590-471F-B18E-5C5E04316610}\\DhcpNameServer -> 68.1.18.237 68.1.18.30 68.10.16.30   (Microsoft(R) Wireless USB 2.0 Adapter MN-710) ->
{224C9E3D-B480-4131-B37B-D04AA84DE8DF}\\DhcpNameServer -> 24.25.227.55 209.18.47.61 24.25.227.53   (Realtek RTL8139/810x Family Fast Ethernet NIC) ->
{C8256A9A-78B4-4C7A-BC9D-4ED2E7C593DB}\\DhcpNameServer -> 68.1.18.237 68.1.18.30 68.10.16.30   (Microsoft(R) Wireless USB 2.0 Adapter MN-710) ->
IE Styles -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ->
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls ->
c:\windows\system32\gisisema.dll -> C:\WINDOWS\System32\gisisema.dll -> File not found
c:\windows\system32\ -> C:\WINDOWS\System32 -> [2009/10/03 10:17:47 | 00,000,000 | ---D | M]
c:\windows\system32\yudegoku.dll -> C:\WINDOWS\System32\yudegoku.dll -> File not found
tehunevo.dll -> C:\WINDOWS\System32\tehunevo.dll -> [2009/07/02 17:22:59 | 00,052,224 | ---- | M] ()
c:\windows\system32\wobihasa.dll -> C:\WINDOWS\System32\wobihasa.dll -> [2009/10/03 05:21:32 | 00,091,136 | ---- | M] ()
*MultiFile Done* -> ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
AtiExtEvent -> C:\WINDOWS\System32\ati2evxx.dll -> [2004/11/03 21:38:16 | 00,090,112 | ---- | M] (ATI Technologies Inc.)
igfxcui -> C:\WINDOWS\System32\igfxsrvc.dll -> [2003/10/02 19:18:52 | 00,319,488 | ---- | M] (Intel Corporation)
NavLogon -> C:\WINDOWS\System32\NavLogon.dll -> [2006/03/17 06:34:36 | 00,043,760 | ---- | M] (Symantec Corporation)
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad ->
"{324fc3bb-4f3e-4c51-84b7-1689cfe42ed0}" [HKLM] -> C:\WINDOWS\System32\yudegoku.dll [ganokiboy] -> File not found
"{de4e9e38-28ca-4548-8ac1-ad002276dd90}" [HKLM] -> C:\WINDOWS\System32\gisisema.dll [kawuhesud] -> File not found
"{d045846b-9cd4-48bf-b327-b0f6757c4d5f}" [HKLM] -> C:\WINDOWS\System32\wobihasa.dll [sebugeban] -> [2009/10/03 05:21:32 | 00,091,136 | ---- | M] ()
< SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler ->
"{324fc3bb-4f3e-4c51-84b7-1689cfe42ed0}" [HKLM] -> C:\WINDOWS\System32\yudegoku.dll [tokatiluy] -> File not found
"{d045846b-9cd4-48bf-b327-b0f6757c4d5f}" [HKLM] -> C:\WINDOWS\System32\wobihasa.dll [mujuzedij] -> [2009/10/03 05:21:32 | 00,091,136 | ---- | M] ()
"{de4e9e38-28ca-4548-8ac1-ad002276dd90}" [HKLM] -> C:\WINDOWS\System32\gisisema.dll [tokatiluy] -> File not found
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
"{56F9679E-7826-4C84-81F3-532071A8BCC5}" [HKLM] -> C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [] -> [2009/05/24 22:41:34 | 00,304,128 | ---- | M] (Microsoft Corporation)
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 08:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 14:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" -> C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger] -> [2005/09/02 21:17:52 | 00,032,768 | ---- | M] (Logitech)
"C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5] -> [2005/09/19 00:02:36 | 07,083,056 | ---- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 08:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 14:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation)
"C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe" -> C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe [C:\Documents and Settings\All Users\Application Data\14267034\14267034.exe:*:Enabled:14267034] -> File not found
"C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe" -> C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe [C:\Documents and Settings\All Users\Application Data\16496404\16496404.exe:*:Enabled:16496404] -> File not found
"C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Civilization4.exe" -> C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Civilization4.exe [C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4 Gold] -> [2007/06/06 19:23:14 | 12,708,560 | ---- | M] (Firaxis Games)
"C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Warlords\Civ4Warlords.exe" -> C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Warlords\Civ4Warlords.exe [C:\Documents and Settings\JD\Application Data\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Warlords\Civ4Warlords.exe:*:Enabled:Sid Meier's Civilization 4: Warlords] -> [2007/06/06 19:22:54 | 12,266,184 | ---- | M] (Firaxis Games)
"C:\Program Files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe" -> C:\Program Files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe [C:\Program Files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe:*:Disabled:Adobe Photoshop Elements Media Server] -> [2008/09/16 12:03:34 | 02,954,592 | ---- | M] (Adobe Systems Incorporated)
"C:\Program Files\BitTorrent\bittorrent.exe" -> C:\Program Files\BitTorrent\bittorrent.exe [C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent] -> [2008/12/16 10:16:10 | 00,637,232 | ---- | M] (BitTorrent, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.)
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" -> C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server] -> [2008/10/10 05:45:26 | 00,013,088 | ---- | M] (Intuit Inc.)
"C:\Program Files\DNA\btdna.exe" -> C:\Program Files\DNA\btdna.exe [C:\Program Files\DNA\btdna.exe:*:Enabled:DNA] -> [2009/01/13 21:10:40 | 00,342,848 | ---- | M] (BitTorrent, Inc.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe [C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe] -> [2007/05/13 23:47:50 | 00,075,352 | ---- | M] (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe [C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe] -> [2007/03/11 21:55:28 | 00,280,152 | ---- | M] (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" -> C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe [C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe] -> [2007/03/11 21:55:28 | 00,053,248 | ---- | M] (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" -> C:\Program Files\HP\Digital Imaging\bin\hposid01.exe [C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe] -> [2007/05/13 23:47:50 | 00,108,120 | ---- | M] (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe [C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe] -> [2007/03/12 03:35:02 | 01,196,032 | ---- | M] (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe [C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe] -> [2007/05/13 23:14:44 | 00,192,512 | ---- | M] (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe [C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe] -> [2007/03/12 03:35:02 | 00,249,856 | ---- | M] ()
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe [C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe] -> [2007/03/11 21:32:42 | 00,151,552 | ---- | M] (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe] -> [2007/03/11 21:26:24 | 00,210,520 | ---- | M] (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" -> C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe [C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe] -> [2007/03/11 21:55:28 | 00,476,760 | ---- | M] (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" -> C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe [C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe] -> [2003/07/02 08:06:42 | 00,364,544 | ---- | M] ()
"C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2009/09/08 21:09:38 | 10,309,408 | ---- | M] (Apple Inc.)
"C:\Program Files\LimeWire\LimeWire.exe" -> C:\Program Files\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire] -> File not found
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" -> C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger] -> [2005/09/02 21:17:52 | 00,032,768 | ---- | M] (Logitech)
"C:\Program Files\Messenger\msmsgs.exe" -> C:\Program Files\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> [2008/04/13 14:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" -> C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook] -> [2009/04/17 03:30:12 | 12,438,896 | ---- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msnmsgr.exe" -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5] -> [2005/09/19 00:02:36 | 07,083,056 | ---- | M] (Microsoft Corporation)
"C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe" -> C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe [C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe:*:Enabled:StartupCopPro] -> [2007/09/26 23:23:28 | 02,211,840 | ---- | M] (Ziff-Davis Media, Inc.)
"C:\Program Files\TurboTax\Premier 2006\32bit\ttax.exe" -> C:\Program Files\TurboTax\Premier 2006\32bit\ttax.exe [C:\Program Files\TurboTax\Premier 2006\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax] -> [2007/03/08 01:25:56 | 09,950,760 | ---- | M] (Intuit, Inc.)
"C:\Program Files\TurboTax\Premier 2006\32bit\updatemgr.exe" -> C:\Program Files\TurboTax\Premier 2006\32bit\updatemgr.exe [C:\Program Files\TurboTax\Premier 2006\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager] -> [2007/02/19 13:06:50 | 03,679,784 | ---- | M] (Intuit, Inc.)
"C:\Program Files\TurboTax\Premier 2007\32bit\ttax.exe" -> C:\Program Files\TurboTax\Premier 2007\32bit\ttax.exe [C:\Program Files\TurboTax\Premier 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax] -> [2008/03/05 23:29:49 | 10,343,712 | ---- | M] (Intuit, Inc.)
"C:\Program Files\TurboTax\Premier 2007\32bit\updatemgr.exe" -> C:\Program Files\TurboTax\Premier 2007\32bit\updatemgr.exe [C:\Program Files\TurboTax\Premier 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager] -> [2007/10/22 18:56:52 | 03,597,600 | ---- | M] (Intuit, Inc.)
"C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" -> C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe:*:Enabled:zlclient] -> [2009/02/16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD)
"C:\WINDOWS\explorer.exe" -> C:\WINDOWS\explorer.exe [C:\WINDOWS\explorer.exe:*:Enabled:Explorer] -> [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
"C:\WINDOWS\pchealth\helpctr\Binaries\helpctr.exe" -> C:\WINDOWS\pchealth\helpctr\Binaries\helpctr.exe [C:\WINDOWS\pchealth\helpctr\Binaries\helpctr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice] -> [2008/04/13 14:12:21 | 00,769,024 | ---- | M] (Microsoft Corporation)
"C:\WINDOWS\system32\hpzipm12.exe" -> C:\WINDOWS\System32\hpzipm12.exe [C:\WINDOWS\system32\hpzipm12.exe:*:Enabled:hpzipm12] -> [2003/05/16 15:54:34 | 00,065,795 | ---- | M] (HP)
"C:\WINDOWS\system32\logonui.exe" -> C:\WINDOWS\System32\logonui.exe [C:\WINDOWS\system32\logonui.exe:*:Enabled:logonui] -> [2008/04/13 14:12:24 | 00,514,560 | ---- | M] (Microsoft Corporation)
"C:\WINDOWS\system32\winlogon.exe" -> C:\WINDOWS\System32\winlogon.exe [C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon] -> [2008/04/13 14:12:39 | 00,507,904 | ---- | M] (Microsoft Corporation)
"C:\WINDOWS\system32\wscntfy.exe" -> C:\WINDOWS\System32\wscntfy.exe [C:\WINDOWS\system32\wscntfy.exe:*:Enabled:wscntfy] -> [2008/04/13 14:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation)
"E:\setup\HPZNUI01.EXE" -> E:\setup\HPZNUI01.EXE [E:\setup\HPZNUI01.EXE:*:Enabled:hpznui01.exe] -> File not found
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" ->  [System32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > ->  ->
C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2003/12/16 19:45:52 | 00,000,000 | ---- | M] ()
D:\AUTOEXEC.BAT [] -> D:\AUTOEXEC.BAT [ FAT32 ] -> [2001/07/28 06:07:38 | 00,000,000 | -HS- | M] ()
D:\Autorun.inf [[AUTORUN] | OPEN=Info.exe folder.htt 480 480 | ] -> D:\Autorun.inf [ FAT32 ] -> [2002/09/11 03:02:32 | 00,000,045 | -HS- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
\{391dd251-46bc-11dd-b7f4-000ea6c3bfc8}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{391dd251-46bc-11dd-b7f4-000ea6c3bfc8}\Shell\AutoRun\command
\{391dd251-46bc-11dd-b7f4-000ea6c3bfc8}\Shell\AutoRun\command\\"" ->  [.\Encryption Tool\MaxtorEncryption.exe] -> File not found
\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\AutoRun\command
\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\AutoRun\command\\"" -> F:\PortableRoboForm.exe [F:\PortableRoboForm.exe] -> File not found
\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\RoboForm2Go\command
\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\RoboForm2Go\command\\"" -> F:\PortableRoboForm.exe [F:\PortableRoboForm.exe] -> File not found
\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\AutoRun\command
\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\AutoRun\command\\"" -> J:\Autorun.exe [J:\Autorun.exe /run] -> File not found
\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell00\Command
\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell00\Command\\"" -> J:\Autorun.exe [J:\Autorun.exe /run] -> File not found
\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell01\Command
\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell01\Command\\"" -> J:\Autorun.exe [J:\Autorun.exe /action] -> File not found
\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell02\Command
\{c5635f3c-be86-11dd-ab7d-000ea6c3bfc8}\Shell\Shell02\Command\\"" -> J:\Autorun.exe [J:\Autorun.exe /uninstall] -> File not found
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
comfile [open] -> "%1" %* -> File not found
exefile [open] -> "%1" %* -> File not found

[Registry - Additional Scans - Safe List]
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
batfile [open] -> "%1" %* -> File not found
chm.file [open] -> "C:\WINDOWS\hh.exe" %1 -> [2008/04/13 14:12:21 | 00,010,752 | ---- | M] (Microsoft Corporation)
cmdfile [open] -> "%1" %* -> File not found
comfile [open] -> "%1" %* -> File not found
exefile [open] -> "%1" %* -> File not found
htmlfile [edit] -> "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" /n /dde -> File not found
htmlfile [open] -> "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome -> [2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation)
htmlfile [opennew] -> "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 -> [2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation)
htmlfile [print] -> Reg Error: Key error.
http [open] -> "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" -> [2009/09/09 19:15:54 | 00,908,280 | ---- | M] (Mozilla Corporation)
https [open] -> "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" -> [2009/09/09 19:15:54 | 00,908,280 | ---- | M] (Mozilla Corporation)
piffile [open] -> "%1" %* -> File not found
regfile [merge] -> Reg Error: Key error.
scrfile [config] -> "%1" -> File not found
scrfile [install] -> rundll32.exe desk.cpl,InstallScreenSaver %l -> [2008/04/13 14:12:41 | 00,135,168 | ---- | M] (Microsoft Corporation)
scrfile [open] -> "%1" %* -> File not found
txtfile [edit] -> Reg Error: Key error.
Directory [AddToPlaylistVLC] -> C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" -> [2008/12/06 04:57:20 | 00,114,840 | ---- | M] ()
Directory [find] -> %SystemRoot%\Explorer.exe -> [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
Directory [PlayWithVLC] -> C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" -> [2008/12/06 04:57:20 | 00,114,840 | ---- | M] ()
Folder [open] -> %SystemRoot%\Explorer.exe /idlist,%I,%L -> [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
Folder [explore] -> %SystemRoot%\Explorer.exe /e,/idlist,%I,%L -> [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
Drive [find] -> %SystemRoot%\Explorer.exe -> [2008/04/13 14:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
Applications\iexplore.exe [open] -> "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 -> [2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -> "C:\Program Files\Internet Explorer\iexplore.exe" -> [2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation)
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 10/3/2009 8:31:05 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685 -> Description =       Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan.  Action: Clean failed : Quarantine failed : Access denied.  Action Description: The file was left unchanged.    
Application [ Error ] 10/3/2009 10:01:18 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726 -> Description =       Security Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan.  Action: Clean failed : Quarantine failed.  Action Description: The file was left unchanged.    
Application [ Error ] 10/3/2009 10:01:18 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685 -> Description =       Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan.  Action: Clean failed : Quarantine failed : Access denied.  Action Description: The file was left unchanged.    
Application [ Error ] 10/3/2009 10:01:19 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685 -> Description =       Risk Found!Risk: Trojan.Vundo in File: c:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan.  Action: Cleaned by Deletion.  Action Description:      
Application [ Error ] 10/3/2009 10:01:26 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711731 -> Description =       Security Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan.  Action: Cleaned by Deletion.  Action Description:      
Application [ Error ] 10/3/2009 10:01:57 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726 -> Description =       Security Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan.  Action: Clean failed : Quarantine failed.  Action Description: The file was left unchanged.    
Application [ Error ] 10/3/2009 10:02:38 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685 -> Description =       Risk Found!Risk: Trojan.Vundo in File: c:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan.  Action: Cleaned by Deletion.  Action Description:      
Application [ Error ] 10/3/2009 10:37:14 AM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726 -> Description =       Security Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\sovaroda.dll by: Auto-Protect scan.  Action: Clean failed : Quarantine failed.  Action Description: The file was left unchanged.    
Application [ Error ] 10/3/2009 3:39:53 PM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711726 -> Description =       Security Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\gatotafi.dll.tmp by: Auto-Protect scan.  Action: Cleaned by Deletion.  Action Description:      
Application [ Error ] 10/3/2009 3:39:53 PM Computer Name = DESKTOP | Source = Symantec AntiVirus | ID = 16711685 -> Description =       Risk Found!Risk: Trojan.Vundo in File: C:\WINDOWS\system32\gatotafi.dll.tmp by: Auto-Protect scan.  Action: Cleaned by Deletion.  Action Description:      
System [ Error ] 8/27/2009 1:27:18 AM Computer Name = DESKTOP | Source = Service Control Manager | ID = 7009 -> Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor service to connect.
System [ Error ] 8/27/2009 1:27:18 AM Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000 -> Description = The TrueVector Internet Monitor service failed to start due to the following error:   %%1053
System [ Error ] 8/30/2009 12:43:18 AM Computer Name = DESKTOP | Source = LDMS | ID = 16780230 -> Description = Unhandled exception, exception code=6B
System [ Error ] 8/30/2009 1:19:10 AM Computer Name = DESKTOP | Source = Service Control Manager | ID = 7009 -> Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor service to connect.
System [ Error ] 8/30/2009 1:19:10 AM Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000 -> Description = The TrueVector Internet Monitor service failed to start due to the following error:   %%1053
System [ Error ] 8/30/2009 1:42:42 AM Computer Name = DESKTOP | Source = Service Control Manager | ID = 7009 -> Description = Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor service to connect.
System [ Error ] 8/30/2009 1:42:43 AM Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000 -> Description = The TrueVector Internet Monitor service failed to start due to the following error:   %%1053

[Files/Folders - Created Within 30 Days]
Application Data -> C:\Documents and Settings\All Users\Application Data -> [2009/10/03 10:17:48 | 00,000,000 | RH-D | M]
{755AC846-7372-4AC8-8550-C52491DAA8BD} -> C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} -> [2009/09/09 19:25:47 | 00,000,000 | ---D | M]
Microsoft Help -> C:\Documents and Settings\All Users\Application Data\Microsoft Help -> [2009/09/09 03:03:23 | 00,000,000 | ---D | M]
Application Data -> C:\Documents and Settings\JD\Application Data -> [2009/10/03 10:17:48 | 00,000,000 | -H-D | M]
Apple Computer -> C:\Documents and Settings\JD\Application Data\Apple Computer -> [2009/09/09 19:29:33 | 00,000,000 | ---D | M]
DNA -> C:\Documents and Settings\JD\Application Data\DNA -> [2009/10/03 10:34:32 | 00,000,000 | ---D | M]
U3 -> C:\Documents and Settings\JD\Application Data\U3 -> [2009/09/21 21:20:18 | 00,000,000 | ---D | M]
Apple Computer -> C:\Documents and Settings\JD\Local Settings\Application Data\Apple Computer -> [2009/10/02 18:10:00 | 00,000,000 | ---D | M]
ApplicationHistory -> C:\Documents and Settings\JD\Local Settings\Application Data\ApplicationHistory -> [2009/09/06 11:24:16 | 00,000,000 | ---D | M]
Microsoft -> C:\Documents and Settings\JD\Local Settings\Application Data\Microsoft -> [2009/09/27 15:47:32 | 00,000,000 | ---D | M]
Temp -> C:\Documents and Settings\JD\Local Settings\Application Data\Temp -> [2009/10/01 20:30:40 | 00,000,000 | ---D | M]
Apple -> C:\Program Files\Common Files\Apple -> [2009/09/09 19:24:33 | 00,000,000 | ---D | M]
Program Files -> C:\Program Files -> [2009/09/27 15:47:27 | 00,000,000 | ---D | M]
CCleaner -> C:\Program Files\CCleaner -> [2009/09/27 13:02:28 | 00,000,000 | ---D | M]
DNA -> C:\Program Files\DNA -> [2009/10/03 10:24:29 | 00,000,000 | ---D | M]
ERUNT -> C:\Program Files\ERUNT -> [2009/09/27 14:19:37 | 00,000,000 | ---D | M]
Google -> C:\Program Files\Google -> [2009/09/08 10:18:39 | 00,000,000 | ---D | M]
iPhone Configuration Utility -> C:\Program Files\iPhone Configuration Utility -> [2009/09/10 18:05:18 | 00,000,000 | ---D | M]
iPod -> C:\Program Files\iPod -> [2009/09/09 19:24:36 | 00,000,000 | ---D | M]
iTunes -> C:\Program Files\iTunes -> [2009/09/09 19:25:47 | 00,000,000 | ---D | M]
Malwarebytes' Anti-Malware -> C:\Program Files\Malwarebytes' Anti-Malware -> [2009/09/18 18:37:54 | 00,000,000 | ---D | M]
Microsoft Silverlight -> C:\Program Files\Microsoft Silverlight -> [2009/09/27 15:47:27 | 00,000,000 | ---D | M]
Mozilla Firefox -> C:\Program Files\Mozilla Firefox -> [2009/10/03 10:29:08 | 00,000,000 | ---D | M]
QuickTime -> C:\Program Files\QuickTime -> [2009/09/09 19:02:21 | 00,000,000 | ---D | M]
Spybot - Search & Destroy -> C:\Program Files\Spybot - Search & Destroy -> [2009/09/19 14:33:40 | 00,000,000 | ---D | M]
Symantec AntiVirus -> C:\Program Files\Symantec AntiVirus -> [2009/10/03 10:26:07 | 00,000,000 | ---D | M]
OTS.exe -> C:\Documents and Settings\JD\Desktop\OTS.exe -> [2009/10/03 10:30:52 | 00,519,680 | ---- | C] (OldTimer Tools)
ERDNT -> C:\WINDOWS\ERDNT -> [2009/09/27 14:20:19 | 00,000,000 | ---D | C]
VundoFix Backups -> C:\VundoFix Backups -> [2009/09/27 13:10:24 | 00,000,000 | ---D | C]
iexplore.exe -> C:\Documents and Settings\JD\Desktop\iexplore.exe -> [2009/09/27 11:24:43 | 03,550,592 | ---- | C] (Sysinternals - www.sysinternals.com)
triedit.dll -> C:\WINDOWS\System32\dllcache\triedit.dll -> [2009/09/08 17:39:37 | 00,153,088 | ---- | C] (Microsoft Corporation)
ATIDEMGR.dll -> C:\WINDOWS\System32\ATIDEMGR.dll -> [2006/02/21 19:21:36 | 00,192,512 | ---- | C] ( )

[Files/Folders - Modified Within 30 Days]
6 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp ->
mehudebe -> C:\WINDOWS\System32\mehudebe -> [2009/10/03 10:42:56 | 00,011,168 | -H-- | M] ()
OTS.exe -> C:\Documents and Settings\JD\Desktop\OTS.exe -> [2009/10/03 10:31:02 | 00,519,680 | ---- | M] (OldTimer Tools)
GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006UA.job -> C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006UA.job -> [2009/10/03 10:30:05 | 00,000,966 | ---- | M] ()
vsconfig.xml -> C:\WINDOWS\System32\vsconfig.xml -> [2009/10/03 10:28:19 | 00,350,197 | -H-- | M] ()
wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2009/10/03 10:25:21 | 00,001,158 | ---- | M] ()
GoogleUpdateTaskMachineCore.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job -> [2009/10/03 10:22:16 | 00,000,882 | ---- | M] ()
SA.DAT -> C:\WINDOWS\tasks\SA.DAT -> [2009/10/03 10:22:13 | 00,000,006 | -H-- | M] ()
bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2009/10/03 10:21:47 | 00,002,048 | --S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2009/10/03 10:21:41 | 16,099,45088 | -HS- | M] ()
ntuser.dat -> C:\Documents and Settings\JD\ntuser.dat -> [2009/10/03 10:20:18 | 12,582,912 | ---- | M] ()
ntuser.ini -> C:\Documents and Settings\JD\ntuser.ini -> [2009/10/03 10:20:13 | 00,000,278 | -HS- | M] ()
IconCache.db -> C:\Documents and Settings\JD\Local Settings\Application Data\IconCache.db -> [2009/10/03 10:19:42 | 09,206,992 | -H-- | M] ()
GoogleUpdateTaskMachineUA.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job -> [2009/10/03 10:17:00 | 00,000,886 | ---- | M] ()
GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006Core.job -> C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006Core.job -> [2009/10/03 09:30:01 | 00,000,914 | ---- | M] ()
wobihasa.dll -> C:\WINDOWS\System32\wobihasa.dll -> [2009/10/03 05:21:32 | 00,091,136 | ---- | M] ()
Incremental Backup.job -> C:\WINDOWS\tasks\Incremental Backup.job -> [2009/10/03 04:00:16 | 00,000,804 | ---- | M] ()
iTunes.lnk -> C:\Documents and Settings\All Users\Desktop\iTunes.lnk -> [2009/10/02 18:00:55 | 00,002,137 | ---- | M] ()
vokafifu.dll -> C:\WINDOWS\System32\vokafifu.dll -> [2009/10/02 17:22:21 | 00,037,888 | -HS- | M] ()
famatoge.dll -> C:\WINDOWS\System32\famatoge.dll -> [2009/10/02 17:22:20 | 00,027,136 | -HS- | M] ()
Google Chrome.lnk -> C:\Documents and Settings\JD\Desktop\Google Chrome.lnk -> [2009/10/01 20:30:52 | 00,002,272 | ---- | M] ()
wayolelu.dll -> C:\WINDOWS\System32\wayolelu.dll -> [2009/10/01 04:27:44 | 00,026,624 | -HS- | M] ()
QUICKEN.INI -> C:\WINDOWS\QUICKEN.INI -> [2009/09/28 19:27:22 | 00,000,221 | ---- | M] ()
Ad-Aware Update (Weekly).job -> C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job -> [2009/09/28 10:42:33 | 00,000,472 | ---- | M] ()
Full Backups.job -> C:\WINDOWS\tasks\Full Backups.job -> [2009/09/28 08:00:11 | 00,000,832 | ---- | M] ()
NTREGOPT.lnk -> C:\Documents and Settings\JD\Desktop\NTREGOPT.lnk -> [2009/09/27 14:19:31 | 00,000,622 | ---- | M] ()
ERUNT.lnk -> C:\Documents and Settings\JD\Desktop\ERUNT.lnk -> [2009/09/27 14:19:31 | 00,000,603 | ---- | M] ()
CCleaner.lnk -> C:\Documents and Settings\JD\Desktop\CCleaner.lnk -> [2009/09/27 13:02:28 | 00,001,559 | ---- | M] ()
iexplore.exe -> C:\Documents and Settings\JD\Desktop\iexplore.exe -> [2009/09/27 11:24:48 | 03,550,592 | ---- | M] (Sysinternals - www.sysinternals.com)
wininit.ini -> C:\WINDOWS\wininit.ini -> [2009/09/25 05:56:21 | 00,000,095 | ---- | M] ()
Media Backup Schedule.job -> C:\WINDOWS\tasks\Media Backup Schedule.job -> [2009/09/22 09:15:28 | 00,000,768 | ---- | M] ()
AppleSoftwareUpdate.job -> C:\WINDOWS\tasks\AppleSoftwareUpdate.job -> [2009/09/10 18:03:04 | 00,000,284 | ---- | M] ()
mbamswissarmy.sys -> C:\WINDOWS\System32\drivers\mbamswissarmy.sys -> [2009/09/10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation)
mbam.sys -> C:\WINDOWS\System32\drivers\mbam.sys -> [2009/09/10 14:53:50 | 00,019,160 | ---- | M] (Malwarebytes Corporation)
imsins.BAK -> C:\WINDOWS\imsins.BAK -> [2009/09/09 03:03:40 | 00,001,355 | ---- | M] ()

[Files - No Company Name]
hiberfil.sys -> C:\hiberfil.sys -> [2009/09/27 17:57:55 | 16,099,45088 | -HS- | C] ()
NTREGOPT.lnk -> C:\Documents and Settings\JD\Desktop\NTREGOPT.lnk -> [2009/09/27 14:19:31 | 00,000,622 | ---- | C] ()
ERUNT.lnk -> C:\Documents and Settings\JD\Desktop\ERUNT.lnk -> [2009/09/27 14:19:31 | 00,000,603 | ---- | C] ()
CCleaner.lnk -> C:\Documents and Settings\JD\Desktop\CCleaner.lnk -> [2009/09/27 13:02:28 | 00,001,559 | ---- | C] ()
wininit.ini -> C:\WINDOWS\wininit.ini -> [2009/09/25 05:56:21 | 00,000,095 | ---- | C] ()
iTunes.lnk -> C:\Documents and Settings\All Users\Desktop\iTunes.lnk -> [2009/09/09 19:26:13 | 00,002,137 | ---- | C] ()
Media Backup Schedule.job -> C:\WINDOWS\tasks\Media Backup Schedule.job -> [2009/09/06 11:18:13 | 00,000,768 | ---- | C] ()
wobihasa.dll -> C:\WINDOWS\System32\wobihasa.dll -> [2009/07/03 05:21:30 | 00,091,136 | ---- | C] ()
tehunevo.dll -> C:\WINDOWS\System32\tehunevo.dll -> [2009/07/02 17:22:59 | 00,052,224 | ---- | C] ()
fedoniko.dll -> C:\WINDOWS\System32\fedoniko.dll -> [2009/07/02 17:22:59 | 00,052,224 | ---- | C] ()
vokafifu.dll -> C:\WINDOWS\System32\vokafifu.dll -> [2009/07/02 17:22:20 | 00,037,888 | -HS- | C] ()
famatoge.dll -> C:\WINDOWS\System32\famatoge.dll -> [2009/07/02 17:22:19 | 00,027,136 | -HS- | C] ()
wayolelu.dll -> C:\WINDOWS\System32\wayolelu.dll -> [2009/07/01 04:27:43 | 00,026,624 | -HS- | C] ()
AviSplitter.INI -> C:\WINDOWS\AviSplitter.INI -> [2009/02/15 20:03:04 | 00,000,038 | ---- | C] ()
prgiso.dll -> C:\WINDOWS\System32\prgiso.dll -> [2008/07/02 02:43:02 | 00,247,560 | ---- | C] ()
lgfwup.ini -> C:\WINDOWS\lgfwup.ini -> [2008/04/20 14:10:51 | 00,000,359 | ---- | C] ()
ppsio2.sys -> C:\WINDOWS\System32\drivers\ppsio2.sys -> [2008/04/17 20:22:20 | 00,022,272 | ---- | C] ()
xfcodec.dll -> C:\WINDOWS\System32\xfcodec.dll -> [2008/01/30 16:03:26 | 00,054,608 | ---- | C] ()
hpqEmlSz.INI -> C:\WINDOWS\hpqEmlSz.INI -> [2007/12/01 16:12:22 | 00,000,000 | ---- | C] ()
idxcntrs.ini -> C:\WINDOWS\System32\idxcntrs.ini -> [2007/09/27 10:51:02 | 00,020,698 | ---- | C] ()
gsrvctr.ini -> C:\WINDOWS\System32\gsrvctr.ini -> [2007/09/27 10:48:48 | 00,030,628 | ---- | C] ()
gthrctr.ini -> C:\WINDOWS\System32\gthrctr.ini -> [2007/09/27 10:48:28 | 00,031,698 | ---- | C] ()
HP_48BitScanUpdatePatch.ini -> C:\WINDOWS\HP_48BitScanUpdatePatch.ini -> [2007/06/12 18:01:48 | 00,000,214 | ---- | C] ()
DragToDiscUserNameE.txt -> C:\Documents and Settings\All Users\Application Data\DragToDiscUserNameE.txt -> [2006/11/12 15:58:20 | 00,000,002 | ---- | C] ()
patchw32.dll -> C:\WINDOWS\patchw32.dll -> [2006/10/30 20:41:08 | 00,205,312 | R--- | C] ()
pw32a.dll -> C:\WINDOWS\pw32a.dll -> [2006/10/30 20:39:51 | 00,205,312 | R--- | C] ()
libeay32.dll -> C:\WINDOWS\System32\libeay32.dll -> [2006/10/30 06:48:44 | 00,684,032 | ---- | C] ()
libeay32_0.9.6l.dll -> C:\WINDOWS\System32\libeay32_0.9.6l.dll -> [2006/07/15 09:18:29 | 00,796,584 | ---- | C] ()
vpc32.INI -> C:\WINDOWS\vpc32.INI -> [2006/04/04 21:27:39 | 00,000,000 | ---- | C] ()
PureEdgeAPI.ini -> C:\WINDOWS\PureEdgeAPI.ini -> [2006/01/05 10:18:52 | 00,000,061 | ---- | C] ()
MSQOLE.DLL -> C:\WINDOWS\System32\MSQOLE.DLL -> [2006/01/05 10:18:48 | 00,167,936 | ---- | C] ()
QTSBandwidthCache -> C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache -> [2005/12/25 13:25:16 | 00,001,778 | ---- | C] ()
maxlink.ini -> C:\WINDOWS\maxlink.ini -> [2005/12/18 15:51:14 | 00,001,018 | ---- | C] ()
calera.ini -> C:\WINDOWS\calera.ini -> [2005/12/18 15:51:14 | 00,000,091 | ---- | C] ()
FPXIG.DLL -> C:\WINDOWS\System32\FPXIG.DLL -> [2005/12/18 15:51:08 | 00,269,312 | ---- | C] ()
IGFPX32P.DLL -> C:\WINDOWS\System32\IGFPX32P.DLL -> [2005/12/18 15:51:08 | 00,068,096 | ---- | C] ()
JPEGACC.DLL -> C:\WINDOWS\System32\JPEGACC.DLL -> [2005/12/18 15:51:08 | 00,065,024 | ---- | C] ()
WELSOF32.DLL -> C:\WINDOWS\System32\WELSOF32.DLL -> [2005/12/18 15:51:00 | 00,101,376 | ---- | C] ()
TTSServer.dll -> C:\WINDOWS\System32\TTSServer.dll -> [2005/11/28 21:11:16 | 00,172,032 | ---- | C] ()
Setup32.INI -> C:\WINDOWS\Setup32.INI -> [2005/11/28 21:10:17 | 00,000,000 | ---- | C] ()
libeay32.dll -> C:\WINDOWS\libeay32.dll -> [2005/11/25 11:37:36 | 00,684,032 | ---- | C] ()
ssleay32.dll -> C:\WINDOWS\ssleay32.dll -> [2005/11/25 11:37:36 | 00,155,648 | ---- | C] ()
iPlayer.INI -> C:\WINDOWS\iPlayer.INI -> [2005/09/24 09:31:20 | 00,000,000 | ---- | C] ()
lvcoinst.ini -> C:\WINDOWS\System32\lvcoinst.ini -> [2005/08/21 11:52:08 | 00,009,255 | R--- | C] ()
IVIresizeW7.dll -> C:\WINDOWS\System32\IVIresizeW7.dll -> [2005/04/01 14:23:31 | 00,204,800 | ---- | C] ()
IVIresizePX.dll -> C:\WINDOWS\System32\IVIresizePX.dll -> [2005/04/01 14:23:31 | 00,188,416 | ---- | C] ()
IVIresizeA6.dll -> C:\WINDOWS\System32\IVIresizeA6.dll -> [2005/04/01 14:23:30 | 00,200,704 | ---- | C] ()
IVIresizeP6.dll -> C:\WINDOWS\System32\IVIresizeP6.dll -> [2005/04/01 14:23:30 | 00,192,512 | ---- | C] ()
IVIresizeM6.dll -> C:\WINDOWS\System32\IVIresizeM6.dll -> [2005/04/01 14:23:30 | 00,192,512 | ---- | C] ()
IVIresize.dll -> C:\WINDOWS\System32\IVIresize.dll -> [2005/04/01 14:23:30 | 00,020,480 | ---- | C] ()
PhotoSnapViewer.INI -> C:\WINDOWS\PhotoSnapViewer.INI -> [2005/03/10 17:05:17 | 00,000,151 | ---- | C] ()
PerWin.ini -> C:\WINDOWS\PerWin.ini -> [2005/01/15 08:19:22 | 00,000,048 | ---- | C] ()
NeroDigital.ini -> C:\WINDOWS\NeroDigital.ini -> [2004/12/30 12:32:25 | 00,000,116 | ---- | C] ()
WNASPI32.DLL -> C:\WINDOWS\System32\WNASPI32.DLL -> [2004/12/26 12:32:37 | 00,030,208 | ---- | C] ()
msfsetup.ini -> C:\WINDOWS\msfsetup.ini -> [2004/12/26 12:32:37 | 00,000,291 | ---- | C] ()
GDIPFONTCACHEV1.DAT -> C:\Documents and Settings\JD\Application Data\GDIPFONTCACHEV1.DAT -> [2004/12/05 17:02:20 | 00,087,720 | ---- | C] ()
cdPlayer.ini -> C:\WINDOWS\cdPlayer.ini -> [2004/10/02 03:10:23 | 00,001,844 | ---- | C] ()
tx11.dll -> C:\WINDOWS\System32\tx11.dll -> [2004/09/29 11:02:00 | 00,569,344 | ---- | C] ()
G-Force Prefs (WindowsMediaPlayer).txt -> C:\Documents and Settings\JD\Application Data\G-Force Prefs (WindowsMediaPlayer).txt -> [2004/09/05 02:24:00 | 00,000,187 | ---- | C] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Documents and Settings\JD\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2004/09/04 14:13:24 | 00,053,248 | ---- | C] ()
encore_launcher.ini -> C:\WINDOWS\encore_launcher.ini -> [2004/09/04 10:34:39 | 00,000,080 | ---- | C] ()
Wh2Robo.dll -> C:\WINDOWS\System32\Wh2Robo.dll -> [2004/09/03 05:34:28 | 00,047,104 | ---- | C] ()
IMPLODE.DLL -> C:\WINDOWS\System32\IMPLODE.DLL -> [2004/08/31 12:40:46 | 00,017,920 | ---- | C] ()
GDIPFONTCACHEV1.DAT -> C:\Documents and Settings\JD\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [2004/08/26 13:09:28 | 00,127,096 | ---- | C] ()
desktop.ini -> C:\Documents and Settings\JD\Application Data\desktop.ini -> [2004/08/23 17:35:17 | 00,000,062 | -HS- | C] ()
IconCache.db -> C:\Documents and Settings\JD\Local Settings\Application Data\IconCache.db -> [2004/08/23 17:35:13 | 09,206,992 | -H-- | C] ()
fusioncache.dat -> C:\Documents and Settings\JD\Local Settings\Application Data\fusioncache.dat -> [2004/08/23 17:35:13 | 00,000,125 | ---- | C] ()
imbrmute.ini -> C:\WINDOWS\System32\imbrmute.ini -> [2004/07/11 12:46:42 | 00,001,193 | ---- | C] ()
QHI.INI -> C:\WINDOWS\QHI.INI -> [2004/06/30 16:17:51 | 00,000,086 | ---- | C] ()
intuprof.ini -> C:\WINDOWS\intuprof.ini -> [2004/06/30 16:06:13 | 00,001,280 | ---- | C] ()
qwimp.ini -> C:\WINDOWS\qwimp.ini -> [2004/06/30 16:06:11 | 00,000,078 | ---- | C] ()
Acroread.ini -> C:\WINDOWS\Acroread.ini -> [2004/06/28 18:46:13 | 00,000,037 | ---- | C] ()
smscfg.ini -> C:\WINDOWS\smscfg.ini -> [2003/12/17 04:08:40 | 00,000,061 | ---- | C] ()
mshrml.ini -> C:\WINDOWS\System32\mshrml.ini -> [2003/12/17 03:29:26 | 00,000,051 | ---- | C] ()
JAWTAccessBridge.dll -> C:\WINDOWS\System32\JAWTAccessBridge.dll -> [2003/12/16 23:09:37 | 00,028,672 | ---- | C] ()
PcdrKernelModeServices.dll -> C:\WINDOWS\System32\PcdrKernelModeServices.dll -> [2003/12/16 23:09:02 | 00,094,208 | ---- | C] ()
ProgressTrace.dll -> C:\WINDOWS\System32\ProgressTrace.dll -> [2003/12/16 23:09:02 | 00,077,824 | ---- | C] ()
PCDrJNI_1_1.dll -> C:\WINDOWS\System32\PCDrJNI_1_1.dll -> [2003/12/16 23:04:11 | 00,167,936 | ---- | C] ()
CHODDI.SYS -> C:\WINDOWS\System32\CHODDI.SYS -> [2003/12/16 22:45:51 | 00,029,259 | ---- | C] ()
syscontr.dll -> C:\WINDOWS\System32\syscontr.dll -> [2003/12/16 22:45:28 | 00,024,576 | ---- | C] ()
hpreg.dll -> C:\WINDOWS\System32\hpreg.dll -> [2003/12/16 22:44:51 | 00,045,056 | ---- | C] ()
ODBC.INI -> C:\WINDOWS\ODBC.INI -> [2003/12/16 22:39:03 | 00,000,376 | ---- | C] ()
QUICKEN.INI -> C:\WINDOWS\QUICKEN.INI -> [2003/12/16 22:24:09 | 00,000,221 | ---- | C] ()
hpzinstall.log -> C:\Documents and Settings\All Users\Application Data\hpzinstall.log -> [2003/12/16 21:10:11 | 00,012,254 | ---- | C] ()
fxsperf.ini -> C:\WINDOWS\System32\fxsperf.ini -> [2003/12/16 20:59:03 | 00,001,793 | ---- | C] ()
PythonCOM22.dll -> C:\WINDOWS\System32\PythonCOM22.dll -> [2003/12/16 20:09:08 | 00,299,073 | ---- | C] ()
PyWinTypes22.dll -> C:\WINDOWS\System32\PyWinTypes22.dll -> [2003/12/16 20:09:08 | 00,065,536 | ---- | C] ()
bcbmm.dll -> C:\WINDOWS\System32\bcbmm.dll -> [2003/12/16 20:08:44 | 00,016,896 | ---- | C] ()
orun32.ini -> C:\WINDOWS\orun32.ini -> [2003/12/16 19:50:41 | 00,000,813 | ---- | C] ()
oeminfo.ini -> C:\WINDOWS\System32\oeminfo.ini -> [2003/12/16 18:30:15 | 00,000,667 | ---- | C] ()
win.ini -> C:\WINDOWS\win.ini -> [2003/12/16 18:29:27 | 00,000,930 | ---- | C] ()
System.ini -> C:\WINDOWS\System.ini -> [2003/12/16 18:29:22 | 00,000,264 | ---- | C] ()
desktop.ini -> C:\Documents and Settings\All Users\Application Data\desktop.ini -> [2003/12/16 11:34:43 | 00,000,062 | -HS- | C] ()
ati2evxx(2).dll -> C:\WINDOWS\System32\ati2evxx(2).dll -> [2003/12/12 03:42:14 | 00,086,016 | ---- | C] ()
psisdecd.dll -> C:\WINDOWS\System32\psisdecd.dll -> [2003/11/12 08:54:00 | 00,363,520 | ---- | C] ()
px.ini -> C:\WINDOWS\System32\px.ini -> [2003/09/22 22:19:42 | 00,000,000 | ---- | C] ()
indounin.dll -> C:\WINDOWS\System32\indounin.dll -> [1999/01/27 13:39:06 | 00,065,024 | ---- | C] ()
Iyvu9_32.dll -> C:\WINDOWS\System32\Iyvu9_32.dll -> [1997/06/13 15:56:08 | 00,056,832 | ---- | C] ()

[File - Lop Check]

[File - Purity Scan]


[Alternate Data Streams]
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:825D5945
< End of report >

---------------------------------------------------------------------------------

Malwarebytes' Anti-Malware 1.41
Database version: 2902
Windows 5.1.2600 Service Pack 3

10/3/2009 9:33:18 PM
mbam-log-2009-10-03 (21-33-18).txt

Scan type: Full Scan (C:\|)
Objects scanned: 404512
Time elapsed: 2 hour(s), 37 minute(s), 15 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 1
Registry Values Infected: 5
Registry Data Items Infected: 3
Folders Infected: 2
Files Infected: 58

Memory Processes Infected:
C:\Documents and Settings\JD\Application Data\5811403403\5811403403.exe (Rogue.SecurityTool) -> Unloaded process successfully.

Memory Modules Infected:
c:\WINDOWS\system32\yirumuno.dll (Trojan.Vundo.H) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{e2d0c46a-a1fb-4932-9e54-26d606df3b4d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wefowuwus (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{e2d0c46a-a1fb-4932-9e54-26d606df3b4d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\kuninoref (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\5811403403 (Rogue.SecurityTool) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\8899869141 (Rogue.SecurityTool) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\yirumuno.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\yirumuno.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Documents and Settings\JD\Application Data\5811403403 (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\Documents and Settings\JD\Application Data\8899869141 (Rogue.SecurityTool) -> Quarantined and deleted successfully.

Files Infected:
c:\WINDOWS\system32\yirumuno.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Documents and Settings\JD\Application Data\5811403403\5811403403.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\Documents and Settings\JD\Application Data\8899869141\8899869141.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP696\A0353559.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP696\A0353593.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP696\A0353594.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP696\A0353595.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP697\A0353658.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP697\A0353664.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP697\A0353706.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP697\A0355712.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP697\A0355713.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP697\A0355715.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP699\A0358807.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359804.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359805.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359806.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359807.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359808.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359813.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359814.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359815.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0359816.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0360870.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0361966.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0361967.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0362003.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP701\A0362004.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP702\A0362050.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP702\A0362051.exe (Rogue.SystemSecurity) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP703\A0362178.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP703\A0362179.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP703\A0362180.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP703\A0362208.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362329.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362330.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362331.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362332.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362333.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362334.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362335.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362336.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362337.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362338.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362339.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362340.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{38619354-A30C-4AA1-999E-C6E4474B633E}\RP704\A0362343.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nunoloje.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\zibuyiri.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\_OTS\MovedFiles\10032009_172248\C_WINDOWS\System32\fedoniko.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\_OTS\MovedFiles\10032009_172248\C_WINDOWS\System32\tehunevo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\_OTS\MovedFiles\10032009_172248\C_WINDOWS\System32\wobihasa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\JD\Application Data\5811403403\5811403403.bat (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\Documents and Settings\JD\Application Data\5811403403\5811403403.cfg (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\Documents and Settings\JD\Application Data\8899869141\8899869141.bat (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\Documents and Settings\JD\Application Data\8899869141\8899869141.cfg (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\biwifasi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gamuduhe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
------------------------------------------------------------------------------------

OTL logfile created on: 10/3/2009 9:51:04 PM - Run 2
OTL by OldTimer - Version 3.0.16.0 Folder = C:\Documents and Settings\JD\My Documents\JD's Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.67 Gb Available Physical Memory | 44.39% Memory free
2.11 Gb Paging File | 1.47 Gb Available in Paging File | 69.87% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 180.00 Gb Total Space | 33.48 Gb Free Space | 18.60% Space Free | Partition Type: NTFS
Drive D: | 6.29 Gb Total Space | 1.12 Gb Free Space | 17.85% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DESKTOP
Current User Name: JD
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Ahead\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\WINDOWS\ehome\ehSched.exe (Microsoft Corporation)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\WINDOWS\System32\GEARSec.exe (GEAR Software)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe (Symantec Corporation)
PRC - C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\MsPMSPSv.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation)
PRC - C:\HP\KBD\KBD.EXE (Hewlett-Packard Company)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Multimedia Card Reader\shwicon2k.exe (Alcor Micro, Corp.)
PRC - C:\WINDOWS\System32\hphmon05.exe (Hewlett-Packard)
PRC - C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (Hewlett-Packard Company)
PRC - C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe ()
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Visioneer\PaperPort\FBDirect.exe (Visioneer Inc.)
PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
PRC - C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.)
PRC - C:\WINDOWS\System32\LVComsX.exe (Logitech Inc.)
PRC - C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Documents and Settings\JD\My Documents\JD's Downloads\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AdobeActiveFileMonitor7.0 [Auto | Running]) -- C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\System32\ati2sgag.exe ()
SRV - (Automatic LiveUpdate Scheduler [Auto | Running]) -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (ccEvtMgr [Auto | Running]) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DefWatch [Auto | Running]) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (ehSched [Auto | Running]) -- C:\WINDOWS\ehome\ehSched.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (FreeAgentGoNext Service [Auto | Running]) -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (GEARSecurity [Auto | Running]) -- C:\WINDOWS\System32\GEARSec.exe (GEAR Software)
SRV - (getPlusHelper [On_Demand | Stopped]) -- C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (gupdate1c9827bbeb07656 [Auto | Stopped]) -- C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [On_Demand | Running]) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Auto | Running]) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (HPSLPSVC [Auto | Running]) -- C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL (Hewlett-Packard Co.)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (InCDsrv [Auto | Running]) -- C:\Program Files\Ahead\InCD\InCDsrv.exe (Nero AG)
SRV - (IntuitUpdateService [Auto | Running]) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Lavasoft Ad-Aware Service [On_Demand | Stopped]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LiveUpdate [On_Demand | Stopped]) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE (Symantec Corporation)
SRV - (MSSQL$SQLEXPRESS [Auto | Running]) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper [Disabled | Stopped]) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (Net Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\System32\HPZinw12.dll (Hewlett-Packard)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (Norton Ghost [Auto | Running]) -- C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe (Symantec Corporation)
SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\System32\HPZipm12.dll (Hewlett-Packard)
SRV - (RichVideo [Auto | Running]) -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (SavRoam [On_Demand | Stopped]) -- C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (SNDSrvc [On_Demand | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc [On_Demand | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (SQLBrowser [Auto | Running]) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (SQLWriter [Auto | Running]) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (Symantec AntiVirus [Auto | Running]) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (UMWdf [Auto | Running]) -- C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
SRV - (vsmon [Auto | Running]) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (WMDM PMSP Service [Auto | Running]) -- C:\WINDOWS\System32\MsPMSPSv.exe (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 41
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.96
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.32.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: statusbar@toodledo.com:1.60
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/24 03:04:09 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2009/09/08 10:18:41 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/09 19:16:03 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/09/09 19:16:03 | 00,000,000 | ---D | M]

[2008/06/18 18:29:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Extensions
[2008/06/18 18:29:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/10/03 09:28:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions
[2008/04/20 09:59:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{1AF3FC34-0725-4485-A939-6B40EB7CA96A}
[2009/06/26 19:17:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/05/02 11:19:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2009/08/16 20:53:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2009/03/20 17:12:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\mozilla\Firefox\Profiles\v2nyddyy.default\extensions\statusbar@toodledo.com
[2008/10/12 18:10:36 | 00,000,276 | ---- | M] () -- C:\Documents and Settings\JD\Application Data\Mozilla\FireFox\Profiles\v2nyddyy.default\searchplugins\search.xml
[2009/10/03 09:28:19 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/09/09 19:16:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/12/11 19:32:04 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2009/09/09 19:15:53 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/09/09 19:15:53 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/03/19 19:23:20 | 00,114,688 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2008/09/03 14:11:24 | 00,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\mozilla firefox\plugins\npbittorrent.dll
[2008/06/17 20:43:04 | 00,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2007/10/11 14:17:50 | 01,435,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/09/09 19:15:56 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2007/05/10 22:52:34 | 00,095,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2006/09/07 10:08:58 | 00,618,496 | ---- | M] (Pixami) -- C:\Program Files\mozilla firefox\plugins\NPPxIm.dll
[2006/09/07 10:08:58 | 00,819,200 | ---- | M] (Pixami) -- C:\Program Files\mozilla firefox\plugins\NPPxPrn.dll
[2009/09/09 19:02:21 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/09/09 19:02:21 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/09/09 19:02:22 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2007/12/25 00:02:38 | 00,024,673 | ---- | M] (Check Point Software Technologies Ltd.) -- C:\Program Files\mozilla firefox\plugins\NPZoneSB.dll
[2009/08/07 12:44:18 | 00,030,400 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\mozilla firefox\plugins\np_gp.dll
[2009/08/15 07:48:37 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/08/15 07:48:37 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/08/15 07:48:37 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/15 07:48:37 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/08/15 07:48:37 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/15 07:48:37 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/08/15 07:48:37 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (319151 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10945 more lines...
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {0A87E45F-537A-40B4-B812-E2544C21A09F} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {bffe81e7-ca83-45d4-893f-519c62f1bcfe} - File not found
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (HP View) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll (Hewlett-Packard Company)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe ()
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HP Component Manager] C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [KBD] C:\HP\KBD\KBD.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [Norton Ghost 9.0] C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PP7600usb] C:\Program Files\Visioneer\PaperPort\FBDirect.exe (Visioneer Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE ()
O4 - HKLM..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Startup Cop Pro Startup Launcher] C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe (Ziff-Davis Media, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Zone Labs Security.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - Startup: C:\Documents and Settings\JD\Start Menu\Programs\Startup\TempClean.bat ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: &Translate English Word - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate Page into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.32.0\gears.dll (Google Inc.)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: PokerTime.net Poker - {E28AB5C9-B58F-4512-AF80-29001BC5A29D} - C:\Program Files\PokerTimeGuestMPP\MPPoker.exe (Microgaming)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: 69 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://activation.rr.com/install/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {1B9935E4-8A50-4DD8-BD09-A7518723BF97} https://quicken.ehosts.net/netagent/objects/custappx3.CAB (eAssist NetAgent Customer ActiveX Control version 3)
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab (LSSupCtl Class)
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} http://asp.mathxl.com/wizmodules/testgen/i...GenXInstall.cab (TTestGenXInstallObject)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://spaces.msn.com//PhotoUpload/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1231725258781 (MUWebControl Class)
O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll (InstallHelper Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll (There Voice Trainer)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab (Pearson Installation Assistant 2)
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} http://download.zonelabs.com/bin/promotion...ctor/WebSWK.cab (WebSpyWareKiller Class)
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} http://download.zonelabs.com/bin/promotion...ctor/WebAAS.cab (Anonymizer Anti-Spyware Scanner)
O16 - DPF: {AAF421E6-7914-430A-9981-72B31AFF3BF4} file://c:\Program Files\There\ThereClient\ThereLauncher.dll (There Launcher)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse...pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} https://www-secure.symantec.com/techsupp/asa/SymAData.cab (ActiveDataInfo Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D44C75D8-C827-473E-8F68-A77E42500782} http://www.samsphotoclub.com/upload/WebUploadClient.cab (Uploader Class)
O16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} http://asp.mathxl.com/books/_Players/EconPlayer.cab (Pearson MyEconLab Player Control)
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} http://216.249.24.60/code/iPIX-ImageWell-ipix.cab (iPIX Media Send Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.25.227.55 209.18.47.61 24.25.227.53
O18 - Protocol\Handler\bw+0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw+0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0 {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0s {9eb19210-0033-48c0-94f0-164d35cb93db} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\offline-8876480 {9EB19210-0033-48C0-94F0-164D35CB93DB} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\windows\system32\) - C:\WINDOWS\System32 [2009/10/03 21:37:11 | 00,000,000 | ---D | M]
O20 - AppInit_DLLs: (tehunevo.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\System32\NavLogon.dll (Symantec Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/12/16 19:45:52 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2002/09/11 03:02:32 | 00,000,045 | -HS- | M] () - D:\Autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{391dd251-46bc-11dd-b7f4-000ea6c3bfc8}\Shell\AutoRun\command - "" = .\Encryption Tool\MaxtorEncryption.exe
O33 - MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\AutoRun\command - "" = F:\PortableRoboForm.exe -- File not found
O33 - MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\RoboForm2Go\command - "" = F:\PortableRoboForm.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 14 Days ==========

[2009/10/03 17:22:48 | 00,000,000 | ---D | C] -- C:\_OTS
[2009/10/03 10:52:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\JD\Desktop\SysProt
[2009/10/03 10:49:54 | 00,355,033 | ---- | C] () -- C:\Documents and Settings\JD\Desktop\SysProt.zip
[2009/10/03 10:30:52 | 00,519,680 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\JD\Desktop\OTS.exe
[2009/09/27 17:57:55 | 16,099,45088 | -HS- | C] () -- C:\hiberfil.sys
[2009/09/27 15:47:27 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2009/09/27 14:20:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/09/27 14:19:31 | 00,000,622 | ---- | C] () -- C:\Documents and Settings\JD\Desktop\NTREGOPT.lnk
[2009/09/27 14:19:31 | 00,000,603 | ---- | C] () -- C:\Documents and Settings\JD\Desktop\ERUNT.lnk
[2009/09/27 14:19:29 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/09/27 13:10:24 | 00,000,000 | ---D | C] -- C:\VundoFix Backups
[2009/09/27 13:02:28 | 00,001,559 | ---- | C] () -- C:\Documents and Settings\JD\Desktop\CCleaner.lnk
[2009/09/27 13:02:26 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009/09/27 11:24:43 | 03,550,592 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\JD\Desktop\iexplore.exe
[2009/09/25 05:56:21 | 00,000,095 | ---- | C] () -- C:\WINDOWS\wininit.ini

========== Files - Modified Within 14 Days ==========

[2009/10/03 21:45:49 | 00,350,197 | -H-- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2009/10/03 21:39:53 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/10/03 21:38:08 | 00,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/10/03 21:38:04 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/03 21:37:20 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/10/03 21:37:15 | 16,099,45088 | -HS- | M] () -- C:\hiberfil.sys
[2009/10/03 21:30:00 | 00,000,966 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006UA.job
[2009/10/03 21:17:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/10/03 17:30:08 | 00,011,168 | -H-- | M] () -- C:\WINDOWS\System32\mehudebe
[2009/10/03 17:25:58 | 00,038,912 | -HS- | M] () -- C:\WINDOWS\System32\benugame.dll
[2009/10/03 17:00:51 | 09,736,692 | -H-- | M] () -- C:\Documents and Settings\JD\Local Settings\Application Data\IconCache.db
[2009/10/03 16:21:24 | 00,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/10/03 10:50:31 | 00,355,033 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\SysProt.zip
[2009/10/03 10:31:02 | 00,519,680 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\JD\Desktop\OTS.exe
[2009/10/03 09:30:01 | 00,000,914 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006Core.job
[2009/10/03 04:00:16 | 00,000,804 | ---- | M] () -- C:\WINDOWS\tasks\Incremental Backup.job
[2009/10/01 20:30:52 | 00,002,272 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\Google Chrome.lnk
[2009/09/28 19:27:22 | 00,000,221 | ---- | M] () -- C:\WINDOWS\QUICKEN.INI
[2009/09/28 10:42:33 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/09/28 08:00:11 | 00,000,832 | ---- | M] () -- C:\WINDOWS\tasks\Full Backups.job
[2009/09/27 14:19:31 | 00,000,622 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\NTREGOPT.lnk
[2009/09/27 14:19:31 | 00,000,603 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\ERUNT.lnk
[2009/09/27 13:02:28 | 00,001,559 | ---- | M] () -- C:\Documents and Settings\JD\Desktop\CCleaner.lnk
[2009/09/27 11:24:48 | 03,550,592 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Documents and Settings\JD\Desktop\iexplore.exe
[2009/09/25 05:56:21 | 00,000,095 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2009/09/22 09:15:28 | 00,000,768 | ---- | M] () -- C:\WINDOWS\tasks\Media Backup Schedule.job

========== LOP Check ==========

[2009/10/03 10:17:48 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/03/27 19:12:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/02/03 23:42:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/09/09 19:25:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/01/25 10:40:14 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/04/09 19:04:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2005/04/10 06:27:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{A695AD8D-651B-4C8A-91DF-51F853449A57}
[2004/12/29 19:20:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ahead
[2008/04/20 14:23:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink
[2007/12/31 14:24:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2008/10/17 18:50:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\espionServerData
[2008/10/17 17:36:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2009/01/24 17:26:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intuit
[2007/10/01 16:43:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2003/12/16 23:06:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Motive
[2006/01/05 10:18:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PureEdge
[2005/03/10 15:28:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RoboForm
[2003/12/16 19:51:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI
[2009/09/01 22:35:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2005/09/19 20:49:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Support.com
[2008/10/13 08:54:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/12/30 22:23:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tenebril
[2005/11/26 13:07:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia
[2004/12/30 14:55:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/11/14 22:02:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/10/03 21:33:18 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\JD\Application Data
[2007/12/31 15:31:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\2K Games
[2007/12/30 22:11:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\AccurateRip
[2004/12/29 19:49:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Ahead
[2007/12/01 14:33:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Amazon
[2009/01/17 16:22:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Any Video Converter
[2004/12/29 16:44:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\ArcSoft
[2009/08/02 20:43:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\BitTorrent
[2007/12/28 15:35:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\BookmarkBridge
[2004/11/14 11:07:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Common Files
[2008/04/20 14:23:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\CyberLink
[2009/10/03 21:53:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\DNA
[2009/08/03 05:11:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\DVD Flick
[2009/06/11 19:56:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\dvdcss
[2004/11/02 15:30:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\EuroTalk
[2005/08/21 11:48:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\FotoWire
[2008/06/29 19:22:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\gtk-2.0
[2007/11/25 15:09:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\interMute
[2004/09/10 15:48:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\InterVideo
[2008/07/22 18:02:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Intuit
[2009/02/07 20:01:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\IObit
[2008/01/05 15:59:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\iPhoneRingToneMaker
[2004/11/02 12:45:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\IsolatedStorage
[2006/10/14 20:15:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\LaCie
[2007/01/26 17:21:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Leadertech
[2008/12/16 20:26:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\LimeWire
[2005/12/22 12:17:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Microgaming
[2004/08/24 14:37:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Motive
[2005/08/27 06:44:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Musicmatch
[2007/07/27 22:45:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\NGC_IKTS
[2005/12/24 11:01:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\OLYMPUS
[2009/01/16 09:56:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\PC Magazine Utilities
[2008/10/17 18:52:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.1
[2006/05/28 08:05:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Premiere
[2006/01/05 10:18:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\PureEdge
[2007/12/13 22:26:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Roxio
[2003/12/16 23:23:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\SampleView
[2004/12/05 13:02:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\spweng
[2007/12/30 22:23:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Tenebril
[2009/09/21 21:20:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\U3
[2004/12/30 15:27:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Ulead Systems
[2008/11/14 22:03:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Viewpoint
[2009/05/13 06:36:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Windows Desktop Search
[2009/06/08 17:58:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\JD\Application Data\Windows Search
[2009/09/28 10:42:33 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/09/10 18:03:04 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2003/07/30 09:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/09/28 08:00:11 | 00,000,832 | ---- | M] () -- C:\WINDOWS\Tasks\Full Backups.job
[2009/10/03 21:38:08 | 00,000,882 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2009/10/03 21:17:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2009/10/03 09:30:01 | 00,000,914 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006Core.job
[2009/10/03 21:30:00 | 00,000,966 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4249377541-764714509-3756006734-1006UA.job
[2009/10/03 04:00:16 | 00,000,804 | ---- | M] () -- C:\WINDOWS\Tasks\Incremental Backup.job
[2009/09/22 09:15:28 | 00,000,768 | ---- | M] () -- C:\WINDOWS\Tasks\Media Backup Schedule.job
[2009/10/03 21:38:04 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:825D5945
< End of report >
-----------------------------------------------------------------------------------

GMER 1.0.15.15125 - http://www.gmer.net
Rootkit scan 2009-10-04 04:06:31
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\JD\LOCALS~1\Temp\kxldapow.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwConnectPort [0xAE928FC0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateFile [0xAE925C80]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateKey [0xAE940170]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreatePort [0xAE929580]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateProcess [0xAE93D900]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateProcessEx [0xAE93DB10]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateSection [0xAE941B10]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0xAE929670]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDeleteFile [0xAE926210]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDeleteKey [0xAE9409F0]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xAEDD1CB0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDuplicateObject [0xAE93D280]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwLoadKey [0xAE940F10]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0xAE940F90]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwOpenFile [0xAE926070]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwOpenProcess [0xAE93F180]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwOpenThread [0xAE93EF40]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRenameKey [0xAE9416F0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwReplaceKey [0xAE941150]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0xAE928BE0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRestoreKey [0xAE941540]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSecureConnectPort [0xAE929190]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0xAE926440]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xAEDD1F10]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSystemDebugControl [0xAE93E200]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwTerminateProcess [0xAE93E080]

---- Kernel code sections - GMER 1.0.15 ----

.text ntoskrnl.exe!ZwYieldExecution + 12E 804E4968 12 Bytes [80, 95, 92, AE, 00, D9, 93, ...] {ADC BYTE [EBP-0x26ff516e], 0x93; SCASB ; ADC BL, BL; XCHG EBX, EAX; SCASB }
? srescan.sys The system cannot find the file specified. !
? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS The system cannot find the file specified. !

---- User code sections - GMER 1.0.15 ----

.text C:\WINDOWS\system32\SearchIndexer.exe[3556] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [AE92DB20] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [AE92D930] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [AE92E260] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [AE92BE90] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [AE92BE90] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [AE92DB20] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [AE92D930] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [AE92E260] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [AE92DB20] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [AE92BE90] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [AE92E260] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [AE92D930] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [AE92E260] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [AE92D930] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [AE92DB20] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCloseAdapter] [AE92E260] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisOpenAdapter] [AE92D930] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisDeregisterProtocol] [AE92BE90] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisRegisterProtocol] [AE92DB20] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [AE92BE90] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [AE92DB20] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [AE92D930] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [AE92E260] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateFile] [AE946B30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [AE92DB20] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [AE92BE90] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [AE92E260] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [AE92D930] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtSetInformationFile] [AE9268D0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateFile] [AE926A80] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtCreateFile] [AE9265E0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtOpenFile] [AE926980] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \FileSystem\Ntfs \Ntfs PQV2i.sys (StorageCraft Volume Snap-Shot/StorageCraft)

Device \Driver\Tcpip \Device\Ip vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
Device pci.sys (NT Plug and Play PCI Enumerator/Microsoft Corporation)
Device \Driver\Tcpip \Device\Tcp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 PQV2i.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 PQV2i.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)

Device atapi.sys (IDE/ATAPI Port Driver/Microsoft Corporation)
Device \Driver\Tcpip \Device\Udp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
Device \Driver\Tcpip \Device\RawIp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat InCDrec.SYS (InCD File System Recognizer/Nero AG)

---- EOF - GMER 1.0.15 ----
Go to the top of the page
 
+Quote Post
hammerman
post Oct 4 2009, 09:57 AM
Post #6


Trusted Helper
Group Icon
Posts: 1,499
From: UK
OS: XP



Hello,

Can you post the latest OTS log file which you will find in the folder C:\_OTS\MovedFiles

Please follow these steps.

-- Step 1 --

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    CODE
    :OTL
    O2 - BHO: (no name) - {bffe81e7-ca83-45d4-893f-519c62f1bcfe} - File not found
    O33 - MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\AutoRun\command - "" = F:\PortableRoboForm.exe -- File not found
    O33 - MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\Shell\RoboForm2Go\command - "" = F:\PortableRoboForm.exe -- File not found
    [2009/10/03 17:30:08 | 00,011,168 | -H-- | M] () -- C:\WINDOWS\System32\mehudebe
    [2009/10/03 17:25:58 | 00,038,912 | -HS- | M] () -- C:\WINDOWS\System32\benugame.dll

    :Services

    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=-

    :Files

    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • This fix will produce a report. Please add this to your reply.


-- Step 2 --

Run Malwarebytes' Anti-Malware.
  • Select the Update tab and then click Check for Updates. If an update is found, it will download and install the latest version.
  • Select the Scanner tab, select "Perform quick scan", then click Scan
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

Go to the top of the page
 
+Quote Post
BuzzBoy22
post Oct 4 2009, 01:30 PM
Post #7


New Member
*
Posts: 9
OS: XP



hammerman,

MBAM found no malicious items. Here are the logs:

All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bffe81e7-ca83-45d4-893f-519c62f1bcfe}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bffe81e7-ca83-45d4-893f-519c62f1bcfe}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\ not found.
File F:\PortableRoboForm.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bdc5d164-4a56-11db-9c4d-000ea6c3bfc8}\ not found.
File F:\PortableRoboForm.exe not found.
C:\WINDOWS\System32\mehudebe moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\benugame.dll
C:\WINDOWS\System32\benugame.dll NOT unregistered.
C:\WINDOWS\System32\benugame.dll moved successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs deleted successfully.
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes

User: Aimee
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: JD
File delete failed. C:\Documents and Settings\JD\Local Settings\Temp\~DF745D.tmp scheduled to be deleted on reboot.
->Temp folder emptied: 322336 bytes
File delete failed. C:\Documents and Settings\JD\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 198389 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 46344735 bytes
->Google Chrome cache emptied: 6299941 bytes
->Apple Safari cache emptied: 0 bytes

User: Kids

User: Laptop

User: LocalService
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
->Temp folder emptied: 65748 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_944.dat scheduled to be deleted on reboot.
->Temp folder emptied: 16384 bytes
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
File delete failed. C:\WINDOWS\temp\ZLT04d24.TMP scheduled to be deleted on reboot.
Windows Temp folder emptied: 23200 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 50.87 mb


OTL by OldTimer - Version 3.0.16.0 log created on 10042009_084725

Files\Folders moved on Reboot...
C:\Documents and Settings\JD\Local Settings\Temp\~DF745D.tmp moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_944.dat not found!
C:\WINDOWS\temp\ZLT04d24.TMP moved successfully.

Registry entries deleted on Reboot...

-------------------------------------------------------------------------------

Malwarebytes' Anti-Malware 1.41
Database version: 2905
Windows 5.1.2600 Service Pack 3

10/4/2009 9:24:10 AM
mbam-log-2009-10-04 (09-24-10).txt

Scan type: Quick Scan
Objects scanned: 140394
Time elapsed: 24 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Go to the top of the page
 
+Quote Post
hammerman
post Oct 4 2009, 02:19 PM
Post #8


Trusted Helper
Group Icon
Posts: 1,499
From: UK
OS: XP



Hello,

Please follow these steps and then give me an update on how your computer's running now.

-- Step 1 --

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

-- Step 2 --

This scan may take a few hours to run but it's very thorough.

Please do an online scan with Kaspersky WebScanner

Click on Accept

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
      Extended (if available otherwise Standard)
    • Scan Options:
      Scan Archives
      Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
      Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.


Go to the top of the page
 
+Quote Post
BuzzBoy22
post Oct 5 2009, 09:47 AM
Post #9


New Member
*
Posts: 9
OS: XP



hammerman,

I ran JavaRa and reinstalled the latest JRE without a problem. So far when I have attempted to run Kapersky WebScanner, I haven't managed to get all the way through to the scan. The database download was only about 50% complete after 12 hours and then I started to get script errors. I was using Firefox, and I plan to attempt the scan again today with Explorer while I'm at work. Besides the failed Kapersky scan, the computer seems to be behaving and I have not received any virus alerts. Just wanted to give you an update. I'll post again after the second try at running Kapersky. Thanks for your help.

BuzzBoy22
Go to the top of the page
 
+Quote Post
hammerman
post Oct 5 2009, 10:05 AM
Post #10


Trusted Helper
Group Icon
Posts: 1,499
From: UK
OS: XP



Thanks for letting me know.

If you continue to have problems, use this scanner instead. Please bear in mind that these scans can take a few hours to complete.

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.
    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .
  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


After that click on Security level then choose Customize then click on the tab that says Heuristic Analyzer then choose Enable Deep rootkit search then choose ok.
Then choose OK again then you are back to the main screen.

  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left un-neutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.


This post has been edited by hammerman: Oct 5 2009, 10:06 AM
Go to the top of the page
 
+Quote Post
BuzzBoy22
post Oct 6 2009, 09:23 AM
Post #11


New Member
*
Posts: 9
OS: XP



hammerman,

I was able to complete the scan on the second try.

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Tuesday, October 6, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, October 06, 2009 04:43:36
Records in database: 2920392
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
G:\
H:\
I:\
J:\
L:\

Scan statistics:
Objects scanned: 254426
Threats found: 28
Infected objects found: 70
Suspicious objects found: 4
Scan duration: 07:28:22


File name / Threat / Threats count
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: Email-Worm.Win32.Mydoom.a 1
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook1.pst Infected: Email-Worm.Win32.Mydoom.a 1
C:\Documents and Settings\Administrator\My Documents\Email\Main\Deleted Items.dbx Infected: Email-Worm.Win32.Mydoom.a 1
C:\Documents and Settings\Aimee\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Suspicious: Trojan-Spy.HTML.Fraud.gen 2
C:\Documents and Settings\Aimee\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: Exploit.HTML.ObjData 1
C:\Documents and Settings\Aimee\My Documents\Email\Main\Deleted Items.dbx Infected: Email-Worm.Win32.Mydoom.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80000\48FAC461.VBN Infected: Exploit.SWF.Downloader.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08B80001\48FACA64.VBN Infected: not-a-virus:AdWare.Win32.BHO.dht 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0000\4B6D6202.VBN Infected: Packed.Win32.Krap.p 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0001\4B6D64F8.VBN Infected: Packed.Win32.Krap.p 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0002\4B6D65AB.VBN Infected: Packed.Win32.Krap.p 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0003\4B6D65D3.VBN Infected: Packed.Win32.Krap.p 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0004\4B6D65FB.VBN Infected: Packed.Win32.Krap.p 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0005\4B6D6623.VBN Infected: Packed.Win32.Krap.p 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0006\4B6D664D.VBN Infected: Packed.Win32.Krap.p 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0007\4B6D6675.VBN Infected: Packed.Win32.Krap.p 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0008\4B6D669B.VBN Infected: Packed.Win32.Krap.p 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\094C0009\4B6D66C3.VBN Infected: Packed.Win32.Krap.p 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C400000\4D5733D3.VBN Infected: Trojan.Win32.FraudPack.grt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C400001\4D5733EE.VBN Infected: Trojan.Win32.FraudPack.grt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C400002\4D574038.VBN Infected: Trojan.Win32.FraudPack.grt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C400003\4D574054.VBN Infected: Trojan-Downloader.Win32.Agent.ames 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0000\4D9CFB79.VBN Infected: Trojan-Downloader.Win32.Zlob.aahv 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0001\4D9CFBB6.VBN Infected: Trojan.Win32.Agent.aiar 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0002\4D9D0508.VBN Infected: Trojan-Downloader.Win32.Small.afpi 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0003\4D9D0D32.VBN Infected: Trojan-Downloader.Win32.Zlob.aaij 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0004\4D9D1567.VBN Infected: Trojan-Downloader.Win32.Zlob.aasq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0005\4D9D1D6B.VBN Infected: Trojan-Downloader.Win32.Zlob.aahr 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0006\4D9D2419.VBN Infected: Trojan.Win32.Agent.agyx 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C9C0007\4D9D2A27.VBN Infected: Hoax.Win32.Agent.ge 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D140000\4DB7E4AC.VBN Infected: Trojan-Downloader.Win32.Small.abfp 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DC00000\4DF2BCD2.VBN Infected: Trojan-Dropper.Win32.KGen.gjp 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DD40001\4DDF68E7.VBN Infected: Trojan-Downloader.Win32.Injecter.ahh 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EB40000\4FF7DB72.VBN Infected: P2P-Worm.Win32.Nugg.w 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EB40001\4FF7DB8D.VBN Infected: P2P-Worm.Win32.Nugg.w 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EB40002\4FFC9E5D.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EB40003\4FFCA5F6.VBN Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EC00000\4FFB328A.VBN Infected: Trojan-Downloader.Win32.FraudLoad.vdck 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0ED80000\4EFCA90D.VBN Infected: Trojan-Downloader.Win32.Zlob.bxi 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080000.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080001.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080002.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080003.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080004.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080005.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080006.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080007.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080008.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080009.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F08000A.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F08000B.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F08000C.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F08000D.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F08000E.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F08000F.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080010.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F080013.VBN Infected: Trojan-Downloader.Win32.Small.abax 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F180000.VBN Infected: Trojan-Downloader.Win32.FraudLoad.wbru 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F300002\4FF7A889.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.balk 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F300003\4FF7A8BD.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.balk 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F300005\4FF7A92E.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.balk 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F300006\4FF7A974.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.balk 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\10900000\59FC5426.VBN Infected: Packed.Win32.Krap.p 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\10900001\59FC55AE.VBN Infected: Packed.Win32.Krap.p 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\10E80000\58EA35DF.VBN Infected: Trojan-Downloader.Win32.Small.abfp 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\13A00000\5BE835E9.VBN Infected: Trojan.Win32.Monder.bzea 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\1CB00000.VBN Infected: not-a-virus:PSWTool.Win32.Dialupass.dp 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\1CB00001.VBN Infected: not-a-virus:PSWTool.Win32.Dialupass.dp 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\1CB00002.VBN Infected: not-a-virus:PSWTool.Win32.Dialupass.dp 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\1CB00003.VBN Infected: not-a-virus:PSWTool.Win32.Dialupass.dp 1
C:\Documents and Settings\Laptop\Aimee\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Suspicious: Trojan-Spy.HTML.Fraud.gen 2
C:\Documents and Settings\Laptop\Aimee\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: Exploit.HTML.ObjData 1

Selected area has been scanned.
Go to the top of the page
 
+Quote Post
hammerman
post Oct 6 2009, 11:15 AM
Post #12


Trusted Helper
Group Icon
Posts: 1,499
From: UK
OS: XP



Hello,

You have some infected e-mail messages in Outlook so you may want to remove any e-mails with suspicious attachments and empty your deleted items folder.

Apart from that, your computer appears clean smile.gif

Let's remove the tools we've been using.

Please follow these steps.

-- Step 1 --
  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.

-- Step 2 --

Your backup files in the System Restore points may be infected and need to be cleared. The only way to do this is to turn off System Restore and then turn it back on again. This will delete all your backup files in the System Restore points, including any that are infected. You can then create a new restore point containing your clean files. Please follow these instructions.

  • Right-click on My Computer and select Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply then click Yes to confirm. This will remove all your System Restore points and infected files.
  • Now uncheck the Turn off System Restore, click Apply then OK.
A new Restore Point has now been created containing backup files for your computer that are clean. You can create additional Restore Points at any time. Click here for instructions.

Here are some measures you can take to ensure that your computer remains clean.

1. Updates

Windows Updates

It is essential that you regularly check and install the latest Windows Updates. Vulnerabilities within Windows can leave your computer open to infection. Regular updates are released to fix these security vulnerabilities. It is recommended that you set Windows to check, download and install your updates automatically.

  • Click Start
  • Select Control Panel
  • Click on Automatic (recommended)
  • Set the day and time for the update check. Set this to a time when your computer will normally be on and connected to the internet.
  • Click Apply then OK.
Java Updates

As with Windows, Java also needs to be regularly updated to fix security vulnerabilites. You can download the latest version of the Java Runtime Environment (JRE) from here. Download, install and reboot your computer. You also need to uininstall older versions of Java.

  • Click Start
  • Select Control Panel
  • Select Add or Remove Programs
  • Remove all Java updates except the latest one you have just installed.
Adobe Updates

Your Adobe reader needs updating. You should ensure you use the latest Adobe Acrobat Reader and install any security updates that are released. You can download the latest reader and updates from here.

Other Updates

Regularly check for updates for all your security programs including firewall, antivirus, antispyware etc

2. Security Programs

Here is a list of security programs that I would recommend.

Firewall

A firewall is essential to stop hackers infiltrating your computer. The following firewalls are free for personal use. Do not install more than one firewall.

Zone Alarm is an excellent free basic firewall which is very easy to use.
Online-Armor Free is a more advanced firewall which includes a Host Intrusion Protection System (HIPS). This ensures that unrecognised programs will not run unless you give permission.

Antivirus

An antivirus program is essential. The following antivirus programs are free for personal use. Do not use more than one antivirus and always update virus definitions regularly.

AVG
Avira Free
Avast

Anti-Malware

Malwarebytes Anti-Malware MBAM is an excellent anti-malware tool that should be updated and a Quick Scan performed regularly. A Full Scan does not have to be carried out on such a regular basis as the developers aim to detect the vast majority of malware with the Quick Scan. The scanner is free for on-demand scans only.

Ad-Aware, Spybot, SuperAntispyware and A-Squared Free are also very good anti-malware programs that are free for on-demand scans. Spybot has a real-time protection feature called TeaTimer.

Prevention

SpywareBlaster is an excellent free tool for preventing the installation of spyware.
SpywareGuard offers real-time protection so that spyware is detected and blocked before it can do any harm.

Cleaner

ATF Cleaner removes temporary Internet Explorer, Firefox and Windows files.

Browser

Firefox is an alternative browser to Internet Explorer and is more secure.
NoScript is an add-on for Firefox and prevents execution of malicious scripts.
MVPS is a HOSTS file to replace your existing file. This prevents you connecting to a list of well-known ad sites.

Go to the top of the page
 
+Quote Post
BuzzBoy22
post Oct 6 2009, 03:16 PM
Post #13


New Member
*
Posts: 9
OS: XP



hammerman,

Thanks a million for helping me out of this mess... you're my hero. Before we close this post, I have a couple of quick questions I hope you can help me with.

Is there a way to determine which email messages are infected?

As you know, I've been using Symantec AntiVirus. In your experience, is this a program you would stick with, or would you switch to AVG or one of the other programs in your post?

Thanks again,
BuzzBoy22
Go to the top of the page
 
+Quote Post
hammerman
post Oct 7 2009, 07:03 AM
Post #14


Trusted Helper
Group Icon
Posts: 1,499
From: UK
OS: XP



Hello,

QUOTE
Is there a way to determine which email messages are infected?


I'm afraid not. The files contain all your emails.

QUOTE
As you know, I've been using Symantec AntiVirus. In your experience, is this a program you would stick with, or would you switch to AVG or one of the other programs in your post?


I would recommend Avira antivirus.
Go to the top of the page
 
+Quote Post
BuzzBoy22
post Oct 7 2009, 09:45 AM
Post #15


New Member
*
Posts: 9
OS: XP



hammerman,

Thanks again for your help. My computer is running well with no sign of the virus.

BuzzBoy22
Go to the top of the page
 
+Quote Post

2 Pages V   1 2 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 20th November 2009 - 08:53 PM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising