ComboFix 06.12.01W - Running from: "D:\Documents and Settings\leobb\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
D:\Program Files\Internet Explorer\PLUGINS\System8.sys
D:\Program Files\INSTALL.LOG
D:\Program Files\Internet Explorer\PLUGINS\system.jmp
D:\autorun.inf
D:\WINDOWS\system32\downdll.dll
D:\WINDOWS\system32\mywl.dll
D:\WINDOWS\system32\SVKP.sys
D:\WINDOWS\system32\QQhx.dat
D:\Program Files\Internet Explorer\plugins\System8.sys
D:\Program Files\DeskAdTop
D:\WINDOWS\system32\3721.8.dll
D:\WINDOWS\system32\3721.8.dll
((((((((((((((((((((((((((((((( Files Created from 2006-11-19 to 2006-12-19 ))))))))))))))))))))))))))))))))))
2006-12-19 21:38 2,368 --a------ D:\WINDOWS\system32\SVKP.sys
2006-12-19 21:37 <DIR> d-------- D:\WINDOWS\erdnt
2006-12-19 01:36 <DIR> d-------- D:\Documents and Settings\leobb\Application Data\CyberLink
2006-12-19 01:35 <DIR> d-------- D:\Program Files\powerdvd
2006-12-19 01:35 <DIR> d-------- D:\download
2006-12-19 01:25 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\CyberLink
2006-12-19 01:15 <DIR> d-------- D:\Documents and Settings\leobb\Application Data\Apple Computer
2006-12-19 01:01 5,672 --a------ D:\WINDOWS\system32\IMSCMIG.exe
2006-12-19 00:55 61,440 --a------ D:\WINDOWS\system32\SysShellKernel.dll
2006-12-19 00:17 3,968 --a------ D:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-12-19 00:17 <DIR> d-------- D:\Program Files\Grisoft
2006-12-18 23:47 41,984 --a------ D:\WINDOWS\system32\windhcp.dll
2006-12-18 23:46 5,732 --a------ D:\WINDOWS\system32\tpxhst32.exe
2006-12-18 18:51 61,952 -r-hs---- D:\WINDOWS\G_SERVER2006KEY.DLL
2006-12-18 18:51 54,392 ---hs---- D:\sxs.exe
2006-12-18 18:28 54,392 ---hs---- D:\WINDOWS\system32\heysgj.exe
2006-12-18 18:28 40,448 ---hs---- D:\WINDOWS\system32\heysgj.dll
2006-12-18 18:28 132,608 --a------ D:\WINDOWS\system32\winrar.exe
2006-12-18 16:44 <DIR> d-------- D:\Program Files\Spybot - Search & Destroy
2006-12-18 16:44 <DIR> d-------- D:\Program Files\Lavasoft
2006-12-18 16:44 <DIR> d-------- D:\Documents and Settings\leobb\Application Data\Lavasoft
2006-12-18 16:44 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2006-12-18 16:08 <DIR> d-------- D:\WINDOWS\east
2006-12-18 16:06 <DIR> d-------- D:\Program Files\Eset
2006-12-16 18:53 <DIR> d-------- D:\Program Files\Warcraft III
2006-12-16 17:17 2,829 --a------ D:\WINDOWS\War3Unin.pif
2006-12-16 17:17 126,976 --a------ D:\WINDOWS\War3Unin.exe
2006-12-16 17:13 <DIR> d-------- D:\Program Files\Warcraft3
2006-12-11 20:37 854,016 --a------ D:\Program Files\Hyalo-ToDo gadget by adni18.exe
2006-12-06 17:06 <DIR> d-------- D:\Program Files\EA GAMES
2006-12-06 02:44 442,368 -ra------ D:\WINDOWS\system32\vp6vfw.dll
2006-12-04 23:12 681,836 --a------ D:\PDK.exe
2006-12-04 21:55 8,941,964 --a------ D:\PDS.exe
2006-12-03 13:22 <DIR> d-------- D:\WINDOWS\MyTvPlayer
2006-11-27 19:23 <DIR> d-------- D:\Documents and Settings\leobb\Application Data\vlc
2006-11-27 19:18 <DIR> d-------- D:\Program Files\VideoLAN
2006-11-26 03:19 <DIR> d-------- D:\Program Files\FlashGet
2006-11-24 02:45 <DIR> d-------- D:\Program Files\Common Files\xing shared
2006-11-23 02:47 <DIR> d-------- D:\WINDOWS\system32\appmgmt
2006-11-22 18:26 774,760 --------- D:\WINDOWS\Hacker.com.cn.exe
2006-11-19 13:24 <DIR> d-------- D:\Program Files\ICQToolbar
2006-11-19 13:24 <DIR> d-------- D:\Program Files\ICQLite
2006-11-19 13:24 <DIR> d-------- D:\Documents and Settings\leobb\Application Data\ICQLite
2006-11-19 00:36 <DIR> d-------- D:\Program Files\MAME32k
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-19 01:35 -------- d--h----- D:\Program Files\InstallShield Installation Information
2006-12-19 00:48 -------- d-------- D:\Program Files\Internet Explorer
2006-12-18 23:46 -------- d-------- D:\Program Files\Ventrilo
2006-12-18 15:46 32512 --a------ D:\WINDOWS\system32\drivers\npf.sys
2006-12-18 14:22 -------- d-------- D:\Program Files\Real
2006-12-16 21:23 -------- d-------- D:\Program Files\WC3Banlist
2006-12-15 23:10 -------- d-------- D:\Documents and Settings\leobb\Application Data\AdobeUM
2006-12-11 20:31 -------- d-------- D:\Program Files\Pimero
2006-12-02 23:33 -------- d-------- D:\Documents and Settings\leobb\Application Data\Hamachi
2006-11-24 02:46 -------- d-------- D:\Documents and Settings\leobb\Application Data\Real
2006-11-24 02:45 -------- d-------- D:\Program Files\Common Files\Real
2006-11-24 02:45 -------- d-------- D:\Program Files\Common Files
2006-11-18 12:50 -------- d-------- D:\Program Files\SC
2006-11-18 02:57 -------- d-------- D:\Program Files\CyberLink
2006-11-17 01:03 -------- d-------- D:\Program Files\eMule
2006-11-10 17:39 98304 --a------ D:\WINDOWS\system32\CmdLineExt.dll
2006-11-10 17:18 -------- d-------- D:\Program Files\KONAMI
2006-10-30 15:52 -------- d---s---- D:\Documents and Settings\leobb\Application Data\Microsoft
2006-10-26 21:26 -------- d-------- D:\Program Files\WinPcap
2006-10-22 02:18 -------- d-------- D:\Program Files\Windows Media Player
2006-10-21 20:48 163644 --a------ D:\WINDOWS\system32\drivers\secdrv.sys
2006-10-21 19:31 -------- d-------- D:\Documents and Settings\leobb\Application Data\DivX
2006-10-19 20:12 -------- d-------- D:\Program Files\DivX
2006-10-03 03:04 806912 --a------ D:\WINDOWS\system32\divx_xx0c.dll
2006-10-03 03:04 806912 --a------ D:\WINDOWS\system32\divx_xx07.dll
2006-10-03 03:04 790528 --a------ D:\WINDOWS\system32\divx_xx11.dll
2006-10-03 03:04 635486 --a------ D:\WINDOWS\system32\DivX.dll
2006-09-16 01:53 863 --a------ D:\Documents and Settings\leobb\Application Data\AdobeDLM.log
2006-09-16 01:53 0 --a------ D:\Documents and Settings\leobb\Application Data\dm.ini
2006-09-12 12:42 62 --ahs---- D:\Documents and Settings\leobb\Application Data\desktop.ini
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="D:\\WINDOWS\\System32\\ctfmon.exe"
"swg"="D:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"
"MSMSGS"="\"D:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"updateMgr"="\"D:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_8 -reboot 1"
"myZt"="D:\\WINDOWS\\east\\SVCH0ST.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE D:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"SoundMan"="SOUNDMAN.EXE"
"QuickTime Task"="\"D:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"CJIMETIPSYNC"="D:\\Program Files\\Common Files\\Microsoft Shared\\IME\\IMTC65\\CHANGJIE\\CINTLCFG.EXE /CJIMETIPSync"
"PHIMETIPSYNC"="D:\\Program Files\\Common Files\\Microsoft Shared\\IME\\IMTC65\\PHONETIC\\TINTLCFG.EXE /PHIMETIPSync"
"NvMediaCenter"="RUNDLL32.EXE D:\\WINDOWS\\System32\\NvMcTray.dll,NvTaskbarInit"
"TkBellExe"="\"D:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"adx.exe"="D:\\Program Files\\real\\adx.exe"
"mhs2"="D:\\DOCUME~1\\leobb\\LOCALS~1\\Temp\\mhs2.exe"
"rxzs"="D:\\DOCUME~1\\leobb\\LOCALS~1\\Temp\\rxzs.exe"
"zts2"="D:\\DOCUME~1\\leobb\\LOCALS~1\\Temp\\zts2.exe"
"wlzs"="D:\\DOCUME~1\\leobb\\LOCALS~1\\Temp\\wlzs.exe"
"WindowsXP"="D:\\DOCUME~1\\leobb\\LOCALS~1\\Temp\\ms.exe"
"IMSCMIG.exe"="D:\\WINDOWS\\System32\\IMSCMIG.exe"
"tpxhst32.exe"="D:\\WINDOWS\\System32\\tpxhst32.exe"
"RemoteControl"="\"D:\\Program Files\\powerdvd\\PDVDServ.exe\""
"LanguageShortcut"="\"D:\\Program Files\\powerdvd\\Language\\Language.exe\""
"ybgxir"="D:\\WINDOWS\\System32\\heysgj.exe"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="D:\\WINDOWS\\System32\\ctfmon.exe"
"swg"="D:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="D:\\WINDOWS\\System32\\ctfmon.exe"
"swg"="D:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{923509F1-45CB-4EC0-BDE0-1DED35B8FD60}"=""
"{1A404685-7563-4d02-B0F6-58B308A406A9}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:000000bd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"hx-2"="2"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0
Completion time: 06-12-19 21:38:35.98
D:\ComboFix.txt ... 06-12-19 21:38
Logfile of HijackThis v1.99.1
Scan saved at 21:54:52, on 19/12/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Program Files\CyberLink\Shared files\RichVideo.exe
D:\WINDOWS\System32\wdfmgr.exe
D:\WINDOWS\SOUNDMAN.EXE
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\DOCUME~1\leobb\LOCALS~1\Temp\mhs2.exe
D:\DOCUME~1\leobb\LOCALS~1\Temp\rxzs.exe
D:\Program Files\powerdvd\PDVDServ.exe
D:\WINDOWS\System32\heysgj.exe
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
D:\Program Files\Messenger\msmsgs.exe
D:\WINDOWS\east\SVCH0ST.EXE
D:\Program Files\Ventrilo\Ventrilo.exe
D:\Program Files\internet explorer\iexplore.exe
D:\Documents and Settings\leobb\Desktop\HijackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: BHOHelper Class - {67A90DD5-128D-43AB-B97C-565D2DD42A28} - D:\Program Files\real\atloader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: SysShellKernel - {E04B27AA-3973-4D68-8F42-B7C2FC8C6CF7} - D:\WINDOWS\System32\SysShellKernel.dll
O2 - BHO: (no name) - {E42222A2-B6E6-4242-A943-CDC0415AD763} - D:\WINDOWS\system32\3721.8.dll (file missing)
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - D:\PROGRA~1\FlashGet\getflash.dll
O3 - Toolbar: 毞狟刲坰 - {56A7DC70-E102-4408-A34A-AE06FEF01586} - D:\WINDOWS\Downloaded Program Files\iebar23.0.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CJIMETIPSYNC] D:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync
O4 - HKLM\..\Run: [PHIMETIPSYNC] D:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [adx.exe] D:\Program Files\real\adx.exe
O4 - HKLM\..\Run: [mhs2] D:\DOCUME~1\leobb\LOCALS~1\Temp\mhs2.exe
O4 - HKLM\..\Run: [rxzs] D:\DOCUME~1\leobb\LOCALS~1\Temp\rxzs.exe
O4 - HKLM\..\Run: [zts2] D:\DOCUME~1\leobb\LOCALS~1\Temp\zts2.exe
O4 - HKLM\..\Run: [wlzs] D:\DOCUME~1\leobb\LOCALS~1\Temp\wlzs.exe
O4 - HKLM\..\Run: [WindowsXP] D:\DOCUME~1\leobb\LOCALS~1\Temp\ms.exe
O4 - HKLM\..\Run: [IMSCMIG.exe] D:\WINDOWS\System32\IMSCMIG.exe
O4 - HKLM\..\Run: [tpxhst32.exe] D:\WINDOWS\System32\tpxhst32.exe
O4 - HKLM\..\Run: [RemoteControl] "D:\Program Files\powerdvd\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "D:\Program Files\powerdvd\Language\Language.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ybgxir] D:\WINDOWS\System32\heysgj.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "D:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [myZt] D:\WINDOWS\east\SVCH0ST.EXE
O4 - Startup: Hyalo-ToDo by adni18.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://D:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: 使用 FlashGet 下載 - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 全部使用 FlashGet 下載 - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 匯出至 Microsoft Office Excel(&X) - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: 建立行動最愛 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: 建立行動最愛... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - D:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: 參考資料 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exe
O12 - Plugin for .TIF: D:\Program Files\Internet Explorer\PLUGINS\npqtplugin7.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...kr.cab31267.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
http://software-dl.r...RdxIE601_tw.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1159436673217O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) -
http://appdirectory....ap/PhtPkMSN.cabO16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} -
http://www.trendmicr...scan/as4web.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{5EA6F7AC-FF1D-4F8C-8F66-BB6CADE8F4AD}: NameServer = 218.102.32.208 205.252.144.126
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: host Service For Windows (mshostsr) - Unknown owner - D:\WINDOWS\mshostsr.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - D:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Provisioning Transaction Service (ttt_13) - Unknown owner - D:\WINDOWS\System32\winrar.exe (file missing)