Hi Essexboy, here is stuff you require:
OTMoveit
C:\Program Files\Internet Explorer\IEXPLORE32.bbs moved successfully.
C:\WINDOWS\Fonts\avwgjst.exe moved successfully.
C:\WINDOWS\Fonts\avwljst.exe moved successfully.
C:\WINDOWS\Fonts\avwlkst.exe moved successfully.
C:\WINDOWS\Fonts\gjcsdzc.exe moved successfully.
C:\WINDOWS\Fonts\kaqhmaz.exe moved successfully.
C:\WINDOWS\Fonts\kawdjaz.exe moved successfully.
C:\WINDOWS\Fonts\kvdxmis.exe moved successfully.
C:\WINDOWS\Fonts\kvdxsois.exe moved successfully.
C:\WINDOWS\Fonts\okmhfaz.exe moved successfully.
C:\WINDOWS\Fonts\rarjftl.exe moved successfully.
C:\WINDOWS\Fonts\ratbutl.exe moved successfully.
C:\WINDOWS\Fonts\rsmyksp.exe moved successfully.
C:\WINDOWS\Fonts\swrcgac.exe moved successfully.
C:\WINDOWS\Fonts\wsmsfax.exe moved successfully.
File/Folder E:\StormCodec6.04.08暴风影音.exe not found. (these four i have deleted before runing software)
File/Folder E:\StormCodec6.04.08暴风影音.exe not found.
File/Folder E:\StormCodec6.04.08暴风影音.exe not found.
File/Folder E:\StormCodec6.04.08暴风影音.exe not found.
OTMoveIt2 v1.0.7 log created on 01242008_142151
Winpfind
WinPFind3 logfile created on: 2008-01-25 02:50:08
WinPFind3U by OldTimer - Version 1.0.44 Folder = C:\Documents and Settings\ke\桌面\WinPFind3u\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 6.0.2900.2180)
254.98 Mb Total Physical Memory | 147.89 Mb Available Physical Memory | 58.00% Memory free
929.86 Mb Paging File | 554.76 Mb Available in Paging File | 59.66% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.65 Gb Total Space | 3.30 Gb Free Space | 22.51% Space Free
Drive D: | 19.53 Gb Total Space | 0.54 Gb Free Space | 2.77% Space Free
Drive E: | 3.08 Gb Total Space | 0.28 Gb Free Space | 9.20% Space Free
F: Drive not present or media not loaded
Computer Name: 何向宇
Current User Name: ke
Logged in as Administrator.
Current Boot Mode: Normal
[Processes - Non-Microsoft Only]
acrotray.exe -> %ProgramFiles%\Adobe\Acrobat 7.0\Distillr\acrotray.exe -> Adobe Systems Inc. [Ver = 6.0.1.2004121400 | Size = 483328 bytes | Modified Date = 2004-12-14 02:12:02 | Attr = ]
avgas.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 2007-06-11 17:25:42 | Attr = ]
ccenter.exe -> %ProgramFiles%\Rising\Rav\CCenter.exe -> Beijing Rising Technology Co., Ltd. [Ver = 18, 0, 0, 3 | Size = 110592 bytes | Modified Date = 2006-10-10 10:42:44 | Attr = ]
guard.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 2007-05-30 20:31:10 | Attr = ]
ibmpmsvc.exe -> %System32%\ibmpmsvc.exe -> [Ver = | Size = 57344 bytes | Modified Date = 2003-07-03 01:25:00 | Attr = ]
issch.exe -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe -> Macrovision Corporation [Ver = 4, 60, 100, 37068 | Size = 81920 bytes | Modified Date = 2005-08-11 15:30:30 | Attr = ]
jucheck.exe -> %ProgramFiles%\Java\jre1.5.0_09\bin\jucheck.exe -> Sun Microsystems, Inc. [Ver = 5.0.90.3 | Size = 241775 bytes | Modified Date = 2006-10-12 03:10:54 | Attr = ]
jusched.exe -> %ProgramFiles%\Java\jre1.5.0_09\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 5.0.90.3 | Size = 49263 bytes | Modified Date = 2006-10-12 03:10:54 | Attr = ]
ravmond.exe -> %ProgramFiles%\Rising\Rav\RavMonD.exe -> Beijing Rising Technology Co., Ltd. [Ver = 19, 0, 0, 41 | Size = 278528 bytes | Modified Date = 2007-01-12 11:01:02 | Attr = ]
ravservice.exe -> %ProgramFiles%\Rising\Rav\RavService.exe -> Beijing Rising Technology Co., Ltd. [Ver = 19, 0, 0, 55 | Size = 1286144 bytes | Modified Date = 2007-05-21 08:31:26 | Attr = ]
ravstub.exe -> %ProgramFiles%\Rising\Rav\RavStub.exe -> Beijing Rising Technology Co., Ltd. [Ver = 19, 0, 0, 4 | Size = 90112 bytes | Modified Date = 2007-01-12 11:01:04 | Attr = ]
ravtray.exe -> %ProgramFiles%\Rising\Rav\RavTray.exe -> Rising [Ver = 19, 0, 0, 16 | Size = 876544 bytes | Modified Date = 2007-03-20 08:31:04 | Attr = ]
superantispyware.exe -> %ProgramFiles%\SUPERAntiSpyware\SUPERAntiSpyware.exe -> SUPERAntiSpyware.com [Ver = 3, 6, 0, 1000 | Size = 1310720 bytes | Modified Date = 2007-02-27 11:39:26 | Attr = ]
tp4mon.exe -> %System32%\tp4mon.exe -> IBM Corporation [Ver = 6.03 (xpsp_sp2_rtm.040803-2158) | Size = 82432 bytes | Modified Date = 2004-08-04 00:52:38 | Attr = ]
winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.44.0 | Size = 371200 bytes | Modified Date = 2007-11-21 09:19:46 | Attr = ]
wpservice.exe -> %ProgramFiles%\CMBCHINA\WebProtect\WPService.exe -> China Merchants Bank [Ver = 1, 0, 0, 1 | Size = 232848 bytes | Modified Date = 2007-08-27 16:35:42 | Attr = ]
[Win32 Services - Non-Microsoft Only]
(Adobe LM Service) Adobe LM Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Adobe Systems Shared\Service\Adobelmsvc.exe -> Adobe Systems [Ver = 2.65.010 | Size = 69632 bytes | Modified Date = 2006-12-30 16:35:00 | Attr = ]
(AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 2007-05-30 20:31:10 | Attr = ]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 223744 bytes | Modified Date = 2004-08-08 11:33:54 | Attr = ]
(IBMPMSVC) IBM PM Service [Win32_Own | Auto | Running] -> %System32%\ibmpmsvc.exe -> [Ver = | Size = 57344 bytes | Modified Date = 2003-07-03 01:25:00 | Attr = ]
(RavService) RavService [Win32_Own | Auto | Running] -> %ProgramFiles%\Rising\Rav\RavService.exe -> Beijing Rising Technology Co., Ltd. [Ver = 19, 0, 0, 55 | Size = 1286144 bytes | Modified Date = 2007-05-21 08:31:26 | Attr = ]
(RsCCenter) Rising Process Communication Center [Win32_Own | Auto | Running] -> %ProgramFiles%\Rising\Rav\CCenter.exe -> Beijing Rising Technology Co., Ltd. [Ver = 18, 0, 0, 3 | Size = 110592 bytes | Modified Date = 2006-10-10 10:42:44 | Attr = ]
(RsRavMon) RsRavMon Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Rising\Rav\RavMonD.exe -> Beijing Rising Technology Co., Ltd. [Ver = 19, 0, 0, 41 | Size = 278528 bytes | Modified Date = 2007-01-12 11:01:02 | Attr = ]
(CMBWPS) Cmb WebProtect Support [Win32_Own | Auto | Running] -> %ProgramFiles%\CMBCHINA\WebProtect\WPService.exe -> China Merchants Bank [Ver = 1, 0, 0, 1 | Size = 232848 bytes | Modified Date = 2007-08-27 16:35:42 | Attr = ]
[Registry - Non-Microsoft Only]
< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
!AVG Anti-Spyware -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 2007-06-11 17:25:42 | Attr = ]
Acrobat Assistant 7.0 -> %ProgramFiles%\Adobe\Acrobat 7.0\Distillr\acrotray.exe -> Adobe Systems Inc. [Ver = 6.0.1.2004121400 | Size = 483328 bytes | Modified Date = 2004-12-14 02:12:02 | Attr = ]
ISUSPM Startup -> %CommonProgramFiles%\InstallShield\UpdateService\isuspm.exe -> File not found
ISUSScheduler -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe -> Macrovision Corporation [Ver = 4, 60, 100, 37068 | Size = 81920 bytes | Modified Date = 2005-08-11 15:30:30 | Attr = ]
RavTray -> %ProgramFiles%\Rising\Rav\RavTray.exe -> Rising [Ver = 19, 0, 0, 16 | Size = 876544 bytes | Modified Date = 2007-03-20 08:31:04 | Attr = ]
SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.5.0_09\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 5.0.90.3 | Size = 49263 bytes | Modified Date = 2006-10-12 03:10:54 | Attr = ]
TrackPointSrv -> %System32%\tp4mon.exe -> IBM Corporation [Ver = 6.03 (xpsp_sp2_rtm.040803-2158) | Size = 82432 bytes | Modified Date = 2004-08-04 00:52:38 | Attr = ]
< OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ ->
IMAIL -> Installed = 1 ->
MAPI -> Installed = 1 ->
MSFS -> Installed = 1 ->
< Run [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
SUPERAntiSpyware -> %ProgramFiles%\SUPERAntiSpyware\SUPERAntiSpyware.exe -> SUPERAntiSpyware.com [Ver = 3, 6, 0, 1000 | Size = 1310720 bytes | Modified Date = 2007-02-27 11:39:26 | Attr = ]
< ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
{32CD708B-60A7-4C00-9377-D73EAA495F0F} [HKLM] -> %System32%\RavExt.dll [Rising Execute File Exts hook] -> Beijing Rising Technology Co., Ltd. [Ver = 19, 0, 0, 7 | Size = 106496 bytes | Modified Date = 2007-01-12 11:01:00 | Attr = ]
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKLM] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> GRISOFT s.r.o. [Ver = 7, 5, 1, 36 | Size = 79408 bytes | Modified Date = 2007-05-30 20:29:58 | Attr = ]
{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} [HKLM] -> %ProgramFiles%\SUPERAntiSpyware\SASSEH.DLL [] -> SuperAdBlocker.com [Ver = 1, 0, 0, 1008 | Size = 77824 bytes | Modified Date = 2006-12-20 12:55:48 | Attr = ]
< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
!SASWinLogon -> %ProgramFiles%\SUPERAntiSpyware\SASWINLO.dll -> SUPERAntiSpyware.com [Ver = 1, 0, 0, 1030 | Size = 282624 bytes | Modified Date = 2007-02-27 11:39:26 | Attr = ]
ImpsSensor -> Reg Data - Value does not exist -> File not found
< CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> 67108863 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 255 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
127.0.0.1 localhost -> ->
< Internet Explorer Settings > -> ->
HKLM: Default_Page_URL ->
http://www.microsoft...p...&ar=msnhome ->
HKLM: Main\\Default_Search_URL ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: Local Page -> %SystemRoot%\system32\blank.htm ->
HKLM: Search Page ->
http://www.yahoo.com.cn ->
HKLM: Start Page ->
http://www.microsoft...p...ER}&ar=home ->
HKLM: CustomizeSearch ->
http://ie.search.msn...st/srchcust.htm ->
HKLM: SearchAssistant ->
http://ie.search.msn...st/srchasst.htm ->
HKCU: Local Page -> C:\WINDOWS\system32\blank.htm ->
HKCU: Search Page ->
http://www.microsoft...amp;ar=iesearch ->
HKCU: Start Page -> about:blank ->
HKCU: ProxyEnable -> 0 ->
< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
msn.com [ - ] -> ->
< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{53763D1D-9CA8-4C7C-9756-A8E6B8FC063B} [HKLM] -> %ProgramFiles%\CMBCHINA\WebProtect\WebProtect.dll [WebProtect] -> China Merchants Bank [Ver = 1, 0, 0, 1 | Size = 341904 bytes | Modified Date = 2007-08-20 16:15:10 | Attr = ]
< Internet Explorer Bars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->
{182EC0BE-5110-49C8-A062-BEB1D02A220B} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> Adobe Systems Incorporated [Ver = 7.0.0.0 | Size = 225280 bytes | Modified Date = 2004-12-14 02:13:40 | Attr = ]
< Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
{47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> Adobe Systems Incorporated [Ver = 7.0.0.0 | Size = 225280 bytes | Modified Date = 2004-12-14 02:13:40 | Attr = ]
< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> Adobe Systems Incorporated [Ver = 7.0.0.0 | Size = 225280 bytes | Modified Date = 2004-12-14 02:13:40 | Attr = ]
< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_09\bin\npjpi150_09.dll [MenuText: Sun Java 控制台] -> Sun Microsystems, Inc. [Ver = 5.0.90.3 | Size = 69746 bytes | Modified Date = 2006-10-12 03:25:44 | Attr = ]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKCU] -> %ProgramFiles%\Java\jre1.5.0_09\bin\ssv.dll [MenuText: Sun Java 控制台] -> Sun Microsystems, Inc. [Ver = 5.0.90.3 | Size = 434279 bytes | Modified Date = 2006-10-12 03:25:44 | Attr = ]
{6354ABE6-05F1-49ed-B850-E423120EC338} -> http:\cn.widget.yahoo.com\index.htm [ButtonText: 雅虎WIDGET] -> File not found
{77BF5300-1474-4EC7-9980-D32B190E9B07} -> Reg Data - Value does not exist [ButtonText: Skype add-on] -> File not found
{92780B25-18CC-41C8-B9BE-3C9C571A8263} -> Reg Data - Value does not exist [ButtonText: 信息检索] -> File not found
{9A687CA6-D585-4947-9ED9-BE96071F5CD9} -> Reg Data - Value does not exist [ButtonText: 词霸] -> File not found
< Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
导出到 Microsoft Office Excel(&X) -> -> File not found
转换链接目标为 Adobe PDF -> %ProgramFiles%\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll\AcroIECapture.htm -> File not found
转换链接目标为现有 PDF -> %ProgramFiles%\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll\AcroIEAppend.htm -> File not found
转换为 Adobe PDF -> %ProgramFiles%\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll\AcroIECapture.htm -> File not found
转换为现有 PDF -> %ProgramFiles%\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll\AcroIEAppend.htm -> File not found
转换选定的链接为 Adobe PDF -> %ProgramFiles%\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll\AcroIECaptureSelLinks.htm -> File not found
转换选定的链接为现有 PDF -> %ProgramFiles%\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll\AcroIEAppendSelLinks.htm -> File not found
转换选项为 Adobe PDF -> %ProgramFiles%\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll\AcroIECapture.htm -> File not found
转换选项为现有 PDF -> %ProgramFiles%\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll\AcroIEAppend.htm -> File not found
< User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform ->
SV1 -> ->
< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{56C3DBAB-E146-48C7-AF70-D062D1121807} -> (1394 网络适配器) ->
{FC2CC0B0-2629-4A3A-A7EA-DF1E225B3DAF} -> (Intel® PRO/100 VE Network Connection) ->
< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
dic -> %ProgramFiles%\Kingsoft\Powerword 2003\XDictExB.dll -> 金山软件股份有限公司 [Ver = 1, 0, 0, 0 | Size = 118784 bytes | Modified Date = 2003-06-02 10:19:42 | Attr = ]
ipp -> Reg Data - Key not found -> File not found
msdaipp -> Reg Data - Key not found -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} -> Edit Class - CodeBase =
https://site.cmbchin...oad/CMBEdit.cab ->
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -> CKAVWebScan Object - CodeBase =
http://www.kaspersky...can_unicode.cab ->
{1E0DFFCF-27FF-4574-849B-55007349FEDA} -> iTrusPTA Class - CodeBase =
https://img.alipay.c...101/aliedit.cab ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.5.0_09 - CodeBase =
http://java.sun.com/...ows-i586-jc.cab ->
{A3CD7F74-93C9-4BC4-B892-CCDF1514F714} -> Submit Class - CodeBase =
https://pbank.95559....nk/ocx/safe.cab ->
{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_09 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_09 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase =
http://download.macr...ash/swflash.cab ->
{ECCBA956-80E5-11D3-9285-0080ADB811C9} -> safeInput Class - CodeBase =
https://pbank.95559....fe_bankcomm.cab ->
[Files/Folders - Created Within 30 days]
Deckard -> %SystemDrive%\Deckard -> [Folder | Created Date = 2008-01-17 00:23:07 | Attr = ]
QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 2008-01-11 23:04:17 | Attr = ]
_OTMoveIt -> %SystemDrive%\_OTMoveIt -> [Folder | Created Date = 2008-01-17 14:51:37 | Attr = ]
erdnt -> %SystemRoot%\erdnt -> [Folder | Created Date = 2008-01-11 23:05:31 | Attr = ]
LastGood -> %SystemRoot%\LastGood -> [Folder | Created Date = 2008-01-24 21:39:39 | Attr = ]
NirCmd.exe -> %SystemRoot%\NirCmd.exe -> NirSoft [Ver = 2.00 | Size = 51200 bytes | Created Date = 2008-01-11 23:03:25 | Attr = ]
RSBDBACKUP.DLL -> %SystemRoot%\RSBDBACKUP.DLL -> [Ver = | Size = 16 bytes | Created Date = 2008-01-16 19:46:21 | Attr = ]
aliedit -> %System32%\aliedit -> [Folder | Created Date = 2008-01-24 21:39:43 | Attr = ]
Kaspersky Lab -> %System32%\Kaspersky Lab -> [Folder | Created Date = 2008-01-22 17:17:33 | Attr = ]
swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.11 | Size = 156160 bytes | Created Date = 2008-01-11 23:03:23 | Attr = ]
swsc.exe -> %System32%\swsc.exe -> SteelWerX [Ver = 2.0.0.5 | Size = 136704 bytes | Created Date = 2008-01-11 23:03:21 | Attr = ]
swxcacls.exe -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 2008-01-11 23:03:21 | Attr = ]
VFind.exe -> %System32%\VFind.exe -> [Ver = | Size = 49152 bytes | Created Date = 2008-01-11 23:03:22 | Attr = ]
AvgAsCln.sys -> %System32%\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 10872 bytes | Created Date = 2008-01-05 15:04:04 | Attr = ]
[Files/Folders - Modified Within 30 days]
Deckard -> %SystemDrive%\Deckard -> [Folder | Modified Date = 2008-01-17 00:23:08 | Attr = ]
Documents and Settings -> %SystemDrive%\Documents and Settings -> [Folder | Modified Date = 2008-01-05 17:32:26 | Attr = ]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 2008-01-24 21:55:18 | Attr = R ]
QooBox -> %SystemDrive%\QooBox -> [Folder | Modified Date = 2008-01-11 23:22:12 | Attr = ]
RAVBIN -> %SystemDrive%\RAVBIN -> [Folder | Modified Date = 2008-01-21 13:46:36 | Attr = RH ]
sqmdata00.sqm -> %SystemDrive%\sqmdata00.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-17 15:50:24 | Attr = H ]
sqmdata01.sqm -> %SystemDrive%\sqmdata01.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-17 23:01:58 | Attr = H ]
sqmdata02.sqm -> %SystemDrive%\sqmdata02.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-18 09:49:00 | Attr = H ]
sqmdata03.sqm -> %SystemDrive%\sqmdata03.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-18 14:20:20 | Attr = H ]
sqmdata04.sqm -> %SystemDrive%\sqmdata04.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-18 16:32:58 | Attr = H ]
sqmdata05.sqm -> %SystemDrive%\sqmdata05.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-19 09:13:16 | Attr = H ]
sqmdata06.sqm -> %SystemDrive%\sqmdata06.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-19 18:37:20 | Attr = H ]
sqmdata07.sqm -> %SystemDrive%\sqmdata07.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-19 23:50:30 | Attr = H ]
sqmdata08.sqm -> %SystemDrive%\sqmdata08.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-20 03:16:32 | Attr = H ]
sqmdata09.sqm -> %SystemDrive%\sqmdata09.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-20 12:20:42 | Attr = H ]
sqmdata10.sqm -> %SystemDrive%\sqmdata10.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-21 13:36:08 | Attr = H ]
sqmdata11.sqm -> %SystemDrive%\sqmdata11.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-22 16:17:52 | Attr = H ]
sqmdata12.sqm -> %SystemDrive%\sqmdata12.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-23 11:22:50 | Attr = H ]
sqmdata13.sqm -> %SystemDrive%\sqmdata13.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-05 14:32:50 | Attr = H ]
sqmdata14.sqm -> %SystemDrive%\sqmdata14.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-13 21:06:16 | Attr = H ]
sqmdata15.sqm -> %SystemDrive%\sqmdata15.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-14 11:34:56 | Attr = H ]
sqmdata16.sqm -> %SystemDrive%\sqmdata16.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-15 10:53:46 | Attr = H ]
sqmdata17.sqm -> %SystemDrive%\sqmdata17.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-16 18:24:04 | Attr = H ]
sqmdata18.sqm -> %SystemDrive%\sqmdata18.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-16 19:49:32 | Attr = H ]
sqmdata19.sqm -> %SystemDrive%\sqmdata19.sqm -> [Ver = | Size = 268 bytes | Modified Date = 2008-01-17 11:24:26 | Attr = H ]
sqmnoopt00.sqm -> %SystemDrive%\sqmnoopt00.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-17 11:24:26 | Attr = H ]
sqmnoopt01.sqm -> %SystemDrive%\sqmnoopt01.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-17 15:50:24 | Attr = H ]
sqmnoopt02.sqm -> %SystemDrive%\sqmnoopt02.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-17 23:01:58 | Attr = H ]
sqmnoopt03.sqm -> %SystemDrive%\sqmnoopt03.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-18 09:48:58 | Attr = H ]
sqmnoopt04.sqm -> %SystemDrive%\sqmnoopt04.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-18 14:20:20 | Attr = H ]
sqmnoopt05.sqm -> %SystemDrive%\sqmnoopt05.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-18 16:32:58 | Attr = H ]
sqmnoopt06.sqm -> %SystemDrive%\sqmnoopt06.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-19 09:13:16 | Attr = H ]
sqmnoopt07.sqm -> %SystemDrive%\sqmnoopt07.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-19 18:37:20 | Attr = H ]
sqmnoopt08.sqm -> %SystemDrive%\sqmnoopt08.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-19 23:50:30 | Attr = H ]
sqmnoopt09.sqm -> %SystemDrive%\sqmnoopt09.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-20 03:16:32 | Attr = H ]
sqmnoopt10.sqm -> %SystemDrive%\sqmnoopt10.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-20 12:20:42 | Attr = H ]
sqmnoopt11.sqm -> %SystemDrive%\sqmnoopt11.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-21 13:36:08 | Attr = H ]
sqmnoopt12.sqm -> %SystemDrive%\sqmnoopt12.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-22 16:17:52 | Attr = H ]
sqmnoopt13.sqm -> %SystemDrive%\sqmnoopt13.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-23 11:22:50 | Attr = H ]
sqmnoopt14.sqm -> %SystemDrive%\sqmnoopt14.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-05 14:32:48 | Attr = H ]
sqmnoopt15.sqm -> %SystemDrive%\sqmnoopt15.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-13 21:06:16 | Attr = H ]
sqmnoopt16.sqm -> %SystemDrive%\sqmnoopt16.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-14 11:34:56 | Attr = H ]
sqmnoopt17.sqm -> %SystemDrive%\sqmnoopt17.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-15 10:53:46 | Attr = H ]
sqmnoopt18.sqm -> %SystemDrive%\sqmnoopt18.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-16 18:24:04 | Attr = H ]
sqmnoopt19.sqm -> %SystemDrive%\sqmnoopt19.sqm -> [Ver = | Size = 244 bytes | Modified Date = 2008-01-16 19:49:32 | Attr = H ]
WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 2008-01-24 21:39:40 | Attr = ]
_OTMoveIt -> %SystemDrive%\_OTMoveIt -> [Folder | Modified Date = 2008-01-17 14:51:38 | Attr = ]
新建文件夹 -> %SystemDrive%\新建文件夹 -> [Folder | Modified Date = 2008-01-06 02:54:22 | Attr = ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 2008-01-24 11:07:28 | Attr = S]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 2008-01-24 21:44:50 | Attr = S]
erdnt -> %SystemRoot%\erdnt -> [Folder | Modified Date = 2008-01-17 00:24:12 | Attr = ]
Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 2008-01-24 14:22:16 | Attr = R S]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 2008-01-22 17:17:34 | Attr = H ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 2008-01-05 17:48:20 | Attr = HS]
LastGood -> %SystemRoot%\LastGood -> [Folder | Modified Date = 2008-01-24 21:44:48 | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 2008-01-24 21:55:28 | Attr = ]
RavTray.INI -> %SystemRoot%\RavTray.INI -> [Ver = | Size = 40 bytes | Modified Date = 2008-01-24 03:39:36 | Attr = ]
RSBDBACKUP.DLL -> %SystemRoot%\RSBDBACKUP.DLL -> [Ver = | Size = 16 bytes | Modified Date = 2008-01-24 03:39:34 | Attr = ]
system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 227 bytes | Modified Date = 2008-01-11 23:38:52 | Attr = ]
system32 -> %System32% -> [Folder | Modified Date = 2008-01-24 21:44:42 | Attr = ]
Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 2008-01-11 23:23:02 | Attr = S]
Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 2008-01-24 21:44:48 | Attr = ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 2008-01-24 11:08:04 | Attr = H ]
aliedit -> %System32%\aliedit -> [Folder | Modified Date = 2008-01-24 21:39:46 | Attr = ]
CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 2008-01-24 21:39:42 | Attr = ]
config -> %System32%\config -> [Folder | Modified Date = 2008-01-11 23:31:34 | Attr = ]
drivers -> %System32%\drivers -> [Folder | Modified Date = 2008-01-19 23:57:10 | Attr = ]
Kaspersky Lab -> %System32%\Kaspersky Lab -> [Folder | Modified Date = 2008-01-22 17:17:34 | Attr = ]
wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 2206 bytes | Modified Date = 2008-01-22 16:13:44 | Attr = ]
etc -> %System32%\drivers\etc -> [Folder | Modified Date = 2008-01-11 23:38:34 | Attr = ]
[File String Scan - Non-Microsoft Only]
UPX0 , -> %System32%\bseng.dll -> Beijing Rising Technology Co., Ltd. [Ver = 19, 0, 0, 13 | Size = 118784 bytes | Modified Date = 2007-01-12 11:02:42 | Attr = ]
PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41131 bytes | Modified Date = 2004-08-08 11:33:54 | Attr = ]
UPX0 , -> %System32%\rsbseng.dll -> Beijing Rising Technology Co., Ltd. [Ver = 19, 0, 0, 25 | Size = 120320 bytes | Modified Date = 2007-04-23 10:01:40 | Attr = ]
UPX! , UPX0 , -> %System32%\safeInput.dll -> Beijing eChannels Century Technology Co.,Ltd [Ver = 2, 3, 1, 0 | Size = 69120 bytes | Modified Date = 2006-09-25 16:32:54 | Attr = ]
UPX! , UPX0 , -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.11 | Size = 156160 bytes | Modified Date = 2000-08-31 08:00:00 | Attr = ]
UPX! , UPX0 , -> %System32%\swsc.exe -> SteelWerX [Ver = 2.0.0.5 | Size = 136704 bytes | Modified Date = 2000-08-31 08:00:00 | Attr = ]
winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 2004-08-08 11:33:54 | Attr = ]
WSUD , UPX0 , -> %System32%\dllcache\hwxjpn.dll -> [Ver = | Size = 13463552 bytes | Modified Date = 2004-08-08 11:33:54 | Attr = ]
< End of report >