========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.microsoft...amp;ar=iesearchIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn...st/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.microsoft...p...&ar=msnhomeIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_Url =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://kankan.xunlei.com/?id=55IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "
http://www.google.com.sg/"FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.28
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - prefs.js..extensions.enabledItems:
[email protected]:3.0.1
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009-03-15 13:47:35 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009-03-15 13:47:35 | 00,000,000 | ---D | M]
[2009-03-13 23:45:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2009-03-13 23:45:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2005-07-22 17:31:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\folr671t.Default User\extensions
[2005-05-23 02:35:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\folr671t.Default User\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2005-07-22 17:30:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\folr671t.Default User\extensions\{e8cba685-830c-1283-6314-a6ae605cc9be}
[2009-03-16 23:26:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\kcg5kv71.default\extensions
[2007-10-20 05:55:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\kcg5kv71.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2009-02-14 03:36:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\kcg5kv71.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2009-02-14 03:36:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\kcg5kv71.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009-03-14 00:04:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\kcg5kv71.default\extensions\
[email protected][2006-01-31 12:26:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\kcg5kv71.default\extensions\temp
[2007-05-08 21:39:30 | 00,001,088 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\kcg5kv71.default\searchplugins\thottbotplugin.xml
[2009-03-16 23:26:20 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009-03-15 13:47:35 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007-09-20 22:46:11 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2008-01-15 01:13:39 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2009-03-15 13:47:16 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-03-15 13:47:16 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008-07-01 17:40:22 | 00,036,864 | ---- | M] (????) -- C:\Program Files\mozilla firefox\components\NsThunderLoader.dll
[2009-03-15 13:47:29 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009-03-15 13:47:29 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009-03-15 13:47:29 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009-03-15 13:47:29 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009-03-15 13:47:29 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009-03-15 13:47:29 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009-03-15 13:47:29 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (WebThunder Browser Helper) - {00000AAA-A363-466E-BEF5-9BB68697AA7F} - C:\Program Files\Mp3 To All Converter\WebThunderBHO_Now.dll (Thunder Networking Technologies,LTD)
O2 - BHO: (ThunderAtOnce Class) - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - C:\Program Files\Mp3 To All Converter\ThunderLoader\ComDlls\TDAtOnce_Now.dll (Thunder Networking Technologies,LTD)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll (BitComet)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Thunder Browser Helper) - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Mp3 To All Converter\ThunderLoader\ComDlls\xunleiBHO_Now.dll (Thunder Networking Technologies,LTD)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1629.0\zh-sg\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AlcxMonitor] ALCXMNTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min (Avira GmbH)
O4 - HKLM..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe File not found
O4 - HKLM..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [KBD] C:\HP\KBD\KBD.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC ()
O4 - HKLM..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe (Openwares)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC (Microsoft Corporation)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE ()
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe (Symantec Corporation)
O4 - HKLM..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r (Sonic Solutions)
O4 - HKCU..\Run: [Acme.PCHButton] C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\pchbutton.exe (Motive Communications, Inc.)
O4 - HKCU..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe File not found
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Google Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1 (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Imation_Flash_Detect.lnk = C:\Documents and Settings\Owner\Local Settings\Temp\Imation\USB_ImationFlashDetect.exe ()
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: ʹÓÃѸÀ×ÏÂÔØ - C:\Program Files\Mp3 To All Converter\ThunderLoader\Program\GetUrl.htm
O8 - Extra context menu item: ʹÓÃѸÀ×ÏÂÔØÈ«²¿Á´½Ó - C:\Program Files\Mp3 To All Converter\ThunderLoader\Program\GetAllUrl.htm
O8 - Extra context menu item: ʹÓÃWEBѸÀ×ÏÂÔØ - C:\Program Files\Mp3 To All Converter\GetUrl.htm
O8 - Extra context menu item: ʹÓÃWEBѸÀ×ÏÂÔØÈ«²¿Á´½Ó - C:\Program Files\Mp3 To All Converter\GetAllUrl.htm
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Æô¶¯Ñ¸À×5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Mp3 To All Converter\ThunderLoader\Thunder.exe (Thunder Networking Technologies,LTD)
O9 - Extra 'Tools' menuitem : Æô¶¯Ñ¸À×5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Mp3 To All Converter\ThunderLoader\Thunder.exe (Thunder Networking Technologies,LTD)
O9 - Extra Button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\Icq.exe (ICQ Inc.)
O9 - Extra 'Tools' menuitem : ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\Icq.exe (ICQ Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Æô¶¯WEBѸÀ× - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - File not found
O9 - Extra 'Tools' menuitem : Æô¶¯WEBѸÀ× - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - File not found
O9 - Extra Button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll (Picasa, Inc.)
O9 - Extra 'Tools' menuitem : Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll (Picasa, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [NTDS] - C:\WINDOWS\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71}
http://codecs.micros...cs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC}
http://messenger.zon...nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {260399DF-4C19-4143-8D78-6383EF95753A}
http://sg.samsungmob...to/album_en.cab (Reg Error: Key error.)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B}
http://messenger.zon...er.cab31267.cab (Minesweeper Flags Class)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0}
http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E}
https://www.e-games....GamesPlugin.cab (EGamesPlugin Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://gfx1.hotmail....es/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24}
http://messenger.zon...1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE}
http://a1540.g.akama...meInstaller.exe (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
http://messenger.zon...StatsClient.cab (MessengerStatsClient Class)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592}
http://messenger.zon...ro.cab47946.cab (ZoneIntro Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_07)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679}
http://drmlicense.on...e/en/crlocx.ocx (CRLDownloadWrapper Class)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
http://www.popcap.co...ploader_v10.cab (PopCapLoader Object)
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF}
http://messenger.zon...wn.cab31267.cab (Solitaire Showdown Class)
O16 - DPF: ppctlcab
http://www.pestscan....er/ppctlcab.cab (Reg Error: Key error.)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\MCPClient: DllName - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll - C:\Program Files\Common Files\Stardock\MCPStub.dll (Stardock)
O20 - Winlogon\Notify\pcc: DllName - C:\DOCUME~1\Owner\LOCALS~1\Temp\ccp.dat - C:\DOCUME~1\Owner\LOCALS~1\Temp\ccp.dat File not found
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\WlNotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wmsav: DllName - C:\DOCUME~1\Owner\LOCALS~1\Temp\vasmw.dat - C:\DOCUME~1\Owner\LOCALS~1\Temp\vasmw.dat File not found
O21 - SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - C:\Program Files\Common Files\Stardock\MCPCore.dll (Stardock)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\System32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\System32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - E:\AUTOEXEC.BAT () - [ FAT32 ]
O32 - Autorun File - E:\autorun.inf () - [ FAT32 ]
O32 - Autorun File - G:\Autorun.inf () - [ CDFS ]
O33 - MountPoints2\{06af0ecc-6e48-11da-80d9-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{06af0ed0-6e48-11da-80d9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{06af0ed0-6e48-11da-80d9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{06af0ed0-6e48-11da-80d9-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{11c27fc9-63d1-11da-8104-000c769fa02c}\Shell - "" = AutoRun
O33 - MountPoints2\{11c27fc9-63d1-11da-8104-000c769fa02c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{11c27fc9-63d1-11da-8104-000c769fa02c}\Shell\AutoRun\command - "" = F:\autorun.exe -- File not found
O33 - MountPoints2\{16bed098-7f93-11da-b899-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{16bed09c-7f93-11da-b899-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{16bed09c-7f93-11da-b899-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{16bed09c-7f93-11da-b899-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{1bb9e698-7aa0-11da-834e-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{1bb9e69c-7aa0-11da-834e-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{1bb9e69c-7aa0-11da-834e-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1bb9e69c-7aa0-11da-834e-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{291016f2-704e-11da-9f46-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{291016f6-704e-11da-9f46-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{291016f6-704e-11da-9f46-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{291016f6-704e-11da-9f46-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{2bf7b898-85ac-11da-84e1-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{2bf7b89c-85ac-11da-84e1-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{2bf7b89c-85ac-11da-84e1-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2bf7b89c-85ac-11da-84e1-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{2e269b3e-63d8-11da-b7aa-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{3a6122a6-925f-11da-b3dc-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{3a6122aa-925f-11da-b3dc-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{3a6122aa-925f-11da-b3dc-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{3a6122aa-925f-11da-b3dc-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{4a4994c4-0610-11dd-8876-000c769fa02c}\Shell\AutoRun\command - "" = H:\sq.com -- File not found
O33 - MountPoints2\{4a4994c4-0610-11dd-8876-000c769fa02c}\Shell\explore\Command - "" = H:\sq.com -- File not found
O33 - MountPoints2\{4a4994c4-0610-11dd-8876-000c769fa02c}\Shell\open\Command - "" = H:\sq.com -- File not found
O33 - MountPoints2\{4b62054c-689e-11da-9de8-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{4b620550-689e-11da-9de8-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{4b620550-689e-11da-9de8-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4b620550-689e-11da-9de8-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{4ffa234c-80c1-11da-98af-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{4ffa2350-80c1-11da-98af-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{4ffa2350-80c1-11da-98af-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4ffa2350-80c1-11da-98af-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{59f17ff2-67f4-11da-b191-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{59f17ff6-67f4-11da-b191-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{59f17ff6-67f4-11da-b191-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{59f17ff6-67f4-11da-b191-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{5f74be26-755a-11da-88d6-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{5f74be2a-755a-11da-88d6-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{5f74be2a-755a-11da-88d6-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5f74be2a-755a-11da-88d6-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{5fe9424c-5f32-11db-8686-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{6560d1cc-7b44-11da-9112-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{6560d1d0-7b44-11da-9112-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{6560d1d0-7b44-11da-9112-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6560d1d0-7b44-11da-9112-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{660b744c-2f2b-11db-9c50-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{660b7450-2f2b-11db-9c50-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{660b7450-2f2b-11db-9c50-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{660b7450-2f2b-11db-9c50-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{687c0312-4811-11d8-bad0-806d6172696f}\Shell\AutoRun\command - "" = D:\Info.exe -- File not found
O33 - MountPoints2\{69323c18-647f-11da-87d7-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{69323c1c-647f-11da-87d7-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{69323c1c-647f-11da-87d7-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{69323c1c-647f-11da-87d7-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{6e0214e4-6406-11da-9d0e-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{6e0214ec-6406-11da-9d0e-000c769fa02c}\Shell - "" = AutoRun
O33 - MountPoints2\{6e0214ec-6406-11da-9d0e-000c769fa02c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6e0214ec-6406-11da-9d0e-000c769fa02c}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{7154334c-6cfe-11da-ba82-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{71543350-6cfe-11da-ba82-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{71543350-6cfe-11da-ba82-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{71543350-6cfe-11da-ba82-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{7385cba6-7f1b-11da-ba78-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{7385cbaa-7f1b-11da-ba78-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{7385cbaa-7f1b-11da-ba78-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7385cbaa-7f1b-11da-ba78-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{78f3fbcc-7817-11da-a2ed-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{78f3fbd0-7817-11da-a2ed-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{78f3fbd0-7817-11da-a2ed-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{78f3fbd0-7817-11da-a2ed-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{8741f74c-8bcc-11da-abca-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{8741f750-8bcc-11da-abca-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{8741f750-8bcc-11da-abca-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{8741f750-8bcc-11da-abca-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{96a54b18-6993-11da-a40c-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{96a54b1c-6993-11da-a40c-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{96a54b1c-6993-11da-a40c-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{96a54b1c-6993-11da-a40c-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{9cf36372-6a3f-11da-a4d0-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{9cf36376-6a3f-11da-a4d0-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{9cf36376-6a3f-11da-a4d0-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9cf36376-6a3f-11da-a4d0-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{a4434126-6bb9-11da-8a53-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{a443412a-6bb9-11da-8a53-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{a443412a-6bb9-11da-8a53-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a443412a-6bb9-11da-8a53-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{ab46cfa6-6579-11da-a822-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{ab46cfaa-6579-11da-a822-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{ab46cfaa-6579-11da-a822-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ab46cfaa-6579-11da-a822-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{b3e726f2-907a-11da-b99f-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{b3e726f6-907a-11da-b99f-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{b3e726f6-907a-11da-b99f-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b3e726f6-907a-11da-b99f-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{ba3d4698-6fce-11da-9b11-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{ba3d469c-6fce-11da-9b11-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{ba3d469c-6fce-11da-9b11-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ba3d469c-6fce-11da-9b11-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{bc52ec26-6466-11da-b51e-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{bc52ec2a-6466-11da-b51e-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{bc52ec2a-6466-11da-b51e-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{bc52ec2a-6466-11da-b51e-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{befdbcf2-7e16-11da-9914-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{befdbcf6-7e16-11da-9914-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{befdbcf6-7e16-11da-9914-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{befdbcf6-7e16-11da-9914-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{cfcba4f2-640a-11da-afc6-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{d421eb98-8a9c-11da-ab54-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{d421eb9c-8a9c-11da-ab54-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{d421eb9c-8a9c-11da-ab54-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d421eb9c-8a9c-11da-ab54-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{d67ac9a2-6d67-11da-a77a-806d6172696f}\Shell\AutoRun\command - "" = D:\Info.exe -- File not found
O33 - MountPoints2\{d67ac9a5-6d67-11da-a77a-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{d67ac9a5-6d67-11da-a77a-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d67ac9a5-6d67-11da-a77a-806d6172696f}\Shell\AutoRun\command - "" = F:\autorun.exe -- File not found
O33 - MountPoints2\{d6b1e54c-6aae-11da-a864-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{d6b1e550-6aae-11da-a864-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{d6b1e550-6aae-11da-a864-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d6b1e550-6aae-11da-a864-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{daf049f2-7cc2-11da-b3b3-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{daf049f6-7cc2-11da-b3b3-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{daf049f6-7cc2-11da-b3b3-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{daf049f6-7cc2-11da-b3b3-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{dca2e150-0980-11db-9f37-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{dca2e150-0980-11db-9f37-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{dca2e150-0980-11db-9f37-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{e2e2c9cc-831c-11da-a333-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{e2e2c9d0-831c-11da-a333-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{e2e2c9d0-831c-11da-a333-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e2e2c9d0-831c-11da-a333-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{fc95bda6-7c10-11da-b64e-806d6172696f}\Shell\AutoRun\command - "" = E:\Info.exe -- [2002-09-10 06:54:58 | 00,040,960 | -HS- | M] (XSS)
O33 - MountPoints2\{fc95bdaa-7c10-11da-b64e-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{fc95bdaa-7c10-11da-b64e-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{fc95bdaa-7c10-11da-b64e-806d6172696f}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found