Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Delft.Tracer, and Spyware


  • Please log in to reply

#1
Kipling09

Kipling09

    New Member

  • Member
  • Pip
  • 1 posts
First of all THANK YOU in advance for any assistance you can give me with the following problems;

I use malwarebytes, spywareblaster and spyware defender to protect my pc, I also use Avast as the antivirus program.

These all detect the following as a problem:
\Documents and Settings\haier\Application Data\Microsoft\Internet Explorer\Quick Launch\启动 Internet Explorer 浏览器.lnk (Hijack.Trace) -> Quarantined and deleted successful
However on reboot they reappear again and are really annoying.
I have done a scan with OTL and Hiackthis but await advice before before taking any action: Here are the Logs
Malwarebytes

Malwarebytes' Anti-Malware 1.41
Database version: 3179
Windows 5.1.2600 Service Pack 3

11/28/2009 9:26:48 AM
mbam-log-2009-11-28 (09-26-48).txt

Scan type: Quick Scan
Objects scanned: 96304
Time elapsed: 4 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\haier\Application Data\Microsoft\Internet Explorer\Quick Launch\启动 Internet Explorer 浏览器.lnk (Hijack.Trace) -> Quarantined and deleted successful

OTL

OTL logfile created on: 11/28/2009 11:42:51 AM - Run 1
OTL by OldTimer - Version 3.1.11.0 Folder = C:\Documents and Settings\haier\Desktop\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

893.10 Mb Total Physical Memory | 352.48 Mb Available Physical Memory | 39.47% Memory free
2.12 Gb Paging File | 1.52 Gb Available in Paging File | 71.77% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.63 Gb Total Space | 8.76 Gb Free Space | 47.03% Space Free | Partition Type: NTFS
Drive D: | 27.93 Gb Total Space | 27.92 Gb Free Space | 99.97% Space Free | Partition Type: FAT32
Drive E: | 27.93 Gb Total Space | 27.93 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive F: | 37.26 Gb Total Space | 37.26 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HAIER-C66E9EDD0
Current User Name: haier
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2009/11/28 11:16:24 | 00,532,992 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\haier\Desktop\Downloads\OTL.exe
PRC - [2009/11/28 07:50:37 | 03,055,616 | ---- | M] (Crawler.com) -- C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
PRC - [2009/11/28 07:50:37 | 02,166,784 | ---- | M] (Crawler.com) -- C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
PRC - [2009/11/28 07:50:37 | 00,488,960 | ---- | M] (Crawler.com) -- C:\Program Files\Spyware Terminator\sp_rsser.exe
PRC - [2009/11/20 19:01:18 | 00,832,296 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2009/11/13 16:52:23 | 00,323,392 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\DNA\btdna.exe
PRC - [2009/09/10 14:53:56 | 01,312,080 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2009/08/18 00:07:23 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/08/18 00:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/08/18 00:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/08/18 00:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009/08/17 23:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/07/25 05:23:12 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/07/25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/05/27 10:41:16 | 24,264,488 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files\Skype\Phone\Skype.exe
PRC - [2008/12/21 10:41:12 | 00,180,269 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2008/04/14 08:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/09/13 07:14:42 | 01,527,808 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
PRC - [2007/08/21 07:38:02 | 16,384,512 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.exe
PRC - [2007/06/26 08:45:42 | 00,262,144 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\sistray.exe
PRC - [2006/04/22 09:03:34 | 00,094,208 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe


========== Modules (SafeList) ==========

MOD - [2009/11/28 11:16:24 | 00,532,992 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\haier\Desktop\Downloads\OTL.exe
MOD - [2009/09/23 15:35:46 | 01,451,448 | ---- | M] (CallingID Ltd.) -- C:\Program Files\CallingID\LinkAdvisor\CIDLinkAdvisor.dll
MOD - [2008/04/14 08:12:01 | 00,413,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcp60.dll
MOD - [2008/04/14 08:11:56 | 00,019,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\linkinfo.dll


========== Win32 Services (SafeList) ==========

SRV - [2009/11/28 07:50:37 | 00,488,960 | ---- | M] (Crawler.com) -- C:\Program Files\Spyware Terminator\sp_rsser.exe -- (sp_rssrv)
SRV - [2009/08/18 00:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV - [2009/08/18 00:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2009/08/18 00:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2009/08/17 23:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
SRV - [2009/07/25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2008/04/14 08:12:02 | 00,065,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\nwwks.dll -- (NWCWorkstation)
SRV - [2006/10/19 12:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc)
SRV - [2003/07/29 04:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)


========== Driver Services (SafeList) ==========

DRV - [2009/11/28 07:50:37 | 00,142,592 | ---- | M] () -- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys -- (sp_rsdrv2)
DRV - [2009/08/18 00:06:43 | 00,094,160 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2009/08/18 00:05:52 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswSP.sys -- (aswSP)
DRV - [2009/08/18 00:05:37 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009/08/18 00:04:40 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2009/08/18 00:04:29 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2009/08/18 00:03:21 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009/01/18 09:04:09 | 00,021,035 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\system32\drivers\AegisP.sys -- (AegisP) AEGIS Protocol (IEEE 802.1x)
DRV - [2008/04/14 02:56:06 | 00,088,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/04/14 02:34:12 | 00,163,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\nwrdr.sys -- (NWRDR)
DRV - [2008/04/14 00:39:15 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)
DRV - [2008/04/14 00:36:05 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/09/19 07:08:22 | 00,044,032 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RTSTOR.sys -- (RTSTOR)
DRV - [2007/08/29 08:55:10 | 04,609,024 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/06/25 17:10:28 | 00,018,432 | R--- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\drivers\srvkp.sys -- (SiSkp)
DRV - [2007/06/25 16:49:08 | 00,321,536 | R--- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315)
DRV - [2007/04/24 06:11:54 | 00,224,896 | ---- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\system32\drivers\wg111v3.sys -- (RTL8187B)
DRV - [2006/12/20 12:00:00 | 00,041,600 | R--- | M] (Silicon Integrated Systems Corp.) -- C:\WINDOWS\system32\drivers\SiSGbeXP.sys -- (SiSGbeXP)
DRV - [2004/08/04 20:00:00 | 00,063,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2004/08/04 20:00:00 | 00,055,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2004/08/04 20:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)
DRV - [2004/08/04 20:00:00 | 00,012,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\fsvga.sys -- (FsVga)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.c...aspx?TbId=60347
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.c...spx?tb_id=60347

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://1111118.com/#2
IE - HKCU\..\URLSearchHook: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.update: false


FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/06/24 22:15:22 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{8b02914c-4e6b-4410-90e1-1a2b1b69b12d}: C:\Program Files\CallingID\LinkAdvisor\Firefox [2009/11/09 23:13:44 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{e9259cba-e7ad-4f74-863f-ef9fe935394d}: C:\Program Files\CallingID\Toolbar\Firefox [2009/11/09 23:20:17 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{8b02914c-4e6b-4410-90e1-1a2b1b69b12d}: C:\Program Files\CallingID\LinkAdvisor\Firefox [2009/11/09 23:13:44 | 00,000,000 | ---D | M]

[2009/01/18 12:45:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\haier\Application Data\Mozilla\Extensions
[2009/11/25 23:46:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\haier\Application Data\Mozilla\Firefox\Profiles\fbyrhmgk.default\extensions
[2009/11/11 22:22:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\haier\Application Data\Mozilla\Firefox\Profiles\fbyrhmgk.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2009/07/22 19:41:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\haier\Application Data\Mozilla\Firefox\Profiles\fbyrhmgk.default\extensions\{398e77b8-2304-11dc-8314-0800200c9a66}
[2009/11/20 18:06:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\haier\Application Data\Mozilla\Firefox\Profiles\fbyrhmgk.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/10/10 11:43:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\haier\Application Data\Mozilla\Firefox\Profiles\fbyrhmgk.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/09/28 18:55:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\haier\Application Data\Mozilla\Firefox\Profiles\fbyrhmgk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/11/20 18:06:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\haier\Application Data\Mozilla\Firefox\Profiles\fbyrhmgk.default\extensions\{e0c7b854-d5ce-4db6-9804-be1438603d89}
[2009/01/18 13:56:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\haier\Application Data\Mozilla\Firefox\Profiles\fbyrhmgk.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/09/28 18:55:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\haier\Application Data\Mozilla\Firefox\Profiles\fbyrhmgk.default\extensions\[email protected]
[2009/10/28 17:28:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\haier\Application Data\Mozilla\Firefox\Profiles\fbyrhmgk.default\extensions\[email protected]
[2009/11/26 21:17:50 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: () - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: () - {31AF61D1-BDF8-4FB1-B19A-590A6EFDF882} - C:\Program Files\Tencent\QQ\ip32help.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (CallingID BHO) - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CallingID\Toolbar\CallingIDIE.dll (CallingID Ltd.)
O2 - BHO: () - {FFFE61D1-BDF8-4FB1-B19A-590A6EFDF882} - C:\Program Files\Tencent\QQ2009\vcf.dll ()
O3 - HKLM\..\Toolbar: (CallingID) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CallingID\Toolbar\CallingIDIE.dll (CallingID Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (&Crawler Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (CallingID) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CallingID\Toolbar\CallingIDIE.dll (CallingID Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (&Crawler Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (CallingID LinkAdvisor) - {F67BEA7B-70D4-4417-9227-480B35DDD500} - C:\Program Files\CallingID\LinkAdvisor\CIDLinkAdvisor.dll (CallingID Ltd.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SiSPower] C:\WINDOWS\System32\SiSPower.dll (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SpywareTerminator] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - HKCU..\Run: [SpywareTerminatorUpdate] C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe (Crawler.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe (Silicon Integrated Systems Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: 25 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\callingid {086D03BA-57AC-4C8E-A33D-0BAABF742411} - C:\Program Files\CallingID\Toolbar\CallingIDToolbar.dll (CallingID Ltd.)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\tbr {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - WgaLogon.dll ()
O28 - HKLM ShellExecuteHooks: {1869181A-9F50-4FCF-8BFF-1B8588ECB85C} - C:\Program Files\CallingID\LinkAdvisor\CIDLinkAdvisor.dll (CallingID Ltd.)
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/21 10:06:03 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/11/16 23:49:33 | 00,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009/11/16 23:49:34 | 00,000,000 | RHSD | M] - D:\autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2009/11/16 23:49:34 | 00,000,000 | RHSD | M] - E:\autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2009/11/16 23:49:34 | 00,000,000 | RHSD | M] - F:\autorun.inf -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/11/28 11:01:17 | 00,000,000 | ---D | C] -- C:\Program Files\baidu
[2009/11/28 10:56:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\haier\Desktop\Documents etc
[2009/11/28 10:38:54 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/11/28 07:50:40 | 00,000,000 | ---D | C] -- C:\Program Files\Crawler
[2009/11/28 07:50:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\haier\Application Data\Spyware Terminator
[2009/11/28 07:50:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
[2009/11/28 07:50:29 | 00,000,000 | ---D | C] -- C:\Program Files\Spyware Terminator
[2009/11/26 21:19:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\haier\Application Data\MSNInstaller
[2009/11/26 19:27:10 | 00,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2009/11/26 19:05:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\haier\Local Settings\Application Data\Threat Expert
[2009/11/25 22:57:39 | 00,000,000 | ---D | C] -- C:\!KillBox
[2009/11/22 23:01:15 | 00,000,000 | ---D | C] -- C:\Program Files\wangwang
[2009/11/20 22:46:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\haier\Local Settings\Application Data\Opera
[2009/11/20 22:46:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\haier\Application Data\Opera
[2009/11/20 22:46:04 | 00,000,000 | ---D | C] -- C:\Program Files\Opera
[2009/11/18 21:52:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\haier\Desktop\Logfiles
[2009/11/17 00:24:22 | 00,472,064 | ---- | C] ( ) -- C:\Documents and Settings\haier\Desktop\RootRepeal.exe
[2009/11/16 23:49:33 | 00,000,000 | RHSD | C] -- C:\autorun.inf
[2009/11/15 17:25:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\haier\Local Settings\Application Data\Conduit
[2009/11/15 17:25:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\haier\Local Settings\Application Data\PHPNukeEN
[2009/11/15 17:25:46 | 00,000,000 | ---D | C] -- C:\Program Files\Conduit
[2009/11/15 17:25:41 | 00,000,000 | ---D | C] -- C:\Program Files\PHPNukeEN
[2009/11/15 17:23:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\haier\Application Data\Malwarebytes
[2009/11/15 17:23:19 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/11/15 17:23:18 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/11/15 17:23:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/11/15 17:23:17 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/11/11 20:56:36 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/11/11 20:56:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/11/10 22:44:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/11/10 22:44:28 | 00,000,000 | ---D | C] -- C:\Program Files\SpywareBlaster
[2009/11/10 22:23:16 | 03,012,768 | ---- | C] (Javacool Software LLC ) -- C:\Documents and Settings\haier\My Documents\spywareblastersetup42.exe
[2009/11/10 20:52:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\haier\Desktop\ICT
[2009/11/09 23:13:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\haier\Application Data\CallingID
[2009/11/09 23:13:44 | 00,000,000 | ---D | C] -- C:\Program Files\CallingID
[2009/11/09 23:12:42 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2009/11/09 22:47:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Google
[2009/11/05 22:26:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\haier\My Documents\New Folder

========== Files - Modified Within 30 Days ==========

[2049/12/31 16:00:00 | 00,115,835 | ---- | M] () -- C:\Documents and Settings\haier\Desktop\FromCamCorder25112008 288.jpg
[2049/12/31 16:00:00 | 00,069,056 | ---- | M] () -- C:\Documents and Settings\haier\Desktop\FromCamCorder112008 047.jpg
[2009/11/28 11:38:00 | 00,000,797 | R--- | M] () -- C:\Documents and Settings\haier\Desktop\Internet Explorer.lnk
[2009/11/28 11:38:00 | 00,000,260 | ---- | M] () -- C:\WINDOWS\tasks\qqupdate2.job
[2009/11/28 11:35:01 | 00,000,336 | ---- | M] () -- C:\WINDOWS\tasks\bfupdate.job
[2009/11/28 11:18:58 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/11/28 11:18:53 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/11/28 11:18:06 | 05,505,024 | -H-- | M] () -- C:\Documents and Settings\haier\NTUSER.DAT
[2009/11/28 11:18:06 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\haier\ntuser.ini
[2009/11/28 11:11:58 | 00,001,273 | ---- | M] () -- C:\Documents and Settings\haier\Desktop\Shortcut to TFC.exe.lnk
[2009/11/28 10:38:54 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\haier\Desktop\HijackThis.lnk
[2009/11/28 09:00:32 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2009/11/28 07:56:58 | 00,000,797 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Spyware Terminator.lnk
[2009/11/28 07:50:37 | 00,142,592 | ---- | M] () -- C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2009/11/27 20:10:16 | 05,012,162 | -H-- | M] () -- C:\Documents and Settings\haier\Local Settings\Application Data\IconCache.db
[2009/11/27 00:40:58 | 00,000,099 | ---- | M] () -- C:\Documents and Settings\haier\default.pls
[2009/11/27 00:40:54 | 00,000,230 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/11/26 20:09:26 | 00,437,128 | ---- | M] (Dynamic Internet Technology, Inc.) -- C:\Documents and Settings\haier\Desktop\fg686p.exe
[2009/11/25 23:06:57 | 00,000,854 | ---- | M] () -- C:\Documents and Settings\haier\Desktop\Shortcut to KillBox.exe.lnk
[2009/11/25 21:00:27 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/11/25 00:58:53 | 00,000,590 | ---- | M] () -- C:\WINDOWS\System32\Shortcut to KB921488.exe.lnk
[2009/11/22 22:26:49 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/11/20 18:14:36 | 00,002,560 | ---- | M] () -- C:\WINDOWS\_MSRSTRT.EXE
[2009/11/16 22:43:55 | 00,206,830 | ---- | M] () -- C:\Documents and Settings\haier\Desktop\Netdiag 16112009 224354.htm
[2009/11/15 21:24:52 | 00,255,064 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/11/15 20:46:26 | 00,057,344 | ---- | M] () -- C:\WINDOWS\System32\KB906873.exe
[2009/11/15 20:46:26 | 00,057,344 | ---- | M] () -- C:\WINDOWS\System32\KB901746.exe
[2009/11/15 17:23:22 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/11/13 00:49:22 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/11/10 22:44:29 | 00,000,690 | ---- | M] () -- C:\Documents and Settings\haier\Desktop\SpywareBlaster.lnk
[2009/11/10 22:40:12 | 03,012,768 | ---- | M] (Javacool Software LLC ) -- C:\Documents and Settings\haier\My Documents\spywareblastersetup42.exe
[2009/11/09 23:19:47 | 03,336,120 | ---- | M] () -- C:\Documents and Settings\haier\My Documents\callingidxp.exe
[2009/11/09 23:10:52 | 04,155,320 | ---- | M] () -- C:\Documents and Settings\haier\My Documents\callingidLinkAdvisor.exe
[2009/11/06 18:02:35 | 00,061,440 | ---- | M] () -- C:\WINDOWS\System32\KB957619.exe
[2009/11/06 18:02:13 | 00,030,720 | ---- | M] () -- C:\WINDOWS\kbdjpn81X.dll
[2009/11/05 22:24:22 | 00,278,016 | ---- | M] () -- C:\Documents and Settings\haier\My Documents\PPT_Online2.ppt
[2009/11/05 17:47:06 | 00,064,456 | ---- | M] () -- C:\Documents and Settings\haier\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/11/05 17:42:48 | 00,061,440 | ---- | M] () -- C:\WINDOWS\System32\KB985154.exe
[2009/11/02 18:25:16 | 00,061,440 | ---- | M] () -- C:\WINDOWS\System32\KB921488.exe
[2009/10/31 19:40:58 | 00,061,440 | ---- | M] () -- C:\WINDOWS\System32\KB945410.exe
[2009/10/31 19:34:23 | 00,000,250 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/10/29 18:24:12 | 00,061,440 | ---- | M] () -- C:\WINDOWS\System32\KB983975.exe

========== Files Created - No Company Name ==========

[2009/11/28 11:11:58 | 00,001,273 | ---- | C] () -- C:\Documents and Settings\haier\Desktop\Shortcut to TFC.exe.lnk
[2009/11/28 10:38:54 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\haier\Desktop\HijackThis.lnk
[2009/11/28 09:00:32 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2009/11/28 08:57:00 | 00,000,797 | R--- | C] () -- C:\Documents and Settings\haier\Desktop\Internet Explorer.lnk
[2009/11/28 07:56:58 | 00,000,797 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Spyware Terminator.lnk
[2009/11/28 07:50:37 | 00,142,592 | ---- | C] () -- C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2009/11/26 20:51:55 | 00,000,099 | ---- | C] () -- C:\Documents and Settings\haier\default.pls
[2009/11/26 00:37:30 | 00,000,278 | -HS- | C] () -- C:\Documents and Settings\haier\ntuser.ini
[2009/11/25 23:06:57 | 00,000,854 | ---- | C] () -- C:\Documents and Settings\haier\Desktop\Shortcut to KillBox.exe.lnk
[2009/11/25 00:58:53 | 00,000,590 | ---- | C] () -- C:\WINDOWS\System32\Shortcut to KB921488.exe.lnk
[2009/11/20 18:14:34 | 00,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE
[2009/11/16 22:43:54 | 00,206,830 | ---- | C] () -- C:\Documents and Settings\haier\Desktop\Netdiag 16112009 224354.htm
[2009/11/15 20:49:42 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\KB901746.exe
[2009/11/15 20:49:22 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\KB906873.exe
[2009/11/15 17:23:22 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/11/13 00:49:22 | 00,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/11/10 22:44:29 | 00,000,690 | ---- | C] () -- C:\Documents and Settings\haier\Desktop\SpywareBlaster.lnk
[2009/11/09 23:18:50 | 03,336,120 | ---- | C] () -- C:\Documents and Settings\haier\My Documents\callingidxp.exe
[2009/11/09 23:09:43 | 04,155,320 | ---- | C] () -- C:\Documents and Settings\haier\My Documents\callingidLinkAdvisor.exe
[2009/11/06 18:02:36 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\KB957619.exe
[2009/11/06 18:02:13 | 00,030,720 | ---- | C] () -- C:\WINDOWS\kbdjpn81X.dll
[2009/11/05 22:18:28 | 00,278,016 | ---- | C] () -- C:\Documents and Settings\haier\My Documents\PPT_Online2.ppt
[2009/11/05 17:42:49 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\KB985154.exe
[2009/11/02 18:25:17 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\KB921488.exe
[2009/10/31 19:40:58 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\KB945410.exe
[2009/10/29 18:24:14 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\KB983975.exe
[2009/10/25 22:26:14 | 00,030,720 | ---- | C] () -- C:\WINDOWS\kbdjpn44P.dll
[2009/10/17 18:58:37 | 00,030,720 | ---- | C] () -- C:\WINDOWS\kbdjpn38B.dll
[2009/07/07 17:08:23 | 00,000,065 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009/03/08 04:04:59 | 00,035,328 | ---- | C] () -- C:\Documents and Settings\haier\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/25 15:43:14 | 00,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2009/02/03 07:23:02 | 00,000,230 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/12/21 10:28:53 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/12/21 10:18:57 | 00,092,761 | ---- | C] () -- C:\WINDOWS\VGAsetup.ini
[2008/12/21 10:18:06 | 00,127,805 | ---- | C] () -- C:\WINDOWS\System32\VGAunistlog.ini
[2003/01/08 07:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\legitcheckcontrol.dll.bak:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\KB906873.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\KB901746.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\haier\ntuser.ini:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\haier\Desktop\LegitLibM.dll:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\haier\Desktop\fg686p.exe:SummaryInformation
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >

Thank You :)
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP