My computer was infected by it a few hours ago so I used Malwarebytes,
scanned my computer and removed it. I turned off my computer because I
was leaving my home and I came back, turned on my computer and Hard
Drive Diagnostic installed itself again. I don't know if it installed
itself again or it wasn't removed in the first place but can anyone tell
me how to get rid of it permanently?
_______
Please download
OTL to your Desktop. (If you already have it downloaded, then just follow the instructions below).
- Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- Under the Custom Scan box paste this in
Code:%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
%APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
%PROGRAMFILES%\PC-Doctor\Downloads\*.*
%PROGRAMFILES%\Internet Explorer\*.tmp
%PROGRAMFILES%\Internet Explorer\*.dat
%USERPROFILE%\My Documents\*.exe
%USERPROFILE%\*.exe
%systemroot%\ADDINS\*.*
%systemroot%\assembly\*.bak2
%systemroot%\Config\*.*
%systemroot%\REPAIR\*.bak2
%systemroot%\SECURITY\Database\*.sdb /x
%systemroot%\SYSTEM\*.bak2
%systemroot%\Web\*.bak2
%systemroot%\Driver Cache\*.*
%PROGRAMFILES%\Mozilla Firefox\*.exe
%ProgramFiles%\Microsoft Common\*.*
%ProgramFiles%\TinyProxy.
%USERPROFILE%\Favorites\*.url /x
%systemroot%\system32\*.bk
%systemroot%\*.te
%systemroot%\system32\system32\*.*
%ALLUSERSPROFILE%\*.dat /x
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\*.exe /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.sys
%systemroot%\system32\drivers\*.dll
%systemroot%\system32\drivers\*.ini
%systemroot%\system32\drivers\*.exe
%systemroot%\system32\Spool\prtprocs\w32x86\*.dll
%SYSTEMDRIVE%\*.*
%PROGRAMFILES%\*.
%appdata%\*.*
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
disk.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
usbstor.sys
/md5stop
CREATERESTOREPOINT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
- Make sure Use Safe List is selected under all categories
- Make sure both Purity Check and LOP Check are selected
- Make sure File Age is set to 30 days
- Click the Run Scan button.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) and paste (Edit->Paste) the contents of these files, one at a time into your thread
Note: in the event that OTL fails to run, please use alternate download links to try again: http://www.itxassociates.com/OT-Tools/OTL.scr
http://www.itxassociates.com/OT-Tools/OTL.com
The post won't fit
Attach it.
OTL logfile created on: 12/6/2010 3:59:31 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Jerry\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
510.00 Mb Total Physical Memory | 70.00 Mb Available Physical Memory | 14.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 55.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.44 Gb Total Space | 8.72 Gb Free Space | 25.31% Space Free | Partition Type: NTFS
Computer Name: LAMFAMILY | User Name: Jerry | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC
- [2010/12/06 15:54:54 | 000,575,488 | ---- | M] (OldTimer Tools) --
C:\Documents and Settings\Jerry\My Documents\Downloads\OTL.exe
PRC - [2010/12/05 20:13:06 | 000,357,376 | ---- | M] () -- C:\Documents and Settings\Jerry\Local Settings\Temp\207750.exe
PRC - [2010/11/16 15:42:57 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\Steam.exe
PRC - [2010/10/29 14:41:34 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC
- [2010/04/16 07:33:40 | 000,144,672 | ---- | M] (Apple Inc.) --
C:\Program Files\Common Files\Apple\Mobile Device
Support\AppleMobileDeviceService.exe
PRC - [2007/06/13 02:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC
- [2007/03/09 11:09:58 | 000,063,712 | ---- | M] (Adobe Systems
Incorporated) -- C:\Program Files\Adobe\Photoshop Album Starter
Edition\3.2\Apps\apdproxy.exe
PRC - [2006/12/01 20:28:06 |
000,095,800 | ---- | M] (OLYMPUS IMAGING CORP.) -- C:\Program
Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
PRC - [2006/08/14 09:12:46 | 000,049,152 | ---- | M] () -- C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
PRC
- [2005/11/21 14:57:49 | 000,140,880 | ---- | M] (Viewpoint
Corporation) -- C:\Program Files\Viewpoint\Viewpoint Toolbar
V35\FotomatDeviceConnect.exe
PRC - [2005/04/17 11:30:48 | 000,085,184 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\VPTray.exe
PRC - [2005/04/17 11:30:40 | 001,706,176 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe
PRC - [2005/04/17 11:30:32 | 000,019,648 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe
PRC - [2005/04/17 11:30:32 | 000,018,624 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DoScan.exe
PRC
- [2005/04/08 14:54:52 | 000,161,392 | ---- | M] (Symantec Corporation)
-- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PRC -
[2005/04/08 14:52:32 | 000,185,968 | ---- | M] (Symantec Corporation) --
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PRC -
[2005/04/08 14:52:30 | 000,048,752 | ---- | M] (Symantec Corporation) --
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC -
[2004/11/10 20:15:31 | 000,111,816 | ---- | M] (Viewpoint Corporation)
-- C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
PRC - [2004/10/14 13:42:54 | 001,404,928 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
PRC - [2003/10/10 08:06:10 | 000,192,512 | ---- | M] () -- C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
PRC - [2003/08/04 17:28:18 | 000,049,152 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\HP Software Update\hpwuSchd.exe
========== Modules (SafeList) ========== MOD
- [2010/12/06 15:54:54 | 000,575,488 | ---- | M] (OldTimer Tools) --
C:\Documents and Settings\Jerry\My Documents\Downloads\OTL.exe
MOD -
[2006/08/25 07:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation)
--
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV
- [2010/04/16 07:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto |
Running] -- C:\Program Files\Common Files\Apple\Mobile Device
Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV -
[2005/04/17 11:30:42 | 000,124,608 | ---- | M] (symantec) [On_Demand |
Stopped] -- C:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam)
SRV
- [2005/04/17 11:30:40 | 001,706,176 | ---- | M] (Symantec Corporation)
[Auto | Running] -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe --
(Symantec AntiVirus)
SRV - [2005/04/17 11:30:32 | 000,019,648 | ---- |
M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec
AntiVirus\DefWatch.exe -- (DefWatch)
SRV - [2005/04/08 14:54:52 |
000,161,392 | ---- | M] (Symantec Corporation) [Auto | Running] --
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr)
SRV
- [2005/04/08 14:54:50 | 000,083,568 | ---- | M] (Symantec Corporation)
[On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec
Shared\ccPwdSvc.exe -- (ccPwdSvc)
SRV - [2005/04/08 14:52:32 |
000,185,968 | ---- | M] (Symantec Corporation) [Auto | Running] --
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr)
SRV
- [2005/04/05 10:17:22 | 000,206,552 | ---- | M] (Symantec Corporation)
[On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec
Shared\SNDSrvc.exe -- (SNDSrvc)
SRV - [2005/03/30 20:48:22 |
000,992,864 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] --
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe --
(SPBBCSvc)
SRV - [2004/01/04 23:30:14 | 000,065,795 | ---- | M] (HP)
[On_Demand | Stopped] -- C:\WINDOWS\system32\hpzipm12.exe -- (Pml Driver
HPZ12)
========== Driver Services (SafeList) ========== DRV - [2010/11/29 17:42:18 | 000,038,224 | ---- | M] (
Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV
- [2010/10/18 00:00:00 | 001,371,184 | ---- | M] (Symantec Corporation)
[Kernel | On_Demand | Running] -- C:\Program Files\Common
Files\Symantec Shared\VirusDefs\20101203.003\NAVEX15.SYS -- (NAVEX15)
DRV
- [2010/10/18 00:00:00 | 000,086,064 | ---- | M] (Symantec Corporation)
[Kernel | On_Demand | Running] -- C:\Program Files\Common
Files\Symantec Shared\VirusDefs\20101203.003\NAVENG.SYS -- (NAVENG)
DRV
- [2010/06/17 00:00:00 | 000,371,248 | ---- | M] (Symantec Corporation)
[Kernel | System | Running] -- C:\Program Files\Common Files\Symantec
Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2007/10/25 02:10:00 |
000,215,040 | R--- | M] (Realtek Semiconductor Corporation
) [Kernel | On_Demand | Running] --
C:\WINDOWS\system32\drivers\RTL8187B.sys -- (RTL8187B)
DRV -
[2005/04/24 21:43:58 | 000,013,225 | ---- | M] (Razer (Asia-Pacific) Pte
Ltd) [Kernel | On_Demand | Running] --
C:\WINDOWS\system32\drivers\DB3G.sys -- (Razerlow)
DRV - [2005/04/05
10:17:02 | 000,267,192 | ---- | M] (Symantec Corporation) [Kernel |
System | Running] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV
- [2005/04/05 10:17:00 | 000,017,976 | ---- | M] (Symantec Corporation)
[Kernel | On_Demand | Running] --
C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV -
[2005/04/01 19:36:04 | 000,123,200 | ---- | M] (Symantec Corporation)
[Kernel | Disabled | Running] -- C:\Program Files\Symantec\SYMEVENT.SYS
-- (SymEvent)
DRV - [2005/03/30 20:48:20 | 000,372,832 | ---- | M]
(Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program
Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV
- [2005/03/29 23:03:06 | 001,035,264 | ---- | M] (ATI Technologies
Inc.) [Kernel | On_Demand | Stopped] --
C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV -
[2005/02/04 19:14:32 | 000,053,896 | ---- | M] (Symantec Corporation)
[Kernel | System | Running] -- C:\Program Files\Symantec
AntiVirus\Savrtpel.sys -- (SAVRTPEL)
DRV - [2005/02/04 19:14:30 |
000,324,232 | ---- | M] (Symantec Corporation) [Kernel | System |
Running] -- C:\Program Files\Symantec AntiVirus\savrt.sys -- (SAVRT)
DRV
- [2005/01/04 01:43:08 | 000,004,682 | ---- | M] (INCA Internet Co.,
Ltd.) [Kernel | System | Running] -- C:\WINDOWS\system32\npptNT2.sys --
(NPPTNT2)
DRV - [2004/09/17 08:02:54 | 000,732,928 | ---- | M]
(Creative Technology Ltd.) [Kernel | On_Demand | Running] --
C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
DRV -
[2004/08/12 06:11:50 | 000,467,200 | ---- | M] (Intel Corporation)
[Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\iaStor.sys --
(iastor)
DRV - [2004/04/29 17:55:42 | 000,186,112 | ---- | M]
(Broadcom Corporation) [Kernel | On_Demand | Running] --
C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2004/02/27
15:03:00 | 000,670,203 | R--- | M] (Intel Corporation) [Kernel |
On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Intels51.sys --
(Intels51) Intel(R)
DRV - [2001/08/22 07:42:58 | 000,013,632 | ---- |
M] (Dell Computer Corporation) [Kernel | System | Running] --
C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI)
DRV - [2001/08/17
11:48:48 | 000,070,528 | ---- | M] (ATI Technologies Inc.) [Kernel |
On_Demand | Running] -- C:\WINDOWS\system32\drivers\atiragem.sys --
(atirage)
DRV - [2001/05/07 02:56:02 | 000,019,805 | R--- | M]
(Thesycon GmbH, Germany) [Kernel | On_Demand | Stopped] --
C:\WINDOWS\system32\drivers\usbio.sys -- (USBIO) USBIO Driver
(usbio.sys)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/ie/defaults/cs/sbcydsl/*http://www.yahoo.com/search/ie.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.msn.com/spbasic.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2776682
IE
- HKCU\..\URLSearchHook: {51a86bb3-6602-4c85-92a5-130ee4864f13} -
C:\Program Files\BrotherSoft_Extreme\tbBrot.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1;*.local
========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://start.mozilla.org/firefox?client=firefox-a&rls=org.mozilla:en-US:official"
FF - user.js..browser.search.defaultenginename: "Yoog Search"
FF - user.js..browser.search.defaulturl: "http://www10.searchonthego.net/search.php?q="
FF - user.js..browser.search.selectedEngine: "Yoog Search"
FF - user.js..keyword.URL: "http://www10.searchonthego.net/search.php?q="
FF - user.js..keyword.enabled: true
FF
- HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components:
C:\Program Files\Mozilla Firefox\components [2010/10/31 14:46:58 |
000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox
3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2010/10/29 14:42:24 | 000,000,000 | ---D | M]
[2008/12/03 20:16:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jerry\Application Data\Mozilla\Extensions
[2009/08/01
15:47:06 | 000,000,000 | ---D | M] -- C:\Documents and
Settings\Jerry\Application
Data\Mozilla\Firefox\Profiles\f1b8zt9n.default\extensions
[2005/08/31
10:26:35 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Documents
and Settings\Jerry\Application
Data\Mozilla\Firefox\Profiles\f1b8zt9n.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/08/01
15:47:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and
Settings\Jerry\Application
Data\Mozilla\Firefox\Profiles\f1b8zt9n.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2006/08/21
10:05:22 | 000,000,000 | ---D | M] -- C:\Documents and
Settings\Jerry\Application
Data\Mozilla\Firefox\Profiles\nx3cpuj5.casey\extensions
[2006/08/21
10:05:22 | 000,000,000 | ---D | M] (Firefox (default)) -- C:\Documents
and Settings\Jerry\Application
Data\Mozilla\Firefox\Profiles\nx3cpuj5.casey\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/12/05
22:48:00 | 000,000,000 | ---D | M] -- C:\Documents and
Settings\Jerry\Application
Data\Mozilla\Firefox\Profiles\t9e7m46d.jerry\extensions
[2010/05/21
15:01:18 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant)
-- C:\Documents and Settings\Jerry\Application
Data\Mozilla\Firefox\Profiles\t9e7m46d.jerry\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/18
14:50:27 | 000,000,256 | ---- | M] () -- C:\Documents and
Settings\Jerry\Application
Data\Mozilla\Firefox\Profiles\f1b8zt9n.default\searchplugins\Yoog
Search.xml
[2010/12/02 21:54:35 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/03/24
14:07:46 | 000,000,000 | ---D | M] (z) -- C:\Program Files\Mozilla
Firefox\extensions\{ab7ba5a8-2cd0-433e-95a6-68331de246dd}
[2009/08/01
15:46:45 | 000,072,960 | ---- | M] (Foxit Software Company) --
C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2007/04/14 13:22:27 | 000,024,576 | ---- | M] (RealNetworks) -- C:\Program Files\Mozilla Firefox\plugins\npgcplug.dll
[2007/05/10 09:46:42 | 000,061,440 | ---- | M] ( ) -- C:\Program Files\Mozilla Firefox\plugins\npkanevapatch.dll
[2005/04/27 12:10:49 | 000,102,400 | ---- | M] (RealNetworks) -- C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
[2006/01/18 11:50:00 | 000,319,488 | ---- | M] ( ) -- C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll
[2010/10/21 15:06:08 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/10/21 15:06:08 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/10/21 15:06:08 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/10/21 15:06:08 | 000,000,831 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2004/08/12 05:57:47 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2
- BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} -
C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 -
BHO: (PnIEBrowserHelperObj Class) -
{4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink
TotalAccess\PnEL.dll (EarthLink, Inc.)
O2 - BHO: (BrotherSoft Extreme
Toolbar) - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program
Files\BrotherSoft_Extreme\tbBrot.dll (Conduit Ltd.)
O2 - BHO:
(Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 -
BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} -
C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O2 - BHO:
(Little Fighter 2 Toolbar Helper) -
{AB41010D-4804-4793-A6A2-3B5EBE2348DD} - C:\Program Files\Little Fighter
2 Toolbar\v2.0.0.1\Little_Fighter_2_Toolbar.dll ()
O3 -
HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} -
C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 -
HKLM\..\Toolbar: (Conduit Engine) -
{30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program
Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 -
HKLM\..\Toolbar: (BrotherSoft Extreme Toolbar) -
{51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program
Files\BrotherSoft_Extreme\tbBrot.dll (Conduit Ltd.)
O3 -
HKLM\..\Toolbar: (Little Fighter 2 Toolbar) -
{C11483F7-D7D8-4804-98D8-6055470BB989} - C:\Program Files\Little Fighter
2 Toolbar\v2.0.0.1\Little_Fighter_2_Toolbar.dll ()
O3 -
HKLM\..\Toolbar: (Pop-Up Blocker) -
{D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink
TotalAccess\PnEL.dll (EarthLink, Inc.)
O3 - HKLM\..\Toolbar: (AOL
Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program
Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar:
(Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 -
HKLM\..\Toolbar: (Viewpoint Toolbar) -
{F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program
Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll (Viewpoint
Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) -
{3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program
Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 -
HKCU\..\Toolbar\WebBrowser: (BrotherSoft Extreme Toolbar) -
{51A86BB3-6602-4C85-92A5-130EE4864F13} - C:\Program
Files\BrotherSoft_Extreme\tbBrot.dll (Conduit Ltd.)
O3 -
HKCU\..\Toolbar\WebBrowser: (Little Fighter 2 Toolbar) -
{C11483F7-D7D8-4804-98D8-6055470BB989} - C:\Program Files\Little Fighter
2 Toolbar\v2.0.0.1\Little_Fighter_2_Toolbar.dll ()
O3 -
HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) -
{DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL
Toolbar 4.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser:
(Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 -
HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop
Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [ClientGW] File not found
O4 - HKLM..\Run: [eSnips] C:\Program Files\eSnips\ClientGW.exe File not found
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [RecoverFromReboot] C:\WINDOWS\Temp\RecoverFromReboot.exe File not found
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
O4
- HKLM..\Run: [ViewpointPhotosDeviceConnect] C:\Program
Files\Viewpoint\Viewpoint Toolbar V35\FotomatDeviceConnect.exe
(Viewpoint Corporation)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [207750] C:\Documents and Settings\Jerry\Local Settings\Temp\207750.exe ()
O4 - HKCU..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe File not found
O4 - HKCU..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe (OLYMPUS IMAGING CORP.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe File not found
O4 - HKCU..\Run: [SpySweeper] File not found
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4
- Startup: C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup:
C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\MyWebSearch Email Plugin.lnk = C:\Program
Files\MyWebSearch\bar\3.bin\MWSOEMON.EXE File not found
O4 - Startup:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SBC
Self Support Tool.lnk = C:\Program Files\SBC Self Support
Tool\bin\matcli.exe (Motive Communications, Inc.)
O4 - Startup:
C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music
Jukebox\ymetray.exe ()
O4 - Startup: C:\Documents and
Settings\Jerry\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk =
C:\Program Files\MyWebSearch\bar\3.bin\MWSOEMON.EXE File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8
- Extra context menu item: &AOL Toolbar Search - c:\Program
Files\AOL\AOL Toolbar 4.0\resources\en-us\local\search.html ()
O8 -
Extra context menu item: &Viewpoint Search - C:\Program
Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll (Viewpoint
Corporation)
O9 - Extra Button: Yahoo! Login -
{2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program
Files\Yahoo!\common\ylogin.dll (Yahoo! Inc.)
O9 - Extra 'Tools'
menuitem : Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} -
C:\Program Files\Yahoo!\common\ylogin.dll (Yahoo! Inc.)
O9 - Extra
Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} -
C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll (AOL LLC)
O9 - Extra
Button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program
Files\Yahoo!\Messenger\yhexbmes.dll (Yahoo! Inc.)
O9 - Extra 'Tools'
menuitem : Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} -
C:\Program Files\Yahoo!\Messenger\yhexbmes.dll (Yahoo! Inc.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9
- Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} -
C:\Documents and Settings\Jerry\Start Menu\Programs\IMVU\Run IMVU.lnk
File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab (Java Plug-in 1.5.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java
file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18
- Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} -
C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard
Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20
- Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll -
C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Jerry\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jerry\Application Data\Mozilla\Firefox\Desktop Background.bmp
O29 - HKLM SecurityProviders - (digeste.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/05/15 16:52:31 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O36 - AppCertDlls: extrmsg - (C:\WINDOWS\system32\esenfc.dll) - C:\WINDOWS\System32\esenfc.dll File not found
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
SafeBootMin: AaaAAAA - Driver
SafeBootMin: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: AaaAAAA - Driver
SafeBootNet: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {0291E591-EA41-4c82-8106-3DC6CE7F7664} - Reg Error: Value error.
ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {166B1BCA-3F9C-11CF-8075-444553540000} - Macromedia Shockwave Director 10.1
ActiveX: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} - Reg Error: Value error.
ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} - Reg Error: Value error.
ActiveX: {25A4B6D0-CF64-48EF-A4A2-7CD30F44FEEC} - Reg Error: Value error.
ActiveX: {26FCDD66-A1AA-49AF-B65A-069DA3A75221} - Reg Error: Value error.
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Macromedia Shockwave Director 10.1
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX:
{2C7339CF-2B09-4501-B3F3-F3508C9228ED} -
%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall
%SystemRoot%\system32\themeui.dll
ActiveX: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - Reg Error: Value error.
ActiveX: {347B0667-C7ED-429B-BDE3-CC8D3BACAA31} - Reg Error: Value error.
ActiveX: {362A5D5E-1BF6-4CA7-87B4-B6686F3C1BEF} - Reg Error: Value error.
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {38539595-3E29-410d-ABBD-3D6A75BC9A73} - Reg Error: Value error.
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX:
{44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook
Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX:
{44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe
advpack.dll,LaunchINFSection
C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:
{4b218e3e-bc98-4770-93d3-2731b9329278} -
%SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection
MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf
ActiveX: {4EC8E993-32C1-47F5-A07A-5B0574655AD4} - Reg Error: Value error.
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:
{5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe
advpack.dll,LaunchINFSection
C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {76C19B33-F0C8-11cf-87CC-0020AFEECF20} - Chinese (Traditional) Language Support
ActiveX:
{7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook
Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - %SystemRoot%\system32\ie4uinit.exe
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {944D7BBB-EA1D-43EB-B49F-F517CF2B6C9D} - Reg Error: Value error.
ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} -
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {CE734E0A-D6D3-4A92-AF9F-499BE87A025C} - Reg Error: Value error.
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - Reg Error: Value error.
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {F53CE5EC-1CD8-41EB-A220-F8EA247E3A06} - Reg Error: Value error.
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)