Results 1 to 10 of 29

Thread: Win32.KillAV-KQ

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Junior Member
    Join Date
    Aug 2009
    Posts
    15

    Default Win32.KillAV-KQ

    When I run Spybot, it comes up that my computer is infected with KillAV-KQ. It finds six entries but says it is unable to delete one of them and to restart the computer and run Spybot again. When I do this Spybot does not find the files. This keeps happening when I run the scan.

    Also I've been receiving a pop up message in the right corner of the screen that says the virtual memory is low, but then the message disappears. Does this have anything to do with this virus?

    Along with Spybot S&D I also have Ad-Aware. I just installed Erunt and HijackThis

    Any help would be greatly appreciated. Thank you!



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:15:39 AM, on 8/17/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
    C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
    C:\Program Files\CA\eTrust Antivirus\InoRT.exe
    C:\Program Files\CA\eTrust Antivirus\InoTask.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\PROGRA~1\CA\ETRUST~1\realmon.exe
    C:\Program Files\Common Files\AOL\1123605174\ee\AOLSoftware.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Belkin\F5D9050\Belkinwcui.exe
    c:\program files\common files\aol\1123605174\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
    C:\Program Files\Common Files\AOL\1123605174\EE\aolsoftware.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    c:\program files\aim toolbar\aimtbServer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll
    R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL Search\AOLSearch.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
    O2 - BHO: Browser Helper Object - {AFD4AD01-58C1-47DB-A404-FBE00A6C5486} - C:\Program Files\Shared\lib.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1123605174\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-21-329068152-115176313-839522115-1003\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
    O4 - HKUS\S-1-5-21-329068152-115176313-839522115-1003\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp (User '?')
    O4 - HKUS\S-1-5-21-329068152-115176313-839522115-1003\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe (User '?')
    O4 - HKUS\S-1-5-21-329068152-115176313-839522115-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O4 - HKUS\S-1-5-21-329068152-115176313-839522115-1003\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
    O4 - S-1-5-21-329068152-115176313-839522115-1003 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User '?')
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O4 - Global Startup: Belkin Wireless Client Utility.lnk = C:\Program Files\Belkin\F5D9050\Belkinwcui.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...oUploader5.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/...toUploader.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1123602472012
    O16 - DPF: {A762E064-A885-40E4-AC10-671BB62DC2B2} (OFMailHTMLCtl Class) - http://www.eomniform.com/OF5/nsplugins/OFMailX.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
    O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/...ploader4_5.cab
    O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia.com/upload/activ...v2.0.0.10.cab?
    O17 - HKLM\System\CCS\Services\Tcpip\..\{367CE849-25D8-4C85-83FF-148336F7665C}: NameServer = 69.18.136.8
    O18 - Filter hijack: text/html - {e2a9c2cf-f792-40ec-bdd8-fcd2b624dbe3} - C:\WINDOWS\system32\xwreg32.dll
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
    O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
    O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
    O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi SM0915

    Please post next spybot report
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Junior Member
    Join Date
    Aug 2009
    Posts
    15

    Default

    Hi, here is the latest spybot report. I didn't know if you needed the system information and startup entries list so I included as well.

    On the latest scan the Win32.KillAV-KQ didn't come up. Also when I go to the processes in the task manager there are many iexplorer.exe's.



    --- Search result list ---
    Win32.Fakealert.ttam: [SBI $353B4316] Library (File, fixed)
    C:\WINDOWS\system32\xwreg32.dll
    Properties.size=0
    Properties.md5=D41D8CD98F00B204E9800998ECF8427E


    --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

    2009-01-26 blindman.exe (1.0.0.8)
    2009-01-26 SDFiles.exe (1.6.1.7)
    2009-01-26 SDMain.exe (1.0.0.6)
    2009-01-26 SDShred.exe (1.0.2.5)
    2009-01-26 SDUpdate.exe (1.6.0.12)
    2009-01-26 SpybotSD.exe (1.6.2.46)
    2009-03-05 TeaTimer.exe (1.6.6.32)
    2009-07-14 unins000.exe (51.49.0.0)
    2009-01-26 Update.exe (1.6.0.7)
    2009-07-28 advcheck.dll (1.6.3.17)
    2007-04-02 aports.dll (2.1.0.0)
    2008-06-14 DelZip179.dll (1.79.11.1)
    2009-01-26 SDHelper.dll (1.6.2.14)
    2008-06-19 sqlite3.dll
    2009-01-26 Tools.dll (2.1.6.10)
    2009-01-16 UninsSrv.dll (1.0.0.0)
    2009-05-19 Includes\Adware.sbi (*)
    2009-08-18 Includes\AdwareC.sbi (*)
    2009-01-22 Includes\Cookies.sbi (*)
    2009-05-19 Includes\Dialer.sbi (*)
    2009-08-19 Includes\DialerC.sbi (*)
    2009-01-22 Includes\HeavyDuty.sbi (*)
    2009-05-26 Includes\Hijackers.sbi (*)
    2009-08-04 Includes\HijackersC.sbi (*)
    2009-06-23 Includes\Keyloggers.sbi (*)
    2009-07-30 Includes\KeyloggersC.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2009-08-19 Includes\Malware.sbi (*)
    2009-08-19 Includes\MalwareC.sbi (*)
    2009-03-25 Includes\PUPS.sbi (*)
    2009-08-18 Includes\PUPSC.sbi (*)
    2009-01-22 Includes\Revision.sbi (*)
    2009-01-13 Includes\Security.sbi (*)
    2009-07-30 Includes\SecurityC.sbi (*)
    2008-06-03 Includes\Spybots.sbi (*)
    2008-06-03 Includes\SpybotsC.sbi (*)
    2009-04-07 Includes\Spyware.sbi (*)
    2009-08-11 Includes\SpywareC.sbi (*)
    2009-06-08 Includes\Tracks.uti
    2009-08-19 Includes\Trojans.sbi (*)
    2009-08-19 Includes\TrojansC.sbi (*)
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2007-12-24 Plugins\TCPIPAddress.dll



    --- System information ---
    Windows XP (Build: 2600) Service Pack 2 (5.1.2600)
    / MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2
    / MSXML4SP2: Security update for MSXML4 SP2 (KB936181)
    / MSXML4SP2: Security update for MSXML4 SP2 (KB954430)
    / Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
    / Windows / SP1: Microsoft National Language Support Downlevel APIs
    / Windows Media Player: Security Update for Windows Media Player (KB952069)
    / Windows Media Player: Security Update for Windows Media Player (KB973540)
    / Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398)
    / Windows Media Player 9: Security Update for Windows Media Player 9 (KB917734)
    / Windows Media Player 9: Security Update for Windows Media Player 9 (KB936782)
    / Windows XP: Security Update for Windows XP (KB923689)
    / Windows XP: Security Update for Windows XP (KB941569)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127-v2)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB956390)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB958215)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB960714)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB961260)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB963027)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB969897)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB972260)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB972260)
    / Windows XP / SP0: Update for Windows Internet Explorer 8 (KB972636)
    / Windows XP / SP3: Windows XP Hotfix - KB873333
    / Windows XP / SP3: Windows XP Hotfix - KB873339
    / Windows XP / SP3: Windows XP Hotfix - KB885250
    / Windows XP / SP3: Windows XP Hotfix - KB885835
    / Windows XP / SP3: Windows XP Hotfix - KB885836
    / Windows XP / SP3: Windows XP Hotfix - KB886185
    / Windows XP / SP3: Windows XP Hotfix - KB887472
    / Windows XP / SP3: Windows XP Hotfix - KB887742
    / Windows XP / SP3: Windows XP Hotfix - KB888113
    / Windows XP / SP3: Windows XP Hotfix - KB888302
    / Windows XP / SP3: Security Update for Windows XP (KB890046)
    / Windows XP / SP3: Windows XP Hotfix - KB890859
    / Windows XP / SP3: Windows XP Hotfix - KB891781
    / Windows XP / SP3: Security Update for Windows XP (KB893066)
    / Windows XP / SP3: Windows XP Hotfix - KB893086
    / Windows XP / SP3: Security Update for Windows XP (KB893756)
    / Windows XP / SP3: Windows Installer 3.1 (KB893803)
    / Windows XP / SP3: Update for Windows XP (KB894391)
    / Windows XP / SP3: Security Update for Windows XP (KB896358)
    / Windows XP / SP3: Security Update for Windows XP (KB896422)
    / Windows XP / SP3: Security Update for Windows XP (KB896423)
    / Windows XP / SP3: Security Update for Windows XP (KB896424)
    / Windows XP / SP3: Security Update for Windows XP (KB896428)
    / Windows XP / SP3: Security Update for Windows XP (KB896688)
    / Windows XP / SP3: Update for Windows XP (KB896727)
    / Windows XP / SP3: Update for Windows XP (KB898461)
    / Windows XP / SP3: Security Update for Windows XP (KB899587)
    / Windows XP / SP3: Security Update for Windows XP (KB899588)
    / Windows XP / SP3: Security Update for Windows XP (KB899589)
    / Windows XP / SP3: Security Update for Windows XP (KB899591)
    / Windows XP / SP3: Update for Windows XP (KB900485)
    / Windows XP / SP3: Security Update for Windows XP (KB900725)
    / Windows XP / SP3: Security Update for Windows XP (KB901017)
    / Windows XP / SP3: Security Update for Windows XP (KB901214)
    / Windows XP / SP3: Security Update for Windows XP (KB902400)
    / Windows XP / SP3: Security Update for Windows XP (KB904706)
    / Windows XP / SP3: Update for Windows XP (KB904942)
    / Windows XP / SP3: Security Update for Windows XP (KB905414)
    / Windows XP / SP3: Security Update for Windows XP (KB905749)
    / Windows XP / SP3: Security Update for Windows XP (KB905915)
    / Windows XP / SP3: Security Update for Windows XP (KB908519)
    / Windows XP / SP3: Security Update for Windows XP (KB908531)
    / Windows XP / SP3: Update for Windows XP (KB910437)
    / Windows XP / SP3: Security Update for Windows XP (KB911280)
    / Windows XP / SP3: Security Update for Windows XP (KB911562)
    / Windows XP / SP3: Security Update for Windows XP (KB911567)
    / Windows XP / SP3: Security Update for Windows XP (KB911927)
    / Windows XP / SP3: Security Update for Windows XP (KB912812)
    / Windows XP / SP3: Security Update for Windows XP (KB912919)
    / Windows XP / SP3: Security Update for Windows XP (KB913446)
    / Windows XP / SP3: Security Update for Windows XP (KB913580)
    / Windows XP / SP3: Security Update for Windows XP (KB914388)
    / Windows XP / SP3: Security Update for Windows XP (KB914389)
    / Windows XP / SP3: Hotfix for Windows XP (KB914440)
    / Windows XP / SP3: Hotfix for Windows XP (KB915865)
    / Windows XP / SP3: Security Update for Windows XP (KB916281)
    / Windows XP / SP3: Update for Windows XP (KB916595)
    / Windows XP / SP3: Security Update for Windows XP (KB917159)
    / Windows XP / SP3: Security Update for Windows XP (KB917344)
    / Windows XP / SP3: Security Update for Windows XP (KB917422)
    / Windows XP / SP3: Security Update for Windows XP (KB917953)
    / Windows XP / SP3: Security Update for Windows XP (KB918118)
    / Windows XP / SP3: Security Update for Windows XP (KB918439)
    / Windows XP / SP3: Security Update for Windows XP (KB918899)
    / Windows XP / SP3: Security Update for Windows XP (KB919007)
    / Windows XP / SP3: Security Update for Windows XP (KB920213)
    / Windows XP / SP3: Security Update for Windows XP (KB920214)
    / Windows XP / SP3: Security Update for Windows XP (KB920670)
    / Windows XP / SP3: Security Update for Windows XP (KB920683)
    / Windows XP / SP3: Security Update for Windows XP (KB920685)
    / Windows XP / SP3: Update for Windows XP (KB920872)
    / Windows XP / SP3: Security Update for Windows XP (KB921398)
    / Windows XP / SP3: Security Update for Windows XP (KB921503)
    / Windows XP / SP3: Security Update for Windows XP (KB921883)
    / Windows XP / SP3: Update for Windows XP (KB922582)
    / Windows XP / SP3: Security Update for Windows XP (KB922616)
    / Windows XP / SP3: Security Update for Windows XP (KB922760)
    / Windows XP / SP3: Security Update for Windows XP (KB922819)
    / Windows XP / SP3: Security Update for Windows XP (KB923191)
    / Windows XP / SP3: Security Update for Windows XP (KB923414)
    / Windows XP / SP3: Security Update for Windows XP (KB923694)
    / Windows XP / SP3: Security Update for Windows XP (KB923980)
    / Windows XP / SP3: Security Update for Windows XP (KB924191)
    / Windows XP / SP3: Security Update for Windows XP (KB924270)
    / Windows XP / SP3: Security Update for Windows XP (KB924496)
    / Windows XP / SP3: Security Update for Windows XP (KB924667)
    / Windows XP / SP3: Security Update for Windows XP (KB925454)
    / Windows XP / SP3: Security Update for Windows XP (KB925486)
    / Windows XP / SP3: Security Update for Windows XP (KB925902)
    / Windows XP / SP3: Security Update for Windows XP (KB926255)
    / Windows XP / SP3: Security Update for Windows XP (KB926436)
    / Windows XP / SP3: Security Update for Windows XP (KB927779)
    / Windows XP / SP3: Security Update for Windows XP (KB927802)
    / Windows XP / SP3: Update for Windows XP (KB927891)
    / Windows XP / SP3: Security Update for Windows XP (KB928090)
    / Windows XP / SP3: Security Update for Windows XP (KB928255)
    / Windows XP / SP3: Security Update for Windows XP (KB928843)
    / Windows XP / SP3: Security Update for Windows XP (KB929123)
    / Windows XP / SP3: Update for Windows XP (KB929338)
    / Windows XP / SP3: Security Update for Windows XP (KB929969)
    / Windows XP / SP3: Security Update for Windows XP (KB930178)
    / Windows XP / SP3: Update for Windows XP (KB930916)
    / Windows XP / SP3: Security Update for Windows XP (KB931261)
    / Windows XP / SP3: Security Update for Windows XP (KB931768)
    / Windows XP / SP3: Security Update for Windows XP (KB931784)
    / Windows XP / SP3: Update for Windows XP (KB931836)
    / Windows XP / SP3: Security Update for Windows XP (KB932168)
    / Windows XP / SP3: Update for Windows XP (KB932823-v3)
    / Windows XP / SP3: Update for Windows XP (KB933360)
    / Windows XP / SP3: Security Update for Windows XP (KB933566)
    / Windows XP / SP3: Security Update for Windows XP (KB933729)
    / Windows XP / SP3: Security Update for Windows XP (KB935839)
    / Windows XP / SP3: Security Update for Windows XP (KB935840)
    / Windows XP / SP3: Security Update for Windows XP (KB936021)
    / Windows XP / SP3: Update for Windows XP (KB936357)
    / Windows XP / SP3: Security Update for Windows XP (KB937143)
    / Windows XP / SP3: Security Update for Windows XP (KB937894)
    / Windows XP / SP3: Security Update for Windows XP (KB938127)
    / Windows XP / SP3: Update for Windows XP (KB938828)
    / Windows XP / SP3: Security Update for Windows XP (KB938829)
    / Windows XP / SP3: Security Update for Windows XP (KB939653)
    / Windows XP / SP3: Security Update for Windows XP (KB941202)
    / Windows XP / SP3: Security Update for Windows XP (KB941568)
    / Windows XP / SP3: Security Update for Windows XP (KB941644)
    / Windows XP / SP3: Security Update for Windows XP (KB941693)
    / Windows XP / SP3: Security Update for Windows XP (KB942615)
    / Windows XP / SP3: Update for Windows XP (KB942763)
    / Windows XP / SP3: Update for Windows XP (KB942840)
    / Windows XP / SP3: Security Update for Windows XP (KB943055)
    / Windows XP / SP3: Security Update for Windows XP (KB943460)
    / Windows XP / SP3: Security Update for Windows XP (KB943485)
    / Windows XP / SP3: Security Update for Windows XP (KB944338)
    / Windows XP / SP3: Security Update for Windows XP (KB944533)
    / Windows XP / SP3: Security Update for Windows XP (KB944653)
    / Windows XP / SP3: Security Update for Windows XP (KB945553)
    / Windows XP / SP3: Security Update for Windows XP (KB946026)
    / Windows XP / SP3: Update for Windows XP (KB946627)
    / Windows XP / SP3: Security Update for Windows XP (KB947864)
    / Windows XP / SP3: Security Update for Windows XP (KB948590)
    / Windows XP / SP3: Security Update for Windows XP (KB948881)
    / Windows XP / SP3: Security Update for Windows XP (KB950749)
    / Windows XP / SP3: Security Update for Windows XP (KB958470)
    / Windows XP / SP3: Security Update for Windows XP (KB971032)
    / Windows XP / SP4: Security Update for Windows XP (KB923561)
    / Windows XP / SP4: Security Update for Windows XP (KB938464)
    / Windows XP / SP4: Security Update for Windows XP (KB946648)
    / Windows XP / SP4: Security Update for Windows XP (KB950759)
    / Windows XP / SP4: Security Update for Windows XP (KB950760)
    / Windows XP / SP4: Security Update for Windows XP (KB950762)
    / Windows XP / SP4: Security Update for Windows XP (KB950974)
    / Windows XP / SP4: Security Update for Windows XP (KB951066)
    / Windows XP / SP4: Update for Windows XP (KB951072-v2)
    / Windows XP / SP4: Security Update for Windows XP (KB951376)
    / Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
    / Windows XP / SP4: Security Update for Windows XP (KB951698)
    / Windows XP / SP4: Security Update for Windows XP (KB951748)
    / Windows XP / SP4: Security Update for Windows XP (KB952004)
    / Windows XP / SP4: Hotfix for Windows XP (KB952287)
    / Windows XP / SP4: Security Update for Windows XP (KB952954)
    / Windows XP / SP4: Security Update for Windows XP (KB953838)
    / Windows XP / SP4: Security Update for Windows XP (KB953839)
    / Windows XP / SP4: Security Update for Windows XP (KB954211)
    / Windows XP / SP4: Security Update for Windows XP (KB954600)
    / Windows XP / SP4: Security Update for Windows XP (KB955069)
    / Windows XP / SP4: Update for Windows XP (KB955839)
    / Windows XP / SP4: Security Update for Windows XP (KB956390)
    / Windows XP / SP4: Security Update for Windows XP (KB956391)
    / Windows XP / SP4: Security Update for Windows XP (KB956572)
    / Windows XP / SP4: Security Update for Windows XP (KB956802)
    / Windows XP / SP4: Security Update for Windows XP (KB956803)
    / Windows XP / SP4: Security Update for Windows XP (KB956841)
    / Windows XP / SP4: Security Update for Windows XP (KB957095)
    / Windows XP / SP4: Security Update for Windows XP (KB957097)
    / Windows XP / SP4: Security Update for Windows XP (KB958644)
    / Windows XP / SP4: Security Update for Windows XP (KB958687)
    / Windows XP / SP4: Security Update for Windows XP (KB958690)
    / Windows XP / SP4: Security Update for Windows XP (KB959426)
    / Windows XP / SP4: Security Update for Windows XP (KB960225)
    / Windows XP / SP4: Security Update for Windows XP (KB960715)
    / Windows XP / SP4: Security Update for Windows XP (KB960803)
    / Windows XP / SP4: Security Update for Windows XP (KB960859)
    / Windows XP / SP4: Security Update for Windows XP (KB961371)
    / Windows XP / SP4: Security Update for Windows XP (KB961373)
    / Windows XP / SP4: Security Update for Windows XP (KB961501)
    / Windows XP / SP4: Update for Windows XP (KB967715)
    / Windows XP / SP4: Security Update for Windows XP (KB968537)
    / Windows XP / SP4: Security Update for Windows XP (KB969898)
    / Windows XP / SP4: Security Update for Windows XP (KB970238)
    / Windows XP / SP4: Security Update for Windows XP (KB971557)
    / Windows XP / SP4: Security Update for Windows XP (KB971633)
    / Windows XP / SP4: Security Update for Windows XP (KB971657)
    / Windows XP / SP4: Security Update for Windows XP (KB973346)
    / Windows XP / SP4: Security Update for Windows XP (KB973354)
    / Windows XP / SP4: Security Update for Windows XP (KB973507)
    / Windows XP / SP4: Update for Windows XP (KB973815)
    / Windows XP / SP4: Security Update for Windows XP (KB973869)


    --- Startup entries list ---
    Located: HK_LM:Run,
    command:
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_LM:Run, Adobe Photo Downloader
    command: "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    file: C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    size: 63712
    MD5: FC9E59FE8BC4FE05382CFF5C8FC59DE1

    Located: HK_LM:Run, AlcxMonitor
    command: ALCXMNTR.EXE
    file: C:\WINDOWS\ALCXMNTR.EXE
    size: 57344
    MD5: 7B8875A5B04932AC73AFD8079864DB68

    Located: HK_LM:Run, AOLDialer
    command: C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    file: C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    size: 71216
    MD5: B9B78F0D9AEBCA8F717680FBABBB5FF4

    Located: HK_LM:Run, HostManager
    command: C:\Program Files\Common Files\AOL\1123605174\ee\AOLSoftware.exe
    file: C:\Program Files\Common Files\AOL\1123605174\ee\AOLSoftware.exe
    size: 41824
    MD5: 22870F235504152FE8873986A3D94905

    Located: HK_LM:Run, iTunesHelper
    command: "C:\Program Files\iTunes\iTunesHelper.exe"
    file: C:\Program Files\iTunes\iTunesHelper.exe
    size: 342312
    MD5: 6B0E8DEE62C0C9695C77F14482DDF178

    Located: HK_LM:Run, NvCplDaemon
    command: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    file: C:\WINDOWS\system32\NvCpl.dll
    size: 3026944
    MD5: 8054EC50CB36C3EFD5BD9CE920D91CAF

    Located: HK_LM:Run, Pure Networks Port Magic
    command: "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
    file: C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe
    size: 99480
    MD5: BA99C608A075C44026720D5383F3D75B

    Located: HK_LM:Run, QuickTime Task
    command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
    file: C:\Program Files\QuickTime\qttask.exe
    size: 413696
    MD5: 0AB3C83FCB8EF6F56E4FB22089F0D3B9

    Located: HK_LM:Run, Realtime Monitor
    command: C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
    file: C:\PROGRA~1\CA\ETRUST~1\realmon.exe
    size: 504080
    MD5: 7427E4995C12F12A0A8987A122C82E5D

    Located: HK_LM:Run, RealTray
    command: C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    file: C:\Program Files\Real\RealPlayer\RealPlay.exe
    size: 26112
    MD5: 849D97FE4CC09CFC2772D10F641E1BAF

    Located: HK_LM:Run, SunJavaUpdateSched
    command: "C:\Program Files\Java\jre6\bin\jusched.exe"
    file: C:\Program Files\Java\jre6\bin\jusched.exe
    size: 148888
    MD5: A2D390F1F2408B94EF34BFE3A00C29D3

    Located: HK_LM:Run, sysfbtray
    command:
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_LM:RunOnce, SpybotDeletingA2508
    command: command.com /c del "C:\WINDOWS\system32\xwreg32.dll_old"
    file: command.com /c del "C:\WINDOWS\system32\xwreg32.dll_old"
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_LM:RunOnce, SpybotDeletingC9588
    command: cmd.exe /c del "C:\WINDOWS\system32\xwreg32.dll_old"
    file: C:\WINDOWS\system32\cmd.exe
    size: 388608
    MD5: EEB024F2C81F0D55936FB825D21A91D6

    Located: HK_LM:RunOnceEx,
    command:
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_CU:Run, AdobeUpdater
    where: S-1-5-21-329068152-115176313-839522115-1003...
    command: C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
    file: C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
    size: 2321600
    MD5: CEBB4703FE0A875947E5F0A3A95FE577

    Located: HK_CU:Run, Aim6
    where: S-1-5-21-329068152-115176313-839522115-1003...
    command: "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    file: C:\Program Files\AIM6\aim6.exe
    size: 49968
    MD5: 5B4AF27E83DA8385A9B08E76DA730C91

    Located: HK_CU:Run, AOL Fast Start
    where: S-1-5-21-329068152-115176313-839522115-1003...
    command: "C:\Program Files\America Online 9.0\AOL.EXE" -b
    file: C:\Program Files\America Online 9.0\AOL.EXE
    size: 50776
    MD5: 9C4239915E23D7DF1DDFB88512C08249

    Located: HK_CU:Run, ctfmon.exe
    where: S-1-5-21-329068152-115176313-839522115-1003...
    command: C:\WINDOWS\system32\ctfmon.exe
    file: C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 24232996A38C0B0CF151C2140AE29FC8

    Located: HK_CU:Run, MSMSGS
    where: S-1-5-21-329068152-115176313-839522115-1003...
    command: "C:\Program Files\Messenger\msmsgs.exe" /background
    file: C:\Program Files\Messenger\msmsgs.exe
    size: 1694208
    MD5: 74E6E96C6F0E2ECA4EDBB7F7A468F259

    Located: HK_CU:Run, swg
    where: S-1-5-21-329068152-115176313-839522115-1003...
    command: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    file: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    size: 39408
    MD5: 5D61BE7DB55B026A5D61A3EED09D0EAD

    Located: HK_CU:RunOnce, SpybotDeletingB5270
    where: S-1-5-21-329068152-115176313-839522115-1003...
    command: command.com /c del "C:\WINDOWS\system32\xwreg32.dll_old"
    file: command.com /c del "C:\WINDOWS\system32\xwreg32.dll_old"
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_CU:RunOnce, SpybotDeletingD8486
    where: S-1-5-21-329068152-115176313-839522115-1003...
    command: cmd.exe /c del "C:\WINDOWS\system32\xwreg32.dll_old"
    file: C:\WINDOWS\system32\cmd.exe
    size: 388608
    MD5: EEB024F2C81F0D55936FB825D21A91D6

    Located: Startup (common), Belkin Wireless Client Utility.lnk
    where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
    command: C:\Program Files\Belkin\F5D9050\Belkinwcui.exe
    file: C:\Program Files\Belkin\F5D9050\Belkinwcui.exe
    size: 1585152
    MD5: 5B625A641E57EF161CA9AE5E1F7FB99C

    Located: Startup (user), ERUNT AutoBackup.lnk
    where: C:\Documents and Settings\user\Start Menu\Programs\Startup...
    command: C:\Program Files\ERUNT\AUTOBACK.EXE
    file: C:\Program Files\ERUNT\AUTOBACK.EXE
    size: 38912
    MD5: E00DE20F0F6BED5CD2160247DDC9443B

    Located: WinLogon, crypt32chain
    command: crypt32.dll
    file: crypt32.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, cryptnet
    command: cryptnet.dll
    file: cryptnet.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, cscdll
    command: cscdll.dll
    file: cscdll.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, ScCertProp
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, Schedule
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, sclgntfy
    command: sclgntfy.dll
    file: sclgntfy.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, SensLogn
    command: WlNotify.dll
    file: WlNotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, termsrv
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, WgaLogon
    command: WgaLogon.dll
    file: WgaLogon.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, wlballoon
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!



    --- Browser helper object list ---
    {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Spybot-S&D IE Protection
    description: Spybot-S&D IE Browser plugin
    classification: Legitimate
    known filename: SDhelper.dll
    info link: http://spybot.eon.net.au/
    info source: Patrick M. Kolla
    Path: C:\PROGRA~1\SPYBOT~1\
    Long name: SDHelper.dll
    Short name:
    Date (created): 7/14/2009 6:43:00 PM
    Date (last access): 8/20/2009 12:18:10 AM
    Date (last write): 1/26/2009 3:31:02 PM
    Filesize: 1879896
    Attributes: archive
    MD5: 022C2F6DCCDFA0AD73024D254E62AFAC
    CRC32: 5BA24007
    Version: 1.6.2.14

    {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Google Toolbar Notifier BHO
    Path: C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\
    Long name: swg.dll
    Short name:
    Date (created): 7/19/2009 7:29:54 PM
    Date (last access): 8/20/2009 12:18:02 AM
    Date (last write): 7/19/2009 7:29:56 PM
    Filesize: 669168
    Attributes: archive
    MD5: 7C987CAB519BC858FD4DBB6B40EE4BD2
    CRC32: 2CC83660
    Version: 5.1.1309.15642

    {DBC80044-A445-435b-BC74-9C25C1C588A9} (Java(tm) Plug-In 2 SSV Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Java(tm) Plug-In 2 SSV Helper
    Path: C:\Program Files\Java\jre6\bin\
    Long name: jp2ssv.dll
    Short name:
    Date (created): 8/10/2009 12:41:28 AM
    Date (last access): 8/20/2009 12:18:12 AM
    Date (last write): 8/10/2009 12:41:28 AM
    Filesize: 35840
    Attributes: archive
    MD5: 96A225C7F5346A9E81FC3DFA89A900C0
    CRC32: BAD5D2EF
    Version: 6.0.130.3

    {E7E6F031-17CE-4C07-BC86-EABFE594F69C} (JQSIEStartDetectorImpl)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name: JQSIEStartDetectorImpl
    CLSID name: JQSIEStartDetectorImpl Class
    Path: C:\Program Files\Java\jre6\lib\deploy\jqs\ie\
    Long name: jqs_plugin.dll
    Short name: JQS_PL~1.DLL
    Date (created): 8/10/2009 12:41:38 AM
    Date (last access): 8/20/2009 12:18:12 AM
    Date (last write): 8/10/2009 12:41:38 AM
    Filesize: 73728
    Attributes: archive
    MD5: 53F8B53918C839F76367B7E612B742B1
    CRC32: 735F7F91
    Version: 6.0.130.3



    --- ActiveX list ---
    {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control)
    DPF name:
    CLSID name: Facebook Photo Uploader 5 Control
    Installer: C:\WINDOWS\Downloaded Program Files\PhotoUploader5.inf
    Codebase: http://upload.facebook.com/controls/...oUploader5.cab
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: PhotoUploader5.ocx
    Short name: PHOTOU~1.OCX
    Date (created): 10/10/2008 3:44:58 PM
    Date (last access): 8/20/2009 12:59:28 AM
    Date (last write): 10/10/2008 3:44:58 PM
    Filesize: 3536384
    Attributes: archive
    MD5: 3F703EC5DB5638C08008132A78430136
    CRC32: AB0E6745
    Version: 5.5.8.0

    {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
    DPF name:
    CLSID name: Shockwave ActiveX Control
    Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
    Codebase: http://download.macromedia.com/pub/s...irector/sw.cab
    description: Macromedia ShockWave Flash Player 7
    classification: Legitimate
    known filename: SWDIR.DLL
    info link:
    info source: Patrick M. Kolla
    Path: C:\WINDOWS\system32\macromed\Director\
    Long name: SwDir.dll
    Short name:
    Date (created): 9/4/2006 8:52:50 PM
    Date (last access): 8/20/2009 12:59:28 AM
    Date (last write): 7/28/2006 9:06:12 AM
    Filesize: 54960
    Attributes:
    MD5: 14115D5C1DE5F3103C169B7F4D1D562A
    CRC32: 819F0513
    Version: 10.1.3.18

    {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control)
    DPF name:
    CLSID name: MySpace Uploader Control
    Installer: C:\WINDOWS\Downloaded Program Files\MySpaceUploader.inf
    Codebase: http://lads.myspace.com/upload/MySpaceUploader1006.cab
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: MySpaceUploader.ocx
    Short name: MYSPAC~1.OCX
    Date (created): 10/12/2007 7:59:12 AM
    Date (last access): 8/20/2009 12:59:28 AM
    Date (last write): 2/1/2008 4:17:04 AM
    Filesize: 2637440
    Attributes: archive
    MD5: 2245B3CAE09AF148D983F88F62153628
    CRC32: A47295FA
    Version: 1.0.0.6

    {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control)
    DPF name:
    CLSID name: Facebook Photo Uploader Control
    Installer: C:\WINDOWS\Downloaded Program Files\FacebookPhotoUploader.inf
    Codebase: http://upload.facebook.com/controls/...toUploader.cab
    description:
    classification: Open for discussion
    known filename: FacebookPhotoUploader.ocx
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: FacebookPhotoUploader.ocx
    Short name: FACEBO~1.OCX
    Date (created): 11/3/2005 9:17:36 PM
    Date (last access): 8/20/2009 12:59:28 AM
    Date (last write): 11/3/2005 9:17:36 PM
    Filesize: 1935120
    Attributes: archive
    MD5: 5A39F109CB87893FD683F49699BCE2B4
    CRC32: 729D4EBC
    Version: 3.5.122.2

    {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
    DPF name:
    CLSID name: WUWebControl Class
    Installer: C:\WINDOWS\Downloaded Program Files\wuweb.inf
    Codebase: http://update.microsoft.com/windowsu...?1123602472012
    description:
    classification: Legitimate
    known filename: wuweb.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\system32\
    Long name: wuweb.dll
    Short name:
    Date (created): 8/9/2005 11:36:32 AM
    Date (last access): 8/20/2009 12:51:48 AM
    Date (last write): 10/16/2008 3:13:40 PM
    Filesize: 202776
    Attributes: archive
    MD5: 1865594AFE88C27A127FF4CF492734B0
    CRC32: F48FD025
    Version: 7.2.6001.788

    {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_13
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    description: Sun Java
    classification: Legitimate
    known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
    info link:
    info source: Patrick M. Kolla
    Path: C:\Program Files\Java\jre6\bin\
    Long name: npjpi160_13.dll
    Short name: NPJPI1~1.DLL
    Date (created): 8/10/2009 12:41:32 AM
    Date (last access): 8/20/2009 12:59:30 AM
    Date (last write): 8/10/2009 12:41:32 AM
    Filesize: 136600
    Attributes: archive
    MD5: 20188EB1790C5EB9057DDFE3EA138FC7
    CRC32: 2EA1ACCF
    Version: 6.0.130.3

    {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ()
    DPF name:
    CLSID name:
    Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
    Codebase: http://fpdownload.macromedia.com/get.../ultrashim.cab
    description:
    classification: Open for discussion
    known filename:
    info link:
    info source: Safer Networking Ltd.

    {A762E064-A885-40E4-AC10-671BB62DC2B2} (OFMailHTMLCtl Class)
    DPF name:
    CLSID name: OFMailHTMLCtl Class
    Installer: C:\WINDOWS\Downloaded Program Files\OFMailX.inf
    Codebase: http://www.eomniform.com/OF5/nsplugins/OFMailX.cab
    Path: C:\WINDOWS\system32\
    Long name: OFMailX.dll
    Short name:
    Date (created): 1/10/2002 7:56:44 PM
    Date (last access): 8/20/2009 12:50:40 AM
    Date (last write): 1/10/2002 7:56:44 PM
    Filesize: 61440
    Attributes: archive
    MD5: 99BEFB47025429FCEC25934CE1E56351
    CRC32: 827F0F73
    Version: 5.0.1.0

    {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
    DPF name: Java Runtime Environment 1.5.0
    CLSID name: Java Plug-in 1.5.0_01
    Installer:
    Codebase: http://java.sun.com/update/1.5.0/jin...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: NPJPI150_01.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre1.5.0_01\bin\
    Long name: NPJPI150_01.dll
    Short name: NPJPI1~1.DLL
    Date (created): 12/6/2068 9:31:52 PM
    Date (last access): 8/20/2009 12:59:30 AM
    Date (last write): 12/6/2004 9:49:16 PM
    Filesize: 69746
    Attributes: archive
    MD5: 7B8F5AAF633987C6F1B88146357D04E5
    CRC32: AD99524A
    Version: 1.5.0.10

    {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
    DPF name: Java Runtime Environment 1.5.0
    CLSID name: Java Plug-in 1.5.0_12
    Installer:
    Codebase: http://java.sun.com/update/1.5.0/jin...ndows-i586.cab
    Path: C:\Program Files\Java\jre1.5.0_12\bin\
    Long name: NPJPI150_12.dll
    Short name: NPJPI1~1.DLL
    Date (created): 5/2/2007 5:01:22 AM
    Date (last access): 8/20/2009 12:59:30 AM
    Date (last write): 5/2/2007 5:15:48 AM
    Filesize: 75528
    Attributes: archive
    MD5: 9256073CD6FC98B5F37167AE3E1906E6
    CRC32: E62CC94E
    Version: 5.0.120.4

    {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_13
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    Path: C:\Program Files\Java\jre6\bin\
    Long name: npjpi160_13.dll
    Short name: NPJPI1~1.DLL
    Date (created): 8/10/2009 12:41:32 AM
    Date (last access): 8/20/2009 12:59:30 AM
    Date (last write): 8/10/2009 12:41:32 AM
    Filesize: 136600
    Attributes: archive
    MD5: 20188EB1790C5EB9057DDFE3EA138FC7
    CRC32: 2EA1ACCF
    Version: 6.0.130.3

    {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_13
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: npjpi150_06.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre6\bin\
    Long name: npjpi160_13.dll
    Short name: NPJPI1~1.DLL
    Date (created): 8/10/2009 12:41:32 AM
    Date (last access): 8/20/2009 12:59:30 AM
    Date (last write): 8/10/2009 12:41:32 AM
    Filesize: 136600
    Attributes: archive
    MD5: 20188EB1790C5EB9057DDFE3EA138FC7
    CRC32: 2EA1ACCF
    Version: 6.0.130.3

    {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class)
    DPF name:
    CLSID name: get_atlcom Class
    Installer: C:\WINDOWS\Downloaded Program Files\gp.inf
    Codebase: http://www.adobe.com/products/acrobat/nos/gp.cab
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: gp.ocx
    Short name:
    Date (created): 5/16/2007 8:22:06 AM
    Date (last access): 8/20/2009 12:59:30 AM
    Date (last write): 5/16/2007 8:22:06 AM
    Filesize: 166512
    Attributes: archive
    MD5: 9BCFC46ECA1BF28E039ECCE2D331086E
    CRC32: A9C6ED85
    Version: 1.2.2.50

    {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
    DPF name:
    CLSID name: Shockwave Flash Object
    Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf
    Codebase: http://fpdownload.macromedia.com/get...nt/swflash.cab
    description: Macromedia Shockwave Flash Player
    classification: Legitimate
    known filename:
    info link:
    info source: Patrick M. Kolla
    Path: C:\WINDOWS\system32\Macromed\Flash\
    Long name: Flash10b.ocx
    Short name:
    Date (created): 2/2/2009 10:07:18 PM
    Date (last access): 8/20/2009 12:59:30 AM
    Date (last write): 2/2/2009 10:07:18 PM
    Filesize: 3866528
    Attributes: readonly archive
    MD5: 8AFC17155ED5AB60B7C52D7F553D579C
    CRC32: 0FBC13F3
    Version: 10.0.22.87

    {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4)
    DPF name:
    CLSID name: Facebook Photo Uploader 4
    Installer: C:\WINDOWS\Downloaded Program Files\ImageUploader4_5.inf
    Codebase: http://upload.facebook.com/controls/...ploader4_5.cab
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: ImageUploader4_5.ocx
    Short name: IMAGEU~3.OCX
    Date (created): 3/20/2008 6:10:34 PM
    Date (last access): 8/20/2009 12:59:30 AM
    Date (last write): 3/20/2008 6:10:34 PM
    Filesize: 2672136
    Attributes: archive
    MD5: AF52969832631A3645156FCCA5DB75A9
    CRC32: F21C131B
    Version: 4.5.57.2

    {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class)
    DPF name:
    CLSID name: Photo Upload Plugin Class
    Installer: C:\WINDOWS\Downloaded Program Files\PCAXSetup.inf
    Codebase: http://cvs.pnimedia.com/upload/activ...v2.0.0.10.cab?
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: Photochannel.dll
    Short name: PHOTOC~1.DLL
    Date (created): 5/15/2007 8:27:48 AM
    Date (last access): 8/20/2009 12:59:30 AM
    Date (last write): 5/15/2007 8:27:48 AM
    Filesize: 290816
    Attributes: archive
    MD5: 4F5B494D4AC0D06BE28775A8EE17E4CE
    CRC32: 47538ECC
    Version: 2.0.0.10



    --- Process list ---
    PID: 0 ( 0) [System]
    PID: 648 ( 4) \SystemRoot\System32\smss.exe
    size: 50688
    PID: 712 ( 648) \??\C:\WINDOWS\system32\csrss.exe
    size: 6144
    PID: 736 ( 648) \??\C:\WINDOWS\system32\winlogon.exe
    size: 502272
    PID: 780 ( 736) C:\WINDOWS\system32\services.exe
    size: 110592
    MD5: 37561F8D4160D62DA86D24AE41FAE8DE
    PID: 792 ( 736) C:\WINDOWS\system32\lsass.exe
    size: 13312
    MD5: 84885F9B82F4D55C6146EBF6065D75D2
    PID: 960 ( 780) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 1008 ( 780) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 1048 ( 780) C:\WINDOWS\System32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 1160 ( 780) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 1196 ( 780) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 1384 ( 780) C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    size: 1029456
    MD5: CC7D978C4F56FB434E841D35788A7F3C
    PID: 1540 ( 780) C:\WINDOWS\system32\spoolsv.exe
    size: 57856
    MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
    PID: 1652 ( 780) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 1688 ( 780) C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    size: 46640
    MD5: 85180CF88C5EBAD73B452A43A004CA51
    PID: 1764 ( 780) C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    size: 100016
    MD5: 7FB54900AA9792AB6307C699EC1859D4
    PID: 1800 ( 780) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    size: 132424
    MD5: 43DC4FC662DF064535E30B17C8B5AB00
    PID: 1824 ( 780) C:\Program Files\Bonjour\mDNSResponder.exe
    size: 238888
    MD5: 3F56903E124E820AEECE6D471583C6C1
    PID: 1856 (1764) C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
    size: 46768
    MD5: CAF7C2FDDADF73A02AC84C6FB6030BBF
    PID: 1868 ( 780) C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
    size: 143360
    MD5: A46BE7F60BB9B16A193B17B0FB5A7B32
    PID: 1932 ( 780) C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
    size: 139536
    MD5: 41C76C4F92254258363A5C280FA6544E
    PID: 1980 ( 780) C:\Program Files\CA\eTrust Antivirus\InoRT.exe
    size: 241936
    MD5: 2A58D93145A6971EAC9193E36EFBCB56
    PID: 2016 ( 780) C:\Program Files\CA\eTrust Antivirus\InoTask.exe
    size: 254224
    MD5: 201ABCC43FABA972B0FD841BFF9CDC05
    PID: 168 ( 780) C:\Program Files\Java\jre6\bin\jqs.exe
    size: 152984
    MD5: 890369AED0DDE1A98F09F7DC239CA2BD
    PID: 208 ( 780) C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
    size: 53248
    MD5: 850A7A21661B97583914A430E9C2DAEA
    PID: 240 ( 780) C:\WINDOWS\system32\nvsvc32.exe
    size: 77824
    MD5: 2CA62BC8F42E2690DA1EB8EA75AD2D99
    PID: 424 ( 780) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 8F078AE4ED187AAABC0A305146DE6716
    PID: 1076 ( 924) C:\WINDOWS\Explorer.EXE
    size: 1033216
    MD5: 97BD6515465659FF8F3B7BE375B2EA87
    PID: 1320 ( 780) C:\WINDOWS\System32\alg.exe
    size: 44544
    MD5: F1958FBF86D5C004CF19A5951A9514B7
    PID: 3140 (1076) C:\WINDOWS\ALCXMNTR.EXE
    size: 57344
    MD5: 7B8875A5B04932AC73AFD8079864DB68
    PID: 3156 (1076) C:\PROGRA~1\CA\ETRUST~1\realmon.exe
    size: 504080
    MD5: 7427E4995C12F12A0A8987A122C82E5D
    PID: 3164 (1076) C:\Program Files\Common Files\AOL\1123605174\ee\AOLSoftware.exe
    size: 41824
    MD5: 22870F235504152FE8873986A3D94905
    PID: 3180 (1076) C:\Program Files\Real\RealPlayer\RealPlay.exe
    size: 26112
    MD5: 849D97FE4CC09CFC2772D10F641E1BAF
    PID: 3196 (1076) C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    size: 63712
    MD5: FC9E59FE8BC4FE05382CFF5C8FC59DE1
    PID: 3232 (1076) C:\Program Files\Java\jre6\bin\jusched.exe
    size: 148888
    MD5: A2D390F1F2408B94EF34BFE3A00C29D3
    PID: 3248 (3188) C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe
    size: 99480
    MD5: BA99C608A075C44026720D5383F3D75B
    PID: 3328 (1076) C:\Program Files\iTunes\iTunesHelper.exe
    size: 342312
    MD5: 6B0E8DEE62C0C9695C77F14482DDF178
    PID: 3340 (1076) C:\Program Files\Messenger\msmsgs.exe
    size: 1694208
    MD5: 74E6E96C6F0E2ECA4EDBB7F7A468F259
    PID: 3420 (1076) C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 24232996A38C0B0CF151C2140AE29FC8
    PID: 3432 (1076) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    size: 39408
    MD5: 5D61BE7DB55B026A5D61A3EED09D0EAD
    PID: 3904 (3456) C:\Program Files\America Online 9.0\waol.exe
    size: 37464
    MD5: 7FAB3C273C8214D517BDD0CBD2BA1815
    PID: 500 (1076) C:\Program Files\Belkin\F5D9050\Belkinwcui.exe
    size: 1585152
    MD5: 5B625A641E57EF161CA9AE5E1F7FB99C
    PID: 2764 ( 780) C:\Program Files\iPod\bin\iPodService.exe
    size: 656168
    MD5: F055C1760ABFA52B159985E551EA0EDC
    PID: 2940 (3164) c:\program files\common files\aol\1123605174\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
    size: 1536
    MD5: 87A2CD3AD5BF4F57C0DF046CC3A8C5A7
    PID: 3024 (3164) C:\Program Files\Common Files\AOL\1123605174\EE\aolsoftware.exe
    size: 41824
    MD5: 22870F235504152FE8873986A3D94905
    PID: 2844 (1048) C:\WINDOWS\system32\wuauclt.exe
    size: 51224
    MD5: E654B78D2F1D791B30D0ED9A8195EC22
    PID: 3936 (1384) C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    size: 520024
    MD5: 2CD3C21B57B2B1E5CC4C82519461C9D2
    PID: 2808 (3904) C:\Program Files\America Online 9.0\shellmon.exe
    size: 54872
    MD5: F093707C39B3B38653CDB94C85A80772
    PID: 988 (1076) C:\Program Files\Internet Explorer\iexplore.exe
    size: 638816
    MD5: B60DDDD2D63CE41CB8C487FCFBB6419E
    PID: 1112 ( 988) C:\Program Files\Internet Explorer\iexplore.exe
    size: 638816
    MD5: B60DDDD2D63CE41CB8C487FCFBB6419E
    PID: 3404 (1076) C:\Program Files\Internet Explorer\iexplore.exe
    size: 638816
    MD5: B60DDDD2D63CE41CB8C487FCFBB6419E
    PID: 3828 (3404) C:\Program Files\Internet Explorer\iexplore.exe
    size: 638816
    MD5: B60DDDD2D63CE41CB8C487FCFBB6419E
    PID: 1516 (1076) C:\Program Files\Internet Explorer\iexplore.exe
    size: 638816
    MD5: B60DDDD2D63CE41CB8C487FCFBB6419E
    PID: 1480 (1516) C:\Program Files\Internet Explorer\iexplore.exe
    size: 638816
    MD5: B60DDDD2D63CE41CB8C487FCFBB6419E
    PID: 456 (3112) C:\Program Files\Internet Explorer\IEXPLORE.EXE
    size: 638816
    MD5: B60DDDD2D63CE41CB8C487FCFBB6419E
    PID: 1700 ( 456) C:\Program Files\Internet Explorer\IEXPLORE.EXE
    size: 638816
    MD5: B60DDDD2D63CE41CB8C487FCFBB6419E
    PID: 2364 (2948) C:\Program Files\Internet Explorer\IEXPLORE.EXE
    size: 638816
    MD5: B60DDDD2D63CE41CB8C487FCFBB6419E
    PID: 3900 (2364) C:\Program Files\Internet Explorer\IEXPLORE.EXE
    size: 638816
    MD5: B60DDDD2D63CE41CB8C487FCFBB6419E
    PID: 3580 (1076) C:\Program Files\Internet Explorer\iexplore.exe
    size: 638816
    MD5: B60DDDD2D63CE41CB8C487FCFBB6419E
    PID: 2212 (3580) C:\Program Files\Internet Explorer\iexplore.exe
    size: 638816
    MD5: B60DDDD2D63CE41CB8C487FCFBB6419E
    PID: 4220 (1076) C:\Program Files\Internet Explorer\iexplore.exe
    size: 638816
    MD5: B60DDDD2D63CE41CB8C487FCFBB6419E
    PID: 5400 (4220) C:\Program Files\Internet Explorer\iexplore.exe
    size: 638816
    MD5: B60DDDD2D63CE41CB8C487FCFBB6419E
    PID: 4224 ( 960) c:\program files\aim toolbar\aimtbServer.exe
    size: 140584
    MD5: 082B255C97B4729E9ABBC19C4145D2C7
    PID: 5476 (1076) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    size: 5365592
    MD5: 0477C2F9171599CA5BC3307FDFBA8D89
    PID: 4 ( 0) System
    PID: 5512 (1048) C:\WINDOWS\system32\wuauclt.exe
    size: 51224
    MD5: E654B78D2F1D791B30D0ED9A8195EC22


    --- Browser start & search pages list ---
    Spybot - Search & Destroy browser pages report, 8/20/2009 1:16:33 AM

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\WINDOWS\system32\blank.htm
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
    http://www.google.com
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
    http://www.google.com/ie
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
    http://www.google.com/
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\WINDOWS\system32\blank.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
    http://go.microsoft.com/fwlink/?LinkId=54896
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
    http://go.microsoft.com/fwlink/?LinkId=69157
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
    http://go.microsoft.com/fwlink/?LinkId=69157
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
    http://go.microsoft.com/fwlink/?LinkId=54896
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
    http://www.google.com
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
    http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


    --- Winsock Layered Service Provider list ---
    Protocol 0: MSAFD Tcpip [TCP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 1: MSAFD Tcpip [UDP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 2: MSAFD Tcpip [RAW/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 3: RSVP UDP Service Provider
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\rsvpsp.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 4: RSVP TCP Service Provider
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\rsvpsp.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{50C1B448-EA68-46AA-A9B0-DCB87FF93716}] SEQPACKET 8
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{50C1B448-EA68-46AA-A9B0-DCB87FF93716}] DATAGRAM 8
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E8B0395E-C150-4C68-830C-8B3CFD552C30}] SEQPACKET 7
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E8B0395E-C150-4C68-830C-8B3CFD552C30}] DATAGRAM 7
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{8DF178DC-769A-4B3C-8CF7-577B3BC5CC9F}] SEQPACKET 6
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{8DF178DC-769A-4B3C-8CF7-577B3BC5CC9F}] DATAGRAM 6
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{367CE849-25D8-4C85-83FF-148336F7665C}] SEQPACKET 0
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{367CE849-25D8-4C85-83FF-148336F7665C}] DATAGRAM 0
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{446600A5-56D9-45D2-BEDC-6E63D0722E58}] SEQPACKET 1
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{446600A5-56D9-45D2-BEDC-6E63D0722E58}] DATAGRAM 1
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4B8026A7-DFD4-4D5F-BC41-5D4DF7A3808A}] SEQPACKET 2
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{4B8026A7-DFD4-4D5F-BC41-5D4DF7A3808A}] DATAGRAM 2
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E86B6CFD-9DE1-4DDC-96FB-892FA03C8CE5}] SEQPACKET 3
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 18: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E86B6CFD-9DE1-4DDC-96FB-892FA03C8CE5}] DATAGRAM 3
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 19: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B09BF15-4FF0-4987-8175-B022FDA60E6F}] SEQPACKET 4
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 20: MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B09BF15-4FF0-4987-8175-B022FDA60E6F}] DATAGRAM 4
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 21: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3312A3CD-3AEF-4497-93BB-32D7C3E537DD}] SEQPACKET 5
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 22: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3312A3CD-3AEF-4497-93BB-32D7C3E537DD}] DATAGRAM 5
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Namespace Provider 0: Tcpip
    GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
    Filename: %SystemRoot%\System32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: TCP/IP

    Namespace Provider 1: NTDS
    GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
    Filename: %SystemRoot%\System32\winrnr.dll
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\winrnr.dll
    DB protocol: NTDS

    Namespace Provider 2: Network Location Awareness (NLA) Namespace
    GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
    Filename: %SystemRoot%\System32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: NLA-Namespace

    Namespace Provider 3: mdnsNSP
    GUID: {B600E6E9-553B-4A19-8696-335E5C896153}
    Filename: C:\Program Files\Bonjour\mdnsNSP.dll
    Description: Apple Rendezvous protocol
    DB filename: %ProgramFiles%\Rendezvous\bin\mdnsNSP.dll
    DB protocol: mdnsNSP

  4. #4
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Please download DDS ... by sUBs.
    Save it to your desktop. Alternate download link:here.
    1. Double click the tool to run it.
    2. A black Screen will open... read the contents but do nothing.
    3. When DDS finishes... Notepad will open with 2 reports... DDS.txt and Attach.txt
      Ignore the comments about zipping / attaching any of the report files. The 2 report files are not saved anywhere,
      if you close Notepad, before copying /pasting them... you will need to run DDS again.
    4. Copy/paste both DDS.txt and Attach.txt reports in your next reply.
    5. Once the reports have been posted, you can delete DDS from your desktop.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  5. #5
    Junior Member
    Join Date
    Aug 2009
    Posts
    15

    Default

    Ok here the the DDS report


    DDS (Ver_09-07-30.01) - NTFSx86
    Run by user at 9:17:11.21 on Thu 08/20/2009
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.5.0_12

    ============== Running Processes ===============


    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = *.local
    mSearchAssistant = hxxp://www.google.com
    uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
    uURLSearchHooks: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aol search\AOLSearch.dll
    mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File
    TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
    TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
    EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp
    uRun: [AdobeUpdater] c:\program files\common files\adobe\updater5\AdobeUpdater.exe
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    uRun: [AOL Fast Start] "c:\program files\america online 9.0\AOL.EXE" -b
    mRun: [AlcxMonitor] ALCXMNTR.EXE
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [Realtime Monitor] c:\progra~1\ca\etrust~1\realmon.exe -s
    mRun: [<NO NAME>]
    mRun: [HostManager] c:\program files\common files\aol\1123605174\ee\AOLSoftware.exe
    mRun: [AOLDialer] c:\program files\common files\aol\acs\AOLDial.exe
    mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    mRun: [Pure Networks Port Magic] "c:\progra~1\purene~1\portma~1\PortAOL.exe" -Run
    mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [sysfbtray]
    StartupFolder: c:\docume~1\user\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\belkin~1.lnk - c:\program files\belkin\f5d9050\Belkinwcui.exe
    uPolicies-system: EnableProfileQuota = 1 (0x1)
    IE: &AIM Toolbar Search - c:\documents and settings\all users\application data\aim toolbar\ietoolbar\resources\en-us\local\search.html
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    Trusted Zone: turbotax.com
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
    DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123602472012
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {A762E064-A885-40E4-AC10-671BB62DC2B2} - hxxp://www.eomniform.com/OF5/nsplugins/OFMailX.cab
    DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://www.adobe.com/products/acrobat/nos/gp.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
    DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} - hxxp://cvs.pnimedia.com/upload/activex/v2_0_0_10/PCAXSetupv2.0.0.10.cab?
    TCP: {367CE849-25D8-4C85-83FF-148336F7665C} = 69.18.136.8
    Filter: text/html - {e2a9c2cf-f792-40ec-bdd8-fcd2b624dbe3} -
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll

    ============= SERVICES / DRIVERS ===============


    =============== Created Last 30 ================

    2009-08-20 01:15 94 a------- c:\windows\wininit.ini
    2009-08-17 18:37 <DIR> --d-h--- c:\windows\system32\GroupPolicy
    2009-08-17 01:15 <DIR> --d----- c:\program files\Trend Micro
    2009-08-13 00:01 <DIR> --dsh--- c:\documents and settings\user\IECompatCache
    2009-08-12 18:50 <DIR> --dsh--- c:\documents and settings\user\PrivacIE
    2009-08-12 18:41 <DIR> --dsh--- c:\documents and settings\user\IETldCache
    2009-08-12 18:36 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
    2009-08-12 18:36 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
    2009-08-12 18:36 <DIR> --d----- c:\windows\ie8updates
    2009-08-12 18:34 101,376 -c------ c:\windows\system32\dllcache\iecompat.dll
    2009-08-12 18:32 <DIR> -cd-h--- c:\windows\ie8
    2009-08-12 00:55 <DIR> --d----- c:\windows\ServicePackFiles
    2009-08-10 00:43 73,728 a------- c:\windows\system32\javacpl.cpl
    2009-08-10 00:43 410,984 a------- c:\windows\system32\deploytk.dll
    2009-07-22 20:52 <DIR> --d----- c:\program files\Shared

    ==================== Find3M ====================

    2009-08-05 05:11 204,800 a------- c:\windows\system32\mswebdvd.dll
    2009-07-17 14:55 58,880 a------- c:\windows\system32\atl.dll
    2009-07-14 00:49 16,266 a------- c:\windows\system32\vimiqis.vbs
    2009-07-13 20:00 18,785 a------- c:\program files\common files\hobis.db
    2009-07-13 20:00 18,418 a------- c:\program files\common files\sumofuvuba.vbs
    2009-07-13 20:00 17,692 a------- c:\program files\common files\agikojycym.scr
    2009-07-13 20:00 15,116 a------- c:\program files\common files\befocyb.vbs
    2009-07-13 20:00 12,229 a------- c:\docume~1\alluse~1\applic~1\awykizihe.dat
    2009-07-13 20:00 12,083 a------- c:\docume~1\alluse~1\applic~1\yqigy.bin
    2009-07-13 20:00 10,748 a------- c:\windows\system32\afulylafys.dll
    2009-07-13 19:52 11,264 a------- C:\benfuse.exe
    2009-07-13 02:18 233,472 a------- c:\windows\system32\wmpdxm.dll
    2009-07-03 13:09 915,456 a------- c:\windows\system32\wininet.dll
    2009-07-03 10:49 64,160 a------- c:\windows\system32\drivers\Lbd.sys
    2009-07-03 10:49 15,688 a------- c:\windows\system32\lsdelete.exe
    2009-06-25 14:36 661,504 a------- c:\windows\system32\mqqm.dll
    2009-06-25 14:36 517,120 a------- c:\windows\system32\mqsnap.dll
    2009-06-25 14:36 471,552 a------- c:\windows\system32\mqutil.dll
    2009-06-25 14:36 225,280 a------- c:\windows\system32\mqoa.dll
    2009-06-25 14:36 186,880 a------- c:\windows\system32\mqtrig.dll
    2009-06-25 14:36 177,152 a------- c:\windows\system32\mqrt.dll
    2009-06-25 14:36 138,240 a------- c:\windows\system32\mqad.dll
    2009-06-25 14:36 123,392 a------- c:\windows\system32\mqrtdep.dll
    2009-06-25 14:36 95,744 a------- c:\windows\system32\mqsec.dll
    2009-06-25 14:36 48,640 a------- c:\windows\system32\mqupgrd.dll
    2009-06-25 14:36 47,104 a------- c:\windows\system32\mqdscli.dll
    2009-06-25 14:36 16,896 a------- c:\windows\system32\mqise.dll
    2009-06-22 07:49 117,248 a------- c:\windows\system32\mqtgsvc.exe
    2009-06-22 07:49 19,968 a------- c:\windows\system32\mqbkup.exe
    2009-06-22 07:49 4,608 a------- c:\windows\system32\mqsvc.exe
    2009-06-22 07:48 91,776 a------- c:\windows\system32\drivers\mqac.sys
    2009-06-16 10:55 119,808 a------- c:\windows\system32\t2embed.dll
    2009-06-16 10:55 82,432 a------- c:\windows\system32\fontsub.dll
    2009-06-12 07:50 80,896 a------- c:\windows\system32\tlntsess.exe
    2009-06-12 07:50 76,288 a------- c:\windows\system32\telnet.exe
    2009-06-10 10:21 84,992 a------- c:\windows\system32\avifil32.dll
    2009-06-10 02:32 132,096 a------- c:\windows\system32\wkssvc.dll
    2009-06-05 03:42 655,872 a------- c:\windows\system32\mstscax.dll
    2009-06-03 15:27 1,290,752 a------- c:\windows\system32\quartz.dll
    2008-12-11 11:05 721,912 a------- c:\documents and settings\user\gotomypc_428.exe
    2007-05-22 05:52 56 ---shr-- c:\windows\system\WINAPPDB.DAT

    ============= FINISH: 9:18:07.03 ===============

    And here is the Attach report


    DDS (Ver_09-07-30.01) - NTFSx86
    Run by user at 9:17:11.21 on Thu 08/20/2009
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.5.0_12

    ============== Running Processes ===============


    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = *.local
    mSearchAssistant = hxxp://www.google.com
    uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
    uURLSearchHooks: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aol search\AOLSearch.dll
    mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File
    TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
    TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
    EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp
    uRun: [AdobeUpdater] c:\program files\common files\adobe\updater5\AdobeUpdater.exe
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    uRun: [AOL Fast Start] "c:\program files\america online 9.0\AOL.EXE" -b
    mRun: [AlcxMonitor] ALCXMNTR.EXE
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [Realtime Monitor] c:\progra~1\ca\etrust~1\realmon.exe -s
    mRun: [<NO NAME>]
    mRun: [HostManager] c:\program files\common files\aol\1123605174\ee\AOLSoftware.exe
    mRun: [AOLDialer] c:\program files\common files\aol\acs\AOLDial.exe
    mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    mRun: [Pure Networks Port Magic] "c:\progra~1\purene~1\portma~1\PortAOL.exe" -Run
    mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [sysfbtray]
    StartupFolder: c:\docume~1\user\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\belkin~1.lnk - c:\program files\belkin\f5d9050\Belkinwcui.exe
    uPolicies-system: EnableProfileQuota = 1 (0x1)
    IE: &AIM Toolbar Search - c:\documents and settings\all users\application data\aim toolbar\ietoolbar\resources\en-us\local\search.html
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    Trusted Zone: turbotax.com
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
    DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123602472012
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {A762E064-A885-40E4-AC10-671BB62DC2B2} - hxxp://www.eomniform.com/OF5/nsplugins/OFMailX.cab
    DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://www.adobe.com/products/acrobat/nos/gp.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
    DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} - hxxp://cvs.pnimedia.com/upload/activex/v2_0_0_10/PCAXSetupv2.0.0.10.cab?
    TCP: {367CE849-25D8-4C85-83FF-148336F7665C} = 69.18.136.8
    Filter: text/html - {e2a9c2cf-f792-40ec-bdd8-fcd2b624dbe3} -
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll

    ============= SERVICES / DRIVERS ===============


    =============== Created Last 30 ================

    2009-08-20 01:15 94 a------- c:\windows\wininit.ini
    2009-08-17 18:37 <DIR> --d-h--- c:\windows\system32\GroupPolicy
    2009-08-17 01:15 <DIR> --d----- c:\program files\Trend Micro
    2009-08-13 00:01 <DIR> --dsh--- c:\documents and settings\user\IECompatCache
    2009-08-12 18:50 <DIR> --dsh--- c:\documents and settings\user\PrivacIE
    2009-08-12 18:41 <DIR> --dsh--- c:\documents and settings\user\IETldCache
    2009-08-12 18:36 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
    2009-08-12 18:36 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
    2009-08-12 18:36 <DIR> --d----- c:\windows\ie8updates
    2009-08-12 18:34 101,376 -c------ c:\windows\system32\dllcache\iecompat.dll
    2009-08-12 18:32 <DIR> -cd-h--- c:\windows\ie8
    2009-08-12 00:55 <DIR> --d----- c:\windows\ServicePackFiles
    2009-08-10 00:43 73,728 a------- c:\windows\system32\javacpl.cpl
    2009-08-10 00:43 410,984 a------- c:\windows\system32\deploytk.dll
    2009-07-22 20:52 <DIR> --d----- c:\program files\Shared

    ==================== Find3M ====================

    2009-08-05 05:11 204,800 a------- c:\windows\system32\mswebdvd.dll
    2009-07-17 14:55 58,880 a------- c:\windows\system32\atl.dll
    2009-07-14 00:49 16,266 a------- c:\windows\system32\vimiqis.vbs
    2009-07-13 20:00 18,785 a------- c:\program files\common files\hobis.db
    2009-07-13 20:00 18,418 a------- c:\program files\common files\sumofuvuba.vbs
    2009-07-13 20:00 17,692 a------- c:\program files\common files\agikojycym.scr
    2009-07-13 20:00 15,116 a------- c:\program files\common files\befocyb.vbs
    2009-07-13 20:00 12,229 a------- c:\docume~1\alluse~1\applic~1\awykizihe.dat
    2009-07-13 20:00 12,083 a------- c:\docume~1\alluse~1\applic~1\yqigy.bin
    2009-07-13 20:00 10,748 a------- c:\windows\system32\afulylafys.dll
    2009-07-13 19:52 11,264 a------- C:\benfuse.exe
    2009-07-13 02:18 233,472 a------- c:\windows\system32\wmpdxm.dll
    2009-07-03 13:09 915,456 a------- c:\windows\system32\wininet.dll
    2009-07-03 10:49 64,160 a------- c:\windows\system32\drivers\Lbd.sys
    2009-07-03 10:49 15,688 a------- c:\windows\system32\lsdelete.exe
    2009-06-25 14:36 661,504 a------- c:\windows\system32\mqqm.dll
    2009-06-25 14:36 517,120 a------- c:\windows\system32\mqsnap.dll
    2009-06-25 14:36 471,552 a------- c:\windows\system32\mqutil.dll
    2009-06-25 14:36 225,280 a------- c:\windows\system32\mqoa.dll
    2009-06-25 14:36 186,880 a------- c:\windows\system32\mqtrig.dll
    2009-06-25 14:36 177,152 a------- c:\windows\system32\mqrt.dll
    2009-06-25 14:36 138,240 a------- c:\windows\system32\mqad.dll
    2009-06-25 14:36 123,392 a------- c:\windows\system32\mqrtdep.dll
    2009-06-25 14:36 95,744 a------- c:\windows\system32\mqsec.dll
    2009-06-25 14:36 48,640 a------- c:\windows\system32\mqupgrd.dll
    2009-06-25 14:36 47,104 a------- c:\windows\system32\mqdscli.dll
    2009-06-25 14:36 16,896 a------- c:\windows\system32\mqise.dll
    2009-06-22 07:49 117,248 a------- c:\windows\system32\mqtgsvc.exe
    2009-06-22 07:49 19,968 a------- c:\windows\system32\mqbkup.exe
    2009-06-22 07:49 4,608 a------- c:\windows\system32\mqsvc.exe
    2009-06-22 07:48 91,776 a------- c:\windows\system32\drivers\mqac.sys
    2009-06-16 10:55 119,808 a------- c:\windows\system32\t2embed.dll
    2009-06-16 10:55 82,432 a------- c:\windows\system32\fontsub.dll
    2009-06-12 07:50 80,896 a------- c:\windows\system32\tlntsess.exe
    2009-06-12 07:50 76,288 a------- c:\windows\system32\telnet.exe
    2009-06-10 10:21 84,992 a------- c:\windows\system32\avifil32.dll
    2009-06-10 02:32 132,096 a------- c:\windows\system32\wkssvc.dll
    2009-06-05 03:42 655,872 a------- c:\windows\system32\mstscax.dll
    2009-06-03 15:27 1,290,752 a------- c:\windows\system32\quartz.dll
    2008-12-11 11:05 721,912 a------- c:\documents and settings\user\gotomypc_428.exe
    2007-05-22 05:52 56 ---shr-- c:\windows\system\WINAPPDB.DAT

    ============= FINISH: 9:18:07.03 ===============

  6. #6
    Junior Member
    Join Date
    Aug 2009
    Posts
    15

    Default

    Sorry I just realized I copied DDS report twice and didn't post the Attach Report. Here it the attach report.



    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-07-30.01)


    ==== Disk Partitions =========================


    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    No restore point in system.

    ==== Installed Programs ======================

    Ad-Aware
    Adobe Flash Player 10 ActiveX
    Adobe Shockwave Player
    Adobe® Photoshop® Album Starter Edition 3.2
    AIM 6
    AIM Toolbar
    AOL Coach Version 2.0(Build:20041026.5 en)
    AOL Deskbar
    AOL Search
    AOL Uninstaller (Choose which Products to Remove)
    Apple Mobile Device Support
    Apple Software Update
    Belkin Wireless G Plus MIMO USB Network Adapter
    Bonjour
    CA eTrust Antivirus
    CA Licensing
    CardRd81
    CCScore
    CR2
    Digimax Converter
    Digimax Master
    Download Updater (AOL LLC)
    Eduware Software
    ERUNT 1.1j
    ESSBrwr
    ESSCDBK
    ESScore
    ESSCT
    ESSgui
    ESShelp
    ESSini
    ESSPCD
    ESSPDock
    ESSSONIC
    ESSTOOLS
    ESSTUTOR
    ESSvpaht
    ESSvpot
    getPlus(R)_ocx
    Gleim's CPA Test Prep 2008 2008
    Gleim's CPA Test Prep 2009
    Google Toolbar for Internet Explorer
    HijackThis 2.0.2
    HLPIndex
    HLPPDOCK
    HLPRFO
    Hotfix for Windows XP (KB914440)
    Hotfix for Windows XP (KB915865)
    Hotfix for Windows XP (KB952287)
    iPod for Windows 2006-01-10
    iTunes
    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 12
    Java(TM) 6 Update 13
    Kodak EasyShare software
    KSU
    Macromedia Flash Player 8
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Standard Edition 2003
    Microsoft VC9 runtime libraries
    Move Media Player
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    Notifier
    NVIDIA Display Driver
    OLYMPUS CAMEDIA Master 4.2
    OTtBP
    OTtBPSDK
    PCDADDIN
    PCDHELP
    Pure Networks Port Magic
    QuickTime
    RealPlayer Basic
    Realtek AC'97 Audio
    Samsung USB Driver
    Security Update for Windows Internet Explorer 7 (KB938127-v2)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Internet Explorer 7 (KB972260)
    Security Update for Windows Internet Explorer 8 (KB972260)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB911565)
    Security Update for Windows Media Player 9 (KB917734)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB890046)
    Security Update for Windows XP (KB893066)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896422)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896424)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB896688)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899588)
    Security Update for Windows XP (KB899589)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB905915)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB908531)
    Security Update for Windows XP (KB911280)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911567)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB912812)
    Security Update for Windows XP (KB912919)
    Security Update for Windows XP (KB913446)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB916281)
    Security Update for Windows XP (KB917159)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB917422)
    Security Update for Windows XP (KB917953)
    Security Update for Windows XP (KB918118)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB918899)
    Security Update for Windows XP (KB919007)
    Security Update for Windows XP (KB920213)
    Security Update for Windows XP (KB920214)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB921398)
    Security Update for Windows XP (KB921503)
    Security Update for Windows XP (KB921883)
    Security Update for Windows XP (KB922616)
    Security Update for Windows XP (KB922760)
    Security Update for Windows XP (KB922819)
    Security Update for Windows XP (KB923191)
    Security Update for Windows XP (KB923414)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB923694)
    Security Update for Windows XP (KB923980)
    Security Update for Windows XP (KB924191)
    Security Update for Windows XP (KB924270)
    Security Update for Windows XP (KB924496)
    Security Update for Windows XP (KB924667)
    Security Update for Windows XP (KB925454)
    Security Update for Windows XP (KB925486)
    Security Update for Windows XP (KB925902)
    Security Update for Windows XP (KB926255)
    Security Update for Windows XP (KB926436)
    Security Update for Windows XP (KB927779)
    Security Update for Windows XP (KB927802)
    Security Update for Windows XP (KB928090)
    Security Update for Windows XP (KB928255)
    Security Update for Windows XP (KB928843)
    Security Update for Windows XP (KB929123)
    Security Update for Windows XP (KB929969)
    Security Update for Windows XP (KB930178)
    Security Update for Windows XP (KB931261)
    Security Update for Windows XP (KB931768)
    Security Update for Windows XP (KB931784)
    Security Update for Windows XP (KB932168)
    Security Update for Windows XP (KB933566)
    Security Update for Windows XP (KB933729)
    Security Update for Windows XP (KB935839)
    Security Update for Windows XP (KB935840)
    Security Update for Windows XP (KB936021)
    Security Update for Windows XP (KB937143)
    Security Update for Windows XP (KB937894)
    Security Update for Windows XP (KB938127)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB938829)
    Security Update for Windows XP (KB939653)
    Security Update for Windows XP (KB941202)
    Security Update for Windows XP (KB941568)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB941644)
    Security Update for Windows XP (KB941693)
    Security Update for Windows XP (KB942615)
    Security Update for Windows XP (KB943055)
    Security Update for Windows XP (KB943460)
    Security Update for Windows XP (KB943485)
    Security Update for Windows XP (KB944338)
    Security Update for Windows XP (KB944533)
    Security Update for Windows XP (KB944653)
    Security Update for Windows XP (KB945553)
    Security Update for Windows XP (KB946026)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB947864)
    Security Update for Windows XP (KB948590)
    Security Update for Windows XP (KB948881)
    Security Update for Windows XP (KB950749)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958470)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB971032)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973869)
    SFR
    SFR2
    SHASTA
    Shockwave
    SKIN0001
    SKINXSDK
    Spybot - Search & Destroy
    TurboTax Deluxe Deduction Maximizer 2006
    Update for Windows Internet Explorer 8 (KB972636)
    Update for Windows XP (KB894391)
    Update for Windows XP (KB896727)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB904942)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Update for Windows XP (KB927891)
    Update for Windows XP (KB929338)
    Update for Windows XP (KB930916)
    Update for Windows XP (KB931836)
    Update for Windows XP (KB932823-v3)
    Update for Windows XP (KB933360)
    Update for Windows XP (KB936357)
    Update for Windows XP (KB938828)
    Update for Windows XP (KB942763)
    Update for Windows XP (KB942840)
    Update for Windows XP (KB946627)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB973815)
    VideoLAN VLC media player 0.8.6i
    Viewpoint Media Player
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    VPRINTOL
    WebFldrs XP
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage v1.3.0254.0
    Windows Installer 3.1 (KB893803)
    Windows Internet Explorer 7
    Windows Internet Explorer 8
    Windows XP Hotfix - KB873333
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB887742
    Windows XP Hotfix - KB888113
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB891781
    Windows XP Hotfix - KB893086
    WIRELESS
    XviD 1.1 final uninstall

    ==== End Of File ===========================

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •