Closed Thread
Page 1 of 3 1 2 3 LastLast
Results 1 to 10 of 22
  1. #1
    Member
    Join Date
    Jan 2010
    Posts
    12
    Points
    0

    Default I think I have a virus/Malware

    Entered - Whole HJT log

    My computer is acting very strangly lately:
    - Symantec Antivirus auto-protect turns itself off automatically once a day
    - The title bar of my different programs (IE8, Explorer, Outlook, Excel) disappears sometime

    I am assuming I have some bad issues. Here are my logs:

    -----------------------------------------------------------
    HIJACKTHIS:
    -----------------------------------------------------------

    Logfile of Trend Micro HijackThis v2.0.3 (BETA)
    Scan saved at 9:01:49 AM, on 1/29/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\system32\bmwebcfg.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\WINDOWS\system32\ifxspmgt.exe
    C:\WINDOWS\system32\ifxtcs.exe
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
    C:\WINDOWS\system32\IfxPsdSv.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Retrospect\Retrospect 7.6\retrorun.exe
    C:\Program Files\Symantec AntiVirus\SavRoam.exe
    C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\PROGRA~1\SYMANT~1\VPTray.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Microsoft IntelliType Pro\itype.exe
    C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\HijackThis\TrendMicro\HiJackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Fan Interactive Marketing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\Snagit 9\SnagitBHO.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\Snagit 9\SnagitIEAddin.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
    O4 - HKLM\..\Run: [IFXSPMGT] C:\WINDOWS\system32\ifxspmgt.exe /NotifyLogon
    O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
    O4 - HKLM\..\Run: [hpbdfawep] C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe 1
    O4 - HKLM\..\Run: [PrnStatusMX] C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [MSCRM] "C:\Program Files\Microsoft Dynamics CRM\Client\ConfigWizard\CrmForOutlookInstaller.exe" /uninstallpst /uninstallabp /deactivateaddin
    O4 - HKCU\..\Run: [XdriveTrayIcon] "C:\Program Files\Xdrive\Xdrive Desktop\XdriveTray.exe"
    O4 - HKCU\..\Run: [XdriveTray] "C:\Program Files\xdrive\xdrive desktop\xdrive.exe" /trayicon
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: bmnet.dll
    O10 - Unknown file in Winsock LSP: bmnet.dll
    O10 - Unknown file in Winsock LSP: bmnet.dll
    O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175...at-no-eula.cab
    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanage...ex-2.2.4.1.cab
    O16 - DPF: {7557F5AA-D486-401D-BE55-0163FA78B5B8} (SkyFex Expert Object) - https://skyfex.com/download/SkyFexExpert.cab
    O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/actives.../as2stubie.cab
    O16 - DPF: {F84E0B64-1E86-4640-8094-5B38CEB28C1E} (SkyFex Client Object) - https://skyfex.com/download/SkyFexClient.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: APSHook.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: OneCard - C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AT&T RcAppSvc (ATTRcAppSvc) - PCTEL - C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe
    O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Drive Encryption Service (HpFkCryptService) - SafeBoot International - C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\ifxspmgt.exe
    O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\ifxtcs.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: Personal Secure Drive service (PersonalSecureDriveService) - Infineon Technologies AG - C:\WINDOWS\system32\IfxPsdSv.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.6\retrorun.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: SWIHPWMI - Sierra Wireless Inc. - C:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    --
    End of file - 13502 bytes


    -----------------------------------------------------------
    Malwarebytes'
    -----------------------------------------------------------

    Malwarebytes' Anti-Malware 1.44
    Database version: 3651
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    1/28/2010 3:38:17 PM
    mbam-log-2010-01-28 (15-38-17).txt

    Scan type: Full Scan (C:\|F:\|G:\|)
    Objects scanned: 625255
    Time elapsed: 6 hour(s), 21 minute(s), 59 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)


    -----------------------------------------------------------
    SUPERAntiSpyware
    -----------------------------------------------------------

    SUPERAntiSpyware Scan Log
    SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!

    Generated 01/28/2010 at 12:49 PM

    Application Version : 4.33.1000

    Core Rules Database Version : 4528
    Trace Rules Database Version: 2340

    Scan type : Complete Scan
    Total Scan Time : 03:42:02

    Memory items scanned : 909
    Memory threats detected : 0
    Registry items scanned : 8261
    Registry threats detected : 1
    File items scanned : 35424
    File threats detected : 507

    Adware.URLBlaze
    HKU\S-1-5-21-746137067-562591055-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE7C3CF0-4B15-11D1-ABED-709549C10000}

    Adware.Tracking Cookie
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adopt.specificclick[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.cnn[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.sun[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.as4x.tmcs.ticketmaster[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@chitika[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adtech[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@specificclick[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@kontera[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@qksrv[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@sales.liveperson[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@fastclick[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@dynamic.media.adrevolver[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-foxsports.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-verizon.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-brcmarketing.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@media6degrees[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@atdmt[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@questionmarket[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@eas.apm.emediate[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@richmedia.yahoo[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.bridgetrack[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@tribalfusion[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-rr.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@serving-sys[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adserver.notebooks[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@trafficmp[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@advertising[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-socaledison.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@statse.webtrendslive[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@apmebf[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal mintz@hg1.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@bs.serving-sys[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@mediaplex[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@zedo[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@data.coremetrics[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@doubleclick[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@windowsmedia[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@realmedia[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@imrworldwide[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@cbs.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@interclick[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@burstnet[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@nhl.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@linksynergy[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal mintz@smallbusiness.findlaw[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.realtechnetwork[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal mintz@dmtracker[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adlegend[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adbrite[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-findlaw.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.3dstats[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@sec1.liveperson[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@tacoda[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal mintz@www.couponmountain[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.neudesicmediagroup[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@microsofteup.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@salesforce.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adopt.euroclick[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@test.coremetrics[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@nextag[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@stat.onestat[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@edge.ru4[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal mintz@xiti[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@casalemedia[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@atwola[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.pointroll[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adrevolver[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@findlaw[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@revsci[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@statcounter[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@server.iad.liveperson[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal mintz@a[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@overture[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@stats.finra[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@media.adrevolver[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@at.atwola[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.visitor-track[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@crossmediaservices[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@partner2profit[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@microsoftwlmessengermkt.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@optimize.indieclick[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ticketsnow.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ad.worldlinks[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.as4x.tmcs[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@roiservice[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@track.bestbuy[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.imediaconnection[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@collective-media[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.monster[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@smartmoney.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@cms.trafficmp[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@web-stat[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.realtechnetwork[5].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@hc2.humanclick[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ev.ads.pointroll[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@trvlnet.adbureau[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@aegadvancedmedia[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adserver.adtechus[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.realtechnetwork[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@lacounty[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.burstbeacon[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@bookit.advertserve[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@pathfinder[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@perf.overture[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@microsoftwlcashback.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@stats.crossmediaservices[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal mintz@CAIKXIXX.txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@hotlog[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@traffic.buyservices[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@livenation.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.ookla[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adinterax[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-deltatre.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@bluestreak[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@hc2.humanclick[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@counter.hitslink[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-myspaceinc.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@mdnh.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.realtechnetwork[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@cf-db02.clickfacts[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-techtarget.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@paypal.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-webex.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@tripod[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@rotator.adjuggler[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@cgm.adbureau[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@msnaccountservices.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@avgtechnologies.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@sales.liveperson[7].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@nba.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.us.e-planning[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.nba[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@trackalyzer[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@nielsen.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@questionpro[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@de.sitestat[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@weborama[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@exacttarget1.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@americanexpress.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@sales.liveperson[11].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@iberiacom.solution.weborama[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@equifax.adbureau[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@creditcardscom.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adviva[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@247realmedia[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@palmone.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@qnsr[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-fifa.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@kiplinger.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal mintz@CAOUEEO5.txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@uk.sitestat[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@lockedonmedia[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-bestwestern.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.widgetbucks[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@microsoftwindows.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.fcaccess[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.lucidmedia[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@specificmedia[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-equifax.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@tourthomascountynebraska[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-barclaysglobal.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-zoom.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@giftscom.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@toplist[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@iacas.adbureau[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@citi.bridgetrack[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@revenue[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.techguy[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@research.backchannelmedia[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-imedia.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.mediastretch[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.realtechnetwork[4].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adverturesnewmediaservices.112.2o7[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@buycom.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.scribefire[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.clickz[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@a.findarticles[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@accountonline[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@yieldmanager[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@leveragemarketing.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.cheapflights[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@gettyimages.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@extrovert.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@stat.dealtime[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@snapfish.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@entrepreneurs.about[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@bizjournals.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.vayama[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@entrepreneur.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@eaeacom.112.2o7[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@clickbank[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@sales.liveperson[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@stats.adbrite[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@findarticles[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.mlsfinder[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.mlsfinder[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ad101com.adbureau[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ticketcity[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@imediac.adbureau[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@enhance[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@fr.sitestat[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.shorttail[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-zvents.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@surfline.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.nolimitmedia[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@nike.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@counter.cnw[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@glumobile.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@hotelscom.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.clickmanage[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@iqtv.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@exefind[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@findata.co[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@harpo.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.satelliteguys[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@incisivemedia.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@goal.adbureau[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@brucespringsteen[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@a1.interclick[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-hartfordfireinsurance.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@clickz[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.super-bowl-tickets.ticketsnow[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@printerinkcartridgesearch.printcountry[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ar.atwola[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@imediaconnection[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@snap9.advertserve[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@farheap.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adserv.brandaffinity[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@emc.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@euroclick[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@madisonsquaregarden.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@prnewswire.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@tribuneinteractive.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@indigio.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@socialmedia[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@stats.finra[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@twctsg.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@v7.stats.load[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal mintz@CAV89U3T.txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@wachovia.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@msnservices.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-jigsaw.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-zoomerang.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@estat[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.eliteemail[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@libertymutual.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@gmgmacmortgage.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@tremor.adbureau[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-speakeasy.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@homestore.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@tracking.realtor[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@assessor.saccounty[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-morningstar.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@e-2dj6wclyqhczchq.stats.esomniture[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@msadcenter.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@safeway.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@experianservicescorp.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@uk.sitestat[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@stats.paypal[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@yieldmanager[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@zillow.adbureau[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@triseptsolutions.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-kodak.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@timeinc.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@traffic.prod.cobaltgroup[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@tracking.foxnews[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.telegraph.co[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@tradedoubler[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@usatoday1.112.2o7[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.googleadservices[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@rm.piximedia[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.anvato[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.tnt[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@burstbeacon[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.mediapost[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@invitemedia[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@eb.adbureau[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-mgmmirageoperations.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.addesktop[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@sales.liveperson[9].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@guthyrenker.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.accountonline[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@trinitymirror.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@myroitracking[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-crain.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ar.atwola[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@technologyquestions[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@atlas.entrepreneur[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@directmediaoptin[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.technologyquestions[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@techtarget.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@hospitalityebusiness.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ice.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@hearstmagazines.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@stats2.clicktracks[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@nbcuniversal.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@myaccount.latimes[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adstats.cdfreaks[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@fr.sitestat[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@cdn4.specificclick[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@stats.townnews[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@gotvmail.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@bannerads.zwire[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.undertone[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@microsoftoffice.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.aoamedia[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.wheretostay[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@espnmediazone[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.addfreestats[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ext-us.bestofmedia[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@premiumtv.122.2o7[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@bannerads.zwire[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@clickbank[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@pentagonfederalcreditunion.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@a.websponsors[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@library.findlaw[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@videoegg.adbureau[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@foxinteractivemedia.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@bnkicom.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@rackspace.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.pgatour[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@superpages.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@click.sendreceivenow[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@kelleybluebook.112.2o7[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@myweather.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@entrepreneurs-journey[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@fireflyhawaii.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@allmediainc[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.insightexpress[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@phg.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@microsoftinternetexplorer.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ad.zanox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@highbeam.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@sales.liveperson[5].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@etgendev1.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@flightstats[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-nokiafin.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-allianceberstein.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@webmarketing123com.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@journalregistercompany.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@service.liveperson[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@anheuserbusch.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@fr.sitestat[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ad.m5prod[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@cb.adbureau[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@mediapost[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@mediapst.adbureau[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@socialmedia[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@clickets[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@bravenet[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ibm.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@leapfrogonline.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@bnkedu.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-bestbuy.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@airtrade.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@mcclatchy.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@dc.tremormedia[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@oasn04.247realmedia[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@tourismqld.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads2.net-communities.co[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@viacomedycentralrl.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@smartadserver[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.insightexpress[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@shineon-media[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.alladvertisingagencies[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ad1.clickhype[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@icebanner[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@aegadvancedmedia[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@montblanc.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-nexusmedia.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@msnbc.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@yadro[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www3.addfreestats[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@alladvertisingagencies[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@bonniercorp.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@traveladvertising[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@pointroll[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-viacom.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@clickintext[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@journalofaccountancy[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@lucidmedia[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@banner.motorcycle-usa[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@insightexpressai[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.w3counter[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@serw.clicksor[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@viator.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.entrepreneurs-journey[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@webex.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@saxosouthbend.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@content.yieldmanager[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.mazzy[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ru4[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@nintendo.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@stats.townnews[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@sales.liveperson[10].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.ticketsnow[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal mintz@CAHB84TF.txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@firstroi.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@tracking.facebooklogin[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@thefind[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@redorbit[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@list[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-penguingroupusa.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@target.db.advertising[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@wpni.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@bookit.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@stats.thaindian[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@webstat[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@lulu.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ad.wsod[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@sojern.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@wolterskluwer.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@dardenrestaurants.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@mlsnet.stats[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@surveymonkey.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@us.sitestat[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@c1.istats[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-newyorkpost.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@lopezbanner328[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ad.yieldmanager[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-reed.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@us.sitestat[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.aws.sitepoint[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@b5media[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@kaboose.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@pentonmedia.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@stats.manticoretechnology[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@beacon.dmsinsights[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.bluecompany[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@llcsexplained[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.pugetsoundsoftware[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@service.liveperson[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@kaspersky.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ad.vote7[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@e-2dj6wjliwndpchp.stats.esomniture[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@mediadecoder.blogs.nytimes[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@chicagosuntimes.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.adap[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@revenue.state.az[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@sales.liveperson[6].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@farecastcom.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@yahooflickr.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adbureau[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@netgear.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@google.lucidmedia[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.stackoverflow[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@oasn03.247realmedia[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@wpninewsweek.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.mlsfinder[5].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@graco.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@microsoftsto.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.sl[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.googleadservices[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@fim.122.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.etracker[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@kango.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@rambler[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-theactivenetwork.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.bleepingcomputer[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.meredithads[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@waterfrontmedia.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@eas4.emediate[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@accountingweb[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@oddcast[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@media.adfrontiers[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@networksolutions.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.asp[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.x17online[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@server.iad.liveperson[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.burstnet[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@usairways.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.lucidmedia[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.active[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-adidas.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@dominionenterprises.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@healthwiseorg.112.2o7[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@adecn[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-indemand.hitbox[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@hometheaterreview.advertserve[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@account.live[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@media.expedia[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@eyewonder[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@www.mlsfinder[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@sales.liveperson[8].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ehg-lussori.hitbox[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@viacom.adbureau[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@herald.plexmedia[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@content.yieldmanager[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@smileycentral[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@richmedia.yahoo[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ads.pointroll[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@advertising[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@content.yieldmanager[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@specificmedia[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@sales.liveperson[3].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@invitemedia[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@invitemedia[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@zedo[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@ad.yieldmanager[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@eyewonder[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@e-2dj6wjligjcjcfp.stats.esomniture[1].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@mediaplex[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@serving-sys[2].txt
    C:\Documents and Settings\Eyal Mintz\Cookies\eyal_mintz@specificclick[2].txt



    ------------------------------------
    Any and all help is greatly appreciated!

    Thanks
    Last edited by JohnB151; 02-01-2010 at 07:24 AM.

  2. #2
    Moderator Forum Moderator JohnB151's Avatar
    Join Date
    Mar 2009
    Location
    The Netherlands
    Posts
    950
    Points
    38

    Default

    Hi and welcome to the Help2Go forums.
    My name is John Brouwer - if it helps, you can call me John for short. I'll be glad to help you with your computer problems.

    First of all, please download HijackThis 2.0.2 from here (on the right):
    HijackThis - Trend Micro USA
    You are now running a beta version which may still contain bugs. After downloading version 2.0.2 please post a log made by it.

    HijackThis logs can take some time to research, so please be patient with me. I know that you need
    your computer working as quickly as possible, and I will work hard to help see that happens.

    Despite that it is important that you first know a couple of things:
    • The fixes are specific to your problem and should only be used for this issue on this machine.
    • It's often worth reading through these instructions and printing them for ease of reference.
    • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
    • If you don't reply within five days after my last instructions this topic will be closed. If you will not be able to reply within five days please tell me how long it will take so the topic will not be closed.


    There are also some things that I want you do so I can work as good as possible:
    • Please be patient. The work I do is voluntary and I also have a private life (school, work, friends and hobbies).
    • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
    • Please reply to this thread. Do not start a new topic.
    • Also, don't post logs as attachments. Other helpers like to view the logs as well and opening a lot of attachments is irritating. It can also contain malware.


    One more thing is very important for users who have Vista as operating system.
    When I instruct to run a tool or program always right-click and choose 'Run as Administrator' instead of just double-clicking the icon.

    Finally, please make a uninstall list using HijackThis and post that log so I know you have read this post.
    To access the Uninstall Manager you would do the following:
    • Start HijackThis
    • Click on the Open The Misc Tool Section button
    • Click on the Open Uninstall Manager button.
    • Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Save the file to your desktop and post the contents in a reply to this topic.


    Regards,
    John.

  3. #3
    Member
    Join Date
    Jan 2010
    Posts
    12
    Points
    0

    Default

    John, thank you for your help. I truelly appreciate you taking your time.

    Here is the updated HijackThis log, run using version 2.0.2. Also added the Uninstall Manager list under it.

    Finally, I am using Windows XP so that Vista issue shouldnt be a problem.

    Thanks again

    -----------------------------------------------------------
    HIJACKTHIS:
    -----------------------------------------------------------

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:14:20 AM, on 1/30/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\system32\bmwebcfg.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\WINDOWS\system32\ifxspmgt.exe
    C:\WINDOWS\system32\ifxtcs.exe
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
    C:\WINDOWS\system32\IfxPsdSv.exe
    C:\Program Files\Retrospect\Retrospect 7.6\retrorun.exe
    C:\Program Files\Symantec AntiVirus\SavRoam.exe
    C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\PROGRA~1\SYMANT~1\VPTray.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Microsoft IntelliType Pro\itype.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Fan Interactive Marketing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\Snagit 9\SnagitBHO.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\Snagit 9\SnagitIEAddin.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
    O4 - HKLM\..\Run: [IFXSPMGT] C:\WINDOWS\system32\ifxspmgt.exe /NotifyLogon
    O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
    O4 - HKLM\..\Run: [hpbdfawep] C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe 1
    O4 - HKLM\..\Run: [PrnStatusMX] C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [MSCRM] "C:\Program Files\Microsoft Dynamics CRM\Client\ConfigWizard\CrmForOutlookInstaller.exe" /uninstallpst /uninstallabp /deactivateaddin
    O4 - HKCU\..\Run: [XdriveTrayIcon] "C:\Program Files\Xdrive\Xdrive Desktop\XdriveTray.exe"
    O4 - HKCU\..\Run: [XdriveTray] "C:\Program Files\xdrive\xdrive desktop\xdrive.exe" /trayicon
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: bmnet.dll
    O10 - Unknown file in Winsock LSP: bmnet.dll
    O10 - Unknown file in Winsock LSP: bmnet.dll
    O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175...at-no-eula.cab
    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanage...ex-2.2.4.1.cab
    O16 - DPF: {7557F5AA-D486-401D-BE55-0163FA78B5B8} (SkyFex Expert Object) - https://skyfex.com/download/SkyFexExpert.cab
    O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/actives.../as2stubie.cab
    O16 - DPF: {F84E0B64-1E86-4640-8094-5B38CEB28C1E} (SkyFex Client Object) - https://skyfex.com/download/SkyFexClient.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: APSHook.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: OneCard - C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AT&T RcAppSvc (ATTRcAppSvc) - PCTEL - C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe
    O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Drive Encryption Service (HpFkCryptService) - SafeBoot International - C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\ifxspmgt.exe
    O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\ifxtcs.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: Personal Secure Drive service (PersonalSecureDriveService) - Infineon Technologies AG - C:\WINDOWS\system32\IfxPsdSv.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.6\retrorun.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: SWIHPWMI - Sierra Wireless Inc. - C:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    --
    End of file - 13165 bytes


    -----------------------------------------------------------
    UNINSTALL:
    -----------------------------------------------------------


    Acrobat.com
    Acrobat.com
    Ad-Aware
    Ad-Aware
    Adobe AIR
    Adobe AIR
    Adobe Anchor Service CS3
    Adobe Asset Services CS3
    Adobe Bridge CS3
    Adobe Bridge Start Meeting
    Adobe Camera Raw 4.0
    Adobe CMaps
    Adobe Color - Photoshop Specific
    Adobe Color Common Settings
    Adobe Color Common Settings
    Adobe Color EU Extra Settings
    Adobe Color JA Extra Settings
    Adobe Color NA Recommended Settings
    Adobe Default Language CS3
    Adobe Device Central CS3
    Adobe Dreamweaver CS3
    Adobe Dreamweaver CS3
    Adobe ExtendScript Toolkit 2
    Adobe ExtendScript Toolkit 2
    Adobe Extension Manager CS3
    Adobe Flash Player 10 ActiveX
    Adobe Fonts All
    Adobe Help Viewer CS3
    Adobe Illustrator CS3
    Adobe Illustrator CS3
    Adobe Linguistics CS3
    Adobe PDF Library Files
    Adobe Photoshop CS3
    Adobe Photoshop CS3
    Adobe Reader 9.2
    Adobe Setup
    Adobe Setup
    Adobe Setup
    Adobe Setup
    Adobe Setup
    Adobe Stock Photos CS3
    Adobe Type Support
    Adobe Update Manager CS3
    Adobe Version Cue CS3 Client
    Adobe WinSoft Linguistics Plugin
    Adobe XMP Panels CS3
    AoA DVD Ripper
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    AT&T Communication Manager
    ATI Catalyst Control Center
    ATI Display Driver
    Bonjour
    Catalyst Control Center - Branding
    Catalyst Control Center - Branding
    CCleaner
    Cisco Systems VPN Client 5.0.03.0530
    Credential Manager for HP ProtectTools
    Critical Update for Windows Media Player 11 (KB959772)
    CutePDF Writer 2.7
    Data Lifeguard Diagnostic for Windows
    Drive Encryption for HP ProtectTools
    Driver Installer
    EA Download Manager
    Embedded Security for HP ProtectTools
    FIFA MANAGER 09
    Flickr Uploadr 3.0.5
    GDR 4053 for SQL Server Database Services 2005 ENU (KB970892)
    GDR 4053 for SQL Server Tools and Workstation Components 2005 ENU (KB970892)
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB932716-v2)
    Hotfix for Windows XP (KB945060-v3)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    HP 3D DriveGuard
    HP BIOS Configuration for ProtectTools
    HP Broadband Wireless Modules
    HP Color LaserJet CP1210 Series
    HP Color LaserJet CP1210 Series
    HP Color LaserJet CP1210 Series Toolbox
    HP Image Zone Express
    HP Imaging Device Functions 5.3
    HP Integrated Module with Bluetooth wireless technology
    HP LaserJet Toolbox
    HP PCMCIA Smart Card Reader
    HP Product Assistant
    HP ProtectTools Security Manager
    HP PSC & OfficeJet 5.3.B
    HP Quick Launch Buttons 6.40 B2
    HP Solution Center & Imaging Support Tools 5.3
    HP Update
    HPCarePackCore
    HPCarePackProducts
    HPSSupply
    Intel(R) PRO Network Connections Drivers
    iPhone Configuration Utility
    iTunes
    Java(TM) 6 Update 17
    Java(TM) 6 Update 7
    LiveUpdate 3.1 (Symantec Corporation)
    Logitech Audio Echo Cancellation Component
    Logitech Video Enumerator
    Logitech® Camera Driver
    Malwarebytes' Anti-Malware
    MetaFrame Presentation Server Web Client for Win32
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft English TTS Engine
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
    Microsoft MapPoint North America 2009
    Microsoft National Language Support Downlevel APIs
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Access database engine 2007 (English)
    Microsoft Office Access MUI (English) 2007
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office Accounting 2008
    Microsoft Office Accounting 2008
    Microsoft Office Accounting 2008 Equifax Addin
    Microsoft Office Accounting 2008 Fixed Asset Manager
    Microsoft Office Accounting 2008 PayPal Addin
    Microsoft Office Accounting ADP Payroll Addin
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Professional 2007
    Microsoft Office Professional 2007 Trial
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Small Business Connectivity Components
    Microsoft Office Word MUI (English) 2007
    Microsoft Silverlight
    Microsoft SQL Server 2005
    Microsoft SQL Server 2005 Express Edition (CRM)
    Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
    Microsoft SQL Server 2005 Tools Express Edition
    Microsoft SQL Server Native Client
    Microsoft SQL Server Setup Support Files (English)
    Microsoft SQL Server VSS Writer
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2005 Redistributable
    Motorola Driver Installation
    MSVCRT
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 6.0 Parser (KB933579)
    MVision
    Nokia Connectivity Adapter Cable DKU-5
    ODBC Driver for Teradata 12.0.0.0
    Panda ActiveScan 2.0
    PC Inspector smart recovery
    PDF Settings
    QuickTime
    Retrospect 7.6
    RICOH R5C853 Driver Ver.1.00.02
    Rosetta Stone Version 3
    Roxio Creator Audio
    Roxio Creator Basic v9
    Roxio Creator Copy
    Roxio Creator Data
    Roxio Creator Tools
    Roxio Express Labeler 3
    Roxio MyDVD Basic v9
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB973704)
    Security Update for CAPICOM (KB931906)
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft Office Excel 2007 (KB973593)
    Security Update for Microsoft Office Outlook 2007 (KB972363)
    Security Update for Microsoft Office PowerPoint 2007 (KB957789)
    Security Update for Microsoft Office Publisher 2007 (KB969693)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB969613)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Security Update for Microsoft Office Word 2007 (KB969604)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 8 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB972260)
    Security Update for Windows Internet Explorer 8 (KB974455)
    Security Update for Windows Internet Explorer 8 (KB976325)
    Security Update for Windows Internet Explorer 8 (KB978207)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953155)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB970483)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Segoe UI
    Shared ICU Libraries for Teradata 12.0
    Skype™ 4.1
    Snagit 9.1.2
    Soft Data Fax Modem with SmartCP
    Sonic Activation Module
    SoundMAX
    SUPERAntiSpyware Free Edition
    Symantec AntiVirus
    Synaptics Pointing Device Driver
    Teradata CLIv2 12.0
    Teradata GSS Client nt-i386
    Teradata GSS Client nt-i386
    Teradata SQL Assistant 12.0.0.9
    Trillian
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office InfoPath 2007 (KB976416)
    Update for Outlook 2007 Junk Email Filter (kb977839)
    Update for Windows Internet Explorer 8 (KB968220)
    Update for Windows Internet Explorer 8 (KB973874)
    Update for Windows Internet Explorer 8 (KB976749)
    Update for Windows XP (KB942763)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB961503)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    Windows Essentials Media Codec Pack 1.0
    Windows Internet Explorer 8
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Essentials
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Upload Tool
    Windows Media Format 11 runtime
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Media Player 11
    Windows Presentation Foundation
    Windows XP Service Pack 3
    WinRAR archiver
    WinSCP 4.1.5
    Xvid 1.1.3 final uninstall

  4. #4
    Moderator Forum Moderator JohnB151's Avatar
    Join Date
    Mar 2009
    Location
    The Netherlands
    Posts
    950
    Points
    38

    Default

    Is this a corporate machine?

  5. #5
    Member
    Join Date
    Jan 2010
    Posts
    12
    Points
    0

    Default

    I use it for primarily personal stuff but of course also do some business from it.

  6. #6
    Moderator Forum Moderator JohnB151's Avatar
    Join Date
    Mar 2009
    Location
    The Netherlands
    Posts
    950
    Points
    38

    Default

    But in the company there is no IT department or contract with third party that should take care of this computer?

    I am asking because we do not want to meddle with business computers too much as they can contain valuable information and if something gets lost the company may wants to sue us, which we don't want logically.

  7. #7
    Member
    Join Date
    Jan 2010
    Posts
    12
    Points
    0

    Default

    Since this is my personal computer they will not work with it (even though I do work from it ). As for valuable information, that is all stored at the work computer and on portable hard drives not connected to this computer any more and through VPN connections to the company.

    Hopefully this makes sense.

  8. #8
    Moderator Forum Moderator JohnB151's Avatar
    Join Date
    Mar 2009
    Location
    The Netherlands
    Posts
    950
    Points
    38

    Default

    Hi,

    Alright, fair enough to me. Let's scan a little deeper because I found nothing in the HijackThis log.

    You aren't running Firewall Software. Please download and install one of them first!

    Use a Firewall - Using a Firewall on your computer can be very important. Without a firewall your computer is susceptible to being hacked and taken over. There are some different situations you can be in where a third-party firewall may or may not be a good addition to your system:
    • If you are not using Windows XP or Vista, but an older version I recommend you to use a firewall.
    • If you are using Windows XP or Vista, but are on dial-up I recommend you to use a firewall.
    • If you are using Windows XP or Vista and are using broadband, but are not experienced in using firewalls and getting the choice to allow or disallow things I recommend you to use Windows Firewall.
    • If you are using Windows XP or Vista, are using broadband and experienced, I recommend you to disable Windows Firewall (as it is not perfect) and get a third-party firewall.


    Here are some firewalls which are free for personal use and most used:
    Kerio Personal Firewall (Free version after 30 days)
    Online Armor Free

    Or you could buy their paid version online or in a shop nearby:
    Kerio Personal Firewall (Continue paid version after 30 days)
    Online Armor or Online Armor AV+ with Anti-Virus included

    As you did this, we can begin with the fix.

    Step 1: Disable Ad-Aware 2007 Service
    Please disable the Ad-Aware 2007 Service as it may interfere with the fix.
    • On your desktop, click Start.
    • Choose Run.
    • Type services.msc in the open box and click OK or press Enter.
    • Scroll down the list of services and double-click Ad-Aware 2007 Service.
    • In the service properties window that opens, click the STOP button.
    • Under Startup Type, use the pull down menu and select Manual from the list of options.
    • Click OK and exit the Services Control Manager.
    • Reboot your machine for the changes to take effect.

    Once your log is clean you can re-enable those settings.

    Step 2: Download and Run OTL
    • Download OTL to your desktop.
    • Double click on the icon to run it. Make sure all other windows are closed to let it run uninterrupted.
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Under the Standard Registry box change it to All.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.


    Step 3: Download and Run CKScanner
    Please download CKScanner from here and save it to your desktop:
    http://downloads.malwareremoval.com/CKScanner.exe

    Doubleclick CKScanner.exe and click Search For Files.
    After a very short time, when the cursor hourglass disappears, click Save List To File.
    A message box will verify the file saved.

    There will now be a file called CKFiles.txt on your desktop.

    Step 4: Post logs
    Please post the following in a reply to this topic (use multiple posts if needed):
    • OTL.txt
    • Extras.txt
    • CKFiles.txt


    Regards,
    John.

  9. #9
    Member
    Join Date
    Jan 2010
    Posts
    12
    Points
    0

    Default

    Thank you for looking into this... the logs were to long so I am spliting it into a couple of posts.

    My Windows Firewall is and was turned on. Does this provide enough security?

    Also, I tried to open PowerPoint and I got an error:
    The application or DLL C:\...\Office\oart.dll is not a valid Windows image. Please check against your installation diskette.
    This is occuring along with the TITLE BAR is disappearing on my programs.



    Here are the logs you asked for:

    ---------------------------------
    OTL
    ---------------------------------

    OTL logfile created on: 1/31/2010 12:24:35 PM - Run 1
    OTL by OldTimer - Version 3.1.27.1 Folder = C:\
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
    4.00 Gb Paging File | 3.00 Gb Available in Paging File | 76.00% Paging File free
    Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 74.52 Gb Total Space | 8.97 Gb Free Space | 12.03% Space Free | Partition Type: NTFS

    Computer Name: EYAL-8ABD29BB0E
    Current User Name: Eyal Mintz
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: Off
    Skip Microsoft Files: Off
    File Age = 30 Days
    Output = Minimal

    ========== Processes (SafeList) ==========

    PRC - C:\OTL.exe (OldTimer Tools)
    PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
    PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
    PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
    PRC - C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
    PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
    PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
    PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
    PRC - c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
    PRC - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
    PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
    PRC - C:\Program Files\Retrospect\Retrospect 7.6\retrorun.exe (EMC Corporation)
    PRC - C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
    PRC - C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
    PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
    PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\WINDOWS\system32\bmwebcfg.exe (Bytemobile, Inc.)
    PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
    PRC - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
    PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe ( Hewlett-Packard Development Company, L.P.)
    PRC - C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe (Microsoft Corporation)
    PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
    PRC - C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe (Marvell Semiconductor, Inc.)
    PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
    PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)
    PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
    PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
    PRC - C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe ()
    PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
    PRC - C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
    PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
    PRC - C:\Program Files\Symantec AntiVirus\DoScan.exe (Symantec Corporation)
    PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
    PRC - C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe (SafeBoot International)
    PRC - C:\WINDOWS\system32\IFXSPMGT.exe (Infineon Technologies AG)
    PRC - C:\WINDOWS\system32\IfxPsdSv.exe (Infineon Technologies AG)
    PRC - C:\Program Files\Hewlett-Packard\IAM\Bin\asghost.exe (Cognizance Corporation)
    PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
    PRC - C:\WINDOWS\system32\IFXTCS.exe (Infineon Technologies AG)
    PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
    PRC - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
    PRC - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe (Hewlett-Packard Development Company, L.P.)
    PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
    PRC - C:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe (Sierra Wireless Inc.)
    PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
    PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
    PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)


    ========== Modules (SafeList) ==========

    MOD - C:\OTL.exe (OldTimer Tools)
    MOD - C:\WINDOWS\system32\APSHook.dll (Bioscrypt Inc.)


    ========== Win32 Services (SafeList) ==========

    SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
    SRV - (iPod Service) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
    SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
    SRV - (MSSQL$MSSMLBIZ) SQL Server (MSSMLBIZ) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
    SRV - (MSSQL$CRM) SQL Server (CRM) -- c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
    SRV - (Bonjour Service) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
    SRV - (RetroLauncher) -- C:\Program Files\Retrospect\Retrospect 7.6\retrorun.exe (EMC Corporation)
    SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
    SRV - (SQLWriter) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
    SRV - (SQLBrowser) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
    SRV - (MSSQLServerADHelper) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
    SRV - (odserv) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
    SRV - (CVPND) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
    SRV - (W3SVC) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
    SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
    SRV - (IISADMIN) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
    SRV - (Irmon) -- C:\WINDOWS\system32\irmon.dll (Microsoft Corporation)
    SRV - (ATTRcAppSvc) -- C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe (PCTEL)
    SRV - (bmwebcfg) -- C:\WINDOWS\System32\bmwebcfg.exe (Bytemobile, Inc.)
    SRV - (Ati HotKey Poller) -- C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
    SRV - (hpqwmiex) -- C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
    SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.exe (HP)
    SRV - (SavRoam) -- C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
    SRV - (Symantec AntiVirus) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
    SRV - (DefWatch) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
    SRV - (HpFkCryptService) -- C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe (SafeBoot International)
    SRV - (IFXSpMgtSrv) -- C:\WINDOWS\system32\IFXSPMGT.exe (Infineon Technologies AG)
    SRV - (PersonalSecureDriveService) -- C:\WINDOWS\system32\IfxPsdSv.exe (Infineon Technologies AG)
    SRV - (SNDSrvc) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
    SRV - (LVSrvLauncher) -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
    SRV - (ASBroker) -- C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll (Cognizance Corporation)
    SRV - (btwdins) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
    SRV - (IFXTCS) -- C:\WINDOWS\system32\IFXTCS.exe (Infineon Technologies AG)
    SRV - (SPBBCSvc) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
    SRV - (SWIHPWMI) -- C:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe (Sierra Wireless Inc.)
    SRV - (ccSetMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
    SRV - (ccEvtMgr) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
    SRV - (RoxMediaDB9) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
    SRV - (stllssvr) -- C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
    SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
    SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE (Symantec Corporation)
    SRV - (ASChannel) -- C:\Program Files\Hewlett-Packard\IAM\Bin\ASChnl.dll (Cognizance Corporation)
    SRV - (IDriverT) -- C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)


    ========== Driver Services (SafeList) ==========

    DRV - (SASENUM) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
    DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    DRV - (NAVEX15) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100129.006\NAVEX15.SYS (Symantec Corporation)
    DRV - (NAVENG) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100129.006\NAVENG.SYS (Symantec Corporation)
    DRV - (USBAAPL) -- C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
    DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
    DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
    DRV - (pavboot) -- C:\WINDOWS\system32\drivers\pavboot.sys (Panda Security, S.L.)
    DRV - (GEARAspiWDM) -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
    DRV - (swmsflt) -- C:\WINDOWS\System32\drivers\swmsflt.sys ()
    DRV - (SymEvent) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
    DRV - (CVPNDRVA) -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
    DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
    DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
    DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider)
    DRV - (DNE) -- C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
    DRV - (tcpipBM) -- C:\WINDOWS\system32\drivers\tcpipBM.sys (Bytemobile, Inc.)
    DRV - (PCTINDIS5) -- C:\WINDOWS\system32\PCTINDIS5.sys (PCTEL Inc.)
    DRV - (PCASp50) -- C:\WINDOWS\system32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
    DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
    DRV - (NuidFltr) -- C:\WINDOWS\system32\drivers\nuidfltr.sys (Microsoft Corporation)
    DRV - (SWUMX56) Sierra Wireless USB MUX Driver (UMTS56) -- C:\WINDOWS\system32\drivers\swumx56.sys (Sierra Wireless Inc.)
    DRV - (SWNC8U56) Sierra Wireless MUX NDIS Driver (UMTS56) -- C:\WINDOWS\system32\drivers\swnc8u56.sys (Sierra Wireless Inc.)
    DRV - (HpqKbFiltr) -- C:\WINDOWS\system32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
    DRV - (BVRPMPR5) -- C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
    DRV - (NETw4x32) Intel(R) -- C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
    DRV - (rimmptsk) -- C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
    DRV - (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor) -- C:\WINDOWS\system32\drivers\atswpdrv.sys (AuthenTec, Inc.)
    DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
    DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
    DRV - (SYMTDI) -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
    DRV - (SYMREDRV) -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
    DRV - (iaStor) -- C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
    DRV - (RsvLock) -- C:\WINDOWS\system32\drivers\rsvlock.sys (SafeBoot International)
    DRV - (SafeBoot) -- C:\WINDOWS\system32\drivers\SafeBoot.sys ()
    DRV - (LVMVDrv) -- C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)
    DRV - (LVcKap) -- C:\WINDOWS\system32\drivers\Lvckap.sys ()
    DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) -- C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
    DRV - (pepifilter) -- C:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
    DRV - (e1express) Intel(R) -- C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
    DRV - (PersonalSecureDrive) -- C:\WINDOWS\System32\drivers\psd.sys (Infineon Technologies AG)
    DRV - (IFXTPM) -- C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
    DRV - (CVirtA) -- C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)
    DRV - (RimVSerPort) -- C:\WINDOWS\system32\drivers\RimSerial.sys (Research in Motion Ltd)
    DRV - (SynTP) -- C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
    DRV - (SPBBCDrv) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
    DRV - (ADIHdAudAddService) -- C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
    DRV - (rismc32) -- C:\WINDOWS\system32\drivers\rismc32.sys (RICOH Company, Ltd.)
    DRV - (HSF_DPV) -- C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
    DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
    DRV - (HSFHWAZL) -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
    DRV - (HP24X) -- C:\WINDOWS\system32\drivers\HP24X.sys (Hewlett Packard)
    DRV - (SbAlg) -- C:\WINDOWS\system32\drivers\SbAlg.sys (SafeBoot N.V.)
    DRV - (SAVRT) -- C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
    DRV - (SAVRTPEL) -- C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
    DRV - (AEAudio) -- C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
    DRV - (PxHelp20) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
    DRV - (Accelerometer) -- C:\WINDOWS\system32\drivers\Accelerometer.sys (Hewlett-Packard Corporation)
    DRV - (hpdskflt) -- C:\WINDOWS\system32\DRIVERS\hpdskflt.sys (Hewlett-Packard Corporation)
    DRV - (HBtnKey) -- C:\WINDOWS\system32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
    DRV - (mdmxsdk) -- C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
    DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
    DRV - (ROOTMODEM) -- C:\WINDOWS\system32\drivers\rootmdm.sys (Microsoft Corporation)
    DRV - (QCMerced) -- C:\WINDOWS\system32\drivers\lvcm.sys ()
    DRV - (LVUSBSta) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
    DRV - (HPZius12) -- C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
    DRV - (HPZipr12) -- C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
    DRV - (HPZid412) -- C:\WINDOWS\system32\drivers\HPZid412.sys (HP)
    DRV - (vsdatant) -- C:\WINDOWS\system32\vsdatant.sys (Zone Labs LLC)
    DRV - (SMCIRDA) -- C:\WINDOWS\system32\drivers\smcirda.sys (SMSC)
    DRV - (ASPI32) -- C:\WINDOWS\system32\drivers\Aspi32.sys (Adaptec)
    DRV - (msloop) -- C:\WINDOWS\system32\drivers\loop.sys (Microsoft Corporation)


    ========== Standard Registry (All) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = Bing
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Google Search

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = Google
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Fan Interactive Marketing
    IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/08/24 17:22:42 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008/12/20 12:30:13 | 000,000,000 | ---D | M]

    [2009/11/04 14:54:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\Mozilla\Extensions
    [2009/11/04 14:54:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\Mozilla\Extensions\uploadr@flickr.com

    O1 HOSTS File: ([2008/07/19 21:21:20 | 000,000,757 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O1 - Hosts: 10.254.254.253 Xdrive
    O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
    O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (Credential Manager for HP ProtectTools) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll (Bioscrypt Inc.)
    O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
    O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
    O3 - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [AT&T Communication Manager] C:\Program Files\AT&T\Communication Manager\ATTCM.exe (ATT)
    O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
    O4 - HKLM..\Run: [CognizanceTS] C:\Program Files\Hewlett-Packard\IAM\Bin\ASTSVCC.dll (Cognizance Corporation)
    O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
    O4 - HKLM..\Run: [hpbdfawep] C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe ()
    O4 - HKLM..\Run: [IFXSPMGT] C:\WINDOWS\System32\ifxspmgt.exe (Infineon Technologies AG)
    O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
    O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe (MediaCodec.Org)
    O4 - HKLM..\Run: [MSCRM] C:\Program Files\Microsoft Dynamics CRM\Client\ConfigWizard\CrmForOutlookInstaller.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [PrnStatusMX] C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe (Marvell Semiconductor, Inc.)
    O4 - HKLM..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE (Hewlett-Packard Development Company, L.P.)
    O4 - HKLM..\Run: [QlbCtrl] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)
    O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
    O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
    O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
    O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
    O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
    O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
    O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
    O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
    O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
    O4 - HKCU..\Run: [XdriveTray] C:\Program Files\xdrive\xdrive desktop\xdrive.exe File not found
    O4 - HKCU..\Run: [XdriveTrayIcon] C:\Program Files\Xdrive\Xdrive Desktop\XdriveTray.exe File not found
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
    O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
    O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
    O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
    O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
    O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/downlo...OGAControl.cab (Office Genuine Advantage Validation Tool)
    O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} http://a516.g.akamai.net/f/516/25175...at-no-eula.cab (Citrix ICA Client)
    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanage...ex-2.2.4.1.cab (DLM Control)
    O16 - DPF: {7557F5AA-D486-401D-BE55-0163FA78B5B8} https://skyfex.com/download/SkyFexExpert.cab (SkyFex Expert Object)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_17)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} http://acs.pandasoftware.com/actives.../as2stubie.cab (ActiveScan 2.0 Installer Class)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_17)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_17)
    O16 - DPF: {F84E0B64-1E86-4640-8094-5B38CEB28C1E} https://skyfex.com/download/SkyFexClient.cab (SkyFex Client Object)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
    O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\ipp - No CLSID value found
    O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
    O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
    O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp - No CLSID value found
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
    O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
    O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
    O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
    O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
    O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
    O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
    O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
    O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
    O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O20 - AppInit_DLLs: (APSHook.dll) - C:\WINDOWS\System32\APSHook.dll (Bioscrypt Inc.)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
    O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
    O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
    O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
    O20 - Winlogon\Notify\OneCard: DllName - C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll - C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll (Cognizance Corporation)
    O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
    O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
    O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
    O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
    O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
    O24 - Desktop Components:0 (My Current Home Page) - About:Home
    O24 - Desktop WallPaper: C:\Documents and Settings\Eyal Mintz\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Eyal Mintz\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
    O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
    O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
    O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
    O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
    O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
    O31 - SafeBoot: AlternateShell - cmd.exe
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2008/07/15 09:52:12 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O33 - MountPoints2\{27ae4297-9c8b-11de-9553-001f3b3cd16d}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\setup.exe -- [2008/04/13 16:12:34 | 000,023,040 | ---- | M] (Microsoft Corporation)
    O33 - MountPoints2\{6d05f894-52b0-11dd-943e-001f3b3ce3d1}\Shell\AutoRun\command - "" = WDSetup.exe
    O33 - MountPoints2\E\Shell - "" = AutoRun
    O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - comfile [open] -- "%1" %*
    O35 - exefile [open] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    [2010/01/31 12:23:27 | 000,548,864 | ---- | C] (OldTimer Tools) -- C:\OTL.exe
    [2010/01/28 09:14:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eyal Mintz\Application Data\Malwarebytes
    [2010/01/28 09:14:26 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/01/28 09:14:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2010/01/28 09:14:22 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/01/28 09:14:21 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
    [2010/01/28 09:04:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    [2010/01/28 09:04:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eyal Mintz\Application Data\SUPERAntiSpyware.com
    [2010/01/28 09:04:33 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
    [2010/01/28 08:58:38 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
    [2010/01/28 08:53:43 | 000,000,000 | ---D | C] -- C:\Program Files\HijackThis
    [2010/01/28 08:51:48 | 000,028,552 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\pavboot.sys
    [2010/01/28 08:51:42 | 000,000,000 | ---D | C] -- C:\Program Files\Panda Security
    [2010/01/25 09:37:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
    [2010/01/12 11:02:34 | 000,471,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aclayers.dll
    [2009/10/13 15:59:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Marvell
    [2008/09/28 19:10:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
    [2008/09/28 18:28:18 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
    [2008/08/13 15:21:30 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
    [2008/08/05 19:32:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
    [2008/08/05 10:19:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
    [2008/07/21 19:43:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Bytemobile
    [2008/07/21 16:24:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
    [6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2010/01/31 12:30:18 | 000,000,326 | ---- | M] () -- C:\WINDOWS\tasks\HP WEP.job
    [2010/01/31 12:23:57 | 000,441,856 | ---- | M] () -- C:\CKScanner.exe
    [2010/01/31 12:23:28 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\OTL.exe
    [2010/01/31 12:18:48 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2010/01/31 12:17:10 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2010/01/31 12:16:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/01/31 12:16:48 | 2146,750,464 | -HS- | M] () -- C:\hiberfil.sys
    [2010/01/31 12:16:10 | 009,437,184 | -H-- | M] () -- C:\Documents and Settings\Eyal Mintz\NTUSER.DAT
    [2010/01/31 12:15:47 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Eyal Mintz\ntuser.ini
    [2010/01/31 12:14:18 | 000,000,432 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{E31DA844-DF35-4E52-B2DD-46D21DC0567E}.job
    [2010/01/30 10:16:21 | 000,000,054 | ---- | M] () -- C:\WINDOWS\System32\rp_stats.dat
    [2010/01/30 10:16:21 | 000,000,039 | ---- | M] () -- C:\WINDOWS\System32\rp_rules.dat
    [2010/01/30 10:16:20 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
    [2010/01/30 10:13:41 | 000,001,580 | ---- | M] () -- C:\Documents and Settings\Eyal Mintz\Desktop\HijackThis.lnk
    [2010/01/29 18:27:42 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\Eyal Mintz\Application Data\winscp.rnd
    [2010/01/29 04:16:12 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
    [2010/01/28 22:16:19 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
    [2010/01/28 16:17:44 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
    [2010/01/28 10:17:07 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
    [2010/01/28 09:04:40 | 000,000,780 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2010/01/28 08:15:29 | 001,696,608 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/01/27 19:48:21 | 000,100,312 | ---- | M] () -- C:\Documents and Settings\Eyal Mintz\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    [2010/01/27 13:47:53 | 000,000,218 | ---- | M] () -- C:\WINDOWS\ODBC.INI
    [2010/01/27 12:59:56 | 000,000,707 | ---- | M] () -- C:\WINDOWS\win.ini
    [2010/01/13 17:10:23 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2010/01/07 16:07:14 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/01/07 16:07:04 | 000,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2010/01/31 12:23:57 | 000,441,856 | ---- | C] () -- C:\CKScanner.exe
    [2010/01/30 10:13:41 | 000,001,580 | ---- | C] () -- C:\Documents and Settings\Eyal Mintz\Desktop\HijackThis.lnk
    [2010/01/28 09:04:40 | 000,000,780 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2010/01/27 10:35:07 | 000,000,054 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat
    [2010/01/27 10:35:07 | 000,000,039 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat
    [2010/01/25 10:19:34 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
    [2010/01/25 10:19:34 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
    [2010/01/25 10:19:34 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
    [2010/01/25 10:19:33 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
    [2010/01/25 10:19:33 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
    [2009/09/23 11:20:23 | 000,009,255 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
    [2009/09/23 11:20:21 | 001,317,152 | ---- | C] () -- C:\WINDOWS\System32\drivers\lvcm.sys
    [2009/04/26 20:30:53 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
    [2009/04/26 19:36:25 | 000,000,190 | ---- | C] () -- C:\WINDOWS\AoADVDRipper.INI
    [2009/04/26 19:36:09 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
    [2009/04/26 19:36:09 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
    [2009/01/11 19:13:51 | 000,044,544 | ---- | C] () -- C:\WINDOWS\System32\Gif89.dll
    [2008/11/23 12:42:05 | 000,002,154 | ---- | C] () -- C:\Documents and Settings\Eyal Mintz\Application Data\HPSU_48BitScanUpdate.log
    [2008/11/23 12:42:05 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
    [2008/11/23 12:37:59 | 000,037,691 | ---- | C] () -- C:\Documents and Settings\Eyal Mintz\Application Data\Update_HP_RedboxHprblog_HPSU.log
    [2008/11/23 12:37:59 | 000,000,221 | ---- | C] () -- C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
    [2008/10/01 10:24:50 | 000,038,510 | ---- | C] () -- C:\Documents and Settings\Eyal Mintz\Application Data\Comma Separated Values (DOS).ADR
    [2008/09/11 17:34:19 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Eyal Mintz\Local Settings\Application Data\FnF4.txt
    [2008/09/11 13:36:48 | 000,025,600 | ---- | C] () -- C:\Documents and Settings\Eyal Mintz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2008/07/23 09:03:34 | 000,000,752 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
    [2008/07/21 19:41:35 | 000,026,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\swmsflt.sys
    [2008/07/21 19:31:26 | 000,021,791 | ---- | C] () -- C:\WINDOWS\System32\smtpctrs.ini
    [2008/07/21 19:31:25 | 000,001,037 | ---- | C] () -- C:\WINDOWS\System32\ntfsdrct.ini
    [2008/07/21 19:31:07 | 000,038,576 | ---- | C] () -- C:\WINDOWS\System32\w3ctrs.ini
    [2008/07/21 19:31:06 | 000,010,225 | ---- | C] () -- C:\WINDOWS\System32\axperf.ini
    [2008/07/21 19:31:04 | 000,011,435 | ---- | C] () -- C:\WINDOWS\System32\infoctrs.ini
    [2008/07/19 21:19:39 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
    [2008/07/17 14:28:36 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
    [2008/07/17 14:23:04 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Eyal Mintz\Application Data\winscp.rnd
    [2008/07/17 13:04:17 | 000,038,413 | ---- | C] () -- C:\Documents and Settings\Eyal Mintz\Application Data\Microsoft Excel 97-2003.ADR
    [2008/07/17 13:04:13 | 000,000,218 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2008/07/15 13:55:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
    [2008/07/15 12:23:38 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Eyal Mintz\Local Settings\Application Data\QSwitch.txt
    [2008/07/15 12:23:38 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Eyal Mintz\Local Settings\Application Data\DSwitch.txt
    [2008/07/15 12:23:38 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Eyal Mintz\Local Settings\Application Data\AtStart.txt
    [2008/04/17 08:08:56 | 000,197,408 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll
    [2008/04/17 08:08:44 | 000,193,312 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
    [2008/02/04 17:23:10 | 000,693,792 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
    [2007/02/07 10:22:46 | 000,100,495 | ---- | C] () -- C:\WINDOWS\System32\drivers\SafeBoot.sys
    [2007/02/06 17:42:40 | 001,691,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys
    [2007/02/06 14:20:00 | 002,842,624 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
    [2007/02/06 13:55:52 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
    [2007/01/19 06:30:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
    [2006/09/18 22:02:40 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
    [2006/09/18 22:02:40 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
    [2005/02/17 10:41:32 | 000,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
    [2005/02/17 10:41:30 | 000,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
    [2001/11/14 11:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
    [2001/07/06 14:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
    [1998/05/06 18:10:00 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\ODMA32.dll

    ========== LOP Check ==========

    [2008/09/02 11:05:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Applications
    [2008/07/21 19:40:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AT&T
    [2009/12/15 13:11:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.4 Output
    [2009/01/25 20:02:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
    [2008/07/15 10:48:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Infineon
    [2009/10/10 19:25:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RetroExp
    [2009/10/30 10:38:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Retrospect
    [2008/11/30 22:31:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Rosetta Stone
    [2008/11/30 21:53:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RosettaStoneLtdBackup
    [2009/09/16 13:34:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
    [2009/04/26 19:36:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
    [2009/04/26 20:29:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2009/09/11 17:17:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    [2008/07/21 19:47:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\AT&T
    [2008/07/21 19:43:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\DBUpdater
    [2009/12/15 13:11:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\eFax Messenger
    [2008/09/15 16:16:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\Flickr
    [2008/08/04 10:05:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\ICAClient
    [2009/03/02 16:56:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\Image Zone Express
    [2008/07/15 10:48:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\Infineon
    [2009/12/15 13:12:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\j2 Global
    [2008/10/20 14:58:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\Kensington
    [2009/09/10 19:02:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\Marvell
    [2008/07/18 14:52:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\NCR
    [2008/07/21 19:38:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\Sierra Wireless
    [2009/02/25 14:32:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\TeamViewer
    [2009/04/05 11:09:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\temp
    [2008/10/02 17:45:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\TurboMeeting
    [2009/04/29 14:32:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\webex
    [2008/07/20 09:21:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\Xdrive
    [2008/07/19 20:07:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eyal Mintz\Application Data\XdriveDesktopLite.D42DF930FC57DEEBEFA7CACA53E3816427CD6B50.1
    [2010/01/30 10:16:20 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job
    [2010/01/28 16:17:44 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job
    [2010/01/28 22:16:19 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job
    [2010/01/29 04:16:12 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job
    [2010/01/28 10:17:07 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
    [2010/01/31 12:14:18 | 000,000,432 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{E31DA844-DF35-4E52-B2DD-46D21DC0567E}.job

    ========== Purity Check ==========


    < End of report >

  10. #10
    Member
    Join Date
    Jan 2010
    Posts
    12
    Points
    0

    Default

    Rest of the logs:

    ---------------------------------
    EXTRAS
    ---------------------------------

    OTL Extras logfile created on: 1/31/2010 12:24:35 PM - Run 1
    OTL by OldTimer - Version 3.1.27.1 Folder = C:\
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
    4.00 Gb Paging File | 3.00 Gb Available in Paging File | 76.00% Paging File free
    Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 74.52 Gb Total Space | 8.97 Gb Free Space | 12.03% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    E: Drive not present or media not loaded
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: EYAL-8ABD29BB0E
    Current User Name: Eyal Mintz
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: Off
    Skip Microsoft Files: Off
    File Age = 30 Days
    Output = Minimal

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
    htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
    htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
    htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
    http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
    https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
    CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "DoNotAllowExceptions" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
    "139:TCP" = 139:TCP:LocalSubNetisabled:@xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:LocalSubNetisabled:@xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:LocalSubNetisabled:@xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:LocalSubNetisabled:@xpsp2res.dll,-22002

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
    "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
    "C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Ltd Services -- (Rosetta Stone Ltd. )
    "C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone Version 3 Application -- (Rosetta Stone Ltd. )
    "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
    "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
    "C:\Program Files\WinSCP\WinSCP.exe" = C:\Program Files\WinSCP\WinSCP.exe:*:Enabled:SFTP, FTP and SCP client -- (Martin Prikryl)
    "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
    "C:\WINDOWS\system32\mstsc.exe" = C:\WINDOWS\system32\mstsc.exe:*:Enabled:Remote Desktop Connection -- (Microsoft Corporation)
    "C:\Program Files\AT&T\Communication Manager\SwiApiMux.exe" = C:\Program Files\AT&T\Communication Manager\SwiApiMux.exe:*:Enabled:SwiApiMux -- (Sierra Wireless, Inc.)
    "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Co.)
    "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Co.)
    "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Co.)
    "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Co.)
    "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.)
    "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe -- ()
    "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard)
    "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe -- (Hewlett-Packard Co.)
    "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe -- (Hewlett-Packard)
    "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Co.)
    "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe -- ()
    "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe -- ( )
    "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.)
    "C:\Documents and Settings\Eyal Mintz\Local Settings\Temp\{E742B489-2A95-4B39-ACDA-5A9933274AB3}\{4B5E17D7-C0CF-4CC3-8870-0181D622B93C}\k_update.exe" = C:\Documents and Settings\Eyal Mintz\Local Settings\Temp\{E742B489-2A95-4B39-ACDA-5A9933274AB3}\{4B5E17D7-C0CF-4CC3-8870-0181D622B93C}\k_update.exe:*:Enabled:Kensington Digital Update of installed software via the Web. -- File not found
    "C:\Documents and Settings\Eyal Mintz\Local Settings\Temp\{2F3516E2-2C14-44EC-B33E-C6DDB9C191DA}\{4C78937F-0C8E-11D9-A3EB-0001025FA304}\k_update.exe" = C:\Documents and Settings\Eyal Mintz\Local Settings\Temp\{2F3516E2-2C14-44EC-B33E-C6DDB9C191DA}\{4C78937F-0C8E-11D9-A3EB-0001025FA304}\k_update.exe:*:Enabled:Kensington Digital Update of installed software via the Web. -- File not found
    "C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Ltd Services -- (Rosetta Stone Ltd. )
    "C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone Version 3 Application -- (Rosetta Stone Ltd. )
    "C:\Program Files\Electronic Arts\EADM\Core.exe" = C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager -- (Electronic Arts)
    "C:\Program Files\Microsoft Dynamics CRM Data Migration Manager\DMClient\res\web\bin\Microsoft.Crm.Application.DMHoster.exe" = C:\Program Files\Microsoft Dynamics CRM Data Migration Manager\DMClient\res\web\bin\Microsoft.Crm.Application.DMHoster.exe:*:Enabled:Microsoft Dynamics CRM Data Migration Manager Application Host -- File not found
    "C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
    "C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
    "C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation)
    "C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
    "C:\Program Files\Microsoft Office\Office12\EXCEL.EXE" = C:\Program Files\Microsoft Office\Office12\EXCEL.EXE:*:Enabled:Microsoft Office Excel -- (Microsoft Corporation)
    "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
    "C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe" = C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice -- (Microsoft Corporation)
    "C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
    "{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
    "{0517CC15-921A-4FC1-BDB6-7B1FA42B02A6}" = Teradata CLIv2
    "{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
    "{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
    "{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
    "{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
    "{09885750-A6D7-4536-B7CA-E61AD7DFE5AB}" = Adobe Setup
    "{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
    "{0A98C77E-A20B-5572-1551-9EAE4BEB6AA1}" = Catalyst Control Center Localization Norwegian
    "{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
    "{0C2AF762-0565-4C91-9F55-B8B53BB82A38}" = Microsoft Office Accounting 2008 Equifax Addin
    "{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
    "{0C667A8A-79AC-F6CD-C6D7-0F4B58FB9584}" = CCC Help Spanish
    "{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
    "{0DC3F5B7-146F-E6D2-CE95-9D6C7CD2177D}" = CCC Help Japanese
    "{10C896F2-EC2F-1294-13BE-7ABF18B44A49}" = CCC Help German
    "{13EA04CA-DB1B-DDDB-1938-F8EBE4C0A34C}" = Catalyst Control Center Localization Polish
    "{148E08FF-D7C4-46ED-8D4D-601C67FE0AFD}" = Rosetta Stone Version 3
    "{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
    "{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
    "{1BA8365C-E93A-2132-4AE2-9C2DFDB27013}" = Catalyst Control Center Graphics Full Existing
    "{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
    "{1CF925D3-1E33-4447-889B-0751D2CF886D}" = Drive Encryption for HP ProtectTools
    "{1DE77520-5F35-6E15-13F8-418D207F17FD}" = CCC Help Greek
    "{1E187923-04E5-4E1F-9BF2-40E32D93A1C4}" = HP Color LaserJet CP1210 Series Toolbox
    "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
    "{20A1D306-CE83-492A-8525-D6DF50B5944A}" = Embedded Security for HP ProtectTools
    "{20B38EEB-1579-3010-D53C-0BE030A48F3F}" = CCC Help Hungarian
    "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
    "{2466E904-7E48-4597-9321-722CF02930EB}" = 5600
    "{24B3DF86-75B9-4DBD-AC39-C0C041583E6F}" = HP PCMCIA Smart Card Reader
    "{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
    "{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 17
    "{26DDB12A-CB5E-4C0B-89AF-817CA0E59CC9}" = HP LaserJet Toolbox
    "{270940EA-C235-40D9-B2AE-2D450356DF8E}" = Microsoft Office Accounting 2008
    "{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
    "{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
    "{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
    "{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
    "{2DB165DC-DDB4-403F-B985-19F3EC7D0357}" = HP ProtectTools Security Manager
    "{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
    "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
    "{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}" = Roxio MyDVD Basic v9
    "{3444E2E9-B768-4490-5050-EEFF0D8869D0}" = Catalyst Control Center Localization Russian
    "{345112D9-0930-4A68-AB71-A831BA5DE7AA}" = Microsoft IntelliType Pro 6.2
    "{34563BF2-2181-EA35-8A6F-5DB23B3DBB82}" = Catalyst Control Center Localization Hungarian
    "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 B2
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
    "{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
    "{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
    "{377E3D59-C8FB-4E16-B3D1-E1D92D30DA00}" = Credential Manager for HP ProtectTools
    "{38C72867-3322-395E-EED1-B8B61851A3E1}" = ccc-utility
    "{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
    "{3E9B8918-3C82-6C6D-ABE1-9DA32E137B17}" = Catalyst Control Center Localization Czech
    "{3F93B2BA-18EC-462B-9ACD-396599353EE1}" = Catalyst Control Center - Branding
    "{429E92A4-159F-4AEC-85A1-D693E1E4274D}" = HP 3D DriveGuard
    "{443027F6-2A85-4ACE-B4E8-5F44C02EA301}" = AT&T Communication Manager
    "{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
    "{48ABA7D9-A1FC-47DA-A0CC-F0E4CD9D4BC1}" = ODBC Driver for Teradata
    "{49FC50FC-F965-40D9-89B4-CBFF80941033}" = Windows Movie Maker 2.0
    "{4C0A3478-F658-424A-FD5F-657E4A701CAC}" = CCC Help Italian
    "{4C271126-C295-4828-A901-5910AE0C258B}" = Cisco Systems VPN Client 5.0.03.0530
    "{4EBDDD97-BC33-4F4C-8DF3-4FA4D83DF84E}" = Retrospect 7.6
    "{4F3E17F8-F1C8-4A4B-9EB8-1EE2D190CDA9}" = Adobe Setup
    "{50273BEF-CF0E-4D97-9478-B2FA2A905CE6}" = Teradata GSS Client nt-i386
    "{50DDB00E-7E08-3463-4FE8-B804E2500D06}" = Catalyst Control Center Graphics Light
    "{50E125D1-88E5-48CE-80AE-98EC9698E639}" = Symantec AntiVirus
    "{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
    "{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
    "{54360A73-B080-4A69-BFD4-53C190DD3AB0}" = HP Color LaserJet CP1210 Series
    "{5468C2E7-8673-0694-A954-82D5D9BDF5E9}" = Catalyst Control Center Localization Greek
    "{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
    "{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
    "{55557243-1193-FFDF-EBF2-AFBD2D672563}" = CCC Help Chinese Standard
    "{55F8D929-8775-51BF-B614-1230AD0DC813}" = CCC Help Korean
    "{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
    "{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
    "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C853 Driver Ver.1.00.02
    "{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
    "{5C67F561-4758-4EC9-A727-CF8CEBD58041}" = Catalyst Control Center - Branding
    "{5E994A95-9388-4D10-8E68-54B8CBF894D3}" = Microsoft Application Error Reporting
    "{5FA793A6-0071-42C1-9355-8F69A428C44F}" = Microsoft Office Accounting ADP Payroll Addin
    "{5FBD03E7-B29E-1900-47AB-4697F01D98E5}" = Catalyst Control Center Localization Chinese Standard
    "{6005B423-E721-3691-15D7-90BE56038203}" = Catalyst Control Center Localization Finnish
    "{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
    "{6255A607-8881-4B02-9859-B4F3C798F7F9}" = Teradata SQL Assistant 12.0.0.9
    "{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
    "{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
    "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
    "{68330407-4C4C-1A8B-4D37-67D5C0588F3D}" = Catalyst Control Center Graphics Full New
    "{68B88EB8-4B1C-91D1-D59C-6205FEA83B0E}" = CCC Help Chinese Traditional
    "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
    "{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
    "{6B388529-8C30-BB57-0295-670C4AC9438B}" = Catalyst Control Center Localization Korean
    "{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
    "{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
    "{6DEF11C0-35FF-4160-A543-FDD336C4DAE5}" = Microsoft SQL Server 2005 Express Edition (CRM)
    "{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{7369B95B-8220-279B-F594-62CF0C6BADA3}" = Catalyst Control Center Localization Dutch
    "{753D852A-D86D-42C9-9978-40AE66FB8985}" = Driver Installer
    "{7691F657-C5C7-C096-F076-36DD98EA7FEC}" = Catalyst Control Center Localization French
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{7735D759-0E41-5A66-8507-96AF384C7A3E}" = ccc-core-static
    "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
    "{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
    "{7902E313-FF0F-4493-ACB1-A8147B78DCD0}" = HPSSupply
    "{7B02BF60-796D-4616-908B-B31A63CFDEFB}" = HPCarePackCore
    "{7C9B95B7-B598-4398-B30F-7F6827192E6C}" = ProductContext
    "{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
    "{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
    "{83ABA477-0CAE-E1AE-5C1D-B8A76009B51C}" = CCC Help Swedish
    "{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
    "{84814E6B-2581-46EC-926A-823BD1C670F6}" = HP Integrated Module with Bluetooth wireless technology
    "{86FA75D6-CF1E-43EB-9FAE-4B0D6214CE30}" = Catalyst Control Center Localization Portuguese
    "{870A9033-7509-7350-970A-5A4755AB84A4}" = Catalyst Control Center Localization German
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8AFBC2EB-BB17-43C8-8AE0-5B7961A4A217}" = Shared ICU Libraries for Teradata
    "{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
    "{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
    "{8FDDAB7A-B11D-4DE9-AA0C-5AC9F40A676E}" = Teradata GSS Client nt-i386
    "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
    "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
    "{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
    "{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
    "{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00D1-0409-0000-0000000FF1CE}" = Microsoft Office Access database engine 2007 (English)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
    "{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
    "{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
    "{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{913D6A0B-FBB5-8B90-19F0-0014D4FB90FC}" = Catalyst Control Center Localization Italian
    "{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
    "{92D64961-80C1-E213-5D6F-289605449685}" = CCC Help Norwegian
    "{94824ADD-8F26-43D2-84DB-22E11F377E5E}" = Microsoft English TTS Engine
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{95299FC9-7883-45B9-6733-8A233332C87B}" = ccc-core-preinstall
    "{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
    "{9579E862-5FC7-4337-B1CC-5E37451524C5}" = Motorola Driver Installation
    "{9597F07F-9F70-5377-35C5-45FF2FDE242E}" = CCC Help French
    "{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
    "{9D79C42A-3635-3551-58F6-378B7F3474C0}" = Catalyst Control Center Core Implementation
    "{A08777B7-7EA8-DD4A-2086-805B1F343D63}" = CCC Help Thai
    "{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
    "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
    "{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
    "{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
    "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
    "{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
    "{A8FEA904-2003-3CE1-1242-26888D691FCA}" = CCC Help Dutch
    "{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
    "{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
    "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
    "{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
    "{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
    "{B391EECE-DFEA-4FC5-9D40-47FA43E2DBE6}" = Microsoft Office Accounting 2008 PayPal Addin
    "{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
    "{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
    "{B440D659-FECA-4BDD-A12B-5C9F05790FF3}" = Snagit 9.1.2
    "{B74B6054-0008-232B-B2AE-3684B7FF036B}" = CCC Help Russian
    "{B786AE68-C697-6829-6D7B-4D9BB7C25E0A}" = CCC Help Czech
    "{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
    "{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
    "{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
    "{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
    "{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
    "{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
    "{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
    "{BFD5AC8A-5884-4da8-9873-3DF8E3DCCE18}" = 5600Trb
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{C35582A6-6F45-BB59-34CA-F70A302DAB6E}" = CCC Help Finnish
    "{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
    "{C579AE41-5875-ACE5-0BD1-221287127896}" = CCC Help English
    "{C6D9AF23-BE25-9287-404E-3A485D76EB00}" = CCC Help Turkish
    "{C74D0FA0-1D49-464F-A707-B427EE3385C1}" = HP BIOS Configuration for ProtectTools
    "{C82185E8-C27B-4EF4-2009-1111BC2C2B6D}" = Microsoft MapPoint North America 2009
    "{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
    "{C9A87D86-FDFD-418B-BF96-EF09320973B3}" = PC Inspector smart recovery
    "{CC7984C5-020D-4944-85A0-58D09D4A8BFB}" = 5600_Help
    "{CDA96CF0-0755-4B38-F551-DE122D2768ED}" = CCC Help Portuguese
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
    "{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{CF103051-98A4-8A56-6CDB-C5E21A131F23}" = CCC Help Danish
    "{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
    "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
    "{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
    "{D6CBCAF3-8C11-D262-4E24-211D3E420147}" = Catalyst Control Center Localization Japanese
    "{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
    "{E0335435-0379-FE9B-F2E2-72D36E42892C}" = Catalyst Control Center Localization Thai
    "{E0742446-2B18-4204-8A46-DA70BB003318}" = HP Broadband Wireless Modules
    "{E3DF6916-2472-43D9-8B3C-9F2F0AAB01B5}" = Microsoft Office Accounting 2008 Fixed Asset Manager
    "{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
    "{E40CE517-0D42-4198-96B4-C8232B257EB5}" = Data Lifeguard Diagnostic for Windows
    "{E622D07D-23CB-AEAB-EBAD-6375A63C3010}" = Catalyst Control Center Localization Chinese Traditional
    "{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
    "{E6D01615-78C9-FF2F-3A2F-F3A8D1102058}" = Catalyst Control Center Localization Swedish
    "{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
    "{EA32E7DD-3799-D84F-D26D-2FC569FEC211}" = Catalyst Control Center Localization Danish
    "{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
    "{EAA13A6E-6C11-AA31-24A4-83E81F0C7B95}" = Catalyst Control Center Localization Spanish
    "{EC2A8F27-4FBF-4E41-B27B-FE822511B761}" = iTunes
    "{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
    "{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
    "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
    "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
    "{F1BA3CD5-89DC-4273-8603-A75F33E9B335}" = Nokia Connectivity Adapter Cable DKU-5
    "{F2472544-9CBB-4595-B925-30FF619AF3F5}" = Catalyst Control Center Localization Turkish
    "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
    "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
    "{F347B7CC-F3F5-4464-8FB2-CC3CB42CC59E}" = Adobe Dreamweaver CS3
    "{F3A52623-4890-415D-A43A-F71A3A39C273}" = HPCarePackProducts
    "{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
    "{F6545202-473B-279E-A13E-DE97EF069DC6}" = CCC Help Polish
    "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
    "{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
    "{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
    "{FE64AE29-0883-4C70-8388-DC026019C900}" = HP Image Zone Express
    "{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
    "ActiveScan 2.0" = Panda ActiveScan 2.0
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
    "Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
    "Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
    "Adobe_7d27d533949941418d33ba1f052e783" = Adobe Dreamweaver CS3
    "Adobe_a04a925a57548091300ada368235fc6" = Adobe Illustrator CS3
    "AoA DVD Ripper_is1" = AoA DVD Ripper
    "ATI Display Driver" = ATI Display Driver
    "CCleaner" = CCleaner
    "Citrix ICA Web Client" = MetaFrame Presentation Server Web Client for Win32
    "CNXT_MODEM_PCI_VEN_14F1&DEV_2C06_hpqZ3795" = Soft Data Fax Modem with SmartCP
    "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
    "CutePDF Writer Installation" = CutePDF Writer 2.7
    "EADM" = EA Download Manager
    "FIFA MANAGER 09" = FIFA MANAGER 09
    "Flickr Uploadr" = Flickr Uploadr 3.0.5
    "HijackThis" = HijackThis 2.0.2
    "HP Color LaserJet CP1210 Series" = HP Color LaserJet CP1210 Series
    "HP Imaging Device Functions" = HP Imaging Device Functions 5.3
    "HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
    "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
    "ie7" = Windows Internet Explorer 7
    "ie8" = Windows Internet Explorer 8
    "InstallShield_{48ABA7D9-A1FC-47DA-A0CC-F0E4CD9D4BC1}" = ODBC Driver for Teradata 12.0.0.0
    "InstallShield_{8AFBC2EB-BB17-43C8-8AE0-5B7961A4A217}" = Shared ICU Libraries for Teradata 12.0
    "LiveUpdate" = LiveUpdate 3.1 (Symantec Corporation)
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft Office Accounting 2008" = Microsoft Office Accounting 2008
    "Microsoft SQL Server 2005" = Microsoft SQL Server 2005
    "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
    "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
    "ODBC Driver for Teradata" = ODBC Driver for Teradata 12.0.0.0
    "PROR" = Microsoft Office Professional 2007 Trial
    "PROSet" = Intel(R) PRO Network Connections Drivers
    "QcDrv" = Logitech® Camera Driver
    "SynTPDeinstKey" = Synaptics Pointing Device Driver
    "Teradata CLIv2" = Teradata CLIv2 12.0
    "Trillian" = Trillian
    "Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
    "Windows Essentials Media Codec Pack" = Windows Essentials Media Codec Pack 1.0
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WinLiveSuite_Wave3" = Windows Live Essentials
    "WinRAR archiver" = WinRAR archiver
    "winscp3_is1" = WinSCP 4.1.5
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
    "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
    "Xvid_is1" = Xvid 1.1.3 final uninstall

    ========== HKEY_CURRENT_USER Uninstall List ==========

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "Cisco Unified Presenter Add-in" = Cisco Unified Presenter Add-in

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 1/26/2010 3:37:18 PM | Computer Name = EYAL-8ABD29BB0E | Source = Application Hang | ID = 1002
    Description = Hanging application OUTLOOK.EXE, version 12.0.6514.5000, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 1/26/2010 3:41:45 PM | Computer Name = EYAL-8ABD29BB0E | Source = Userenv | ID = 1512
    Description = Windows cannot unload your registry file. The memory used by the registry
    has not been freed. This is often caused by services running as a user account,
    try configuring the services to run in either the LocalService or NetworkService
    account. If this problem persists, contact your administrator. DETAIL - Insufficient
    system resources exist to complete the requested service.

    Error - 1/27/2010 12:18:02 PM | Computer Name = EYAL-8ABD29BB0E | Source = Microsoft Office 12 | ID = 1000
    Description = Faulting application outlook.exe, version 12.0.6514.5000, stamp 4a89dc70,
    faulting module wwlib.dll, version 12.0.6504.5000, stamp 49e7f5f9, debug? 0, fault
    address 0x005258f0.

    Error - 1/27/2010 12:32:39 PM | Computer Name = EYAL-8ABD29BB0E | Source = Userenv | ID = 1512
    Description = Windows cannot unload your registry file. The memory used by the registry
    has not been freed. This is often caused by services running as a user account,
    try configuring the services to run in either the LocalService or NetworkService
    account. If this problem persists, contact your administrator. DETAIL - Insufficient
    system resources exist to complete the requested service.

    Error - 1/27/2010 5:06:53 PM | Computer Name = EYAL-8ABD29BB0E | Source = Microsoft Office 12 | ID = 5000
    Description = EventType offdiag12, P1 017ef32a-065c-4acd-a9f7-5dbac3576b74de01f7d5-c61f-452a-9833-cfa2e5926e1b,
    P2 NIL, P3 NIL, P4 NIL, P5 NIL, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.

    Error - 1/28/2010 12:46:10 PM | Computer Name = EYAL-8ABD29BB0E | Source = Microsoft Office 12 | ID = 5000
    Description = EventType office12asserttimer, P1 p1ml, P2 12.0.6425.0, P3 2, P4 0,
    P5 NIL, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.

    Error - 1/28/2010 1:17:08 PM | Computer Name = EYAL-8ABD29BB0E | Source = Application Error | ID = 1000
    Description = Faulting application skypepm.exe, version 2.0.0.65, faulting module
    kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

    Error - 1/29/2010 12:42:12 PM | Computer Name = EYAL-8ABD29BB0E | Source = Application Hang | ID = 1002
    Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 1/29/2010 12:42:32 PM | Computer Name = EYAL-8ABD29BB0E | Source = Application Hang | ID = 1001
    Description = Fault bucket 734562961.

    Error - 1/30/2010 2:22:20 PM | Computer Name = EYAL-8ABD29BB0E | Source = Microsoft Office 12 | ID = 5000
    Description = EventType office12asserttimer, P1 p1ml, P2 12.0.6425.0, P3 1, P4 0,
    P5 NIL, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.

    [ OSession Events ]
    Error - 11/11/2009 5:46:27 PM | Computer Name = EYAL-8ABD29BB0E | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.4518.1014, Microsoft Office Version: 12.0.4518.1031. This session lasted 254
    seconds with 0 seconds of active time. This session ended with a crash.

    Error - 11/11/2009 5:47:48 PM | Computer Name = EYAL-8ABD29BB0E | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.4518.1014, Microsoft Office Version: 12.0.4518.1031. This session lasted 65
    seconds with 0 seconds of active time. This session ended with a crash.

    Error - 11/16/2009 2:54:22 PM | Computer Name = EYAL-8ABD29BB0E | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
    12.0.4518.1014, Microsoft Office Version: 12.0.4518.1031. This session lasted 12140
    seconds with 1800 seconds of active time. This session ended with a crash.

    Error - 11/17/2009 5:43:57 PM | Computer Name = EYAL-8ABD29BB0E | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.4518.1014, Microsoft Office Version: 12.0.4518.1031. This session lasted 11251
    seconds with 1440 seconds of active time. This session ended with a crash.

    Error - 12/15/2009 6:02:10 PM | Computer Name = EYAL-8ABD29BB0E | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 23552
    seconds with 5400 seconds of active time. This session ended with a crash.

    Error - 1/7/2010 6:45:03 PM | Computer Name = EYAL-8ABD29BB0E | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 187
    seconds with 60 seconds of active time. This session ended with a crash.

    Error - 1/21/2010 3:36:46 PM | Computer Name = EYAL-8ABD29BB0E | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
    12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 100717
    seconds with 8460 seconds of active time. This session ended with a crash.

    Error - 1/21/2010 5:19:57 PM | Computer Name = EYAL-8ABD29BB0E | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
    12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2644
    seconds with 1860 seconds of active time. This session ended with a crash.

    Error - 1/27/2010 12:17:51 PM | Computer Name = EYAL-8ABD29BB0E | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 83
    seconds with 60 seconds of active time. This session ended with a crash.

    Error - 1/28/2010 12:48:21 PM | Computer Name = EYAL-8ABD29BB0E | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1014
    seconds with 600 seconds of active time. This session ended with a crash.

    [ System Events ]
    Error - 1/27/2010 2:10:10 PM | Computer Name = EYAL-8ABD29BB0E | Source = Server | ID = 2505
    Description = The server could not bind to the transport \Device\NetBT_Tcpip_{FF81EE36-F7D8-4EE7-963F-05624AA17E8A}
    because another computer on the network has the same name. The server could not
    start.

    Error - 1/27/2010 2:15:28 PM | Computer Name = EYAL-8ABD29BB0E | Source = Server | ID = 2505
    Description = The server could not bind to the transport \Device\NetBT_Tcpip_{FF81EE36-F7D8-4EE7-963F-05624AA17E8A}
    because another computer on the network has the same name. The server could not
    start.

    Error - 1/27/2010 2:44:12 PM | Computer Name = EYAL-8ABD29BB0E | Source = SAVRT | ID = 458772
    Description = Unable to initialize the virus scanning engine database files.

    Error - 1/28/2010 12:17:01 PM | Computer Name = EYAL-8ABD29BB0E | Source = Service Control Manager | ID = 7011
    Description = Timeout (30000 milliseconds) waiting for a transaction response from
    the WZCSVC service.

    Error - 1/28/2010 12:17:30 PM | Computer Name = EYAL-8ABD29BB0E | Source = Service Control Manager | ID = 7011
    Description = Timeout (30000 milliseconds) waiting for a transaction response from
    the Schedule service.

    Error - 1/28/2010 12:18:01 PM | Computer Name = EYAL-8ABD29BB0E | Source = Service Control Manager | ID = 7011
    Description = Timeout (30000 milliseconds) waiting for a transaction response from
    the ShellHWDetection service.

    Error - 1/28/2010 10:48:58 PM | Computer Name = EYAL-8ABD29BB0E | Source = SAVRT | ID = 458772
    Description = Unable to initialize the virus scanning engine database files.

    Error - 1/30/2010 2:09:31 PM | Computer Name = EYAL-8ABD29BB0E | Source = Dhcp | ID = 1000
    Description = Your computer has lost the lease to its IP address 192.168.1.5 on
    the Network Card with network address 001EEC1ACE80.

    Error - 1/31/2010 4:11:16 PM | Computer Name = EYAL-8ABD29BB0E | Source = Dhcp | ID = 1000
    Description = Your computer has lost the lease to its IP address 192.168.1.31 on
    the Network Card with network address 001F3B3CD16D.

    Error - 1/31/2010 4:11:16 PM | Computer Name = EYAL-8ABD29BB0E | Source = Dhcp | ID = 1000
    Description = Your computer has lost the lease to its IP address 192.168.1.5 on
    the Network Card with network address 001EEC1ACE80.


    < End of report >



    ---------------------------------
    CKFILES
    ---------------------------------
    CKScanner - Additional Security Risks - These are not necessarily bad
    c:\program files\adobe\adobe dreamweaver cs3\configuration\content\reference\html\keygen.html
    c:\program files\adobe\adobe dreamweaver cs3\configuration\content\reference\php\crackf.html
    scanner sequence 3.LB.11
    ----- EOF -----


    THANKS AGAIN

Closed Thread
Page 1 of 3 1 2 3 LastLast