"{00F3712A-CA79-45B4-9E4D-D7891E7F8B9D}" = "Windows Live Photo Gallery Editor Drop Target Shim"
-> {HKLM...CLSID} = "Windows Live Photo Gallery Editor Shim"
\InProcServer32\(Default) = "C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll" [MS]
"{00F30F90-3E96-453B-AFCD-D71989ECC2C7}" = "Windows Live Photo Gallery Autoplay Drop Target Shim"
-> {HKLM...CLSID} = "Windows Live Photo Gallery Viewer Autoplay Shim"
\InProcServer32\(Default) = "C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll" [MS]
"{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A}" = "*Nokia Phone Browser*" (unwritable string)
-> {HKLM...CLSID} = "*Nokia Phone Browser*" (unwritable string)
\InProcServer32\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll" ["Nokia"]
"{6af09ec9-b429-11d4-a1fb-0090960218cb}" = "My Bluetooth Places"
-> {HKLM...CLSID} = "My Bluetooth Places"
\InProcServer32\(Default) = "C:\WINDOWS\system32\BTNEIG~1.DLL" ["Broadcom Corporation."]
"{7842554E-6BED-11D2-8CDB-B05550C10000}" = "Monitor"
-> {HKLM...CLSID} = "Monitor Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\btncopy.dll" ["Broadcom Corporation."]
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
"{4255A182-CAD9-4214-A19B-7BA7FB633BBD}" = "Comodo Antivirus"
-> {HKLM...CLSID} = "Comodo AntiVirus"
\InProcServer32\(Default) = "C:\Program Files\COMODO\COMODO Internet Security\cavshell.dll" ["COMODO"]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<<!>> "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"
-> {HKLM...CLSID} = "Groove GFS Stub Execution Hook"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
-> {HKLM...CLSID} = "WPDShServiceObj Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]
HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\
<<!>> text/xml\CLSID = "{807563E5-5146-11D5-A672-00B0D022E945}"
-> {HKLM...CLSID} = "Microsoft Office InfoPath XML Mime Filter"
\InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL" [MS]
HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\
<<!>> grooveLocalGWS\CLSID = "{88FED34C-F0CA-4636-A375-3CB6248B04CD}"
-> {HKLM...CLSID} = "Local Groove Web Services Protocol"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll" [MS]
<<!>> livecall\CLSID = "{828030A1-22C1-4009-854F-8E305202313F}"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL" [MS]
<<!>> ms-help\CLSID = "{314111c7-a502-11d2-bbca-00c04f8ec294}"
-> {HKLM...CLSID} = "HxProtocol Class"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll" [MS]
<<!>> msnim\CLSID = "{828030A1-22C1-4009-854F-8E305202313F}"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL" [MS]
<<!>> wlmailhtml\CLSID = "{03C514A3-1EFB-4856-9F99-10D7BE1653C0}"
-> {HKLM...CLSID} = "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler"
\InProcServer32\(Default) = "C:\Program Files\Windows Live\Mail\mailcomm.dll" [MS]
HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
Comodo Antivirus\(Default) = "{4255A182-CAD9-4214-A19B-7BA7FB633BBD}"
-> {HKLM...CLSID} = "Comodo AntiVirus"
\InProcServer32\(Default) = "C:\Program Files\COMODO\COMODO Internet Security\cavshell.dll" ["COMODO"]
HexWorkshopContextMenu\(Default) = "{DB34D5DC-D41A-482E-A5EF-8FA0F88761DA}"
-> {HKLM...CLSID} = "Hex Workshop Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\BreakPoint Software\Hex Workshop v6\HWExt.dll" ["BreakPoint Software, Inc."]
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}"
-> {HKLM...CLSID} = "IEContextMenu Class"
\InProcServer32\(Default) = ""C:\Program Files\Norton Internet Security\Engine\18.1.0.37\NavShExt.dll"" ["Symantec Corporation"]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]
HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
MBAMShlExt\(Default) = "{57CE581A-0CB6-4266-9CA0-19364C90A0B3}"
-> {HKLM...CLSID} = "MBAMShlExt Class"
\InProcServer32\(Default) = "C:\Program Files\************' Anti-Malware\mbamext.dll" [file not found]
XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]
HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]
HKLM\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\
Monitor\(Default) = "{7842554E-6BED-11D2-8CDB-B05550C10000}"
-> {HKLM...CLSID} = "Monitor Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\btncopy.dll" ["Broadcom Corporation."]
Nokia\(Default) = "{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A}"
-> {HKLM...CLSID} = "*Nokia Phone Browser*" (unwritable string)
\InProcServer32\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll" ["Nokia"]
HKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\
WinZip\(Default) = "{E0D79305-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\
XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
-> {HKLM...CLSID} = "PDF Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
Comodo Antivirus\(Default) = "{4255A182-CAD9-4214-A19B-7BA7FB633BBD}"
-> {HKLM...CLSID} = "Comodo AntiVirus"
\InProcServer32\(Default) = "C:\Program Files\COMODO\COMODO Internet Security\cavshell.dll" ["COMODO"]
MBAMShlExt\(Default) = "{57CE581A-0CB6-4266-9CA0-19364C90A0B3}"
-> {HKLM...CLSID} = "MBAMShlExt Class"
\InProcServer32\(Default) = "C:\Program Files\************' Anti-Malware\mbamext.dll" [file not found]
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}"
-> {HKLM...CLSID} = "IEContextMenu Class"
\InProcServer32\(Default) = ""C:\Program Files\Norton Internet Security\Engine\18.1.0.37\NavShExt.dll"" ["Symantec Corporation"]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
-> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]
HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\
WinZip\(Default) = "{E0D79305-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."]
Group Policies {GPedit.msc branch and setting}:
-----------------------------------------------
Note: detected settings may not have any effect.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
"NoDesktop" = (REG_DWORD) dword:0x00000000
{unrecognized setting}
"NoActiveDesktop" = (REG_DWORD) dword:0x00000000
{User Configuration|Administrative Templates|Desktop|Desktop / Active Desktop|
Disable Active Desktop}
Active Desktop and Wallpaper:
-----------------------------
Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\web\wallpaper\Bliss.bmp"
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\WINDOWS\web\wallpaper\Bliss.bmp"
Enabled Screen Saver:
---------------------
HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]
Windows Portable Device AutoPlay Handlers
-----------------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\
GOMPlayDVDOnArrival\
"Provider" = "GOM Player"
"InvokeProgID" = "GomPlayer.DVD"
"InvokeVerb" = "open"
HKLM\SOFTWARE\Classes\GomPlayer.DVD\shell\open\command\(Default) = ""C:\Program Files\GRETECH\GomPlayer\GOM.exe" /open "%1"" ["Gretech Corp."]
GOMPlayMediaOnArrival\
"Provider" = "GOM Player"
"InvokeProgID" = "GomPlayer.MediaFile"
"InvokeVerb" = "open"
HKLM\SOFTWARE\Classes\GomPlayer.MediaFile\shell\open\command\(Default) = ""C:\Program Files\GRETECH\GomPlayer\GOM.exe" /open "%1"" ["Gretech Corp."]
HKLM\SOFTWARE\Classes\GomPlayer.MediaFile\shell\open\DropTarget\CLSID = "{D0F0AD6B-ECCC-401E-8E71-C4363D41399C}"
-> {HKLM...CLSID} = (no title provided)
\LocalServer32\(Default) = "C:\PROGRA~1\GRETECH\GOMPLA~1\GOM.exe" ["Gretech Corp."]
MSLivePhotoAcqHWEventHandler\
"Provider" = "@%ProgramFiles%\Windows Live\Photo Gallery\regres.dll,-10"
"ProgID" = "Microsoft.LivePhotoAcqHWEventHandler"
HKLM\SOFTWARE\Classes\Microsoft.LivePhotoAcqHWEventHandler\CLSID\(Default) = "{3BD0ACD1-71CA-4475-92CC-E0AA0AAF843F}"
-> {HKLM...CLSID} = (no title provided)
\LocalServer32\(Default) = "C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe" [MS]
MSLivePhotoAcquireDropHandler\
"Provider" = "@%ProgramFiles%\Windows Live\Photo Gallery\regres.dll,-10"
"InvokeProgID" = "Microsoft.LivePhotoAcqDTShim.1"
"InvokeVerb" = "open"
HKLM\SOFTWARE\Classes\Microsoft.LivePhotoAcqDTShim.1\shell\open\DropTarget\CLSID = "{00F33137-EE26-412F-8D71-F84E4C2C6625}"
-> {HKLM...CLSID} = "Windows Live Photo Gallery Viewer Autoplay Shim"
\InProcServer32\(Default) = "C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll" [MS]
MSLiveShowPicturesOnArrival\
"Provider" = "@%ProgramFiles%\Windows Live\Photo Gallery\regres.dll,-10"
"InvokeProgID" = "Microsoft.Photos.LiveAutoplayShim.1"
"InvokeVerb" = "open"
HKLM\SOFTWARE\Classes\Microsoft.Photos.LiveAutoplayShim.1\shell\open\DropTarget\CLSID = "{00F30F90-3E96-453B-AFCD-D71989ECC2C7}"
-> {HKLM...CLSID} = "Windows Live Photo Gallery Viewer Autoplay Shim"
\InProcServer32\(Default) = "C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll" [MS]
MSLiveVideoCameraArrivalCaptureWizard\
"Provider" = "@%ProgramFiles%\Windows Live\Photo Gallery\regres.dll,-10"
"ProgID" = "WLXAutoPlayMgr.WLXHWEventHandler"
"InitCmdLine" = "WLXVideoAcquireWizard"
HKLM\SOFTWARE\Classes\WLXAutoPlayMgr.WLXHWEventHandler\CLSID\(Default) = "{9B5C97F6-B3A5-4A6D-8B03-993EC7291A22}"
-> {HKLM...CLSID} = "WLXWEventHandler Class"
\LocalServer32\(Default) = ""C:\Program Files\Windows Live\Photo Gallery\WLXVideoCameraAutoPlayManager.exe"" [MS]
MSWPDShellNamespaceHandler\
"Provider" = "@%SystemRoot%\System32\WPDShextRes.dll,-501"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = " "
-> {HKLM...CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\WINDOWS\system32\WPDShextAutoplay.exe" [MS]
DESKTOP.INI DLL launch in local fixed drive directories:
--------------------------------------------------------
C:\Program Files\WIDCOMM\Bluetooth Software\My Bluetooth Places\DESKTOP.INI
[.ShellClassInfo]
CLSID={6af09ec9-b429-11d4-a1fb-0090960218cb}
-> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\BTNEIG~1.DLL" ["Broadcom Corporation."]
Startup items in "Administrator" & "All Users" startup folders:
---------------------------------------------------------------
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"Bluetooth" -> shortcut to: "C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe" ["Broadcom Corporation."]
"DynDNS Updater Tray Icon" -> shortcut to: "C:\Program Files\DynDNS Updater\DynTray.exe" ["Dynamic Network Services, Inc."]
Enabled Scheduled Tasks:
------------------------
"MP Scheduled Scan" -> launches: "C:\Program Files\Microsoft Security Essentials\MpCmdRun.exe Scan -ScheduleJob -WinTask -RestrictPrivilegesScan" [file not found]
"User_Feed_Synchronization-{468C0CDC-CD64-4B4D-8E98-30BFB6E18728}" -> launches: "C:\WINDOWS\system32\msfeedssync.exe sync" [MS]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
Transport Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 19
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"
-> {HKLM...CLSID} = "Norton Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll" ["Symantec Corporation"]
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" = "Norton Toolbar"
-> {HKLM...CLSID} = "Norton Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll" ["Symantec Corporation"]
Explorer Bars
HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\
HKLM\SOFTWARE\Classes\CLSID\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}\(Default) = "Groove Folder Synchronization"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]
HKLM\SOFTWARE\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "أب&حاث"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL" [MS]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
{219C3416-8CB2-491A-A3C7-D9FCDDC9D600}\
"ButtonText" = "تدوين هذا في المدونة"
"MenuText" = "&تدوين هذا في Windows Live Writer"
"CLSIDExtension" = "{5F7B1267-94A9-47F5-98DB-E99415F33AEC}"
-> {HKLM...CLSID} = "BlogThisToolbarButton Class"
\InProcServer32\(Default) = "C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll" [MS]
{2670000A-7350-4F3C-8081-5663EE0C6C49}\
"ButtonText" = "إرسال إلى OneNote"
"MenuText" = "إر&سال إلى OneNote"
"CLSIDExtension" = "{48E73304-E1D6-4330-914C-F5F514E3486C}"
-> {HKLM...CLSID} = "Send to OneNote from Internet Explorer button"
\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll" [MS]
{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
"ButtonText" = "Research"
{CCA281CA-C863-46EF-9331-5C8D4460577F}\
"ButtonText" = "@btrez.dll,-4015"
"MenuText" = "@btrez.dll,-12650"
"Script" = "C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm" [null data]
{E2E2DD38-D088-4134-82B7-F2BA38496583}\
"MenuText" = "@xpsp3res.dll,-20001"
"Exec" = "%windir%\Network Diagnostic\xpnetdiag.exe" [MS]
{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
Bluetooth Service, btwdins, "C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe" ["Broadcom Corporation."]
COMODO Internet Security Helper Service, cmdAgent, ""C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"" ["COMODO"]
Dell Wireless WLAN Tray Service, wltrysvc, "C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe" [null data]
DynDNS Updater, DynDNS Updater, "C:\Program Files\DynDNS Updater\DynUpSvc.exe" ["Dynamic Network Services, Inc."]
MySQL, MySQL, "C:\AppServ\mysql\bin\mysqld-nt.exe MySQL" [null data]
Norton Internet Security, NIS, ""C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe" /s "NIS" /m "C:\Program Files\Norton Internet Security\Engine\18.1.0.37\diMaster.dll" /prefetch:1" ["Symantec Corporation"]
ServiceLayer, ServiceLayer, ""C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"" ["Nokia"]
SigmaTel Audio Service, STacSV, "C:\WINDOWS\system32\STacSV.exe" ["SigmaTel, Inc."]
Print Monitors:
---------------
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\
Bluetooth Printer Port\Driver = "bthcrp.dll" ["Broadcom Corporation."]
Send To Microsoft OneNote Monitor\Driver = "msonpmon.dll" [MS]
---------- (launch time: 2010-11-30 13:09:56)
<<!>>: Suspicious data at a malware launch point.
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 475 seconds.
---------- (total run time: 554 seconds)
*********** جميع عمليات الذاكرة ***********
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\AppServ\mysql\bin\mysqld-nt.exe
C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe
C:\WINDOWS\system32\STacSV.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\DynDNS Updater\DynUpSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\OEM02Mon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\DynDNS Updater\DynTray.exe
C:\Program Files\DellTPad\Apntex.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\Zyzoom_Report_Tool.exe
*********** عمليات الذاكره الغير موقعه رقميا _ بدون عمليات النظام _ ***********
C:\AppServ\mysql\bin\mysqld-nt.exe
C:\WINDOWS\system32\STacSV.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\OEM02Mon.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\Zyzoom_Report_Tool.exe
*********** المجلدات والملفات التي تم انشاؤها في آخر شهر ***********
2010-11-30 13:08:51 ----A---- C:\zzlog.txt
2010-11-30 13:08:51 ----A---- C:\WINDOWS\system32\Gif89.dll
2010-11-30 09:06:45 ----D---- C:\Documents and Settings\All Users\Application Data\hsswpr
2010-11-28 13:48:27 ----SHD---- C:\WINDOWS\CSC
2010-11-28 10:08:16 ----A---- C:\WINDOWS\SpeedyFox Uninstall Log.txt
2010-11-28 10:04:33 ----D---- C:\WINDOWS\SpeedyFox
2010-11-28 09:59:21 ----A---- C:\WINDOWS\SpeedyFox Setup Log.txt
2010-11-28 09:50:36 ----D---- C:\Program Files\Symantec
2010-11-28 09:50:36 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-11-28 09:50:36 ----A---- C:\WINDOWS\system32\S32EVNT1.DLL
2010-11-28 09:49:38 ----D---- C:\Program Files\Norton Internet Security
2010-11-28 09:49:37 ----D---- C:\Program Files\Windows Sidebar
2010-11-28 09:49:35 ----D---- C:\Documents and Settings\All Users\Application Data\Norton
2010-11-28 09:49:26 ----D---- C:\Program Files\NortonInstaller
2010-11-28 01:39:33 ----D---- C:\WINDOWS\Temp
2010-11-26 09:27:42 ----HD---- C:\Program Files\Uninstall Information
2010-11-26 07:55:50 ----D---- C:\Program Files\Conduit
2010-11-26 07:54:30 ----D---- C:\WINDOWS\Simple Port Forwarding
2010-11-26 07:54:26 ----A---- C:\WINDOWS\Simple Port Forwarding Setup Log.txt
2010-11-26 06:30:43 ----D---- C:\Program Files\PFConfig
2010-11-26 00:50:06 ----D---- C:\Program Files\outlook express
2010-11-25 17:27:50 ----D---- C:\Program Files\Microsoft Silverlight
2010-11-25 03:44:27 ----D---- C:\Program Files\WinPcap
2010-11-24 23:24:23 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
2010-11-23 06:30:21 ----N---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2010-11-23 03:57:07 ----D---- C:\Program Files\CamStudio
2010-11-23 01:48:15 ----D---- C:\Documents and Settings\Administrator\Application Data\Publish Providers
2010-11-23 01:47:54 ----D---- C:\Documents and Settings\Administrator\Application Data\Sony
2010-11-23 01:30:42 ----D---- C:\Program Files\Sony
2010-11-23 01:30:38 ----A---- C:\WINDOWS\system32\wmv8dmoe.dll
2010-11-23 01:30:38 ----A---- C:\WINDOWS\system32\wmv8dmod.dll
2010-11-23 01:30:37 ----A---- C:\WINDOWS\system32\wmvdmoe.dll
2010-11-23 01:30:36 ----A---- C:\WINDOWS\system32\wmvcore2.dll
2010-11-23 01:20:01 ----D---- C:\Program Files\Sony Setup
2010-11-21 18:26:47 ----A---- C:\WINDOWS\InstRun.ini
2010-11-21 18:23:21 ----D---- C:\Documents and Settings\Administrator\Application Data\Jiangmin
2010-11-21 18:23:18 ----D---- C:\Documents and Settings\All Users\Application Data\Jiangmin
2010-11-21 18:22:58 ----A---- C:\WINDOWS\system32\KVInstall.dll
2010-11-21 18:22:58 ----A---- C:\WINDOWS\system32\HiveBase.dll
2010-11-21 03:42:40 ----D---- C:\Program Files\WinUtilities Process Security
2010-11-21 03:41:36 ----A---- C:\WINDOWS\system32\wbhelp2.dll
2010-11-21 03:41:36 ----A---- C:\WINDOWS\system32\unicows.dll
2010-11-21 03:41:35 ----A---- C:\WINDOWS\system32\W95INF32.DLL
2010-11-21 03:41:35 ----A---- C:\WINDOWS\system32\W95INF16.DLL
2010-11-21 03:41:35 ----A---- C:\WINDOWS\system32\shfolder.inf
2010-11-21 03:41:35 ----A---- C:\WINDOWS\system32\gdiplus.dll
2010-11-21 03:41:35 ----A---- C:\WINDOWS\system32\anim.dll
2010-11-21 03:41:34 ----D---- C:\Program Files\WinUtilities
2010-11-20 20:47:26 ----HD---- C:\VritualRoot
2010-11-20 04:41:57 ----D---- C:\Documents and Settings\Administrator\Application Data\GRETECH
2010-11-20 00:22:25 ----D---- C:\Program Files\windows nt
2010-11-20 00:22:25 ----D---- C:\Program Files\microsoft frontpage
2010-11-19 17:38:47 ----D---- C:\WINDOWS\Prefetch
2010-11-16 16:02:14 ----A---- C:\WINDOWS\ntbtlog.txt
2010-11-15 22:31:35 ----D---- C:\Program Files\Wise Disk Cleaner
2010-11-15 22:30:57 ----D---- C:\Program Files\Wise Registry Cleaner
2010-11-15 21:04:50 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2010-11-15 21:04:50 ----A---- C:\WINDOWS\system32\mucltui.dll
2010-11-15 01:52:02 ----D---- C:\Documents and Settings\Administrator\Application Data\************
2010-11-15 01:51:30 ----D---- C:\Documents and Settings\All Users\Application Data\************
2010-11-14 23:51:28 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2010-11-14 21:43:08 ----D---- C:\Documents and Settings\Administrator\Application Data\Thinstall
2010-11-14 06:07:09 ----D---- C:\Program Files\DynDNS Updater
2010-11-14 06:07:09 ----D---- C:\Documents and Settings\All Users\Application Data\DynDNS
2010-11-14 05:02:21 ----D---- C:\Program Files\No-IP
2010-11-14 00:31:25 ----D---- C:\Program Files\Havij 13
2010-11-13 21:59:09 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-11-13 20:37:37 ----D---- C:\WINDOWS\pss
2010-11-13 20:36:40 ----D---- C:\Documents and Settings\Administrator\Application Data\Godlike
2010-11-13 18:41:02 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2010-11-13 17:50:27 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-11-13 17:50:27 ----A---- C:\WINDOWS\system32\irclass.dll
2010-11-13 15:33:48 ----SHD---- C:\$RECYCLE.BIN
2010-11-13 14:55:08 ----SHD---- C:\Boot
2010-11-13 00:54:42 ----D---- C:\Program Files\Havij
2010-11-13 00:49:37 ----D---- C:\WINDOWS\system32\tr-tr
2010-11-13 00:49:34 ----D---- C:\WINDOWS\system32\th-th
2010-11-13 00:49:31 ----D---- C:\WINDOWS\system32\sv-se
2010-11-13 00:49:27 ----D---- C:\WINDOWS\system32\sk-sk
2010-11-13 00:49:23 ----D---- C:\WINDOWS\system32\sl-si
2010-11-13 00:49:16 ----D---- C:\WINDOWS\system32\ru-ru
2010-11-13 00:49:12 ----D---- C:\WINDOWS\system32\ro-ro
2010-11-13 00:49:07 ----D---- C:\WINDOWS\system32\pt-pt
2010-11-13 00:49:03 ----D---- C:\WINDOWS\system32\pt-br
2010-11-13 00:48:59 ----D---- C:\WINDOWS\system32\pl-pl
2010-11-13 00:48:55 ----D---- C:\WINDOWS\system32\nb-no
2010-11-13 00:48:51 ----D---- C:\WINDOWS\system32\nl-nl
2010-11-13 00:48:46 ----D---- C:\WINDOWS\system32\lv-lv
2010-11-13 00:48:43 ----D---- C:\WINDOWS\system32\lt-lt
2010-11-13 00:48:34 ----D---- C:\WINDOWS\system32\ko-kr
2010-11-13 00:48:30 ----D---- C:\WINDOWS\system32\ja-jp
2010-11-13 00:48:25 ----D---- C:\WINDOWS\system32\it-it
2010-11-13 00:48:19 ----D---- C:\WINDOWS\system32\hu-hu
2010-11-13 00:48:15 ----D---- C:\WINDOWS\system32\hr-hr
2010-11-13 00:48:12 ----D---- C:\WINDOWS\system32\he-il
2010-11-13 00:48:07 ----D---- C:\WINDOWS\system32\fr-fr
2010-11-13 00:48:02 ----D---- C:\WINDOWS\system32\fi-fi
2010-11-13 00:47:57 ----D---- C:\WINDOWS\system32\et-ee
2010-11-13 00:47:55 ----D---- C:\WINDOWS\system32\es-es
2010-11-13 00:47:53 ----D---- C:\WINDOWS\system32\el-gr
2010-11-13 00:47:51 ----D---- C:\WINDOWS\system32\de-de
2010-11-13 00:47:50 ----D---- C:\WINDOWS\system32\da-dk
2010-11-13 00:47:48 ----D---- C:\WINDOWS\system32\cs-cz
2010-11-13 00:47:46 ----D---- C:\WINDOWS\system32\zh-tw
2010-11-13 00:47:44 ----D---- C:\WINDOWS\system32\zh-cn
2010-11-13 00:47:42 ----D---- C:\WINDOWS\system32\bg-bg
2010-11-13 00:39:13 ----D---- C:\Hotspot Shield
2010-11-13 00:33:22 ----A---- C:\WINDOWS\unvise32.exe
2010-11-13 00:32:53 ----D---- C:\AppServ
2010-11-13 00:03:03 ----D---- C:\Documents and Settings\All Users\Application Data\WinZip
2010-11-13 00:02:50 ----D---- C:\Program Files\WinZip
2010-11-12 23:58:05 ----HDC---- C:\WINDOWS\ie8
2010-11-12 23:17:44 ----D---- C:\Documents and Settings\Administrator\Application Data\Mavituna Security Ltd
2010-11-12 23:14:44 ----N---- C:\WINDOWS\system32\spmsg2.dll
2010-11-12 23:13:44 ----D---- C:\WINDOWS\system32\ar-SA
2010-11-12 23:09:33 ----D---- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2010-11-12 23:08:50 ----D---- C:\WINDOWS\system32\XPSViewer
2010-11-12 23:08:41 ----D---- C:\Program Files\Reference Assemblies
2010-11-12 23:07:24 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-11-12 23:07:24 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-11-12 23:07:23 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-11-12 22:52:41 ----D---- C:\Documents and Settings\Administrator\Application Data\IDM
2010-11-12 22:52:40 ----D---- C:\Documents and Settings\Administrator\Application Data\DMCache
2010-11-12 22:52:37 ----D---- C:\Program Files\Internet Download Manager
2010-11-12 22:50:30 ----D---- C:\Program Files\Microsoft Synchronization Services
2010-11-12 22:34:44 ----D---- C:\Documents and Settings\Administrator\Application Data\Adobe
2010-11-12 22:29:31 ----D---- C:\Program Files\Mavituna Security
2010-11-12 22:27:35 ----A---- C:\WINDOWS\system32\btw_ci.dll
2010-11-12 22:27:19 ----D---- C:\Program Files\WIDCOMM
2010-11-12 22:24:51 ----D---- C:\Program Files\BreakPoint Software
2010-11-12 22:22:41 ----D---- C:\Program Files\ConTEXT
2010-11-12 22:22:29 ----D---- C:\Program Files\WinTools Software
2010-11-12 22:15:35 ----A---- C:\WINDOWS\system32\stlang.dll
2010-11-12 22:15:35 ----A---- C:\WINDOWS\system32\stacsv.exe
2010-11-12 22:15:35 ----A---- C:\WINDOWS\stsystra.exe
2010-11-12 22:15:18 ----A---- C:\WINDOWS\system32\stacapi.dll
2010-11-12 22:15:18 ----A---- C:\WINDOWS\system32\st325602.dll
2010-11-12 22:11:16 ----D---- C:\Documents and Settings\Administrator\Application Data\Nokia
2010-11-12 22:11:13 ----D---- C:\Documents and Settings\Administrator\Application Data\PC Suite
2010-11-12 22:11:10 ----HD---- C:\Program Files\InstallShield Installation Information
2010-11-12 22:11:10 ----D---- C:\Documents and Settings\All Users\Application Data\PC Suite
2010-11-12 22:10:14 ----D---- C:\Program Files\Common Files\PCSuite
2010-11-12 22:10:09 ----D---- C:\Program Files\Common Files\Nokia
2010-11-12 22:09:44 ----D---- C:\Program Files\DIFX
2010-11-12 22:09:40 ----A---- C:\WINDOWS\system32\BCMLogon.dll
2010-11-12 22:09:37 ----A---- C:\WINDOWS\system32\vcredist_x86.exe
2010-11-12 22:09:37 ----A---- C:\WINDOWS\system32\vcredist_x86.bat
2010-11-12 22:09:36 ----A---- C:\WINDOWS\system32\wltrynt.dll
2010-11-12 22:09:36 ----A---- C:\WINDOWS\system32\preflib.dll
2010-11-12 22:09:36 ----A---- C:\WINDOWS\system32\bcmwlu00.exe
2010-11-12 22:09:36 ----A---- C:\WINDOWS\system32\bcmwlpkt.dll
2010-11-12 22:09:35 ----A---- C:\WINDOWS\system32\WLTRYSVC.EXE
2010-11-12 22:09:35 ----A---- C:\WINDOWS\system32\WLTRAY.EXE
2010-11-12 22:09:35 ----A---- C:\WINDOWS\system32\WLBCGCBPRO731.DLL
2010-11-12 22:09:35 ----A---- C:\WINDOWS\system32\BCMWLTRY.EXE
2010-11-12 22:09:35 ----A---- C:\WINDOWS\system32\bcm1xsup.dll
2010-11-12 22:09:34 ----D---- C:\Program Files\Dell
2010-11-12 21:48:26 ----D---- C:\Program Files\PC Connectivity Solution
2010-11-12 21:48:18 ----A---- C:\WINDOWS\system32\wdfcoinstaller01009.dll
2010-11-12 21:48:18 ----A---- C:\WINDOWS\system32\nmwcdcocls.dll
2010-11-12 21:48:15 ----D---- C:\Program Files\Nokia
2010-11-12 21:48:15 ----A---- C:\WINDOWS\system32\nmwcdcls.dll
2010-11-12 21:47:21 ----D---- C:\Documents and Settings\Administrator\Application Data\InstallShield
2010-11-12 21:46:56 ----D---- C:\Program Files\SigmaTel
2010-11-12 21:46:56 ----D---- C:\Program Files\DellTPad
2010-11-12 21:46:47 ----A---- C:\WINDOWS\system32\WdfCoInstaller01005.dll
2010-11-12 21:46:47 ----A---- C:\WINDOWS\system32\Vxdif.dll
2010-11-12 21:45:38 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-11-12 21:44:50 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2010-11-12 21:44:29 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2010-11-12 21:42:04 ----D---- C:\Program Files\Microsoft
2010-11-12 21:41:41 ----D---- C:\Program Files\Windows Live SkyDrive
2010-11-12 21:41:26 ----D---- C:\Program Files\Windows Live
2010-11-12 21:34:01 ----A---- C:\WINDOWS\system32\msonpmon.dll
2010-11-12 21:30:38 ----D---- C:\Program Files\MSBuild
2010-11-12 21:30:16 ----D---- C:\Program Files\Common Files\DESIGNER
2010-11-12 21:27:39 ----D---- C:\Documents and Settings\All Users\Application Data\Installations
2010-11-12 21:27:34 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-11-12 21:26:19 ----D---- C:\Program Files\Common Files\Windows Live
2010-11-12 21:25:59 ----HD---- C:\WINDOWS\ShellNew
2010-11-12 21:25:11 ----D---- C:\Program Files\Microsoft Office
2010-11-12 21:25:09 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-11-12 21:24:43 ----RHD---- C:\MSOCache
2010-11-12 21:13:32 ----A---- C:\WINDOWS\system32\jit.dll
2010-11-12 21:13:32 ----A---- C:\WINDOWS\setdebug.exe
2010-11-12 21:13:30 ----A---- C:\WINDOWS\system32\javaee.dll
2010-11-12 21:13:29 ----A---- C:\WINDOWS\system32\dx3j.dll
2010-11-12 21:13:10 ----A---- C:\WINDOWS\system32\wjview.exe
2010-11-12 21:13:09 ----A---- C:\WINDOWS\system32\vmhelper.dll
2010-11-12 21:13:08 ----A---- C:\WINDOWS\system32\msjdbc10.dll
2010-11-12 21:13:07 ----A---- C:\WINDOWS\system32\msjava.dll
2010-11-12 21:13:06 ----A---- C:\WINDOWS\system32\msawt.dll
2010-11-12 21:13:05 ----A---- C:\WINDOWS\system32\jview.exe
2010-11-12 21:13:05 ----A---- C:\WINDOWS\system32\jdbgmgr.exe
2010-11-12 21:13:04 ----A---- C:\WINDOWS\system32\javart.dll
2010-11-12 21:13:03 ----A---- C:\WINDOWS\system32\javaprxy.dll
2010-11-12 21:13:03 ----A---- C:\WINDOWS\system32\javacypt.dll
2010-11-12 21:13:02 ----A---- C:\WINDOWS\system32\clspack.exe
2010-11-12 21:12:01 ----D---- C:\Program Files\Microsoft.NET
2010-11-12 21:10:27 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-11-12 21:09:57 ----D---- C:\Program Files\Common Files\Adobe
2010-11-12 21:09:57 ----D---- C:\Program Files\Adobe
2010-11-12 21:08:53 ----D---- C:\Program Files\GRETECH
2010-11-12 20:57:09 ----D---- C:\WINDOWS\system32\WindowsPowerShell
2010-11-12 20:57:08 ----D---- C:\WINDOWS\system32\winrm
2010-11-12 20:57:04 ----HDC---- C:\WINDOWS\$968930Uinstall_KB968930$
2010-11-12 20:45:31 ----D---- C:\WINDOWS\ie8updates
2010-11-12 20:44:49 ----D---- C:\WINDOWS\WBEM
2010-11-12 20:42:30 ----A---- C:\WINDOWS\system32\MRT.exe
2010-11-12 18:41:20 ----D---- C:\Program Files\COMODO
2010-11-12 18:38:41 ----D---- C:\Documents and Settings\Administrator\Application Data\Macromedia
2010-11-12 17:21:19 ----D---- C:\WINDOWS\system32\GroupPolicy
2010-11-12 17:20:13 ----D---- C:\Program Files\IDT
2010-11-12 17:19:50 ----D---- C:\Program Files\Windows Media Connect 2
2010-11-12 17:19:00 ----D---- C:\WINDOWS\system32\LogFiles
2010-11-12 17:18:39 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-11-12 17:17:40 ----RSD---- C:\WINDOWS\assembly
2010-11-12 17:17:40 ----D---- C:\WINDOWS\Microsoft.NET
2010-11-12 17:17:38 ----D---- C:\WINDOWS\system32\URTTemp
2010-11-12 16:58:36 ----D---- C:\Documents and Settings\Administrator\Application Data\Mozilla
2010-11-12 16:58:31 ----D---- C:\Program Files\Mozilla Firefox
2010-11-12 16:47:09 ----D---- C:\Documents and Settings\Administrator\Application Data\Help
2010-11-12 16:43:00 ----A---- C:\WINDOWS\system32\xpsp4res.dll
2010-11-12 16:33:30 ----D---- C:\Documents and Settings\All Users\Application Data\Comodo
2010-11-12 16:33:26 ----A---- C:\WINDOWS\system32\msvcr71.dll
2010-11-12 16:33:26 ----A---- C:\WINDOWS\system32\mfc71.dll
2010-11-12 14:51:18 ----SHD---- C:\RECYCLER
2010-11-11 19:26:28 ----A---- C:\WINDOWS\system32\h323log.txt
2010-11-11 18:40:53 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2010-11-11 18:40:53 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-11-11 18:37:51 ----SHD---- C:\WINDOWS\Installer
2010-11-11 18:37:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-11-11 18:37:50 ----D---- C:\Program Files\Common Files\ODBC
2010-11-11 18:37:50 ----A---- C:\WINDOWS\ODBCINST.INI
2010-11-11 18:37:47 ----D---- C:\Program Files\Common Files\SpeechEngines
2010-11-11 18:37:46 ----RD---- C:\Program Files
2010-11-11 18:37:46 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-11-11 18:37:46 ----D---- C:\Program Files\Common Files
2010-11-11 18:37:34 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2010-11-11 18:37:34 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2010-11-11 18:37:30 ----A---- C:\WINDOWS\system32\storprop.dll
2010-11-11 18:37:22 ----ASH---- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
2010-11-11 18:37:22 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2010-11-11 18:37:09 ----D---- C:\WINDOWS\system32\CatRoot2
2010-11-11 18:37:09 ----D---- C:\WINDOWS\system32\CatRoot
2010-11-11 18:37:03 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-11-11 18:36:44 ----A---- C:\WINDOWS\setuplog.txt
2010-11-11 18:36:41 ----D---- C:\Documents and Settings
2010-11-11 18:36:40 ----SHD---- C:\System Volume Information
2010-11-11 18:35:52 ----SH---- C:\boot.ini
2010-11-11 18:35:49 ----A---- C:\WINDOWS\system32\$winnt$.inf
2010-11-11 18:28:25 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-11-11 18:28:25 ----RSD---- C:\WINDOWS\Fonts
2010-11-11 18:28:25 ----RD---- C:\WINDOWS\Web
2010-11-11 18:28:25 ----HD---- C:\WINDOWS\inf
2010-11-11 18:28:25 ----D---- C:\WINDOWS\WinSxS
2010-11-11 18:28:25 ----D---- C:\WINDOWS\twain_32
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\wins
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\wbem
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\usmt
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\spool
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\ShellExt
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\Setup
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\scripting
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\ras
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\oobe
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\npp
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\mui
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\inetsrv
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\IME
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\icsxml
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\ias
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\export
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\en
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\drivers
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\dhcp
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\config
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\3com_dmi
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\3076
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\2052
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\1054
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\1042
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\1041
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\1037
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\1033
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\1031
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\1028
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32\1025
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system32
2010-11-11 18:28:25 ----D---- C:\WINDOWS\system
2010-11-11 18:28:25 ----D---- C:\WINDOWS\security
2010-11-11 18:28:25 ----D---- C:\WINDOWS\Resources
2010-11-11 18:28:25 ----D---- C:\WINDOWS\repair
2010-11-11 18:28:25 ----D---- C:\WINDOWS\Provisioning
2010-11-11 18:28:25 ----D---- C:\WINDOWS\PeerNet
2010-11-11 18:28:25 ----D---- C:\WINDOWS\pchealth
2010-11-11 18:28:25 ----D---- C:\WINDOWS\Network Diagnostic
2010-11-11 18:28:25 ----D---- C:\WINDOWS\mui
2010-11-11 18:28:25 ----D---- C:\WINDOWS\msapps
2010-11-11 18:28:25 ----D---- C:\WINDOWS\msagent