I've run HJT (see log below) and OTScanIt (see additional log below); I've also downloaded ERUNT and backed up my registry. I know I'll need to start getting heavy with my registry to get rid of this, so would very much appreciate your help
HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:31:08, on 14/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Documents and Settings\Lawrie.GORT\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll
O3 - Toolbar: &Google; Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (file missing)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5036.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://128.243.100.37/activex/AMC.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
–
End of file - 7631 bytes
OTScanIt Log:
OTScanIt2 logfile created on: 14/03/2009 16:02:15 - Run 1
OTScanIt2 by OldTimer - Version 1.0.8.0 Folder = C:\Documents and Settings\Lawrie.GORT\Desktop\OTScanIt2
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1.99 Gb Total Physical Memory | 1.44 Gb Available Physical Memory | 72.49% Memory free
3.84 Gb Paging File | 3.41 Gb Available in Paging File | 88.80% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 200.19 Gb Total Space | 55.95 Gb Free Space | 27.95% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 172.42 Gb Total Space | 127.49 Gb Free Space | 73.94% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: GORT
Current User Name: Lawrie
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
[Processes - Safe List]
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/10/01 13:06:14 | 00,116,040 | —- | M] (Apple Inc.)
avgrsx.exe -> %ProgramFiles%\AVG\AVG8\avgrsx.exe -> [2008/10/24 23:45:23 | 00,287,000 | —- | M] (AVG Technologies CZ, s.r.o.)
avgwdsvc.exe -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2008/10/24 23:45:19 | 00,231,704 | —- | M] (AVG Technologies CZ, s.r.o.)
bgsvcgen.exe -> %SystemRoot%\system32\bgsvcgen.exe -> [2007/06/14 18:57:42 | 00,145,504 | —- | M] (B.H.A Corporation)
explorer.exe -> %SystemRoot%\explorer.exe -> [2008/04/14 00:12:19 | 01,033,728 | —- | M] (Microsoft Corporation)
googleupdate.exe -> %UserProfile%\Local Settings\Application Data\Google\Update\GoogleUpdate.exe -> [2008/09/03 14:23:45 | 00,133,104 | —- | M] (Google Inc.)
hkcmd.exe -> %SystemRoot%\system32\hkcmd.exe -> [2006/03/19 20:13:40 | 00,077,824 | R— | M] (Intel Corporation)
igfxpers.exe -> %SystemRoot%\system32\igfxpers.exe -> [2006/03/19 20:17:50 | 00,118,784 | R— | M] (Intel Corporation)
jqs.exe -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2009/01/08 11:10:38 | 00,152,984 | —- | M] (Sun Microsystems, Inc.)
jusched.exe -> %ProgramFiles%\Java\jre6\bin\jusched.exe -> [2009/01/08 11:10:38 | 00,136,600 | —- | M] (Sun Microsystems, Inc.)
kservice.exe -> %ProgramFiles%\Kontiki\KService.exe -> [2007/04/23 10:22:14 | 03,068,352 | —- | M] (Kontiki Inc.)
lexbces.exe -> %SystemRoot%\system32\LEXBCES.EXE -> [2006/04/17 17:42:14 | 00,311,296 | —- | M] (Lexmark International, Inc.)
lexpps.exe -> %SystemRoot%\system32\LEXPPS.EXE -> [2006/04/17 17:41:24 | 00,174,592 | —- | M] (Lexmark International, Inc.)
lxczbmgr.exe -> %ProgramFiles%\Lexmark 1200 Series\lxczbmgr.exe -> [2006/07/13 05:22:50 | 00,057,344 | —- | M] (Lexmark International, Inc.)
lxczbmon.exe -> %ProgramFiles%\Lexmark 1200 Series\lxczbmon.exe -> [2006/07/13 05:33:14 | 00,053,248 | —- | M] (Lexmark International, Inc.)
mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.)
openvpnas.exe -> %ProgramFiles%\Hotspot Shield\bin\openvpnas.exe -> [2008/11/25 19:41:50 | 00,088,024 | —- | M] ()
otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2009/02/19 11:15:40 | 00,489,984 | —- | M] (OldTimer Tools)
rthdcpl.exe -> %SystemRoot%\RTHDCPL.EXE -> [2006/10/30 19:49:54 | 16,269,312 | —- | M] (Realtek Semiconductor Corp.)
tsvncache.exe -> %ProgramFiles%\TortoiseSVN\bin\TSVNCache.exe -> [2008/12/23 08:07:16 | 00,577,024 | —- | M] (http://tortoisesvn.net)
viewpointservice.exe -> %ProgramFiles%\Viewpoint\Common\ViewpointService.exe -> [2007/01/04 21:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation)
vsmon.exe -> %SystemRoot%\system32\ZoneLabs\vsmon.exe -> [2008/07/09 08:05:18 | 00,075,304 | —- | M] (Zone Labs, LLC)
wmpnetwk.exe -> %ProgramFiles%\Windows Media Player\WMPNetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)
wmpnscfg.exe -> %ProgramFiles%\Windows Media Player\WMPNSCFG.exe -> [2006/10/18 20:05:26 | 00,204,288 | —- | M] (Microsoft Corporation)
zlclient.exe -> %ProgramFiles%\Zone Labs\ZoneAlarm\zlclient.exe -> [2008/07/09 08:05:20 | 00,919,016 | —- | M] (Zone Labs, LLC)
[Win32 Services - Safe List]
(Adobe LM Service) Adobe LM Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Adobe Systems Shared\Service\Adobelmsvc.exe -> [2007/04/24 18:12:48 | 00,072,704 | —- | M] (Adobe Systems)
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/10/01 13:06:14 | 00,116,040 | —- | M] (Apple Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007/04/13 02:20:52 | 00,033,632 | —- | M] (Microsoft Corporation)
(ATMsrvc) ATM Service [Win32_Own | Disabled | Stopped] -> %SystemRoot%\System32\ATMsrvc.exe -> [2000/05/24 15:20:36 | 00,015,360 | —- | M] (Adobe Systems Incorporated)
(avg8wd) AVG Free8 WatchDog [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2008/10/24 23:45:19 | 00,231,704 | —- | M] (AVG Technologies CZ, s.r.o.)
(bgsvcgen) B's Recorder GOLD Library General Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\bgsvcgen.exe -> [2007/06/14 18:57:42 | 00,145,504 | —- | M] (B.H.A Corporation)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.)
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007/04/13 02:21:18 | 00,068,952 | —- | M] (Microsoft Corporation)
(FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> [2008/10/20 19:42:41 | 00,655,624 | —- | M] (Acresso Software Inc.)
(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2008/12/22 11:30:04 | 00,137,200 | —- | M] (Google)
(helpsvc) Help and Support [Win32_Shared | Auto | Running] -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/14 00:12:02 | 00,038,400 | —- | M] (Microsoft Corporation)
(HotspotShieldService) Hotspot Shield Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Hotspot Shield\bin\openvpnas.exe -> [2008/11/25 19:41:50 | 00,088,024 | —- | M] ()
(iPod Service) iPod Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/10/01 18:57:00 | 00,536,872 | —- | M] (Apple Inc.)
(JavaQuickStarterService) Java Quick Starter [Win32_Own | Auto | Running] -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2009/01/08 11:10:38 | 00,152,984 | —- | M] (Sun Microsystems, Inc.)
(KService) KService [Win32_Own | Auto | Running] -> %ProgramFiles%\Kontiki\KService.exe -> [2007/04/23 10:22:14 | 03,068,352 | —- | M] (Kontiki Inc.)
(LexBceS) LexBce Server [Win32_Own | Auto | Running] -> %SystemRoot%\system32\LEXBCES.EXE -> [2006/04/17 17:42:14 | 00,311,296 | —- | M] (Lexmark International, Inc.)
(Macromedia Licensing Service) Macromedia Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macromedia Shared\Service\Macromedia Licensing.exe -> [2004/07/30 01:19:22 | 00,069,632 | —- | M] (Macromedia)
(usnjsvc) Messenger Sharing Folders USN Journal Reader service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\Messenger\usnsvc.exe -> [2007/10/18 10:31:54 | 00,098,328 | —- | M] (Microsoft Corporation)
(Viewpoint Manager Service) Viewpoint Manager Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Viewpoint\Common\ViewpointService.exe -> [2007/01/04 21:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation)
(vsmon) TrueVector Internet Monitor [Win32_Own | Auto | Running] -> %SystemRoot%\system32\ZoneLabs\vsmon.exe -> [2008/07/09 08:05:18 | 00,075,304 | —- | M] (Zone Labs, LLC)
(WLSetupSvc) Windows Live Setup Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\installer\WLSetupSvc.exe -> [2007/10/25 14:27:54 | 00,266,240 | —- | M] (Microsoft Corporation)
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Windows Media Player\WMPNetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)
[Driver Services - Safe List]
(adfs) adfs [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\adfs.sys -> [2009/01/31 17:28:23 | 00,073,312 | —- | M] (Adobe Systems, Inc.)
(AvgLdx86) AVG Free AVI Loader Driver x86 [Kernel | System | Running] -> %SystemRoot%\System32\Drivers\avgldx86.sys -> [2008/10/24 23:45:37 | 00,097,928 | —- | M] (AVG Technologies CZ, s.r.o.)
(AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> %SystemRoot%\System32\Drivers\avgmfx86.sys -> [2008/10/24 23:45:35 | 00,026,824 | —- | M] (AVG Technologies CZ, s.r.o.)
(cdrbsdrv) cdrbsdrv [Kernel | System | Running] -> %SystemRoot%\System32\drivers\cdrbsdrv.sys -> [2006/02/20 01:17:40 | 00,033,408 | —- | M] (B.H.A Corporation)
(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\Drivers\GEARAspiWDM.sys -> [2008/04/17 13:12:54 | 00,015,464 | —- | M] (GEAR Software Inc.)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HDAudBus.sys -> [2008/04/13 16:36:05 | 00,144,384 | —- | M] (Windows ® Server 2003 DDK provider)
(ialm) ialm [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ialmnt5.sys -> [2006/03/19 20:47:06 | 01,166,972 | R— | M] (Intel Corporation)
(IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\RtkHDAud.sys -> [2006/11/03 09:32:30 | 04,394,496 | —- | M] (Realtek Semiconductor Corp.)
(KLIF) KLIF [File_System | System | Running] -> %SystemRoot%\system32\DRIVERS\klif.sys -> [2007/07/19 14:10:28 | 00,127,768 | —- | M] (Kaspersky Lab)
(MarvinBus) Pinnacle Marvin Bus [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\MarvinBus.sys -> [2005/09/23 22:18:32 | 00,171,520 | —- | M] (Pinnacle Systems GmbH)
(netwg311) NETGEAR WG311v2 802.11g Wireless PCI Adapter [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\netwg311.sys -> [2004/06/17 22:41:16 | 00,386,688 | —- | M] (Texas Instruments)
(pfc) Padus ASPI Shell [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\pfc.sys -> [2003/09/19 15:45:48 | 00,021,248 | —- | M] (Padus, Inc.)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ptilink.sys -> [2006/02/28 12:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.)
(ROOTMODEM) Microsoft Legacy Modem Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\Drivers\RootMdm.sys -> [2006/02/28 12:00:00 | 00,005,888 | —- | M] (Microsoft Corporation)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\secdrv.sys -> [2007/11/13 10:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(SQTECH930B) Trust WB-3500T USB2 Webcam [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\Capt930b.sys -> [2005/04/21 16:55:38 | 00,273,982 | —- | M] (Salix)
(srescan) srescan [Kernel | Boot | Running] -> %SystemRoot%\system32\ZoneLabs\srescan.sys -> [2008/02/27 02:10:44 | 00,051,176 | —- | M] (Zone Labs, LLC)
(tapvpn) TAP VPN Adapter [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\tapvpn.sys -> [2008/01/23 21:25:32 | 00,027,136 | —- | M] (The OpenVPN Project)
(USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\usbaapl.sys -> [2008/02/18 10:16:24 | 00,030,464 | —- | M] (Apple, Inc.)
(usbsermpt) Motorola USB Modem Driver for MPT [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\usbsermpt.sys -> [2008/01/29 22:03:23 | 00,022,768 | —- | M] (Microsoft Corporation)
(vsdatant) vsdatant [Kernel | System | Running] -> %SystemRoot%\System32\vsdatant.sys -> [2008/07/09 08:05:22 | 00,394,952 | —- | M] (Zone Labs, LLC)
(yukonwxp) NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\yk51x86.sys -> [2006/07/04 00:56:00 | 00,248,832 | R— | M] (Marvell)
[Registry - All]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> Reg Error: Invalid data type. ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_CURRENT_USER\: Main\\"Page_Transitions" -> Reg Error: Invalid data type. ->
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch ->
HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.google.com/ ->
HKEY_CURRENT_USER\: URLSearchHooks\\"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" [HKLM] -> %SystemRoot%\system32\ieframe.dll [Microsoft Url Search Hook] -> [2008/12/20 23:15:21 | 06,066,688 | —- | M] (Microsoft Corporation)
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 ->
< FireFox Settings [Default Profile] > -> C:\Documents and Settings\Lawrie.GORT\Application Data\Mozilla\FireFox\Profiles\rsdedr0s.default\prefs.js ->
browser.startup.homepage_override.mstone -> "rv:1.9.0.7" ->
extensions.enabledItems -> {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.1 ->
extensions.enabledItems -> [removed]:1.3.3 ->
extensions.enabledItems -> {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.4 ->
extensions.enabledItems -> {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11 ->
extensions.enabledItems -> [removed]:1.0 ->
extensions.enabledItems -> {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.6 ->
extensions.enabledItems -> {C1572E0F-42E3-4243-88EE-5DB3D978A919}:1.0 ->
extensions.enabledItems -> [removed]:1.0.2 ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7 ->
< HOSTS File > (302083 bytes and 10462 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
First 25 entries…
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1001namen.com
127.0.0.1 1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D; IE Protection] -> [2009/01/26 15:31:02 | 01,879,896 | —- | M] (Safer Networking Limited)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre6\bin\ssv.dll [Java™ Plug-In SSV Helper] -> [2009/01/08 11:10:40 | 00,320,920 | —- | M] (Sun Microsystems, Inc.)
{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [HKLM] -> %ProgramFiles%\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [Google Dictionary Compression sdch] -> [2008/12/22 10:41:45 | 00,522,224 | —- | M] (Google Inc.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> %ProgramFiles%\Java\jre6\bin\jp2ssv.dll [Java™ Plug-In 2 SSV Helper] -> [2009/01/08 11:10:38 | 00,034,816 | —- | M] (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} [HKLM] -> %ProgramFiles%\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [JQSIEStartDetectorImpl Class] -> [2009/01/08 11:10:42 | 00,073,728 | —- | M] (Sun Microsystems, Inc.)
{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} [HKLM] -> %ProgramFiles%\Hotspot Shield\hssie\HssIE.dll [Hotspot Shield Class] -> [2009/01/08 17:57:49 | 00,204,248 | —- | M] (AnchorFree Inc.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google; Toolbar] -> File not found
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\"{01E04581-4EEE-11D0-BFE9-00AA005B4383}" [HKLM] -> %SystemRoot%\system32\browseui.dll [&Address;] -> [2008/04/14 00:11:50 | 01,025,024 | —- | M] (Microsoft Corporation)
WebBrowser\\"{01E04581-4EEE-11D0-BFE9-00AA005B4383}" [HKLM] -> %SystemRoot%\system32\browseui.dll [&Address;] -> [2008/04/14 00:11:50 | 01,025,024 | —- | M] (Microsoft Corporation)
WebBrowser\\"{0E5CBF21-D15F-11D0-8301-00AA005B4383}" [HKLM] -> %SystemRoot%\system32\SHELL32.dll [&Links;] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google; Toolbar] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"AdobeCS4ServiceManager" -> %CommonProgramFiles%\Adobe\CS4ServiceManager\CS4ServiceManager.exe ["C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin] -> [2008/11/13 08:03:18 | 00,611,712 | —- | M] (Adobe Systems Incorporated)
"igfxhkcmd" -> %SystemRoot%\system32\hkcmd.exe [C:\WINDOWS\system32\hkcmd.exe] -> [2006/03/19 20:13:40 | 00,077,824 | R— | M] (Intel Corporation)
"igfxpers" -> %SystemRoot%\system32\igfxpers.exe [C:\WINDOWS\system32\igfxpers.exe] -> [2006/03/19 20:17:50 | 00,118,784 | R— | M] (Intel Corporation)
"igfxtray" -> %SystemRoot%\system32\igfxtray.exe [C:\WINDOWS\system32\igfxtray.exe] -> [2006/03/19 20:17:04 | 00,094,208 | R— | M] (Intel Corporation)
"Lexmark 1200 Series" -> %ProgramFiles%\Lexmark 1200 Series\lxczbmgr.exe ["C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"] -> [2006/07/13 05:22:50 | 00,057,344 | —- | M] (Lexmark International, Inc.)
"QuickTime Task" -> %ProgramFiles%\QuickTime\qttask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> [2008/09/06 15:09:14 | 00,413,696 | —- | M] (Apple Inc.)
"RTHDCPL" -> %SystemRoot%\RTHDCPL.EXE [RTHDCPL.EXE] -> [2006/10/30 19:49:54 | 16,269,312 | —- | M] (Realtek Semiconductor Corp.)
"SunJavaUpdateSched" -> %ProgramFiles%\Java\jre6\bin\jusched.exe ["C:\Program Files\Java\jre6\bin\jusched.exe"] -> [2009/01/08 11:10:38 | 00,136,600 | —- | M] (Sun Microsystems, Inc.)
"ZoneAlarm Client" -> %ProgramFiles%\Zone Labs\ZoneAlarm\zlclient.exe ["C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"] -> [2008/07/09 08:05:20 | 00,919,016 | —- | M] (Zone Labs, LLC)
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"WMPNSCFG" -> %ProgramFiles%\Windows Media Player\WMPNSCFG.exe [C:\Program Files\Windows Media Player\WMPNSCFG.exe] -> [2006/10/18 20:05:26 | 00,204,288 | —- | M] (Microsoft Corporation)
< All Users.WINDOWS Startup Folder > -> C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup ->
< Lawrie.GORT Startup Folder > -> C:\Documents and Settings\Lawrie.GORT\Start Menu\Programs\Startup ->
< Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [323] -> File not found
\\"NoDrives" -> [0] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"HonorAutoRunSetting" -> [1] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" -> [0] -> File not found
\\"legalnoticecaption" -> [] -> File not found
\\"legalnoticetext" -> [] -> File not found
\\"shutdownwithoutlogon" -> [1] -> File not found
\\"undockwithoutlogon" -> [1] -> File not found
\\"DisableRegistryTools" -> [0] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDrives" -> [0] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"NoDriveTypeAutoRun" -> [323] -> File not found
< CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
Sothink SWF Catcher -> %CommonProgramFiles%\SourceTec\SWF Catcher\InternetExplorer.htm [C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm] -> [2008/09/18 23:30:00 | 00,000,191 | —- | M] ()
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Menu: Spybot - Search & Destroy Configuration] -> [2009/01/26 15:31:02 | 01,879,896 | —- | M] (Safer Networking Limited)
{E19ADC6E-3909-43E4-9A89-B7B676377EE3}:C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm [HKLM] -> %CommonProgramFiles%\SourceTec\SWF Catcher\InternetExplorer.htm [Button: Sothink SWF Catcher] -> [2008/09/18 23:30:00 | 00,000,191 | —- | M] ()
{E19ADC6E-3909-43E4-9A89-B7B676377EE3}:C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm [HKLM] -> %CommonProgramFiles%\SourceTec\SWF Catcher\InternetExplorer.htm [Menu: Sothink SWF Catcher] -> [2008/09/18 23:30:00 | 00,000,191 | —- | M] ()
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/14 00:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/14 00:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> [Reg Error: Value error.] -> File not found
CmdMapping\\"{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}" [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> [2009/01/26 15:31:02 | 01,879,896 | —- | M] (Safer Networking Limited)
CmdMapping\\"{E19ADC6E-3909-43E4-9A89-B7B676377EE3}" [HKLM] -> %CommonProgramFiles%\SourceTec\SWF Catcher\SWFCatcher.dll [SWFDecompiler.InternetExplorer] -> [2007/02/09 09:00:00 | 00,397,312 | —- | M] (SourceTec)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 00:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find…=%s&mime;=%s ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5448 domain(s) found. ->
50 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5449 domain(s) found. ->
49 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{1239CC52-59EF-4DFA-8C61-90FFA846DF7E} [HKLM] -> http://www.musicnotes.com/download/mnviewer.cab [Musicnotes Viewer] ->
{166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwa…director/sw.cab [Shockwave ActiveX Control] ->
{4871A87A-BFDD-4106-8153-FFDE2BAC2967} [HKLM] -> http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab [DLM Control] ->
{5ED80217-570B-4DA9-BF44-BE107C0EC166} [HKLM] -> http://cdn.scan.onecare.live.com/resource/…lscbase5036.cab [Windows Live Safety Center Base Module] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab [Java Plug-in 1.6.0_11] ->
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab [Reg Error: Key error.] ->
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab [Java Plug-in 1.6.0_03] ->
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab [Java Plug-in 1.6.0_05] ->
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab [Java Plug-in 1.6.0_07] ->
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab [Java Plug-in 1.6.0_11] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab [Java Plug-in 1.6.0_11] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab [Shockwave Flash Object] ->
{DE625294-70E6-45ED-B895-CFFA13AEB044} [HKLM] -> http://128.243.100.37/activex/AMC.cab [AxisMediaControlEmb Class] ->
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{048A18A9-741B-4785-9540-C16433D3201A} -> () ->
{4820FF25-7CE6-4425-999B-AD9A7284958F} -> (1394 Net Adapter) ->
{7A444C36-76E8-4C6F-8863-0E8D46EA74AA} -> (NETGEAR WG311v2 802.11g Wireless PCI Adapter) ->
{B263F0DD-8276-46F2-9900-5253DFF88FA3} -> (Generic Marvell Yukon Chipset based Ethernet Controller) ->
{B7D89C76-E1D1-4318-AEE1-E2BA4E8B5891} -> () ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> %SystemRoot%\Explorer.exe -> [2008/04/14 00:12:19 | 01,033,728 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
*UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit ->
C:\WINDOWS\system32\userinit.exe -> %SystemRoot%\system32\userinit.exe -> [2008/04/14 00:12:38 | 00,026,112 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
*UIHost* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost ->
logonui.exe -> %SystemRoot%\system32\logonui.exe -> [2008/04/14 00:12:24 | 00,514,560 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet ->
rundll32 shell32 -> %SystemRoot%\System32\shell32.dll -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
Control_RunDLL "sysdm.cpl" -> %SystemRoot%\system32\sysdm.cpl -> [2008/04/14 00:12:41 | 00,300,544 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
crypt32chain -> %SystemRoot%\system32\crypt32.dll -> [2008/04/14 00:11:51 | 00,599,040 | —- | M] (Microsoft Corporation)
cryptnet -> %SystemRoot%\system32\cryptnet.dll -> [2008/04/14 00:11:51 | 00,064,512 | —- | M] (Microsoft Corporation)
cscdll -> %SystemRoot%\system32\cscdll.dll -> [2008/04/14 00:11:51 | 00,101,888 | —- | M] (Microsoft Corporation)
dimsntfy -> %SystemRoot%\System32\dimsntfy.dll -> [2008/04/14 00:11:52 | 00,019,456 | —- | M] (Microsoft Corporation)
igfxcui -> %SystemRoot%\system32\igfxdev.dll -> [2006/03/19 20:12:42 | 00,139,264 | R— | M] (Intel Corporation)
ScCertProp -> %SystemRoot%\system32\wlnotify.dll -> [2008/04/14 00:12:09 | 00,092,672 | —- | M] (Microsoft Corporation)
Schedule -> %SystemRoot%\system32\wlnotify.dll -> [2008/04/14 00:12:09 | 00,092,672 | —- | M] (Microsoft Corporation)
sclgntfy -> %SystemRoot%\system32\sclgntfy.dll -> [2008/04/14 00:12:05 | 00,020,480 | —- | M] (Microsoft Corporation)
SensLogn -> %SystemRoot%\system32\WlNotify.dll -> [2008/04/14 00:12:09 | 00,092,672 | —- | M] (Microsoft Corporation)
termsrv -> %SystemRoot%\system32\wlnotify.dll -> [2008/04/14 00:12:09 | 00,092,672 | —- | M] (Microsoft Corporation)
wlballoon -> %SystemRoot%\system32\wlnotify.dll -> [2008/04/14 00:12:09 | 00,092,672 | —- | M] (Microsoft Corporation)
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad ->
"{fbeb8a05-beee-4442-804e-409d6c4515e9}" [HKLM] -> %SystemRoot%\system32\SHELL32.dll [CDBurn] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
"{7849596a-48ea-486e-8937-a2a3009f31a9}" [HKLM] -> %SystemRoot%\system32\SHELL32.dll [PostBootReminder] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
"{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKLM] -> %SystemRoot%\system32\stobject.dll [SysTray] -> [2008/04/14 00:12:07 | 00,121,856 | —- | M] (Microsoft Corporation)
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> %SystemRoot%\system32\webcheck.dll [WebCheck] -> [2008/12/20 23:15:40 | 00,233,472 | —- | M] (Microsoft Corporation)
"{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" [HKLM] -> %SystemRoot%\system32\WPDShServiceObj.dll [WPDShServiceObj] -> [2006/10/18 21:47:22 | 00,133,632 | —- | M] (Microsoft Corporation)
< SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler ->
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}" [HKLM] -> %SystemRoot%\system32\browseui.dll [Browseui preloader] -> [2008/04/14 00:11:50 | 01,025,024 | —- | M] (Microsoft Corporation)
"{8C7461EF-2B13-11d2-BE35-3078302C2030}" [HKLM] -> %SystemRoot%\system32\browseui.dll [Component Categories cache daemon] -> [2008/04/14 00:11:50 | 01,025,024 | —- | M] (Microsoft Corporation)
< IFEO [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ ->
Your Image File Name Here without a path -> %SystemRoot%\System32\ntsd.exe [Debugger] -> [2006/02/28 12:00:00 | 00,031,744 | —- | M] (Microsoft Corporation)
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" [HKLM] -> %SystemRoot%\system32\shell32.dll [] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
*SecurityProviders* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
msapsspc.dll -> %SystemRoot%\system32\msapsspc.dll -> [2008/04/14 00:11:58 | 00,086,016 | —- | M] (Microsoft Corporation)
schannel.dll -> %SystemRoot%\system32\schannel.dll -> [2008/12/05 06:54:55 | 00,144,896 | —- | M] (Microsoft Corporation)
digest.dll -> %SystemRoot%\system32\digest.dll -> [2008/04/14 00:11:52 | 00,068,608 | —- | M] (Microsoft Corporation)
msnsspc.dll -> %SystemRoot%\system32\msnsspc.dll -> [2008/04/14 00:12:00 | 00,290,816 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages ->
*LSA Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages ->
msv1_0 -> %SystemRoot%\System32\msv1_0.dll -> [2008/04/14 00:12:00 | 00,132,608 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages ->
*LSA Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages ->
kerberos -> %SystemRoot%\System32\kerberos.dll -> [2008/04/14 00:11:56 | 00,299,520 | —- | M] (Microsoft Corporation)
msv1_0 -> %SystemRoot%\System32\msv1_0.dll -> [2008/04/14 00:12:00 | 00,132,608 | —- | M] (Microsoft Corporation)
schannel -> %SystemRoot%\System32\schannel.dll -> [2008/12/05 06:54:55 | 00,144,896 | —- | M] (Microsoft Corporation)
wdigest -> %SystemRoot%\System32\wdigest.dll -> [2008/04/14 00:12:08 | 00,049,152 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 18:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 00:12:34 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\livecall.exe" -> C:\Program Files\Windows Live\Messenger\livecall.exe [C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007/10/02 16:18:24 | 00,304,488 | —- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007/10/18 10:34:02 | 05,724,184 | —- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 18:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 00:12:34 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\installs\utorrent.exe" -> C:\installs\utorrent.exe [C:\installs\utorrent.exe:*:Enabled:µTorrent] -> [2009/02/21 18:26:29 | 00,270,128 | —- | M] (BitTorrent, Inc.)
"C:\Program Files\AVG\AVG8\avgupd.exe" -> C:\Program Files\AVG\AVG8\avgupd.exe [C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe] -> [2008/10/24 23:45:22 | 00,641,304 | —- | M] (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.)
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -> C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4] -> [2008/11/13 08:03:18 | 00,611,712 | —- | M] (Adobe Systems Incorporated)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" -> C:\Program Files\Common Files\AOL\Loader\aolload.exe [C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader] -> [2006/11/03 07:17:27 | 00,010,800 | —- | M] (AOL LLC)
"C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2008/10/01 18:57:04 | 14,258,472 | —- | M] (Apple Inc.)
"C:\Program Files\Kontiki\KService.exe" -> C:\Program Files\Kontiki\KService.exe [C:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service] -> [2007/04/23 10:22:14 | 03,068,352 | —- | M] (Kontiki Inc.)
"C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe" -> C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe [C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe:*:Enabled:Render Manager] -> [2008/05/13 11:42:40 | 00,079,120 | —- | M] (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe" -> C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe [C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe:*:Enabled:Studio] -> [2008/05/13 11:26:04 | 06,034,704 | —- | M] (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe" -> C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe [C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe:*:Enabled:umi] -> [2008/05/13 11:42:42 | 00,087,312 | —- | M] (Pinnacle Systems)
"C:\Program Files\Skype\Phone\Skype.exe" -> C:\Program Files\Skype\Phone\Skype.exe [C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype] -> [2007/09/13 12:31:38 | 22,880,040 | R— | M] (Skype Technologies S.A.)
"C:\Program Files\Spotify\spotify.exe" -> C:\Program Files\Spotify\spotify.exe [C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify] -> [2009/02/27 22:51:24 | 02,517,888 | —- | M] (Spotify AB)
"C:\Program Files\Windows Live\Messenger\livecall.exe" -> C:\Program Files\Windows Live\Messenger\livecall.exe [C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007/10/02 16:18:24 | 00,304,488 | —- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007/10/18 10:34:02 | 05,724,184 | —- | M] (Microsoft Corporation)
"C:\xampplite\apache\bin\apache.exe" -> C:\xampplite\apache\bin\apache.exe [C:\xampplite\apache\bin\apache.exe:*:Enabled:Apache HTTP Server] -> [2007/03/05 10:23:02 | 00,016,896 | —- | M] (Apache Software Foundation)
"C:\xampplite\mysql\bin\mysqld.exe" -> C:\xampplite\mysql\bin\mysqld.exe [C:\xampplite\mysql\bin\mysqld.exe:*:Enabled:mysqld] -> [2007/03/13 09:51:45 | 05,468,160 | —- | M] ()
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> %SystemRoot%\system32\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/04/13 18:40:46 | 00,062,976 | —- | M] (Microsoft Corporation)
< Drives with AutoRun files > -> ->
C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2004/02/06 20:58:24 | 00,000,000 | —- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
\{197fa470-2e28-11dd-8113-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{197fa470-2e28-11dd-8113-000138300101}\Shell\Auto\command
\{197fa470-2e28-11dd-8113-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{197fa470-2e28-11dd-8113-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{197fa470-2e28-11dd-8113-000138300101}\Shell\AutoRun
\{197fa470-2e28-11dd-8113-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{197fa470-2e28-11dd-8113-000138300101}\Shell\AutoRun\command
\{197fa470-2e28-11dd-8113-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{2bfa8dc6-9520-11dd-ab77-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bfa8dc6-9520-11dd-ab77-000138300101}\Shell\Auto\command
\{2bfa8dc6-9520-11dd-ab77-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{2bfa8dc6-9520-11dd-ab77-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bfa8dc6-9520-11dd-ab77-000138300101}\Shell\AutoRun
\{2bfa8dc6-9520-11dd-ab77-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bfa8dc6-9520-11dd-ab77-000138300101}\Shell\AutoRun\command
\{2bfa8dc6-9520-11dd-ab77-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{2bfa8dd3-9520-11dd-ab77-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bfa8dd3-9520-11dd-ab77-000138300101}\Shell\Auto\command
\{2bfa8dd3-9520-11dd-ab77-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{2bfa8dd3-9520-11dd-ab77-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bfa8dd3-9520-11dd-ab77-000138300101}\Shell\AutoRun
\{2bfa8dd3-9520-11dd-ab77-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bfa8dd3-9520-11dd-ab77-000138300101}\Shell\AutoRun\command
\{2bfa8dd3-9520-11dd-ab77-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{54b5f96c-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5f96c-8f93-11dd-ab6e-000138300101}\Shell\Auto\command
\{54b5f96c-8f93-11dd-ab6e-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{54b5f96c-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5f96c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun
\{54b5f96c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5f96c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command
\{54b5f96c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{54b5fb20-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb20-8f93-11dd-ab6e-000138300101}\Shell\Auto\command
\{54b5fb20-8f93-11dd-ab6e-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{54b5fb20-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb20-8f93-11dd-ab6e-000138300101}\Shell\AutoRun
\{54b5fb20-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb20-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command
\{54b5fb20-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{54b5fb2c-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb2c-8f93-11dd-ab6e-000138300101}\Shell\Auto\command
\{54b5fb2c-8f93-11dd-ab6e-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{54b5fb2c-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb2c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun
\{54b5fb2c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb2c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command
\{54b5fb2c-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{54b5fb3e-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb3e-8f93-11dd-ab6e-000138300101}\Shell\Auto\command
\{54b5fb3e-8f93-11dd-ab6e-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{54b5fb3e-8f93-11dd-ab6e-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb3e-8f93-11dd-ab6e-000138300101}\Shell\AutoRun
\{54b5fb3e-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b5fb3e-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command
\{54b5fb3e-8f93-11dd-ab6e-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{79178b5f-eec8-11dd-ada3-00301b434687}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{79178b5f-eec8-11dd-ada3-00301b434687}\Shell
\{79178b5f-eec8-11dd-ada3-00301b434687}\Shell\\"" -> [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{79178b5f-eec8-11dd-ada3-00301b434687}\Shell\AutoRun
\{79178b5f-eec8-11dd-ada3-00301b434687}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{79178b5f-eec8-11dd-ada3-00301b434687}\Shell\AutoRun\command
\{79178b5f-eec8-11dd-ada3-00301b434687}\Shell\AutoRun\command\\"" -> D:\LaunchU3.exe [D:\LaunchU3.exe -a] -> File not found
\{aefd0edc-905e-11dd-ab6f-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aefd0edc-905e-11dd-ab6f-000138300101}\Shell\Auto\command
\{aefd0edc-905e-11dd-ab6f-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{aefd0edc-905e-11dd-ab6f-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aefd0edc-905e-11dd-ab6f-000138300101}\Shell\AutoRun
\{aefd0edc-905e-11dd-ab6f-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aefd0edc-905e-11dd-ab6f-000138300101}\Shell\AutoRun\command
\{aefd0edc-905e-11dd-ab6f-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
\{e068c68f-6921-11dd-af99-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e068c68f-6921-11dd-af99-000138300101}\Shell\Auto\command
\{e068c68f-6921-11dd-af99-000138300101}\Shell\Auto\command\\"" -> [Run Me.exe] -> File not found
\{e068c68f-6921-11dd-af99-000138300101}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e068c68f-6921-11dd-af99-000138300101}\Shell\AutoRun
\{e068c68f-6921-11dd-af99-000138300101}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e068c68f-6921-11dd-af99-000138300101}\Shell\AutoRun\command
\{e068c68f-6921-11dd-af99-000138300101}\Shell\AutoRun\command\\"" -> %SystemRoot%\system32\Shell32.DLL [C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RunMe.exe] -> [2008/06/17 19:02:19 | 08,461,312 | —- | M] (Microsoft Corporation)
[Files/Folders - Created Within 30 Days]
1 C:\*.tmp files -> C:\*.tmp ->
ERUNT -> %ProgramFiles%\ERUNT -> [2009/03/14 14:52:57 | 00,000,000 | —D | C]
OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2009/03/14 14:52:29 | 00,000,000 | —D | C]
stuff.html -> %UserProfile%\Desktop\stuff.html -> [2009/03/14 14:47:26 | 00,007,736 | —- | C] ()
ComboFix -> %SystemDrive%\ComboFix -> [2009/03/14 14:23:37 | 00,000,000 | —D | C]
MRT.exe -> %SystemRoot%\System32\MRT.exe -> [2009/03/12 23:31:10 | 24,768,960 | —- | C] (Microsoft Corporation)
gdlogo.swf -> %UserProfile%\Desktop\gdlogo.swf -> [2009/03/11 19:38:43 | 00,000,846 | —- | C] ()
gdlogo.fla -> %UserProfile%\Desktop\gdlogo.fla -> [2009/03/11 19:38:41 | 00,083,456 | —- | C] ()
push.jpg -> %UserProfile%\Desktop\push.jpg -> [2009/03/11 11:45:34 | 00,198,647 | —- | C] ()
cmldr -> %SystemDrive%\cmldr -> [2009/03/07 17:22:15 | 00,260,272 | —- | C] ()
cmdcons -> %SystemDrive%\cmdcons -> [2009/03/07 17:22:13 | 00,000,000 | RHSD | C]
Malwarebytes -> %AppData%\Malwarebytes -> [2009/03/06 16:47:38 | 00,000,000 | —D | C]
mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009/03/06 16:47:33 | 00,015,504 | —- | C] (Malwarebytes Corporation)
mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009/03/06 16:47:30 | 00,038,496 | —- | C] (Malwarebytes Corporation)
Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [2009/03/06 16:47:29 | 00,000,000 | —D | C]
Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware -> [2009/03/06 16:47:28 | 00,000,000 | —D | C]
Plasmaplugs Scroll Bar Quickstart Guide (Trial).pdf -> %UserProfile%\My Documents\Plasmaplugs Scroll Bar Quickstart Guide (Trial).pdf -> [2009/02/27 22:30:51 | 00,325,610 | —- | C] ()
sqmnoopt04.sqm -> %SystemDrive%\sqmnoopt04.sqm -> [2009/02/24 19:23:57 | 00,000,244 | -H– | C] ()
sqmdata04.sqm -> %SystemDrive%\sqmdata04.sqm -> [2009/02/24 19:23:57 | 00,000,232 | -H– | C] ()
sqmnoopt03.sqm -> %SystemDrive%\sqmnoopt03.sqm -> [2009/02/24 19:23:35 | 00,000,244 | -H– | C] ()
sqmdata03.sqm -> %SystemDrive%\sqmdata03.sqm -> [2009/02/24 19:23:35 | 00,000,232 | -H– | C] ()
Grammatics.zip -> %UserProfile%\Desktop\Grammatics.zip -> [2009/02/20 16:07:13 | 90,643,434 | —- | C] ()
[Files/Folders - Modified Within 30 Days]
1 C:\*.tmp files -> C:\*.tmp ->
1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp ->
2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->
2 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp ->
fidbox.dat -> %SystemRoot%\System32\drivers\fidbox.dat -> [2009/03/14 16:02:59 | 53,960,736 | -HS- | M] ()
rtdrvmon.exe -> %UserProfile%\Local Settings\temp\rtdrvmon.exe -> [2009/03/14 15:40:25 | 00,040,960 | —- | M] (Realtek)
qmgr0.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2009/03/14 15:34:14 | 00,004,232 | —- | M] ()
qmgr1.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2009/03/14 15:34:13 | 00,005,847 | —- | M] ()
GoogleUpdateTaskUserS-1-5-21-1275210071-1580436667-682003330-1004.job -> %SystemRoot%\tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-1580436667-682003330-1004.job -> [2009/03/14 15:33:58 | 00,001,210 | —- | M] ()
NTUSER.DAT -> %UserProfile%\NTUSER.DAT -> [2009/03/14 14:52:59 | 11,796,480 | -H– | M] ()
stuff.html -> %UserProfile%\Desktop\stuff.html -> [2009/03/14 14:47:26 | 00,007,736 | —- | M] ()
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2009/03/14 14:35:58 | 00,000,006 | -H– | M] ()
system.ini -> %SystemRoot%\system.ini -> [2009/03/14 14:30:55 | 00,000,227 | —- | M] ()
vsconfig.xml -> %SystemRoot%\System32\vsconfig.xml -> [2009/03/14 11:19:12 | 00,352,918 | —- | M] ()
Perflib_Perfdata_660.dat -> %SystemRoot%\Temp\Perflib_Perfdata_660.dat -> [2009/03/14 11:19:02 | 00,016,384 | —- | M] ()
Perflib_Perfdata_378.dat -> %SystemRoot%\Temp\Perflib_Perfdata_378.dat -> [2009/03/14 11:19:02 | 00,016,384 | —- | M] ()
bootstat.dat -> %SystemRoot%\bootstat.dat -> [2009/03/14 11:18:28 | 00,002,048 | –S- | M] ()
fidbox.idx -> %SystemRoot%\System32\drivers\fidbox.idx -> [2009/03/13 21:57:50 | 00,633,236 | -HS- | M] ()
ntuser.ini -> %UserProfile%\ntuser.ini -> [2009/03/13 21:57:25 | 00,000,178 | -HS- | M] ()
hosts -> %SystemRoot%\System32\drivers\etc\hosts -> [2009/03/13 17:20:54 | 00,302,083 | R— | M] ()
win.ini -> %SystemRoot%\win.ini -> [2009/03/13 14:42:19 | 00,000,754 | —- | M] ()
gdlogo.swf -> %UserProfile%\Desktop\gdlogo.swf -> [2009/03/12 21:17:37 | 00,000,846 | —- | M] ()
gdlogo.fla -> %UserProfile%\Desktop\gdlogo.fla -> [2009/03/11 19:39:57 | 00,083,456 | —- | M] ()
FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2009/03/11 17:51:37 | 02,614,840 | —- | M] ()
imsins.BAK -> %SystemRoot%\imsins.BAK -> [2009/03/11 14:23:19 | 00,001,374 | —- | M] ()
GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [2009/03/11 12:03:23 | 00,277,768 | —- | M] ()
push.jpg -> %UserProfile%\Desktop\push.jpg -> [2009/03/11 11:45:34 | 00,198,647 | —- | M] ()
wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2009/03/11 11:39:19 | 00,013,646 | —- | M] ()
WORDPAD.INI -> %SystemRoot%\WORDPAD.INI -> [2009/03/08 19:00:35 | 00,000,754 | —- | M] ()
boot.ini -> %SystemDrive%\boot.ini -> [2009/03/07 17:22:16 | 00,000,281 | RHS- | M] ()
puhutibi -> %SystemRoot%\System32\puhutibi -> [2009/03/06 20:08:41 | 00,006,456 | -H– | M] ()
wininit.ini -> %SystemRoot%\wininit.ini -> [2009/03/06 15:34:54 | 00,000,211 | —- | M] ()
hosts.20090313-172054.backup -> %SystemRoot%\System32\drivers\etc\hosts.20090313-172054.backup -> [2009/03/06 14:56:59 | 00,301,855 | R— | M] ()
PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [2009/03/06 14:55:55 | 00,458,340 | —- | M] ()
hosts.20090306-145659.backup -> %SystemRoot%\System32\drivers\etc\hosts.20090306-145659.backup -> [2009/03/06 14:45:19 | 00,301,855 | R— | M] ()
seRapid.INI -> %SystemRoot%\seRapid.INI -> [2009/03/05 18:29:39 | 00,008,581 | —- | M] ()
My Sharing Folders.lnk -> %UserProfile%\My Documents\My Sharing Folders.lnk -> [2009/03/05 18:05:18 | 00,000,598 | —- | M] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009/03/04 20:13:58 | 00,114,688 | —- | M] ()
Boot.bak -> %SystemDrive%\Boot.bak -> [2009/03/01 16:37:43 | 00,000,211 | —- | M] ()
Plasmaplugs Scroll Bar Quickstart Guide (Trial).pdf -> %UserProfile%\My Documents\Plasmaplugs Scroll Bar Quickstart Guide (Trial).pdf -> [2009/02/27 22:30:54 | 00,325,610 | —- | M] ()
MRT.exe -> %SystemRoot%\System32\MRT.exe -> [2009/02/25 12:55:00 | 24,768,960 | —- | M] (Microsoft Corporation)
sqmnoopt04.sqm -> %SystemDrive%\sqmnoopt04.sqm -> [2009/02/24 19:23:57 | 00,000,244 | -H– | M] ()
sqmdata04.sqm -> %SystemDrive%\sqmdata04.sqm -> [2009/02/24 19:23:57 | 00,000,232 | -H– | M] ()
sqmnoopt03.sqm -> %SystemDrive%\sqmnoopt03.sqm -> [2009/02/24 19:23:35 | 00,000,244 | -H– | M] ()
sqmdata03.sqm -> %SystemDrive%\sqmdata03.sqm -> [2009/02/24 19:23:35 | 00,000,232 | -H– | M] ()
Grammatics.zip -> %UserProfile%\Desktop\Grammatics.zip -> [2009/02/20 16:07:33 | 90,643,434 | —- | M] ()
[Alternate Data Streams]
@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
[CatchMe Rootkit Scan by GMER]
< Windows folder & sub-folders >
scanning hidden processes …
scanning hidden services & system hive …
scanning hidden registry entries …
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8087AC70-BFCC-FFCC-CD69-BCEDAE79A4B5}]
"nafaejpagpjnheabmnbhkbnaocao"=hex:6a,61,70,6a,67,6a,6c,6b,70,6c,66,6c,6e,61,62,63,61,6e,6b,67,00,..
"oalaoigdkiafheenbpphbhfjcmkodl"=hex:6a,61,6f,6a,61,6e,62,67,70,66,6e,6d,61,6c,68,67,6a,6f,6f,68,00,..
"gbdonjpjfmeadhemcjgldpindhbhfoljjbkcpdcnpjkiij"=hex:6c,61,69,61,6b,69,6c,68,64,61,66,6c,70,6c,6c,6c,6d,6a,65,67,6f,..
"bbnodjjipgeoeehkifmkmbjccdelfaledoil"=hex:67,61,6e,70,61,6e,69,6c,62,6f,70,67,69,66,00,6c
"oalaoigdkiafheenbpphbhfjplnmnh"=hex:6a,61,70,6a,67,6a,6c,6b,70,6c,66,6c,6e,61,62,63,61,6e,6b,67,00,..
"nafaejpagpjnheabmnbhkboancja"=hex:6a,61,70,6a,67,6a,6c,6b,70,6c,66,6c,6e,61,62,63,61,6e,6b,67,00,..
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 6
< Document and Settings folder & sub folders >
scanning hidden files …
C:\Documents and Settings\All Users\Application Data\Symantec\hpc:3898751835 113 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:364682BC 104 bytes
C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:8CE646EE 119 bytes
C:\Documents and Settings\Lawrie\Favorites\Abandonia - Home of abandonware DOS games.url:favicon 1150 bytes
C:\Documents and Settings\Lawrie.GORT\Cookies\[removed][2].txt 2194 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Bugmenot.com - login with these free web passwords to bypass compulsory registration.url:favicon 3638 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\CineWord Nottingham.url:favicon 1406 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Em Calculator.url:favicon 1406 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Flickr API Documentation.url:favicon 0 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Krop - Creative & Tech Jobs.url:favicon 1150 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Mumfy\52 Cupcakes.url:favicon 3638 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Mumfy\BBC - Food - Recipes - Chorizo chicken with sauteed chorizo, potatoes and spinach.url:favicon 958 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Mumfy\How To Make A Gumpaste Stargazer Lily (Asian Lily) on CakeCentral.com.url:favicon 1022 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Mumfy\Sprinkles Cupcakes Flavors.url:favicon 3638 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Radio Times TV listings grid.url:favicon 3638 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\The Anonymous Philanthropist.url:favicon 2550 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\tunecore - digital distribution.url:favicon 894 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\WhatTheFont MyFonts.url:favicon 318 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Who is Hosting This.url:favicon 3638 bytes
C:\Documents and Settings\Lawrie.GORT\Favorites\Zamzar - Free online file conversion.url:favicon 3638 bytes
C:\Documents and Settings\Mumfy\Local Settings\Temporary Internet Files\AntiPhishing\07FB382D-AA75-4683-82F4-EAB265A275CB.dat 78924 bytes
C:\Documents and Settings\Mumfy\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat 78924 bytes
scan completed successfully
Thanks for the help.