This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Did THIS break my internet?

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, new to all this today, but Google is re-directing to other places and PC keeps crashing, so read this was a good thing to do. Any help gratefully appreciated!

Hijack log here:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:15:30, on 09/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Program Files\Cheetah Burner\Cheetah DVD Burner\NMSAccess.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\dvd43\dvd43_tray.exe
D:\Program Files\Winamp\winampa.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\windows\ld08.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\SYS32DLL.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\System32\SYS32DLL.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
D:\Documents\windows-kb890830-v2.9.exe
d:\d2cc77214a9cc51beb850e\mrtstub.exe
C:\WINDOWS\system32\MRT.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\pavuppad.exe,C:\WINDOWS\system32\twext.exe,C:\WINDOWS\system32\sdra64.exe,
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MS extension - {1925C7E1-5540-4675-8198-8A2779D4072A} - msfgw32.dll (file missing)
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Matt Hughes Toolbar - {A057A204-BACC-4D26-BAF6-49F8CCAB3ED4} - C:\PROGRA~1\PRODEG~1\PRODEG~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Matt Hughes Toolbar - {A057A204-BACC-4D26-BAF6-49F8CCAB3ED4} - C:\PROGRA~1\PRODEG~1\PRODEG~1.DLL
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [vssms32] C:\WINDOWS\system32\vssms32.exe
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [sysldtray] C:\windows\ld08.exe
O4 - HKLM\..\Run: [pp] C:\windows\pp06.exe
O4 - HKLM\..\Run: [muBlinder] C:\Program Files\muBlinder\muBlinder.exe -startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Spamone] C:\DOCUME~1\ANDREW~1\APPLIC~1\JUGSHE~1\online 4 program.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [internat] C:\WINDOWS\internat.exe
O4 - HKCU\..\Run: [SYS32DLL] SYS32DLL
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Xfire.lnk = D:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1220281776046
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1220281767609
O16 - DPF: {6F714D46-E4EF-11D4-93EF-00D0D7032099} (Active DJ Studio ActiveX Control) - http://www.christianrock2.net/amp3dj.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: NMSAccess - Unknown owner - D:\Program Files\Cheetah Burner\Cheetah DVD Burner\NMSAccess.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe

–
End of file - 13758 bytes
Hi there unfortunately Hijackthis no longer shows the full picture - so I will need to use another tool. But, first lets try to stop the redirects

Go to Control Panel and select Internet Options
Select the Connections TAB
Select LAN settings button
Ensure there is no tick in the Proxy Server box
Select OK and restart Internet explorer


And for Firefox there are instructions on this page and you want the setting to be no proxy

THEN

Download Rooter.exe to your desktop
  • Doubleclick it to start the tool.
  • A Notepad file containing the report will open, also found at %systemdrive%(usually C:)\Rooter.txt. Copy and paste it with your OTLI log.

THEN

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Wow somehow I have lost my internet connection all together. My downloads are still working, so the connection IS still there, but no internet is working despite repairing connection and trying to set it up again - any ideas anyone? Obviously I can't do what you've suggested until my internet is working again!
Hi everyone,

following the advice of a friend, I did a 'Hijackthis' analysis on my PC. However, I accidentally deleted the first thing it showed up, which was all about my homepage (by memory I THINK it was like this: R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dooyoo.co.uk


Anyway, now the internet won't work. I have tried all the things I know, like 'repairing connection', but it just isn't working. I know there is a signal coming through because my downloads are still working, but I just can't get on the net. It says something about failing to connect with the server (I am doing this from work).

My question is this: if I deleted the above file (it definitely was one that had my homepage listed on it), would that account for the non-working internet, and what can I do to mend it? If someone tells me something that mends this I will send them $10 on Paypal!

If it's relevant, I also did a malwarebytes anti malware analysis and deleted what it found, and did ATF cleaner too. I am a novice at PCs and dead stuck!

Thanks

Bruffyboy
OK, first off, the net is now working (from unchecking 'use a proxy server') so thanks so much for that.

Rooter analysis is here:

Microsoft Windows XP Professional (5.1.2600) Service Pack 2

C:\ [Fixed] - NTFS - (Total:10103 Mo/Free:2299 Mo)
D:\ [Fixed] - NTFS - (Total:142521 Mo/Free:1963 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)

11/05/2009|18:36

———————-\\ Processes..

–Locked– [System Process]
———- System
———- \??\C:\WINDOWS\system32\csrss.exe
———- \??\C:\WINDOWS\system32\winlogon.exe
———- C:\WINDOWS\system32\services.exe
———- C:\WINDOWS\system32\lsass.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
———- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
———- C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
———- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
———- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
———- C:\WINDOWS\Explorer.EXE
———- C:\WINDOWS\system32\spoolsv.exe
———- C:\Program Files\Bonjour\mDNSResponder.exe
———- C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\Program Files\Kontiki\KService.exe
———- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
———- C:\WINDOWS\system32\nvsvc32.exe
———- C:\WINDOWS\system32\oodag.exe
———- C:\WINDOWS\system32\PnkBstrA.exe
———- C:\WINDOWS\system32\PnkBstrB.exe
———- C:\Program Files\CyberLink\Shared Files\RichVideo.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
———- C:\Program Files\Windows Media Player\WMPNetwk.exe
———- C:\WINDOWS\System32\alg.exe
———- C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
———- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
———- C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
———- C:\Program Files\MessengerPlus! 3\MsgPlus.exe
———- C:\WINDOWS\system32\RUNDLL32.EXE
———- C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
———- C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
———- D:\Program Files\Winamp\winampa.exe
———- C:\Program Files\iTunes\iTunesHelper.exe
———- C:\WINDOWS\system32\ctfmon.exe
———- C:\Program Files\Messenger\msmsgs.exe
———- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
———- C:\Program Files\Kontiki\KHost.exe
———- C:\Program Files\Windows Media Player\WMPNSCFG.exe
———- C:\Program Files\iPod\bin\iPodService.exe
———- D:\Program Files\Winamp\Winamp.exe
———- C:\Program Files\Internet Explorer\iexplore.exe
———- C:\Program Files\Internet Explorer\iexplore.exe
———- C:\Program Files\uTorrent\uTorrent.exe
———- C:\Program Files\Internet Explorer\iexplore.exe
———- C:\Program Files\Internet Explorer\iexplore.exe
———- C:\Documents and Settings\Andrew and Claire\Desktop\Rooter.exe
———- C:\WINDOWS\system32\cmd.exe
———- C:\Rooter$\RK.exe

———————-\\ Search..

Trojan ! .. c:\docume~1\andrew~1\applic~1\jugshe~1\trustcornoption.exe

———————-\\ Tasks



Next up, OTListOT

OTListIt logfile created on: 11/05/2009 18:40:14 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.6 Folder = C:\Documents and Settings\Andrew and Claire\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 422.29 Mb Available Physical Memory | 41.26% Memory free
1.65 Gb Paging File | 1.19 Gb Available in Paging File | 71.75% Paging File free
Paging file location(s): D:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9.87 Gb Total Space | 2.24 Gb Free Space | 22.74% Space Free | Partition Type: NTFS
Drive D: | 139.18 Gb Total Space | 9.92 Gb Free Space | 7.13% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STEPHEN
Current User Name: Andrew and Claire
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\system32\oodag.exe (O&O Software GmbH)
PRC - C:\WINDOWS\system32\PnkBstrA.exe ()
PRC - C:\WINDOWS\system32\PnkBstrB.exe ()
PRC - C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe (NVIDIA Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\MessengerPlus! 3\MsgPlus.exe (Patchou)
PRC - C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE (Logitech Inc.)
PRC - C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - D:\Program Files\Winamp\winampa.exe ()
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
PRC - C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Documents and Settings\Andrew and Claire\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (ccEvtMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (ccProxy [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
SRV - (ccPwdSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DefWatch [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (ISSVC [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (Symantec Corporation)
SRV - (KService [Auto | Running]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (O&O Defrag [Auto | Running]) – C:\WINDOWS\system32\oodag.exe (O&O Software GmbH)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PnkBstrA [Auto | Running]) – C:\WINDOWS\system32\PnkBstrA.exe ()
SRV - (PnkBstrB [Auto | Running]) – C:\WINDOWS\system32\PnkBstrB.exe ()
SRV - (RichVideo [Auto | Running]) – C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (SavRoam [On_Demand | Stopped]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (SNDSrvc [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (Symantec AntiVirus [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (SymSecurePort [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe (Symantec Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AmdK8 [System | Running]) – C:\WINDOWS\system32\DRIVERS\AmdK8.sys (Advanced Micro Devices)
DRV - (ASPI32 [Auto | Running]) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
DRV - (E100B [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (NAVENG [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090508.003\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090508.003\NAVEX15.SYS (Symantec Corporation)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvatabus [Boot | Running]) – C:\WINDOWS\System32\drivers\NvAtaBus.sys (NVIDIA Corporation)
DRV - (nvax [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)
DRV - (nvnforce [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (Pcouffin [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\Pcouffin.sys (VSO Software)
DRV - (PhilCam8116 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\CamDrL21.sys (Philips Semiconductors)
DRV - (PnkBstrK [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\PnkBstrK.sys ()
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ROOTMODEM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (SAVRT [System | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL [System | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SPBBCDrv [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (sptd [Boot | Running]) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (SYMDNS [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMFW [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMIDSCO [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\SymcData\scfidsdefs\20090428.001\SymIDSCo.sys (Symantec Corporation)
DRV - (SYMNDIS [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Running]) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (UnlockerDriver4 [On_Demand | Stopped]) – C:\WINDOWS\system32\UnlockerDriver4.sys ()
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (USBCM [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\Sacm2A.sys ( )

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;



O1 HOSTS File: (4169 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 bin.errorprotector.com ## added by CiD
O1 - Hosts: 127.0.0.1 br.errorsafe.com ## added by CiD
O1 - Hosts: 127.0.0.1 br.winantivirus.com ## added by CiD
O1 - Hosts: 127.0.0.1 br.winfixer.com ## added by CiD
O1 - Hosts: 127.0.0.1 de.errorsafe.com ## added by CiD
O1 - Hosts: 127.0.0.1 de.winantivirus.com ## added by CiD
O1 - Hosts: 127.0.0.1 download.cdn.winsoftware.com ## added by CiD
O1 - Hosts: 127.0.0.1 download.errorsafe.com ## added by CiD
O1 - Hosts: 127.0.0.1 download.systemdoctor.com ## added by CiD
O1 - Hosts: 127.0.0.1 download.winantispyware.com ## added by CiD
O1 - Hosts: 127.0.0.1 download.windrivecleaner.com ## added by CiD
O1 - Hosts: 127.0.0.1 download.winfixer.com ## added by CiD
O1 - Hosts: 127.0.0.1 drivecleaner.com ## added by CiD
O1 - Hosts: 127.0.0.1 dynamique.drivecleaner.com ## added by CiD
O1 - Hosts: 127.0.0.1 errorprotector.com ## added by CiD
O1 - Hosts: 127.0.0.1 errorsafe.com ## added by CiD
O1 - Hosts: 127.0.0.1 es.winantivirus.com ## added by CiD
O1 - Hosts: 127.0.0.1 fr.winantivirus.com ## added by CiD
O1 - Hosts: 127.0.0.1 fr.winfixer.com ## added by CiD
O1 - Hosts: 127.0.0.1 go.drivecleaner.com ## added by CiD
O1 - Hosts: 127.0.0.1 go.errorsafe.com ## added by CiD
O1 - Hosts: 127.0.0.1 go.winantispyware.com ## added by CiD
O1 - Hosts: 127.0.0.1 go.winantivirus.com ## added by CiD
O1 - Hosts: 127.0.0.1 hk.winantivirus.com ## added by CiD
O1 - Hosts: 49 more lines…
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (bho2gr Class) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-BAF6-49F8CCAB3ED4} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe (Logitech Inc.)
O4 - HKLM..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE (Logitech Inc.)
O4 - HKLM..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" (Patchou)
O4 - HKLM..\Run: [muBlinder] C:\Program Files\muBlinder\muBlinder.exe -startup (KRX)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [vssms32] C:\WINDOWS\system32\vssms32.exe File not found
O4 - HKLM..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe ()
O4 - HKCU..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun File not found
O4 - HKCU..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all (Kontiki Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [Spamone] C:\DOCUME~1\ANDREW~1\APPLIC~1\JUGSHE~1\online 4 program.exe File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Andrew and Claire\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Andrew and Claire\Start Menu\Programs\Startup\Xfire.lnk = D:\Program Files\Xfire\Xfire.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1220281776046 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1220281767609 (MUWebControl Class)
O16 - DPF: {6F714D46-E4EF-11D4-93EF-00D0D7032099} http://www.christianrock2.net/amp3dj.cab (Active DJ Studio ActiveX Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\pavuppad.exe) - C:\WINDOWS\system32\pavuppad.exe ()
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\sdra64.exe) - C:\WINDOWS\system32\sdra64.exe ()
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/03 10:58:28 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (OODBS) - C:\WINDOWS\System32\OODBS.exe (O&O Software GmbH)

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[2016/10/29 20:12:56 | 00,379,912 | —- | C] () – D:\Documents\S8002705.JPG
[2016/10/28 21:15:18 | 19,383,516 | —- | C] () – D:\Documents\S8002696.AVI
[2009/05/11 18:38:37 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Andrew and Claire\Desktop\OTListIt2.exe
[2009/05/11 18:36:01 | 00,267,612 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\Rooter.exe
[2009/05/11 18:35:35 | 00,000,000 | —D | C] – C:\Rooter$
[2009/05/11 07:36:42 | 00,000,000 | -HSD | C] – C:\WINDOWS\System32\lowsec
[2009/05/09 18:33:40 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/05/09 12:26:02 | 00,000,000 | —D | C] – C:\Documents and Settings\Andrew and Claire\Application Data\Malwarebytes
[2009/05/09 12:25:53 | 00,000,706 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/09 12:25:51 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/09 12:25:45 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/09 12:25:43 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/05/09 12:25:42 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/09 12:24:44 | 02,967,800 | —- | C] (Malwarebytes Corporation ) – D:\Documents\mbam-setup.exe
[2009/05/09 12:09:12 | 00,001,744 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\HijackThis.lnk
[2009/05/09 12:09:11 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/05/09 12:08:59 | 00,812,344 | —- | C] (Trend Micro Inc.) – D:\Documents\HJTInstall.exe
[2009/05/09 12:00:10 | 09,924,040 | —- | C] (Microsoft Corporation) – D:\Documents\windows-kb890830-v2.9.exe
[2009/05/09 11:53:41 | 00,025,088 | —- | C] () – D:\Documents\andrews new reviews 9th may.doc
[2009/05/09 08:56:42 | 00,026,112 | —- | C] () – D:\Documents\Mummy do you love me.doc
[2009/05/08 11:33:49 | 00,030,720 | —- | C] () – D:\Documents\Tommee tippee cup,library..doc
[2009/05/08 11:33:49 | 00,000,162 | -H– | C] () – D:\Documents\~$mmee tippee cup,library..doc
[2009/05/07 07:26:34 | 00,000,000 | -HSD | C] – C:\WINDOWS\System32\bookls
[2009/05/07 07:26:32 | 00,059,392 | —- | C] () – C:\WINDOWS\System32\inform.dat
[2009/05/07 07:26:32 | 00,013,733 | —- | C] () – C:\WINDOWS\System32\ormh
[2009/05/06 07:50:34 | 14,897,3650 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\JohnB_Live_at_VirginClub_Pforzheim_14Feb2009.mp3
[2009/05/04 13:05:25 | 51,272,088 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\videoFileNo130122.mpg
[2009/05/04 13:01:22 | 04,820,424 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\videoFileNo130122.flv
[2009/05/04 13:01:11 | 00,000,002 | -HS- | C] () – C:\Documents and Settings\Andrew and Claire\Application Data\evf
[2009/05/04 13:00:41 | 00,000,000 | —D | C] – C:\Program Files\ZillaTube
[2009/05/01 22:26:52 | 00,000,162 | -H– | C] () – D:\Documents\~$randad.doc
[2009/05/01 22:26:51 | 00,024,064 | —- | C] () – D:\Documents\grandad.doc
[2009/05/01 16:57:17 | 00,001,804 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\iTunes.lnk
[2009/05/01 16:56:48 | 00,000,000 | —D | C] – C:\Program Files\iPod
[2009/05/01 16:56:45 | 00,000,000 | —D | C] – C:\Program Files\iTunes
[2009/05/01 16:56:45 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/04/27 18:20:41 | 00,035,328 | —- | C] () – D:\Documents\reviews 27th april.doc
[2009/04/27 18:20:41 | 00,000,162 | -H– | C] () – D:\Documents\~$views 27th april.doc
[2009/04/26 07:24:29 | 00,000,162 | -H– | C] () – D:\Documents\~$aires reviews 25th april.doc
[2009/04/25 18:40:06 | 00,027,648 | —- | C] () – D:\Documents\claires reviews 25th april.doc
[2009/04/25 14:46:25 | 03,763,349 | —- | C] () – D:\Documents\S8003138.JPG
[2009/04/25 14:46:20 | 03,489,540 | —- | C] () – D:\Documents\S8003137.JPG
[2009/04/25 14:46:15 | 03,623,748 | —- | C] () – D:\Documents\S8003136.JPG
[2009/04/25 14:46:08 | 03,687,965 | —- | C] () – D:\Documents\S8003135.JPG
[2009/04/25 14:46:02 | 03,623,254 | —- | C] () – D:\Documents\S8003134.JPG
[2009/04/25 10:53:40 | 00,000,162 | -H– | C] () – D:\Documents\~$views 25th april.doc
[2009/04/25 10:53:39 | 00,041,984 | —- | C] () – D:\Documents\reviews 25th april.doc
[2009/04/24 10:46:24 | 00,029,696 | —- | C] () – D:\Documents\I normally buy the very cheap Smartprice wipes from Asda but unfortunately I ran out last week.doc
[2009/04/24 10:46:24 | 00,000,162 | -H– | C] () – D:\Documents\~$normally buy the very cheap Smartprice wipes from Asda but unfortunately I ran out last week.doc
[2009/04/22 09:08:21 | 00,000,162 | -H– | C] () – D:\Documents\~$da codes.doc
[2009/04/21 20:16:59 | 00,024,064 | —- | C] () – D:\Documents\asda codes.doc
[2009/04/20 19:27:25 | 00,024,064 | —- | C] () – D:\Documents\money 20th April.doc
[2009/04/20 19:27:25 | 00,000,162 | -H– | C] () – D:\Documents\~$ney 20th April.doc
[2009/04/17 17:05:43 | 18,063,038 | —- | C] () – D:\Documents\S8003127.AVI
[2009/04/17 15:36:59 | 18,611,758 | —- | C] () – D:\Documents\S8003122.AVI
[2009/04/16 18:44:37 | 00,058,368 | —- | C] () – D:\Documents\reviews 16th april.doc
[2009/04/16 18:44:37 | 00,000,162 | -H– | C] () – D:\Documents\~$views 16th april.doc
[2009/04/15 21:07:28 | 00,000,162 | -H– | C] () – D:\Documents\~$proved food order.doc
[2009/04/15 21:07:27 | 00,045,056 | —- | C] () – D:\Documents\approved food order.doc
[2009/04/15 12:41:59 | 00,024,064 | —- | C] () – D:\Documents\money april 15th.doc
[2009/04/15 12:41:59 | 00,000,162 | -H– | C] () – D:\Documents\~$ney april 15th.doc
[2009/04/14 12:17:27 | 00,042,496 | —- | C] () – D:\Documents\top ten autobiographies.doc
[2009/04/14 12:17:27 | 00,000,162 | -H– | C] () – D:\Documents\~$p ten autobiographies.doc
[2009/04/13 20:27:14 | 00,035,840 | —- | C] () – D:\Documents\reviews 13th april.doc
[2009/04/13 20:27:14 | 00,000,162 | -H– | C] () – D:\Documents\~$views 13th april.doc
[2009/04/13 20:27:06 | 00,032,768 | —- | C] () – D:\Documents\reviews 9th april.doc
[2008/11/21 22:47:52 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/11/21 22:45:16 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/11/21 22:45:16 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/11/21 22:44:16 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/08/31 08:58:15 | 00,000,000 | —- | C] () – C:\WINDOWS\PhotoNow.INI
[2008/07/20 16:01:41 | 00,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/07/20 16:01:39 | 00,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/07/20 16:01:39 | 00,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/05/29 15:58:19 | 00,000,056 | —- | C] () – C:\WINDOWS\VideoConvert.INI
[2008/03/31 17:38:04 | 00,717,296 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2008/03/31 16:27:14 | 00,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2008/03/30 18:22:06 | 00,000,067 | —- | C] () – C:\WINDOWS\Easy Avi Divx Xvid to DVD Burner.INI
[2007/08/25 20:19:56 | 00,140,216 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2006/11/26 19:29:55 | 00,000,018 | —- | C] () – C:\WINDOWS\gfact.ini
[2006/11/02 14:28:20 | 00,008,784 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2006/08/16 12:49:26 | 00,000,067 | —- | C] () – C:\WINDOWS\#1 DVD Ripper.INI
[2006/08/09 21:36:56 | 00,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2006/07/01 13:41:23 | 00,000,025 | —- | C] () – C:\WINDOWS\XCopyDVD.INI
[2006/02/07 18:51:31 | 00,006,850 | R— | C] () – C:\WINDOWS\Disktool.INI
[2006/02/07 18:51:31 | 00,003,677 | R— | C] () – C:\WINDOWS\PlaySnd.INI
[2006/02/07 18:51:29 | 00,005,628 | R— | C] () – C:\WINDOWS\fwupgrade.ini
[2005/11/07 13:52:16 | 00,000,241 | —- | C] () – C:\WINDOWS\QSync.INI
[2005/11/07 13:51:15 | 00,005,187 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2005/11/04 08:48:16 | 00,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/11/03 21:05:36 | 00,013,312 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2005/11/03 20:41:21 | 00,053,693 | R— | C] () – C:\WINDOWS\UNDPX2A.sys
[2005/11/03 20:41:21 | 00,015,429 | R— | C] ( ) – C:\WINDOWS\System32\drivers\Sacm2A.sys
[2005/11/03 11:17:58 | 00,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2005/11/03 11:13:10 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/03 11:05:42 | 00,761,856 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2005/11/03 11:05:42 | 00,421,888 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2005/11/03 11:05:42 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2005/11/03 11:05:39 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2005/11/03 10:54:21 | 00,394,240 | —- | C] () – C:\WINDOWS\System32\HMTCD.dll
[2005/11/03 10:54:21 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\ContextMenuExt.dll
[2005/11/03 10:54:21 | 00,009,728 | —- | C] () – C:\WINDOWS\System32\UnlockerCOM.dll
[2005/11/03 10:54:21 | 00,003,584 | —- | C] () – C:\WINDOWS\System32\UnlockerDriver4.sys
[2005/11/03 10:49:35 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005/11/03 10:49:35 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2005/11/03 10:49:35 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/11/03 10:49:34 | 01,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/11/03 10:35:21 | 00,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005/11/03 10:35:21 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2005/10/10 22:49:00 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2004/06/01 16:31:13 | 00,069,632 | —- | C] () – C:\WINDOWS\System32\akrip32.dll
[2003/11/13 15:28:02 | 00,012,570 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2003/11/13 15:28:02 | 00,012,570 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2003/01/07 16:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/12/31 13:00:00 | 00,000,603 | —- | C] () – C:\WINDOWS\win.ini
[2002/12/31 13:00:00 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini
[1999/01/27 14:39:06 | 00,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[97 D:\Documents\*.tmp files]
[2017/04/17 15:08:10 | 03,763,349 | —- | M] () – D:\Documents\S8003138.JPG
[2017/04/17 15:07:14 | 03,489,540 | —- | M] () – D:\Documents\S8003137.JPG
[2017/04/17 15:06:24 | 03,623,748 | —- | M] () – D:\Documents\S8003136.JPG
[2017/04/17 14:58:28 | 03,687,965 | —- | M] () – D:\Documents\S8003135.JPG
[2017/04/17 14:57:28 | 03,623,254 | —- | M] () – D:\Documents\S8003134.JPG
[2017/04/09 17:48:22 | 18,063,038 | —- | M] () – D:\Documents\S8003127.AVI
[2017/04/09 16:20:08 | 18,611,758 | —- | M] () – D:\Documents\S8003122.AVI
[2017/03/11 20:48:00 | 10,801,652 | —- | M] () – D:\Documents\S8003102.AVI
[2017/03/11 20:47:06 | 08,776,114 | —- | M] () – D:\Documents\S8003101.AVI
[2017/03/11 15:30:36 | 03,663,555 | —- | M] () – D:\Documents\S8003096.JPG
[2017/03/11 15:30:32 | 03,714,325 | —- | M] () – D:\Documents\S8003095.JPG
[2017/03/11 15:30:26 | 03,708,984 | —- | M] () – D:\Documents\S8003094.JPG
[2017/03/11 11:15:40 | 03,716,578 | —- | M] () – D:\Documents\S8003093.JPG
[2017/03/11 11:15:34 | 03,507,233 | —- | M] () – D:\Documents\S8003092.JPG
[2017/03/11 11:15:26 | 03,663,839 | —- | M] () – D:\Documents\S8003091.JPG
[2017/03/11 11:14:56 | 03,682,951 | —- | M] () – D:\Documents\S8003090.JPG
[2017/03/11 11:14:48 | 03,477,071 | —- | M] () – D:\Documents\S8003089.JPG
[2017/03/11 11:14:42 | 03,441,892 | —- | M] () – D:\Documents\S8003088.JPG
[2017/02/18 21:18:16 | 03,648,047 | —- | M] () – D:\Documents\S8003082.JPG
[2017/02/17 20:15:26 | 03,673,601 | —- | M] () – D:\Documents\S8003081.JPG
[2017/02/16 20:00:42 | 03,499,989 | —- | M] () – D:\Documents\S8003077.JPG
[2017/02/15 20:19:18 | 03,643,656 | —- | M] () – D:\Documents\S8003076.JPG
[2017/02/14 19:10:04 | 03,888,699 | —- | M] () – D:\Documents\S8003074.JPG
[2017/02/14 19:09:50 | 03,918,969 | —- | M] () – D:\Documents\S8003073.JPG
[2017/02/14 19:06:50 | 04,032,828 | —- | M] () – D:\Documents\S8003065.JPG
[2017/02/14 19:03:56 | 03,462,410 | —- | M] () – D:\Documents\S8003062.JPG
[2017/02/14 19:02:44 | 03,588,873 | —- | M] () – D:\Documents\S8003059.JPG
[2017/02/14 19:02:30 | 03,552,490 | —- | M] () – D:\Documents\S8003058.JPG
[2017/02/14 19:02:20 | 03,882,996 | —- | M] () – D:\Documents\S8003057.JPG
[2017/02/14 19:01:00 | 03,616,824 | —- | M] () – D:\Documents\S8003056.JPG
[2017/02/14 18:55:32 | 03,735,231 | —- | M] () – D:\Documents\S8003052.JPG
[2017/02/14 18:54:52 | 03,537,626 | —- | M] () – D:\Documents\S8003051.JPG
[2017/02/14 18:53:58 | 03,039,240 | —- | M] () – D:\Documents\S8003049.JPG
[2017/02/14 18:53:24 | 03,088,220 | —- | M] () – D:\Documents\S8003048.JPG
[2017/02/14 18:49:46 | 03,422,123 | —- | M] () – D:\Documents\S8003045.JPG
[2017/02/12 15:34:12 | 03,640,028 | —- | M] () – D:\Documents\S8003041.JPG
[2017/02/12 15:32:44 | 03,597,350 | —- | M] () – D:\Documents\S8003040.JPG
[2017/02/11 20:11:50 | 03,383,866 | —- | M] () – D:\Documents\S8003032.JPG
[2017/02/11 20:09:42 | 03,317,057 | —- | M] () – D:\Documents\S8003029.JPG
[2017/02/11 18:57:06 | 38,761,660 | —- | M] () – D:\Documents\S8003024.AVI
[2017/02/10 14:07:02 | 03,664,500 | —- | M] () – D:\Documents\S8003011.JPG
[2017/02/10 14:06:30 | 03,529,037 | —- | M] () – D:\Documents\S8003009.JPG
[2017/02/04 20:57:00 | 03,632,481 | —- | M] () – D:\Documents\S8003008.JPG
[2017/02/04 20:56:54 | 03,766,801 | —- | M] () – D:\Documents\S8003007.JPG
[2017/02/04 20:56:48 | 03,762,596 | —- | M] () – D:\Documents\S8003006.JPG
[2017/02/04 20:56:42 | 03,620,148 | —- | M] () – D:\Documents\S8003005.JPG
[2017/02/04 20:55:40 | 03,748,302 | —- | M] () – D:\Documents\S8003004.JPG
[2017/02/04 20:55:34 | 03,712,921 | —- | M] () – D:\Documents\S8003003.JPG
[2017/02/04 20:55:24 | 03,742,045 | —- | M] () – D:\Documents\S8003001.JPG
[2017/02/01 23:06:48 | 08,844,590 | —- | M] () – D:\Documents\S8002990.AVI
[2017/02/01 23:05:56 | 06,274,206 | —- | M] () – D:\Documents\S8002989.AVI
[2017/02/01 23:05:18 | 04,819,684 | —- | M] () – D:\Documents\S8002988.AVI
[2017/01/29 23:31:36 | 07,230,174 | —- | M] () – D:\Documents\S8002987.AVI
[2017/01/26 21:42:10 | 13,496,886 | —- | M] () – D:\Documents\S8002986.AVI
[2017/01/24 21:03:02 | 03,470,198 | —- | M] () – D:\Documents\S8002985.JPG
[2017/01/24 21:02:44 | 03,729,006 | —- | M] () – D:\Documents\S8002984.JPG
[2017/01/24 20:53:36 | 03,153,885 | —- | M] () – D:\Documents\S8002978.JPG
[2017/01/24 20:53:14 | 03,008,534 | —- | M] () – D:\Documents\S8002977.JPG
[2017/01/24 20:53:02 | 03,007,245 | —- | M] () – D:\Documents\S8002976.JPG
[2017/01/21 20:52:12 | 26,667,520 | —- | M] () – D:\Documents\S8002975.AVI
[2017/01/16 17:40:34 | 08,028,276 | —- | M] () – D:\Documents\S8002974.AVI
[2017/01/16 17:39:32 | 07,225,952 | —- | M] () – D:\Documents\S8002973.AVI
[2017/01/16 17:38:58 | 04,661,484 | —- | M] () – D:\Documents\S8002972.AVI
[2017/01/16 17:38:38 | 08,134,334 | —- | M] () – D:\Documents\S8002971.AVI
[2017/01/16 17:37:24 | 11,613,468 | —- | M] () – D:\Documents\S8002970.AVI
[2017/01/16 17:36:36 | 08,788,884 | —- | M] () – D:\Documents\S8002969.AVI
[2017/01/14 21:40:10 | 03,476,086 | —- | M] () – D:\Documents\S8002968.JPG
[2017/01/05 21:09:30 | 09,276,668 | —- | M] () – D:\Documents\S8002967.AVI
[2017/01/05 21:08:48 | 01,807,018 | —- | M] () – D:\Documents\S8002966.AVI
[2017/01/04 16:04:32 | 03,926,859 | —- | M] () – D:\Documents\S8002965.JPG
[2017/01/04 16:04:18 | 04,038,331 | —- | M] () – D:\Documents\S8002964.JPG
[2017/01/04 16:04:04 | 02,478,024 | —- | M] () – D:\Documents\S8002963.JPG
[2017/01/04 16:03:56 | 03,966,993 | —- | M] () – D:\Documents\S8002962.JPG
[2016/12/30 16:08:32 | 02,580,421 | —- | M] () – D:\Documents\S8002961.JPG
[2016/12/30 16:07:40 | 03,453,957 | —- | M] () – D:\Documents\S8002959.JPG
[2016/12/30 16:04:20 | 03,662,601 | —- | M] () – D:\Documents\S8002958.JPG
[2016/12/23 19:14:18 | 02,941,982 | —- | M] () – D:\Documents\S8002948.AVI
[2016/12/18 17:45:20 | 00,119,898 | —- | M] () – D:\Documents\S8002912.WAV
[2016/12/17 13:48:02 | 05,443,604 | —- | M] () – D:\Documents\S8002889.AVI
[2016/12/17 10:58:56 | 09,478,544 | —- | M] () – D:\Documents\S8002884.AVI
[2016/12/16 19:32:44 | 01,092,660 | —- | M] () – D:\Documents\S8002865.AVI
[2016/12/11 19:51:28 | 43,629,660 | —- | M] () – D:\Documents\S8002864.AVI
[2016/12/11 19:46:28 | 08,036,124 | —- | M] () – D:\Documents\S8002863.AVI
[2016/12/10 19:52:34 | 39,698,312 | —- | M] () – D:\Documents\S8002858.AVI
[2016/11/28 21:12:44 | 14,290,272 | —- | M] () – D:\Documents\S8002844.AVI
[2016/10/28 21:16:44 | 19,383,516 | —- | M] () – D:\Documents\S8002696.AVI
[2016/10/23 20:46:56 | 27,106,884 | —- | M] () – D:\Documents\S8002685.AVI
[2016/10/11 10:31:56 | 03,517,939 | —- | M] () – D:\Documents\S8002572.JPG
[2016/10/05 16:38:46 | 03,414,466 | —- | M] () – D:\Documents\S8002485.JPG
[2016/10/05 13:11:08 | 03,685,773 | —- | M] () – D:\Documents\S8002470.JPG
[2016/09/25 19:55:46 | 15,029,548 | —- | M] () – D:\Documents\S8002333.AVI
[2016/09/25 19:54:32 | 08,406,098 | —- | M] () – D:\Documents\S8002332.AVI
[2016/09/25 19:53:44 | 06,681,860 | —- | M] () – D:\Documents\S8002331.AVI
[2016/09/25 19:53:10 | 21,426,506 | —- | M] () – D:\Documents\S8002330.AVI
[2016/09/25 19:46:04 | 05,985,844 | —- | M] () – D:\Documents\S8002329.AVI
[2016/09/25 19:36:44 | 16,101,660 | —- | M] () – D:\Documents\S8002328.AVI
[2016/09/25 19:17:26 | 04,384,882 | —- | M] () – D:\Documents\S8002325.AVI
[2009/05/11 18:38:42 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Andrew and Claire\Desktop\OTListIt2.exe
[2009/05/11 18:36:04 | 00,267,612 | —- | M] () – C:\Documents and Settings\Andrew and Claire\Desktop\Rooter.exe
[2009/05/11 18:00:00 | 00,000,296 | -H– | M] () – C:\WINDOWS\tasks\8FB4905588AB3B65.job
[2009/05/11 17:43:59 | 00,000,278 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2009/05/11 17:18:57 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/05/11 17:16:49 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/05/11 17:16:25 | 00,039,568 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/05/11 17:14:32 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/11 17:14:28 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Andrew and Claire\Local Settings\desktop.ini
[2009/05/11 17:14:24 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/11 17:14:18 | 00,566,286 | —- | M] () – C:\WINDOWS\System32\OODBS.lor
[2009/05/10 21:10:36 | 00,000,366 | —- | M] () – C:\WINDOWS\tasks\Symantec NetDetect.job
[2009/05/10 20:12:17 | 00,000,151 | —- | M] () – C:\WINDOWS\PhotoSnapViewer.INI
[2009/05/09 18:25:42 | 00,000,839 | —- | M] () – D:\Documents\My Sharing Folders.lnk
[2009/05/09 16:52:33 | 00,000,040 | —- | M] () – C:\WINDOWS\System32\profile.dat
[2009/05/09 12:25:53 | 00,000,706 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/09 12:24:44 | 02,967,800 | —- | M] (Malwarebytes Corporation ) – D:\Documents\mbam-setup.exe
[2009/05/09 12:09:12 | 00,001,744 | —- | M] () – C:\Documents and Settings\Andrew and Claire\Desktop\HijackThis.lnk
[2009/05/09 12:09:02 | 00,812,344 | —- | M] (Trend Micro Inc.) – D:\Documents\HJTInstall.exe
[2009/05/09 12:00:10 | 09,924,040 | —- | M] (Microsoft Corporation) – D:\Documents\windows-kb890830-v2.9.exe
[2009/05/09 11:53:41 | 00,025,088 | —- | M] () – D:\Documents\andrews new reviews 9th may.doc
[2009/05/09 08:56:43 | 00,026,112 | —- | M] () – D:\Documents\Mummy do you love me.doc
[2009/05/08 12:05:12 | 00,030,720 | —- | M] () – D:\Documents\Tommee tippee cup,library..doc
[2009/05/08 11:33:49 | 00,000,162 | -H– | M] () – D:\Documents\~$mmee tippee cup,library..doc
[2009/05/07 07:26:32 | 00,059,392 | —- | M] () – C:\WINDOWS\System32\inform.dat
[2009/05/07 07:26:32 | 00,013,733 | —- | M] () – C:\WINDOWS\System32\ormh
[2009/05/05 07:58:28 | 00,002,228 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/05/05 07:40:14 | 23,672,585 | —- | M] () – D:\Documents\falling epik killah mix.mp3
[2009/05/04 13:04:45 | 51,272,088 | —- | M] () – C:\Documents and Settings\Andrew and Claire\Desktop\videoFileNo130122.mpg
[2009/05/04 13:03:37 | 04,820,424 | —- | M] () – C:\Documents and Settings\Andrew and Claire\Desktop\videoFileNo130122.flv
[2009/05/04 13:01:11 | 00,000,002 | -HS- | M] () – C:\Documents and Settings\Andrew and Claire\Application Data\evf
[2009/05/01 22:26:52 | 00,000,162 | -H– | M] () – D:\Documents\~$randad.doc
[2009/05/01 22:26:51 | 00,024,064 | —- | M] () – D:\Documents\grandad.doc
[2009/05/01 16:57:17 | 00,001,804 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\iTunes.lnk
[2009/04/30 12:21:18 | 00,027,648 | —- | M] () – D:\Documents\claires reviews 25th april.doc
[2009/04/27 18:20:41 | 00,035,328 | —- | M] () – D:\Documents\reviews 27th april.doc
[2009/04/27 18:20:41 | 00,000,162 | -H– | M] () – D:\Documents\~$views 27th april.doc
[2009/04/26 10:54:20 | 00,041,984 | —- | M] () – D:\Documents\reviews 25th april.doc
[2009/04/26 07:24:29 | 00,000,162 | -H– | M] () – D:\Documents\~$aires reviews 25th april.doc
[2009/04/25 10:53:40 | 00,000,162 | -H– | M] () – D:\Documents\~$views 25th april.doc
[2009/04/24 10:46:24 | 00,029,696 | —- | M] () – D:\Documents\I normally buy the very cheap Smartprice wipes from Asda but unfortunately I ran out last week.doc
[2009/04/24 10:46:24 | 00,000,162 | -H– | M] () – D:\Documents\~$normally buy the very cheap Smartprice wipes from Asda but unfortunately I ran out last week.doc
[2009/04/22 09:08:21 | 00,000,162 | -H– | M] () – D:\Documents\~$da codes.doc
[2009/04/21 20:17:00 | 00,024,064 | —- | M] () – D:\Documents\asda codes.doc
[2009/04/20 19:32:16 | 00,058,368 | —- | M] () – D:\Documents\reviews 16th april.doc
[2009/04/20 19:27:25 | 00,024,064 | —- | M] () – D:\Documents\money 20th April.doc
[2009/04/20 19:27:25 | 00,000,162 | -H– | M] () – D:\Documents\~$ney 20th April.doc
[2009/04/16 18:44:37 | 00,000,162 | -H– | M] () – D:\Documents\~$views 16th april.doc
[2009/04/15 21:07:28 | 00,000,162 | -H– | M] () – D:\Documents\~$proved food order.doc
[2009/04/15 21:07:27 | 00,045,056 | —- | M] () – D:\Documents\approved food order.doc
[2009/04/15 12:42:24 | 00,024,064 | —- | M] () – D:\Documents\money april 15th.doc
[2009/04/15 12:41:59 | 00,000,162 | -H– | M] () – D:\Documents\~$ney april 15th.doc
[2009/04/14 12:47:47 | 00,042,496 | —- | M] () – D:\Documents\top ten autobiographies.doc
[2009/04/14 12:43:39 | 00,035,840 | —- | M] () – D:\Documents\reviews 13th april.doc
[2009/04/14 12:17:27 | 00,000,162 | -H– | M] () – D:\Documents\~$p ten autobiographies.doc
[2009/04/13 20:27:14 | 00,000,162 | -H– | M] () – D:\Documents\~$views 13th april.doc
[2009/04/13 20:27:06 | 00,032,768 | —- | M] () – D:\Documents\reviews 9th april.doc

========== LOP Check ==========

[2009/05/09 12:25:43 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/05/01 16:57:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/04/05 09:57:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/10/17 21:06:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe Systems
[2006/07/15 10:30:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ahead
[2006/09/12 16:12:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
[2007/08/17 12:09:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/02/22 20:13:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/04/13 08:46:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Channel4
[2005/11/03 11:28:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/11/12 22:06:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Documents
[2006/10/14 23:09:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/05/11 17:15:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2009/01/13 21:35:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\hps
[2006/10/20 19:21:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2009/05/11 18:40:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2009/05/09 12:25:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2005/11/07 11:32:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2007/05/11 03:02:06 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2005/11/03 11:16:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2006/07/19 18:40:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Propellerhead Software
[2005/11/03 11:05:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Real
[2007/03/14 19:01:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2005/11/04 09:11:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2005/11/04 11:42:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008/03/02 19:31:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2005/11/03 11:35:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/09/14 09:00:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
[2009/05/09 12:26:02 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Andrew and Claire\Application Data
[2006/03/24 20:27:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\.ABC
[2006/01/18 11:31:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\.bittorrent
[2008/04/05 10:00:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Adobe
[2006/06/14 15:53:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Ahead
[2008/06/26 16:21:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Apple Computer
[2006/01/18 11:30:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Azureus
[2007/03/14 19:10:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\CyberLink
[2006/08/09 12:29:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\DeepBurner Pro
[2008/04/11 13:29:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Diskeeper Corporation
[2009/01/29 14:16:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\DivX
[2006/08/16 12:40:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\dvdcss
[2006/08/05 16:36:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Elaborate Bytes
[2006/10/15 09:09:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Google
[2007/02/20 13:07:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Help
[2005/11/03 11:24:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Identities
[2009/03/27 16:50:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\InstallShield
[2005/11/04 11:43:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\IsolatedStorage
[2006/03/25 20:54:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Lavasoft
[2005/11/07 13:26:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Macromedia
[2009/05/09 12:26:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Malwarebytes
[2005/11/04 08:50:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Media Player Classic
[2009/01/25 15:13:13 | 00,000,000 | –SD | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Microsoft
[2005/11/03 17:05:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\MSNInstaller
[2006/10/03 16:30:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\My Battle for Middle-earth Files
[2007/02/23 23:35:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\MySpace
[2006/10/20 18:07:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Opera
[2008/08/16 18:26:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\PRODEGETOOLBAR728
[2005/11/08 12:40:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Real
[2005/11/25 08:44:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Sun
[2009/05/11 18:40:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\uTorrent
[2006/07/09 13:37:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\vlc
[2008/03/31 16:25:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Vso
[2006/07/01 12:05:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\VSO_HWE
[2008/03/03 18:21:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew and Claire\Application Data\Xfire
[2009/05/11 18:00:00 | 00,000,296 | -H– | M] () – C:\WINDOWS\Tasks\8FB4905588AB3B65.job
[2009/05/11 17:43:59 | 00,000,278 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
[2002/12/31 13:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/05/11 17:16:49 | 00,000,868 | —- | M] () – C:\WINDOWS\Tasks\Google Software Updater.job
[2009/05/11 17:14:32 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/05/10 21:10:36 | 00,000,366 | —- | M] () – C:\WINDOWS\Tasks\Symantec NetDetect.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 32945 bytes -> C:\WINDOWS:system
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E62B5918
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC6124CA
< End of report >


Finally, 'Extras', which I guess is what you mean?

OTListIt Extras logfile created on: 11/05/2009 18:40:14 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.6 Folder = C:\Documents and Settings\Andrew and Claire\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 422.29 Mb Available Physical Memory | 41.26% Memory free
1.65 Gb Paging File | 1.19 Gb Available in Paging File | 71.75% Paging File free
Paging file location(s): D:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9.87 Gb Total Space | 2.24 Gb Free Space | 22.74% Space Free | Partition Type: NTFS
Drive D: | 139.18 Gb Total Space | 9.92 Gb Free Space | 7.13% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STEPHEN
Current User Name: Andrew and Claire
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirewallDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"80:TCP" = 80:TCP:*:Enabled:SYS32DLL
"7171:TCP" = 7171:TCP:*:Enabled:SYS32DLL

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 File not found
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent File not found
D:\Games\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2 ()
D:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire File not found
C:\Program Files\GetRight\getright.exe:*:Enabled:GetRight® Download Manager. www.GetRight.com (Headlight Software, Inc.)
D:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus File not found
D:\Program Files\ABC\abc.exe:*:Enabled:abc File not found
D:\Downloads\utorrent.exe:*:Enabled:µTorrent File not found
D:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes File not found
C:\WINDOWS\system32\vssms32.exe:*:Enabled:Dnode File not found
D:\Program Files\EA GAMES\The Battle for Middle-earth ™\game.dat:*:Enabled:The Battle for Middle-earth ™ File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer (Microsoft Corporation)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 File not found
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) File not found
C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent (BitTorrent, Inc.)
C:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service (Kontiki Inc.)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2™
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08D0B71E-472F-443D-80C3-BED3EA7BCE1C}" = Literacy Skills Test
"{10CE1EA2-12E9-11D3-825E-00C04F6843FE}" = Microsoft Office Sounds
"{117CD9C0-0F15-4633-93D7-F957B50535A5}" = Popup Blocker (Windows Live Toolbar)
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1D171963-9063-4423-898B-8EC4F1F190B7}" = EA downloader
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3727B920-F5A3-46A4-AC02-94F421A039C7}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{38024121-D084-4E7D-B1A2-1A04CB5C4CF3}" = Windows Live Toolbar Feed Detector (Windows Live Toolbar)
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{53480370-6CA2-47EC-BC05-02B4B9271C31}" = O&O Defrag Professional Edition
"{5A24DD7E-7B01-41AC-ADA8-F1776177A3BA}" = Logitech ImageStudio
"{5BBFB0E4-2250-49C3-A8A3-65BE2197D13B}" = MP3 Player Utilities V1.28
"{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8E240C1C-25D0-4248-BC6C-ACC3472E35CE}" = SigmaTel MSCN Audio Player
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{95FC661A-A0C5-4B18-92CE-90347DA79CC9}" = Smart Menus (Windows Live Toolbar)
"{993A18C1-0C61-47B6-9B42-075E699F4E11}" = Video Vault
"{A40D6757-B145-4FE7-B694-89180A9F3F64}" = Windows Live Outlook Toolbar (Windows Live Toolbar)
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0.3
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB406CEB-6207-4512-9BB2-89950DC9D6B6}_is1" = ConvertXtoDVD 2.2.3.258
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 SP1 with KB886903 Hotfix
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow! 1.0
"{D7A6C517-11F2-419F-B5BB-27772B939698}" = NvMixer
"{DA0FFF7B-DA9D-46A2-A329-87804ECA58EA}" = Windows Live Toolbar
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{DCE65B11-710D-4C54-9DE5-1A6A0BD2186B}" = Windows Live Favorites for Windows Live Toolbar
"{DF821FC5-C198-452B-A0D4-82433EFEAE9B}" = OneCare Advisor (Windows Live Toolbar)
"{E25BC708-9133-49C5-BC6C-C82F4652EE73}" = Digimax S800
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{E9FA3047-0B15-4E19-85CE-EE7FC6E60F99}" = Symantec Client Security
"{ECDA9BD9-A54E-462A-8191-A2B569D9AB34}" = Map Button (Windows Live Toolbar)
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"AoA Audio Extractor_is1" = AoA Audio Extractor 1.0
"AtomixMP3 v2.3 Trial" = AtomixMP3 v2.3 Trial
"Azureus" = Azureus
"BitTorrent" = BitTorrent 4.1.7-Beta
"CD Audio Reader Filter" = CD Audio Reader Filter (remove only)
"GetRight Pro" = GetRight Pro
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"KLiteCodecPack_is1" = K-Lite Codec Pack 2.53 Full
"LiveUpdate" = LiveUpdate 2.6 (Symantec Corporation)
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Magic ISO Maker v5.4 (build 0239)" = Magic ISO Maker v5.4 (build 0239)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"MixVibes.exe" = MixVibes STANDARD 6 uninstall
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MsgPlus! Plugin" = Messenger Plus! 3 & Sponsor
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NeroShowTime!UninstallKey" = Nero ShowTime CE
"NeroVision!UninstallKey" = Nero Digital
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PowerDVD" = PowerDVD
"PROSet" = Intel® PRO Network Connections Drivers
"RealAlt_is1" = Real Alternative 1.43
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"TuneXP_1.5" = TuneXP 1.5
"VLC media player" = VideoLAN VLC media player 0.8.5
"WebSTAR DPC2100 Uninstall" = Scientific-Atlanta WebSTAR 2000 series Cable Modem
"WIC" = Windows Imaging Component
"Winamp" = Winamp (remove only)
"Windows Live Toolbar" = Windows Live Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XviD_is1" = XviD 1.1 final uninstall
"ZoomPlayer" = Zoom Player (remove only)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"memo byte keep" = Zone Media
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 09/05/2009 06:59:10 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Trojan Horse in File: C:\Documents and Settings\Andrew
and Claire\Local Settings\Temporary Internet Files\Content.IE5\NN2RWTAA\6244[1].exe
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 09/05/2009 06:59:43 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Trojan Horse in File: C:\DOCUME~1\ANDREW~1\LOCALS~1\TEMPOR~1\Content.IE5\NN2RWTAA\6244_1~1.EXE
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 09/05/2009 07:00:02 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: Trojan Horse in File: C:\WINDOWS\ST_124~1.EXE
by: Auto-Protect scan. Action: Quarantine succeeded. Action Description: The
file was quarantined successfully.

Error - 09/05/2009 07:00:02 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Trojan Horse in File: C:\WINDOWS\st_1241866774.exe
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 09/05/2009 07:00:05 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Trojan Horse in File: C:\WINDOWS\ST_124~1.EXE
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 09/05/2009 07:40:21 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: W32.Koobface.B in File: C:\System Volume Information\_restore{B0FF0B71-E938-4937-9F7B-698A23B9E8F7}\RP1087\A1127380.exe
by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Access denied.
Action Description: The file was left unchanged.

Error - 09/05/2009 07:43:22 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: Bloodhound.Exploit.213 in File: D:\Temp\TMP\Acr116.tmp
by: Auto-Protect scan. Action: Quarantine succeeded. Action Description: The
file was quarantined successfully.

Error - 09/05/2009 07:43:23 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Bloodhound.Exploit.213 in File: D:\Temp\TMP\Acr116.tmp
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 09/05/2009 07:43:23 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Bloodhound.Exploit.213 in File: D:\Temp\TMP\Acr116.tmp
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 09/05/2009 13:11:12 | Computer Name = STEPHEN | Source = MsiInstaller | ID = 11905
Description = Product: 4oD – Error 1905.Module C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx
failed to unregister. HRESULT -2147220472. Contact your support personnel.

[ Application Events ]
Error - 09/05/2009 06:59:10 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Trojan Horse in File: C:\Documents and Settings\Andrew
and Claire\Local Settings\Temporary Internet Files\Content.IE5\NN2RWTAA\6244[1].exe
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 09/05/2009 06:59:43 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Trojan Horse in File: C:\DOCUME~1\ANDREW~1\LOCALS~1\TEMPOR~1\Content.IE5\NN2RWTAA\6244_1~1.EXE
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 09/05/2009 07:00:02 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: Trojan Horse in File: C:\WINDOWS\ST_124~1.EXE
by: Auto-Protect scan. Action: Quarantine succeeded. Action Description: The
file was quarantined successfully.

Error - 09/05/2009 07:00:02 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Trojan Horse in File: C:\WINDOWS\st_1241866774.exe
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 09/05/2009 07:00:05 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Trojan Horse in File: C:\WINDOWS\ST_124~1.EXE
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 09/05/2009 07:40:21 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: W32.Koobface.B in File: C:\System Volume Information\_restore{B0FF0B71-E938-4937-9F7B-698A23B9E8F7}\RP1087\A1127380.exe
by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Access denied.
Action Description: The file was left unchanged.

Error - 09/05/2009 07:43:22 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: Bloodhound.Exploit.213 in File: D:\Temp\TMP\Acr116.tmp
by: Auto-Protect scan. Action: Quarantine succeeded. Action Description: The
file was quarantined successfully.

Error - 09/05/2009 07:43:23 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Bloodhound.Exploit.213 in File: D:\Temp\TMP\Acr116.tmp
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 09/05/2009 07:43:23 | Computer Name = STEPHEN | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Bloodhound.Exploit.213 in File: D:\Temp\TMP\Acr116.tmp
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 09/05/2009 13:11:12 | Computer Name = STEPHEN | Source = MsiInstaller | ID = 11905
Description = Product: 4oD – Error 1905.Module C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx
failed to unregister. HRESULT -2147220472. Contact your support personnel.

[ System Events ]
Error - 26/04/2009 17:52:26 | Computer Name = STEPHEN | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.

Error - 26/04/2009 17:52:27 | Computer Name = STEPHEN | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.

Error - 26/04/2009 17:52:28 | Computer Name = STEPHEN | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.

Error - 26/04/2009 17:52:29 | Computer Name = STEPHEN | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.

Error - 26/04/2009 17:52:30 | Computer Name = STEPHEN | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.

Error - 26/04/2009 17:52:31 | Computer Name = STEPHEN | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.

Error - 26/04/2009 17:52:32 | Computer Name = STEPHEN | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.

Error - 26/04/2009 17:52:33 | Computer Name = STEPHEN | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.

Error - 28/04/2009 15:36:40 | Computer Name = STEPHEN | Source = Print | ID = 19
Description = Sharing printer failed + 1722, Printer Microsoft XPS Document Writer
share name Printer2.

Error - 01/05/2009 07:37:08 | Computer Name = STEPHEN | Source = Print | ID = 19
Description = Sharing printer failed + 1722, Printer Microsoft XPS Document Writer
share name Printer2.


< End of report >


Thanks!
First a warning

One or more of the identified infections is a backdoor Trojan and a key logger.

If this computer is ever used for on-line banking, I suggest you do the following immediately:

1. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.

2. From a clean computer, change ALL your on-line passwords for email, for banks, financial accounts, PayPal, eBay, on-line companies, any on-line forums or groups you belong to.

Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

OK, first off, the net is now working (from unchecking 'use a proxy server') so thanks so much for that.

So it stopped before you did that ? Self help can cause problems if you are not aware of what you are doing

As I am in GMT I was having my beauty sleep when you posted ;)

OK lets start clearing this rubbish off

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-BAF6-49F8CCAB3ED4} - Reg Error: Key error. File not found
    O4 - HKLM..\Run: [vssms32] C:\WINDOWS\system32\vssms32.exe File not found
    O4 - HKCU..\Run: [Spamone] C:\DOCUME~1\ANDREW~1\APPLIC~1\JUGSHE~1\online 4 program.exe File not found
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\pavuppad.exe) - C:\WINDOWS\system32\pavuppad.exe ()
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\sdra64.exe) - C:\WINDOWS\system32\sdra64.exe ()
    [2006/11/26 19:29:55 | 00,000,018 | —- | C] () – C:\WINDOWS\gfact.ini
    [2006/11/02 14:28:20 | 00,008,784 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
    [2009/05/11 18:00:00 | 00,000,296 | -H– | M] () – C:\WINDOWS\Tasks\8FB4905588AB3B65.job
    
    :Files
    c:\docume~1\andrew~1\applic~1\jugshe~1
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )

THEN

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Thanks so much for all this help.

OK, I ran the OTlist scan but didn't get to save the results before the combofix restarted, so ran one again after (not sure if it will now be relevant).

OTLIST SCAN:
OTListIt logfile created on: 11/05/2009 22:31:20 - Run 3
OTListIt2 by OldTimer - Version 2.0.15.6 Folder = C:\Documents and Settings\Andrew and Claire\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 446.13 Mb Available Physical Memory | 43.59% Memory free
1.65 Gb Paging File | 1.22 Gb Available in Paging File | 73.63% Paging File free
Paging file location(s): D:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9.87 Gb Total Space | 2.28 Gb Free Space | 23.10% Space Free | Partition Type: NTFS
Drive D: | 139.18 Gb Total Space | 29.41 Gb Free Space | 21.13% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STEPHEN
Current User Name: Andrew and Claire
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe (NVIDIA Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\MessengerPlus! 3\MsgPlus.exe (Patchou)
PRC - C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE (Logitech Inc.)
PRC - C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - D:\Program Files\Winamp\winampa.exe ()
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
PRC - C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\oodag.exe (O&O Software GmbH)
PRC - C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\NMain.exe (Symantec Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - D:\Program Files\Winamp\winamp.exe (Nullsoft)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Andrew and Claire\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (ccEvtMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (ccProxy [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
SRV - (ccPwdSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DefWatch [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (ISSVC [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (Symantec Corporation)
SRV - (KService [Auto | Running]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (O&O Defrag [Auto | Running]) – C:\WINDOWS\system32\oodag.exe (O&O Software GmbH)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PnkBstrA [Auto | Stopped]) – C:\WINDOWS\system32\PnkBstrA.exe ()
SRV - (PnkBstrB [Auto | Stopped]) – C:\WINDOWS\system32\PnkBstrB.exe ()
SRV - (RichVideo [Auto | Running]) – C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (SavRoam [On_Demand | Stopped]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (SNDSrvc [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (Symantec AntiVirus [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (SymSecurePort [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe (Symantec Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AmdK8 [System | Running]) – C:\WINDOWS\system32\DRIVERS\AmdK8.sys (Advanced Micro Devices)
DRV - (ASPI32 [Auto | Running]) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
DRV - (catchme [Disabled | Running]) – File not found
DRV - (E100B [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilDrv10910 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys (Symantec Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (NAVENG [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090508.003\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090508.003\NAVEX15.SYS (Symantec Corporation)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvatabus [Boot | Running]) – C:\WINDOWS\System32\drivers\NvAtaBus.sys (NVIDIA Corporation)
DRV - (nvax [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)
DRV - (nvnforce [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (Pcouffin [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\Pcouffin.sys (VSO Software)
DRV - (PhilCam8116 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\CamDrL21.sys (Philips Semiconductors)
DRV - (PnkBstrK [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\PnkBstrK.sys ()
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ROOTMODEM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (SAVRT [System | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL [System | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SPBBCDrv [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (sptd [Boot | Running]) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (SYMDNS [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMFW [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMIDSCO [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\SymcData\scfidsdefs\20090428.001\SymIDSCo.sys (Symantec Corporation)
DRV - (SYMNDIS [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Running]) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (UnlockerDriver4 [On_Demand | Stopped]) – C:\WINDOWS\system32\UnlockerDriver4.sys ()
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (USBCM [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\Sacm2A.sys ( )

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;



O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (bho2gr Class) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe (Logitech Inc.)
O4 - HKLM..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE (Logitech Inc.)
O4 - HKLM..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" (Patchou)
O4 - HKLM..\Run: [muBlinder] C:\Program Files\muBlinder\muBlinder.exe -startup (KRX)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe ()
O4 - HKCU..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all (Kontiki Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Andrew and Claire\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Andrew and Claire\Start Menu\Programs\Startup\Xfire.lnk = D:\Program Files\Xfire\Xfire.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1220281776046 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1220281767609 (MUWebControl Class)
O16 - DPF: {6F714D46-E4EF-11D4-93EF-00D0D7032099} http://www.christianrock2.net/amp3dj.cab (Active DJ Studio ActiveX Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\pavuppad.exe) - C:\WINDOWS\system32\pavuppad.exe ()
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/03 10:58:28 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (OODBS) - C:\WINDOWS\System32\OODBS.exe (O&O Software GmbH)

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2016/10/29 20:12:56 | 00,379,912 | —- | C] () – D:\Documents\S8002705.JPG
[2016/10/28 21:15:18 | 19,383,516 | —- | C] () – D:\Documents\S8002696.AVI
[2009/05/11 22:29:55 | 00,000,000 | —D | C] – C:\Documents and Settings\Andrew and Claire\Local Settings\temp
[2009/05/11 22:22:01 | 00,000,000 | —D | C] – C:\WINDOWS\temp
[2009/05/11 22:20:17 | 00,000,211 | —- | C] () – C:\Boot.bak
[2009/05/11 22:20:16 | 00,260,272 | —- | C] () – C:\cmldr
[2009/05/11 22:20:14 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/05/11 22:19:01 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/05/11 22:19:01 | 00,117,248 | —- | C] () – C:\WINDOWS\vFind.exe
[2009/05/11 22:19:01 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/05/11 22:19:01 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/05/11 22:19:01 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/05/11 22:19:01 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/05/11 22:19:00 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/05/11 22:19:00 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/05/11 22:18:51 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/05/11 22:18:45 | 00,000,000 | —D | C] – C:\Qoobox
[2009/05/11 22:15:58 | 03,020,851 | R— | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\ComboFix.exe
[2009/05/11 22:10:50 | 00,000,000 | —D | C] – C:\Kontiki
[2009/05/11 22:06:55 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/05/11 22:04:19 | 00,034,816 | —- | C] () – D:\Documents\andrew reviews.doc
[2009/05/11 18:38:37 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Andrew and Claire\Desktop\OTListIt2.exe
[2009/05/11 18:36:01 | 00,267,612 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\Rooter.exe
[2009/05/11 18:35:35 | 00,000,000 | —D | C] – C:\Rooter$
[2009/05/09 18:33:40 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/05/09 12:26:02 | 00,000,000 | —D | C] – C:\Documents and Settings\Andrew and Claire\Application Data\Malwarebytes
[2009/05/09 12:25:53 | 00,000,706 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/09 12:25:51 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/09 12:25:45 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/09 12:25:43 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/05/09 12:25:42 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/09 12:24:44 | 02,967,800 | —- | C] (Malwarebytes Corporation ) – D:\Documents\mbam-setup.exe
[2009/05/09 12:09:12 | 00,001,744 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\HijackThis.lnk
[2009/05/09 12:09:11 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/05/09 12:08:59 | 00,812,344 | —- | C] (Trend Micro Inc.) – D:\Documents\HJTInstall.exe
[2009/05/09 12:00:10 | 09,924,040 | —- | C] (Microsoft Corporation) – D:\Documents\windows-kb890830-v2.9.exe
[2009/05/09 11:53:41 | 00,025,088 | —- | C] () – D:\Documents\andrews new reviews 9th may.doc
[2009/05/09 08:56:42 | 00,026,112 | —- | C] () – D:\Documents\Mummy do you love me.doc
[2009/05/08 11:33:49 | 00,030,720 | —- | C] () – D:\Documents\Tommee tippee cup,library..doc
[2009/05/08 11:33:49 | 00,000,162 | -H– | C] () – D:\Documents\~$mmee tippee cup,library..doc
[2009/05/07 07:26:34 | 00,000,000 | -HSD | C] – C:\WINDOWS\System32\bookls
[2009/05/07 07:26:32 | 00,013,733 | —- | C] () – C:\WINDOWS\System32\ormh
[2009/05/06 07:50:34 | 14,897,3650 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\JohnB_Live_at_VirginClub_Pforzheim_14Feb2009.mp3
[2009/05/04 13:05:25 | 51,272,088 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\videoFileNo130122.mpg
[2009/05/04 13:01:22 | 04,820,424 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\videoFileNo130122.flv
[2009/05/04 13:01:11 | 00,000,002 | -HS- | C] () – C:\Documents and Settings\Andrew and Claire\Application Data\evf
[2009/05/04 13:00:41 | 00,000,000 | —D | C] – C:\Program Files\ZillaTube
[2009/05/01 22:26:52 | 00,000,162 | -H– | C] () – D:\Documents\~$randad.doc
[2009/05/01 22:26:51 | 00,024,064 | —- | C] () – D:\Documents\grandad.doc
[2009/05/01 16:57:17 | 00,001,804 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/05/01 16:56:48 | 00,000,000 | —D | C] – C:\Program Files\iPod
[2009/05/01 16:56:45 | 00,000,000 | —D | C] – C:\Program Files\iTunes
[2009/05/01 16:56:45 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/04/27 18:20:41 | 00,035,328 | —- | C] () – D:\Documents\reviews 27th april.doc
[2009/04/27 18:20:41 | 00,000,162 | -H– | C] () – D:\Documents\~$views 27th april.doc
[2009/04/26 07:24:29 | 00,000,162 | -H– | C] () – D:\Documents\~$aires reviews 25th april.doc
[2009/04/25 18:40:06 | 00,027,648 | —- | C] () – D:\Documents\claires reviews 25th april.doc
[2009/04/25 14:46:25 | 03,763,349 | —- | C] () – D:\Documents\S8003138.JPG
[2009/04/25 14:46:20 | 03,489,540 | —- | C] () – D:\Documents\S8003137.JPG
[2009/04/25 14:46:15 | 03,623,748 | —- | C] () – D:\Documents\S8003136.JPG
[2009/04/25 14:46:08 | 03,687,965 | —- | C] () – D:\Documents\S8003135.JPG
[2009/04/25 14:46:02 | 03,623,254 | —- | C] () – D:\Documents\S8003134.JPG
[2009/04/25 10:53:40 | 00,000,162 | -H– | C] () – D:\Documents\~$views 25th april.doc
[2009/04/25 10:53:39 | 00,041,984 | —- | C] () – D:\Documents\reviews 25th april.doc
[2009/04/24 10:46:24 | 00,029,696 | —- | C] () – D:\Documents\I normally buy the very cheap Smartprice wipes from Asda but unfortunately I ran out last week.doc
[2009/04/24 10:46:24 | 00,000,162 | -H– | C] () – D:\Documents\~$normally buy the very cheap Smartprice wipes from Asda but unfortunately I ran out last week.doc
[2009/04/22 09:08:21 | 00,000,162 | -H– | C] () – D:\Documents\~$da codes.doc
[2009/04/21 20:16:59 | 00,024,064 | —- | C] () – D:\Documents\asda codes.doc
[2009/04/20 19:27:25 | 00,024,064 | —- | C] () – D:\Documents\money 20th April.doc
[2009/04/20 19:27:25 | 00,000,162 | -H– | C] () – D:\Documents\~$ney 20th April.doc
[2009/04/17 17:05:43 | 18,063,038 | —- | C] () – D:\Documents\S8003127.AVI
[2009/04/17 15:36:59 | 18,611,758 | —- | C] () – D:\Documents\S8003122.AVI
[2009/04/16 18:44:37 | 00,058,368 | —- | C] () – D:\Documents\reviews 16th april.doc
[2009/04/16 18:44:37 | 00,000,162 | -H– | C] () – D:\Documents\~$views 16th april.doc
[2009/04/15 21:07:28 | 00,000,162 | -H– | C] () – D:\Documents\~$proved food order.doc
[2009/04/15 21:07:27 | 00,045,056 | —- | C] () – D:\Documents\approved food order.doc
[2009/04/15 12:41:59 | 00,024,064 | —- | C] () – D:\Documents\money april 15th.doc
[2009/04/15 12:41:59 | 00,000,162 | -H– | C] () – D:\Documents\~$ney april 15th.doc
[2009/04/14 12:17:27 | 00,042,496 | —- | C] () – D:\Documents\top ten autobiographies.doc
[2009/04/14 12:17:27 | 00,000,162 | -H– | C] () – D:\Documents\~$p ten autobiographies.doc
[2009/04/13 20:27:14 | 00,035,840 | —- | C] () – D:\Documents\reviews 13th april.doc
[2009/04/13 20:27:14 | 00,000,162 | -H– | C] () – D:\Documents\~$views 13th april.doc
[2009/04/13 20:27:06 | 00,032,768 | —- | C] () – D:\Documents\reviews 9th april.doc
[2008/11/21 22:47:52 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/11/21 22:45:16 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/11/21 22:45:16 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/11/21 22:44:16 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/08/31 08:58:15 | 00,000,000 | —- | C] () – C:\WINDOWS\PhotoNow.INI
[2008/07/20 16:01:41 | 00,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/07/20 16:01:39 | 00,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/07/20 16:01:39 | 00,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/05/29 15:58:19 | 00,000,056 | —- | C] () – C:\WINDOWS\VideoConvert.INI
[2008/03/31 17:38:04 | 00,717,296 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2008/03/31 16:27:14 | 00,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2008/03/30 18:22:06 | 00,000,067 | —- | C] () – C:\WINDOWS\Easy Avi Divx Xvid to DVD Burner.INI
[2007/08/25 20:19:56 | 00,140,216 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2006/08/16 12:49:26 | 00,000,067 | —- | C] () – C:\WINDOWS\#1 DVD Ripper.INI
[2006/08/09 21:36:56 | 00,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2006/07/01 13:41:23 | 00,000,025 | —- | C] () – C:\WINDOWS\XCopyDVD.INI
[2006/02/07 18:51:31 | 00,006,850 | R— | C] () – C:\WINDOWS\Disktool.INI
[2006/02/07 18:51:31 | 00,003,677 | R— | C] () – C:\WINDOWS\PlaySnd.INI
[2006/02/07 18:51:29 | 00,005,628 | R— | C] () – C:\WINDOWS\fwupgrade.ini
[2005/11/07 13:52:16 | 00,000,241 | —- | C] () – C:\WINDOWS\QSync.INI
[2005/11/07 13:51:15 | 00,005,187 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2005/11/04 08:48:16 | 00,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/11/03 21:05:36 | 00,013,312 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2005/11/03 20:41:21 | 00,053,693 | R— | C] () – C:\WINDOWS\UNDPX2A.sys
[2005/11/03 20:41:21 | 00,015,429 | R— | C] ( ) – C:\WINDOWS\System32\drivers\Sacm2A.sys
[2005/11/03 11:17:58 | 00,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2005/11/03 11:13:10 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/03 11:05:42 | 00,761,856 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2005/11/03 11:05:42 | 00,421,888 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2005/11/03 11:05:42 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2005/11/03 11:05:39 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2005/11/03 10:54:21 | 00,394,240 | —- | C] () – C:\WINDOWS\System32\HMTCD.dll
[2005/11/03 10:54:21 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\ContextMenuExt.dll
[2005/11/03 10:54:21 | 00,009,728 | —- | C] () – C:\WINDOWS\System32\UnlockerCOM.dll
[2005/11/03 10:54:21 | 00,003,584 | —- | C] () – C:\WINDOWS\System32\UnlockerDriver4.sys
[2005/11/03 10:49:35 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005/11/03 10:49:35 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2005/11/03 10:49:35 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/11/03 10:49:34 | 01,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/11/03 10:35:21 | 00,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005/11/03 10:35:21 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2005/10/10 22:49:00 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2004/06/01 16:31:13 | 00,069,632 | —- | C] () – C:\WINDOWS\System32\akrip32.dll
[2003/11/13 15:28:02 | 00,012,570 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2003/11/13 15:28:02 | 00,012,570 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2003/01/07 16:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/12/31 13:00:00 | 00,000,603 | —- | C] () – C:\WINDOWS\win.ini
[2002/12/31 13:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[1999/01/27 14:39:06 | 00,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[97 D:\Documents\*.tmp files]
[2017/04/17 15:08:10 | 03,763,349 | —- | M] () – D:\Documents\S8003138.JPG
[2017/04/17 15:07:14 | 03,489,540 | —- | M] () – D:\Documents\S8003137.JPG
[2017/04/17 15:06:24 | 03,623,748 | —- | M] () – D:\Documents\S8003136.JPG
[2017/04/17 14:58:28 | 03,687,965 | —- | M] () – D:\Documents\S8003135.JPG
[2017/04/17 14:57:28 | 03,623,254 | —- | M] () – D:\Documents\S8003134.JPG
[2017/04/09 17:48:22 | 18,063,038 | —- | M] () – D:\Documents\S8003127.AVI
[2017/04/09 16:20:08 | 18,611,758 | —- | M] () – D:\Documents\S8003122.AVI
[2017/03/11 20:48:00 | 10,801,652 | —- | M] () – D:\Documents\S8003102.AVI
[2017/03/11 20:47:06 | 08,776,114 | —- | M] () – D:\Documents\S8003101.AVI
[2017/03/11 15:30:36 | 03,663,555 | —- | M] () – D:\Documents\S8003096.JPG
[2017/03/11 15:30:32 | 03,714,325 | —- | M] () – D:\Documents\S8003095.JPG
[2017/03/11 15:30:26 | 03,708,984 | —- | M] () – D:\Documents\S8003094.JPG
[2017/03/11 11:15:40 | 03,716,578 | —- | M] () – D:\Documents\S8003093.JPG
[2017/03/11 11:15:34 | 03,507,233 | —- | M] () – D:\Documents\S8003092.JPG
[2017/03/11 11:15:26 | 03,663,839 | —- | M] () – D:\Documents\S8003091.JPG
[2017/03/11 11:14:56 | 03,682,951 | —- | M] () – D:\Documents\S8003090.JPG
[2017/03/11 11:14:48 | 03,477,071 | —- | M] () – D:\Documents\S8003089.JPG
[2017/03/11 11:14:42 | 03,441,892 | —- | M] () – D:\Documents\S8003088.JPG
[2017/02/18 21:18:16 | 03,648,047 | —- | M] () – D:\Documents\S8003082.JPG
[2017/02/17 20:15:26 | 03,673,601 | —- | M] () – D:\Documents\S8003081.JPG
[2017/02/16 20:00:42 | 03,499,989 | —- | M] () – D:\Documents\S8003077.JPG
[2017/02/15 20:19:18 | 03,643,656 | —- | M] () – D:\Documents\S8003076.JPG
[2017/02/14 19:10:04 | 03,888,699 | —- | M] () – D:\Documents\S8003074.JPG
[2017/02/14 19:09:50 | 03,918,969 | —- | M] () – D:\Documents\S8003073.JPG
[2017/02/14 19:06:50 | 04,032,828 | —- | M] () – D:\Documents\S8003065.JPG
[2017/02/14 19:03:56 | 03,462,410 | —- | M] () – D:\Documents\S8003062.JPG
[2017/02/14 19:02:44 | 03,588,873 | —- | M] () – D:\Documents\S8003059.JPG
[2017/02/14 19:02:30 | 03,552,490 | —- | M] () – D:\Documents\S8003058.JPG
[2017/02/14 19:02:20 | 03,882,996 | —- | M] () – D:\Documents\S8003057.JPG
[2017/02/14 19:01:00 | 03,616,824 | —- | M] () – D:\Documents\S8003056.JPG
[2017/02/14 18:55:32 | 03,735,231 | —- | M] () – D:\Documents\S8003052.JPG
[2017/02/14 18:54:52 | 03,537,626 | —- | M] () – D:\Documents\S8003051.JPG
[2017/02/14 18:53:58 | 03,039,240 | —- | M] () – D:\Documents\S8003049.JPG
[2017/02/14 18:53:24 | 03,088,220 | —- | M] () – D:\Documents\S8003048.JPG
[2017/02/14 18:49:46 | 03,422,123 | —- | M] () – D:\Documents\S8003045.JPG
[2017/02/12 15:34:12 | 03,640,028 | —- | M] () – D:\Documents\S8003041.JPG
[2017/02/12 15:32:44 | 03,597,350 | —- | M] () – D:\Documents\S8003040.JPG
[2017/02/11 20:11:50 | 03,383,866 | —- | M] () – D:\Documents\S8003032.JPG
[2017/02/11 20:09:42 | 03,317,057 | —- | M] () – D:\Documents\S8003029.JPG
[2017/02/11 18:57:06 | 38,761,660 | —- | M] () – D:\Documents\S8003024.AVI
[2017/02/10 14:07:02 | 03,664,500 | —- | M] () – D:\Documents\S8003011.JPG
[2017/02/10 14:06:30 | 03,529,037 | —- | M] () – D:\Documents\S8003009.JPG
[2017/02/04 20:57:00 | 03,632,481 | —- | M] () – D:\Documents\S8003008.JPG
[2017/02/04 20:56:54 | 03,766,801 | —- | M] () – D:\Documents\S8003007.JPG
[2017/02/04 20:56:48 | 03,762,596 | —- | M] () – D:\Documents\S8003006.JPG
[2017/02/04 20:56:42 | 03,620,148 | —- | M] () – D:\Documents\S8003005.JPG
[2017/02/04 20:55:40 | 03,748,302 | —- | M] () – D:\Documents\S8003004.JPG
[2017/02/04 20:55:34 | 03,712,921 | —- | M] () – D:\Documents\S8003003.JPG
[2017/02/04 20:55:24 | 03,742,045 | —- | M] () – D:\Documents\S8003001.JPG
[2017/02/01 23:06:48 | 08,844,590 | —- | M] () – D:\Documents\S8002990.AVI
[2017/02/01 23:05:56 | 06,274,206 | —- | M] () – D:\Documents\S8002989.AVI
[2017/02/01 23:05:18 | 04,819,684 | —- | M] () – D:\Documents\S8002988.AVI
[2017/01/29 23:31:36 | 07,230,174 | —- | M] () – D:\Documents\S8002987.AVI
[2017/01/26 21:42:10 | 13,496,886 | —- | M] () – D:\Documents\S8002986.AVI
[2017/01/24 21:03:02 | 03,470,198 | —- | M] () – D:\Documents\S8002985.JPG
[2017/01/24 21:02:44 | 03,729,006 | —- | M] () – D:\Documents\S8002984.JPG
[2017/01/24 20:53:36 | 03,153,885 | —- | M] () – D:\Documents\S8002978.JPG
[2017/01/24 20:53:14 | 03,008,534 | —- | M] () – D:\Documents\S8002977.JPG
[2017/01/24 20:53:02 | 03,007,245 | —- | M] () – D:\Documents\S8002976.JPG
[2017/01/21 20:52:12 | 26,667,520 | —- | M] () – D:\Documents\S8002975.AVI
[2017/01/16 17:40:34 | 08,028,276 | —- | M] () – D:\Documents\S8002974.AVI
[2017/01/16 17:39:32 | 07,225,952 | —- | M] () – D:\Documents\S8002973.AVI
[2017/01/16 17:38:58 | 04,661,484 | —- | M] () – D:\Documents\S8002972.AVI
[2017/01/16 17:38:38 | 08,134,334 | —- | M] () – D:\Documents\S8002971.AVI
[2017/01/16 17:37:24 | 11,613,468 | —- | M] () – D:\Documents\S8002970.AVI
[2017/01/16 17:36:36 | 08,788,884 | —- | M] () – D:\Documents\S8002969.AVI
[2017/01/14 21:40:10 | 03,476,086 | —- | M] () – D:\Documents\S8002968.JPG
[2017/01/05 21:09:30 | 09,276,668 | —- | M] () – D:\Documents\S8002967.AVI
[2017/01/05 21:08:48 | 01,807,018 | —- | M] () – D:\Documents\S8002966.AVI
[2017/01/04 16:04:32 | 03,926,859 | —- | M] () – D:\Documents\S8002965.JPG
[2017/01/04 16:04:18 | 04,038,331 | —- | M] () – D:\Documents\S8002964.JPG
[2017/01/04 16:04:04 | 02,478,024 | —- | M] () – D:\Documents\S8002963.JPG
[2017/01/04 16:03:56 | 03,966,993 | —- | M] () – D:\Documents\S8002962.JPG
[2016/12/30 16:08:32 | 02,580,421 | —- | M] () – D:\Documents\S8002961.JPG
[2016/12/30 16:07:40 | 03,453,957 | —- | M] () – D:\Documents\S8002959.JPG
[2016/12/30 16:04:20 | 03,662,601 | —- | M] () – D:\Documents\S8002958.JPG
[2016/12/23 19:14:18 | 02,941,982 | —- | M] () – D:\Documents\S8002948.AVI
[2016/12/18 17:45:20 | 00,119,898 | —- | M] () – D:\Documents\S8002912.WAV
[2016/12/17 13:48:02 | 05,443,604 | —- | M] () – D:\Documents\S8002889.AVI
[2016/12/17 10:58:56 | 09,478,544 | —- | M] () – D:\Documents\S8002884.AVI
[2016/12/16 19:32:44 | 01,092,660 | —- | M] () – D:\Documents\S8002865.AVI
[2016/12/11 19:51:28 | 43,629,660 | —- | M] () – D:\Documents\S8002864.AVI
[2016/12/11 19:46:28 | 08,036,124 | —- | M] () – D:\Documents\S8002863.AVI
[2016/12/10 19:52:34 | 39,698,312 | —- | M] () – D:\Documents\S8002858.AVI
[2016/11/28 21:12:44 | 14,290,272 | —- | M] () – D:\Documents\S8002844.AVI
[2016/10/28 21:16:44 | 19,383,516 | —- | M] () – D:\Documents\S8002696.AVI
[2016/10/23 20:46:56 | 27,106,884 | —- | M] () – D:\Documents\S8002685.AVI
[2016/10/11 10:31:56 | 03,517,939 | —- | M] () – D:\Documents\S8002572.JPG
[2016/10/05 16:38:46 | 03,414,466 | —- | M] () – D:\Documents\S8002485.JPG
[2016/10/05 13:11:08 | 03,685,773 | —- | M] () – D:\Documents\S8002470.JPG
[2016/09/25 19:55:46 | 15,029,548 | —- | M] () – D:\Documents\S8002333.AVI
[2016/09/25 19:54:32 | 08,406,098 | —- | M] () – D:\Documents\S8002332.AVI
[2016/09/25 19:53:44 | 06,681,860 | —- | M] () – D:\Documents\S8002331.AVI
[2016/09/25 19:53:10 | 21,426,506 | —- | M] () – D:\Documents\S8002330.AVI
[2016/09/25 19:46:04 | 05,985,844 | —- | M] () – D:\Documents\S8002329.AVI
[2016/09/25 19:36:44 | 16,101,660 | —- | M] () – D:\Documents\S8002328.AVI
[2016/09/25 19:17:26 | 04,384,882 | —- | M] () – D:\Documents\S8002325.AVI
[2009/05/11 22:27:24 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/05/11 22:27:13 | 00,000,433 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2009/05/11 22:24:07 | 00,039,568 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/05/11 22:23:57 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/05/11 22:23:55 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/11 22:23:50 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Andrew and Claire\Local Settings\desktop.ini
[2009/05/11 22:23:46 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/11 22:23:41 | 00,566,868 | —- | M] () – C:\WINDOWS\System32\OODBS.lor
[2009/05/11 22:20:17 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/05/11 22:15:58 | 03,020,851 | R— | M] () – C:\Documents and Settings\Andrew and Claire\Desktop\ComboFix.exe
[2009/05/11 22:12:15 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/05/11 22:10:50 | 00,000,040 | —- | M] () – C:\WINDOWS\System32\profile.dat
[2009/05/11 22:04:19 | 00,034,816 | —- | M] () – D:\Documents\andrew reviews.doc
[2009/05/11 21:42:00 | 00,000,278 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2009/05/11 21:10:12 | 00,000,366 | —- | M] () – C:\WINDOWS\tasks\Symantec NetDetect.job
[2009/05/11 18:38:42 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Andrew and Claire\Desktop\OTListIt2.exe
[2009/05/11 18:36:04 | 00,267,612 | —- | M] () – C:\Documents and Settings\Andrew and Claire\Desktop\Rooter.exe
[2009/05/11 17:18:57 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/05/10 20:12:17 | 00,000,151 | —- | M] () – C:\WINDOWS\PhotoSnapViewer.INI
[2009/05/09 18:25:42 | 00,000,839 | —- | M] () – D:\Documents\My Sharing Folders.lnk
[2009/05/09 12:25:53 | 00,000,706 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/09 12:24:44 | 02,967,800 | —- | M] (Malwarebytes Corporation ) – D:\Documents\mbam-setup.exe
[2009/05/09 12:09:12 | 00,001,744 | —- | M] () – C:\Documents and Settings\Andrew and Claire\Desktop\HijackThis.lnk
[2009/05/09 12:09:02 | 00,812,344 | —- | M] (Trend Micro Inc.) – D:\Documents\HJTInstall.exe
[2009/05/09 12:00:10 | 09,924,040 | —- | M] (Microsoft Corporation) – D:\Documents\windows-kb890830-v2.9.exe
[2009/05/09 11:53:41 | 00,025,088 | —- | M] () – D:\Documents\andrews new reviews 9th may.doc
[2009/05/09 08:56:43 | 00,026,112 | —- | M] () – D:\Documents\Mummy do you love me.doc
[2009/05/08 12:05:12 | 00,030,720 | —- | M] () – D:\Documents\Tommee tippee cup,library..doc
[2009/05/08 11:33:49 | 00,000,162 | -H– | M] () – D:\Documents\~$mmee tippee cup,library..doc
[2009/05/07 07:26:32 | 00,013,733 | —- | M] () – C:\WINDOWS\System32\ormh
[2009/05/05 07:58:28 | 00,002,228 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/05/05 07:40:14 | 23,672,585 | —- | M] () – D:\Documents\falling epik killah mix.mp3
[2009/05/04 13:04:45 | 51,272,088 | —- | M] () – C:\Documents and Settings\Andrew and Claire\Desktop\videoFileNo130122.mpg
[2009/05/04 13:03:37 | 04,820,424 | —- | M] () – C:\Documents and Settings\Andrew and Claire\Desktop\videoFileNo130122.flv
[2009/05/04 13:01:11 | 00,000,002 | -HS- | M] () – C:\Documents and Settings\Andrew and Claire\Application Data\evf
[2009/05/01 22:26:52 | 00,000,162 | -H– | M] () – D:\Documents\~$randad.doc
[2009/05/01 22:26:51 | 00,024,064 | —- | M] () – D:\Documents\grandad.doc
[2009/05/01 16:57:17 | 00,001,804 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/05/01 15:36:46 | 00,117,248 | —- | M] () – C:\WINDOWS\vFind.exe
[2009/04/30 12:21:18 | 00,027,648 | —- | M] () – D:\Documents\claires reviews 25th april.doc
[2009/04/27 18:20:41 | 00,035,328 | —- | M] () – D:\Documents\reviews 27th april.doc
[2009/04/27 18:20:41 | 00,000,162 | -H– | M] () – D:\Documents\~$views 27th april.doc
[2009/04/26 10:54:20 | 00,041,984 | —- | M] () – D:\Documents\reviews 25th april.doc
[2009/04/26 07:24:29 | 00,000,162 | -H– | M] () – D:\Documents\~$aires reviews 25th april.doc
[2009/04/25 10:53:40 | 00,000,162 | -H– | M] () – D:\Documents\~$views 25th april.doc
[2009/04/24 10:46:24 | 00,029,696 | —- | M] () – D:\Documents\I normally buy the very cheap Smartprice wipes from Asda but unfortunately I ran out last week.doc
[2009/04/24 10:46:24 | 00,000,162 | -H– | M] () – D:\Documents\~$normally buy the very cheap Smartprice wipes from Asda but unfortunately I ran out last week.doc
[2009/04/22 09:08:21 | 00,000,162 | -H– | M] () – D:\Documents\~$da codes.doc
[2009/04/21 20:17:00 | 00,024,064 | —- | M] () – D:\Documents\asda codes.doc
[2009/04/20 19:32:16 | 00,058,368 | —- | M] () – D:\Documents\reviews 16th april.doc
[2009/04/20 19:27:25 | 00,024,064 | —- | M] () – D:\Documents\money 20th April.doc
[2009/04/20 19:27:25 | 00,000,162 | -H– | M] () – D:\Documents\~$ney 20th April.doc
[2009/04/20 12:56:28 | 00,031,232 | —- | M] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/04/16 18:44:37 | 00,000,162 | -H– | M] () – D:\Documents\~$views 16th april.doc
[2009/04/15 21:07:28 | 00,000,162 | -H– | M] () – D:\Documents\~$proved food order.doc
[2009/04/15 21:07:27 | 00,045,056 | —- | M] () – D:\Documents\approved food order.doc
[2009/04/15 12:42:24 | 00,024,064 | —- | M] () – D:\Documents\money april 15th.doc
[2009/04/15 12:41:59 | 00,000,162 | -H– | M] () – D:\Documents\~$ney april 15th.doc
[2009/04/14 12:47:47 | 00,042,496 | —- | M] () – D:\Documents\top ten autobiographies.doc
[2009/04/14 12:43:39 | 00,035,840 | —- | M] () – D:\Documents\reviews 13th april.doc
[2009/04/14 12:17:27 | 00,000,162 | -H– | M] () – D:\Documents\~$p ten autobiographies.doc
[2009/04/13 20:27:14 | 00,000,162 | -H– | M] () – D:\Documents\~$views 13th april.doc
[2009/04/13 20:27:06 | 00,032,768 | —- | M] () – D:\Documents\reviews 9th april.doc
< End of report >



RESULTS FROM COMBOFIX:


ComboFix 09-05-11.01 - Andrew and Claire 11/05/2009 22:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1023.482 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: Symantec Client Firewall *disabled*
.
ADS - WINDOWS: deleted 32945 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Andrew and Claire\Application Data\inst.exe
c:\documents and settings\Andrew and Claire\Application Data\wiaserva.log
c:\windows\IE4 Error Log.txt
c:\windows\system32\dz1.txt
c:\windows\system32\inform.dat
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\p1.txt
c:\windows\system32\r24.txt
c:\windows\system32\sdra64.exe
c:\windows\system32\wbem\grpconv.exe

.
((((((((((((((((((((((((( Files Created from 2009-04-11 to 2009-05-11 )))))))))))))))))))))))))))))))
.

2009-05-11 21:10 . 2009-05-11 21:10 ——– d—–w C:\Kontiki
2009-05-11 21:06 . 2009-05-11 21:06 ——– d—–w C:\_OTListIt
2009-05-11 17:35 . 2009-05-11 17:36 ——– d—–w C:\Rooter$
2009-05-09 11:26 . 2009-05-09 11:26 ——– d—–w c:\documents and settings\Andrew and Claire\Application Data\Malwarebytes
2009-05-09 11:25 . 2009-04-06 14:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-09 11:25 . 2009-04-06 14:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-09 11:25 . 2009-05-09 11:25 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-09 11:25 . 2009-05-09 11:25 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-09 11:09 . 2009-05-09 11:09 ——– d—–w c:\program files\Trend Micro
2009-05-07 06:26 . 2009-05-11 21:27 ——– d-sh–w c:\windows\system32\bookls
2009-05-04 12:00 . 2009-05-09 17:26 ——– d—–w c:\program files\ZillaTube
2009-05-01 15:56 . 2009-05-01 15:56 ——– d—–w c:\program files\iPod
2009-05-01 15:56 . 2009-05-01 15:57 ——– d—–w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-01 15:56 . 2009-05-01 15:57 ——– d—–w c:\program files\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-11 21:27 . 2005-11-03 10:13 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-05-11 21:10 . 2005-11-03 10:21 40 —-a-w c:\windows\system32\profile.dat
2009-05-09 17:39 . 2008-04-13 07:46 ——– d—–w c:\program files\Kontiki
2009-05-09 17:35 . 2009-01-27 17:40 ——– d—–w c:\program files\Gabest
2009-05-09 17:34 . 2007-03-22 18:37 ——– d—–w c:\program files\AVI MPEG WMV RM to MP3 Converter
2009-05-09 17:33 . 2007-02-22 19:13 ——– d—–w c:\program files\Apple Software Update
2009-05-09 17:32 . 2007-08-17 11:09 ——– d—–w c:\program files\Common Files\Apple
2009-05-09 17:32 . 2008-05-29 14:57 ——– d—–w c:\program files\AimOne Video Converter
2009-05-09 17:30 . 2006-06-28 15:10 ——– d—–w c:\program files\dvd43
2009-05-09 17:29 . 2005-12-31 18:48 ——– d—–w c:\program files\Google
2009-05-09 17:24 . 2007-03-19 22:20 ——– d—–w c:\program files\VirtualDJ
2009-05-09 17:14 . 2005-11-03 10:00 ——– d–h–w c:\program files\InstallShield Installation Information
2009-03-19 15:32 . 2008-01-29 11:01 23400 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
.

——- Sigcheck ——-

[-] 2002-12-31 12:00 14336 8F078AE4ED187AAABC0A305146DE6716 c:\windows\system32\svchost.exe

[-] 2002-12-31 12:00 82944 2ED0B7F12A60F90092081C50FA0EC2B2 c:\windows\system32\ws2_32.dll

[-] 2002-12-31 12:00 182912 558635D3AF1C7546D26067D5D9B6959E c:\windows\system32\drivers\ndis.sys

[-] 2002-12-31 12:00 29056 4448006B6BC60E6C027932CFC38D6855 c:\windows\system32\drivers\ip6fw.sys

[-] 2002-12-31 12:00 108032 C6CE6EEC82F187615D1002BB3BB50ED4 c:\windows\system32\services.exe

[-] 2002-12-31 12:00 13312 84885F9B82F4D55C6146EBF6065D75D2 c:\windows\system32\lsass.exe

[-] 2002-12-31 12:00 15360 24232996A38C0B0CF151C2140AE29FC8 c:\windows\system32\ctfmon.exe

[-] 2002-12-31 12:00 24576 39B1FFB03C2296323832ACBAE50D2AFF c:\windows\system32\userinit.exe

[-] 2002-12-31 12:00 17408 1B5F6923ABB450692E9FE0672C897AED c:\windows\system32\powrprof.dll

[-] 2002-12-31 12:00 110080 87CA7CE6469577F059297B9D6556D66D c:\windows\system32\imm32.dll

[-] 2002-12-31 12:00 1580544 30A609E00BD1D4FFC49D6B5A432BE7F2 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2002-12-31 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-20 68856]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 131072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-10-10 7286784]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 48752]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~2\VPTray.exe" [2005-04-17 85184]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2006-03-24 190024]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-10-10 86016]
"LVCOMS"="c:\program files\Common Files\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 127022]
"LogitechGalleryRepair"="c:\program files\Logitech\ImageStudio\ISStart.exe" [2002-12-10 155648]
"LogitechImageStudioTray"="c:\program files\Logitech\ImageStudio\LogiTray.exe" [2002-12-10 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"WinampAgent"="d:\program files\Winamp\winampa.exe" [2006-06-21 35328]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"muBlinder"="c:\program files\muBlinder\muBlinder.exe" [2008-03-27 1406464]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-10-10 1519616]

c:\documents and settings\Andrew and Claire\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - d:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableProfileQuota"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,c:\windows\system32\pavuppad.exe,"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Games\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\GetRight\\getright.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:@xpsp2res.dll,-22004
"445:TCP"= 445:TCP:@xpsp2res.dll,-22005
"137:UDP"= 137:UDP:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:@xpsp2res.dll,-22002

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings]
"RemoteAddresses"= *
"Enabled"= 1 (0x1)

R3 EraserUtilDrv10910;EraserUtilDrv10910;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys [08/05/2009 17:15 101936]
S3 SavRoam;SAVRoam;c:\program files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [17/04/2005 13:30 124608]
S3 UnlockerDriver4;UnlockerDriver4 Driver;c:\windows\system32\UnlockerDriver4.sys [03/11/2005 10:54 3584]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{901A929E-1477-4b67-94FA-7A8EE43ED159}]
rundll32 msfgw32.dll,InitO
.
Contents of the 'Scheduled Tasks' folder

2009-05-11 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 16:39]

2009-05-11 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-27 16:29]

2009-05-11 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-11-03 17:32]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-DAEMON Tools Lite - c:\program files\DAEMON Tools Lite\daemon.exe


.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local;
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {6F714D46-E4EF-11D4-93EF-00D0D7032099} - hxxp://www.christianrock2.net/amp3dj.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-11 22:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Preview\PONMLK^]\[*¬ d*]
"IDSLD"="JJGMNEIIFG"

[HKEY_USERS\S-1-5-21-1409082233-57989841-725345543-1005\Software\Preview\PONMLK^]\[*¬ d*]
"IDSLD"="JJGMNEIICE"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1852)
c:\program files\MessengerPlus! 3\MsgPlusLoader.dll
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\windows\system32\rundll32.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\oodag.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
c:\program files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Kontiki\KService.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Symantec Shared\NMain.exe
.
**************************************************************************
.
Completion time: 2009-05-11 22:29 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-11 21:29

Pre-Run: 2,484,408,320 bytes free
Post-Run: 2,431,578,112 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

213
A few more bits to go - could you let me know how your system is running on completion

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

RegLockDel::
[HKEY_USERS\.Default\Software\Preview\PONMLK^]\[*¬ d*]
[HKEY_USERS\S-1-5-21-1409082233-57989841-725345543-1005\Software\Preview\PONMLK^]\[*¬ d*]

File::
c:\windows\system32\msfgw32.dll

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{901A929E-1477-4b67-94FA-7A8EE43ED159}]

3. Then in the text file go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES

4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new OTListit log.
ok, I did as you said, but it popped up saying something about 'Windows cannot find GRPconv', and then it went to a page saying I should download a new copy of combofix which I did, then this was the result:

ComboFix 09-05-11.08 - Andrew and Claire 12/05/2009 18:01.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1023.388 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: d:\documents\CFScript.txt
FW: Symantec Client Firewall *disabled*

FILE ::
c:\windows\system32\msfgw32.dll
.

((((((((((((((((((((((((( Files Created from 2009-04-12 to 2009-05-12 )))))))))))))))))))))))))))))))
.

2009-05-12 16:58 . 2009-05-12 16:58 0 —-a-w c:\documents and settings\Andrew and Claire\.exe
2009-05-11 21:10 . 2009-05-11 21:10 ——– d—–w C:\Kontiki
2009-05-11 21:06 . 2009-05-11 21:06 ——– d—–w C:\_OTListIt
2009-05-11 17:35 . 2009-05-11 21:36 ——– d—–w C:\Rooter$
2009-05-09 11:26 . 2009-05-09 11:26 ——– d—–w c:\documents and settings\Andrew and Claire\Application Data\Malwarebytes
2009-05-09 11:25 . 2009-04-06 14:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-09 11:25 . 2009-04-06 14:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-09 11:25 . 2009-05-09 11:25 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-09 11:25 . 2009-05-09 11:25 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-09 11:09 . 2009-05-09 11:09 ——– d—–w c:\program files\Trend Micro
2009-05-07 06:26 . 2009-05-12 16:53 ——– d-sh–w c:\windows\system32\bookls
2009-05-04 12:00 . 2009-05-09 17:26 ——– d—–w c:\program files\ZillaTube
2009-05-01 15:56 . 2009-05-01 15:56 ——– d—–w c:\program files\iPod
2009-05-01 15:56 . 2009-05-01 15:57 ——– d—–w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-01 15:56 . 2009-05-01 15:57 ——– d—–w c:\program files\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-11 21:27 . 2005-11-03 10:13 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-05-11 21:10 . 2005-11-03 10:21 40 —-a-w c:\windows\system32\profile.dat
2009-05-09 17:39 . 2008-04-13 07:46 ——– d—–w c:\program files\Kontiki
2009-05-09 17:35 . 2009-01-27 17:40 ——– d—–w c:\program files\Gabest
2009-05-09 17:34 . 2007-03-22 18:37 ——– d—–w c:\program files\AVI MPEG WMV RM to MP3 Converter
2009-05-09 17:33 . 2007-02-22 19:13 ——– d—–w c:\program files\Apple Software Update
2009-05-09 17:32 . 2007-08-17 11:09 ——– d—–w c:\program files\Common Files\Apple
2009-05-09 17:32 . 2008-05-29 14:57 ——– d—–w c:\program files\AimOne Video Converter
2009-05-09 17:30 . 2006-06-28 15:10 ——– d—–w c:\program files\dvd43
2009-05-09 17:29 . 2005-12-31 18:48 ——– d—–w c:\program files\Google
2009-05-09 17:24 . 2007-03-19 22:20 ——– d—–w c:\program files\VirtualDJ
2009-05-09 17:14 . 2005-11-03 10:00 ——– d–h–w c:\program files\InstallShield Installation Information
2009-03-19 15:32 . 2008-01-29 11:01 23400 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
.

——- Sigcheck ——-

[-] 2002-12-31 12:00 14336 8F078AE4ED187AAABC0A305146DE6716 c:\windows\system32\svchost.exe

[-] 2002-12-31 12:00 82944 2ED0B7F12A60F90092081C50FA0EC2B2 c:\windows\system32\ws2_32.dll

[-] 2002-12-31 12:00 182912 558635D3AF1C7546D26067D5D9B6959E c:\windows\system32\drivers\ndis.sys

[-] 2002-12-31 12:00 29056 4448006B6BC60E6C027932CFC38D6855 c:\windows\system32\drivers\ip6fw.sys

[-] 2002-12-31 12:00 108032 C6CE6EEC82F187615D1002BB3BB50ED4 c:\windows\system32\services.exe

[-] 2002-12-31 12:00 13312 84885F9B82F4D55C6146EBF6065D75D2 c:\windows\system32\lsass.exe

[-] 2002-12-31 12:00 15360 24232996A38C0B0CF151C2140AE29FC8 c:\windows\system32\ctfmon.exe

[-] 2002-12-31 12:00 24576 39B1FFB03C2296323832ACBAE50D2AFF c:\windows\system32\userinit.exe

[-] 2002-12-31 12:00 17408 1B5F6923ABB450692E9FE0672C897AED c:\windows\system32\powrprof.dll

[-] 2002-12-31 12:00 110080 87CA7CE6469577F059297B9D6556D66D c:\windows\system32\imm32.dll

[-] 2002-12-31 12:00 1580544 30A609E00BD1D4FFC49D6B5A432BE7F2 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2002-12-31 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-20 68856]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 131072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-10-10 7286784]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 48752]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~2\VPTray.exe" [2005-04-17 85184]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2006-03-24 190024]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-10-10 86016]
"LVCOMS"="c:\program files\Common Files\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 127022]
"LogitechGalleryRepair"="c:\program files\Logitech\ImageStudio\ISStart.exe" [2002-12-10 155648]
"LogitechImageStudioTray"="c:\program files\Logitech\ImageStudio\LogiTray.exe" [2002-12-10 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"WinampAgent"="d:\program files\Winamp\winampa.exe" [2006-06-21 35328]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"muBlinder"="c:\program files\muBlinder\muBlinder.exe" [2008-03-27 1406464]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-10-10 1519616]

c:\documents and settings\Andrew and Claire\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - d:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableProfileQuota"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,c:\windows\system32\pavuppad.exe,"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Games\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\GetRight\\getright.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:@xpsp2res.dll,-22004
"445:TCP"= 445:TCP:@xpsp2res.dll,-22005
"137:UDP"= 137:UDP:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:@xpsp2res.dll,-22002

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings]
"RemoteAddresses"= *
"Enabled"= 1 (0x1)

R3 EraserUtilDrv10910;EraserUtilDrv10910;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys [08/05/2009 17:15 101936]
S3 SavRoam;SAVRoam;c:\program files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [17/04/2005 13:30 124608]
S3 UnlockerDriver4;UnlockerDriver4 Driver;c:\windows\system32\UnlockerDriver4.sys [03/11/2005 10:54 3584]
.
Contents of the 'Scheduled Tasks' folder

2009-05-12 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 16:39]

2009-05-12 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-27 16:29]

2009-05-12 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-11-03 17:32]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local;
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {6F714D46-E4EF-11D4-93EF-00D0D7032099} - hxxp://www.christianrock2.net/amp3dj.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-12 18:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Preview\PONMLK^]\[*¬ d*]
"IDSLD"="JJGMNEIIFG"

[HKEY_USERS\S-1-5-21-1409082233-57989841-725345543-1005\Software\Preview\PONMLK^]\[*¬ d*]
"IDSLD"="JJGMNEIICE"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(596)
c:\program files\MessengerPlus! 3\MsgPlusLoader.dll
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-05-12 18:04
ComboFix-quarantined-files.txt 2009-05-12 17:04
ComboFix2.txt 2009-05-11 21:29

Pre-Run: 2,420,715,520 bytes free
Post-Run: 2,466,148,352 bytes free

170

THEN THE OTLIST:

OTListIt logfile created on: 12/05/2009 18:08:02 - Run 4
OTListIt2 by OldTimer - Version 2.0.15.6 Folder = C:\Documents and Settings\Andrew and Claire\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 363.53 Mb Available Physical Memory | 35.52% Memory free
1.65 Gb Paging File | 1.17 Gb Available in Paging File | 71.04% Paging File free
Paging file location(s): D:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9.87 Gb Total Space | 2.31 Gb Free Space | 23.42% Space Free | Partition Type: NTFS
Drive D: | 139.18 Gb Total Space | 29.41 Gb Free Space | 21.13% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STEPHEN
Current User Name: Andrew and Claire
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe (NVIDIA Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\MessengerPlus! 3\MsgPlus.exe (Patchou)
PRC - C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE (Logitech Inc.)
PRC - C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - D:\Program Files\Winamp\winampa.exe ()
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
PRC - C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\oodag.exe (O&O Software GmbH)
PRC - C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\NMain.exe (Symantec Corporation)
PRC - D:\Program Files\Winamp\winamp.exe (Nullsoft)
PRC - C:\Documents and Settings\Andrew and Claire\Desktop\OTListIt2.exe (OldTimer Tools)
PRC - C:\WINDOWS\notepad.exe (Microsoft Corporation)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Andrew and Claire\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (ccEvtMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (ccProxy [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
SRV - (ccPwdSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DefWatch [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (ISSVC [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (Symantec Corporation)
SRV - (KService [Auto | Running]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (O&O Defrag [Auto | Running]) – C:\WINDOWS\system32\oodag.exe (O&O Software GmbH)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PnkBstrA [Auto | Stopped]) – C:\WINDOWS\system32\PnkBstrA.exe ()
SRV - (PnkBstrB [Auto | Stopped]) – C:\WINDOWS\system32\PnkBstrB.exe ()
SRV - (RichVideo [Auto | Running]) – C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (SavRoam [On_Demand | Stopped]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (SNDSrvc [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (Symantec AntiVirus [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (SymSecurePort [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe (Symantec Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AmdK8 [System | Running]) – C:\WINDOWS\system32\DRIVERS\AmdK8.sys (Advanced Micro Devices)
DRV - (ASPI32 [Auto | Running]) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
DRV - (catchme [Disabled | Running]) – File not found
DRV - (E100B [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilDrv10910 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys (Symantec Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (NAVENG [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090508.003\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090508.003\NAVEX15.SYS (Symantec Corporation)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvatabus [Boot | Running]) – C:\WINDOWS\System32\drivers\NvAtaBus.sys (NVIDIA Corporation)
DRV - (nvax [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)
DRV - (nvnforce [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (Pcouffin [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\Pcouffin.sys (VSO Software)
DRV - (PhilCam8116 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\CamDrL21.sys (Philips Semiconductors)
DRV - (PnkBstrK [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\PnkBstrK.sys ()
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ROOTMODEM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (SAVRT [System | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL [System | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SPBBCDrv [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (sptd [Boot | Running]) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (SYMDNS [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMFW [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMIDSCO [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\SymcData\scfidsdefs\20090428.001\SymIDSCo.sys (Symantec Corporation)
DRV - (SYMNDIS [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Running]) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (UnlockerDriver4 [On_Demand | Stopped]) – C:\WINDOWS\system32\UnlockerDriver4.sys ()
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (USBCM [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\Sacm2A.sys ( )

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;



O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (bho2gr Class) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe (Logitech Inc.)
O4 - HKLM..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE (Logitech Inc.)
O4 - HKLM..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" (Patchou)
O4 - HKLM..\Run: [muBlinder] C:\Program Files\muBlinder\muBlinder.exe -startup (KRX)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe ()
O4 - HKCU..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all (Kontiki Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Andrew and Claire\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Andrew and Claire\Start Menu\Programs\Startup\Xfire.lnk = D:\Program Files\Xfire\Xfire.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1220281776046 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1220281767609 (MUWebControl Class)
O16 - DPF: {6F714D46-E4EF-11D4-93EF-00D0D7032099} http://www.christianrock2.net/amp3dj.cab (Active DJ Studio ActiveX Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\pavuppad.exe) - C:\WINDOWS\system32\pavuppad.exe ()
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/03 10:58:28 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (OODBS) - C:\WINDOWS\System32\OODBS.exe (O&O Software GmbH)

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2016/10/29 20:12:56 | 00,379,912 | —- | C] () – D:\Documents\S8002705.JPG
[2016/10/28 21:15:18 | 19,383,516 | —- | C] () – D:\Documents\S8002696.AVI
[2009/05/12 18:04:47 | 00,000,000 | —D | C] – C:\Documents and Settings\Andrew and Claire\Local Settings\temp
[2009/05/12 15:54:53 | 00,000,162 | -H– | C] () – D:\Documents\~$ttle stars yogurt.doc
[2009/05/12 15:54:52 | 00,024,576 | —- | C] () – D:\Documents\Little stars yogurt.doc
[2009/05/11 22:22:01 | 00,000,000 | —D | C] – C:\WINDOWS\temp
[2009/05/11 22:20:17 | 00,000,211 | —- | C] () – C:\Boot.bak
[2009/05/11 22:20:16 | 00,260,272 | —- | C] () – C:\cmldr
[2009/05/11 22:20:14 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/05/11 22:19:01 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/05/11 22:19:01 | 00,117,248 | —- | C] () – C:\WINDOWS\vFind.exe
[2009/05/11 22:19:01 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/05/11 22:19:01 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/05/11 22:19:01 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/05/11 22:19:01 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/05/11 22:19:00 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/05/11 22:19:00 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/05/11 22:18:51 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/05/11 22:18:45 | 00,000,000 | —D | C] – C:\Qoobox
[2009/05/11 22:15:58 | 03,021,140 | R— | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\ComboFix.exe
[2009/05/11 22:10:50 | 00,000,000 | —D | C] – C:\Kontiki
[2009/05/11 22:06:55 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/05/11 22:04:19 | 00,034,816 | —- | C] () – D:\Documents\andrew reviews.doc
[2009/05/11 18:38:37 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Andrew and Claire\Desktop\OTListIt2.exe
[2009/05/11 18:36:01 | 00,267,612 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\Rooter.exe
[2009/05/11 18:35:35 | 00,000,000 | —D | C] – C:\Rooter$
[2009/05/09 18:33:40 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/05/09 12:26:02 | 00,000,000 | —D | C] – C:\Documents and Settings\Andrew and Claire\Application Data\Malwarebytes
[2009/05/09 12:25:53 | 00,000,706 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/09 12:25:51 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/09 12:25:45 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/09 12:25:43 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/05/09 12:25:42 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/09 12:24:44 | 02,967,800 | —- | C] (Malwarebytes Corporation ) – D:\Documents\mbam-setup.exe
[2009/05/09 12:09:12 | 00,001,744 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\HijackThis.lnk
[2009/05/09 12:09:11 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/05/09 12:08:59 | 00,812,344 | —- | C] (Trend Micro Inc.) – D:\Documents\HJTInstall.exe
[2009/05/09 12:00:10 | 09,924,040 | —- | C] (Microsoft Corporation) – D:\Documents\windows-kb890830-v2.9.exe
[2009/05/09 11:53:41 | 00,025,088 | —- | C] () – D:\Documents\andrews new reviews 9th may.doc
[2009/05/09 08:56:42 | 00,026,112 | —- | C] () – D:\Documents\Mummy do you love me.doc
[2009/05/08 11:33:49 | 00,030,720 | —- | C] () – D:\Documents\Tommee tippee cup,library..doc
[2009/05/08 11:33:49 | 00,000,162 | -H– | C] () – D:\Documents\~$mmee tippee cup,library..doc
[2009/05/07 07:26:34 | 00,000,000 | -HSD | C] – C:\WINDOWS\System32\bookls
[2009/05/07 07:26:32 | 00,013,733 | —- | C] () – C:\WINDOWS\System32\ormh
[2009/05/06 07:50:34 | 14,897,3650 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\JohnB_Live_at_VirginClub_Pforzheim_14Feb2009.mp3
[2009/05/04 13:05:25 | 51,272,088 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\videoFileNo130122.mpg
[2009/05/04 13:01:22 | 04,820,424 | —- | C] () – C:\Documents and Settings\Andrew and Claire\Desktop\videoFileNo130122.flv
[2009/05/04 13:01:11 | 00,000,002 | -HS- | C] () – C:\Documents and Settings\Andrew and Claire\Application Data\evf
[2009/05/04 13:00:41 | 00,000,000 | —D | C] – C:\Program Files\ZillaTube
[2009/05/01 22:26:52 | 00,000,162 | -H– | C] () – D:\Documents\~$randad.doc
[2009/05/01 22:26:51 | 00,024,064 | —- | C] () – D:\Documents\grandad.doc
[2009/05/01 16:57:17 | 00,001,804 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/05/01 16:56:48 | 00,000,000 | —D | C] – C:\Program Files\iPod
[2009/05/01 16:56:45 | 00,000,000 | —D | C] – C:\Program Files\iTunes
[2009/05/01 16:56:45 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/04/27 18:20:41 | 00,035,328 | —- | C] () – D:\Documents\reviews 27th april.doc
[2009/04/27 18:20:41 | 00,000,162 | -H– | C] () – D:\Documents\~$views 27th april.doc
[2009/04/26 07:24:29 | 00,000,162 | -H– | C] () – D:\Documents\~$aires reviews 25th april.doc
[2009/04/25 18:40:06 | 00,027,648 | —- | C] () – D:\Documents\claires reviews 25th april.doc
[2009/04/25 14:46:25 | 03,763,349 | —- | C] () – D:\Documents\S8003138.JPG
[2009/04/25 14:46:20 | 03,489,540 | —- | C] () – D:\Documents\S8003137.JPG
[2009/04/25 14:46:15 | 03,623,748 | —- | C] () – D:\Documents\S8003136.JPG
[2009/04/25 14:46:08 | 03,687,965 | —- | C] () – D:\Documents\S8003135.JPG
[2009/04/25 14:46:02 | 03,623,254 | —- | C] () – D:\Documents\S8003134.JPG
[2009/04/25 10:53:40 | 00,000,162 | -H– | C] () – D:\Documents\~$views 25th april.doc
[2009/04/25 10:53:39 | 00,041,984 | —- | C] () – D:\Documents\reviews 25th april.doc
[2009/04/24 10:46:24 | 00,029,696 | —- | C] () – D:\Documents\I normally buy the very cheap Smartprice wipes from Asda but unfortunately I ran out last week.doc
[2009/04/24 10:46:24 | 00,000,162 | -H– | C] () – D:\Documents\~$normally buy the very cheap Smartprice wipes from Asda but unfortunately I ran out last week.doc
[2009/04/22 09:08:21 | 00,000,162 | -H– | C] () – D:\Documents\~$da codes.doc
[2009/04/21 20:16:59 | 00,024,064 | —- | C] () – D:\Documents\asda codes.doc
[2009/04/20 19:27:25 | 00,024,064 | —- | C] () – D:\Documents\money 20th April.doc
[2009/04/20 19:27:25 | 00,000,162 | -H– | C] () – D:\Documents\~$ney 20th April.doc
[2009/04/17 17:05:43 | 18,063,038 | —- | C] () – D:\Documents\S8003127.AVI
[2009/04/17 15:36:59 | 18,611,758 | —- | C] () – D:\Documents\S8003122.AVI
[2009/04/16 18:44:37 | 00,058,368 | —- | C] () – D:\Documents\reviews 16th april.doc
[2009/04/16 18:44:37 | 00,000,162 | -H– | C] () – D:\Documents\~$views 16th april.doc
[2009/04/15 21:07:28 | 00,000,162 | -H– | C] () – D:\Documents\~$proved food order.doc
[2009/04/15 21:07:27 | 00,045,056 | —- | C] () – D:\Documents\approved food order.doc
[2009/04/15 12:41:59 | 00,024,064 | —- | C] () – D:\Documents\money april 15th.doc
[2009/04/15 12:41:59 | 00,000,162 | -H– | C] () – D:\Documents\~$ney april 15th.doc
[2009/04/14 12:17:27 | 00,042,496 | —- | C] () – D:\Documents\top ten autobiographies.doc
[2009/04/14 12:17:27 | 00,000,162 | -H– | C] () – D:\Documents\~$p ten autobiographies.doc
[2009/04/13 20:27:14 | 00,035,840 | —- | C] () – D:\Documents\reviews 13th april.doc
[2009/04/13 20:27:14 | 00,000,162 | -H– | C] () – D:\Documents\~$views 13th april.doc
[2009/04/13 20:27:06 | 00,032,768 | —- | C] () – D:\Documents\reviews 9th april.doc
[2008/11/21 22:47:52 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/11/21 22:45:16 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/11/21 22:45:16 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/11/21 22:44:16 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/08/31 08:58:15 | 00,000,000 | —- | C] () – C:\WINDOWS\PhotoNow.INI
[2008/07/20 16:01:41 | 00,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/07/20 16:01:39 | 00,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/07/20 16:01:39 | 00,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/05/29 15:58:19 | 00,000,056 | —- | C] () – C:\WINDOWS\VideoConvert.INI
[2008/03/31 17:38:04 | 00,717,296 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2008/03/31 16:27:14 | 00,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2008/03/30 18:22:06 | 00,000,067 | —- | C] () – C:\WINDOWS\Easy Avi Divx Xvid to DVD Burner.INI
[2007/08/25 20:19:56 | 00,140,216 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2006/08/16 12:49:26 | 00,000,067 | —- | C] () – C:\WINDOWS\#1 DVD Ripper.INI
[2006/08/09 21:36:56 | 00,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2006/07/01 13:41:23 | 00,000,025 | —- | C] () – C:\WINDOWS\XCopyDVD.INI
[2006/02/07 18:51:31 | 00,006,850 | R— | C] () – C:\WINDOWS\Disktool.INI
[2006/02/07 18:51:31 | 00,003,677 | R— | C] () – C:\WINDOWS\PlaySnd.INI
[2006/02/07 18:51:29 | 00,005,628 | R— | C] () – C:\WINDOWS\fwupgrade.ini
[2005/11/07 13:52:16 | 00,000,241 | —- | C] () – C:\WINDOWS\QSync.INI
[2005/11/07 13:51:15 | 00,005,187 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2005/11/04 08:48:16 | 00,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/11/03 21:05:36 | 00,013,312 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2005/11/03 20:41:21 | 00,053,693 | R— | C] () – C:\WINDOWS\UNDPX2A.sys
[2005/11/03 20:41:21 | 00,015,429 | R— | C] ( ) – C:\WINDOWS\System32\drivers\Sacm2A.sys
[2005/11/03 11:17:58 | 00,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2005/11/03 11:13:10 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/03 11:05:42 | 00,761,856 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2005/11/03 11:05:42 | 00,421,888 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2005/11/03 11:05:42 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2005/11/03 11:05:39 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2005/11/03 10:54:21 | 00,394,240 | —- | C] () – C:\WINDOWS\System32\HMTCD.dll
[2005/11/03 10:54:21 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\ContextMenuExt.dll
[2005/11/03 10:54:21 | 00,009,728 | —- | C] () – C:\WINDOWS\System32\UnlockerCOM.dll
[2005/11/03 10:54:21 | 00,003,584 | —- | C] () – C:\WINDOWS\System32\UnlockerDriver4.sys
[2005/11/03 10:49:35 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005/11/03 10:49:35 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2005/11/03 10:49:35 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/11/03 10:49:34 | 01,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/11/03 10:35:21 | 00,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005/11/03 10:35:21 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2005/10/10 22:49:00 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2004/06/01 16:31:13 | 00,069,632 | —- | C] () – C:\WINDOWS\System32\akrip32.dll
[2003/11/13 15:28:02 | 00,012,570 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2003/11/13 15:28:02 | 00,012,570 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2003/01/07 16:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/12/31 13:00:00 | 00,000,603 | —- | C] () – C:\WINDOWS\win.ini
[2002/12/31 13:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[1999/01/27 14:39:06 | 00,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[97 D:\Documents\*.tmp files]
[2017/04/17 15:08:10 | 03,763,349 | —- | M] () – D:\Documents\S8003138.JPG
[2017/04/17 15:07:14 | 03,489,540 | —- | M] () – D:\Documents\S8003137.JPG
[2017/04/17 15:06:24 | 03,623,748 | —- | M] () – D:\Documents\S8003136.JPG
[2017/04/17 14:58:28 | 03,687,965 | —- | M] () – D:\Documents\S8003135.JPG
[2017/04/17 14:57:28 | 03,623,254 | —- | M] () – D:\Documents\S8003134.JPG
[2017/04/09 17:48:22 | 18,063,038 | —- | M] () – D:\Documents\S8003127.AVI
[2017/04/09 16:20:08 | 18,611,758 | —- | M] () – D:\Documents\S8003122.AVI
[2017/03/11 20:48:00 | 10,801,652 | —- | M] () – D:\Documents\S8003102.AVI
[2017/03/11 20:47:06 | 08,776,114 | —- | M] () – D:\Documents\S8003101.AVI
[2017/03/11 15:30:36 | 03,663,555 | —- | M] () – D:\Documents\S8003096.JPG
[2017/03/11 15:30:32 | 03,714,325 | —- | M] () – D:\Documents\S8003095.JPG
[2017/03/11 15:30:26 | 03,708,984 | —- | M] () – D:\Documents\S8003094.JPG
[2017/03/11 11:15:40 | 03,716,578 | —- | M] () – D:\Documents\S8003093.JPG
[2017/03/11 11:15:34 | 03,507,233 | —- | M] () – D:\Documents\S8003092.JPG
[2017/03/11 11:15:26 | 03,663,839 | —- | M] () – D:\Documents\S8003091.JPG
[2017/03/11 11:14:56 | 03,682,951 | —- | M] () – D:\Documents\S8003090.JPG
[2017/03/11 11:14:48 | 03,477,071 | —- | M] () – D:\Documents\S8003089.JPG
[2017/03/11 11:14:42 | 03,441,892 | —- | M] () – D:\Documents\S8003088.JPG
[2017/02/18 21:18:16 | 03,648,047 | —- | M] () – D:\Documents\S8003082.JPG
[2017/02/17 20:15:26 | 03,673,601 | —- | M] () – D:\Documents\S8003081.JPG
[2017/02/16 20:00:42 | 03,499,989 | —- | M] () – D:\Documents\S8003077.JPG
[2017/02/15 20:19:18 | 03,643,656 | —- | M] () – D:\Documents\S8003076.JPG
[2017/02/14 19:10:04 | 03,888,699 | —- | M] () – D:\Documents\S8003074.JPG
[2017/02/14 19:09:50 | 03,918,969 | —- | M] () – D:\Documents\S8003073.JPG
[2017/02/14 19:06:50 | 04,032,828 | —- | M] () – D:\Documents\S8003065.JPG
[2017/02/14 19:03:56 | 03,462,410 | —- | M] () – D:\Documents\S8003062.JPG
[2017/02/14 19:02:44 | 03,588,873 | —- | M] () – D:\Documents\S8003059.JPG
[2017/02/14 19:02:30 | 03,552,490 | —- | M] () – D:\Documents\S8003058.JPG
[2017/02/14 19:02:20 | 03,882,996 | —- | M] () – D:\Documents\S8003057.JPG
[2017/02/14 19:01:00 | 03,616,824 | —- | M] () – D:\Documents\S8003056.JPG
[2017/02/14 18:55:32 | 03,735,231 | —- | M] () – D:\Documents\S8003052.JPG
[2017/02/14 18:54:52 | 03,537,626 | —- | M] () – D:\Documents\S8003051.JPG
[2017/02/14 18:53:58 | 03,039,240 | —- | M] () – D:\Documents\S8003049.JPG
[2017/02/14 18:53:24 | 03,088,220 | —- | M] () – D:\Documents\S8003048.JPG
[2017/02/14 18:49:46 | 03,422,123 | —- | M] () – D:\Documents\S8003045.JPG
[2017/02/12 15:34:12 | 03,640,028 | —- | M] () – D:\Documents\S8003041.JPG
[2017/02/12 15:32:44 | 03,597,350 | —- | M] () – D:\Documents\S8003040.JPG
[2017/02/11 20:11:50 | 03,383,866 | —- | M] () – D:\Documents\S8003032.JPG
[2017/02/11 20:09:42 | 03,317,057 | —- | M] () – D:\Documents\S8003029.JPG
[2017/02/11 18:57:06 | 38,761,660 | —- | M] () – D:\Documents\S8003024.AVI
[2017/02/10 14:07:02 | 03,664,500 | —- | M] () – D:\Documents\S8003011.JPG
[2017/02/10 14:06:30 | 03,529,037 | —- | M] () – D:\Documents\S8003009.JPG
[2017/02/04 20:57:00 | 03,632,481 | —- | M] () – D:\Documents\S8003008.JPG
[2017/02/04 20:56:54 | 03,766,801 | —- | M] () – D:\Documents\S8003007.JPG
[2017/02/04 20:56:48 | 03,762,596 | —- | M] () – D:\Documents\S8003006.JPG
[2017/02/04 20:56:42 | 03,620,148 | —- | M] () – D:\Documents\S8003005.JPG
[2017/02/04 20:55:40 | 03,748,302 | —- | M] () – D:\Documents\S8003004.JPG
[2017/02/04 20:55:34 | 03,712,921 | —- | M] () – D:\Documents\S8003003.JPG
[2017/02/04 20:55:24 | 03,742,045 | —- | M] () – D:\Documents\S8003001.JPG
[2017/02/01 23:06:48 | 08,844,590 | —- | M] () – D:\Documents\S8002990.AVI
[2017/02/01 23:05:56 | 06,274,206 | —- | M] () – D:\Documents\S8002989.AVI
[2017/02/01 23:05:18 | 04,819,684 | —- | M] () – D:\Documents\S8002988.AVI
[2017/01/29 23:31:36 | 07,230,174 | —- | M] () – D:\Documents\S8002987.AVI
[2017/01/26 21:42:10 | 13,496,886 | —- | M] () – D:\Documents\S8002986.AVI
[2017/01/24 21:03:02 | 03,470,198 | —- | M] () – D:\Documents\S8002985.JPG
[2017/01/24 21:02:44 | 03,729,006 | —- | M] () – D:\Documents\S8002984.JPG
[2017/01/24 20:53:36 | 03,153,885 | —- | M] () – D:\Documents\S8002978.JPG
[2017/01/24 20:53:14 | 03,008,534 | —- | M] () – D:\Documents\S8002977.JPG
[2017/01/24 20:53:02 | 03,007,245 | —- | M] () – D:\Documents\S8002976.JPG
[2017/01/21 20:52:12 | 26,667,520 | —- | M] () – D:\Documents\S8002975.AVI
[2017/01/16 17:40:34 | 08,028,276 | —- | M] () – D:\Documents\S8002974.AVI
[2017/01/16 17:39:32 | 07,225,952 | —- | M] () – D:\Documents\S8002973.AVI
[2017/01/16 17:38:58 | 04,661,484 | —- | M] () – D:\Documents\S8002972.AVI
[2017/01/16 17:38:38 | 08,134,334 | —- | M] () – D:\Documents\S8002971.AVI
[2017/01/16 17:37:24 | 11,613,468 | —- | M] () – D:\Documents\S8002970.AVI
[2017/01/16 17:36:36 | 08,788,884 | —- | M] () – D:\Documents\S8002969.AVI
[2017/01/14 21:40:10 | 03,476,086 | —- | M] () – D:\Documents\S8002968.JPG
[2017/01/05 21:09:30 | 09,276,668 | —- | M] () – D:\Documents\S8002967.AVI
[2017/01/05 21:08:48 | 01,807,018 | —- | M] () – D:\Documents\S8002966.AVI
[2017/01/04 16:04:32 | 03,926,859 | —- | M] () – D:\Documents\S8002965.JPG
[2017/01/04 16:04:18 | 04,038,331 | —- | M] () – D:\Documents\S8002964.JPG
[2017/01/04 16:04:04 | 02,478,024 | —- | M] () – D:\Documents\S8002963.JPG
[2017/01/04 16:03:56 | 03,966,993 | —- | M] () – D:\Documents\S8002962.JPG
[2016/12/30 16:08:32 | 02,580,421 | —- | M] () – D:\Documents\S8002961.JPG
[2016/12/30 16:07:40 | 03,453,957 | —- | M] () – D:\Documents\S8002959.JPG
[2016/12/30 16:04:20 | 03,662,601 | —- | M] () – D:\Documents\S8002958.JPG
[2016/12/23 19:14:18 | 02,941,982 | —- | M] () – D:\Documents\S8002948.AVI
[2016/12/18 17:45:20 | 00,119,898 | —- | M] () – D:\Documents\S8002912.WAV
[2016/12/17 13:48:02 | 05,443,604 | —- | M] () – D:\Documents\S8002889.AVI
[2016/12/17 10:58:56 | 09,478,544 | —- | M] () – D:\Documents\S8002884.AVI
[2016/12/16 19:32:44 | 01,092,660 | —- | M] () – D:\Documents\S8002865.AVI
[2016/12/11 19:51:28 | 43,629,660 | —- | M] () – D:\Documents\S8002864.AVI
[2016/12/11 19:46:28 | 08,036,124 | —- | M] () – D:\Documents\S8002863.AVI
[2016/12/10 19:52:34 | 39,698,312 | —- | M] () – D:\Documents\S8002858.AVI
[2016/11/28 21:12:44 | 14,290,272 | —- | M] () – D:\Documents\S8002844.AVI
[2016/10/28 21:16:44 | 19,383,516 | —- | M] () – D:\Documents\S8002696.AVI
[2016/10/23 20:46:56 | 27,106,884 | —- | M] () – D:\Documents\S8002685.AVI
[2016/10/11 10:31:56 | 03,517,939 | —- | M] () – D:\Documents\S8002572.JPG
[2016/10/05 16:38:46 | 03,414,466 | —- | M] () – D:\Documents\S8002485.JPG
[2016/10/05 13:11:08 | 03,685,773 | —- | M] () – D:\Documents\S8002470.JPG
[2016/09/25 19:55:46 | 15,029,548 | —- | M] () – D:\Documents\S8002333.AVI
[2016/09/25 19:54:32 | 08,406,098 | —- | M] () – D:\Documents\S8002332.AVI
[2016/09/25 19:53:44 | 06,681,860 | —- | M] () – D:\Documents\S8002331.AVI
[2016/09/25 19:53:10 | 21,426,506 | —- | M] () – D:\Documents\S8002330.AVI
[2016/09/25 19:46:04 | 05,985,844 | —- | M] () – D:\Documents\S8002329.AVI
[2016/09/25 19:36:44 | 16,101,660 | —- | M] () – D:\Documents\S8002328.AVI
[2016/09/25 19:17:26 | 04,384,882 | —- | M] () – D:\Documents\S8002325.AVI
[2009/05/12 18:04:46 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/12 18:03:04 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/05/12 18:00:28 | 03,021,140 | R— | M] () – C:\Documents and Settings\Andrew and Claire\Desktop\ComboFix.exe
[2009/05/12 17:42:00 | 00,000,278 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2009/05/12 17:38:25 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/05/12 17:10:12 | 00,000,366 | —- | M] () – C:\WINDOWS\tasks\Symantec NetDetect.job
[2009/05/12 15:54:53 | 00,024,576 | —- | M] () – D:\Documents\Little stars yogurt.doc
[2009/05/12 15:54:53 | 00,000,162 | -H– | M] () – D:\Documents\~$ttle stars yogurt.doc
[2009/05/11 22:27:13 | 00,000,433 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2009/05/11 22:24:07 | 00,039,568 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/05/11 22:23:57 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/05/11 22:23:50 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Andrew and Claire\Local Settings\desktop.ini
[2009/05/11 22:23:46 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/11 22:23:41 | 00,566,868 | —- | M] () – C:\WINDOWS\System32\OODBS.lor
[2009/05/11 22:20:17 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/05/11 22:10:50 | 00,000,040 | —- | M] () – C:\WINDOWS\System32\profile.dat
[2009/05/11 22:04:19 | 00,034,816 | —- | M] () – D:\Documents\andrew reviews.doc
[2009/05/11 18:38:42 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Andrew and Claire\Desktop\OTListIt2.exe
[2009/05/11 18:36:04 | 00,267,612 | —- | M] () – C:\Documents and Settings\Andrew and Claire\Desktop\Rooter.exe
[2009/05/11 17:18:57 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/05/10 20:12:17 | 00,000,151 | —- | M] () – C:\WINDOWS\PhotoSnapViewer.INI
[2009/05/09 18:25:42 | 00,000,839 | —- | M] () – D:\Documents\My Sharing Folders.lnk
[2009/05/09 12:25:53 | 00,000,706 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/09 12:24:44 | 02,967,800 | —- | M] (Malwarebytes Corporation ) – D:\Documents\mbam-setup.exe
[2009/05/09 12:09:12 | 00,001,744 | —- | M] () – C:\Documents and Settings\Andrew and Claire\Desktop\HijackThis.lnk
[2009/05/09 12:09:02 | 00,812,344 | —- | M] (Trend Micro Inc.) – D:\Documents\HJTInstall.exe
[2009/05/09 12:00:10 | 09,924,040 | —- | M] (Microsoft Corporation) – D:\Documents\windows-kb890830-v2.9.exe
[2009/05/09 11:53:41 | 00,025,088 | —- | M] () – D:\Documents\andrews new reviews 9th may.doc
[2009/05/09 08:56:43 | 00,026,112 | —- | M] () – D:\Documents\Mummy do you love me.doc
[2009/05/08 12:05:12 | 00,030,720 | —- | M] () – D:\Documents\Tommee tippee cup,library..doc
[2009/05/08 11:33:49 | 00,000,162 | -H– | M] () – D:\Documents\~$mmee tippee cup,library..doc
[2009/05/07 07:26:32 | 00,013,733 | —- | M] () – C:\WINDOWS\System32\ormh
[2009/05/05 07:58:28 | 00,002,228 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/05/05 07:40:14 | 23,672,585 | —- | M] () – D:\Documents\falling epik killah mix.mp3
[2009/05/04 13:04:45 | 51,272,088 | —- | M] () – C:\Documents and Settings\Andrew and Claire\Desktop\videoFileNo130122.mpg
[2009/05/04 13:03:37 | 04,820,424 | —- | M] () – C:\Documents and Settings\Andrew and Claire\Desktop\videoFileNo130122.flv
[2009/05/04 13:01:11 | 00,000,002 | -HS- | M] () – C:\Documents and Settings\Andrew and Claire\Application Data\evf
[2009/05/01 22:26:52 | 00,000,162 | -H– | M] () – D:\Documents\~$randad.doc
[2009/05/01 22:26:51 | 00,024,064 | —- | M] () – D:\Documents\grandad.doc
[2009/05/01 16:57:17 | 00,001,804 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/05/01 15:36:46 | 00,117,248 | —- | M] () – C:\WINDOWS\vFind.exe
[2009/04/30 12:21:18 | 00,027,648 | —- | M] () – D:\Documents\claires reviews 25th april.doc
[2009/04/27 18:20:41 | 00,035,328 | —- | M] () – D:\Documents\reviews 27th april.doc
[2009/04/27 18:20:41 | 00,000,162 | -H– | M] () – D:\Documents\~$views 27th april.doc
[2009/04/26 10:54:20 | 00,041,984 | —- | M] () – D:\Documents\reviews 25th april.doc
[2009/04/26 07:24:29 | 00,000,162 | -H– | M] () – D:\Documents\~$aires reviews 25th april.doc
[2009/04/25 10:53:40 | 00,000,162 | -H– | M] () – D:\Documents\~$views 25th april.doc
[2009/04/24 10:46:24 | 00,029,696 | —- | M] () – D:\Documents\I normally buy the very cheap Smartprice wipes from Asda but unfortunately I ran out last week.doc
[2009/04/24 10:46:24 | 00,000,162 | -H– | M] () – D:\Documents\~$normally buy the very cheap Smartprice wipes from Asda but unfortunately I ran out last week.doc
[2009/04/22 09:08:21 | 00,000,162 | -H– | M] () – D:\Documents\~$da codes.doc
[2009/04/21 20:17:00 | 00,024,064 | —- | M] () – D:\Documents\asda codes.doc
[2009/04/20 19:32:16 | 00,058,368 | —- | M] () – D:\Documents\reviews 16th april.doc
[2009/04/20 19:27:25 | 00,024,064 | —- | M] () – D:\Documents\money 20th April.doc
[2009/04/20 19:27:25 | 00,000,162 | -H– | M] () – D:\Documents\~$ney 20th April.doc
[2009/04/20 12:56:28 | 00,031,232 | —- | M] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/04/16 18:44:37 | 00,000,162 | -H– | M] () – D:\Documents\~$views 16th april.doc
[2009/04/15 21:07:28 | 00,000,162 | -H– | M] () – D:\Documents\~$proved food order.doc
[2009/04/15 21:07:27 | 00,045,056 | —- | M] () – D:\Documents\approved food order.doc
[2009/04/15 12:42:24 | 00,024,064 | —- | M] () – D:\Documents\money april 15th.doc
[2009/04/15 12:41:59 | 00,000,162 | -H– | M] () – D:\Documents\~$ney april 15th.doc
[2009/04/14 12:47:47 | 00,042,496 | —- | M] () – D:\Documents\top ten autobiographies.doc
[2009/04/14 12:43:39 | 00,035,840 | —- | M] () – D:\Documents\reviews 13th april.doc
[2009/04/14 12:17:27 | 00,000,162 | -H– | M] () – D:\Documents\~$p ten autobiographies.doc
[2009/04/13 20:27:14 | 00,000,162 | -H– | M] () – D:\Documents\~$views 13th april.doc
[2009/04/13 20:27:06 | 00,032,768 | —- | M] () – D:\Documents\reviews 9th april.doc
< End of report >



In terms of how the PC is running, it's running great THANKS! Just one question; I seem to make myself vulnerable to malware from downloading torrents. Is there a way of checking torrents before downloading to make sure they aren't infected?

Thanks again,

Andrew
There is one thing I would like to check as you have some suspect files here which I did not notice at first. There are these AVI's do you recognise them as they were made in eight years time (date is 2017 ? ) if not I will kill them plus one other. If you did make them then let me know and I will reconfigure the fix, otherwise run this fix

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    c:\documents and settings\Andrew and Claire\.exe
    [2017/04/17 15:08:10 | 03,763,349 | —- | M] () – D:\Documents\S8003138.JPG
    [2017/04/17 15:07:14 | 03,489,540 | —- | M] () – D:\Documents\S8003137.JPG
    [2017/04/17 15:06:24 | 03,623,748 | —- | M] () – D:\Documents\S8003136.JPG
    [2017/04/17 14:58:28 | 03,687,965 | —- | M] () – D:\Documents\S8003135.JPG
    [2017/04/17 14:57:28 | 03,623,254 | —- | M] () – D:\Documents\S8003134.JPG
    [2017/04/09 17:48:22 | 18,063,038 | —- | M] () – D:\Documents\S8003127.AVI
    [2017/04/09 16:20:08 | 18,611,758 | —- | M] () – D:\Documents\S8003122.AVI
    [2017/03/11 20:48:00 | 10,801,652 | —- | M] () – D:\Documents\S8003102.AVI
    [2017/03/11 20:47:06 | 08,776,114 | —- | M] () – D:\Documents\S8003101.AVI
    [2017/03/11 15:30:36 | 03,663,555 | —- | M] () – D:\Documents\S8003096.JPG
    [2017/03/11 15:30:32 | 03,714,325 | —- | M] () – D:\Documents\S8003095.JPG
    [2017/03/11 15:30:26 | 03,708,984 | —- | M] () – D:\Documents\S8003094.JPG
    [2017/03/11 11:15:40 | 03,716,578 | —- | M] () – D:\Documents\S8003093.JPG
    [2017/03/11 11:15:34 | 03,507,233 | —- | M] () – D:\Documents\S8003092.JPG
    [2017/03/11 11:15:26 | 03,663,839 | —- | M] () – D:\Documents\S8003091.JPG
    [2017/03/11 11:14:56 | 03,682,951 | —- | M] () – D:\Documents\S8003090.JPG
    [2017/03/11 11:14:48 | 03,477,071 | —- | M] () – D:\Documents\S8003089.JPG
    [2017/03/11 11:14:42 | 03,441,892 | —- | M] () – D:\Documents\S8003088.JPG
    [2017/02/18 21:18:16 | 03,648,047 | —- | M] () – D:\Documents\S8003082.JPG
    [2017/02/17 20:15:26 | 03,673,601 | —- | M] () – D:\Documents\S8003081.JPG
    [2017/02/16 20:00:42 | 03,499,989 | —- | M] () – D:\Documents\S8003077.JPG
    [2017/02/15 20:19:18 | 03,643,656 | —- | M] () – D:\Documents\S8003076.JPG
    [2017/02/14 19:10:04 | 03,888,699 | —- | M] () – D:\Documents\S8003074.JPG
    [2017/02/14 19:09:50 | 03,918,969 | —- | M] () – D:\Documents\S8003073.JPG
    [2017/02/14 19:06:50 | 04,032,828 | —- | M] () – D:\Documents\S8003065.JPG
    [2017/02/14 19:03:56 | 03,462,410 | —- | M] () – D:\Documents\S8003062.JPG
    [2017/02/14 19:02:44 | 03,588,873 | —- | M] () – D:\Documents\S8003059.JPG
    [2017/02/14 19:02:30 | 03,552,490 | —- | M] () – D:\Documents\S8003058.JPG
    [2017/02/14 19:02:20 | 03,882,996 | —- | M] () – D:\Documents\S8003057.JPG
    [2017/02/14 19:01:00 | 03,616,824 | —- | M] () – D:\Documents\S8003056.JPG
    [2017/02/14 18:55:32 | 03,735,231 | —- | M] () – D:\Documents\S8003052.JPG
    [2017/02/14 18:54:52 | 03,537,626 | —- | M] () – D:\Documents\S8003051.JPG
    [2017/02/14 18:53:58 | 03,039,240 | —- | M] () – D:\Documents\S8003049.JPG
    [2017/02/14 18:53:24 | 03,088,220 | —- | M] () – D:\Documents\S8003048.JPG
    [2017/02/14 18:49:46 | 03,422,123 | —- | M] () – D:\Documents\S8003045.JPG
    [2017/02/12 15:34:12 | 03,640,028 | —- | M] () – D:\Documents\S8003041.JPG
    [2017/02/12 15:32:44 | 03,597,350 | —- | M] () – D:\Documents\S8003040.JPG
    [2017/02/11 20:11:50 | 03,383,866 | —- | M] () – D:\Documents\S8003032.JPG
    [2017/02/11 20:09:42 | 03,317,057 | —- | M] () – D:\Documents\S8003029.JPG
    [2017/02/11 18:57:06 | 38,761,660 | —- | M] () – D:\Documents\S8003024.AVI
    [2017/02/10 14:07:02 | 03,664,500 | —- | M] () – D:\Documents\S8003011.JPG
    [2017/02/10 14:06:30 | 03,529,037 | —- | M] () – D:\Documents\S8003009.JPG
    [2017/02/04 20:57:00 | 03,632,481 | —- | M] () – D:\Documents\S8003008.JPG
    [2017/02/04 20:56:54 | 03,766,801 | —- | M] () – D:\Documents\S8003007.JPG
    [2017/02/04 20:56:48 | 03,762,596 | —- | M] () – D:\Documents\S8003006.JPG
    [2017/02/04 20:56:42 | 03,620,148 | —- | M] () – D:\Documents\S8003005.JPG
    [2017/02/04 20:55:40 | 03,748,302 | —- | M] () – D:\Documents\S8003004.JPG
    [2017/02/04 20:55:34 | 03,712,921 | —- | M] () – D:\Documents\S8003003.JPG
    [2017/02/04 20:55:24 | 03,742,045 | —- | M] () – D:\Documents\S8003001.JPG
    [2017/02/01 23:06:48 | 08,844,590 | —- | M] () – D:\Documents\S8002990.AVI
    [2017/02/01 23:05:56 | 06,274,206 | —- | M] () – D:\Documents\S8002989.AVI
    [2017/02/01 23:05:18 | 04,819,684 | —- | M] () – D:\Documents\S8002988.AVI
    [2017/01/29 23:31:36 | 07,230,174 | —- | M] () – D:\Documents\S8002987.AVI
    [2017/01/26 21:42:10 | 13,496,886 | —- | M] () – D:\Documents\S8002986.AVI
    [2017/01/24 21:03:02 | 03,470,198 | —- | M] () – D:\Documents\S8002985.JPG
    [2017/01/24 21:02:44 | 03,729,006 | —- | M] () – D:\Documents\S8002984.JPG
    [2017/01/24 20:53:36 | 03,153,885 | —- | M] () – D:\Documents\S8002978.JPG
    [2017/01/24 20:53:14 | 03,008,534 | —- | M] () – D:\Documents\S8002977.JPG
    [2017/01/24 20:53:02 | 03,007,245 | —- | M] () – D:\Documents\S8002976.JPG
    [2017/01/21 20:52:12 | 26,667,520 | —- | M] () – D:\Documents\S8002975.AVI
    [2017/01/16 17:40:34 | 08,028,276 | —- | M] () – D:\Documents\S8002974.AVI
    [2017/01/16 17:39:32 | 07,225,952 | —- | M] () – D:\Documents\S8002973.AVI
    [2017/01/16 17:38:58 | 04,661,484 | —- | M] () – D:\Documents\S8002972.AVI
    [2017/01/16 17:38:38 | 08,134,334 | —- | M] () – D:\Documents\S8002971.AVI
    [2017/01/16 17:37:24 | 11,613,468 | —- | M] () – D:\Documents\S8002970.AVI
    [2017/01/16 17:36:36 | 08,788,884 | —- | M] () – D:\Documents\S8002969.AVI
    [2017/01/14 21:40:10 | 03,476,086 | —- | M] () – D:\Documents\S8002968.JPG
    [2017/01/05 21:09:30 | 09,276,668 | —- | M] () – D:\Documents\S8002967.AVI
    [2017/01/05 21:08:48 | 01,807,018 | —- | M] () – D:\Documents\S8002966.AVI
    [2017/01/04 16:04:32 | 03,926,859 | —- | M] () – D:\Documents\S8002965.JPG
    [2017/01/04 16:04:18 | 04,038,331 | —- | M] () – D:\Documents\S8002964.JPG
    [2017/01/04 16:04:04 | 02,478,024 | —- | M] () – D:\Documents\S8002963.JPG
    [2017/01/04 16:03:56 | 03,966,993 | —- | M] () – D:\Documents\S8002962.JPG
    [2016/12/30 16:08:32 | 02,580,421 | —- | M] () – D:\Documents\S8002961.JPG
    [2016/12/30 16:07:40 | 03,453,957 | —- | M] () – D:\Documents\S8002959.JPG
    [2016/12/30 16:04:20 | 03,662,601 | —- | M] () – D:\Documents\S8002958.JPG
    [2016/12/23 19:14:18 | 02,941,982 | —- | M] () – D:\Documents\S8002948.AVI
    [2016/12/18 17:45:20 | 00,119,898 | —- | M] () – D:\Documents\S8002912.WAV
    [2016/12/17 13:48:02 | 05,443,604 | —- | M] () – D:\Documents\S8002889.AVI
    [2016/12/17 10:58:56 | 09,478,544 | —- | M] () – D:\Documents\S8002884.AVI
    [2016/12/16 19:32:44 | 01,092,660 | —- | M] () – D:\Documents\S8002865.AVI
    [2016/12/11 19:51:28 | 43,629,660 | —- | M] () – D:\Documents\S8002864.AVI
    [2016/12/11 19:46:28 | 08,036,124 | —- | M] () – D:\Documents\S8002863.AVI
    [2016/12/10 19:52:34 | 39,698,312 | —- | M] () – D:\Documents\S8002858.AVI
    [2016/11/28 21:12:44 | 14,290,272 | —- | M] () – D:\Documents\S8002844.AVI
    [2016/10/28 21:16:44 | 19,383,516 | —- | M] () – D:\Documents\S8002696.AVI
    [2016/10/23 20:46:56 | 27,106,884 | —- | M] () – D:\Documents\S8002685.AVI
    [2016/10/11 10:31:56 | 03,517,939 | —- | M] () – D:\Documents\S8002572.JPG
    [2016/10/05 16:38:46 | 03,414,466 | —- | M] () – D:\Documents\S8002485.JPG
    [2016/10/05 13:11:08 | 03,685,773 | —- | M] () – D:\Documents\S8002470.JPG
    [2016/09/25 19:55:46 | 15,029,548 | —- | M] () – D:\Documents\S8002333.AVI
    [2016/09/25 19:54:32 | 08,406,098 | —- | M] () – D:\Documents\S8002332.AVI
    [2016/09/25 19:53:44 | 06,681,860 | —- | M] () – D:\Documents\S8002331.AVI
    [2016/09/25 19:53:10 | 21,426,506 | —- | M] () – D:\Documents\S8002330.AVI
    [2016/09/25 19:46:04 | 05,985,844 | —- | M] () – D:\Documents\S8002329.AVI
    [2016/09/25 19:36:44 | 16,101,660 | —- | M] () – D:\Documents\S8002328.AVI
    [2016/09/25 19:17:26 | 04,384,882 | —- | M] () – D:\Documents\S8002325.AVI
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
Yes those are my files (not sure why the date is wrong), but I checked them and they're recent photos and video clips I've made (maybe date set wrong on my PC?) Anything else or am I all good now? Thanks Andrew
Ta for that - no there is one more file to kill and then you should be good to go. Tell you what I shall put it all in one :)

FIX

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :Files
    c:\documents and settings\Andrew and Claire\.exe
    
    :Commands
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done

ONCE DONE

Now the best part of the day —– Your log now appears clean :thumbup:

A good workman always cleans up after himself so..Run OTListit and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 13.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u13-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u13-windows-i586-p.exe and select "Run as an Administrator.")

XP
Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SuperAntispyware Run weekly to keep your system clean
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wavey:
thanks so much - sending some cash now as a small token of my appreciation. I may well send some more asap too! I really do appreciate the help.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI