Here is the mbam log
Malwarebytes' Anti-Malware 1.38
Database version: 2355
Windows 5.1.2600 Service Pack 3
6/30/2009 9:59:48 AM
mbam-log-2009-06-30 (09-59-48).txt
Scan type: Quick Scan
Objects scanned: 116808
Time elapsed: 12 minute(s), 25 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Here is the OTL log
OTL logfile created on: 6/30/2009 10:14:07 AM - Run 1
OTL by OldTimer - Version 3.0.5.3 Folder = C:\A Files\computer fix
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.49 Mb Total Physical Memory | 527.69 Mb Available Physical Memory | 51.56% Memory free
1.65 Gb Paging File | 1.35 Gb Available in Paging File | 81.71% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 34.43 Gb Free Space | 46.20% Space Free | Partition Type: NTFS
Drive D: | 501.61 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
Drive F: | 149.05 Gb Total Space | 134.98 Gb Free Space | 90.56% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
Drive H: | 111.79 Gb Total Space | 18.27 Gb Free Space | 16.34% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
Drive M: | 232.88 Gb Total Space | 34.63 Gb Free Space | 14.87% Space Free | Partition Type: NTFS
Computer Name: COREL
Current User Name: Test
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe (CANON INC.)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
PRC - C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe (CANON INC.)
PRC - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe (CANON INC.)
PRC - C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Brownie\BrstsWnd.exe (brother)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
PRC - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Brownie\brpjp04a.exe (brother)
PRC - C:\Program Files\Secunia\PSI\psi.exe (Secunia)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\A Files\computer fix\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (AcrSch2Svc [Auto | Running]) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Net Driver HPZ12 [Auto | Running]) – C:\WINDOWS\System32\HPZinw12.dll (Hewlett-Packard)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (PDUiP6000DMemCrdMgr [Auto | Running]) – C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe (CANON INC.)
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\WINDOWS\System32\HPZipm12.dll (Hewlett-Packard)
SRV - (SBAMSvc [Auto | Running]) – C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (ALCXSENS [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ALCXSENS.SYS (Sensaura Ltd)
DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Avance Logic, Inc.)
DRV - (ASPI32 [Auto | Running]) – C:\WINDOWS\System32\drivers\Aspi32.sys (Adaptec)
DRV - (CorexCardScan [System | Stopped]) – C:\WINDOWS\System32\drivers\slcorex.sys (CYPRESS Corporation)
DRV - (DgiVecp [Auto | Running]) – C:\WINDOWS\System32\Drivers\DgiVecp.sys (DeviceGuys, Inc.)
DRV - (FETND5BV [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys (VIA Technologies, Inc. )
DRV - (FETNDIS [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. )
DRV - (FileDisk [System | Running]) – C:\WINDOWS\System32\drivers\FILEDISK.SYS (iolo technologies, LLC (based on original work by Bo Brantén))
DRV - (G400 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\G400m.sys (Matrox Graphics Inc.)
DRV - (HCF_MSFT [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HCF_MSFT.sys (Conexant)
DRV - (HidBatt [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (HPZid412 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (IFP800 [Boot | Running]) – C:\WINDOWS\system32\drivers\ifp800.sys (iRiver, Inc.)
DRV - (MASPINT [Auto | Running]) – C:\WINDOWS\System32\drivers\MASPINT.SYS (MicroStaff Co.,Ltd.)
DRV - (NtApm [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\NtApm.sys (Microsoft Corporation)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (OlCamudp [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\olcamudp.sys (OLYMPUS Optical Co.,Ltd.)
DRV - (PAR1284 [Auto | Running]) – C:\WINDOWS\System32\Drivers\PAR1284.SYS (Warp Nine Engineering)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (PPNT [Auto | Running]) – C:\WINDOWS\System32\Drivers\PPNT.SYS (Corex Technologies Corp.)
DRV - (PSI [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\psi_mf.sys (Secunia)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (sbaphd [System | Running]) – C:\WINDOWS\System32\drivers\sbaphd.sys (Sunbelt Software)
DRV - (sbapifs [Auto | Running]) – C:\WINDOWS\System32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (SBRE [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\SBREdrv.sys (Sunbelt Software)
DRV - (sbtis [System | Running]) – C:\WINDOWS\System32\drivers\sbtis.sys (Sunbelt Software)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Sentinel [Auto | Running]) – C:\WINDOWS\System32\Drivers\SENTINEL.SYS ()
DRV - (snapman [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (Sparrow [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (TechStyler [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\oyots.sys ()
DRV - (tifsfilter [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\tifsfilt.sys (Acronis)
DRV - (timounter [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (TPkd [Boot | Running]) – C:\WINDOWS\System32\drivers\TPkd.sys (PACE Anti-Piracy, Inc.)
DRV - (UDNT [Auto | Stopped]) – C:\WINDOWS\System32\drivers\UDNT.SYS ()
DRV - (WINFLASH [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\WINFLASH.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://login.yahoo.com/config/login_verify…=us&.src=ym
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/05/25 13:33:50 | 00,000,000 | —D | M]
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe (brother)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PDUiP6000DMon] C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMon.exe (CANON INC.)
O4 - HKLM..\Run: [PDUiP6000DTskbr] C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DTskbr.exe (CANON INC.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [Samsung Common SM] C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe File not found
O4 - HKLM..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Pro\Components\QBAgent\qbdagent2002.exe ()
O4 - Startup: C:\Documents and Settings\Test\Start Menu\Programs\Startup\Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe (Secunia)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab (System Requirements Lab Class)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab (HouseCall Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
http://v4.windowsupdate.microsoft.com/CAB/…39014.342025463 (Reg Error: Key error.)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389}
http://bin.mcafee.com/molbin/shared/mcgdmg…,16/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Registry Information Class)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE}
http://officeupdate.microsoft.com/Template…nloads/outc.cab (Microsoft Office Tools on the Web Control)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\SYSTEM\dajava.cab (Reg Error: Key error.)
O16 - DPF: Internet Explorer Classes for Java file://C:\WINDOWS\SYSTEM\iejava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 192.168.1.1 [removed] [removed]
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\ole db\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\ole db\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\ole db\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\ole db\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\ole db\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\ole db\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\ole db\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2000/02/02 10:12:56 | 00,000,249 | -HS- | M] () - C:\AUTOEXEC.BAK – [ NTFS ]
O32 - AutoRun File - [2002/07/03 14:03:00 | 00,000,149 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [1999/06/25 16:28:38 | 00,000,437 | -HS- | M] () - C:\AUTOEXEC.DOS – [ NTFS ]
O32 - AutoRun File - [2000/10/10 16:55:58 | 00,000,134 | -HS- | M] () - C:\AUTOEXEC.OLD – [ NTFS ]
O32 - AutoRun File - [1999/11/24 15:28:32 | 00,000,531 | —- | M] () - C:\AUTOEXEC.SYD – [ NTFS ]
O32 - AutoRun File - [1999/06/25 16:43:02 | 00,000,437 | —- | M] () - C:\AUTOEXEC.VIA – [ NTFS ]
O32 - AutoRun File - [2008/04/25 09:42:47 | 00,000,045 | R— | M] () - D:\Autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
========== Files/Folders - Created Within 30 Days ==========
[2009/06/30 09:30:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/06/25 11:09:26 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/06/25 11:09:14 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Test\Desktop\HJTInstall.exe
[2009/06/22 17:35:40 | 00,001,613 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/06/22 15:34:46 | 00,000,778 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TweakNow RegCleaner.lnk
[2009/06/22 15:34:32 | 00,000,000 | —D | C] – C:\Program Files\TweakNow RegCleaner
[2009/06/22 15:34:32 | 00,000,000 | —D | C] – C:\Documents and Settings\Test\Application Data\TweakNow RegCleaner
[2009/06/17 16:56:10 | 00,236,544 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\Carfsw20.dll
[2009/06/17 16:56:10 | 00,230,400 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\Carclw60.dll
[2009/06/17 16:56:08 | 01,706,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\gdiplus.dll
[2009/06/17 16:56:08 | 00,274,432 | —- | C] () – C:\WINDOWS\System32\Carcla40.dll
[2009/06/17 16:56:08 | 00,069,632 | —- | C] (The Software Company, Inc.) – C:\WINDOWS\System32\ActiveAddress.dll
[2009/06/17 16:56:08 | 00,053,035 | —- | C] () – C:\WINDOWS\System32\ActiveAddress.ref
[2009/06/17 16:56:07 | 01,318,912 | —- | C] (Chilkat Software, Inc.) – C:\WINDOWS\System32\ChilkatXml.dll
[2009/06/17 16:56:07 | 00,733,184 | —- | C] (Chilkat Software, Inc.) – C:\WINDOWS\System32\ChilkatUtil.dll
[2009/06/17 16:56:07 | 00,607,528 | —- | C] (DL Technology Ltd) – C:\WINDOWS\System32\axbarcode.ocx
[2009/06/17 16:56:06 | 01,236,992 | —- | C] (Chilkat Software, Inc.) – C:\WINDOWS\System32\ChilkatHttp.dll
[2009/06/17 16:56:06 | 00,978,944 | —- | C] (Chilkat Software, Inc.) – C:\WINDOWS\System32\ChilkatCert.dll
[2009/06/17 16:56:05 | 01,155,072 | —- | C] (Chilkat Software, Inc.) – C:\WINDOWS\System32\ChilkatCrypt2.dll
[2009/06/17 16:56:05 | 00,774,144 | —- | C] (Chilkat Software, Inc.) – C:\WINDOWS\System32\HtmlToXml.dll
[2009/06/17 16:56:05 | 00,573,440 | —- | C] (Chilkat Software, Inc.) – C:\WINDOWS\System32\CkString.dll
[2009/06/17 16:44:32 | 00,002,489 | —- | C] () – C:\Documents and Settings\Test\Desktop\FastManager.lnk
[2009/06/17 16:44:21 | 00,000,000 | —D | C] – C:\Program Files\Common Files\fast register
[2009/06/17 13:46:24 | 00,069,936 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbapifs.sys
[2009/06/17 13:45:01 | 00,013,360 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbaphd.sys
[2009/06/10 06:00:54 | 00,068,392 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\sbbd.exe
[2009/06/03 08:32:04 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\compbatt.sys
[2009/06/03 08:32:04 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\compbatt.sys
[2009/06/03 08:32:00 | 00,020,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidbatt.sys
[2009/06/03 08:32:00 | 00,020,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidbatt.sys
[2009/06/03 08:32:00 | 00,014,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\battc.sys
[2009/06/03 08:32:00 | 00,014,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\battc.sys
[2009/06/01 14:30:31 | 00,001,738 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2009/06/01 14:16:41 | 00,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2009/06/01 14:16:41 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2009/06/01 14:02:36 | 00,000,000 | —D | C] – C:\OpenOffice.org 2.4 (en-US) Installation Files
[2009/06/01 13:24:58 | 00,000,729 | —- | C] () – C:\Documents and Settings\Test\Start Menu\Programs\Startup\Secunia PSI.lnk
[2009/06/01 13:22:55 | 00,000,000 | —D | C] – C:\Program Files\Secunia
[2009/01/22 13:33:41 | 00,000,145 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2009/01/22 13:33:41 | 00,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2009/01/22 13:33:20 | 00,000,114 | —- | C] () – C:\WINDOWS\System32\brlmw03a.ini
[2009/01/22 13:33:19 | 00,009,853 | —- | C] () – C:\WINDOWS\HL-2140.INI
[2009/01/22 13:33:13 | 00,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/01/22 13:31:53 | 00,000,331 | —- | C] () – C:\WINDOWS\Brownie.ini
[2008/01/18 16:53:55 | 00,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2007/09/10 14:21:29 | 00,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/10/22 12:22:00 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/10/22 12:22:00 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/10/22 12:22:00 | 00,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/10/22 12:22:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/10/22 12:22:00 | 00,212,992 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/05/15 12:34:33 | 00,002,568 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2005/10/19 17:52:58 | 00,000,281 | —- | C] () – C:\WINDOWS\System32\Trbininterface.ini
[2005/10/19 17:52:58 | 00,000,281 | —- | C] () – C:\WINDOWS\System32\bininterface.ini
[2004/12/27 07:23:32 | 00,003,266 | R— | C] () – C:\WINDOWS\System32\drivers\WinFlash.sys
[2004/12/09 12:42:55 | 00,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2004/12/09 12:25:38 | 00,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS69.DLL
[2004/10/04 11:53:42 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/09/24 16:41:58 | 00,007,296 | —- | C] () – C:\WINDOWS\System32\drivers\oyots.sys
[2004/09/17 18:37:42 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2004/06/17 14:02:07 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[2004/05/04 14:09:22 | 00,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2004/05/04 14:09:22 | 00,000,823 | —- | C] () – C:\WINDOWS\TSC.INI
[2004/05/04 14:08:35 | 00,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2004/05/03 17:19:11 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2004/05/03 17:19:09 | 01,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2004/04/13 14:08:44 | 00,000,047 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2003/11/14 14:27:28 | 00,000,291 | —- | C] () – C:\WINDOWS\MSFSETUP.INI
[2002/12/20 17:18:00 | 00,076,260 | —- | C] () – C:\WINDOWS\System32\drivers\UDNT.SYS
[2002/12/19 12:34:28 | 00,073,216 | —- | C] () – C:\WINDOWS\System32\drivers\SENTINEL.SYS
[2002/12/19 12:34:28 | 00,049,152 | —- | C] () – C:\WINDOWS\System32\SNTI386.DLL
[2002/12/19 12:34:28 | 00,017,920 | —- | C] () – C:\WINDOWS\System32\RNBOVDD.DLL
[2002/12/18 19:41:58 | 00,000,397 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2002/12/18 19:33:30 | 00,012,327 | —- | C] () – C:\WINDOWS\IOS.INI
[2002/12/18 19:33:30 | 00,002,324 | —- | C] () – C:\WINDOWS\VISTA32D.INI
[2002/12/18 19:33:30 | 00,002,193 | —- | C] () – C:\WINDOWS\SIGNWZ32.INI
[2002/12/18 19:33:30 | 00,001,878 | —- | C] () – C:\WINDOWS\WINZIP32.INI
[2002/12/18 19:33:30 | 00,001,406 | —- | C] () – C:\WINDOWS\PAGEIMG.INI
[2002/12/18 19:33:30 | 00,001,324 | —- | C] () – C:\WINDOWS\VTWAIN.INI
[2002/12/18 19:33:30 | 00,001,276 | —- | C] () – C:\WINDOWS\ODBC.INI
[2002/12/18 19:33:30 | 00,000,941 | —- | C] () – C:\WINDOWS\MEDIAPAQ.INI
[2002/12/18 19:33:30 | 00,000,856 | —- | C] () – C:\WINDOWS\PCAuth.ini
[2002/12/18 19:33:30 | 00,000,787 | —- | C] () – C:\WINDOWS\SCANREG.INI
[2002/12/18 19:33:30 | 00,000,639 | —- | C] () – C:\WINDOWS\UCM_16.INI
[2002/12/18 19:33:30 | 00,000,383 | —- | C] () – C:\WINDOWS\HPFSCHED.INI
[2002/12/18 19:33:30 | 00,000,307 | —- | C] () – C:\WINDOWS\ROMCAT.INI
[2002/12/18 19:33:30 | 00,000,298 | —- | C] () – C:\WINDOWS\WSST_Screen_Saver.ini
[2002/12/18 19:33:30 | 00,000,254 | —- | C] () – C:\WINDOWS\CTDelLau.INI
[2002/12/18 19:33:30 | 00,000,252 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2002/12/18 19:33:30 | 00,000,240 | —- | C] () – C:\WINDOWS\UMXADDIN.INI
[2002/12/18 19:33:30 | 00,000,232 | —- | C] () – C:\WINDOWS\NETSCAPE.INI
[2002/12/18 19:33:30 | 00,000,231 | —- | C] () – C:\WINDOWS\Ac3api.ini
[2002/12/18 19:33:30 | 00,000,227 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2002/12/18 19:33:30 | 00,000,189 | —- | C] () – C:\WINDOWS\CTSYN.INI
[2002/12/18 19:33:30 | 00,000,187 | —- | C] () – C:\WINDOWS\VATWAIN.INI
[2002/12/18 19:33:30 | 00,000,082 | —- | C] () – C:\WINDOWS\GBAFORM1.INI
[2002/12/18 19:33:30 | 00,000,075 | —- | C] () – C:\WINDOWS\CTNET.INI
[2002/12/18 19:33:30 | 00,000,071 | —- | C] () – C:\WINDOWS\4DISCBIB.INI
[2002/12/18 19:33:30 | 00,000,062 | —- | C] () – C:\WINDOWS\ACROREAD.INI
[2002/12/18 19:33:30 | 00,000,057 | —- | C] () – C:\WINDOWS\SHAREMEM.INI
[2002/12/18 19:33:30 | 00,000,050 | —- | C] () – C:\WINDOWS\WINFILE.INI
[2002/12/18 19:33:30 | 00,000,038 | —- | C] () – C:\WINDOWS\BACKDOOR.INI
[2002/12/18 19:33:30 | 00,000,037 | —- | C] () – C:\WINDOWS\Viewer.ini
[2002/12/18 19:33:30 | 00,000,034 | —- | C] () – C:\WINDOWS\SOL.INI
[2002/12/18 19:33:30 | 00,000,028 | —- | C] () – C:\WINDOWS\QTW.INI
[2002/12/18 19:33:30 | 00,000,026 | —- | C] () – C:\WINDOWS\SPSETUP.INI
[2002/12/18 19:33:30 | 00,000,026 | —- | C] () – C:\WINDOWS\MSOFFICE.INI
[2002/12/18 19:33:30 | 00,000,000 | —- | C] () – C:\WINDOWS\ZDDBVIEW.INI
[2002/12/18 19:33:30 | 00,000,000 | —- | C] () – C:\WINDOWS\ZDBUI32.INI
[2002/12/18 19:33:30 | 00,000,000 | —- | C] () – C:\WINDOWS\SWPM32.INI
[2002/12/18 19:33:30 | 00,000,000 | —- | C] () – C:\WINDOWS\MSINFO32.INI
[2002/12/18 19:33:29 | 00,007,885 | —- | C] () – C:\WINDOWS\NETDET.INI
[2002/12/18 19:33:29 | 00,005,068 | —- | C] () – C:\WINDOWS\DELETEFI.INI
[2002/12/18 19:33:29 | 00,003,598 | —- | C] () – C:\WINDOWS\HTMLHELP.INI
[2002/12/18 19:33:29 | 00,000,865 | —- | C] () – C:\WINDOWS\DOSREP.INI
[2002/12/18 19:33:29 | 00,000,299 | —- | C] () – C:\WINDOWS\PRELUDE.INI
[2002/12/18 19:33:29 | 00,000,226 | —- | C] () – C:\WINDOWS\TELEPHON.INI
[2002/12/18 19:33:29 | 00,000,175 | —- | C] () – C:\WINDOWS\WINMINE.INI
[2002/12/18 19:33:29 | 00,000,153 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2002/12/18 19:33:29 | 00,000,060 | —- | C] () – C:\WINDOWS\POWERPNT.INI
[2002/12/18 19:33:29 | 00,000,054 | —- | C] () – C:\WINDOWS\WAVEMIX.INI
[2002/12/18 19:33:29 | 00,000,000 | —- | C] () – C:\WINDOWS\PROGMAN.INI
[2002/11/01 17:17:50 | 00,000,256 | —- | C] () – C:\WINDOWS\AUCFG.INI
[2002/07/04 16:05:34 | 00,000,269 | —- | C] () – C:\WINDOWS\TMUPDATE.INI
[2002/07/01 15:53:20 | 00,057,344 | —- | C] () – C:\WINDOWS\System32\icmfilter.dll
[2001/12/14 14:34:46 | 00,164,864 | —- | C] () – C:\WINDOWS\patchw32.dll
[2001/08/23 13:00:00 | 00,002,931 | —- | C] () – C:\WINDOWS\WIN.INI
[2001/08/23 13:00:00 | 00,000,635 | —- | C] () – C:\WINDOWS\SYSTEM.INI
[2001/07/07 04:00:00 | 00,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2001/04/03 17:56:48 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\HPFPNP.DLL
[2001/03/05 18:23:34 | 00,036,352 | —- | C] () – C:\WINDOWS\UTHUNK32.DLL
[2000/05/26 18:08:44 | 00,047,104 | —- | C] () – C:\WINDOWS\System32\KMVIDC32.DLL
[2000/02/07 14:15:45 | 00,150,016 | —- | C] () – C:\WINDOWS\crlasp95.dll
[2000/02/02 16:04:54 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[2000/02/02 16:04:48 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1999/11/22 09:45:29 | 00,210,944 | —- | C] () – C:\WINDOWS\MSVCRT10.DLL
[1999/11/22 09:45:29 | 00,056,832 | —- | C] () – C:\WINDOWS\UCM_16.DLL
[1999/11/22 09:45:29 | 00,049,152 | —- | C] () – C:\WINDOWS\UCM_32.DLL
[1999/11/22 09:45:28 | 00,433,680 | —- | C] () – C:\WINDOWS\VSTASCAN.DLL
[1999/11/22 09:45:28 | 00,131,264 | —- | C] () – C:\WINDOWS\KCME0.DLL
[1999/11/22 09:45:28 | 00,098,236 | —- | C] () – C:\WINDOWS\KCME1.DLL
[1999/11/22 09:45:28 | 00,097,914 | —- | C] () – C:\WINDOWS\32KCME0.DLL
[1999/11/22 09:45:28 | 00,096,256 | —- | C] () – C:\WINDOWS\KPAPI.DLL
[1999/11/22 09:45:28 | 00,093,184 | —- | C] () – C:\WINDOWS\KPAPI32.DLL
[1999/11/22 09:45:28 | 00,070,548 | —- | C] () – C:\WINDOWS\KPMON.DLL
[1999/11/22 09:45:28 | 00,050,176 | —- | C] () – C:\WINDOWS\KPCP.DLL
[1999/11/22 09:45:28 | 00,017,920 | —- | C] () – C:\WINDOWS\VS32.DLL
[1999/11/22 09:45:28 | 00,017,920 | —- | C] () – C:\WINDOWS\KCMS_SYS.DLL
[1999/11/22 09:45:28 | 00,011,280 | —- | C] () – C:\WINDOWS\VS16.DLL
[1999/11/22 09:45:27 | 00,234,512 | —- | C] () – C:\WINDOWS\UDEPP16.DLL
[1999/11/22 09:45:26 | 00,023,552 | —- | C] () – C:\WINDOWS\VSCLI32.DLL
[1999/11/22 09:45:26 | 00,019,456 | —- | C] () – C:\WINDOWS\UMAX_CLI.DLL
[1999/11/18 14:27:16 | 00,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[1999/11/18 14:21:34 | 00,112,688 | —- | C] () – C:\WINDOWS\System32\SHW32.DLL
[1999/11/12 12:29:43 | 00,017,408 | —- | C] () – C:\WINDOWS\UnInstall.dll
[1999/07/23 14:46:48 | 00,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 11:53:20 | 00,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
[1999/01/22 19:46:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1980/01/01 01:00:00 | 00,222,390 | —- | C] () – C:\WINDOWS\IO.SYS
[1980/01/01 01:00:00 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\MEMBG.DLL
[1980/01/01 01:00:00 | 00,000,007 | —- | C] () – C:\WINDOWS\MSDOS.SYS
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[12 C:\WINDOWS\*.tmp files]
[2009/06/30 09:35:01 | 00,000,331 | —- | M] () – C:\WINDOWS\Brownie.ini
[2009/06/30 09:34:49 | 00,088,566 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/06/30 09:34:29 | 00,011,954 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2009/06/30 09:34:07 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/06/30 09:34:05 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/06/30 08:49:28 | 00,002,568 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/06/30 08:49:20 | 00,002,549 | —- | M] () – C:\Documents and Settings\Test\Desktop\CorelDRAW X3.lnk
[2009/06/30 08:23:28 | 00,002,489 | —- | M] () – C:\Documents and Settings\Test\Desktop\FastManager.lnk
[2009/06/25 11:49:03 | 00,000,281 | —- | M] () – C:\WINDOWS\System32\Trbininterface.ini
[2009/06/25 11:49:03 | 00,000,281 | —- | M] () – C:\WINDOWS\System32\bininterface.ini
[2009/06/25 11:09:18 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Test\Desktop\HJTInstall.exe
[2009/06/22 17:35:40 | 00,001,613 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/06/22 17:26:45 | 00,001,738 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2009/06/22 15:34:46 | 00,000,778 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TweakNow RegCleaner.lnk
[2009/06/19 08:06:27 | 03,686,454 | —- | M] () – C:\WINDOWS\wallpaper.bmp
[2009/06/18 15:52:23 | 80,530,6368 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2009/06/17 17:50:02 | 00,002,931 | —- | M] () – C:\WINDOWS\WIN.INI
[2009/06/17 17:50:02 | 00,001,878 | —- | M] () – C:\WINDOWS\WINZIP32.INI
[2009/06/17 11:27:56 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/16 16:48:46 | 04,319,458 | -H– | M] () – C:\Documents and Settings\Test\Local Settings\Application Data\IconCache.db
[2009/06/12 08:04:27 | 00,379,240 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/11 18:01:40 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/06/10 06:00:54 | 00,068,392 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\sbbd.exe
[2009/06/01 14:28:56 | 00,098,024 | —- | M] () – C:\Documents and Settings\Test\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/06/01 14:16:44 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/06/01 13:24:59 | 00,000,729 | —- | M] () – C:\Documents and Settings\Test\Start Menu\Programs\Startup\Secunia PSI.lnk
[2009/06/01 11:51:12 | 23,635,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
========== LOP Check ==========
[2009/06/30 09:30:21 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/10/04 12:24:12 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{101CEB38-EB1F-4487-8308-EF431174FBB0}
[2007/03/08 18:22:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{1A6E2773-3F02-4D0C-84B7-FDC9D08D5E56}
[2006/10/11 10:51:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{427AC175-E3C6-475F-A606-39F049F75179}
[2007/01/24 13:44:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{529FE8BA-D3D1-4F0D-91A1-A196102A4E8C}
[2006/11/08 17:00:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{614BC858-2826-4467-8984-B0F963F2FA84}
[2007/01/12 17:03:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{7687B166-1669-44E8-9615-567E0CF711AD}
[2006/09/14 17:18:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{A49C5BD7-28C2-413F-A907-FB345AD05292}
[2006/08/16 17:35:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{AAD5D5D4-78DF-4BEF-9198-31803B433B2C}
[2006/09/05 08:51:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{D6FDFB5A-DA29-488D-BF85-CA13BA8A5F8C}
[2007/12/20 18:55:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2005/11/01 14:42:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bitstream Font Navigator
[2007/11/16 17:55:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CardScan
[2009/05/26 16:03:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Linksys
[2005/12/30 15:54:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2009/06/30 09:30:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/06/22 15:34:32 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Test\Application Data
[2008/11/19 18:05:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Test\Application Data\AMPSoft
[2009/01/22 15:50:29 | 00,000,000 | R–D | M] – C:\Documents and Settings\Test\Application Data\Brother
[2008/07/30 08:52:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Test\Application Data\CardScan
[2008/05/23 16:12:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Test\Application Data\Corel
[2008/07/10 10:27:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Test\Application Data\My Sam's Club Digital Photo Center
[2009/06/24 15:01:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Test\Application Data\OpenOffice.org2
[2009/06/22 15:34:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Test\Application Data\TweakNow RegCleaner
[2009/05/19 14:07:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Test\Application Data\Uniblue
[2009/06/01 14:16:44 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/07/01 15:53:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/06/30 09:34:07 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
< End of report >
My computer is running a little better. I am running windows firewall.