tobyjones
Topic Starter
Please if anyone can help, I think I have some sort of virus, my Panda virus scanner won't scan and also IE goes very slow and then just freezes. It also won't let me download any files in IE, it gets to 99% and just hangs there.
I have run malwarebytes and it came back clean and I have also run ad-aware and it picked up a panda file called Borindmm.dll which it does not like.
Below is a copy of my HiJackThis report.
Thank you for any help you can give me.
Cheers.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:08:19, on 21/07/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\TPSrv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\PROGRAM FILES\PANDA SECURITY\PANDA GLOBAL PROTECTION 2010\WebProxy.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\PsCtrls.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\PavFnSvr.exe
c:\program files\panda security\panda global protection 2010\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Global Protection 2010\PsImSvc.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\PskSvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\pavsrv51.exe
C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\AVENGINE.EXE
C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\ApVxdWin.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\WINDOWS\system32\nvraidservice.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\SRVLOAD.EXE
C:\Program Files\Panda Security\Panda Global Protection 2010\PavBckPT.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\PAVJOBS.EXE
C:\Program Files\Panda Security\Panda Global Protection 2010\PAVJOBS.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: KTBho Class - {25EDC164-41A6-47C3-80BD-5E4FBE1BA7AB} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &RoboForm; - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Kaboodle Toolbar - {92857633-2441-4A14-8236-DFCB97AD3E87} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Global Protection 2010\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Security\Panda Global Protection 2010\Inicio.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [UpdatePDRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com (file missing)
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~1\NUCLEA~1\VideoGet\Plugins\VIDEOG~1.DLL
O9 - Extra 'Tools' menuitem: Add to &VideoGet; - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~1\NUCLEA~1\VideoGet\Plugins\VIDEOG~1.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1172259541828
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Software Controller - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2010\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Unknown owner - C:\Program Files\Panda Security\Panda Global Protection 2010\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Security\PavShld\pavprsrv.exe (file missing)
O23 - Service: Panda On-Access Anti-Malware Service (PAVSRV) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2010\pavsrv51.exe
O23 - Service: Panda Host Service (PSHost) - Unknown owner - c:\program files\panda security\panda global protection 2010\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Security S.L. - C:\Program Files\Panda Security\Panda Global Protection 2010\PsImSvc.exe
O23 - Service: Panda PSK service (PskSvcRetail) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2010\PskSvc.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2010\TPSrv.exe
–
End of file - 14927 bytes
OTL Log
OTL logfile created on: 21/07/2010 17:37:41 - Run 4
OTL by OldTimer - Version 3.1.17.0 Folder = C:\Documents and Settings\adam\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 0.67 Gb Available Physical Memory | 33.31% Memory free
3.85 Gb Paging File | 2.33 Gb Available in Paging File | 60.70% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 106.89 Gb Free Space | 45.90% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 232.88 Gb Total Space | 223.87 Gb Free Space | 96.13% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ADAM-464QH60QYD
Current User Name: adam
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/07/01 12:07:20 | 01,361,128 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
PRC - [2010/07/01 12:07:18 | 00,840,936 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
PRC - [2010/06/28 09:49:36 | 00,014,808 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2010/06/28 09:49:32 | 00,910,296 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/06/09 09:06:33 | 00,976,832 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
PRC - [2010/04/17 12:12:42 | 00,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2010/02/18 11:43:18 | 00,248,040 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Common Files\Java\Java Update\jusched.exe
PRC - [2010/02/04 21:09:13 | 01,181,328 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010/01/27 15:09:30 | 01,643,272 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
PRC - [2010/01/27 15:09:28 | 00,788,880 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2009/12/27 14:25:41 | 00,160,592 | —- | M] (Siber Systems) – C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
PRC - [2009/12/15 14:25:04 | 00,538,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\adam\Desktop\OTL.exe
PRC - [2009/09/25 13:51:04 | 00,906,496 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\ApVxdWin.exe
PRC - [2009/09/25 13:51:04 | 00,201,984 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\pavjobs.exe
PRC - [2009/09/17 13:17:26 | 00,291,584 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\PAVSRV51.EXE
PRC - [2009/09/07 17:40:04 | 00,198,400 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\AVENGINE.EXE
PRC - [2009/08/25 14:28:20 | 00,028,928 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\psksvc.exe
PRC - [2009/08/10 14:46:08 | 00,173,312 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\PsCtrlS.exe
PRC - [2009/08/10 14:45:52 | 00,169,216 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\PavFnSvr.exe
PRC - [2009/08/10 14:45:48 | 00,111,872 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\PavBckPT.exe
PRC - [2009/04/23 13:31:16 | 00,107,776 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\WebProxy.exe
PRC - [2009/04/17 18:01:12 | 00,247,152 | —- | M] () – C:\Program Files\CyberLink\Shared files\RichVideo.exe
PRC - [2009/04/17 11:17:24 | 00,157,440 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\TPSrv.exe
PRC - [2009/04/08 11:56:24 | 00,226,560 | —- | M] (Panda Security International) – c:\Program Files\Panda Security\Panda Global Protection 2010\FIREWALL\PSHOST.EXE
PRC - [2009/03/08 14:09:26 | 00,638,816 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2008/06/27 14:23:00 | 00,091,392 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\SrvLoad.exe
PRC - [2008/06/19 13:59:50 | 00,108,288 | —- | M] (Panda Security S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\PsImSvc.exe
PRC - [2008/04/14 01:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/03/07 22:44:07 | 00,039,936 | —- | M] (C-Dilla Ltd) – C:\WINDOWS\system32\drivers\CDAC11BA.EXE
PRC - [2006/12/18 14:34:36 | 00,868,352 | R— | M] (Analog Devices, Inc.) – C:\Program Files\Analog Devices\Core\smax4pnp.exe
PRC - [2006/09/11 19:59:28 | 00,172,032 | —- | M] () – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
PRC - [2006/09/11 19:56:02 | 00,135,227 | —- | M] (NVIDIA Corporation) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
PRC - [2006/09/11 19:55:42 | 00,065,599 | —- | M] (NVIDIA Corporation) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
PRC - [2006/04/13 16:14:26 | 00,020,543 | —- | M] (Apache Software Foundation) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
PRC - [2005/10/10 14:49:00 | 00,131,139 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe
PRC - [2005/07/12 08:55:26 | 00,081,920 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\SOUNDMAN.EXE
PRC - [2005/01/17 07:43:46 | 00,084,480 | R— | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvraidservice.exe
PRC - [2004/06/03 09:51:27 | 00,172,032 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft IntelliType Pro\type32.exe
PRC - [2004/06/03 09:50:07 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft IntelliPoint\point32.exe
PRC - [2002/08/29 13:00:00 | 00,016,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wbem\unsecapp.exe
========== Modules (SafeList) ==========
MOD - [2010/06/07 18:07:08 | 00,541,928 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\rooksbas.dll
MOD - [2009/12/15 14:25:04 | 00,538,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\adam\Desktop\OTL.exe
MOD - [2009/08/10 14:45:54 | 00,095,488 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\PavOEpl.dll
MOD - [2009/03/30 19:22:58 | 00,518,400 | —- | M] (Panda Security, S.L.) – C:\WINDOWS\system32\PavSHook.dll
MOD - [2007/02/08 11:53:40 | 00,107,568 | —- | M] (Panda Software) – C:\WINDOWS\system32\SYSTOOLS.DLL
MOD - [2006/11/10 19:49:42 | 00,499,712 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcp71.dll
MOD - [2006/11/10 19:49:42 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcr71.dll
MOD - [2002/08/29 13:00:00 | 00,014,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\serwvdrv.dll
MOD - [2002/08/29 13:00:00 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\umdmxfrm.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] – – (PavPrSrv)
SRV - [2010/07/01 12:07:18 | 00,840,936 | —- | M] (Trusteer Ltd.) [Auto | Running] – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe – (RapportMgmtService)
SRV - [2010/04/17 12:12:42 | 00,153,376 | —- | M] (Sun Microsystems, Inc.) [Auto | Running] – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2010/02/04 21:09:13 | 01,181,328 | —- | M] (Lavasoft) [Auto | Running] – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service)
SRV - [2009/09/17 13:17:26 | 00,291,584 | —- | M] (Panda Security, S.L.) [Auto | Running] – C:\Program Files\Panda Security\Panda Global Protection 2010\pavsrv51.exe – (PAVSRV)
SRV - [2009/08/25 14:28:20 | 00,028,928 | —- | M] (Panda Security, S.L.) [Auto | Running] – C:\Program Files\Panda Security\Panda Global Protection 2010\PskSvc.exe – (PskSvcRetail)
SRV - [2009/08/10 14:46:08 | 00,173,312 | —- | M] (Panda Security, S.L.) [Auto | Running] – C:\Program Files\Panda Security\Panda Global Protection 2010\PsCtrls.exe – (Panda Software Controller)
SRV - [2009/08/10 14:45:52 | 00,169,216 | —- | M] (Panda Security, S.L.) [Auto | Running] – C:\Program Files\Panda Security\Panda Global Protection 2010\PavFnSvr.exe – (PAVFNSVR)
SRV - [2009/04/18 01:36:45 | 00,182,768 | —- | M] (Google) [On_Demand | Stopped] – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc)
SRV - [2009/04/17 18:01:12 | 00,247,152 | —- | M] () [Auto | Running] – C:\Program Files\CyberLink\Shared files\RichVideo.exe – (RichVideo) Cyberlink RichVideo Service(CRVS)
SRV - [2009/04/17 11:17:24 | 00,157,440 | —- | M] (Panda Security, S.L.) [Auto | Running] – C:\Program Files\Panda Security\Panda Global Protection 2010\TPSrv.exe – (TPSrv)
SRV - [2009/04/08 11:56:24 | 00,226,560 | —- | M] (Panda Security International) [Auto | Running] – c:\program files\panda security\panda global protection 2010\firewall\PSHOST.EXE – (PSHost)
SRV - [2008/07/02 15:09:36 | 00,060,160 | —- | M] (Panda Security, S.L.) [Auto | Running] – C:\Program Files\Panda Security\Panda Global Protection 2010\GWMsrv.dll – (Gwmsrv)
SRV - [2008/06/19 13:59:50 | 00,108,288 | —- | M] (Panda Security S.L.) [Auto | Running] – C:\Program Files\Panda Security\Panda Global Protection 2010\PsImSvc.exe – (PSIMSVC)
SRV - [2008/03/30 10:36:30 | 00,504,104 | —- | M] (Apple Inc.) [Disabled | Stopped] – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service)
SRV - [2007/03/12 13:49:46 | 00,271,920 | —- | M] (Nero AG) [Disabled | Stopped] – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe – (NMIndexingService)
SRV - [2007/03/07 22:44:07 | 00,039,936 | —- | M] (C-Dilla Ltd) [Auto | Running] – C:\WINDOWS\system32\drivers\CDAC11BA.EXE – (C-DillaCdaC11BA)
SRV - [2007/02/24 10:18:52 | 00,068,096 | —- | M] () [On_Demand | Stopped] – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe – (Adobe LM Service)
SRV - [2006/10/26 19:49:34 | 00,441,136 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv)
SRV - [2006/10/26 14:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose)
SRV - [2006/09/11 19:59:28 | 00,172,032 | —- | M] () [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe – (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2006/09/11 19:56:02 | 00,135,227 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe – (nSvcIp)
SRV - [2006/09/11 19:55:42 | 00,065,599 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe – (nSvcLog)
SRV - [2006/04/13 16:14:26 | 00,020,543 | —- | M] (Apache Software Foundation) [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe – (ForcewareWebInterface)
SRV - [2005/10/10 14:49:00 | 00,131,139 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\WINDOWS\system32\nvsvc32.exe – (NVSvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Running] – – (PavTPK.sys)
DRV - File not found [Kernel | On_Demand | Running] – – (PavSRK.sys)
DRV - File not found [File_System | On_Demand | Running] – – (AvFlt)
DRV - [2010/07/21 16:17:16 | 00,013,880 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\COMFiltr.sys – (ComFiltr)
DRV - [2010/07/01 12:07:30 | 00,166,632 | —- | M] (Trusteer Ltd.) [Kernel | System | Running] – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys – (RapportPG)
DRV - [2010/07/01 12:07:30 | 00,059,240 | —- | M] (Trusteer Ltd.) [Kernel | System | Running] – C:\Program Files\Trusteer\Rapport\bin\RapportKELL.sys – (RapportKELL)
DRV - [2010/02/11 13:02:15 | 00,226,880 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\tcpip6.sys – (Tcpip6)
DRV - [2009/10/01 08:44:52 | 00,047,360 | —- | M] (VSO Software) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pcouffin.sys – (pcouffin)
DRV - [2009/10/01 00:07:44 | 00,075,016 | —- | M] (Panda Security, S.L.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\APPFLT.SYS – (APPFLT)
DRV - [2009/09/23 13:55:23 | 00,064,288 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd)
DRV - [2009/09/09 11:29:18 | 00,199,432 | —- | M] (Panda Security, S.L.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\neti1639.sys – (NETIMFLT01060039)
DRV - [2009/07/23 12:57:22 | 00,102,528 | R— | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ewusbmdm.sys – (hwdatacard)
DRV - [2009/06/30 11:37:16 | 00,028,552 | —- | M] (Panda Security, S.L.) [File_System | Boot | Running] – C:\WINDOWS\system32\Drivers\pavboot.sys – (pavboot)
DRV - [2009/06/16 14:33:02 | 00,046,728 | —- | M] (Panda Security, S.L.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\wnmflt.sys – (WNMFLT)
DRV - [2009/06/16 14:33:00 | 00,159,112 | —- | M] (Panda Security, S.L.) [TDI Layer] [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NETFLTDI.SYS – (NETFLTDI)
DRV - [2009/06/16 14:32:58 | 00,193,800 | —- | M] (Panda Security, S.L.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\idsflt.sys – (IDSFLT)
DRV - [2009/06/16 14:32:58 | 00,053,128 | —- | M] (Panda Security, S.L.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\dsaflt.sys – (DSAFLT)
DRV - [2009/05/09 01:14:20 | 00,014,736 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nuidfltr.sys – (NuidFltr)
DRV - [2008/04/28 19:09:46 | 00,051,072 | —- | M] (PCTools Research Pty Ltd.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ikhlayer.sys – (ikhlayer)
DRV - [2008/04/28 19:09:45 | 00,030,592 | —- | M] (PCTools Research Pty Ltd.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\ikhfile.sys – (ikhfile)
DRV - [2008/04/28 18:35:14 | 00,084,024 | —- | M] (Panda Security, S.L.) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\pavdrv51.sys – (PAVDRV)
DRV - [2008/04/13 19:45:29 | 00,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2008/04/13 19:45:12 | 00,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\usbaudio.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 17:36:05 | 00,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2008/03/28 12:25:06 | 00,022,072 | —- | M] (Panda Security, S.L.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\fnetmon.sys – (FNETMON)
DRV - [2008/01/29 12:01:28 | 00,016,168 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2007/11/15 21:30:48 | 00,034,064 | —- | M] (CACE Technologies) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\npf.sys – (npf)
DRV - [2007/11/13 11:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv)
DRV - [2007/10/12 14:07:10 | 00,055,808 | —- | M] (The SHVPN Project) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\tap0801.sys – (tap0801)
DRV - [2007/01/31 14:33:46 | 00,005,632 | —- | M] (GRISOFT, s.r.o.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\avgarkt.sys – (AVG Anti-Rootkit)
DRV - [2007/01/18 13:00:28 | 00,003,968 | —- | M] (GRISOFT, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AvgArCln.sys – (AvgArCln)
DRV - [2007/01/16 02:09:06 | 00,293,888 | R— | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ADIHdAud.sys – (ADIHdAudAddService)
DRV - [2006/09/11 12:45:38 | 00,019,968 | R— | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nvnetbus.sys – (nvnetbus)
DRV - [2006/09/11 12:45:36 | 00,057,856 | R— | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\NVENETFD.sys – (NVENETFD)
DRV - [2006/09/11 12:45:26 | 00,110,592 | R— | M] (NVIDIA Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\nvtcp.sys – (NVTCP)
DRV - [2006/08/21 11:24:28 | 00,105,344 | R— | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\nvata.sys – (nvata)
DRV - [2006/08/06 23:57:30 | 00,093,952 | R— | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\aeaudio.sys – (AEAudio)
DRV - [2006/03/17 10:18:58 | 00,392,960 | R— | M] (Sensaura) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\senfilt.sys – (SenFiltService)
DRV - [2005/10/10 14:49:00 | 03,530,432 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2005/07/15 10:40:36 | 03,640,000 | R— | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005/05/17 18:45:12 | 00,076,288 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\nvraid.sys – (nvraid) NVIDIA nForce™
DRV - [2005/05/17 10:45:08 | 00,092,800 | R— | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\nvatabus.sys – (nvatabus)
DRV - [2004/08/13 03:56:20 | 00,005,810 | R— | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ASACPI.sys – (MTsensor)
DRV - [2004/08/03 23:41:56 | 00,011,868 | —- | M] (Conexant) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\mdmxsdk.sys – (mdmxsdk)
DRV - [2004/06/03 09:50:07 | 00,020,352 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\point32.sys – (Point32)
DRV - [2002/11/18 15:29:26 | 00,399,700 | —- | M] (NVIDIA Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\dumant.sys – (DumaNT)
DRV - [2002/08/29 13:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink)
DRV - [2002/06/26 10:06:50 | 00,875,191 | —- | M] (Conexant) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\WINACHCF.sys – (Winachcf)
DRV - [2002/04/11 15:21:38 | 00,013,335 | R— | M] (Microsystems Corp) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\usbcm.sys – (usbcm)
DRV - [2001/08/17 15:00:04 | 00,002,944 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\msmpu401.sys – (ms_mpu401)
DRV - [2001/08/17 13:57:38 | 00,016,128 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\MODEMCSA.sys – (MODEMCSA)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk"
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.98
FF - prefs.js..extensions.enabledItems: [removed]:1.3.2
FF - prefs.js..extensions.enabledItems: {0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.80
FF - prefs.js..extensions.enabledItems: {a880aeee-06f6-48e7-87c5-876fb64a2a56}:0.70
FF - prefs.js..extensions.enabledItems: {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {c2b1f3ae-5cd5-49b7-8a0c-2c3bcbbbb294}:1.1
FF - prefs.js..extensions.enabledItems: [removed]:2
FF - prefs.js..extensions.enabledItems: 4
FF - prefs.js..extensions.enabledItems: 9
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0.17
FF - prefs.js..extensions.enabledItems: {7CEA821D-3DAB-4238-B424-BF7324531750}:0.4.95
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2009/04/19 14:00:31 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/21 16:10:53 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/21 16:10:52 | 00,000,000 | —D | M]
[2009/12/14 16:26:49 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Extensions
[2009/12/14 16:26:49 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Extensions\[removed]
[2010/07/20 23:28:14 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions
[2009/12/19 20:34:55 | 00,000,000 | —D | M] (FireShot) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2009/12/19 20:35:08 | 00,000,000 | —D | M] (SeoQuake) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
[2009/06/20 11:47:29 | 00,000,000 | —D | M] (ChatZilla) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2010/05/31 18:08:12 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{7CEA821D-3DAB-4238-B424-BF7324531750}
[2010/06/10 14:43:52 | 00,000,000 | —D | M] (iMacros for Firefox) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
[2009/06/16 20:42:33 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{a880aeee-06f6-48e7-87c5-876fb64a2a56}
[2009/03/05 12:23:38 | 00,000,000 | —D | M] (Google Global) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{B97F57B9-1B42-4aed-9475-0022600C62DC}
[2009/05/24 14:25:02 | 00,000,000 | —D | M] (Article Marketing Impact) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{BFB5F154-9212-46F3-B547-AC6106030A54}
[2010/03/17 16:48:15 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{c2b1f3ae-5cd5-49b7-8a0c-2c3bcbbbb294}
[2009/09/22 09:05:20 | 00,000,000 | —D | M] (Clipmarks) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
[2009/06/16 13:36:46 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{ec9CEB59-8266-438b-91D9-82F56D595E15}
[2010/04/17 00:17:24 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{fae5bcbc-dd73-439a-a15e-5b9ff39c0e9b}
[2009/12/19 20:34:46 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]
[2009/12/16 02:11:55 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]
[2008/11/05 20:30:01 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]
[2009/03/06 23:01:42 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]
[2010/03/08 10:46:43 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]
[2009/06/20 11:47:46 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]
[2010/05/15 14:43:44 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]
[2010/07/20 16:35:34 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/17 12:12:54 | 00,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/17 12:12:42 | 00,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/16 01:55:13 | 00,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/01/16 01:55:13 | 00,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/01/16 01:55:13 | 00,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/01/16 01:55:13 | 00,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: (736 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (KTBho Class) - {25EDC164-41A6-47C3-80BD-5E4FBE1BA7AB} - C:\Program Files\kaboodle\Kaboodle IE Toolbar\KTBar.dll ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (PCTools Site Guard) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\Program Files\Spyware Doctor\tools\iesdsg.dll (PC Tools)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (PCTools Browser Monitor) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\Program Files\Spyware Doctor\tools\iesdpb.dll (PC Tools)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Kaboodle Toolbar) - {92857633-2441-4A14-8236-DFCB97AD3E87} - C:\Program Files\kaboodle\Kaboodle IE Toolbar\KTBar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APVXDWIN] C:\Program Files\Panda Security\Panda Global Protection 2010\APVXDWIN.EXE (Panda Security, S.L.)
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\point32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SCANINICIO] C:\Program Files\Panda Security\Panda Global Protection 2010\Inicio.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [type32] C:\Program Files\Microsoft IntelliType Pro\type32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [UpdatePDRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - File not found
O9 - Extra Button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\Program Files\Spyware Doctor\tools\iesdpb.dll (PC Tools)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O9 - Extra 'Tools' menuitem : Add to &VideoGet; - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Expression\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} http://download.microsoft.com/download/7/4…helpcontrol.cab (Microsoft Genuine Advantage Self Support Tool)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1172259541828 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avldr: DllName - avldr.dll - C:\WINDOWS\System32\avldr.dll (Panda Security, S.L.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/02/23 19:46:58 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{43792500-3684-11df-94d4-001e8c709532}\Shell - "" = AutoRun
O33 - MountPoints2\{43792500-3684-11df-94d4-001e8c709532}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{43792500-3684-11df-94d4-001e8c709532}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe – File not found
O33 - MountPoints2\{43792501-3684-11df-94d4-001e8c709532}\Shell - "" = AutoRun
O33 - MountPoints2\{43792501-3684-11df-94d4-001e8c709532}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{43792501-3684-11df-94d4-001e8c709532}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe – File not found
O33 - MountPoints2\{b11f0d38-36d7-11df-94d5-001e8c709532}\Shell - "" = AutoRun
O33 - MountPoints2\{b11f0d38-36d7-11df-94d5-001e8c709532}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{b11f0d38-36d7-11df-94d5-001e8c709532}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe – File not found
O33 - MountPoints2\{b11f0d39-36d7-11df-94d5-001e8c709532}\Shell - "" = AutoRun
O33 - MountPoints2\{b11f0d39-36d7-11df-94d5-001e8c709532}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{b11f0d39-36d7-11df-94d5-001e8c709532}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/07/21 17:13:36 | 00,000,000 | RHSD | C] – C:\WINDOWS\PSICache
[2010/07/21 16:11:01 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Panda Security
[2010/07/20 20:32:49 | 00,000,000 | —D | C] – C:\Documents and Settings\adam\Desktop\Virus Removal Tool
[2010/07/14 07:56:51 | 00,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/07/08 09:17:38 | 00,000,000 | —D | C] – C:\Documents and Settings\adam\Application Data\acccore
[2010/07/08 09:17:36 | 00,000,000 | —D | C] – C:\Documents and Settings\adam\Local Settings\Application Data\AOL
[2010/07/08 09:17:36 | 00,000,000 | —D | C] – C:\Documents and Settings\adam\Local Settings\Application Data\AIM
[2010/07/08 09:17:28 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AIM
[2010/07/08 09:17:22 | 00,000,000 | —D | C] – C:\Program Files\AIM
[2010/07/08 09:17:19 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Software Update Utility
[2010/07/08 09:17:18 | 00,000,000 | —D | C] – C:\Program Files\Common Files\AOL
[2010/07/01 08:18:03 | 00,000,000 | —D | C] – C:\WINDOWS\System32\Adobe
[2010/04/21 12:45:53 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Trusteer
[2010/03/29 11:56:47 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Trusteer
[2010/03/23 15:00:21 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Vodafone
[2009/10/01 08:44:52 | 00,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\adam\Application Data\pcouffin.sys
[2009/01/07 10:37:41 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Panda Software
[2008/02/08 00:39:00 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2007/05/26 09:00:54 | 00,594,800 | —- | C] (Softnik Technologies ) – C:\Program Files\gkwv2_setup.exe
[2007/05/24 21:04:34 | 14,279,822 | —- | C] (SoftwareClub.ws ) – C:\Program Files\scvc6000.exe
[2007/03/06 09:50:42 | 02,683,984 | —- | C] (Piriform Ltd) – C:\Program Files\ccsetup137.exe
[2007/03/06 09:39:12 | 11,352,928 | —- | C] (PC Tools ) – C:\Program Files\spydocsetup.exe
[2007/02/25 10:52:01 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2007/02/24 20:25:45 | 33,170,212 | —- | C] ( ) – C:\Program Files\klmcodec165.exe
[2007/02/24 10:52:20 | 01,145,896 | —- | C] (Google) – C:\Program Files\GoogleToolbarInstaller.exe
[2007/02/24 08:55:26 | 25,755,448 | —- | C] (Microsoft Corporation) – C:\Program Files\wmp11-windowsxp-x86-enu.exe
[2007/02/23 21:40:06 | 24,265,736 | —- | C] (Microsoft) – C:\Program Files\dotnetfx.exe
[2007/02/23 21:00:11 | 21,822,168 | —- | C] ( ) – C:\Program Files\AdbeRdr80_en_US.exe
[2007/02/23 20:56:15 | 36,808,256 | —- | C] (Apple Computer, Inc.) – C:\Program Files\iTunesSetup.exe
[2007/02/23 20:03:01 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/02/23 19:51:49 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2007/02/23 19:46:46 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
========== Files - Modified Within 30 Days ==========
[2010/07/21 17:19:27 | 00,008,627 | —- | M] () – C:\WINDOWS\System32\PAV_FOG.OPC
[2010/07/21 17:13:47 | 00,348,452 | —- | M] () – C:\WINDOWS\System32\drivers\APPFCONT.DAT.bck
[2010/07/21 17:13:47 | 00,348,452 | —- | M] () – C:\WINDOWS\System32\drivers\APPFCONT.DAT
[2010/07/21 17:07:54 | 00,002,445 | —- | M] () – C:\Documents and Settings\adam\Desktop\HiJackThis.lnk
[2010/07/21 16:45:32 | 00,000,522 | —- | M] () – C:\WINDOWS\System32\drivers\etc\pfdnnt.act
[2010/07/21 16:20:30 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/07/21 16:20:30 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2010/07/21 16:20:30 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2010/07/21 16:20:30 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2010/07/21 16:20:30 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2010/07/21 16:19:23 | 00,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{CF5E3D8D-1EED-4D74-931D-56B0FEE9941C}.job
[2010/07/21 16:17:31 | 00,001,132 | —- | M] () – C:\WINDOWS\System32\drivers\APPFLTR.CFG.bck
[2010/07/21 16:17:31 | 00,001,132 | —- | M] () – C:\WINDOWS\System32\drivers\APPFLTR.CFG
[2010/07/21 16:17:31 | 00,000,252 | —- | M] () – C:\WINDOWS\System32\drivers\etc\IdsFlt.cfg.bck
[2010/07/21 16:17:31 | 00,000,252 | —- | M] () – C:\WINDOWS\System32\drivers\etc\IdsFlt.cfg
[2010/07/21 16:17:31 | 00,000,152 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetLoc.wlt.bck
[2010/07/21 16:17:31 | 00,000,152 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetLoc.wlt
[2010/07/21 16:17:31 | 00,000,068 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetFlt.cfg.bck
[2010/07/21 16:17:31 | 00,000,068 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetFlt.cfg
[2010/07/21 16:17:31 | 00,000,056 | —- | M] () – C:\WINDOWS\System32\drivers\etc\WnmFlt.cfg.bck
[2010/07/21 16:17:31 | 00,000,056 | —- | M] () – C:\WINDOWS\System32\drivers\etc\WnmFlt.cfg
[2010/07/21 16:17:31 | 00,000,056 | —- | M] () – C:\WINDOWS\System32\drivers\etc\DsaFlt.cfg.bck
[2010/07/21 16:17:31 | 00,000,056 | —- | M] () – C:\WINDOWS\System32\drivers\etc\DsaFlt.cfg
[2010/07/21 16:17:30 | 00,447,324 | —- | M] () – C:\WINDOWS\System32\drivers\etc\DsaFlt.rls.bck
[2010/07/21 16:17:30 | 00,447,324 | —- | M] () – C:\WINDOWS\System32\drivers\etc\DsaFlt.rls
[2010/07/21 16:17:16 | 00,013,880 | —- | M] () – C:\WINDOWS\System32\drivers\COMFiltr.sys
[2010/07/21 16:16:36 | 00,039,291 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/07/21 16:15:38 | 00,000,120 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetAdapt.cfg.bck
[2010/07/21 16:15:38 | 00,000,120 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetAdapt.cfg
[2010/07/21 16:15:38 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetAR.wlt.bck
[2010/07/21 16:15:38 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetAR.wlt
[2010/07/21 16:15:35 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/21 16:13:26 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/21 16:13:10 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/07/21 15:36:22 | 00,008,627 | —- | M] () – C:\Documents and Settings\adam\PAV_FOG.OPC
[2010/07/21 09:56:44 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/07/21 00:17:16 | 00,485,302 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/07/21 00:17:16 | 00,089,450 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/07/21 00:10:52 | 00,000,262 | —- | M] () – C:\WINDOWS\System32\PavCPL.dat
[2010/07/21 00:10:47 | 00,000,492 | —- | M] () – C:\WINDOWS\tasks\Basic clean-up.job
[2010/07/19 19:52:52 | 09,957,376 | —- | M] () – C:\Documents and Settings\adam\ntuser.dat
[2010/07/19 18:43:36 | 00,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/07/19 14:59:59 | 00,000,668 | —- | M] () – C:\Documents and Settings\adam\Application Data\vso_ts_preview.xml
[2010/07/19 13:48:55 | 00,185,344 | —- | M] () – C:\Documents and Settings\adam\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/19 13:34:15 | 00,000,699 | —- | M] () – C:\Documents and Settings\adam\Desktop\Shortcut to scrapebox.lnk
[2010/07/17 11:05:44 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/07/12 23:08:59 | 00,000,695 | —- | M] () – C:\WINDOWS\win.ini
[2010/07/12 23:08:59 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/07/12 23:08:59 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2010/07/08 11:24:40 | 20,434,768 | —- | M] () – C:\Documents and Settings\adam\Desktop\Images.zip
[2010/07/08 09:17:36 | 00,000,361 | -H– | M] () – C:\IPH.PH
[2010/07/08 09:17:27 | 00,001,574 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AIM.lnk
[2010/06/29 20:21:27 | 00,002,497 | —- | M] () – C:\Documents and Settings\adam\Desktop\Microsoft Office Word 2003.lnk
[2010/06/24 08:38:49 | 00,564,552 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
========== Files Created - No Company Name ==========
[2010/07/21 00:10:52 | 00,000,262 | —- | C] () – C:\WINDOWS\System32\PavCPL.dat
[2010/07/21 00:10:46 | 00,000,492 | —- | C] () – C:\WINDOWS\tasks\Basic clean-up.job
[2010/07/19 19:52:51 | 09,957,376 | —- | C] () – C:\Documents and Settings\adam\ntuser.dat
[2010/07/19 13:34:15 | 00,000,699 | —- | C] () – C:\Documents and Settings\adam\Desktop\Shortcut to scrapebox.lnk
[2010/07/10 12:00:26 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/07/10 12:00:26 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/07/08 11:20:07 | 20,434,768 | —- | C] () – C:\Documents and Settings\adam\Desktop\Images.zip
[2010/07/08 09:17:27 | 00,001,574 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AIM.lnk
[2010/07/08 09:17:06 | 00,000,361 | -H– | C] () – C:\IPH.PH
[2010/04/14 20:46:08 | 00,011,774 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\2754096141
[2010/04/14 20:46:08 | 00,011,774 | -HS- | C] () – C:\Documents and Settings\adam\Local Settings\Application Data\2754096141
[2010/04/14 20:46:07 | 00,011,782 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\3769731055
[2010/04/14 20:46:07 | 00,011,782 | -HS- | C] () – C:\Documents and Settings\adam\Local Settings\Application Data\3769731055
[2010/04/14 20:41:08 | 00,011,750 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\6Y5qPA2XU80
[2010/04/14 20:41:08 | 00,011,750 | -HS- | C] () – C:\Documents and Settings\adam\Local Settings\Application Data\6Y5qPA2XU80
[2010/01/08 13:08:45 | 00,013,880 | —- | C] () – C:\WINDOWS\System32\drivers\COMFiltr.sys
[2009/11/17 14:46:46 | 00,000,091 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/10/16 08:51:23 | 00,000,038 | —- | C] () – C:\WINDOWS\AviSplitter.INI
[2009/10/01 08:45:18 | 00,000,668 | —- | C] () – C:\Documents and Settings\adam\Application Data\vso_ts_preview.xml
[2009/10/01 08:44:58 | 00,000,034 | —- | C] () – C:\Documents and Settings\adam\Application Data\pcouffin.log
[2009/10/01 08:44:52 | 00,087,608 | —- | C] () – C:\Documents and Settings\adam\Application Data\inst.exe
[2009/10/01 08:44:52 | 00,007,887 | —- | C] () – C:\Documents and Settings\adam\Application Data\pcouffin.cat
[2009/10/01 08:44:52 | 00,001,144 | —- | C] () – C:\Documents and Settings\adam\Application Data\pcouffin.inf
[2008/09/04 20:51:02 | 01,069,056 | —- | C] () – C:\WINDOWS\System32\libmySQL.dll
[2008/07/12 01:29:13 | 00,000,082 | —- | C] () – C:\WINDOWS\DeliveryReader.INI
[2008/03/31 17:19:19 | 00,032,834 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/03/31 13:31:36 | 00,000,804 | R— | C] () – C:\WINDOWS\System32\AsusSetup.ini
[2008/02/04 18:23:10 | 00,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2008/01/04 17:16:38 | 00,888,832 | —- | C] () – C:\WINDOWS\System32\securenet.dll
[2007/11/11 16:20:10 | 00,000,000 | —- | C] () – C:\WINDOWS\msicpl.ini
[2007/05/25 15:42:18 | 14,659,071 | —- | C] () – C:\Program Files\KE_setup13143.exe
[2007/05/25 15:40:47 | 01,585,247 | —- | C] () – C:\Program Files\SEOE_setup4081.exe
[2007/05/24 21:09:26 | 00,237,568 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2007/05/23 16:27:32 | 09,389,672 | —- | C] () – C:\Program Files\winzip111.exe
[2007/05/21 18:54:06 | 64,625,683 | —- | C] () – C:\Program Files\xsiteprosetup.exe
[2007/03/10 10:04:48 | 00,001,353 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/03/07 23:00:47 | 00,096,768 | —- | C] () – C:\WINDOWS\SlantAdj.dll
[2007/03/07 23:00:47 | 00,000,072 | —- | C] () – C:\WINDOWS\System32\epDPE.ini
[2007/03/07 22:48:04 | 00,000,029 | —- | C] () – C:\WINDOWS\DEBUGSM.INI
[2007/03/07 22:40:06 | 00,000,022 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2007/03/07 22:39:10 | 00,000,025 | —- | C] () – C:\WINDOWS\CDE P242580EF.ini
[2007/03/02 21:47:51 | 00,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/02/28 01:03:19 | 19,987,4112 | —- | C] () – C:\Program Files\Nero-7.7.5.1_eng_trial.exe
[2007/02/24 20:26:50 | 00,815,104 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2007/02/24 20:26:50 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2007/02/24 20:26:49 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/02/24 20:26:49 | 00,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007/02/24 20:26:48 | 00,084,480 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2007/02/24 19:20:59 | 00,411,509 | —- | C] () – C:\Program Files\GSpot270a.zip
[2007/02/24 18:52:16 | 06,241,753 | —- | C] () – C:\Program Files\XP-Codec-Pack-2.0.6.zip
[2007/02/24 18:47:43 | 00,185,344 | —- | C] () – C:\Documents and Settings\adam\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/24 18:41:27 | 05,134,848 | —- | C] () – C:\Program Files\SVCD2DVDv2.msi
[2007/02/24 18:38:27 | 00,000,127 | —- | C] () – C:\Documents and Settings\adam\Local Settings\Application Data\fusioncache.dat
[2007/02/24 11:46:28 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/02/24 09:24:54 | 00,060,640 | —- | C] () – C:\Program Files\AC3ACM.zip
[2007/02/24 09:23:39 | 01,045,001 | —- | C] () – C:\Program Files\VirtualDub-MPEG2.zip
[2007/02/24 09:07:07 | 01,094,021 | —- | C] () – C:\Program Files\dvdshrink32setup1.zip
[2007/02/23 21:44:50 | 01,201,041 | —- | C] () – C:\Program Files\winrar.exe
[2007/02/23 21:38:59 | 05,968,384 | —- | C] () – C:\Program Files\SVCD2DVD.msi
[2007/02/23 20:25:06 | 00,006,656 | —- | C] () – C:\WINDOWS\System32\CNMVS5m.DLL
[2007/02/23 20:20:55 | 00,156,672 | R— | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2007/02/23 20:18:46 | 00,000,269 | R— | C] () – C:\WINDOWS\System32\raidmgmt.ini
[2007/02/23 20:18:31 | 00,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2007/02/23 20:18:28 | 00,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/02/23 20:08:19 | 00,009,728 | R— | C] () – C:\WINDOWS\System32\sysinfoX64.sys
[2007/02/23 20:08:19 | 00,008,192 | R— | C] () – C:\WINDOWS\System32\sysinfo.sys
[2006/05/02 23:38:24 | 00,000,748 | —- | C] () – C:\WINDOWS\SetBrowser.ini
[2006/04/23 00:00:10 | 00,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2005/10/10 14:49:00 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005/10/10 14:49:00 | 01,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/10/10 14:49:00 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2005/10/10 14:49:00 | 00,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005/10/10 14:49:00 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/10/10 14:49:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2005/10/10 14:49:00 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2003/01/07 16:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/11/18 15:29:28 | 00,368,640 | —- | C] () – C:\WINDOWS\System32\nvimage.dll
[2002/11/18 15:29:28 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\stereoi.dll
[2002/08/29 13:00:00 | 01,287,680 | —- | C] () – C:\WINDOWS\System32\quartz(2).dll
[2002/08/29 13:00:00 | 00,498,205 | —- | C] () – C:\WINDOWS\System32\dxmasf(2).dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 161 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B63300D1
< End of report >
I have run malwarebytes and it came back clean and I have also run ad-aware and it picked up a panda file called Borindmm.dll which it does not like.
Below is a copy of my HiJackThis report.
Thank you for any help you can give me.
Cheers.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:08:19, on 21/07/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\TPSrv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\PROGRAM FILES\PANDA SECURITY\PANDA GLOBAL PROTECTION 2010\WebProxy.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\PsCtrls.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\PavFnSvr.exe
c:\program files\panda security\panda global protection 2010\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Global Protection 2010\PsImSvc.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\PskSvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\pavsrv51.exe
C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\AVENGINE.EXE
C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\ApVxdWin.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\WINDOWS\system32\nvraidservice.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\SRVLOAD.EXE
C:\Program Files\Panda Security\Panda Global Protection 2010\PavBckPT.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Panda Security\Panda Global Protection 2010\PAVJOBS.EXE
C:\Program Files\Panda Security\Panda Global Protection 2010\PAVJOBS.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: KTBho Class - {25EDC164-41A6-47C3-80BD-5E4FBE1BA7AB} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &RoboForm; - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Kaboodle Toolbar - {92857633-2441-4A14-8236-DFCB97AD3E87} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Global Protection 2010\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Security\Panda Global Protection 2010\Inicio.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [UpdatePDRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com (file missing)
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~1\NUCLEA~1\VideoGet\Plugins\VIDEOG~1.DLL
O9 - Extra 'Tools' menuitem: Add to &VideoGet; - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~1\NUCLEA~1\VideoGet\Plugins\VIDEOG~1.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1172259541828
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Software Controller - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2010\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Unknown owner - C:\Program Files\Panda Security\Panda Global Protection 2010\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Security\PavShld\pavprsrv.exe (file missing)
O23 - Service: Panda On-Access Anti-Malware Service (PAVSRV) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2010\pavsrv51.exe
O23 - Service: Panda Host Service (PSHost) - Unknown owner - c:\program files\panda security\panda global protection 2010\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Security S.L. - C:\Program Files\Panda Security\Panda Global Protection 2010\PsImSvc.exe
O23 - Service: Panda PSK service (PskSvcRetail) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2010\PskSvc.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2010\TPSrv.exe
–
End of file - 14927 bytes
OTL Log
OTL logfile created on: 21/07/2010 17:37:41 - Run 4
OTL by OldTimer - Version 3.1.17.0 Folder = C:\Documents and Settings\adam\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 0.67 Gb Available Physical Memory | 33.31% Memory free
3.85 Gb Paging File | 2.33 Gb Available in Paging File | 60.70% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 106.89 Gb Free Space | 45.90% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 232.88 Gb Total Space | 223.87 Gb Free Space | 96.13% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ADAM-464QH60QYD
Current User Name: adam
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/07/01 12:07:20 | 01,361,128 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
PRC - [2010/07/01 12:07:18 | 00,840,936 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
PRC - [2010/06/28 09:49:36 | 00,014,808 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2010/06/28 09:49:32 | 00,910,296 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/06/09 09:06:33 | 00,976,832 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
PRC - [2010/04/17 12:12:42 | 00,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2010/02/18 11:43:18 | 00,248,040 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Common Files\Java\Java Update\jusched.exe
PRC - [2010/02/04 21:09:13 | 01,181,328 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010/01/27 15:09:30 | 01,643,272 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
PRC - [2010/01/27 15:09:28 | 00,788,880 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2009/12/27 14:25:41 | 00,160,592 | —- | M] (Siber Systems) – C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
PRC - [2009/12/15 14:25:04 | 00,538,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\adam\Desktop\OTL.exe
PRC - [2009/09/25 13:51:04 | 00,906,496 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\ApVxdWin.exe
PRC - [2009/09/25 13:51:04 | 00,201,984 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\pavjobs.exe
PRC - [2009/09/17 13:17:26 | 00,291,584 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\PAVSRV51.EXE
PRC - [2009/09/07 17:40:04 | 00,198,400 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\AVENGINE.EXE
PRC - [2009/08/25 14:28:20 | 00,028,928 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\psksvc.exe
PRC - [2009/08/10 14:46:08 | 00,173,312 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\PsCtrlS.exe
PRC - [2009/08/10 14:45:52 | 00,169,216 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\PavFnSvr.exe
PRC - [2009/08/10 14:45:48 | 00,111,872 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\PavBckPT.exe
PRC - [2009/04/23 13:31:16 | 00,107,776 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\WebProxy.exe
PRC - [2009/04/17 18:01:12 | 00,247,152 | —- | M] () – C:\Program Files\CyberLink\Shared files\RichVideo.exe
PRC - [2009/04/17 11:17:24 | 00,157,440 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\TPSrv.exe
PRC - [2009/04/08 11:56:24 | 00,226,560 | —- | M] (Panda Security International) – c:\Program Files\Panda Security\Panda Global Protection 2010\FIREWALL\PSHOST.EXE
PRC - [2009/03/08 14:09:26 | 00,638,816 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2008/06/27 14:23:00 | 00,091,392 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\SrvLoad.exe
PRC - [2008/06/19 13:59:50 | 00,108,288 | —- | M] (Panda Security S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\PsImSvc.exe
PRC - [2008/04/14 01:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/03/07 22:44:07 | 00,039,936 | —- | M] (C-Dilla Ltd) – C:\WINDOWS\system32\drivers\CDAC11BA.EXE
PRC - [2006/12/18 14:34:36 | 00,868,352 | R— | M] (Analog Devices, Inc.) – C:\Program Files\Analog Devices\Core\smax4pnp.exe
PRC - [2006/09/11 19:59:28 | 00,172,032 | —- | M] () – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
PRC - [2006/09/11 19:56:02 | 00,135,227 | —- | M] (NVIDIA Corporation) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
PRC - [2006/09/11 19:55:42 | 00,065,599 | —- | M] (NVIDIA Corporation) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
PRC - [2006/04/13 16:14:26 | 00,020,543 | —- | M] (Apache Software Foundation) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
PRC - [2005/10/10 14:49:00 | 00,131,139 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe
PRC - [2005/07/12 08:55:26 | 00,081,920 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\SOUNDMAN.EXE
PRC - [2005/01/17 07:43:46 | 00,084,480 | R— | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvraidservice.exe
PRC - [2004/06/03 09:51:27 | 00,172,032 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft IntelliType Pro\type32.exe
PRC - [2004/06/03 09:50:07 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft IntelliPoint\point32.exe
PRC - [2002/08/29 13:00:00 | 00,016,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wbem\unsecapp.exe
========== Modules (SafeList) ==========
MOD - [2010/06/07 18:07:08 | 00,541,928 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\rooksbas.dll
MOD - [2009/12/15 14:25:04 | 00,538,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\adam\Desktop\OTL.exe
MOD - [2009/08/10 14:45:54 | 00,095,488 | —- | M] (Panda Security, S.L.) – C:\Program Files\Panda Security\Panda Global Protection 2010\PavOEpl.dll
MOD - [2009/03/30 19:22:58 | 00,518,400 | —- | M] (Panda Security, S.L.) – C:\WINDOWS\system32\PavSHook.dll
MOD - [2007/02/08 11:53:40 | 00,107,568 | —- | M] (Panda Software) – C:\WINDOWS\system32\SYSTOOLS.DLL
MOD - [2006/11/10 19:49:42 | 00,499,712 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcp71.dll
MOD - [2006/11/10 19:49:42 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcr71.dll
MOD - [2002/08/29 13:00:00 | 00,014,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\serwvdrv.dll
MOD - [2002/08/29 13:00:00 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\umdmxfrm.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] – – (PavPrSrv)
SRV - [2010/07/01 12:07:18 | 00,840,936 | —- | M] (Trusteer Ltd.) [Auto | Running] – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe – (RapportMgmtService)
SRV - [2010/04/17 12:12:42 | 00,153,376 | —- | M] (Sun Microsystems, Inc.) [Auto | Running] – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2010/02/04 21:09:13 | 01,181,328 | —- | M] (Lavasoft) [Auto | Running] – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service)
SRV - [2009/09/17 13:17:26 | 00,291,584 | —- | M] (Panda Security, S.L.) [Auto | Running] – C:\Program Files\Panda Security\Panda Global Protection 2010\pavsrv51.exe – (PAVSRV)
SRV - [2009/08/25 14:28:20 | 00,028,928 | —- | M] (Panda Security, S.L.) [Auto | Running] – C:\Program Files\Panda Security\Panda Global Protection 2010\PskSvc.exe – (PskSvcRetail)
SRV - [2009/08/10 14:46:08 | 00,173,312 | —- | M] (Panda Security, S.L.) [Auto | Running] – C:\Program Files\Panda Security\Panda Global Protection 2010\PsCtrls.exe – (Panda Software Controller)
SRV - [2009/08/10 14:45:52 | 00,169,216 | —- | M] (Panda Security, S.L.) [Auto | Running] – C:\Program Files\Panda Security\Panda Global Protection 2010\PavFnSvr.exe – (PAVFNSVR)
SRV - [2009/04/18 01:36:45 | 00,182,768 | —- | M] (Google) [On_Demand | Stopped] – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc)
SRV - [2009/04/17 18:01:12 | 00,247,152 | —- | M] () [Auto | Running] – C:\Program Files\CyberLink\Shared files\RichVideo.exe – (RichVideo) Cyberlink RichVideo Service(CRVS)
SRV - [2009/04/17 11:17:24 | 00,157,440 | —- | M] (Panda Security, S.L.) [Auto | Running] – C:\Program Files\Panda Security\Panda Global Protection 2010\TPSrv.exe – (TPSrv)
SRV - [2009/04/08 11:56:24 | 00,226,560 | —- | M] (Panda Security International) [Auto | Running] – c:\program files\panda security\panda global protection 2010\firewall\PSHOST.EXE – (PSHost)
SRV - [2008/07/02 15:09:36 | 00,060,160 | —- | M] (Panda Security, S.L.) [Auto | Running] – C:\Program Files\Panda Security\Panda Global Protection 2010\GWMsrv.dll – (Gwmsrv)
SRV - [2008/06/19 13:59:50 | 00,108,288 | —- | M] (Panda Security S.L.) [Auto | Running] – C:\Program Files\Panda Security\Panda Global Protection 2010\PsImSvc.exe – (PSIMSVC)
SRV - [2008/03/30 10:36:30 | 00,504,104 | —- | M] (Apple Inc.) [Disabled | Stopped] – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service)
SRV - [2007/03/12 13:49:46 | 00,271,920 | —- | M] (Nero AG) [Disabled | Stopped] – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe – (NMIndexingService)
SRV - [2007/03/07 22:44:07 | 00,039,936 | —- | M] (C-Dilla Ltd) [Auto | Running] – C:\WINDOWS\system32\drivers\CDAC11BA.EXE – (C-DillaCdaC11BA)
SRV - [2007/02/24 10:18:52 | 00,068,096 | —- | M] () [On_Demand | Stopped] – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe – (Adobe LM Service)
SRV - [2006/10/26 19:49:34 | 00,441,136 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv)
SRV - [2006/10/26 14:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose)
SRV - [2006/09/11 19:59:28 | 00,172,032 | —- | M] () [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe – (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2006/09/11 19:56:02 | 00,135,227 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe – (nSvcIp)
SRV - [2006/09/11 19:55:42 | 00,065,599 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe – (nSvcLog)
SRV - [2006/04/13 16:14:26 | 00,020,543 | —- | M] (Apache Software Foundation) [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe – (ForcewareWebInterface)
SRV - [2005/10/10 14:49:00 | 00,131,139 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\WINDOWS\system32\nvsvc32.exe – (NVSvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Running] – – (PavTPK.sys)
DRV - File not found [Kernel | On_Demand | Running] – – (PavSRK.sys)
DRV - File not found [File_System | On_Demand | Running] – – (AvFlt)
DRV - [2010/07/21 16:17:16 | 00,013,880 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\COMFiltr.sys – (ComFiltr)
DRV - [2010/07/01 12:07:30 | 00,166,632 | —- | M] (Trusteer Ltd.) [Kernel | System | Running] – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys – (RapportPG)
DRV - [2010/07/01 12:07:30 | 00,059,240 | —- | M] (Trusteer Ltd.) [Kernel | System | Running] – C:\Program Files\Trusteer\Rapport\bin\RapportKELL.sys – (RapportKELL)
DRV - [2010/02/11 13:02:15 | 00,226,880 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\tcpip6.sys – (Tcpip6)
DRV - [2009/10/01 08:44:52 | 00,047,360 | —- | M] (VSO Software) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pcouffin.sys – (pcouffin)
DRV - [2009/10/01 00:07:44 | 00,075,016 | —- | M] (Panda Security, S.L.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\APPFLT.SYS – (APPFLT)
DRV - [2009/09/23 13:55:23 | 00,064,288 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd)
DRV - [2009/09/09 11:29:18 | 00,199,432 | —- | M] (Panda Security, S.L.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\neti1639.sys – (NETIMFLT01060039)
DRV - [2009/07/23 12:57:22 | 00,102,528 | R— | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ewusbmdm.sys – (hwdatacard)
DRV - [2009/06/30 11:37:16 | 00,028,552 | —- | M] (Panda Security, S.L.) [File_System | Boot | Running] – C:\WINDOWS\system32\Drivers\pavboot.sys – (pavboot)
DRV - [2009/06/16 14:33:02 | 00,046,728 | —- | M] (Panda Security, S.L.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\wnmflt.sys – (WNMFLT)
DRV - [2009/06/16 14:33:00 | 00,159,112 | —- | M] (Panda Security, S.L.) [TDI Layer] [Kernel | System | Running] – C:\WINDOWS\system32\drivers\NETFLTDI.SYS – (NETFLTDI)
DRV - [2009/06/16 14:32:58 | 00,193,800 | —- | M] (Panda Security, S.L.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\idsflt.sys – (IDSFLT)
DRV - [2009/06/16 14:32:58 | 00,053,128 | —- | M] (Panda Security, S.L.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\dsaflt.sys – (DSAFLT)
DRV - [2009/05/09 01:14:20 | 00,014,736 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nuidfltr.sys – (NuidFltr)
DRV - [2008/04/28 19:09:46 | 00,051,072 | —- | M] (PCTools Research Pty Ltd.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ikhlayer.sys – (ikhlayer)
DRV - [2008/04/28 19:09:45 | 00,030,592 | —- | M] (PCTools Research Pty Ltd.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\ikhfile.sys – (ikhfile)
DRV - [2008/04/28 18:35:14 | 00,084,024 | —- | M] (Panda Security, S.L.) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\pavdrv51.sys – (PAVDRV)
DRV - [2008/04/13 19:45:29 | 00,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2008/04/13 19:45:12 | 00,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\usbaudio.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 17:36:05 | 00,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2008/03/28 12:25:06 | 00,022,072 | —- | M] (Panda Security, S.L.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\fnetmon.sys – (FNETMON)
DRV - [2008/01/29 12:01:28 | 00,016,168 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2007/11/15 21:30:48 | 00,034,064 | —- | M] (CACE Technologies) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\npf.sys – (npf)
DRV - [2007/11/13 11:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv)
DRV - [2007/10/12 14:07:10 | 00,055,808 | —- | M] (The SHVPN Project) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\tap0801.sys – (tap0801)
DRV - [2007/01/31 14:33:46 | 00,005,632 | —- | M] (GRISOFT, s.r.o.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\avgarkt.sys – (AVG Anti-Rootkit)
DRV - [2007/01/18 13:00:28 | 00,003,968 | —- | M] (GRISOFT, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AvgArCln.sys – (AvgArCln)
DRV - [2007/01/16 02:09:06 | 00,293,888 | R— | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ADIHdAud.sys – (ADIHdAudAddService)
DRV - [2006/09/11 12:45:38 | 00,019,968 | R— | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nvnetbus.sys – (nvnetbus)
DRV - [2006/09/11 12:45:36 | 00,057,856 | R— | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\NVENETFD.sys – (NVENETFD)
DRV - [2006/09/11 12:45:26 | 00,110,592 | R— | M] (NVIDIA Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\nvtcp.sys – (NVTCP)
DRV - [2006/08/21 11:24:28 | 00,105,344 | R— | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\nvata.sys – (nvata)
DRV - [2006/08/06 23:57:30 | 00,093,952 | R— | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\aeaudio.sys – (AEAudio)
DRV - [2006/03/17 10:18:58 | 00,392,960 | R— | M] (Sensaura) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\senfilt.sys – (SenFiltService)
DRV - [2005/10/10 14:49:00 | 03,530,432 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2005/07/15 10:40:36 | 03,640,000 | R— | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005/05/17 18:45:12 | 00,076,288 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\nvraid.sys – (nvraid) NVIDIA nForce™
DRV - [2005/05/17 10:45:08 | 00,092,800 | R— | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\nvatabus.sys – (nvatabus)
DRV - [2004/08/13 03:56:20 | 00,005,810 | R— | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ASACPI.sys – (MTsensor)
DRV - [2004/08/03 23:41:56 | 00,011,868 | —- | M] (Conexant) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\mdmxsdk.sys – (mdmxsdk)
DRV - [2004/06/03 09:50:07 | 00,020,352 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\point32.sys – (Point32)
DRV - [2002/11/18 15:29:26 | 00,399,700 | —- | M] (NVIDIA Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\dumant.sys – (DumaNT)
DRV - [2002/08/29 13:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink)
DRV - [2002/06/26 10:06:50 | 00,875,191 | —- | M] (Conexant) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\WINACHCF.sys – (Winachcf)
DRV - [2002/04/11 15:21:38 | 00,013,335 | R— | M] (Microsystems Corp) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\usbcm.sys – (usbcm)
DRV - [2001/08/17 15:00:04 | 00,002,944 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\msmpu401.sys – (ms_mpu401)
DRV - [2001/08/17 13:57:38 | 00,016,128 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\MODEMCSA.sys – (MODEMCSA)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk"
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.98
FF - prefs.js..extensions.enabledItems: [removed]:1.3.2
FF - prefs.js..extensions.enabledItems: {0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.80
FF - prefs.js..extensions.enabledItems: {a880aeee-06f6-48e7-87c5-876fb64a2a56}:0.70
FF - prefs.js..extensions.enabledItems: {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {c2b1f3ae-5cd5-49b7-8a0c-2c3bcbbbb294}:1.1
FF - prefs.js..extensions.enabledItems: [removed]:2
FF - prefs.js..extensions.enabledItems: 4
FF - prefs.js..extensions.enabledItems: 9
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0.17
FF - prefs.js..extensions.enabledItems: {7CEA821D-3DAB-4238-B424-BF7324531750}:0.4.95
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2009/04/19 14:00:31 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/21 16:10:53 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/21 16:10:52 | 00,000,000 | —D | M]
[2009/12/14 16:26:49 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Extensions
[2009/12/14 16:26:49 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Extensions\[removed]
[2010/07/20 23:28:14 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions
[2009/12/19 20:34:55 | 00,000,000 | —D | M] (FireShot) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2009/12/19 20:35:08 | 00,000,000 | —D | M] (SeoQuake) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
[2009/06/20 11:47:29 | 00,000,000 | —D | M] (ChatZilla) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2010/05/31 18:08:12 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{7CEA821D-3DAB-4238-B424-BF7324531750}
[2010/06/10 14:43:52 | 00,000,000 | —D | M] (iMacros for Firefox) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
[2009/06/16 20:42:33 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{a880aeee-06f6-48e7-87c5-876fb64a2a56}
[2009/03/05 12:23:38 | 00,000,000 | —D | M] (Google Global) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{B97F57B9-1B42-4aed-9475-0022600C62DC}
[2009/05/24 14:25:02 | 00,000,000 | —D | M] (Article Marketing Impact) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{BFB5F154-9212-46F3-B547-AC6106030A54}
[2010/03/17 16:48:15 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{c2b1f3ae-5cd5-49b7-8a0c-2c3bcbbbb294}
[2009/09/22 09:05:20 | 00,000,000 | —D | M] (Clipmarks) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{e1170235-2845-420c-acc3-42261a29dd46}
[2009/06/16 13:36:46 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{ec9CEB59-8266-438b-91D9-82F56D595E15}
[2010/04/17 00:17:24 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{fae5bcbc-dd73-439a-a15e-5b9ff39c0e9b}
[2009/12/19 20:34:46 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]
[2009/12/16 02:11:55 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]
[2008/11/05 20:30:01 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]
[2009/03/06 23:01:42 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]
[2010/03/08 10:46:43 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]
[2009/06/20 11:47:46 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]
[2010/05/15 14:43:44 | 00,000,000 | —D | M] – C:\Documents and Settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]
[2010/07/20 16:35:34 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/17 12:12:54 | 00,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/17 12:12:42 | 00,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/16 01:55:13 | 00,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/01/16 01:55:13 | 00,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/01/16 01:55:13 | 00,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/01/16 01:55:13 | 00,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: (736 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (KTBho Class) - {25EDC164-41A6-47C3-80BD-5E4FBE1BA7AB} - C:\Program Files\kaboodle\Kaboodle IE Toolbar\KTBar.dll ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (PCTools Site Guard) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\Program Files\Spyware Doctor\tools\iesdsg.dll (PC Tools)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (PCTools Browser Monitor) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\Program Files\Spyware Doctor\tools\iesdpb.dll (PC Tools)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Kaboodle Toolbar) - {92857633-2441-4A14-8236-DFCB97AD3E87} - C:\Program Files\kaboodle\Kaboodle IE Toolbar\KTBar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APVXDWIN] C:\Program Files\Panda Security\Panda Global Protection 2010\APVXDWIN.EXE (Panda Security, S.L.)
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\point32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SCANINICIO] C:\Program Files\Panda Security\Panda Global Protection 2010\Inicio.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [type32] C:\Program Files\Microsoft IntelliType Pro\type32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [UpdatePDRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - File not found
O9 - Extra Button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\Program Files\Spyware Doctor\tools\iesdpb.dll (PC Tools)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O9 - Extra 'Tools' menuitem : Add to &VideoGet; - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Expression\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} http://download.microsoft.com/download/7/4…helpcontrol.cab (Microsoft Genuine Advantage Self Support Tool)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1172259541828 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avldr: DllName - avldr.dll - C:\WINDOWS\System32\avldr.dll (Panda Security, S.L.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/02/23 19:46:58 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{43792500-3684-11df-94d4-001e8c709532}\Shell - "" = AutoRun
O33 - MountPoints2\{43792500-3684-11df-94d4-001e8c709532}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{43792500-3684-11df-94d4-001e8c709532}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe – File not found
O33 - MountPoints2\{43792501-3684-11df-94d4-001e8c709532}\Shell - "" = AutoRun
O33 - MountPoints2\{43792501-3684-11df-94d4-001e8c709532}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{43792501-3684-11df-94d4-001e8c709532}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe – File not found
O33 - MountPoints2\{b11f0d38-36d7-11df-94d5-001e8c709532}\Shell - "" = AutoRun
O33 - MountPoints2\{b11f0d38-36d7-11df-94d5-001e8c709532}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{b11f0d38-36d7-11df-94d5-001e8c709532}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe – File not found
O33 - MountPoints2\{b11f0d39-36d7-11df-94d5-001e8c709532}\Shell - "" = AutoRun
O33 - MountPoints2\{b11f0d39-36d7-11df-94d5-001e8c709532}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{b11f0d39-36d7-11df-94d5-001e8c709532}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/07/21 17:13:36 | 00,000,000 | RHSD | C] – C:\WINDOWS\PSICache
[2010/07/21 16:11:01 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Panda Security
[2010/07/20 20:32:49 | 00,000,000 | —D | C] – C:\Documents and Settings\adam\Desktop\Virus Removal Tool
[2010/07/14 07:56:51 | 00,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/07/08 09:17:38 | 00,000,000 | —D | C] – C:\Documents and Settings\adam\Application Data\acccore
[2010/07/08 09:17:36 | 00,000,000 | —D | C] – C:\Documents and Settings\adam\Local Settings\Application Data\AOL
[2010/07/08 09:17:36 | 00,000,000 | —D | C] – C:\Documents and Settings\adam\Local Settings\Application Data\AIM
[2010/07/08 09:17:28 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AIM
[2010/07/08 09:17:22 | 00,000,000 | —D | C] – C:\Program Files\AIM
[2010/07/08 09:17:19 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Software Update Utility
[2010/07/08 09:17:18 | 00,000,000 | —D | C] – C:\Program Files\Common Files\AOL
[2010/07/01 08:18:03 | 00,000,000 | —D | C] – C:\WINDOWS\System32\Adobe
[2010/04/21 12:45:53 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Trusteer
[2010/03/29 11:56:47 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Trusteer
[2010/03/23 15:00:21 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Vodafone
[2009/10/01 08:44:52 | 00,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\adam\Application Data\pcouffin.sys
[2009/01/07 10:37:41 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Panda Software
[2008/02/08 00:39:00 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2007/05/26 09:00:54 | 00,594,800 | —- | C] (Softnik Technologies ) – C:\Program Files\gkwv2_setup.exe
[2007/05/24 21:04:34 | 14,279,822 | —- | C] (SoftwareClub.ws ) – C:\Program Files\scvc6000.exe
[2007/03/06 09:50:42 | 02,683,984 | —- | C] (Piriform Ltd) – C:\Program Files\ccsetup137.exe
[2007/03/06 09:39:12 | 11,352,928 | —- | C] (PC Tools ) – C:\Program Files\spydocsetup.exe
[2007/02/25 10:52:01 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2007/02/24 20:25:45 | 33,170,212 | —- | C] ( ) – C:\Program Files\klmcodec165.exe
[2007/02/24 10:52:20 | 01,145,896 | —- | C] (Google) – C:\Program Files\GoogleToolbarInstaller.exe
[2007/02/24 08:55:26 | 25,755,448 | —- | C] (Microsoft Corporation) – C:\Program Files\wmp11-windowsxp-x86-enu.exe
[2007/02/23 21:40:06 | 24,265,736 | —- | C] (Microsoft) – C:\Program Files\dotnetfx.exe
[2007/02/23 21:00:11 | 21,822,168 | —- | C] ( ) – C:\Program Files\AdbeRdr80_en_US.exe
[2007/02/23 20:56:15 | 36,808,256 | —- | C] (Apple Computer, Inc.) – C:\Program Files\iTunesSetup.exe
[2007/02/23 20:03:01 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/02/23 19:51:49 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2007/02/23 19:46:46 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
========== Files - Modified Within 30 Days ==========
[2010/07/21 17:19:27 | 00,008,627 | —- | M] () – C:\WINDOWS\System32\PAV_FOG.OPC
[2010/07/21 17:13:47 | 00,348,452 | —- | M] () – C:\WINDOWS\System32\drivers\APPFCONT.DAT.bck
[2010/07/21 17:13:47 | 00,348,452 | —- | M] () – C:\WINDOWS\System32\drivers\APPFCONT.DAT
[2010/07/21 17:07:54 | 00,002,445 | —- | M] () – C:\Documents and Settings\adam\Desktop\HiJackThis.lnk
[2010/07/21 16:45:32 | 00,000,522 | —- | M] () – C:\WINDOWS\System32\drivers\etc\pfdnnt.act
[2010/07/21 16:20:30 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/07/21 16:20:30 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2010/07/21 16:20:30 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2010/07/21 16:20:30 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2010/07/21 16:20:30 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2010/07/21 16:19:23 | 00,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{CF5E3D8D-1EED-4D74-931D-56B0FEE9941C}.job
[2010/07/21 16:17:31 | 00,001,132 | —- | M] () – C:\WINDOWS\System32\drivers\APPFLTR.CFG.bck
[2010/07/21 16:17:31 | 00,001,132 | —- | M] () – C:\WINDOWS\System32\drivers\APPFLTR.CFG
[2010/07/21 16:17:31 | 00,000,252 | —- | M] () – C:\WINDOWS\System32\drivers\etc\IdsFlt.cfg.bck
[2010/07/21 16:17:31 | 00,000,252 | —- | M] () – C:\WINDOWS\System32\drivers\etc\IdsFlt.cfg
[2010/07/21 16:17:31 | 00,000,152 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetLoc.wlt.bck
[2010/07/21 16:17:31 | 00,000,152 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetLoc.wlt
[2010/07/21 16:17:31 | 00,000,068 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetFlt.cfg.bck
[2010/07/21 16:17:31 | 00,000,068 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetFlt.cfg
[2010/07/21 16:17:31 | 00,000,056 | —- | M] () – C:\WINDOWS\System32\drivers\etc\WnmFlt.cfg.bck
[2010/07/21 16:17:31 | 00,000,056 | —- | M] () – C:\WINDOWS\System32\drivers\etc\WnmFlt.cfg
[2010/07/21 16:17:31 | 00,000,056 | —- | M] () – C:\WINDOWS\System32\drivers\etc\DsaFlt.cfg.bck
[2010/07/21 16:17:31 | 00,000,056 | —- | M] () – C:\WINDOWS\System32\drivers\etc\DsaFlt.cfg
[2010/07/21 16:17:30 | 00,447,324 | —- | M] () – C:\WINDOWS\System32\drivers\etc\DsaFlt.rls.bck
[2010/07/21 16:17:30 | 00,447,324 | —- | M] () – C:\WINDOWS\System32\drivers\etc\DsaFlt.rls
[2010/07/21 16:17:16 | 00,013,880 | —- | M] () – C:\WINDOWS\System32\drivers\COMFiltr.sys
[2010/07/21 16:16:36 | 00,039,291 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/07/21 16:15:38 | 00,000,120 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetAdapt.cfg.bck
[2010/07/21 16:15:38 | 00,000,120 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetAdapt.cfg
[2010/07/21 16:15:38 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetAR.wlt.bck
[2010/07/21 16:15:38 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\etc\NetAR.wlt
[2010/07/21 16:15:35 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/21 16:13:26 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/21 16:13:10 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/07/21 15:36:22 | 00,008,627 | —- | M] () – C:\Documents and Settings\adam\PAV_FOG.OPC
[2010/07/21 09:56:44 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/07/21 00:17:16 | 00,485,302 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/07/21 00:17:16 | 00,089,450 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/07/21 00:10:52 | 00,000,262 | —- | M] () – C:\WINDOWS\System32\PavCPL.dat
[2010/07/21 00:10:47 | 00,000,492 | —- | M] () – C:\WINDOWS\tasks\Basic clean-up.job
[2010/07/19 19:52:52 | 09,957,376 | —- | M] () – C:\Documents and Settings\adam\ntuser.dat
[2010/07/19 18:43:36 | 00,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/07/19 14:59:59 | 00,000,668 | —- | M] () – C:\Documents and Settings\adam\Application Data\vso_ts_preview.xml
[2010/07/19 13:48:55 | 00,185,344 | —- | M] () – C:\Documents and Settings\adam\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/19 13:34:15 | 00,000,699 | —- | M] () – C:\Documents and Settings\adam\Desktop\Shortcut to scrapebox.lnk
[2010/07/17 11:05:44 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/07/12 23:08:59 | 00,000,695 | —- | M] () – C:\WINDOWS\win.ini
[2010/07/12 23:08:59 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/07/12 23:08:59 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2010/07/08 11:24:40 | 20,434,768 | —- | M] () – C:\Documents and Settings\adam\Desktop\Images.zip
[2010/07/08 09:17:36 | 00,000,361 | -H– | M] () – C:\IPH.PH
[2010/07/08 09:17:27 | 00,001,574 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AIM.lnk
[2010/06/29 20:21:27 | 00,002,497 | —- | M] () – C:\Documents and Settings\adam\Desktop\Microsoft Office Word 2003.lnk
[2010/06/24 08:38:49 | 00,564,552 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
========== Files Created - No Company Name ==========
[2010/07/21 00:10:52 | 00,000,262 | —- | C] () – C:\WINDOWS\System32\PavCPL.dat
[2010/07/21 00:10:46 | 00,000,492 | —- | C] () – C:\WINDOWS\tasks\Basic clean-up.job
[2010/07/19 19:52:51 | 09,957,376 | —- | C] () – C:\Documents and Settings\adam\ntuser.dat
[2010/07/19 13:34:15 | 00,000,699 | —- | C] () – C:\Documents and Settings\adam\Desktop\Shortcut to scrapebox.lnk
[2010/07/10 12:00:26 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/07/10 12:00:26 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/07/08 11:20:07 | 20,434,768 | —- | C] () – C:\Documents and Settings\adam\Desktop\Images.zip
[2010/07/08 09:17:27 | 00,001,574 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AIM.lnk
[2010/07/08 09:17:06 | 00,000,361 | -H– | C] () – C:\IPH.PH
[2010/04/14 20:46:08 | 00,011,774 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\2754096141
[2010/04/14 20:46:08 | 00,011,774 | -HS- | C] () – C:\Documents and Settings\adam\Local Settings\Application Data\2754096141
[2010/04/14 20:46:07 | 00,011,782 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\3769731055
[2010/04/14 20:46:07 | 00,011,782 | -HS- | C] () – C:\Documents and Settings\adam\Local Settings\Application Data\3769731055
[2010/04/14 20:41:08 | 00,011,750 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\6Y5qPA2XU80
[2010/04/14 20:41:08 | 00,011,750 | -HS- | C] () – C:\Documents and Settings\adam\Local Settings\Application Data\6Y5qPA2XU80
[2010/01/08 13:08:45 | 00,013,880 | —- | C] () – C:\WINDOWS\System32\drivers\COMFiltr.sys
[2009/11/17 14:46:46 | 00,000,091 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/10/16 08:51:23 | 00,000,038 | —- | C] () – C:\WINDOWS\AviSplitter.INI
[2009/10/01 08:45:18 | 00,000,668 | —- | C] () – C:\Documents and Settings\adam\Application Data\vso_ts_preview.xml
[2009/10/01 08:44:58 | 00,000,034 | —- | C] () – C:\Documents and Settings\adam\Application Data\pcouffin.log
[2009/10/01 08:44:52 | 00,087,608 | —- | C] () – C:\Documents and Settings\adam\Application Data\inst.exe
[2009/10/01 08:44:52 | 00,007,887 | —- | C] () – C:\Documents and Settings\adam\Application Data\pcouffin.cat
[2009/10/01 08:44:52 | 00,001,144 | —- | C] () – C:\Documents and Settings\adam\Application Data\pcouffin.inf
[2008/09/04 20:51:02 | 01,069,056 | —- | C] () – C:\WINDOWS\System32\libmySQL.dll
[2008/07/12 01:29:13 | 00,000,082 | —- | C] () – C:\WINDOWS\DeliveryReader.INI
[2008/03/31 17:19:19 | 00,032,834 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/03/31 13:31:36 | 00,000,804 | R— | C] () – C:\WINDOWS\System32\AsusSetup.ini
[2008/02/04 18:23:10 | 00,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2008/01/04 17:16:38 | 00,888,832 | —- | C] () – C:\WINDOWS\System32\securenet.dll
[2007/11/11 16:20:10 | 00,000,000 | —- | C] () – C:\WINDOWS\msicpl.ini
[2007/05/25 15:42:18 | 14,659,071 | —- | C] () – C:\Program Files\KE_setup13143.exe
[2007/05/25 15:40:47 | 01,585,247 | —- | C] () – C:\Program Files\SEOE_setup4081.exe
[2007/05/24 21:09:26 | 00,237,568 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2007/05/23 16:27:32 | 09,389,672 | —- | C] () – C:\Program Files\winzip111.exe
[2007/05/21 18:54:06 | 64,625,683 | —- | C] () – C:\Program Files\xsiteprosetup.exe
[2007/03/10 10:04:48 | 00,001,353 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/03/07 23:00:47 | 00,096,768 | —- | C] () – C:\WINDOWS\SlantAdj.dll
[2007/03/07 23:00:47 | 00,000,072 | —- | C] () – C:\WINDOWS\System32\epDPE.ini
[2007/03/07 22:48:04 | 00,000,029 | —- | C] () – C:\WINDOWS\DEBUGSM.INI
[2007/03/07 22:40:06 | 00,000,022 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2007/03/07 22:39:10 | 00,000,025 | —- | C] () – C:\WINDOWS\CDE P242580EF.ini
[2007/03/02 21:47:51 | 00,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/02/28 01:03:19 | 19,987,4112 | —- | C] () – C:\Program Files\Nero-7.7.5.1_eng_trial.exe
[2007/02/24 20:26:50 | 00,815,104 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2007/02/24 20:26:50 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2007/02/24 20:26:49 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/02/24 20:26:49 | 00,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007/02/24 20:26:48 | 00,084,480 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2007/02/24 19:20:59 | 00,411,509 | —- | C] () – C:\Program Files\GSpot270a.zip
[2007/02/24 18:52:16 | 06,241,753 | —- | C] () – C:\Program Files\XP-Codec-Pack-2.0.6.zip
[2007/02/24 18:47:43 | 00,185,344 | —- | C] () – C:\Documents and Settings\adam\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/24 18:41:27 | 05,134,848 | —- | C] () – C:\Program Files\SVCD2DVDv2.msi
[2007/02/24 18:38:27 | 00,000,127 | —- | C] () – C:\Documents and Settings\adam\Local Settings\Application Data\fusioncache.dat
[2007/02/24 11:46:28 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/02/24 09:24:54 | 00,060,640 | —- | C] () – C:\Program Files\AC3ACM.zip
[2007/02/24 09:23:39 | 01,045,001 | —- | C] () – C:\Program Files\VirtualDub-MPEG2.zip
[2007/02/24 09:07:07 | 01,094,021 | —- | C] () – C:\Program Files\dvdshrink32setup1.zip
[2007/02/23 21:44:50 | 01,201,041 | —- | C] () – C:\Program Files\winrar.exe
[2007/02/23 21:38:59 | 05,968,384 | —- | C] () – C:\Program Files\SVCD2DVD.msi
[2007/02/23 20:25:06 | 00,006,656 | —- | C] () – C:\WINDOWS\System32\CNMVS5m.DLL
[2007/02/23 20:20:55 | 00,156,672 | R— | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2007/02/23 20:18:46 | 00,000,269 | R— | C] () – C:\WINDOWS\System32\raidmgmt.ini
[2007/02/23 20:18:31 | 00,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2007/02/23 20:18:28 | 00,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/02/23 20:08:19 | 00,009,728 | R— | C] () – C:\WINDOWS\System32\sysinfoX64.sys
[2007/02/23 20:08:19 | 00,008,192 | R— | C] () – C:\WINDOWS\System32\sysinfo.sys
[2006/05/02 23:38:24 | 00,000,748 | —- | C] () – C:\WINDOWS\SetBrowser.ini
[2006/04/23 00:00:10 | 00,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2005/10/10 14:49:00 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005/10/10 14:49:00 | 01,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/10/10 14:49:00 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2005/10/10 14:49:00 | 00,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005/10/10 14:49:00 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/10/10 14:49:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2005/10/10 14:49:00 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2003/01/07 16:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/11/18 15:29:28 | 00,368,640 | —- | C] () – C:\WINDOWS\System32\nvimage.dll
[2002/11/18 15:29:28 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\stereoi.dll
[2002/08/29 13:00:00 | 01,287,680 | —- | C] () – C:\WINDOWS\System32\quartz(2).dll
[2002/08/29 13:00:00 | 00,498,205 | —- | C] () – C:\WINDOWS\System32\dxmasf(2).dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 161 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B63300D1
< End of report >