This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Keylogger/Viruse/Trojan? =(

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I recently went through the instructions on this website to remove what I thought was a key logger from my system, and I believe it had worked. However, when signing in to my hotmail account yesterday, I noticed someone had read my junk mail, and a few of my deleted emails had been deleted permanantly. I logged in once more today to find yet more of my deleted emails were gone, and Hotmail doesnt have any automatic delete feature I am aware of, not autoreading junk mail. The only thing I can think of is someone has been on my hotmail, and no one would possibly know my password. But I have not typed it in since I had it changed after I thought the key logger was removed? How could someone have got hold of it…..If I didnt remove the key logger before, why would they wait this long and then just delete some emails? Would you mind having a look over these scans please, and let me know if theres anything obviously wrong and anyway i can solve it please? Thanks very much!


This is the Hijack this scan results.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:10:12, on 21/09/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe
C:\Program Files\Toshiba TEMPRO\TemproTray.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\CurseClient.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Users\jamie\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100916142404.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
O4 - HKLM\..\Run: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
O4 - HKLM\..\Run: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
O4 - HKLM\..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
O4 - HKLM\..\Run: [NetFxUpdate_v1.1.4322] "C:\Windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe" 1 v1.1.4322 GAC + NI NID
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'Default user')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Startup: CurseClientStartup.ccip
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: TOSHIBA Modem region select service (RSELSVC) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe

–
End of file - 8896 bytes




This is the OTL scan results.

OTL logfile created on: 9/21/2010 4:04:55 PM - Run 2
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Users\jamie\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 71.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 116.29 Gb Total Space | 66.75 Gb Free Space | 57.40% Space Free | Partition Type: NTFS
Drive D: | 116.21 Gb Total Space | 110.68 Gb Free Space | 95.25% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BOBDAVE
Current User Name: jamie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\jamie\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\CurseClient.exe (Curse)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\ConfigFree\CFIWmxSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
PRC - C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (Toshiba Europe GmbH)
PRC - C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSENotify.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Toshiba\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Toshiba\RSelect\RSelSvc.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\jamie\Downloads\OTL.exe (OldTimer Tools)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\Program Files\Common Files\Mcafee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (aspnet_state) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetTcpActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetPipeActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetMsmqActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (TMachInfo) – C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (cfWiMAXService) – C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe (TOSHIBA CORPORATION)
SRV - (TemproMonitoringService) Notebook Performance Tuning Service (TEMPRO) – C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (Toshiba Europe GmbH)
SRV - (TosCoSrv) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (RSELSVC) – C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe (TOSHIBA Corporation)
SRV - (HsfXAudioService) – C:\Windows\System32\XAudio32.dll (Conexant Systems, Inc.)
SRV - (ConfigFree Service) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)


========== Driver Services (SafeList) ==========

DRV - (USBCCID) – C:\Windows\System32\DRIVERS\RtsUCcid.sys File not found
DRV - (RtsUIR) – C:\Windows\System32\DRIVERS\Rts516xIR.sys File not found
DRV - (RSUSBSTOR) – C:\Windows\System32\Drivers\RtsUStor.sys File not found
DRV - (catchme) – C:\Users\jamie\AppData\Local\Temp\catchme.sys File not found
DRV - (mfehidk) – C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfewfpk) – C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfenlfk) – C:\Windows\System32\drivers\mfenlfk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\Windows\System32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\Windows\System32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (RTL8167) – C:\Windows\System32\drivers\Rt86win7.sys (Realtek )
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (RTL8187B) – C:\Windows\System32\drivers\RTL8187B.sys (Realtek Semiconductor Corporation )
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (tos_sps32) – C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwififlt) – C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\system32\DRIVERS\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) – C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\System32\drivers\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (SrvHsfV92) – C:\Windows\System32\drivers\VSTDPV3.SYS (Conexant Systems, Inc.)
DRV - (SrvHsfWinac) – C:\Windows\System32\drivers\VSTCNXT3.SYS (Conexant Systems, Inc.)
DRV - (SrvHsfHDA) – C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (FwLnk) – C:\Windows\system32\DRIVERS\FwLnk.sys (TOSHIBA Corporation)
DRV - (RTHDMIAzAudService) – C:\Windows\System32\drivers\RtHDMIV.sys (Realtek Semiconductor Corp.)
DRV - (PGEffect) – C:\Windows\System32\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\system32\DRIVERS\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio32.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.defaultthis.engineName: "ooVoo Chat Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1572363&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.1
FF - prefs.js..keyword.URL: "http://uk.search.yahoo.com/search?fr=mcafee&p;="

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/09/15 23:19:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/16 14:24:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/23 13:48:08 | 000,000,000 | —D | M]

[2010/01/13 10:55:48 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Mozilla\Extensions
[2009/11/15 02:18:38 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/02/13 21:17:59 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Mozilla\Firefox\Profiles\e1ix0fhw.default\extensions
[2009/10/06 19:07:30 | 000,000,882 | —- | M] () – C:\Users\jamie\AppData\Roaming\Mozilla\Firefox\Profiles\e1ix0fhw.default\searchplugins\conduit.xml
[2010/04/25 18:13:56 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/08/24 14:57:38 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\Mozilla Firefox\components\Scriptff.dll
[2010/08/23 13:48:02 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/08/23 13:48:02 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/08/23 13:48:02 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/08/23 13:48:02 | 000,000,831 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/07/29 00:12:15 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20100916142404.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [HSON] C:\Program Files\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NetFxUpdate_v1.1.4322] C:\Windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe (Microsoft)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosNC] C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosSENotify] C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Users\jamie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O4 - Startup: C:\Users\jamie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

========== Files/Folders - Created Within 30 Days ==========

[2010/09/18 13:39:57 | 000,000,000 | —D | C] – C:\Users\jamie\AppData\Local\Adobe
[2010/09/14 00:59:57 | 000,009,344 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeclnk.sys
[2010/09/14 00:59:06 | 000,312,904 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfefirek.sys
[2010/09/14 00:59:06 | 000,164,808 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfewfpk.sys
[2010/09/14 00:59:06 | 000,152,992 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeavfk.sys
[2010/09/14 00:59:06 | 000,084,264 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mferkdet.sys
[2010/09/14 00:59:06 | 000,064,304 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfenlfk.sys
[2010/09/14 00:59:06 | 000,055,840 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\cfwids.sys
[2010/09/14 00:59:06 | 000,052,104 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfebopk.sys
[2010/09/14 00:58:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2010/09/14 00:58:57 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/21 16:09:49 | 003,145,728 | -HS- | M] () – C:\Users\jamie\ntuser.dat
[2010/09/21 16:04:38 | 000,016,304 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/21 16:04:38 | 000,016,304 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/21 15:57:34 | 000,001,795 | —- | M] () – C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2010/09/21 15:57:31 | 000,000,374 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2010/09/21 15:56:47 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/21 15:56:43 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/21 15:56:39 | 2816,864,256 | -HS- | M] () – C:\hiberfil.sys
[2010/09/21 00:01:37 | 006,627,727 | -H– | M] () – C:\Users\jamie\AppData\Local\IconCache.db
[2010/09/19 01:31:12 | 000,771,582 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/09/19 01:31:12 | 000,668,192 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/09/19 01:31:12 | 000,127,954 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/09/14 00:46:35 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{fab405a5-bf8d-11df-817f-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/09/14 00:46:35 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{fab405a5-bf8d-11df-817f-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/09/14 00:46:35 | 000,065,536 | -HS- | M] () – C:\Users\jamie\ntuser.dat{fab405a5-bf8d-11df-817f-001e33fd7fdd}.TM.blf
[2010/09/07 17:33:07 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{77c7126e-ba96-11df-a06d-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/09/07 17:33:07 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{77c7126e-ba96-11df-a06d-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/09/07 17:33:07 | 000,065,536 | -HS- | M] () – C:\Users\jamie\ntuser.dat{77c7126e-ba96-11df-a06d-001e33fd7fdd}.TM.blf
[2010/08/24 14:57:38 | 000,386,712 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfehidk.sys
[2010/08/24 14:57:38 | 000,312,904 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfefirek.sys
[2010/08/24 14:57:38 | 000,164,808 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfewfpk.sys
[2010/08/24 14:57:38 | 000,152,992 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeavfk.sys
[2010/08/24 14:57:38 | 000,095,600 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeapfk.sys
[2010/08/24 14:57:38 | 000,084,264 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mferkdet.sys
[2010/08/24 14:57:38 | 000,064,304 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfenlfk.sys
[2010/08/24 14:57:38 | 000,055,840 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\cfwids.sys
[2010/08/24 14:57:38 | 000,052,104 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfebopk.sys
[2010/08/24 14:57:38 | 000,009,344 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeclnk.sys
[2010/08/23 00:13:04 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{6a7f9efc-ae41-11df-945e-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/08/23 00:13:04 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{6a7f9efc-ae41-11df-945e-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/08/23 00:13:04 | 000,065,536 | -HS- | M] () – C:\Users\jamie\ntuser.dat{6a7f9efc-ae41-11df-945e-001e33fd7fdd}.TM.blf
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/14 01:00:59 | 000,001,795 | —- | C] () – C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2010/09/14 00:24:23 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{fab405a5-bf8d-11df-817f-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/09/14 00:24:23 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{fab405a5-bf8d-11df-817f-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/09/14 00:24:23 | 000,065,536 | -HS- | C] () – C:\Users\jamie\ntuser.dat{fab405a5-bf8d-11df-817f-001e33fd7fdd}.TM.blf
[2010/09/07 16:42:28 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{77c7126e-ba96-11df-a06d-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/09/07 16:42:28 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{77c7126e-ba96-11df-a06d-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/09/07 16:42:28 | 000,065,536 | -HS- | C] () – C:\Users\jamie\ntuser.dat{77c7126e-ba96-11df-a06d-001e33fd7fdd}.TM.blf
[2010/08/23 00:03:28 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{6a7f9efc-ae41-11df-945e-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/08/23 00:03:28 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{6a7f9efc-ae41-11df-945e-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/08/23 00:03:28 | 000,065,536 | -HS- | C] () – C:\Users\jamie\ntuser.dat{6a7f9efc-ae41-11df-945e-001e33fd7fdd}.TM.blf
[2010/02/13 19:51:21 | 000,000,093 | —- | C] () – C:\Users\jamie\AppData\Local\fusioncache.dat
[2010/01/14 12:49:35 | 000,000,000 | —- | C] () – C:\Users\jamie\AppData\Roaming\wklnhst.dat
[2009/12/03 10:27:28 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/11/13 19:14:17 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/10/23 19:29:34 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/07/14 00:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll

========== LOP Check ==========

[2010/07/03 18:14:05 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Amazon
[2010/05/09 20:09:20 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\FOG Downloader
[2010/04/01 03:30:48 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\GetRightToGo
[2010/09/21 15:57:23 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\LimeWire
[2010/07/25 17:23:14 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\OnlineArmor
[2010/01/23 19:49:28 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\ooVoo Details
[2010/07/25 14:41:32 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Simply Super Software
[2010/01/14 12:49:37 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Template
[2010/02/18 16:57:01 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Toshiba
[2010/03/04 02:34:02 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Turbine
[2010/07/25 14:15:47 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Uniblue
[2010/09/18 12:13:41 | 000,032,608 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 22:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 22:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2010/09/21 15:56:39 | 2816,864,256 | -HS- | M] () – C:\hiberfil.sys
[2010/09/21 15:56:41 | 3755,823,104 | -HS- | M] () – C:\pagefile.sys
[2009/09/04 20:04:40 | 000,000,070 | -H– | M] () – C:\SWSTAMP.TXT
[2010/07/25 15:31:59 | 000,184,320 | -H– | M] () – C:\SZKGFS.dat
[2009/12/25 20:14:00 | 000,000,000 | —- | M] () – C:\WindowsLiveMessenger-uccapi-0.uccapilog

< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 02:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/14 02:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/11/11 14:15:20 | 000,000,221 | -HS- | M] () – C:\Users\jamie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/07/28 09:39:25 | 006,153,384 | —- | M] (Malwarebytes Corporation ) – C:\Users\jamie\Desktop\mbam-setup.exe
[2010/07/26 15:47:03 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Users\jamie\Desktop\spybotsd162.exe
[2010/05/18 18:22:48 | 001,766,824 | —- | M] () – C:\Users\jamie\Desktop\SystemCheck_enGB.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-15 14:38:14

========== Alternate Data Streams ==========

@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:CB0AACC9

< End of report >
Hi Jamie,

My name is Blottedisk and I will be helping you with your malware issues. We apologize for the delay in responding to your request for help. Here at WhattheTech we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Options box to the right of your topic title and selecting Track This Topic.
  • Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.
  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice. This may cause a delay in response time, but I will do my best to keep it as short as possible.
The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.

Please bear with me, I will post back to you shortly with instructions.

Thanks :thumbup:
Hi again Jamie


Please change your email passwords from a clean computer. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:

  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps.


You're using LimeWire. These are what we call an optional removal. However, anytime you are running any type of peer-to-peer application, you are more prone to infection by malware, and this is probably how you became infected in the first place. The choice to remove them is entirely up to you, but I would strongly recommend that you do.
If you do not want to, please at least refrain from using any peer-to-peer programs for the remainder of my fix.


Ok, now please follow these steps in order:


Step 1 | Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2


——————————————————————–
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :dir
    C:\Users\jamie\AppData\Local\Apps /s

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


Step 2 | Please go to the following site to scan a file: Virus Total

  • Click on Browse, and upload the following file for analysis:

    • C:\Windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
  • Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
  • If it says already scanned – click "reanalyze now"
  • Please post the results in your next reply.


Please post back with:

SystemLook.txt
VirusTotal results
SystemLook 04.09.10 by jpshortstuff Log created at 20:42 on 25/09/2010 by jamie Administrator - Elevation successful ========== dir ========== C:\Users\jamie\AppData\Local\Apps - Parameters: "/s" —Files— None found. C:\Users\jamie\AppData\Local\Apps\2.0 d—— [15:42 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\Data d—— [15:42 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\Data\76RA7DPD.23K d—— [15:15 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\Data\76RA7DPD.23K\J164QEVG.CKX d—— [15:15 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\Data\76RA7DPD.23K\J164QEVG.CKX\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48 d—— [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\Data\76RA7DPD.23K\J164QEVG.CKX\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\Data d—— [21:06 29/07/2010] AddOnDatabase.dat –a—- 955 bytes [21:07 29/07/2010] [12:19 25/09/2010] CategoryDatabase.dat –a—- 432292 bytes [21:07 29/07/2010] [12:19 25/09/2010] CurseClient.log –a—- 262026 bytes [21:07 29/07/2010] [12:19 25/09/2010] GameDatabase.dat –a—- 16161 bytes [21:07 29/07/2010] [12:19 25/09/2010] GameInstanceDatabase.dat –a—- 4100 bytes [21:07 29/07/2010] [12:19 25/09/2010] NotificationDatabase.dat –a—- 1116 bytes [21:07 29/07/2010] [12:19 25/09/2010] C:\Users\jamie\AppData\Local\Apps\2.0\Data\76RA7DPD.23K\J164QEVG.CKX\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\Data\4.0.0.10 d—— [21:07 29/07/2010] user.config –a—- 1184 bytes [21:07 29/07/2010] [12:19 25/09/2010] C:\Users\jamie\AppData\Local\Apps\2.0\Data\G2M4CYPL.43Q d—— [15:42 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\Data\G2M4CYPL.43Q\3D5RWTNO.T20 d—— [15:42 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\Data\G2M4CYPL.43Q\3D5RWTNO.T20\curs..tion_eee711038731a406_0004.0000_172b37d625a03ec8 d—— [10:12 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\Data\G2M4CYPL.43Q\3D5RWTNO.T20\curs..tion_eee711038731a406_0004.0000_172b37d625a03ec8\Data d—— [10:12 15/06/2010] AddOnDatabase.dat –a—- 13003 bytes [10:12 15/06/2010] [10:12 15/06/2010] CategoryDatabase.dat –a—- 432180 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.ThemePack.dll ——- 35328 bytes [10:12 15/06/2010] [15:45 28/03/2010] CurseClient.log –a—- 263948 bytes [10:12 15/06/2010] [10:12 15/06/2010] GameDatabase.dat –a—- 18511 bytes [10:12 15/06/2010] [10:12 15/06/2010] GameInstanceDatabase.dat –a—- 19960 bytes [10:12 15/06/2010] [10:12 15/06/2010] NotificationDatabase.dat –a—- 1116 bytes [10:12 15/06/2010] [10:12 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\Data\G2M4CYPL.43Q\3D5RWTNO.T20\curs..tion_eee711038731a406_0004.0000_172b37d625a03ec8\Data\4.0.0.10 d—— [10:12 15/06/2010] user.config –a—- 3383 bytes [10:12 15/06/2010] [10:12 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\Data\G2M4CYPL.43Q\3D5RWTNO.T20\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48 d—— [21:24 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\Data\G2M4CYPL.43Q\3D5RWTNO.T20\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\Data d—— [21:24 15/06/2010] AddOnDatabase.dat –a—- 13003 bytes [21:24 15/06/2010] [21:13 28/07/2010] CategoryDatabase.dat –a—- 432212 bytes [21:24 15/06/2010] [21:13 28/07/2010] Curse.CurseClient.ThemePack.dll –a—- 179200 bytes [21:24 15/06/2010] [21:23 12/07/2010] CurseClient.log –a—- 562767 bytes [21:24 15/06/2010] [21:13 28/07/2010] GameDatabase.dat –a—- 18511 bytes [21:24 15/06/2010] [21:13 28/07/2010] GameInstanceDatabase.dat –a—- 19960 bytes [21:24 15/06/2010] [21:13 28/07/2010] NotificationDatabase.dat –a—- 1116 bytes [21:24 15/06/2010] [21:13 28/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\Data\G2M4CYPL.43Q\3D5RWTNO.T20\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\Data\4.0.0.10 d—— [21:24 15/06/2010] user.config –a—- 3518 bytes [21:24 15/06/2010] [21:13 28/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY d—— [23:15 28/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3 d—— [23:15 28/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs…exe_eee711038731a406_0004.0000_none_23379ba02ddddf46 d—— [21:06 29/07/2010] CurseClient.exe.config –a—- 955 bytes [21:06 29/07/2010] [21:04 29/07/2010] GammaJul.LgLcd.Native32.dll –a—- 12288 bytes [21:06 29/07/2010] [21:04 29/07/2010] GammaJul.LgLcd.Native64.dll –a—- 14848 bytes [21:06 29/07/2010] [21:04 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs…exe_eee711038731a406_0004.0000_none_23379ba02ddddf46\ClientIcons d—— [21:06 29/07/2010] CCIP.ico –a—- 285478 bytes [21:06 29/07/2010] [21:04 29/07/2010] CurseClient.ico –a—- 63104 bytes [21:06 29/07/2010] [21:04 29/07/2010] CurseClientTray-Normal.ico –a—- 2862 bytes [21:06 29/07/2010] [21:04 29/07/2010] CurseClientTray-Updates.ico –a—- 2862 bytes [21:06 29/07/2010] [21:04 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..dels_823b3ca1d8c473c0_0001.0000_none_828d8225eff00f16 d—— [21:06 29/07/2010] Curse.ClientService.Models.dll –a—- 32256 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..dons_a7ce87cfdd4ba154_0001.0000_none_88033998b61b4817 d—— [21:06 29/07/2010] Curse.AddOns.dll –a—- 28672 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..hash_8432f15c15e06b4f_0001.0000_none_54bc766006c2d238 d—— [21:06 29/07/2010] Curse.MurmurHash.dll –a—- 4608 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..ient_3cbc29eb0a26dbf9_0004.0000_none_0c5254890c13bfbf d—— [21:06 29/07/2010] CurseClient.exe –a—- 1701888 bytes [21:06 29/07/2010] [21:05 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..ions_7e7f879797d04a51_0001.0000_none_a248efbfe62cb319 d—— [21:06 29/07/2010] Curse.CurseClient.Enumerations.dll –a—- 7680 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..kens_447bcc00e712a048_0001.0000_none_5b0b9063dd0b7ca4 d—— [21:06 29/07/2010] Curse.DownloadSecurity.Tokens.dll –a—- 5632 bytes [21:06 29/07/2010] [21:04 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..mmon_c85bb4cad3a5dfb5_0001.0000_none_590134cd92e07a01 d—— [21:06 29/07/2010] Curse.CurseClient.Common.dll –a—- 276992 bytes [21:06 29/07/2010] [21:05 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..rces_b0514d04fccbdb72_0001.0000_fr-fr_dd2c1cd776e13c74 d—— [21:06 29/07/2010] Curse.CurseClient.Localization.resources.dll –a—- 4608 bytes [21:06 29/07/2010] [21:04 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..rols_00072c358aa93735_0001.0000_none_b9453a0fa2a31513 d—— [21:06 29/07/2010] Curse.CurseClient.Controls.dll –a—- 173056 bytes [21:06 29/07/2010] [21:04 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..tech_aa8c8c3656845a34_0001.0000_none_9f528297112c886a d—— [21:06 29/07/2010] Curse.CurseClient.Logitech.dll –a—- 58880 bytes [21:06 29/07/2010] [21:04 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..tion_b0514d04fccbdb72_0001.0000_none_31aa88590a5e716c d—— [21:06 29/07/2010] Curse.CurseClient.Localization.dll –a—- 35840 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48 d—— [21:06 29/07/2010] Curse.AddOns.dll –a—- 28672 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.AddOns.manifest –a—- 1394 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.ClientService.Models.dll –a—- 32256 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.ClientService.Models.manifest –a—- 1244 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.CurseClient.Common.dll –a—- 276992 bytes [21:06 29/07/2010] [21:05 29/07/2010] Curse.CurseClient.Common.manifest –a—- 5235 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.CurseClient.Common.XmlSerializers.dll –a—- 13312 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.CurseClient.Common.XmlSerializers.manifest –a—- 1079 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.CurseClient.Controls.dll –a—- 173056 bytes [21:06 29/07/2010] [21:04 29/07/2010] Curse.CurseClient.Controls.manifest –a—- 3889 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.CurseClient.Enumerations.dll –a—- 7680 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.CurseClient.Enumerations.manifest –a—- 861 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.CurseClient.Localization.dll –a—- 35840 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.CurseClient.Localization.manifest –a—- 861 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.CurseClient.Logitech.dll –a—- 58880 bytes [21:06 29/07/2010] [21:04 29/07/2010] Curse.CurseClient.Logitech.manifest –a—- 2347 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.dll –a—- 53248 bytes [21:06 29/07/2010] [21:05 29/07/2010] Curse.DownloadSecurity.Tokens.dll –a—- 5632 bytes [21:06 29/07/2010] [21:04 29/07/2010] Curse.DownloadSecurity.Tokens.manifest –a—- 869 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.manifest –a—- 1722 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.MurmurHash.dll –a—- 4608 bytes [21:06 29/07/2010] [21:06 29/07/2010] Curse.MurmurHash.manifest –a—- 655 bytes [21:06 29/07/2010] [21:06 29/07/2010] CurseClient.exe –a—- 1701888 bytes [21:06 29/07/2010] [21:05 29/07/2010] CurseClient.exe.config –a—- 955 bytes [21:06 29/07/2010] [21:04 29/07/2010] CurseClient.exe.manifest –a—- 31794 bytes [21:06 29/07/2010] [21:06 29/07/2010] CurseClient.manifest –a—- 4656 bytes [21:06 29/07/2010] [21:06 29/07/2010] GammaJul.LgLcd.dll –a—- 51712 bytes [21:06 29/07/2010] [21:06 29/07/2010] GammaJul.LgLcd.manifest –a—- 1015 bytes [21:06 29/07/2010] [21:06 29/07/2010] GammaJul.LgLcd.Native32.dll –a—- 12288 bytes [21:06 29/07/2010] [21:04 29/07/2010] GammaJul.LgLcd.Native64.dll –a—- 14848 bytes [21:06 29/07/2010] [21:04 29/07/2010] GammaJul.LgLcd.Wpf.dll –a—- 6656 bytes [21:06 29/07/2010] [21:06 29/07/2010] GammaJul.LgLcd.Wpf.manifest –a—- 1409 bytes [21:06 29/07/2010] [21:06 29/07/2010] ICSharpCode.SharpZipLib.dll –a—- 192512 bytes [21:06 29/07/2010] [21:06 29/07/2010] ICSharpCode.SharpZipLib.manifest –a—- 850 bytes [21:06 29/07/2010] [21:06 29/07/2010] Interop.NetFwTypeLib.dll –a—- 19968 bytes [21:06 29/07/2010] [21:06 29/07/2010] Interop.NetFwTypeLib.manifest –a—- 663 bytes [21:06 29/07/2010] [21:06 29/07/2010] Microsoft.Windows.Shell.dll –a—- 160064 bytes [21:06 29/07/2010] [21:04 29/07/2010] Microsoft.Windows.Shell.manifest –a—- 1415 bytes [21:06 29/07/2010] [21:06 29/07/2010] Win32Interop.dll –a—- 11264 bytes [21:06 29/07/2010] [21:04 29/07/2010] Win32Interop.manifest –a—- 832 bytes [21:06 29/07/2010] [21:06 29/07/2010] WPF.Themes.dll –a—- 79360 bytes [21:06 29/07/2010] [21:06 29/07/2010] WPF.Themes.manifest –a—- 1572 bytes [21:06 29/07/2010] [21:06 29/07/2010] Xceed.Wpf.Controls.dll –a—- 168600 bytes [21:06 29/07/2010] [21:06 29/07/2010] Xceed.Wpf.Controls.manifest –a—- 1591 bytes [21:06 29/07/2010] [21:06 29/07/2010] Xceed.Wpf.DataGrid.dll –a—- 2704024 bytes [21:06 29/07/2010] [21:06 29/07/2010] Xceed.Wpf.DataGrid.manifest –a—- 3283 bytes [21:06 29/07/2010] [21:06 29/07/2010] zlib.net.dll –a—- 69632 bytes [21:06 29/07/2010] [21:06 29/07/2010] zlib.net.manifest –a—- 613 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\ClientIcons d—— [21:06 29/07/2010] CCIP.ico –a—- 285478 bytes [21:06 29/07/2010] [21:04 29/07/2010] CurseClient.ico –a—- 63104 bytes [21:06 29/07/2010] [21:04 29/07/2010] CurseClientTray-Normal.ico –a—- 2862 bytes [21:06 29/07/2010] [21:04 29/07/2010] CurseClientTray-Updates.ico –a—- 2862 bytes [21:06 29/07/2010] [21:04 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\fr-FR d—— [21:06 29/07/2010] Curse.CurseClient.Localization.resources.dll –a—- 4608 bytes [21:06 29/07/2010] [21:04 29/07/2010] Curse.CurseClient.Localization.resources.manifest –a—- 720 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..zers_c85bb4cad3a5dfb5_0001.0000_none_311750f664a5eb21 d—— [21:06 29/07/2010] Curse.CurseClient.Common.XmlSerializers.dll –a—- 13312 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curse_a9ab3e4b97c6f141_0001.0000_none_2639d79cd6d239af d—— [21:06 29/07/2010] Curse.dll –a—- 53248 bytes [21:06 29/07/2010] [21:05 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\gamm…wpf_f3239ab6a2f8f304_0001.0001_none_4082f3cc1e3c6874 d—— [21:06 29/07/2010] GammaJul.LgLcd.Wpf.dll –a—- 6656 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\gamm..glcd_7904f4aa6fca30ba_0001.0001_none_1567cfb883b21611 d—— [21:06 29/07/2010] GammaJul.LgLcd.dll –a—- 51712 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\icsh..plib_08a258a57e9138b3_0000.0055_none_392f0ecbd2490bc8 d—— [21:06 29/07/2010] ICSharpCode.SharpZipLib.dll –a—- 192512 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\inte..elib_c85bb4cad3a5dfb5_0001.0000_none_2de83b338c8598e1 d—— [21:06 29/07/2010] Interop.NetFwTypeLib.dll –a—- 19968 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\manifests d—— [23:15 28/07/2010] curs…exe_eee711038731a406_0004.0000_none_23379ba02ddddf46.cdf-ms –a—- 51060 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs…exe_eee711038731a406_0004.0000_none_23379ba02ddddf46.manifest –a—- 31794 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..dels_823b3ca1d8c473c0_0001.0000_none_828d8225eff00f16.cdf-ms –a—- 3492 bytes [21:06 29/07/2010] [21:07 29/07/2010] curs..dels_823b3ca1d8c473c0_0001.0000_none_828d8225eff00f16.manifest –a—- 1244 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..dons_a7ce87cfdd4ba154_0001.0000_none_88033998b61b4817.cdf-ms –a—- 3932 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..dons_a7ce87cfdd4ba154_0001.0000_none_88033998b61b4817.manifest –a—- 1394 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..hash_8432f15c15e06b4f_0001.0000_none_54bc766006c2d238.cdf-ms –a—- 2104 bytes [21:06 29/07/2010] [21:07 29/07/2010] curs..hash_8432f15c15e06b4f_0001.0000_none_54bc766006c2d238.manifest –a—- 655 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..ient_3cbc29eb0a26dbf9_0004.0000_none_0c5254890c13bfbf.cdf-ms –a—- 12468 bytes [21:06 29/07/2010] [21:07 29/07/2010] curs..ient_3cbc29eb0a26dbf9_0004.0000_none_0c5254890c13bfbf.manifest –a—- 4656 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..ions_7e7f879797d04a51_0001.0000_none_a248efbfe62cb319.cdf-ms –a—- 2580 bytes [21:06 29/07/2010] [21:07 29/07/2010] curs..ions_7e7f879797d04a51_0001.0000_none_a248efbfe62cb319.manifest –a—- 861 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..kens_447bcc00e712a048_0001.0000_none_5b0b9063dd0b7ca4.cdf-ms –a—- 2648 bytes [21:06 29/07/2010] [21:07 29/07/2010] curs..kens_447bcc00e712a048_0001.0000_none_5b0b9063dd0b7ca4.manifest –a—- 869 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..mmon_c85bb4cad3a5dfb5_0001.0000_none_590134cd92e07a01.cdf-ms –a—- 13724 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..mmon_c85bb4cad3a5dfb5_0001.0000_none_590134cd92e07a01.manifest –a—- 5235 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..rces_b0514d04fccbdb72_0001.0000_fr-fr_dd2c1cd776e13c74.cdf-ms –a—- 2312 bytes [21:06 29/07/2010] [21:07 29/07/2010] curs..rces_b0514d04fccbdb72_0001.0000_fr-fr_dd2c1cd776e13c74.manifest –a—- 720 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..rols_00072c358aa93735_0001.0000_none_b9453a0fa2a31513.cdf-ms –a—- 10264 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..rols_00072c358aa93735_0001.0000_none_b9453a0fa2a31513.manifest –a—- 3889 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..tech_aa8c8c3656845a34_0001.0000_none_9f528297112c886a.cdf-ms –a—- 6432 bytes [21:06 29/07/2010] [21:07 29/07/2010] curs..tech_aa8c8c3656845a34_0001.0000_none_9f528297112c886a.manifest –a—- 2347 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..tion_b0514d04fccbdb72_0001.0000_none_31aa88590a5e716c.cdf-ms –a—- 2580 bytes [21:06 29/07/2010] [21:07 29/07/2010] curs..tion_b0514d04fccbdb72_0001.0000_none_31aa88590a5e716c.manifest –a—- 861 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..tion_eee711038731a406_0004.0000_none_63d59c6f0e2d6eb7.cdf-ms –a—- 14956 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..tion_eee711038731a406_0004.0000_none_63d59c6f0e2d6eb7.manifest –a—- 11896 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..zers_c85bb4cad3a5dfb5_0001.0000_none_311750f664a5eb21.cdf-ms –a—- 3120 bytes [21:06 29/07/2010] [21:06 29/07/2010] curs..zers_c85bb4cad3a5dfb5_0001.0000_none_311750f664a5eb21.manifest –a—- 1079 bytes [21:06 29/07/2010] [21:06 29/07/2010] curse_a9ab3e4b97c6f141_0001.0000_none_2639d79cd6d239af.cdf-ms –a—- 4704 bytes [21:06 29/07/2010] [21:07 29/07/2010] curse_a9ab3e4b97c6f141_0001.0000_none_2639d79cd6d239af.manifest –a—- 1722 bytes [21:06 29/07/2010] [21:06 29/07/2010] gamm…wpf_f3239ab6a2f8f304_0001.0001_none_4082f3cc1e3c6874.cdf-ms –a—- 3984 bytes [21:06 29/07/2010] [21:07 29/07/2010] gamm…wpf_f3239ab6a2f8f304_0001.0001_none_4082f3cc1e3c6874.manifest –a—- 1409 bytes [21:06 29/07/2010] [21:06 29/07/2010] gamm..glcd_7904f4aa6fca30ba_0001.0001_none_1567cfb883b21611.cdf-ms –a—- 2996 bytes [21:06 29/07/2010] [21:06 29/07/2010] gamm..glcd_7904f4aa6fca30ba_0001.0001_none_1567cfb883b21611.manifest –a—- 1015 bytes [21:06 29/07/2010] [21:06 29/07/2010] icsh..plib_08a258a57e9138b3_0000.0055_none_392f0ecbd2490bc8.cdf-ms –a—- 2556 bytes [21:06 29/07/2010] [21:07 29/07/2010] icsh..plib_08a258a57e9138b3_0000.0055_none_392f0ecbd2490bc8.manifest –a—- 850 bytes [21:06 29/07/2010] [21:06 29/07/2010] inte..elib_c85bb4cad3a5dfb5_0001.0000_none_2de83b338c8598e1.cdf-ms –a—- 2120 bytes [21:06 29/07/2010] [21:06 29/07/2010] inte..elib_c85bb4cad3a5dfb5_0001.0000_none_2de83b338c8598e1.manifest –a—- 663 bytes [21:06 29/07/2010] [21:06 29/07/2010] micr..hell_31bf3856ad364e35_0003.0000_none_c495b3ffab1bf08e.cdf-ms –a—- 3940 bytes [21:06 29/07/2010] [21:06 29/07/2010] micr..hell_31bf3856ad364e35_0003.0000_none_c495b3ffab1bf08e.manifest –a—- 1415 bytes [21:06 29/07/2010] [21:06 29/07/2010] win3..erop_aa54df1bbb4d668d_0001.0000_none_4857e8052bed1e45.cdf-ms –a—- 2516 bytes [21:06 29/07/2010] [21:07 29/07/2010] win3..erop_aa54df1bbb4d668d_0001.0000_none_4857e8052bed1e45.manifest –a—- 832 bytes [21:06 29/07/2010] [21:06 29/07/2010] wpf.themes_8a76f3ebbd64ea05_0001.0000_none_7cf45c5deb30ea73.cdf-ms –a—- 4460 bytes [21:06 29/07/2010] [21:07 29/07/2010] wpf.themes_8a76f3ebbd64ea05_0001.0000_none_7cf45c5deb30ea73.manifest –a—- 1572 bytes [21:06 29/07/2010] [21:06 29/07/2010] xcee..grid_ba83ff368b7563c6_0003.0005_none_594a4965080405af.cdf-ms –a—- 8372 bytes [21:06 29/07/2010] [21:07 29/07/2010] xcee..grid_ba83ff368b7563c6_0003.0005_none_594a4965080405af.manifest –a—- 3283 bytes [21:06 29/07/2010] [21:06 29/07/2010] xcee..rols_ba83ff368b7563c6_0003.0005_none_844b5f88f02013c1.cdf-ms –a—- 4388 bytes [21:06 29/07/2010] [21:07 29/07/2010] xcee..rols_ba83ff368b7563c6_0003.0005_none_844b5f88f02013c1.manifest –a—- 1591 bytes [21:06 29/07/2010] [21:06 29/07/2010] zlib.net_47d7877cb3620160_0001.0000_none_755f576146efa063.cdf-ms –a—- 1948 bytes [21:06 29/07/2010] [21:07 29/07/2010] zlib.net_47d7877cb3620160_0001.0000_none_755f576146efa063.manifest –a—- 613 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\micr..hell_31bf3856ad364e35_0003.0000_none_c495b3ffab1bf08e d—— [21:06 29/07/2010] Microsoft.Windows.Shell.dll –a—- 160064 bytes [21:06 29/07/2010] [21:04 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\win3..erop_aa54df1bbb4d668d_0001.0000_none_4857e8052bed1e45 d—— [21:06 29/07/2010] Win32Interop.dll –a—- 11264 bytes [21:06 29/07/2010] [21:04 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\wpf.themes_8a76f3ebbd64ea05_0001.0000_none_7cf45c5deb30ea73 d—— [21:06 29/07/2010] WPF.Themes.dll –a—- 79360 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\xcee..grid_ba83ff368b7563c6_0003.0005_none_594a4965080405af d—— [21:06 29/07/2010] Xceed.Wpf.DataGrid.dll –a—- 2704024 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\xcee..rols_ba83ff368b7563c6_0003.0005_none_844b5f88f02013c1 d—— [21:06 29/07/2010] Xceed.Wpf.Controls.dll –a—- 168600 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\zlib.net_47d7877cb3620160_0001.0000_none_755f576146efa063 d—— [21:06 29/07/2010] zlib.net.dll –a—- 69632 bytes [21:06 29/07/2010] [21:06 29/07/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR d—— [15:42 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ d—— [15:42 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs…exe_eee711038731a406_0004.0000_none_23379ba02ddddf44 d—— [10:12 15/06/2010] CurseClient.exe.config –a—- 955 bytes [10:12 15/06/2010] [10:11 15/06/2010] GammaJul.LgLcd.Native32.dll –a—- 12288 bytes [10:12 15/06/2010] [10:11 15/06/2010] GammaJul.LgLcd.Native64.dll –a—- 14848 bytes [10:12 15/06/2010] [10:11 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs…exe_eee711038731a406_0004.0000_none_23379ba02ddddf44\ClientIcons d—— [10:12 15/06/2010] CCIP.ico –a—- 285478 bytes [10:12 15/06/2010] [10:11 15/06/2010] CurseClient.ico –a—- 63104 bytes [10:12 15/06/2010] [10:11 15/06/2010] CurseClientTray-Normal.ico –a—- 2862 bytes [10:12 15/06/2010] [10:11 15/06/2010] CurseClientTray-Updates.ico –a—- 2862 bytes [10:12 15/06/2010] [10:11 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs…exe_eee711038731a406_0004.0000_none_23379ba02ddddf46 d—— [21:24 15/06/2010] CurseClient.exe.config –a—- 955 bytes [21:24 15/06/2010] [21:24 15/06/2010] GammaJul.LgLcd.Native32.dll –a—- 12288 bytes [21:24 15/06/2010] [21:24 15/06/2010] GammaJul.LgLcd.Native64.dll –a—- 14848 bytes [21:24 15/06/2010] [21:24 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs…exe_eee711038731a406_0004.0000_none_23379ba02ddddf46\ClientIcons d—— [21:24 15/06/2010] CCIP.ico –a—- 285478 bytes [21:24 15/06/2010] [21:24 15/06/2010] CurseClient.ico –a—- 63104 bytes [21:24 15/06/2010] [21:24 15/06/2010] CurseClientTray-Normal.ico –a—- 2862 bytes [21:24 15/06/2010] [21:24 15/06/2010] CurseClientTray-Updates.ico –a—- 2862 bytes [21:24 15/06/2010] [21:24 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..dels_823b3ca1d8c473c0_0001.0000_none_828d8225eff00f16 d—— [15:43 28/03/2010] Curse.ClientService.Models.dll –a—- 32256 bytes [15:43 28/03/2010] [15:43 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..dons_a7ce87cfdd4ba154_0001.0000_none_88033998b61b4817 d—— [15:43 28/03/2010] Curse.AddOns.dll –a—- 28672 bytes [15:43 28/03/2010] [15:43 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..hash_8432f15c15e06b4f_0001.0000_none_54bc766006c2d238 d—— [15:43 28/03/2010] Curse.MurmurHash.dll –a—- 4608 bytes [15:43 28/03/2010] [15:43 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..ient_3cbc29eb0a26dbf9_0004.0000_none_0c5254890c13bfbf d—— [15:43 28/03/2010] CurseClient.exe –a—- 1682944 bytes [15:43 28/03/2010] [15:43 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..ions_7e7f879797d04a51_0001.0000_none_a248efbfe62cb319 d—— [15:43 28/03/2010] Curse.CurseClient.Enumerations.dll –a—- 7680 bytes [15:43 28/03/2010] [15:42 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..kens_447bcc00e712a048_0001.0000_none_5b0b9063dd0b7ca4 d—— [15:43 28/03/2010] Curse.DownloadSecurity.Tokens.dll –a—- 5632 bytes [15:43 28/03/2010] [15:43 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..mmon_c85bb4cad3a5dfb5_0001.0000_none_590134cd92e07a01 d—— [15:43 28/03/2010] Curse.CurseClient.Common.dll –a—- 270336 bytes [15:43 28/03/2010] [15:42 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..rces_b0514d04fccbdb72_0001.0000_fr-fr_dd2c1cd776e13c74 d—— [15:43 28/03/2010] Curse.CurseClient.Localization.resources.dll –a—- 4608 bytes [15:43 28/03/2010] [15:43 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..rols_00072c358aa93735_0001.0000_none_b9453a0fa2a31513 d—— [15:43 28/03/2010] Curse.CurseClient.Controls.dll –a—- 173056 bytes [15:43 28/03/2010] [15:43 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..tech_aa8c8c3656845a34_0001.0000_none_9f528297112c886a d—— [19:43 14/06/2010] Curse.CurseClient.Logitech.dll –a—- 61440 bytes [19:43 14/06/2010] [19:43 14/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..tion_b0514d04fccbdb72_0001.0000_none_31aa88590a5e716c d—— [15:43 28/03/2010] Curse.CurseClient.Localization.dll –a—- 35840 bytes [15:43 28/03/2010] [15:42 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..tion_eee711038731a406_0004.0000_172b37d625a03ec8 d—— [10:12 15/06/2010] Curse.AddOns.cdf-ms –a—- 3928 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.AddOns.dll ——- 28672 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.AddOns.manifest –a—- 1394 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.cdf-ms –a—- 4700 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.ClientService.Models.cdf-ms –a—- 3488 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.ClientService.Models.dll ——- 32256 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.ClientService.Models.manifest –a—- 1244 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.Common.cdf-ms –a—- 13720 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.Common.dll ——- 275456 bytes [10:12 15/06/2010] [10:11 15/06/2010] Curse.CurseClient.Common.manifest –a—- 5235 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.Common.XmlSerializers.cdf-ms –a—- 3116 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.Common.XmlSerializers.dll ——- 13312 bytes [10:12 15/06/2010] [10:11 15/06/2010] Curse.CurseClient.Common.XmlSerializers.manifest –a—- 1079 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.Controls.cdf-ms –a—- 10260 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.Controls.dll ——- 173056 bytes [10:12 15/06/2010] [10:11 15/06/2010] Curse.CurseClient.Controls.manifest –a—- 3889 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.Enumerations.cdf-ms –a—- 2576 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.Enumerations.dll ——- 7680 bytes [10:12 15/06/2010] [10:11 15/06/2010] Curse.CurseClient.Enumerations.manifest –a—- 861 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.Localization.cdf-ms –a—- 2576 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.Localization.dll ——- 35840 bytes [10:12 15/06/2010] [10:11 15/06/2010] Curse.CurseClient.Localization.manifest –a—- 861 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.Logitech.cdf-ms –a—- 6372 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.Logitech.dll ——- 58880 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.Logitech.manifest –a—- 2347 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.dll ——- 53248 bytes [10:12 15/06/2010] [10:11 15/06/2010] Curse.DownloadSecurity.Tokens.cdf-ms –a—- 2644 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.DownloadSecurity.Tokens.dll ——- 5632 bytes [10:12 15/06/2010] [10:11 15/06/2010] Curse.DownloadSecurity.Tokens.manifest –a—- 869 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.manifest –a—- 1722 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.MurmurHash.cdf-ms –a—- 2100 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.MurmurHash.dll ——- 4608 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.MurmurHash.manifest –a—- 655 bytes [10:12 15/06/2010] [10:12 15/06/2010] CurseClient.cdf-ms –a—- 12464 bytes [10:12 15/06/2010] [10:12 15/06/2010] CurseClient.exe ——- 1701376 bytes [10:12 15/06/2010] [10:12 15/06/2010] CurseClient.exe.cdf-ms –a—- 51004 bytes [10:12 15/06/2010] [10:12 15/06/2010] CurseClient.exe.config –a—- 955 bytes [10:12 15/06/2010] [10:11 15/06/2010] CurseClient.exe.manifest –a—- 31794 bytes [10:12 15/06/2010] [10:12 15/06/2010] CurseClient.manifest –a—- 4656 bytes [10:12 15/06/2010] [10:12 15/06/2010] GammaJul.LgLcd.cdf-ms –a—- 2992 bytes [19:43 14/06/2010] [19:43 14/06/2010] GammaJul.LgLcd.dll –a—- 51712 bytes [19:43 14/06/2010] [19:43 14/06/2010] GammaJul.LgLcd.manifest –a—- 1015 bytes [19:43 14/06/2010] [19:43 14/06/2010] GammaJul.LgLcd.Native32.dll –a—- 12288 bytes [10:12 15/06/2010] [10:11 15/06/2010] GammaJul.LgLcd.Native64.dll –a—- 14848 bytes [10:12 15/06/2010] [10:11 15/06/2010] GammaJul.LgLcd.Wpf.cdf-ms –a—- 3980 bytes [19:43 14/06/2010] [19:43 14/06/2010] GammaJul.LgLcd.Wpf.dll –a—- 6656 bytes [19:43 14/06/2010] [19:43 14/06/2010] GammaJul.LgLcd.Wpf.manifest –a—- 1409 bytes [19:43 14/06/2010] [19:43 14/06/2010] ICSharpCode.SharpZipLib.cdf-ms –a—- 2552 bytes [10:12 15/06/2010] [10:12 15/06/2010] ICSharpCode.SharpZipLib.dll ——- 192512 bytes [10:12 15/06/2010] [10:11 15/06/2010] ICSharpCode.SharpZipLib.manifest –a—- 850 bytes [10:12 15/06/2010] [10:12 15/06/2010] Interop.NetFwTypeLib.cdf-ms –a—- 2116 bytes [10:12 15/06/2010] [10:12 15/06/2010] Interop.NetFwTypeLib.dll ——- 19968 bytes [10:12 15/06/2010] [10:11 15/06/2010] Interop.NetFwTypeLib.manifest –a—- 663 bytes [10:12 15/06/2010] [10:12 15/06/2010] Microsoft.Windows.Shell.cdf-ms –a—- 3936 bytes [19:43 14/06/2010] [19:43 14/06/2010] Microsoft.Windows.Shell.dll –a—- 160064 bytes [19:43 14/06/2010] [19:43 14/06/2010] Microsoft.Windows.Shell.manifest –a—- 1415 bytes [19:43 14/06/2010] [19:43 14/06/2010] Win32Interop.cdf-ms –a—- 2512 bytes [10:12 15/06/2010] [10:12 15/06/2010] Win32Interop.dll –a—- 11264 bytes [10:12 15/06/2010] [10:11 15/06/2010] Win32Interop.manifest –a—- 832 bytes [10:12 15/06/2010] [10:12 15/06/2010] WPF.Themes.cdf-ms –a—- 4456 bytes [10:12 15/06/2010] [10:12 15/06/2010] WPF.Themes.dll ——- 79360 bytes [10:12 15/06/2010] [10:12 15/06/2010] WPF.Themes.manifest –a—- 1572 bytes [10:12 15/06/2010] [10:12 15/06/2010] Xceed.Wpf.Controls.cdf-ms –a—- 4384 bytes [15:43 28/03/2010] [15:43 28/03/2010] Xceed.Wpf.Controls.dll –a—- 168600 bytes [15:43 28/03/2010] [15:43 28/03/2010] Xceed.Wpf.Controls.manifest –a—- 1591 bytes [15:43 28/03/2010] [15:43 28/03/2010] Xceed.Wpf.DataGrid.cdf-ms –a—- 8368 bytes [15:43 28/03/2010] [15:43 28/03/2010] Xceed.Wpf.DataGrid.dll –a—- 2704024 bytes [15:43 28/03/2010] [15:43 28/03/2010] Xceed.Wpf.DataGrid.manifest –a—- 3283 bytes [15:43 28/03/2010] [15:43 28/03/2010] zlib.net.cdf-ms –a—- 1944 bytes [15:43 28/03/2010] [15:43 28/03/2010] zlib.net.dll –a—- 69632 bytes [15:43 28/03/2010] [15:42 28/03/2010] zlib.net.manifest –a—- 613 bytes [15:43 28/03/2010] [15:43 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..tion_eee711038731a406_0004.0000_172b37d625a03ec8\ClientIcons d—— [10:12 15/06/2010] CCIP.ico –a—- 285478 bytes [10:12 15/06/2010] [10:11 15/06/2010] CurseClient.ico –a—- 63104 bytes [10:12 15/06/2010] [10:11 15/06/2010] CurseClientTray-Normal.ico –a—- 2862 bytes [10:12 15/06/2010] [10:11 15/06/2010] CurseClientTray-Updates.ico –a—- 2862 bytes [10:12 15/06/2010] [10:11 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..tion_eee711038731a406_0004.0000_172b37d625a03ec8\fr-FR d—— [10:12 15/06/2010] Curse.CurseClient.Localization.resources.cdf-ms –a—- 2308 bytes [10:12 15/06/2010] [10:12 15/06/2010] Curse.CurseClient.Localization.resources.dll ——- 4608 bytes [10:12 15/06/2010] [10:11 15/06/2010] Curse.CurseClient.Localization.resources.manifest –a—- 720 bytes [10:12 15/06/2010] [10:12 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48 d—— [21:24 15/06/2010] Curse.AddOns.cdf-ms –a—- 3928 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.AddOns.dll ——- 28672 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.AddOns.manifest –a—- 1394 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.cdf-ms –a—- 4700 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.ClientService.Models.cdf-ms –a—- 3488 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.ClientService.Models.dll ——- 32256 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.ClientService.Models.manifest –a—- 1244 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Common.cdf-ms –a—- 13720 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Common.dll ——- 276992 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Common.manifest –a—- 5235 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Common.XmlSerializers.cdf-ms –a—- 3116 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Common.XmlSerializers.dll ——- 13312 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Common.XmlSerializers.manifest –a—- 1079 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Controls.cdf-ms –a—- 10260 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Controls.dll ——- 173056 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Controls.manifest –a—- 3889 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Enumerations.cdf-ms –a—- 2576 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Enumerations.dll ——- 7680 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Enumerations.manifest –a—- 861 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Localization.cdf-ms –a—- 2576 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Localization.dll ——- 35840 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Localization.manifest –a—- 861 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Logitech.cdf-ms –a—- 6428 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Logitech.dll ——- 58880 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Logitech.manifest –a—- 2347 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.dll ——- 53248 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.DownloadSecurity.Tokens.cdf-ms –a—- 2644 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.DownloadSecurity.Tokens.dll ——- 5632 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.DownloadSecurity.Tokens.manifest –a—- 869 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.manifest –a—- 1722 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.MurmurHash.cdf-ms –a—- 2100 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.MurmurHash.dll ——- 4608 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.MurmurHash.manifest –a—- 655 bytes [21:24 15/06/2010] [21:24 15/06/2010] CurseClient.cdf-ms –a—- 12464 bytes [21:24 15/06/2010] [21:24 15/06/2010] CurseClient.exe ——- 1701888 bytes [21:24 15/06/2010] [21:24 15/06/2010] CurseClient.exe.cdf-ms –a—- 51056 bytes [21:24 15/06/2010] [21:24 15/06/2010] CurseClient.exe.config –a—- 955 bytes [21:24 15/06/2010] [21:24 15/06/2010] CurseClient.exe.manifest –a—- 31794 bytes [21:24 15/06/2010] [21:24 15/06/2010] CurseClient.manifest –a—- 4656 bytes [21:24 15/06/2010] [21:24 15/06/2010] GammaJul.LgLcd.cdf-ms –a—- 2992 bytes [21:24 15/06/2010] [21:24 15/06/2010] GammaJul.LgLcd.dll –a—- 51712 bytes [21:24 15/06/2010] [21:24 15/06/2010] GammaJul.LgLcd.manifest –a—- 1015 bytes [21:24 15/06/2010] [21:24 15/06/2010] GammaJul.LgLcd.Native32.dll –a—- 12288 bytes [21:24 15/06/2010] [21:24 15/06/2010] GammaJul.LgLcd.Native64.dll –a—- 14848 bytes [21:24 15/06/2010] [21:24 15/06/2010] GammaJul.LgLcd.Wpf.cdf-ms –a—- 3980 bytes [21:24 15/06/2010] [21:24 15/06/2010] GammaJul.LgLcd.Wpf.dll –a—- 6656 bytes [21:24 15/06/2010] [21:24 15/06/2010] GammaJul.LgLcd.Wpf.manifest –a—- 1409 bytes [21:24 15/06/2010] [21:24 15/06/2010] ICSharpCode.SharpZipLib.cdf-ms –a—- 2552 bytes [21:24 15/06/2010] [21:24 15/06/2010] ICSharpCode.SharpZipLib.dll ——- 192512 bytes [21:24 15/06/2010] [21:24 15/06/2010] ICSharpCode.SharpZipLib.manifest –a—- 850 bytes [21:24 15/06/2010] [21:24 15/06/2010] Interop.NetFwTypeLib.cdf-ms –a—- 2116 bytes [21:24 15/06/2010] [21:24 15/06/2010] Interop.NetFwTypeLib.dll ——- 19968 bytes [21:24 15/06/2010] [21:24 15/06/2010] Interop.NetFwTypeLib.manifest –a—- 663 bytes [21:24 15/06/2010] [21:24 15/06/2010] Microsoft.Windows.Shell.cdf-ms –a—- 3936 bytes [19:43 14/06/2010] [19:43 14/06/2010] Microsoft.Windows.Shell.dll –a—- 160064 bytes [19:43 14/06/2010] [19:43 14/06/2010] Microsoft.Windows.Shell.manifest –a—- 1415 bytes [19:43 14/06/2010] [19:43 14/06/2010] Win32Interop.cdf-ms –a—- 2512 bytes [21:24 15/06/2010] [21:24 15/06/2010] Win32Interop.dll –a—- 11264 bytes [21:24 15/06/2010] [21:24 15/06/2010] Win32Interop.manifest –a—- 832 bytes [21:24 15/06/2010] [21:24 15/06/2010] WPF.Themes.cdf-ms –a—- 4456 bytes [21:24 15/06/2010] [21:24 15/06/2010] WPF.Themes.dll ——- 79360 bytes [21:24 15/06/2010] [21:24 15/06/2010] WPF.Themes.manifest –a—- 1572 bytes [21:24 15/06/2010] [21:24 15/06/2010] Xceed.Wpf.Controls.cdf-ms –a—- 4384 bytes [15:43 28/03/2010] [15:43 28/03/2010] Xceed.Wpf.Controls.dll –a—- 168600 bytes [15:43 28/03/2010] [15:43 28/03/2010] Xceed.Wpf.Controls.manifest –a—- 1591 bytes [15:43 28/03/2010] [15:43 28/03/2010] Xceed.Wpf.DataGrid.cdf-ms –a—- 8368 bytes [15:43 28/03/2010] [15:43 28/03/2010] Xceed.Wpf.DataGrid.dll –a—- 2704024 bytes [15:43 28/03/2010] [15:43 28/03/2010] Xceed.Wpf.DataGrid.manifest –a—- 3283 bytes [15:43 28/03/2010] [15:43 28/03/2010] zlib.net.cdf-ms –a—- 1944 bytes [15:43 28/03/2010] [15:43 28/03/2010] zlib.net.dll –a—- 69632 bytes [15:43 28/03/2010] [15:42 28/03/2010] zlib.net.manifest –a—- 613 bytes [15:43 28/03/2010] [15:43 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\ClientIcons d—— [21:24 15/06/2010] CCIP.ico –a—- 285478 bytes [21:24 15/06/2010] [21:24 15/06/2010] CurseClient.ico –a—- 63104 bytes [21:24 15/06/2010] [21:24 15/06/2010] CurseClientTray-Normal.ico –a—- 2862 bytes [21:24 15/06/2010] [21:24 15/06/2010] CurseClientTray-Updates.ico –a—- 2862 bytes [21:24 15/06/2010] [21:24 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\fr-FR d—— [21:24 15/06/2010] Curse.CurseClient.Localization.resources.cdf-ms –a—- 2308 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Localization.resources.dll ——- 4608 bytes [21:24 15/06/2010] [21:24 15/06/2010] Curse.CurseClient.Localization.resources.manifest –a—- 720 bytes [21:24 15/06/2010] [21:24 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curs..zers_c85bb4cad3a5dfb5_0001.0000_none_311750f664a5eb21 d—— [15:43 28/03/2010] Curse.CurseClient.Common.XmlSerializers.dll –a—- 13312 bytes [15:43 28/03/2010] [15:43 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\curse_a9ab3e4b97c6f141_0001.0000_none_2639d79cd6d239af d—— [15:43 28/03/2010] Curse.dll –a—- 53248 bytes [15:43 28/03/2010] [15:42 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\gamm…wpf_79429b4c9fe572da_0001.0001_none_283a3ff44400930d d—— [19:43 14/06/2010] GammaJul.LgLcd.Wpf.dll –a—- 6656 bytes [19:43 14/06/2010] [19:43 14/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\gamm…wpf_f3239ab6a2f8f304_0001.0001_none_4082f3cc1e3c6874 d—— [21:24 15/06/2010] GammaJul.LgLcd.Wpf.dll –a—- 6656 bytes [21:24 15/06/2010] [21:24 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\gamm..glcd_7904f4aa6fca30ba_0001.0001_none_1567cfb883b21611 d—— [21:24 15/06/2010] GammaJul.LgLcd.dll –a—- 51712 bytes [21:24 15/06/2010] [21:24 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\gamm..glcd_79429b4c9fe572da_0001.0001_none_dbd9ed1f84806644 d—— [19:43 14/06/2010] GammaJul.LgLcd.dll –a—- 51712 bytes [19:43 14/06/2010] [19:43 14/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\icsh..plib_08a258a57e9138b3_0000.0055_none_392f0ecbd2490bc8 d—— [15:43 28/03/2010] ICSharpCode.SharpZipLib.dll –a—- 192512 bytes [15:43 28/03/2010] [15:42 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\inte..elib_c85bb4cad3a5dfb5_0001.0000_none_2de83b338c8598e1 d—— [15:43 28/03/2010] Interop.NetFwTypeLib.dll –a—- 28672 bytes [15:43 28/03/2010] [15:42 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\manifests d—— [15:42 28/03/2010] curs…exe_eee711038731a406_0004.0000_none_23379ba02ddddf44.cdf-ms –a—- 51004 bytes [10:12 15/06/2010] [10:12 15/06/2010] curs…exe_eee711038731a406_0004.0000_none_23379ba02ddddf44.manifest –a—- 31794 bytes [10:12 15/06/2010] [10:12 15/06/2010] curs…exe_eee711038731a406_0004.0000_none_23379ba02ddddf46.cdf-ms –a—- 51056 bytes [21:24 15/06/2010] [21:24 15/06/2010] curs…exe_eee711038731a406_0004.0000_none_23379ba02ddddf46.manifest –a—- 31794 bytes [21:24 15/06/2010] [21:24 15/06/2010] curs..dels_823b3ca1d8c473c0_0001.0000_none_828d8225eff00f16.cdf-ms –a—- 3488 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..dels_823b3ca1d8c473c0_0001.0000_none_828d8225eff00f16.manifest –a—- 1244 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..dons_a7ce87cfdd4ba154_0001.0000_none_88033998b61b4817.cdf-ms –a—- 3928 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..dons_a7ce87cfdd4ba154_0001.0000_none_88033998b61b4817.manifest –a—- 1394 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..hash_8432f15c15e06b4f_0001.0000_none_54bc766006c2d238.cdf-ms –a—- 2100 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..hash_8432f15c15e06b4f_0001.0000_none_54bc766006c2d238.manifest –a—- 655 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..ient_3cbc29eb0a26dbf9_0004.0000_none_0c5254890c13bfbf.cdf-ms –a—- 11148 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..ient_3cbc29eb0a26dbf9_0004.0000_none_0c5254890c13bfbf.manifest –a—- 4259 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..ions_7e7f879797d04a51_0001.0000_none_a248efbfe62cb319.cdf-ms –a—- 2576 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..ions_7e7f879797d04a51_0001.0000_none_a248efbfe62cb319.manifest –a—- 861 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..kens_447bcc00e712a048_0001.0000_none_5b0b9063dd0b7ca4.cdf-ms –a—- 2644 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..kens_447bcc00e712a048_0001.0000_none_5b0b9063dd0b7ca4.manifest –a—- 869 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..mmon_c85bb4cad3a5dfb5_0001.0000_none_590134cd92e07a01.cdf-ms –a—- 13720 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..mmon_c85bb4cad3a5dfb5_0001.0000_none_590134cd92e07a01.manifest –a—- 5235 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..rces_b0514d04fccbdb72_0001.0000_fr-fr_dd2c1cd776e13c74.cdf-ms –a—- 2308 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..rces_b0514d04fccbdb72_0001.0000_fr-fr_dd2c1cd776e13c74.manifest –a—- 720 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..rols_00072c358aa93735_0001.0000_none_b9453a0fa2a31513.cdf-ms –a—- 10260 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..rols_00072c358aa93735_0001.0000_none_b9453a0fa2a31513.manifest –a—- 3889 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..tech_aa8c8c3656845a34_0001.0000_none_9f528297112c886a.cdf-ms –a—- 7280 bytes [19:43 14/06/2010] [19:43 14/06/2010] curs..tech_aa8c8c3656845a34_0001.0000_none_9f528297112c886a.manifest –a—- 2719 bytes [19:43 14/06/2010] [19:43 14/06/2010] curs..tion_b0514d04fccbdb72_0001.0000_none_31aa88590a5e716c.cdf-ms –a—- 2576 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..tion_b0514d04fccbdb72_0001.0000_none_31aa88590a5e716c.manifest –a—- 861 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..tion_eee711038731a406_0004.0000_none_63d59c6f0e2d6eb5.cdf-ms –a—- 14952 bytes [10:12 15/06/2010] [10:12 15/06/2010] curs..tion_eee711038731a406_0004.0000_none_63d59c6f0e2d6eb5.manifest –a—- 11896 bytes [10:12 15/06/2010] [10:12 15/06/2010] curs..tion_eee711038731a406_0004.0000_none_63d59c6f0e2d6eb7.cdf-ms –a—- 14952 bytes [21:24 15/06/2010] [21:24 15/06/2010] curs..tion_eee711038731a406_0004.0000_none_63d59c6f0e2d6eb7.manifest –a—- 11896 bytes [21:24 15/06/2010] [21:24 15/06/2010] curs..zers_c85bb4cad3a5dfb5_0001.0000_none_311750f664a5eb21.cdf-ms –a—- 3116 bytes [15:43 28/03/2010] [15:43 28/03/2010] curs..zers_c85bb4cad3a5dfb5_0001.0000_none_311750f664a5eb21.manifest –a—- 1079 bytes [15:43 28/03/2010] [15:43 28/03/2010] curse_a9ab3e4b97c6f141_0001.0000_none_2639d79cd6d239af.cdf-ms –a—- 4700 bytes [15:43 28/03/2010] [15:43 28/03/2010] curse_a9ab3e4b97c6f141_0001.0000_none_2639d79cd6d239af.manifest –a—- 1722 bytes [15:43 28/03/2010] [15:43 28/03/2010] gamm…wpf_79429b4c9fe572da_0001.0001_none_283a3ff44400930d.cdf-ms –a—- 3980 bytes [19:43 14/06/2010] [19:43 14/06/2010] gamm…wpf_79429b4c9fe572da_0001.0001_none_283a3ff44400930d.manifest –a—- 1409 bytes [19:43 14/06/2010] [19:43 14/06/2010] gamm…wpf_f3239ab6a2f8f304_0001.0001_none_4082f3cc1e3c6874.cdf-ms –a—- 3980 bytes [21:24 15/06/2010] [21:24 15/06/2010] gamm…wpf_f3239ab6a2f8f304_0001.0001_none_4082f3cc1e3c6874.manifest –a—- 1409 bytes [21:24 15/06/2010] [21:24 15/06/2010] gamm..glcd_7904f4aa6fca30ba_0001.0001_none_1567cfb883b21611.cdf-ms –a—- 2992 bytes [21:24 15/06/2010] [21:24 15/06/2010] gamm..glcd_7904f4aa6fca30ba_0001.0001_none_1567cfb883b21611.manifest –a—- 1015 bytes [21:24 15/06/2010] [21:24 15/06/2010] gamm..glcd_79429b4c9fe572da_0001.0001_none_dbd9ed1f84806644.cdf-ms –a—- 2992 bytes [19:43 14/06/2010] [19:43 14/06/2010] gamm..glcd_79429b4c9fe572da_0001.0001_none_dbd9ed1f84806644.manifest –a—- 1015 bytes [19:43 14/06/2010] [19:43 14/06/2010] icsh..plib_08a258a57e9138b3_0000.0055_none_392f0ecbd2490bc8.cdf-ms –a—- 2552 bytes [15:43 28/03/2010] [15:43 28/03/2010] icsh..plib_08a258a57e9138b3_0000.0055_none_392f0ecbd2490bc8.manifest –a—- 850 bytes [15:43 28/03/2010] [15:43 28/03/2010] inte..elib_c85bb4cad3a5dfb5_0001.0000_none_2de83b338c8598e1.cdf-ms –a—- 2116 bytes [15:43 28/03/2010] [15:43 28/03/2010] inte..elib_c85bb4cad3a5dfb5_0001.0000_none_2de83b338c8598e1.manifest –a—- 663 bytes [15:43 28/03/2010] [15:43 28/03/2010] micr..hell_31bf3856ad364e35_0003.0000_none_c495b3ffab1bf08e.cdf-ms –a—- 3936 bytes [19:43 14/06/2010] [19:43 14/06/2010] micr..hell_31bf3856ad364e35_0003.0000_none_c495b3ffab1bf08e.manifest –a—- 1415 bytes [19:43 14/06/2010] [19:43 14/06/2010] win3..erop_aa54df1bbb4d668d_0001.0000_none_480fda5b2c8e3fae.cdf-ms –a—- 2512 bytes [10:12 15/06/2010] [10:12 15/06/2010] win3..erop_aa54df1bbb4d668d_0001.0000_none_480fda5b2c8e3fae.manifest –a—- 832 bytes [10:12 15/06/2010] [10:12 15/06/2010] win3..erop_aa54df1bbb4d668d_0001.0000_none_4857e8052bed1e45.cdf-ms –a—- 2512 bytes [21:24 15/06/2010] [21:24 15/06/2010] win3..erop_aa54df1bbb4d668d_0001.0000_none_4857e8052bed1e45.manifest –a—- 832 bytes [21:24 15/06/2010] [21:24 15/06/2010] wpf.themes_8a76f3ebbd64ea05_0001.0000_none_7cf45c5deb30ea73.cdf-ms –a—- 4456 bytes [15:43 28/03/2010] [15:43 28/03/2010] wpf.themes_8a76f3ebbd64ea05_0001.0000_none_7cf45c5deb30ea73.manifest –a—- 1572 bytes [15:43 28/03/2010] [15:43 28/03/2010] xcee..grid_ba83ff368b7563c6_0003.0005_none_594a4965080405af.cdf-ms –a—- 8368 bytes [15:43 28/03/2010] [15:43 28/03/2010] xcee..grid_ba83ff368b7563c6_0003.0005_none_594a4965080405af.manifest –a—- 3283 bytes [15:43 28/03/2010] [15:43 28/03/2010] xcee..rols_ba83ff368b7563c6_0003.0005_none_844b5f88f02013c1.cdf-ms –a—- 4384 bytes [15:43 28/03/2010] [15:43 28/03/2010] xcee..rols_ba83ff368b7563c6_0003.0005_none_844b5f88f02013c1.manifest –a—- 1591 bytes [15:43 28/03/2010] [15:43 28/03/2010] zlib.net_47d7877cb3620160_0001.0000_none_755f576146efa063.cdf-ms –a—- 1944 bytes [15:43 28/03/2010] [15:43 28/03/2010] zlib.net_47d7877cb3620160_0001.0000_none_755f576146efa063.manifest –a—- 613 bytes [15:43 28/03/2010] [15:43 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\micr..hell_31bf3856ad364e35_0003.0000_none_c495b3ffab1bf08e d—— [19:43 14/06/2010] Microsoft.Windows.Shell.dll –a—- 160064 bytes [19:43 14/06/2010] [19:43 14/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\win3..erop_aa54df1bbb4d668d_0001.0000_none_480fda5b2c8e3fae d—— [10:12 15/06/2010] Win32Interop.dll –a—- 11264 bytes [10:12 15/06/2010] [10:11 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\win3..erop_aa54df1bbb4d668d_0001.0000_none_4857e8052bed1e45 d—— [21:24 15/06/2010] Win32Interop.dll –a—- 11264 bytes [21:24 15/06/2010] [21:24 15/06/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\wpf.themes_8a76f3ebbd64ea05_0001.0000_none_7cf45c5deb30ea73 d—— [15:43 28/03/2010] WPF.Themes.dll –a—- 79360 bytes [15:43 28/03/2010] [15:43 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\xcee..grid_ba83ff368b7563c6_0003.0005_none_594a4965080405af d—— [15:43 28/03/2010] Xceed.Wpf.DataGrid.dll –a—- 2704024 bytes [15:43 28/03/2010] [15:43 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\xcee..rols_ba83ff368b7563c6_0003.0005_none_844b5f88f02013c1 d—— [15:43 28/03/2010] Xceed.Wpf.Controls.dll –a—- 168600 bytes [15:43 28/03/2010] [15:43 28/03/2010] C:\Users\jamie\AppData\Local\Apps\2.0\YRXTRY4Q.ETR\4OJTYYH3.GMZ\zlib.net_47d7877cb3620160_0001.0000_none_755f576146efa063 d—— [15:43 28/03/2010] zlib.net.dll –a—- 69632 bytes [15:43 28/03/2010] [15:42 28/03/2010] -= EOF =- Antivirus Version Last Update Result AhnLab-V3 2010.09.25.00 2010.09.24 - AntiVir 7.10.12.30 2010.09.24 - Antiy-AVL 2.0.3.7 2010.09.25 - Authentium 5.2.0.5 2010.09.25 - Avast 4.8.1351.0 2010.09.25 - Avast5 5.0.594.0 2010.09.25 - AVG 9.0.0.851 2010.09.25 - BitDefender 7.2 2010.09.25 - CAT-QuickHeal 11.00 2010.09.24 - ClamAV 0.96.2.0-git 2010.09.25 - Comodo 6196 2010.09.25 - DrWeb 5.0.2.03300 2010.09.25 - Emsisoft 5.0.0.37 2010.09.25 - eSafe 7.0.17.0 2010.09.21 - eTrust-Vet 36.1.7875 2010.09.25 - F-Prot 4.6.2.117 2010.09.25 - F-Secure 9.0.15370.0 2010.09.25 - Fortinet 4.1.143.0 2010.09.25 - GData 21 2010.09.25 - Ikarus T3.1.1.88.0 2010.09.25 - Jiangmin 13.0.900 2010.09.25 - K7AntiVirus 9.63.2608 2010.09.25 - Kaspersky 7.0.0.125 2010.09.25 - McAfee 5.400.0.1158 2010.09.25 - McAfee-GW-Edition 2010.1C 2010.09.25 - Microsoft 1.6201 2010.09.25 - NOD32 5479 2010.09.25 - Norman 6.06.06 2010.09.25 - nProtect 2010-09-25.01 2010.09.25 - Panda 10.0.2.7 2010.09.25 - PCTools 7.0.3.5 2010.09.25 - Prevx 3.0 2010.09.25 - Rising 22.66.04.00 2010.09.25 - Sophos 4.58.0 2010.09.25 - Sunbelt 6928 2010.09.25 - SUPERAntiSpyware 4.40.0.1006 2010.09.25 - Symantec 20101.1.1.7 2010.09.25 - TheHacker [removed].032 2010.09.25 - TrendMicro 9.120.0.1004 2010.09.25 - TrendMicro-HouseCall 9.120.0.1004 2010.09.25 - VBA32 3.12.14.1 2010.09.24 - ViRobot 2010.9.25.4060 2010.09.25 - VirusBuster 12.65.25.0 2010.09.24 - Additional information Show all MD5 : d872daefe322a9ccd5f2b6899e3e2c02 SHA1 : 9818769245ec28fb0decd774d84a6c80fdd54848 SHA256: cbc7bfb53c3c32505df1a799b8adc5dad7d8fc570d4a95c165b4c82803c940d6
Follow these steps in order:


Step 1 | Please download TFC by OldTimer to your desktop.

  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • Click the Start button in the bottom left of TFC
  • If prompted, click "Yes" to reboot.
Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It should not take longer than a couple of minutes , and may only take a few seconds. Only if needed will you be prompted to reboot.


Step 2 | As you have Malwarebytes' Anti-Malware installed on your computer. Could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform Quick scan, then click on Scan
  • When done, you will be prompted. Click OK. If Items are found, then click on Show Results
  • Check all items then click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply.

The log can also be found here:

  • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when the application is started.

Note: MBAM may ask to reboot your computer so it can continue with the removal process, please do so immediately.
Failure to reboot will prevent MBAM from removing all the malware.


Step 3 | Please go to Kaspersky website and perform an online antivirus scan. Note: Internet Explorer should be used.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan and then put the kettle on!
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place like your Desktop. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Copy and paste the report into your next.

[external image: Posted Image]

Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4695 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 26/09/2010 01:01:04 mbam-log-2010-09-26 (01-01-04).txt Scan type: Quick scan Objects scanned: 142189 Time elapsed: 10 minute(s), 46 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Sunday, September 26, 2010 Operating system: Microsoft Home Edition (build 7600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Sunday, September 26, 2010 07:39:16 Records in database: 4240748 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Objects scanned: 79491 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 01:47:29 No threats found. Scanned area is clean. Selected area has been scanned.
errrm i have, but I never open them up…I did get one off someone last week which I opened, but it was obviously a scam so I didnt click the link…and I have changed my password since but Im sure someones been on my hotmail account….One of my junk mails was read, and random deleted emails keep being deleted…Im not sure how knowledageable about all this you guys are, does any of that make any sense to you? Is there some kind of feature Im not aware of?
Jamie,

Thanks for the info.


I notice you have the Curse Client installed in your computer. There are lot's of account hacking cases in which Curse.com is involved. I'm not saying that the Curse program is infected itself (in fact it seems to be a pretty well known manager in the WoW community), but you may have downloaded an infected addon or something. So please do the following:


  • Click "start" on the taskbar and then click on the "Control Panel" icon.
  • Doubleclick the "Add or Remove Programs" icon
  • A list of programs installed will be "populated" (this may take a bit of time).
  • In this list please find the program that you would like to remove and click "Change" (or "Change/Remove"). I would suggest you to remove the following:

    • Curse Client
    • LimeWire
  • A wizard should then open for each program to remove, which will guide you through the uninstallation.
If you find a visual aid appealing, you may like to watch the following video presentation which will show the above steps exactly as you would see them on your computer:
Video showing how to uninstall a program


Step 2 | Lets take another OTL log. Double click on the OTL icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

  • Click the Quick Scan button without changing any settings. The scan wont take long.
    • When the scan completes, it will open a notepad window: OTL.Txt. It is saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of OTL.Txt, and post it in your next reply.
  • Note: there will only be an OTL.txt this time
OTL logfile created on: 9/27/2010 10:49:27 AM - Run 3
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Users\jamie\Downloads
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 68.00% Memory free
7.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 116.29 Gb Total Space | 62.59 Gb Free Space | 53.82% Space Free | Partition Type: NTFS
Drive D: | 116.21 Gb Total Space | 110.64 Gb Free Space | 95.21% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BOBDAVE
Current User Name: jamie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Public\Documents\World of Warcraft\Launcher.exe (Blizzard Entertainment)
PRC - C:\Users\jamie\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\CurseClient.exe (Curse)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\ConfigFree\CFIWmxSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
PRC - C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (Toshiba Europe GmbH)
PRC - C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSENotify.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
PRC - C:\Program Files\Toshiba\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Toshiba\RSelect\RSelSvc.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\jamie\Downloads\OTL.exe (OldTimer Tools)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\Program Files\Common Files\Mcafee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (aspnet_state) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetTcpActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetPipeActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (NetMsmqActivator) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (TMachInfo) – C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (cfWiMAXService) – C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe (TOSHIBA CORPORATION)
SRV - (TemproMonitoringService) Notebook Performance Tuning Service (TEMPRO) – C:\Program Files\Toshiba TEMPRO\TemproSvc.exe (Toshiba Europe GmbH)
SRV - (TosCoSrv) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (RSELSVC) – C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe (TOSHIBA Corporation)
SRV - (HsfXAudioService) – C:\Windows\System32\XAudio32.dll (Conexant Systems, Inc.)
SRV - (ConfigFree Service) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)


========== Driver Services (SafeList) ==========

DRV - (USBCCID) – C:\Windows\System32\DRIVERS\RtsUCcid.sys File not found
DRV - (RtsUIR) – C:\Windows\System32\DRIVERS\Rts516xIR.sys File not found
DRV - (RSUSBSTOR) – C:\Windows\System32\Drivers\RtsUStor.sys File not found
DRV - (catchme) – C:\Users\jamie\AppData\Local\Temp\catchme.sys File not found
DRV - (mfehidk) – C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfewfpk) – C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfenlfk) – C:\Windows\System32\drivers\mfenlfk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\Windows\System32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\Windows\System32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (RTL8167) – C:\Windows\System32\drivers\Rt86win7.sys (Realtek )
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (RTL8187B) – C:\Windows\System32\drivers\RTL8187B.sys (Realtek Semiconductor Corporation )
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (tos_sps32) – C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwififlt) – C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\system32\DRIVERS\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) – C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\System32\drivers\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (SrvHsfV92) – C:\Windows\System32\drivers\VSTDPV3.SYS (Conexant Systems, Inc.)
DRV - (SrvHsfWinac) – C:\Windows\System32\drivers\VSTCNXT3.SYS (Conexant Systems, Inc.)
DRV - (SrvHsfHDA) – C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (FwLnk) – C:\Windows\system32\DRIVERS\FwLnk.sys (TOSHIBA Corporation)
DRV - (RTHDMIAzAudService) – C:\Windows\System32\drivers\RtHDMIV.sys (Realtek Semiconductor Corp.)
DRV - (PGEffect) – C:\Windows\System32\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV - (AtiPcie) AMD PCI Express (3GIO) – C:\Windows\system32\DRIVERS\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio32.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.defaultthis.engineName: "ooVoo Chat Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1572363&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.1
FF - prefs.js..keyword.URL: "http://uk.search.yahoo.com/search?fr=mcafee&p;="

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/09/15 23:19:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/16 14:24:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/23 13:48:08 | 000,000,000 | —D | M]

[2010/01/13 10:55:48 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Mozilla\Extensions
[2009/11/15 02:18:38 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/02/13 21:17:59 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Mozilla\Firefox\Profiles\e1ix0fhw.default\extensions
[2009/10/06 19:07:30 | 000,000,882 | —- | M] () – C:\Users\jamie\AppData\Roaming\Mozilla\Firefox\Profiles\e1ix0fhw.default\searchplugins\conduit.xml
[2010/04/25 18:13:56 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/08/24 14:57:38 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\Mozilla Firefox\components\Scriptff.dll
[2010/08/23 13:48:02 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/08/23 13:48:02 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/08/23 13:48:02 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/08/23 13:48:02 | 000,000,831 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/07/29 00:12:15 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20100916142404.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [HSON] C:\Program Files\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NetFxUpdate_v1.1.4322] C:\Windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe (Microsoft)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosNC] C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosSENotify] C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Users\jamie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/09/18 13:39:57 | 000,000,000 | —D | C] – C:\Users\jamie\AppData\Local\Adobe
[2010/09/14 00:59:57 | 000,009,344 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeclnk.sys
[2010/09/14 00:59:06 | 000,312,904 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfefirek.sys
[2010/09/14 00:59:06 | 000,164,808 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfewfpk.sys
[2010/09/14 00:59:06 | 000,152,992 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeavfk.sys
[2010/09/14 00:59:06 | 000,084,264 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mferkdet.sys
[2010/09/14 00:59:06 | 000,064,304 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfenlfk.sys
[2010/09/14 00:59:06 | 000,055,840 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\cfwids.sys
[2010/09/14 00:59:06 | 000,052,104 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfebopk.sys
[2010/09/14 00:58:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2010/09/14 00:58:57 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2010/08/22 09:41:05 | 000,000,000 | —D | C] – C:\ProgramData\TOSHIBA Tempro
[2010/08/11 23:46:10 | 000,000,000 | —D | C] – C:\Program Files\Warcraft III
[2010/08/04 02:20:00 | 000,000,000 | R–D | C] – C:\Users\jamie\Saved Games
[2010/08/04 02:20:00 | 000,000,000 | R–D | C] – C:\Users\jamie\Downloads
[2010/07/29 00:15:58 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/07/29 00:15:54 | 000,000,000 | —D | C] – C:\Users\jamie\AppData\Local\temp
[2010/07/29 00:02:16 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/07/29 00:02:16 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/07/29 00:02:16 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/07/29 00:02:09 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/07/28 23:59:09 | 000,000,000 | —D | C] – C:\Qoobox
[2010/07/28 23:58:48 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/07/28 09:40:09 | 000,000,000 | —D | C] – C:\Users\jamie\AppData\Roaming\Malwarebytes
[2010/07/28 09:40:02 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/07/28 09:40:01 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/07/28 09:40:00 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/07/28 09:40:00 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/28 09:39:08 | 006,153,384 | —- | C] (Malwarebytes Corporation ) – C:\Users\jamie\Desktop\mbam-setup.exe
[2010/07/26 15:48:25 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/07/26 15:48:25 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/07/26 15:46:18 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Users\jamie\Desktop\spybotsd162.exe
[2010/07/25 18:13:01 | 000,000,000 | —D | C] – C:\Program Files\Spyware Doctor
[2010/07/25 18:13:01 | 000,000,000 | —D | C] – C:\Users\jamie\AppData\Roaming\PC Tools
[2010/07/25 18:13:01 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2010/07/25 18:13:01 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2010/07/25 18:05:19 | 000,000,000 | —D | C] – C:\ProgramData\Google Updater
[2010/07/25 18:04:59 | 000,000,000 | —D | C] – C:\Program Files\Google
[2010/07/25 17:22:52 | 000,000,000 | —D | C] – C:\Users\jamie\AppData\Roaming\OnlineArmor
[2010/07/25 17:22:52 | 000,000,000 | —D | C] – C:\ProgramData\OnlineArmor
[2010/07/25 17:14:45 | 000,000,000 | —D | C] – C:\Program Files\Emsisoft
[2010/07/25 15:28:21 | 000,000,000 | —D | C] – C:\ProgramData\SITEguard
[2010/07/25 15:26:54 | 000,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2010/07/25 15:26:52 | 000,000,000 | —D | C] – C:\ProgramData\STOPzilla!
[2010/07/25 14:42:08 | 000,000,000 | —D | C] – C:\Users\jamie\Documents\Simply Super Software
[2010/07/25 14:41:32 | 000,000,000 | —D | C] – C:\Program Files\Trojan Remover
[2010/07/25 14:41:32 | 000,000,000 | —D | C] – C:\Users\jamie\AppData\Roaming\Simply Super Software
[2010/07/25 14:41:32 | 000,000,000 | —D | C] – C:\ProgramData\Simply Super Software
[2010/07/25 14:15:47 | 000,000,000 | —D | C] – C:\Users\jamie\AppData\Roaming\Uniblue
[2010/07/25 13:20:49 | 000,000,000 | —D | C] – C:\ProgramData\SecTaskMan
[2010/07/25 12:57:50 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2010/07/16 21:45:01 | 000,000,000 | —D | C] – C:\Users\jamie\Documents\My Games
[2010/07/03 18:14:05 | 000,000,000 | —D | C] – C:\Users\jamie\AppData\Roaming\Amazon
[2010/07/03 18:13:00 | 000,000,000 | —D | C] – C:\Program Files\Amazon

========== Files - Modified Within 90 Days ==========

[2010/09/27 10:51:55 | 000,016,304 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/27 10:51:55 | 000,016,304 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/27 10:45:28 | 003,145,728 | -HS- | M] () – C:\Users\jamie\ntuser.dat
[2010/09/27 10:45:23 | 000,001,795 | —- | M] () – C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2010/09/27 10:44:45 | 000,000,374 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2010/09/27 10:44:37 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/27 10:44:35 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/27 10:44:31 | 2816,864,256 | -HS- | M] () – C:\hiberfil.sys
[2010/09/27 01:41:08 | 006,389,937 | -H– | M] () – C:\Users\jamie\AppData\Local\IconCache.db
[2010/09/26 01:04:52 | 000,000,056 | -H– | M] () – C:\Windows\System32\ezsidmv.dat
[2010/09/22 22:25:14 | 000,000,074 | —- | M] () – C:\Users\jamie\Desktop\National Statistics Online - Population Estimates.URL
[2010/09/22 22:13:54 | 000,000,069 | —- | M] () – C:\Users\jamie\Desktop\Home UK National Statistics Publication Hub.URL
[2010/09/21 16:17:00 | 000,000,082 | —- | M] () – C:\Users\jamie\Desktop\KeyloggerViruseTrojan =(.URL
[2010/09/19 01:31:12 | 000,771,582 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/09/19 01:31:12 | 000,668,192 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/09/19 01:31:12 | 000,127,954 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/09/14 00:46:35 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{fab405a5-bf8d-11df-817f-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/09/14 00:46:35 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{fab405a5-bf8d-11df-817f-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/09/14 00:46:35 | 000,065,536 | -HS- | M] () – C:\Users\jamie\ntuser.dat{fab405a5-bf8d-11df-817f-001e33fd7fdd}.TM.blf
[2010/09/07 17:33:07 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{77c7126e-ba96-11df-a06d-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/09/07 17:33:07 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{77c7126e-ba96-11df-a06d-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/09/07 17:33:07 | 000,065,536 | -HS- | M] () – C:\Users\jamie\ntuser.dat{77c7126e-ba96-11df-a06d-001e33fd7fdd}.TM.blf
[2010/08/24 14:57:38 | 000,386,712 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfehidk.sys
[2010/08/24 14:57:38 | 000,312,904 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfefirek.sys
[2010/08/24 14:57:38 | 000,164,808 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfewfpk.sys
[2010/08/24 14:57:38 | 000,152,992 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeavfk.sys
[2010/08/24 14:57:38 | 000,095,600 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeapfk.sys
[2010/08/24 14:57:38 | 000,084,264 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mferkdet.sys
[2010/08/24 14:57:38 | 000,064,304 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfenlfk.sys
[2010/08/24 14:57:38 | 000,055,840 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\cfwids.sys
[2010/08/24 14:57:38 | 000,052,104 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfebopk.sys
[2010/08/24 14:57:38 | 000,009,344 | —- | M] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeclnk.sys
[2010/08/23 00:13:04 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{6a7f9efc-ae41-11df-945e-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/08/23 00:13:04 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{6a7f9efc-ae41-11df-945e-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/08/23 00:13:04 | 000,065,536 | -HS- | M] () – C:\Users\jamie\ntuser.dat{6a7f9efc-ae41-11df-945e-001e33fd7fdd}.TM.blf
[2010/08/12 13:56:59 | 000,416,208 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/08/11 01:37:02 | 000,000,097 | —- | M] () – C:\Users\jamie\Desktop\Erikson's Stages of Psychosocial Development.URL
[2010/07/29 00:12:41 | 000,000,215 | —- | M] () – C:\Windows\system.ini
[2010/07/29 00:12:15 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/07/28 09:40:05 | 000,000,946 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/28 09:39:25 | 006,153,384 | —- | M] (Malwarebytes Corporation ) – C:\Users\jamie\Desktop\mbam-setup.exe
[2010/07/27 00:36:44 | 000,000,099 | —- | M] () – C:\Users\jamie\Desktop\Keylogger removal.URL
[2010/07/26 22:07:29 | 000,000,082 | —- | M] () – C:\Users\jamie\Desktop\Are you Infected Need Help.URL
[2010/07/26 15:48:31 | 000,001,207 | —- | M] () – C:\Users\jamie\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/07/26 15:48:31 | 000,001,183 | —- | M] () – C:\Users\jamie\Desktop\Spybot - Search & Destroy.lnk
[2010/07/26 15:47:03 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Users\jamie\Desktop\spybotsd162.exe
[2010/07/25 19:32:57 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{8459b70d-9814-11df-b603-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/07/25 19:32:57 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{8459b70d-9814-11df-b603-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/07/25 19:32:57 | 000,065,536 | -HS- | M] () – C:\Users\jamie\ntuser.dat{8459b70d-9814-11df-b603-001e33fd7fdd}.TM.blf
[2010/07/25 18:53:03 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{8459b68a-9814-11df-b603-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/07/25 18:53:03 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{8459b68a-9814-11df-b603-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/07/25 18:53:03 | 000,065,536 | -HS- | M] () – C:\Users\jamie\ntuser.dat{8459b68a-9814-11df-b603-001e33fd7fdd}.TM.blf
[2010/07/25 18:00:09 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{735577fe-980a-11df-aecd-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/07/25 18:00:09 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{735577fe-980a-11df-aecd-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/07/25 18:00:09 | 000,065,536 | -HS- | M] () – C:\Users\jamie\ntuser.dat{735577fe-980a-11df-aecd-001e33fd7fdd}.TM.blf
[2010/07/25 17:41:08 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{735577a0-980a-11df-aecd-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/07/25 17:41:08 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{735577a0-980a-11df-aecd-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/07/25 17:41:08 | 000,065,536 | -HS- | M] () – C:\Users\jamie\ntuser.dat{735577a0-980a-11df-aecd-001e33fd7fdd}.TM.blf
[2010/07/25 16:27:42 | 000,065,536 | -HS- | M] () – C:\Users\jamie\ntuser.dat{f986ef6f-9800-11df-b46b-001e33fd7fdd}.TM.blf
[2010/07/25 16:27:41 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{f986ef6f-9800-11df-b46b-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/07/25 16:27:41 | 000,524,288 | -HS- | M] () – C:\Users\jamie\ntuser.dat{f986ef6f-9800-11df-b46b-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/07/25 15:31:59 | 000,184,320 | -H– | M] () – C:\SZKGFS.dat
[2010/07/25 15:21:28 | 000,000,109 | —- | M] () – C:\Users\jamie\Desktop\WikiAnswers - How do youremove a keylogger file on your computer.URL
[2010/07/19 13:37:58 | 000,000,089 | —- | M] () – C:\Users\jamie\Desktop\Replacement certification for GCE, GCSE, IGCSE, ELC (Academic) and AEA qualifications - information for students Edexcel.URL
[2010/07/17 14:28:45 | 000,000,254 | —- | M] () – C:\Users\jamie\Documents\Document.rtf
[2010/07/15 22:49:29 | 000,000,167 | —- | M] () – C:\Users\jamie\Desktop\Vodafone My phones and plans.URL
[2010/07/12 22:02:23 | 000,001,084 | —- | M] () – C:\Users\jamie\Documents - Shortcut.lnk
[2010/07/06 22:39:39 | 000,001,951 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/07/05 14:48:58 | 000,000,104 | —- | M] () – C:\Users\jamie\Desktop\Freud's psychosexual theory.URL
[2010/07/01 21:40:41 | 000,000,066 | —- | M] () – C:\Users\jamie\Desktop\Faction Champions - WoWWiki - Your guide to the World of Warcraft.URL

========== Files Created - No Company Name ==========

[2010/09/26 01:04:52 | 000,000,056 | -H– | C] () – C:\Windows\System32\ezsidmv.dat
[2010/09/22 22:25:14 | 000,000,074 | —- | C] () – C:\Users\jamie\Desktop\National Statistics Online - Population Estimates.URL
[2010/09/22 22:13:54 | 000,000,069 | —- | C] () – C:\Users\jamie\Desktop\Home UK National Statistics Publication Hub.URL
[2010/09/21 16:17:00 | 000,000,082 | —- | C] () – C:\Users\jamie\Desktop\KeyloggerViruseTrojan =(.URL
[2010/09/14 01:00:59 | 000,001,795 | —- | C] () – C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2010/09/14 00:24:23 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{fab405a5-bf8d-11df-817f-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/09/14 00:24:23 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{fab405a5-bf8d-11df-817f-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/09/14 00:24:23 | 000,065,536 | -HS- | C] () – C:\Users\jamie\ntuser.dat{fab405a5-bf8d-11df-817f-001e33fd7fdd}.TM.blf
[2010/09/07 16:42:28 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{77c7126e-ba96-11df-a06d-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/09/07 16:42:28 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{77c7126e-ba96-11df-a06d-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/09/07 16:42:28 | 000,065,536 | -HS- | C] () – C:\Users\jamie\ntuser.dat{77c7126e-ba96-11df-a06d-001e33fd7fdd}.TM.blf
[2010/08/23 00:03:28 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{6a7f9efc-ae41-11df-945e-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/08/23 00:03:28 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{6a7f9efc-ae41-11df-945e-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/08/23 00:03:28 | 000,065,536 | -HS- | C] () – C:\Users\jamie\ntuser.dat{6a7f9efc-ae41-11df-945e-001e33fd7fdd}.TM.blf
[2010/08/11 01:37:02 | 000,000,097 | —- | C] () – C:\Users\jamie\Desktop\Erikson's Stages of Psychosocial Development.URL
[2010/07/29 00:02:16 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/07/29 00:02:16 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/07/29 00:02:16 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/07/29 00:02:16 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/07/29 00:02:16 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/07/28 09:40:05 | 000,000,946 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/27 00:36:44 | 000,000,099 | —- | C] () – C:\Users\jamie\Desktop\Keylogger removal.URL
[2010/07/26 22:07:29 | 000,000,082 | —- | C] () – C:\Users\jamie\Desktop\Are you Infected Need Help.URL
[2010/07/26 15:48:31 | 000,001,207 | —- | C] () – C:\Users\jamie\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/07/26 15:48:31 | 000,001,183 | —- | C] () – C:\Users\jamie\Desktop\Spybot - Search & Destroy.lnk
[2010/07/25 19:14:01 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{8459b70d-9814-11df-b603-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/07/25 19:14:01 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{8459b70d-9814-11df-b603-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/07/25 19:14:01 | 000,065,536 | -HS- | C] () – C:\Users\jamie\ntuser.dat{8459b70d-9814-11df-b603-001e33fd7fdd}.TM.blf
[2010/07/25 18:47:47 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{8459b68a-9814-11df-b603-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/07/25 18:47:47 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{8459b68a-9814-11df-b603-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/07/25 18:47:47 | 000,065,536 | -HS- | C] () – C:\Users\jamie\ntuser.dat{8459b68a-9814-11df-b603-001e33fd7fdd}.TM.blf
[2010/07/25 18:00:09 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{735577fe-980a-11df-aecd-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/07/25 18:00:09 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{735577fe-980a-11df-aecd-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/07/25 18:00:09 | 000,065,536 | -HS- | C] () – C:\Users\jamie\ntuser.dat{735577fe-980a-11df-aecd-001e33fd7fdd}.TM.blf
[2010/07/25 17:37:20 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{735577a0-980a-11df-aecd-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/07/25 17:37:20 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{735577a0-980a-11df-aecd-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/07/25 17:37:20 | 000,065,536 | -HS- | C] () – C:\Users\jamie\ntuser.dat{735577a0-980a-11df-aecd-001e33fd7fdd}.TM.blf
[2010/07/25 16:27:41 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{f986ef6f-9800-11df-b46b-001e33fd7fdd}.TMContainer00000000000000000002.regtrans-ms
[2010/07/25 16:27:41 | 000,524,288 | -HS- | C] () – C:\Users\jamie\ntuser.dat{f986ef6f-9800-11df-b46b-001e33fd7fdd}.TMContainer00000000000000000001.regtrans-ms
[2010/07/25 16:27:41 | 000,065,536 | -HS- | C] () – C:\Users\jamie\ntuser.dat{f986ef6f-9800-11df-b46b-001e33fd7fdd}.TM.blf
[2010/07/25 15:31:59 | 000,184,320 | -H– | C] () – C:\SZKGFS.dat
[2010/07/25 15:21:28 | 000,000,109 | —- | C] () – C:\Users\jamie\Desktop\WikiAnswers - How do youremove a keylogger file on your computer.URL
[2010/07/19 13:37:58 | 000,000,089 | —- | C] () – C:\Users\jamie\Desktop\Replacement certification for GCE, GCSE, IGCSE, ELC (Academic) and AEA qualifications - information for students Edexcel.URL
[2010/07/17 14:28:45 | 000,000,254 | —- | C] () – C:\Users\jamie\Documents\Document.rtf
[2010/07/15 22:49:29 | 000,000,167 | —- | C] () – C:\Users\jamie\Desktop\Vodafone My phones and plans.URL
[2010/07/12 22:02:23 | 000,001,084 | —- | C] () – C:\Users\jamie\Documents - Shortcut.lnk
[2010/07/05 14:48:58 | 000,000,104 | —- | C] () – C:\Users\jamie\Desktop\Freud's psychosexual theory.URL
[2010/07/01 21:40:41 | 000,000,066 | —- | C] () – C:\Users\jamie\Desktop\Faction Champions - WoWWiki - Your guide to the World of Warcraft.URL
[2010/02/13 19:51:21 | 000,000,093 | —- | C] () – C:\Users\jamie\AppData\Local\fusioncache.dat
[2010/01/14 12:49:35 | 000,000,000 | —- | C] () – C:\Users\jamie\AppData\Roaming\wklnhst.dat
[2009/12/03 10:27:28 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/10/23 19:29:34 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/07/14 00:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll

========== LOP Check ==========

[2010/07/03 18:14:05 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Amazon
[2010/05/09 20:09:20 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\FOG Downloader
[2010/04/01 03:30:48 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\GetRightToGo
[2010/07/25 17:23:14 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\OnlineArmor
[2010/01/23 19:49:28 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\ooVoo Details
[2010/07/25 14:41:32 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Simply Super Software
[2010/01/14 12:49:37 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Template
[2010/02/18 16:57:01 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Toshiba
[2010/03/04 02:34:02 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Turbine
[2010/07/25 14:15:47 | 000,000,000 | —D | M] – C:\Users\jamie\AppData\Roaming\Uniblue
[2010/09/18 12:13:41 | 000,032,608 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:CB0AACC9
< End of report >
Okay, please follow these steps:


Step 1 | Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\Users\jamie\AppData\Local\Apps\2.0\YPK0YGLM.WTY\J26G0RD7.6Z3\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\CurseClient.exe (Curse)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O4 - Startup: C:\Users\jamie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
    
    :Files
    C:\Users\jamie\AppData\Local\Apps
    
    :Commands
    [purity]
    [EmptyFlash]
    [emptytemp]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • It will produce a log for you on reboot, please post that log in your next reply.

Step 2 | Please go to your C drive and open the following text file:

C:\ComboFix.txt

Paste it's contents in your next reply

Also, navigate to the following folder:

C:\Qoobox

Copy the contents of every ComboFix log (if present), and paste them in your next reply.
C:\Qoobox Was the only one I could find, I did run the on OTL and it said the curseclient couldnt be found. But I cant find the log it made. Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.3.3 Amazon MP3 Downloader 1.0.9 ATI Catalyst Install Manager ATI Catalyst Registration Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center Graphics Previews Vista Catalyst Control Center HydraVision Full Catalyst Control Center InstallProxy ccc-core-static ccc-utility CCC Help English Compatibility Pack for the 2007 Office system Curse Client HDAUDIO Soft Data Fax Modem with SmartCP Java™ 6 Update 14 Junk Mail filter update LimeWire 5.5.8 Malwarebytes' Anti-Malware McAfee SecurityCenter Messenger Plus! Live Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual J# .NET Redistributable Package 1.1 Mozilla Firefox (3.5.10) MSVCRT OGA Notifier 2.0.0048.0 Realtek Ethernet Controller Driver Realtek High Definition Audio Driver Realtek USB 2.0 Card Reader Realtek WLAN Driver Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for 2007 Microsoft Office System (KB982312) Security Update for 2007 Microsoft Office System (KB982331) Security Update for Microsoft Office Access 2007 (KB979440) Security Update for Microsoft Office Excel 2007 (KB982308) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office Outlook 2007 (KB980376) Security Update for Microsoft Office PowerPoint 2007 (KB982158) Security Update for Microsoft Office Publisher 2007 (KB982124) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB982135) Skype™ 4.2 Spybot - Search & Destroy TOSHIBA Bulletin Board TOSHIBA ConfigFree TOSHIBA Disc Creator TOSHIBA Extended Tiles for Windows Mobility Center TOSHIBA Hardware Setup TOSHIBA HDD/SSD Alert TOSHIBA Internal Modem Region Select Utility Toshiba Manuals Toshiba Online Product Information TOSHIBA Recovery Media Creator TOSHIBA Recovery Media Creator Reminder TOSHIBA ReelTime TOSHIBA Service Station TOSHIBA Supervisor Password Toshiba TEMPRO TOSHIBA Value Added Package TOSHIBA Web Camera Application TRORMCLauncher Update for 2007 Microsoft Office System (KB967642) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update for Outlook 2007 Junk Email Filter (kb2202131) V.92 Modem On Hold Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Mail Windows Live Messenger World of Warcraft 2010-07-28 23:15:28 . 2010-07-28 23:15:28 1,214 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-WildTangentGameProvider-toshiba-genres.reg.dat 2010-07-28 23:15:03 . 2010-07-28 23:15:03 884 —-a-w- C:\Qoobox\Quarantine\Registry_backups\MSConfigStartUp-ZagrebLand.reg.dat 2010-07-28 23:15:03 . 2010-07-28 23:15:03 876 —-a-w- C:\Qoobox\Quarantine\Registry_backups\MSConfigStartUp-Videocan.reg.dat 2010-07-28 23:14:39 . 2010-07-28 23:14:39 166 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-ATICustomerCare.reg.dat 2010-07-28 23:09:22 . 2010-07-28 23:09:22 9,235 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg 2010-07-28 23:02:09 . 2010-07-28 23:03:47 62 —-a-w- C:\Qoobox\Quarantine\catchme.log 2010-03-15 22:32:08 . 2010-03-15 22:32:08 0 —-a-w- C:\Qoobox\Quarantine\C\LHTD8DB.tmp.vir
Hi Jamie,


Sorry for the delay. Please navigate to the following location:

C:\_OTL\Moved Files

Open the file logfile created by OTL. It will have the following name: MMDDYYY_HHMMSS.log where MMDDYYY is date format and HHMMSS is time format.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI